4CE0000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
0000000C.00000002.2697502538.0000000004CE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4CE0000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
5780000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
0000000D.00000002.2699158883.0000000005780000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5780000
|
Size: |
659456
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3A20000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000007.00000002.1800345962.0000000003A20000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3A20000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
400000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000007.00000002.1799971563.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
290816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
4C00000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000007.00000002.1800824318.0000000004C00000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4C00000
|
Size: |
9310208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3190000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
0000000B.00000002.2697537339.0000000003190000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3190000
|
Size: |
9310208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3000000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
0000000C.00000002.2695985493.0000000003000000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
3000000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
4C90000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
0000000C.00000002.2697439176.0000000004C90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4C90000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
4A3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496394812.0000000004A3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4A3E000
|
Size: |
8192
|
|
7F1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696156614.00000000007F1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7F1000
|
Size: |
4096
|
|
4683000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1557127081.0000000004683000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4683000
|
Size: |
507904
|
|
3114000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1987792478.0000000003114000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3114000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
42F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1564417820.00000000042F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
42F0000
|
Size: |
12288
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982675108.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
1DC08750000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000010.00000003.2050301856.000001DC08750000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DC08750000
|
Size: |
4096
|
|
818F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.000000000818F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
818F000
|
Size: |
4096
|
|
3734000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697738139.0000000003734000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3734000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982974918.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983184081.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
811B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1993844402.000000000811B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
811B000
|
Size: |
8192
|
|
314E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.000000000314E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
314E000
|
Size: |
4096
|
|
716F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1570486030.000000000716F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
716F000
|
Size: |
8192
|
|
13A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1874879561.00000000013A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13A0000
|
Size: |
8192
|
|
6E60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569972824.0000000006E60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6E60000
|
Size: |
36864
|
|
3DCD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.1800388098.0000000003DCD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3DCD000
|
Size: |
4096
|
|
6860000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495609878.0000000006860000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
6860000
|
Size: |
180224
|
|
1390000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2696943202.0000000001390000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1390000
|
Size: |
4096
|
|
2D0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697190135.0000000002D0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D0E000
|
Size: |
8192
|
|
73D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1572229030.00000000073D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
73D0000
|
Size: |
65536
|
|
8087000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1574010491.0000000008087000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8087000
|
Size: |
118784
|
|
1DC06E70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000010.00000003.2051332400.000001DC06E70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DC06E70000
|
Size: |
4096
|
|
4C0B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496769243.0000000004C0B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C0B000
|
Size: |
20480
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1996515091.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
92E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696261877.000000000092E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
92E000
|
Size: |
57344
|
|
1300000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1874782376.0000000001300000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1300000
|
Size: |
4096
|
|
817F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.000000000817F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
817F000
|
Size: |
8192
|
|
A20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.1559196345.0000000000A20000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A20000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983622721.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
80FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699825131.00000000080FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
80FE000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979914483.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
1DC06E6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000010.00000003.2051332400.000001DC06E6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DC06E6C000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980540413.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
2568000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1563552873.0000000002568000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2568000
|
Size: |
32768
|
|
2828000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1563670266.0000000002828000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2828000
|
Size: |
28672
|
|
7D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1494827614.00000000007D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D0000
|
Size: |
4096
|
|
7190000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1571138613.0000000007190000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7190000
|
Size: |
4096
|
|
484E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565426233.000000000484E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
484E000
|
Size: |
8192
|
|
4800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697363686.0000000004800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4800000
|
Size: |
4096
|
|
3980000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800309510.0000000003980000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3980000
|
Size: |
274432
|
|
47DD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1550365432.00000000047DD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
47DD000
|
Size: |
458752
|
|
3419000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800144174.0000000003419000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3419000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985243808.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
1ABE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1544037929.0000000001ABE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1ABE000
|
Size: |
114688
|
|
9C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720683633.00000000009C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C0000
|
Size: |
32768
|
|
1650000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559517896.0000000001650000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1650000
|
Size: |
8192
|
|
7163000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1570486030.0000000007163000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7163000
|
Size: |
12288
|
|
6A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2695985198.00000000006A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A0000
|
Size: |
8192
|
|
179E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559556792.000000000179E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
179E000
|
Size: |
8192
|
|
4B88000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496485818.0000000004B88000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B88000
|
Size: |
86016
|
|
12F000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2695980394.000000000012F000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
12F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
69AB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569093331.00000000069AB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
69AB000
|
Size: |
20480
|
|
1DC08800000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2101249940.000001DC08800000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DC08800000
|
Size: |
4096
|
|
EB0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.1874533031.0000000000EB0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EB0000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979264116.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
3151000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.0000000003151000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3151000
|
Size: |
16384
|
|
6A1C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569277961.0000000006A1C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6A1C000
|
Size: |
16384
|
|
4633000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1551120326.0000000004633000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4633000
|
Size: |
507904
|
|
2D10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697235346.0000000002D10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D10000
|
Size: |
20480
|
|
30CF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1800742188.00000000030CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30CF000
|
Size: |
20480
|
|
7070000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1570348625.0000000007070000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
7070000
|
Size: |
4096
|
|
4B80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496485818.0000000004B80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B80000
|
Size: |
28672
|
|
1A72000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1539717139.0000000001A72000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A72000
|
Size: |
339968
|
|
9CE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720683633.00000000009CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9CE000
|
Size: |
90112
|
|
51BD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.2697687599.00000000051BD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
51BD000
|
Size: |
4096
|
|
9CA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2696806857.00000000009CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9CA000
|
Size: |
8192
|
|
5242000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2698221269.0000000005242000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5242000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985861492.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
7340000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1571733725.0000000007340000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7340000
|
Size: |
61440
|
|
2E9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2695845914.00000000002E9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E9000
|
Size: |
28672
|
|
1DC06CC1000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000010.00000002.2100915300.000001DC06CC1000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
1DC06CC1000
|
Size: |
8192
|
|
1DC08660000
|
heap
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2101195660.000001DC08660000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DC08660000
|
Size: |
4096
|
|
4633000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1550181977.0000000004633000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4633000
|
Size: |
507904
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982468972.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
341A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1768024347.000000000341A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
341A000
|
Size: |
4096
|
|
44C5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496267303.00000000044C5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
44C5000
|
Size: |
12288
|
|
2F4C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800016152.0000000002F4C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F4C000
|
Size: |
16384
|
|
141A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697245010.000000000141A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
141A000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979703698.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
4200000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.1800824318.0000000004200000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4200000
|
Size: |
10485760
|
|
C8F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720754824.0000000000C8F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C8F000
|
Size: |
4096
|
|
17DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559576310.00000000017DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
17DE000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1984521180.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1703584945.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981953093.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981992924.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
49FA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496371296.00000000049FA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
49FA000
|
Size: |
24576
|
|
8192000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1574516896.0000000008192000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8192000
|
Size: |
57344
|
|
499C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.000000000499C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
499C000
|
Size: |
4096
|
|
58FC000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2699488130.00000000058FC000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
58FC000
|
Size: |
16384
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980884874.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B90000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2697405663.0000000004B90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B90000
|
Size: |
4096
|
|
1A53000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559764252.0000000001A53000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A53000
|
Size: |
131072
|
|
100D000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2696642374.000000000100D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
100D000
|
Size: |
4096
|
|
3090000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696158995.0000000003090000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3090000
|
Size: |
4096
|
|
1AC5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1539967573.0000000001AC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1AC5000
|
Size: |
245760
|
|
447C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496240479.000000000447C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
447C000
|
Size: |
16384
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1717269723.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980196808.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
940000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2696726301.0000000000940000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
940000
|
Size: |
4096
|
|
6C2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569628812.0000000006C2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6C2E000
|
Size: |
8192
|
|
A21000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000006.00000002.1559213347.0000000000A21000.00000020.00000001.01000000.00000009.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
A21000
|
Size: |
581632
|
|
7FEA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1573481868.0000000007FEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7FEA000
|
Size: |
155648
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
4829000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1556852418.0000000004829000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4829000
|
Size: |
4096
|
|
3200000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800093009.0000000003200000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3200000
|
Size: |
4096
|
|
692D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1568988936.000000000692D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
692D000
|
Size: |
12288
|
|
5B3F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2699604787.0000000005B3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5B3F000
|
Size: |
4096
|
|
4AE0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495796363.0000000004AE0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4AE0000
|
Size: |
4096
|
|
4320000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1564845892.0000000004320000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4320000
|
Size: |
4096
|
|
88EF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2700866304.00000000088EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
88EF000
|
Size: |
4096
|
|
5E1000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1720540295.00000000005E1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5E1000
|
Size: |
12288
|
|
5BB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698817389.0000000005BB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BB0000
|
Size: |
16384
|
|
1C38000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559997118.0000000001C38000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C38000
|
Size: |
4096
|
|
3B00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.1800388098.0000000003B00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3B00000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7EE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1573106345.0000000007EE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7EE0000
|
Size: |
24576
|
|
2790000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.2697537339.0000000002790000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
2790000
|
Size: |
10485760
|
|
813B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.000000000813B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
813B000
|
Size: |
20480
|
|
4B20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496439280.0000000004B20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B20000
|
Size: |
4096
|
|
8171000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.0000000008171000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8171000
|
Size: |
12288
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981906807.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
25E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1563587990.00000000025E0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25E0000
|
Size: |
4096
|
|
F2A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2696263801.0000000000F2A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F2A000
|
Size: |
24576
|
|
4980000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.0000000004980000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4980000
|
Size: |
8192
|
|
EC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2696200106.0000000000EC0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EC0000
|
Size: |
4096
|
|
296E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1563957517.000000000296E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
296E000
|
Size: |
8192
|
|
4E7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496795814.0000000004E7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E7F000
|
Size: |
4096
|
|
489E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1558217703.000000000489E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
489E000
|
Size: |
24576
|
|
30D3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1800847308.00000000030D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30D3000
|
Size: |
24576
|
|
F70000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2696354000.0000000000F70000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F70000
|
Size: |
4096
|
|
884F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2700781279.000000000884F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
884F000
|
Size: |
4096
|
|
3400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800127282.0000000003400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3400000
|
Size: |
45056
|
|
311E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1987927885.000000000311E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
311E000
|
Size: |
8192
|
|
4A40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496418381.0000000004A40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4A40000
|
Size: |
8192
|
|
3A58000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697738139.0000000003A58000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3A58000
|
Size: |
8192
|
|
582C000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2699158883.000000000582C000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
582C000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
121000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000B.00000002.2695937840.0000000000121000.00000020.00000001.01000000.0000000A.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
121000
|
Size: |
57344
|
|
4988000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.0000000004988000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4988000
|
Size: |
8192
|
|
4829000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1557262259.0000000004829000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4829000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1713635041.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
4BC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496662253.0000000004BC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BC3000
|
Size: |
65536
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981247104.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
7F20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1573271903.0000000007F20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7F20000
|
Size: |
53248
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1978796488.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
73C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1572149172.00000000073C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
73C0000
|
Size: |
65536
|
|
8069000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1573481868.0000000008069000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8069000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
696F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569022046.000000000696F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
696F000
|
Size: |
4096
|
|
47F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565403569.00000000047F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
47F0000
|
Size: |
65536
|
|
4804000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697363686.0000000004804000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4804000
|
Size: |
4096
|
|
8179000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.0000000008179000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8179000
|
Size: |
8192
|
|
7ED0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1572966426.0000000007ED0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7ED0000
|
Size: |
8192
|
|
4E90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1813855351.0000000004E90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E90000
|
Size: |
176128
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1984372201.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981715076.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
1A87000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559878776.0000000001A87000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A87000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985715368.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982731037.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
6D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696054610.00000000006D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6D0000
|
Size: |
16384
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983743923.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
3164000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.0000000003164000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3164000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1823780113.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
241664
|
|
4A49000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565515176.0000000004A49000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A49000
|
Size: |
2473984
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985760813.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
814C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.000000000814C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
814C000
|
Size: |
8192
|
|
47DD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1554283321.00000000047DD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
47DD000
|
Size: |
458752
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1977784901.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
1A24000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1539886102.0000000001A24000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A24000
|
Size: |
49152
|
|
7350000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1571838096.0000000007350000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7350000
|
Size: |
65536
|
|
430D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1564504428.000000000430D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
430D000
|
Size: |
8192
|
|
5302000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2698221269.0000000005302000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5302000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1996368979.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4BAE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495457014.0000000004BAE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BAE000
|
Size: |
65536
|
|
3FA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1560146552.0000000003FA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3FA0000
|
Size: |
4096
|
|
5848000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2699158883.0000000005848000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5848000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983385561.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1823863983.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4994000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.0000000004994000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4994000
|
Size: |
4096
|
|
1DC08ABE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000010.00000003.2051217787.000001DC08ABE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DC08ABE000
|
Size: |
12288
|
|
141E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1874951378.000000000141E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
141E000
|
Size: |
90112
|
|
7182000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1570486030.0000000007182000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7182000
|
Size: |
53248
|
|
6D6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569893234.0000000006D6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6D6E000
|
Size: |
8192
|
|
4F0C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698459559.0000000004F0C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F0C000
|
Size: |
16384
|
|
6BAD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569572268.0000000006BAD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BAD000
|
Size: |
12288
|
|
47D9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1554283321.00000000047D9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
47D9000
|
Size: |
4096
|
|
73B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1572102696.00000000073B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
73B0000
|
Size: |
65536
|
|
33E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2697375627.00000000033E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33E0000
|
Size: |
16384
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979420901.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
F80000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.1874639333.0000000000F80000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F80000
|
Size: |
4096
|
|
101F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1495004287.000000000101F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
101F000
|
Size: |
4096
|
|
83AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1575291494.00000000083AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83AE000
|
Size: |
8192
|
|
4BD3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495204703.0000000004BD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BD3000
|
Size: |
131072
|
|
7EEB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1573106345.0000000007EEB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7EEB000
|
Size: |
4096
|
|
1DC08921000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2101299045.000001DC08921000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DC08921000
|
Size: |
4096
|
|
535C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2698221269.000000000535C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
535C000
|
Size: |
4096
|
|
3189000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.0000000003189000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3189000
|
Size: |
8192
|
|
70D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1570486030.00000000070D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70D6000
|
Size: |
131072
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
51C1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.2697687599.00000000051C1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
51C1000
|
Size: |
458752
|
|
3123000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1987927885.0000000003123000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3123000
|
Size: |
12288
|
|
286E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1563745855.000000000286E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
286E000
|
Size: |
454656
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2F7F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697552693.0000000002F7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F7F000
|
Size: |
4096
|
|
6AAD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569331036.0000000006AAD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6AAD000
|
Size: |
12288
|
|
1A51000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559723552.0000000001A51000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A51000
|
Size: |
4096
|
|
3BEA000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697738139.0000000003BEA000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3BEA000
|
Size: |
4096
|
|
313C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1992625129.000000000313C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
313C000
|
Size: |
4096
|
|
43E0000
|
heap
|
page readonly
|
|
|
|
Name: |
00000003.00000002.1565050948.00000000043E0000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
43E0000
|
Size: |
4096
|
|
310F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1987792478.000000000310F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
310F000
|
Size: |
4096
|
|
AD4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1539239351.0000000000AD4000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AD4000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
6820000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495713383.0000000006820000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
6820000
|
Size: |
262144
|
|
FA0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2696473621.0000000000FA0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
FA0000
|
Size: |
4096
|
|
489E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1557262259.000000000489E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
489E000
|
Size: |
24576
|
|
39D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1713548278.00000000039D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39D0000
|
Size: |
180224
|
|
950000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696991367.0000000000950000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
950000
|
Size: |
4096
|
|
7400000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1572420794.0000000007400000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7400000
|
Size: |
65536
|
|
870C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2700572704.000000000870C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
870C000
|
Size: |
16384
|
|
1390000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1874860723.0000000001390000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1390000
|
Size: |
4096
|
|
6AEB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569369554.0000000006AEB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6AEB000
|
Size: |
20480
|
|
EA0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.1874515670.0000000000EA0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EA0000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983847365.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
F70000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.1874620800.0000000000F70000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F70000
|
Size: |
4096
|
|
4E90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1876669229.0000000004E90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E90000
|
Size: |
176128
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983123966.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
8D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696261877.00000000008D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D7000
|
Size: |
69632
|
|
121000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000D.00000002.2695939913.0000000000121000.00000020.00000001.01000000.0000000A.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
121000
|
Size: |
57344
|
|
C3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1494901637.0000000000C3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C3E000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980920846.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
3405000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1700671872.0000000003405000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3405000
|
Size: |
49152
|
|
4D8F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698368951.0000000004D8F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D8F000
|
Size: |
4096
|
|
484E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1550365432.000000000484E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
484E000
|
Size: |
24576
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981478057.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983259368.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4D42000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1803238497.0000000004D42000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D42000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1A12000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559663208.0000000001A12000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A12000
|
Size: |
122880
|
|
4560000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1557592765.0000000004560000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4560000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985099606.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
ADE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559308599.0000000000ADE000.00000004.00000001.01000000.00000009.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
ADE000
|
Size: |
36864
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980426577.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
26A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2697361066.00000000026A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
26A0000
|
Size: |
925696
|
|
1A89000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1540287319.0000000001A89000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A89000
|
Size: |
32768
|
|
85FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1575697643.00000000085FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
85FE000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981868277.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4951000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565515176.0000000004951000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4951000
|
Size: |
1003520
|
|
482D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1556852418.000000000482D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
482D000
|
Size: |
458752
|
|
5F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720558491.00000000005F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F0000
|
Size: |
20480
|
|
4BD7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495426856.0000000004BD7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BD7000
|
Size: |
114688
|
|
880E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2700756706.000000000880E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
880E000
|
Size: |
8192
|
|
4A70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698256418.0000000004A70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4A70000
|
Size: |
4096
|
|
FEE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1874712613.0000000000FEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FEE000
|
Size: |
8192
|
|
4952000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.0000000004952000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4952000
|
Size: |
4096
|
|
4CB3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565515176.0000000004CB3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4CB3000
|
Size: |
8192
|
|
716B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1570486030.000000000716B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
716B000
|
Size: |
4096
|
|
590000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1720431381.0000000000590000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
590000
|
Size: |
4096
|
|
30B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.00000000030B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30B0000
|
Size: |
24576
|
|
1AAD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559894527.0000000001AAD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1AAD000
|
Size: |
20480
|
|
918000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1456752609.0000000000918000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
918000
|
Size: |
49152
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1709234367.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
5DEF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2699196690.0000000005DEF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5DEF000
|
Size: |
4096
|
|
7FDA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1573481868.0000000007FDA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7FDA000
|
Size: |
20480
|
|
3141000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1992625129.0000000003141000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3141000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
1DC08750000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000010.00000003.2050247448.000001DC08750000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DC08750000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1703526369.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
8120000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.0000000008120000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8120000
|
Size: |
8192
|
|
1A42000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559723552.0000000001A42000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A42000
|
Size: |
49152
|
|
4CB8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1800364851.0000000004CB8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB8000
|
Size: |
512000
|
|
30D3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1800636000.00000000030D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30D3000
|
Size: |
24576
|
|
484E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1556394129.000000000484E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
484E000
|
Size: |
24576
|
|
4683000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1556718654.0000000004683000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4683000
|
Size: |
507904
|
|
6BEA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569600389.0000000006BEA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BEA000
|
Size: |
24576
|
|
6B6F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569530165.0000000006B6F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6B6F000
|
Size: |
4096
|
|
1DC08740000
|
heap
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2101219953.000001DC08740000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DC08740000
|
Size: |
12288
|
|
1AB2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1549878021.0000000001AB2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1AB2000
|
Size: |
69632
|
|
1020000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1720804516.0000000001020000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1020000
|
Size: |
397312
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
8B4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696261877.00000000008B4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8B4000
|
Size: |
36864
|
|
500E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698533972.000000000500E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
500E000
|
Size: |
8192
|
|
725E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1571299261.000000000725E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
725E000
|
Size: |
8192
|
|
13B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697060357.00000000013B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13B0000
|
Size: |
16384
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981169150.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4700000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1557262259.0000000004700000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4700000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7F980000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1576306874.000000007F980000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7F980000
|
Size: |
4096
|
|
5CEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2699162387.0000000005CEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5CEE000
|
Size: |
8192
|
|
810D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1986308875.000000000810D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
810D000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
9CE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2696806857.00000000009CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9CE000
|
Size: |
229376
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
55A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720408763.000000000055A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
55A000
|
Size: |
24576
|
|
4C0B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495486422.0000000004C0B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C0B000
|
Size: |
20480
|
|
504B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698556029.000000000504B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
504B000
|
Size: |
20480
|
|
1680000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559537056.0000000001680000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1680000
|
Size: |
4096
|
|
7360000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1571889742.0000000007360000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7360000
|
Size: |
65536
|
|
4EF0000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.2697537339.0000000004EF0000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
4EF0000
|
Size: |
10485760
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983892781.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
2864000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1563745855.0000000002864000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2864000
|
Size: |
36864
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1986492797.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1984069684.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
3202000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800093009.0000000003202000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3202000
|
Size: |
20480
|
|
2430000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2697185419.0000000002430000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2430000
|
Size: |
4096
|
|
7294000
|
system
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2099568350.0000000007294000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
7294000
|
Size: |
4096
|
|
4E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1720361416.00000000004E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4E0000
|
Size: |
4096
|
|
8BE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696261877.00000000008BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8BE000
|
Size: |
36864
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980464679.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983068666.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
480F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697363686.000000000480F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
480F000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1978105335.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
283A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1563745855.000000000283A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
283A000
|
Size: |
151552
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980161225.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
1A77000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1559794439.0000000001A77000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1A77000
|
Size: |
16384
|
|
121000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000D.00000000.1874437484.0000000000121000.00000020.00000001.01000000.0000000A.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
121000
|
Size: |
57344
|
|
43F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565119868.00000000043F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
43F0000
|
Size: |
4096
|
|
1DC06C40000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000010.00000002.2100915300.000001DC06C40000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
1DC06C40000
|
Size: |
471040
|
|
7DF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1572572716.0000000007DF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DF0000
|
Size: |
61440
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982380756.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
319D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.000000000319D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
319D000
|
Size: |
73728
|
|
1A32000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1539833181.0000000001A32000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A32000
|
Size: |
126976
|
|
6880000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495668663.0000000006880000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
6880000
|
Size: |
49152
|
|
47DD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1556394129.00000000047DD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
47DD000
|
Size: |
458752
|
|
71D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1494742818.000000000071D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
71D000
|
Size: |
12288
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983016067.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
30C8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1800796809.00000000030C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C8000
|
Size: |
28672
|
|
5B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1720480166.00000000005B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5B0000
|
Size: |
4096
|
|
30CA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1800716352.00000000030CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30CA000
|
Size: |
36864
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1717383735.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
245760
|
|
1A00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559641817.0000000001A00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A00000
|
Size: |
69632
|
|
1DC0890A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2101299045.000001DC0890A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DC0890A000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982138017.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
2430000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720855507.0000000002430000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2430000
|
Size: |
4096
|
|
AAF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.1559262519.0000000000AAF000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AAF000
|
Size: |
147456
|
|
4CB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565515176.0000000004CB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4CB0000
|
Size: |
8192
|
|
5BB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698817389.0000000005BB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BB5000
|
Size: |
24576
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1984214394.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
8C9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696261877.00000000008C9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8C9000
|
Size: |
53248
|
|
1DC08ACE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000010.00000003.2051188151.000001DC08ACE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DC08ACE000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1996808351.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
1A89000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559894527.0000000001A89000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A89000
|
Size: |
114688
|
|
6D2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569788953.0000000006D2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6D2E000
|
Size: |
8192
|
|
5B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2696393810.00000000005B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5B0000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981681894.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981402354.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
26A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1720989510.00000000026A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
26A0000
|
Size: |
925696
|
|
52DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698678284.00000000052DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52DE000
|
Size: |
8192
|
|
139000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.1874495856.0000000000139000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
139000
|
Size: |
61440
|
|
1A70000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.1875055172.0000000001A70000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A70000
|
Size: |
397312
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
2712000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1560126310.0000000002712000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2712000
|
Size: |
8192
|
|
2830000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1563745855.0000000002830000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2830000
|
Size: |
36864
|
|
4700000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1558217703.0000000004700000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4700000
|
Size: |
1196032
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1996322966.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981320322.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
46B0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1554283321.00000000046B0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
46B0000
|
Size: |
1196032
|
|
4EE0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1803238497.0000000004EE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EE0000
|
Size: |
24576
|
|
4310000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1564529478.0000000004310000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4310000
|
Size: |
32768
|
|
4BA1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1496160115.0000000004BA1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BA1000
|
Size: |
53248
|
|
8EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696261877.00000000008EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8EA000
|
Size: |
36864
|
|
3900000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1702775205.0000000003900000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3900000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
68F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496839281.00000000068F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
68F0000
|
Size: |
8192
|
|
13A4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1874879561.00000000013A4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13A4000
|
Size: |
4096
|
|
444C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565217706.000000000444C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
444C000
|
Size: |
16384
|
|
4683000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1557592765.0000000004683000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4683000
|
Size: |
507904
|
|
2820000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1563670266.0000000002820000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2820000
|
Size: |
28672
|
|
812D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1993844402.000000000812D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
812D000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1984684053.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
EB0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2696158556.0000000000EB0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EB0000
|
Size: |
4096
|
|
1320000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2696804336.0000000001320000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1320000
|
Size: |
16384
|
|
3147000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1992625129.0000000003147000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3147000
|
Size: |
4096
|
|
292B1FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2100865187.000000292B1FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
292B1FE000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979209989.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
7E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1572718232.0000000007E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7E00000
|
Size: |
8192
|
|
1AC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1544367757.0000000001AC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1AC3000
|
Size: |
126976
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980347715.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
1DC08AA9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000010.00000003.2051267924.000001DC08AA9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DC08AA9000
|
Size: |
8192
|
|
30CA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.00000000030CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30CA000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
4332000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1564921785.0000000004332000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4332000
|
Size: |
12288
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979112316.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4330000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1564902036.0000000004330000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4330000
|
Size: |
4096
|
|
8F6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1456839478.00000000008F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F6000
|
Size: |
20480
|
|
2594000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2697272870.0000000002594000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2594000
|
Size: |
4096
|
|
99E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720643061.000000000099E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
99E000
|
Size: |
8192
|
|
7EB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1572878272.0000000007EB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7EB0000
|
Size: |
4096
|
|
29B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1564009583.00000000029B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29B0000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1984969055.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
59FC000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2699524379.00000000059FC000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
59FC000
|
Size: |
16384
|
|
49A2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.00000000049A2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
49A2000
|
Size: |
4096
|
|
8132000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1993844402.0000000008132000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8132000
|
Size: |
8192
|
|
501D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.2697687599.000000000501D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
501D000
|
Size: |
458752
|
|
4B9D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495983193.0000000004B9D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B9D000
|
Size: |
69632
|
|
1DC06E73000
|
heap
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2101153620.000001DC06E73000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DC06E73000
|
Size: |
28672
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1717119865.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
88CC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1576198381.00000000088CC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
88CC000
|
Size: |
16384
|
|
2594000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720926116.0000000002594000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2594000
|
Size: |
4096
|
|
3187000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.0000000003187000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3187000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982319648.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4C09000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495344371.0000000004C09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C09000
|
Size: |
28672
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979825782.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
3072000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697738139.0000000003072000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3072000
|
Size: |
4096
|
|
8660000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1575775037.0000000008660000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8660000
|
Size: |
40960
|
|
AE7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1539316022.0000000000AE7000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AE7000
|
Size: |
409600
|
|
4BB9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496614498.0000000004BB9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BB9000
|
Size: |
20480
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980265745.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983584041.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4335000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1564945823.0000000004335000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
4335000
|
Size: |
45056
|
|
C90000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1720780908.0000000000C90000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C90000
|
Size: |
40960
|
|
8128000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1993844402.0000000008128000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8128000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7370000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1571931913.0000000007370000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7370000
|
Size: |
65536
|
|
874D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2700609641.000000000874D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
874D000
|
Size: |
12288
|
|
3A2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1702775205.0000000003A2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3A2D000
|
Size: |
458752
|
|
53B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698755202.00000000053B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53B0000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979880161.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
BF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1494881587.0000000000BF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BF0000
|
Size: |
20480
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981366183.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4976000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.0000000004976000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4976000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979457922.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
489E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1556852418.000000000489E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
489E000
|
Size: |
24576
|
|
61D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2699264517.00000000061D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
61D0000
|
Size: |
65536
|
|
43F8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565119868.00000000043F8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
43F8000
|
Size: |
12288
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985545767.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
5A96000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2698221269.0000000005A96000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5A96000
|
Size: |
4096
|
|
4560000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1556718654.0000000004560000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4560000
|
Size: |
1187840
|
|
2D1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697235346.0000000002D1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D1A000
|
Size: |
20480
|
|
4BFB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495267214.0000000004BFB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BFB000
|
Size: |
4096
|
|
8078000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1574010491.0000000008078000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8078000
|
Size: |
45056
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980085188.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
7F40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1573380601.0000000007F40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7F40000
|
Size: |
32768
|
|
5A87000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1567609765.0000000005A87000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5A87000
|
Size: |
28672
|
|
7E6D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1572745575.0000000007E6D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7E6D000
|
Size: |
12288
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980579063.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1709415415.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
245760
|
|
4304000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1564483154.0000000004304000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4304000
|
Size: |
36864
|
|
5F4C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2698221269.0000000005F4C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5F4C000
|
Size: |
4096
|
|
5A9F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1567609765.0000000005A9F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5A9F000
|
Size: |
4096
|
|
5A3E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2699550019.0000000005A3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A3E000
|
Size: |
8192
|
|
4510000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1551120326.0000000004510000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4510000
|
Size: |
1187840
|
|
252C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1563508881.000000000252C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
252C000
|
Size: |
16384
|
|
36F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800217998.00000000036F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
36F0000
|
Size: |
4096
|
|
12F000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2695984415.000000000012F000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
12F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FD2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1573481868.0000000007FD2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7FD2000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1713785278.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1977316195.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
3A9E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1702775205.0000000003A9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3A9E000
|
Size: |
24576
|
|
8F5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1456772258.00000000008F5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F5000
|
Size: |
24576
|
|
15BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559400940.00000000015BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15BE000
|
Size: |
8192
|
|
508E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.2697687599.000000000508E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
508E000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1573481868.0000000007FE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7FE3000
|
Size: |
16384
|
|
4998000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.0000000004998000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4998000
|
Size: |
4096
|
|
4829000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1558217703.0000000004829000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4829000
|
Size: |
4096
|
|
13B5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697060357.00000000013B5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13B5000
|
Size: |
12288
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979949290.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
343E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1767938286.000000000343E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
343E000
|
Size: |
8192
|
|
5919000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1567609765.0000000005919000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5919000
|
Size: |
184320
|
|
387E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800273486.000000000387E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
387E000
|
Size: |
8192
|
|
7EC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1572905605.0000000007EC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7EC0000
|
Size: |
4096
|
|
4BE9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496745154.0000000004BE9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BE9000
|
Size: |
4096
|
|
61E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2699264517.00000000061E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
61E1000
|
Size: |
12288
|
|
3390000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1808453965.0000000003390000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3390000
|
Size: |
176128
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1717032231.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
13A4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2696982317.00000000013A4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13A4000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979152621.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4AE6000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495796363.0000000004AE6000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4AE6000
|
Size: |
40960
|
|
1A7F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559844447.0000000001A7F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A7F000
|
Size: |
12288
|
|
8122000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1993844402.0000000008122000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8122000
|
Size: |
8192
|
|
4B60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496461093.0000000004B60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B60000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982631840.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
38C6000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697738139.00000000038C6000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
38C6000
|
Size: |
4096
|
|
3380000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2697289910.0000000003380000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3380000
|
Size: |
4096
|
|
3128000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.0000000003128000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3128000
|
Size: |
12288
|
|
49A8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.00000000049A8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
49A8000
|
Size: |
4096
|
|
1A9A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1540307322.0000000001A9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A9A000
|
Size: |
65536
|
|
943000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696261877.0000000000943000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
943000
|
Size: |
49152
|
|
7F998000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1576367831.000000007F998000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7F998000
|
Size: |
4096
|
|
4C01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495122124.0000000004C01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C01000
|
Size: |
8192
|
|
73E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1572306523.00000000073E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
73E0000
|
Size: |
65536
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985911507.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1803520747.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
65536
|
|
1439000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697245010.0000000001439000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1439000
|
Size: |
81920
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
8186000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.0000000008186000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8186000
|
Size: |
20480
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982202098.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
CD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1494924886.0000000000CD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD0000
|
Size: |
24576
|
|
42CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1564360937.00000000042CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
42CE000
|
Size: |
8192
|
|
4F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2696197777.00000000004F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4F0000
|
Size: |
4096
|
|
3135000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1987927885.0000000003135000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3135000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
16DF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697416492.00000000016DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
16DF000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982531033.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
488E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565442726.000000000488E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
488E000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985408663.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
8FC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720579252.00000000008FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8FC000
|
Size: |
16384
|
|
8210000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2700534334.0000000008210000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8210000
|
Size: |
4096
|
|
6B2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569499752.0000000006B2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6B2E000
|
Size: |
8192
|
|
1DC0890E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2101299045.000001DC0890E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DC0890E000
|
Size: |
4096
|
|
4AE2000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495796363.0000000004AE2000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4AE2000
|
Size: |
12288
|
|
2F8A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800037494.0000000002F8A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F8A000
|
Size: |
24576
|
|
383F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800255013.000000000383F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
383F000
|
Size: |
4096
|
|
90E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1456824162.000000000090E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
90E000
|
Size: |
16384
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982809816.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979495214.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1703670461.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
245760
|
|
721E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1571227347.000000000721E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
721E000
|
Size: |
8192
|
|
30CE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1800636000.00000000030CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30CE000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981606958.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
2DC8000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2695940805.0000000002DC8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DC8000
|
Size: |
32768
|
|
F2A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1874573958.0000000000F2A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F2A000
|
Size: |
24576
|
|
30D9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1800577543.00000000030D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30D9000
|
Size: |
20480
|
|
4E6B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1803238497.0000000004E6B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E6B000
|
Size: |
4096
|
|
136000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1874478366.0000000000136000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
136000
|
Size: |
8192
|
|
8157000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.0000000008157000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8157000
|
Size: |
8192
|
|
46B0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1550365432.00000000046B0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
46B0000
|
Size: |
1196032
|
|
4B84000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698280721.0000000004B84000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B84000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979984723.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
44C0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1560168288.00000000044C0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
44C0000
|
Size: |
290816
|
|
2601000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1560064405.0000000002601000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2601000
|
Size: |
8192
|
|
55A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2696265002.000000000055A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
55A000
|
Size: |
24576
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1977684260.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
5A98000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1567609765.0000000005A98000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5A98000
|
Size: |
20480
|
|
30D8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.00000000030D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30D8000
|
Size: |
8192
|
|
1DC06E40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2101059567.000001DC06E40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DC06E40000
|
Size: |
36864
|
|
71DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1571198763.00000000071DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
71DE000
|
Size: |
8192
|
|
7F90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1573459610.0000000007F90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F90000
|
Size: |
4096
|
|
6CEC000
|
system
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2099568350.0000000006CEC000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
6CEC000
|
Size: |
4096
|
|
A00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697072130.0000000000A00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A00000
|
Size: |
4096
|
|
1DC06E4F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2101059567.000001DC06E4F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DC06E4F000
|
Size: |
40960
|
|
583C000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2699158883.000000000583C000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
583C000
|
Size: |
4096
|
|
81C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1574728670.00000000081C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
81C0000
|
Size: |
65536
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983985906.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
30D3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1800598097.00000000030D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30D3000
|
Size: |
24576
|
|
812A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.000000000812A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
812A000
|
Size: |
8192
|
|
318C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697738139.000000000318C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
318C000
|
Size: |
4096
|
|
4ECF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698435630.0000000004ECF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4ECF000
|
Size: |
4096
|
|
F90000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2696433323.0000000000F90000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F90000
|
Size: |
4096
|
|
13B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1874917814.00000000013B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13B0000
|
Size: |
20480
|
|
6E5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569948620.0000000006E5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6E5E000
|
Size: |
8192
|
|
4954000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.0000000004954000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4954000
|
Size: |
24576
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981206284.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
6C92000
|
system
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2099568350.0000000006C92000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
6C92000
|
Size: |
4096
|
|
589F000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2699158883.000000000589F000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
589F000
|
Size: |
90112
|
|
5A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1720452525.00000000005A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5A0000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1984906699.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1986738493.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4978000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.0000000004978000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4978000
|
Size: |
24576
|
|
7CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1494800072.00000000007CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7CE000
|
Size: |
8192
|
|
4AF2000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495796363.0000000004AF2000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4AF2000
|
Size: |
188416
|
|
6960000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.1800824318.0000000006960000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
6960000
|
Size: |
10485760
|
|
58F1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1567609765.00000000058F1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
58F1000
|
Size: |
135168
|
|
5AA7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1567609765.0000000005AA7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5AA7000
|
Size: |
425984
|
|
1DC08903000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2101299045.000001DC08903000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DC08903000
|
Size: |
16384
|
|
3123000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.0000000003123000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3123000
|
Size: |
12288
|
|
69D0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1569150197.00000000069D0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
69D0000
|
Size: |
12288
|
|
44C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496267303.00000000044C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
44C0000
|
Size: |
16384
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981828002.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983669043.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982770812.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985367742.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
16DF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1875015371.00000000016DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
16DF000
|
Size: |
4096
|
|
30D3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1800675633.00000000030D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30D3000
|
Size: |
24576
|
|
3064000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1803546830.0000000003064000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3064000
|
Size: |
4096
|
|
7153000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1570486030.0000000007153000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7153000
|
Size: |
61440
|
|
44E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496316889.00000000044E0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
44E0000
|
Size: |
4096
|
|
1C39000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1544059789.0000000001C39000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C39000
|
Size: |
57344
|
|
595B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1567609765.000000000595B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
595B000
|
Size: |
1200128
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8011000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1573481868.0000000008011000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8011000
|
Size: |
307200
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
1DC08AC4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000010.00000003.2051217787.000001DC08AC4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DC08AC4000
|
Size: |
24576
|
|
4633000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1556199068.0000000004633000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4633000
|
Size: |
507904
|
|
1AB2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1544017715.0000000001AB2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1AB2000
|
Size: |
8192
|
|
3080000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696113778.0000000003080000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3080000
|
Size: |
4096
|
|
5D0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720521420.00000000005D0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5D0000
|
Size: |
4096
|
|
F60000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2696308180.0000000000F60000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F60000
|
Size: |
4096
|
|
4BA7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1496190170.0000000004BA7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BA7000
|
Size: |
28672
|
|
1C39000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1544624013.0000000001C39000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C39000
|
Size: |
339968
|
|
120000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.1874416496.0000000000120000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
120000
|
Size: |
4096
|
|
4806000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697363686.0000000004806000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4806000
|
Size: |
32768
|
|
30B7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.00000000030B7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30B7000
|
Size: |
69632
|
|
4C8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698348351.0000000004C8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C8E000
|
Size: |
8192
|
|
72DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1571344612.00000000072DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
72DE000
|
Size: |
8192
|
|
4BA8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496568993.0000000004BA8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BA8000
|
Size: |
24576
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979654691.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
15FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559400940.00000000015FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15FC000
|
Size: |
16384
|
|
4938000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.0000000004938000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4938000
|
Size: |
20480
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982577803.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4E6F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1803238497.0000000004E6F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E6F000
|
Size: |
458752
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981438248.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
12F000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.1874458968.000000000012F000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
12F000
|
Size: |
28672
|
|
878E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2700668366.000000000878E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
878E000
|
Size: |
8192
|
|
FF1000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.1874736198.0000000000FF1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FF1000
|
Size: |
12288
|
|
5560000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.1800824318.0000000005560000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
5560000
|
Size: |
10485760
|
|
9A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1720664290.00000000009A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
9A0000
|
Size: |
16384
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1996746811.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
3D7C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697738139.0000000003D7C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3D7C000
|
Size: |
4096
|
|
8330000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1574865670.0000000008330000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8330000
|
Size: |
65536
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979575959.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
7FD7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1573481868.0000000007FD7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7FD7000
|
Size: |
8192
|
|
590000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2696307478.0000000000590000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
590000
|
Size: |
4096
|
|
6F72000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1570295691.0000000006F72000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6F72000
|
Size: |
8192
|
|
3823000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1700226963.0000000003823000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3823000
|
Size: |
507904
|
|
141A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1874951378.000000000141A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
141A000
|
Size: |
8192
|
|
8195000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.0000000008195000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8195000
|
Size: |
36864
|
|
4B80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698280721.0000000004B80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B80000
|
Size: |
8192
|
|
1320000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.1874800964.0000000001320000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1320000
|
Size: |
16384
|
|
121000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000B.00000000.1720229929.0000000000121000.00000020.00000001.01000000.0000000A.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
121000
|
Size: |
57344
|
|
4510000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1556199068.0000000004510000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4510000
|
Size: |
1187840
|
|
1DC08900000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2101275469.000001DC08900000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DC08900000
|
Size: |
4096
|
|
7E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699708600.0000000007E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7E00000
|
Size: |
4096
|
|
4CB6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565515176.0000000004CB6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4CB6000
|
Size: |
4419584
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4C07000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495267214.0000000004C07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C07000
|
Size: |
36864
|
|
482D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1557262259.000000000482D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
482D000
|
Size: |
458752
|
|
136000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2696030568.0000000000136000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
136000
|
Size: |
8192
|
|
3417000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1700730045.0000000003417000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3417000
|
Size: |
20480
|
|
731D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1571368047.000000000731D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
731D000
|
Size: |
12288
|
|
69D5000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1569150197.00000000069D5000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
69D5000
|
Size: |
8192
|
|
8192000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.0000000008192000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8192000
|
Size: |
8192
|
|
4BAF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495534522.0000000004BAF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BAF000
|
Size: |
61440
|
|
584B000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2699158883.000000000584B000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
584B000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982895692.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
8116000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1993844402.0000000008116000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8116000
|
Size: |
8192
|
|
29299FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2100788085.00000029299FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
29299FB000
|
Size: |
20480
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981057586.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4C01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495267214.0000000004C01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C01000
|
Size: |
8192
|
|
4A40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698226256.0000000004A40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A40000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985956058.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
5F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2696616232.00000000005F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F0000
|
Size: |
20480
|
|
343E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1768041309.000000000343E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
343E000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979303554.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1809168658.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
3AF0000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.2697537339.0000000003AF0000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3AF0000
|
Size: |
10485760
|
|
3390000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2697323173.0000000003390000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3390000
|
Size: |
4096
|
|
2D17000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697235346.0000000002D17000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D17000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1996623293.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
AFD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1494859538.0000000000AFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AFD000
|
Size: |
12288
|
|
FA0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1874687753.0000000000FA0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
FA0000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1984332135.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
269F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720970533.000000000269F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
269F000
|
Size: |
4096
|
|
1A31000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1539862276.0000000001A31000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A31000
|
Size: |
4096
|
|
3132000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697738139.0000000003132000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3132000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980848724.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980229685.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
120000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2695841722.0000000000120000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
120000
|
Size: |
4096
|
|
317E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.000000000317E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
317E000
|
Size: |
12288
|
|
25FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1560040258.00000000025FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
25FE000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981096888.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
818C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.000000000818C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
818C000
|
Size: |
8192
|
|
4922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697549272.0000000004922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4922000
|
Size: |
16384
|
|
1021000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2697062623.0000000001021000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1021000
|
Size: |
393216
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
24B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2697232586.00000000024B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24B0000
|
Size: |
8192
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1713889081.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
245760
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983492196.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
5A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2696352428.00000000005A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5A0000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979533132.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
881000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696261877.0000000000881000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
881000
|
Size: |
114688
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981281929.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
3DD1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.1800388098.0000000003DD1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3DD1000
|
Size: |
458752
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1709076827.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
1DC08A00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000010.00000003.2050760261.000001DC08A00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DC08A00000
|
Size: |
4096
|
|
4DE0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.2697624215.0000000004DE0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
4DE0000
|
Size: |
94208
|
|
28DF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1563745855.00000000028DF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28DF000
|
Size: |
327680
|
|
17E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559596707.00000000017E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17E0000
|
Size: |
4096
|
|
5BBC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698817389.0000000005BBC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BBC000
|
Size: |
8192
|
|
341B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1767938286.000000000341B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
341B000
|
Size: |
139264
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
50EE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565515176.00000000050EE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
50EE000
|
Size: |
16384
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980042447.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
7167000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1570486030.0000000007167000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7167000
|
Size: |
12288
|
|
1C39000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1540372973.0000000001C39000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C39000
|
Size: |
98304
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982846781.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
3A29000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1702775205.0000000003A29000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3A29000
|
Size: |
4096
|
|
39D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1716944607.00000000039D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39D0000
|
Size: |
180224
|
|
3700000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1708661036.0000000003700000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3700000
|
Size: |
180224
|
|
1DC08A01000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2101444372.000001DC08A01000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DC08A01000
|
Size: |
4096
|
|
139000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2696069697.0000000000139000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
139000
|
Size: |
61440
|
|
4457000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565268698.0000000004457000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4457000
|
Size: |
12288
|
|
6D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696054610.00000000006D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6D5000
|
Size: |
16384
|
|
902000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1456798881.0000000000902000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
902000
|
Size: |
65536
|
|
47E0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1565372542.00000000047E0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
47E0000
|
Size: |
49152
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979346325.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
1040000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1495026158.0000000001040000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1040000
|
Size: |
8192
|
|
F80000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2696393291.0000000000F80000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F80000
|
Size: |
4096
|
|
812D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.000000000812D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
812D000
|
Size: |
32768
|
|
1A31000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559693215.0000000001A31000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A31000
|
Size: |
65536
|
|
5C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720499986.00000000005C0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C0000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981133461.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
8670000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1575967349.0000000008670000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8670000
|
Size: |
32768
|
|
5823000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2699158883.0000000005823000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5823000
|
Size: |
8192
|
|
8FC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2696667355.00000000008FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8FC000
|
Size: |
16384
|
|
7380000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1571972385.0000000007380000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7380000
|
Size: |
65536
|
|
858000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696261877.0000000000858000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
858000
|
Size: |
86016
|
|
780000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1494765957.0000000000780000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
780000
|
Size: |
4096
|
|
810000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696198819.0000000000810000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
810000
|
Size: |
4096
|
|
4970000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.0000000004970000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4970000
|
Size: |
12288
|
|
44F0000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.2697537339.00000000044F0000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
44F0000
|
Size: |
10485760
|
|
13C0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697160573.00000000013C0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13C0000
|
Size: |
12288
|
|
EA0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2696131935.0000000000EA0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EA0000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1984296701.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1984583211.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981643963.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1808904636.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
237568
|
|
8182000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.0000000008182000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8182000
|
Size: |
12288
|
|
4E90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1820789312.0000000004E90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E90000
|
Size: |
176128
|
|
5904000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2698221269.0000000005904000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5904000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985155119.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
4BDE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496719363.0000000004BDE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BDE000
|
Size: |
36864
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1984823535.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
86E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696261877.000000000086E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
86E000
|
Size: |
73728
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982071977.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
3501000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800179951.0000000003501000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3501000
|
Size: |
4096
|
|
54F8000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.1800824318.00000000054F8000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
54F8000
|
Size: |
4096
|
|
1DC06CC4000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000010.00000002.2100915300.000001DC06CC4000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
1DC06CC4000
|
Size: |
8192
|
|
1A84000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559862069.0000000001A84000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A84000
|
Size: |
8192
|
|
3C9E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.1800388098.0000000003C9E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3C9E000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
5BD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698817389.0000000005BD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BD0000
|
Size: |
8192
|
|
1DC08911000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2101299045.000001DC08911000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DC08911000
|
Size: |
24576
|
|
1A72000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1539998041.0000000001A72000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A72000
|
Size: |
339968
|
|
F90000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1874663767.0000000000F90000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F90000
|
Size: |
4096
|
|
482D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1558217703.000000000482D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
482D000
|
Size: |
458752
|
|
70CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1570486030.00000000070CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70CE000
|
Size: |
20480
|
|
139000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1720314817.0000000000139000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
139000
|
Size: |
61440
|
|
46B0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1556394129.00000000046B0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
46B0000
|
Size: |
1196032
|
|
3060000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696071164.0000000003060000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3060000
|
Size: |
16384
|
|
484E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1554283321.000000000484E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
484E000
|
Size: |
24576
|
|
3178000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.0000000003178000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3178000
|
Size: |
12288
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985813878.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
FF1000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2696594102.0000000000FF1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FF1000
|
Size: |
12288
|
|
2F7F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1875115155.0000000002F7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F7F000
|
Size: |
4096
|
|
30DB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.00000000030DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30DB000
|
Size: |
126976
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4BB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496614498.0000000004BB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BB5000
|
Size: |
12288
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1996458383.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
6840000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495763038.0000000006840000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
6840000
|
Size: |
131072
|
|
47D9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1550365432.00000000047D9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
47D9000
|
Size: |
4096
|
|
5F60000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.1800824318.0000000005F60000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
5F60000
|
Size: |
10485760
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985499200.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
4560000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1557127081.0000000004560000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4560000
|
Size: |
1187840
|
|
AE7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.1559329066.0000000000AE7000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AE7000
|
Size: |
409600
|
|
138E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2696896759.000000000138E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
138E000
|
Size: |
8192
|
|
6CAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569723573.0000000006CAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6CAE000
|
Size: |
8192
|
|
7320000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1571401144.0000000007320000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7320000
|
Size: |
65536
|
|
4D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2696107778.00000000004D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4D0000
|
Size: |
4096
|
|
499E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.000000000499E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
499E000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982276173.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
29D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1564039227.00000000029D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29D0000
|
Size: |
24576
|
|
29D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1564039227.00000000029D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29D7000
|
Size: |
12288
|
|
292A1FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2100816892.000000292A1FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
292A1FE000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983706243.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
3C29000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.1800388098.0000000003C29000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3C29000
|
Size: |
4096
|
|
1630000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559482917.0000000001630000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1630000
|
Size: |
4096
|
|
C90000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2697015107.0000000000C90000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C90000
|
Size: |
40960
|
|
3072000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1875230388.0000000003072000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3072000
|
Size: |
4096
|
|
15CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559400940.00000000015CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15CE000
|
Size: |
8192
|
|
3EA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2695873000.00000000003EA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3EA000
|
Size: |
24576
|
|
EC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.1874552719.0000000000EC0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EC0000
|
Size: |
4096
|
|
4960000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.0000000004960000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4960000
|
Size: |
32768
|
|
70F9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1570486030.00000000070F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70F9000
|
Size: |
73728
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979747137.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
373E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800236122.000000000373E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
373E000
|
Size: |
8192
|
|
58F0000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.2697537339.00000000058F0000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
58F0000
|
Size: |
9134080
|
|
136000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2696030859.0000000000136000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
136000
|
Size: |
8192
|
|
2D8B000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2695852098.0000000002D8B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D8B000
|
Size: |
20480
|
|
9C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2696806857.00000000009C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C0000
|
Size: |
32768
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983792461.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
51DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698645727.00000000051DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
51DE000
|
Size: |
8192
|
|
A20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1539170261.0000000000A20000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A20000
|
Size: |
4096
|
|
4303000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1564461583.0000000004303000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
4303000
|
Size: |
4096
|
|
AAF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1539239351.0000000000AAF000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AAF000
|
Size: |
147456
|
|
311E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.000000000311E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
311E000
|
Size: |
8192
|
|
2FE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800072047.0000000002FE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FE0000
|
Size: |
4096
|
|
1A7E000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.1559794439.0000000001A7E000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1A7E000
|
Size: |
4096
|
|
70CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1570486030.00000000070CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70CA000
|
Size: |
12288
|
|
12FC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1874761510.00000000012FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12FC000
|
Size: |
16384
|
|
2860000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1563745855.0000000002860000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2860000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980802171.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
81A0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1574632395.00000000081A0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
81A0000
|
Size: |
4096
|
|
710C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1570486030.000000000710C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
710C000
|
Size: |
229376
|
|
4BB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495556590.0000000004BB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BB4000
|
Size: |
40960
|
|
1A71000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2697474919.0000000001A71000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A71000
|
Size: |
393216
|
|
43DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565022756.00000000043DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
43DF000
|
Size: |
4096
|
|
428E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1564179986.000000000428E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
428E000
|
Size: |
8192
|
|
47DD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565352111.00000000047DD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
47DD000
|
Size: |
12288
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980122289.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980739453.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
7145000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1570486030.0000000007145000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7145000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1713703437.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
9CA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720683633.00000000009CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9CA000
|
Size: |
8192
|
|
16E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2697447433.00000000016E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
16E0000
|
Size: |
40960
|
|
7EE7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1573106345.0000000007EE7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7EE7000
|
Size: |
12288
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981004137.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
5E1000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2696569163.00000000005E1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5E1000
|
Size: |
12288
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1986055076.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
3183000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.0000000003183000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3183000
|
Size: |
12288
|
|
432A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1564875944.000000000432A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
432A000
|
Size: |
4096
|
|
888C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1576113290.000000000888C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
888C000
|
Size: |
16384
|
|
2C8F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697118334.0000000002C8F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C8F000
|
Size: |
4096
|
|
120000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1720160124.0000000000120000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
120000
|
Size: |
4096
|
|
39D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1767994496.00000000039D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39D0000
|
Size: |
180224
|
|
2CCB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697158478.0000000002CCB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2CCB000
|
Size: |
20480
|
|
1DC06E90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2101176381.000001DC06E90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DC06E90000
|
Size: |
8192
|
|
5C28000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2698221269.0000000005C28000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5C28000
|
Size: |
8192
|
|
8125000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.0000000008125000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8125000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981787350.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
49A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.00000000049A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
49A0000
|
Size: |
4096
|
|
850000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696261877.0000000000850000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
850000
|
Size: |
24576
|
|
48F1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565515176.00000000048F1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
48F1000
|
Size: |
385024
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980386589.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
4F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1720385751.00000000004F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4F0000
|
Size: |
4096
|
|
3064000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1809058991.0000000003064000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3064000
|
Size: |
4096
|
|
2590000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2697272870.0000000002590000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2590000
|
Size: |
8192
|
|
7DE0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1572463786.0000000007DE0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7DE0000
|
Size: |
36864
|
|
1DC06E4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2101059567.000001DC06E4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DC06E4A000
|
Size: |
16384
|
|
30D3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1800796809.00000000030D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30D3000
|
Size: |
24576
|
|
6E78000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569972824.0000000006E78000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6E78000
|
Size: |
282624
|
|
292A9FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2100841668.000000292A9FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
292A9FE000
|
Size: |
8192
|
|
FEE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2696519743.0000000000FEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FEE000
|
Size: |
8192
|
|
3700000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1700226963.0000000003700000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3700000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4319000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1564529478.0000000004319000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4319000
|
Size: |
16384
|
|
6BD2000
|
system
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2099568350.0000000006BD2000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
6BD2000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1984254672.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
688E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495609878.000000000688E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
688E000
|
Size: |
24576
|
|
1DC06D60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2101031485.000001DC06D60000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DC06D60000
|
Size: |
4096
|
|
12FC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2696709937.00000000012FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12FC000
|
Size: |
16384
|
|
7FD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1573481868.0000000007FD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7FD4000
|
Size: |
4096
|
|
397F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800291359.000000000397F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
397F000
|
Size: |
4096
|
|
1802000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559613215.0000000001802000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1802000
|
Size: |
20480
|
|
4450000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565268698.0000000004450000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4450000
|
Size: |
20480
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979614253.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
86F5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1576062153.00000000086F5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
86F5000
|
Size: |
36864
|
|
AD4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.1559262519.0000000000AD4000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AD4000
|
Size: |
40960
|
|
4BD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496693509.0000000004BD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BD4000
|
Size: |
12288
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985635783.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
940000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720623256.0000000000940000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
940000
|
Size: |
4096
|
|
5330000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698721771.0000000005330000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5330000
|
Size: |
4096
|
|
3610000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800197049.0000000003610000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3610000
|
Size: |
4096
|
|
6C6D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569656500.0000000006C6D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6C6D000
|
Size: |
12288
|
|
139000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2696091192.0000000000139000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
139000
|
Size: |
61440
|
|
FF9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559370174.0000000000FF9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FF9000
|
Size: |
28672
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1986009706.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981522802.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
6E74000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569972824.0000000006E74000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6E74000
|
Size: |
4096
|
|
3C2D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.1800388098.0000000003C2D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3C2D000
|
Size: |
458752
|
|
514E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698605866.000000000514E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
514E000
|
Size: |
8192
|
|
3417000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1700543516.0000000003417000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3417000
|
Size: |
20480
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1703380387.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1984768721.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
48E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565492768.00000000048E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
48E0000
|
Size: |
20480
|
|
4EF0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.2697687599.0000000004EF0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4EF0000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
5BBF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698817389.0000000005BBF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BBF000
|
Size: |
8192
|
|
16E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.1875035870.00000000016E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
16E0000
|
Size: |
40960
|
|
8111000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1993844402.0000000008111000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8111000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983531085.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980500737.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
87CF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2700719908.00000000087CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
87CF000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983939618.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
866B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1575775037.000000000866B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
866B000
|
Size: |
16384
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985319899.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
3412000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800144174.0000000003412000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3412000
|
Size: |
24576
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985454532.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
1C00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559957911.0000000001C00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C00000
|
Size: |
212992
|
|
2701000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1560083604.0000000002701000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2701000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983447668.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1977828910.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
1300000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2696756281.0000000001300000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1300000
|
Size: |
4096
|
|
507E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496817864.000000000507E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
507E000
|
Size: |
8192
|
|
851E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1575442139.000000000851E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
851E000
|
Size: |
8192
|
|
1340000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2696857563.0000000001340000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1340000
|
Size: |
12288
|
|
492E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697549272.000000000492E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
492E000
|
Size: |
4096
|
|
8340000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1574957460.0000000008340000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8340000
|
Size: |
65536
|
|
8F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696261877.00000000008F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F4000
|
Size: |
229376
|
|
4CA6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565515176.0000000004CA6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4CA6000
|
Size: |
36864
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1986113524.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
3064000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1809089491.0000000003064000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3064000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979382885.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
73A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1572055809.00000000073A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
73A0000
|
Size: |
65536
|
|
3A88000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.2697537339.0000000003A88000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3A88000
|
Size: |
4096
|
|
141E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697245010.000000000141E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
141E000
|
Size: |
94208
|
|
3405000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1700498630.0000000003405000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3405000
|
Size: |
49152
|
|
4300000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1564441688.0000000004300000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4300000
|
Size: |
12288
|
|
493E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.000000000493E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
493E000
|
Size: |
20480
|
|
8A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2696261877.00000000008A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8A6000
|
Size: |
20480
|
|
24B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720880792.00000000024B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24B0000
|
Size: |
8192
|
|
2590000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720926116.0000000002590000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2590000
|
Size: |
8192
|
|
8FB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1456698501.00000000008FB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FB000
|
Size: |
167936
|
|
1DC06E73000
|
heap
|
page read and write
|
|
|
|
Name: |
00000010.00000003.2051332400.000001DC06E73000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DC06E73000
|
Size: |
28672
|
|
30FB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.00000000030FB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30FB000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
30D3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1800886729.00000000030D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30D3000
|
Size: |
24576
|
|
30C8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1800598097.00000000030C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C8000
|
Size: |
28672
|
|
7060000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1570323537.0000000007060000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7060000
|
Size: |
32768
|
|
80BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699797519.00000000080BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
80BE000
|
Size: |
8192
|
|
292B9FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2100891918.000000292B9FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
292B9FF000
|
Size: |
4096
|
|
4AA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495951615.0000000004AA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4AA0000
|
Size: |
118784
|
|
45FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496345660.00000000045FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
45FD000
|
Size: |
12288
|
|
922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1456854413.0000000000922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
922000
|
Size: |
8192
|
|
650000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2695936162.0000000000650000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
650000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982427597.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
85BB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1575606922.00000000085BB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
85BB000
|
Size: |
20480
|
|
2F80000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.1875133845.0000000002F80000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2F80000
|
Size: |
925696
|
|
6CEA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569760841.0000000006CEA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6CEA000
|
Size: |
24576
|
|
9FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697027028.00000000009FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9FE000
|
Size: |
8192
|
|
4350000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1564967314.0000000004350000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4350000
|
Size: |
4096
|
|
81D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1574823416.00000000081D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
81D0000
|
Size: |
8192
|
|
49A4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697679161.00000000049A4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
49A4000
|
Size: |
4096
|
|
855E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1575528572.000000000855E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
855E000
|
Size: |
8192
|
|
7090000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1570370285.0000000007090000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7090000
|
Size: |
139264
|
|
A07000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2696806857.0000000000A07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A07000
|
Size: |
20480
|
|
4920000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697549272.0000000004920000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4920000
|
Size: |
4096
|
|
4BEA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495486422.0000000004BEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BEA000
|
Size: |
36864
|
|
688E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495668663.000000000688E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
688E000
|
Size: |
24576
|
|
4BA2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496485818.0000000004BA2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BA2000
|
Size: |
20480
|
|
8100000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699851695.0000000008100000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8100000
|
Size: |
4096
|
|
3128000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1987927885.0000000003128000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3128000
|
Size: |
12288
|
|
3135000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.0000000003135000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3135000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
4BF3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495164049.0000000004BF3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BF3000
|
Size: |
12288
|
|
7390000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1572012991.0000000007390000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7390000
|
Size: |
65536
|
|
21FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1560021125.00000000021FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
21FE000
|
Size: |
8192
|
|
4B00000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495913595.0000000004B00000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4B00000
|
Size: |
131072
|
|
4510000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1550181977.0000000004510000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4510000
|
Size: |
1187840
|
|
47D9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1556394129.00000000047D9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
47D9000
|
Size: |
4096
|
|
136000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720282956.0000000000136000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
136000
|
Size: |
8192
|
|
4928000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697549272.0000000004928000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4928000
|
Size: |
20480
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985594007.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
316F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.000000000316F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
316F000
|
Size: |
4096
|
|
729E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1571321593.000000000729E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
729E000
|
Size: |
8192
|
|
4001000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800794183.0000000004001000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4001000
|
Size: |
8192
|
|
7330000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1571702865.0000000007330000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7330000
|
Size: |
20480
|
|
F60000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.1874596659.0000000000F60000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F60000
|
Size: |
4096
|
|
4C07000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495122124.0000000004C07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C07000
|
Size: |
36864
|
|
3E42000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.1800388098.0000000003E42000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3E42000
|
Size: |
40960
|
|
815C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.000000000815C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
815C000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1984025437.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
81B0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1574660870.00000000081B0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
81B0000
|
Size: |
4096
|
|
13D0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697199400.00000000013D0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13D0000
|
Size: |
4096
|
|
4B95000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1800364851.0000000004B95000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B95000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
5019000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.2697687599.0000000005019000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
5019000
|
Size: |
4096
|
|
9A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2696761085.00000000009A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
9A0000
|
Size: |
16384
|
|
2FC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1800056177.0000000002FC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FC0000
|
Size: |
4096
|
|
93E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1720604035.000000000093E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
93E000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982939153.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
25F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1563630268.00000000025F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25F0000
|
Size: |
12288
|
|
4E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2696154985.00000000004E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4E0000
|
Size: |
4096
|
|
4812000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2697363686.0000000004812000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4812000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985022478.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981750011.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
7EAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1572812970.0000000007EAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7EAE000
|
Size: |
8192
|
|
A21000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000006.00000000.1539189343.0000000000A21000.00000020.00000001.01000000.00000009.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
A21000
|
Size: |
581632
|
|
7149000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1570486030.0000000007149000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7149000
|
Size: |
4096
|
|
48A0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1565468940.00000000048A0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
48A0000
|
Size: |
4096
|
|
49A8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1696957706.00000000049A8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
49A8000
|
Size: |
4096
|
|
8110000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.0000000008110000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8110000
|
Size: |
4096
|
|
120000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2695847417.0000000000120000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
120000
|
Size: |
4096
|
|
6E70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569972824.0000000006E70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6E70000
|
Size: |
4096
|
|
13A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2696982317.00000000013A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13A0000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985679111.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
4700000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000006.00000003.1556852418.0000000004700000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4700000
|
Size: |
1196032
|
|
4D30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2697562432.0000000004D30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4D30000
|
Size: |
94208
|
|
88AE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2700834532.00000000088AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
88AE000
|
Size: |
8192
|
|
4BBE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495393211.0000000004BBE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BBE000
|
Size: |
86016
|
|
4BB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1496590895.0000000004BB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BB1000
|
Size: |
12288
|
|
84D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1575407665.00000000084D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
84D0000
|
Size: |
4096
|
|
1DC06E5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000010.00000002.2101059567.000001DC06E5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
16
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DC06E5C000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1984476684.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
342B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1768041309.000000000342B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
342B000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1982029800.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
ECF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1494983560.0000000000ECF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
ECF000
|
Size: |
4096
|
|
912000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1456726499.0000000000912000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
912000
|
Size: |
73728
|
|
15DB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559400940.00000000015DB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15DB000
|
Size: |
20480
|
|
5DF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2699223014.0000000005DF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5DF0000
|
Size: |
4096
|
|
8152000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2699874862.0000000008152000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8152000
|
Size: |
8192
|
|
ADE000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000006.00000000.1539283679.0000000000ADE000.00000008.00000001.01000000.00000009.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
ADE000
|
Size: |
8192
|
|
30D9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1800767480.00000000030D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30D9000
|
Size: |
20480
|
|
2F80000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2697590299.0000000002F80000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2F80000
|
Size: |
925696
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1984414008.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1709324681.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
1AF9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.1559940775.0000000001AF9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1AF9000
|
Size: |
32768
|
|
7F30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1573341353.0000000007F30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7F30000
|
Size: |
65536
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1979786091.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
4BF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495344371.0000000004BF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BF4000
|
Size: |
8192
|
|
4DCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2698397537.0000000004DCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4DCE000
|
Size: |
8192
|
|
84AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1575350318.00000000084AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
84AE000
|
Size: |
8192
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980615684.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
AE2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000006.00000000.1539283679.0000000000AE2000.00000008.00000001.01000000.00000009.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
AE2000
|
Size: |
8192
|
|
5C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2696442220.00000000005C0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C0000
|
Size: |
4096
|
|
1410000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1874951378.0000000001410000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1410000
|
Size: |
32768
|
|
4BFB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495164049.0000000004BFB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BFB000
|
Size: |
4096
|
|
7360000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.1800824318.0000000007360000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
7360000
|
Size: |
9134080
|
|
CD8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1494924886.0000000000CD8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD8000
|
Size: |
65536
|
|
439E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1565000146.000000000439E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
439E000
|
Size: |
8192
|
|
5232000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.2697687599.0000000005232000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
5232000
|
Size: |
40960
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980301061.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
8192
|
|
12F000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1720253846.000000000012F000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
12F000
|
Size: |
28672
|
|
29AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1563982155.00000000029AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
29AF000
|
Size: |
4096
|
|
7EF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1573248886.0000000007EF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7EF0000
|
Size: |
8192
|
|
4BE7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1495578385.0000000004BE7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BE7000
|
Size: |
12288
|
|
5D0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2696474232.00000000005D0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5D0000
|
Size: |
4096
|
|
6E1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1569922173.0000000006E1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6E1E000
|
Size: |
8192
|
|
30CE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1800847308.00000000030CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30CE000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1983325652.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
4B91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981570811.0000000004B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B91000
|
Size: |
4096
|
|
3158000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2696221255.0000000003158000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3158000
|
Size: |
16384
|
|
73F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1572385727.00000000073F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
73F0000
|
Size: |
65536
|
|
4D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1720340520.00000000004D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4D0000
|
Size: |
4096
|
|
1340000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1874821332.0000000001340000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1340000
|
Size: |
8192
|
|
5DBA000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2698221269.0000000005DBA000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5DBA000
|
Size: |
4096
|
|
138E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.1874839312.000000000138E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
138E000
|
Size: |
8192
|
|
1410000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2697245010.0000000001410000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1410000
|
Size: |
32768
|
|