3900000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000007.00000002.3831416913.0000000003900000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3900000
|
Size: |
376832
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected WebBrowserPassView password recovery tool |
Stealing of Sensitive Information |
|
Found strings which match to known social media urls |
Networking |
|
SQL strings found in memory and binary data |
System Summary |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
400000
|
remote allocation
|
page execute and read and write
|
 |
|
|
Name: |
00000007.00000002.3828986225.0000000000400000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
475136
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected UAC Bypass using CMSTP |
Exploits |
|
Yara detected Keylogger Generic |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
F18000
|
heap
|
page read and write
|
 |
|
|
Name: |
00000007.00000002.3829845640.0000000000F18000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F18000
|
Size: |
192512
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
5EB3000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000005.00000002.1456271424.0000000005EB3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5EB3000
|
Size: |
1167360
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected UAC Bypass using CMSTP |
Exploits |
|
Yara detected Keylogger Generic |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
|
Yara signature match |
System Summary |
|
Public key (encryption) found |
Cryptography |
|
URLs found in memory or binary data |
Networking |
|
|
5AF7000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000005.00000002.1456271424.0000000005AF7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5AF7000
|
Size: |
1302528
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected UAC Bypass using CMSTP |
Exploits |
|
Yara detected Keylogger Generic |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
400000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000008.00000002.1506972386.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
376832
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected WebBrowserPassView password recovery tool |
Stealing of Sensitive Information |
|
Found strings which match to known social media urls |
Networking |
|
SQL strings found in memory and binary data |
System Summary |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4CC5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1499190864.0000000004CC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC5000
|
Size: |
40960
|
|
365A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393067688.000000000365A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
365A000
|
Size: |
86016
|
|
35C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1392133583.00000000035C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C0000
|
Size: |
12288
|
|
73A8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1464551335.00000000073A8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
73A8000
|
Size: |
73728
|
|
4A91000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004A91000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A91000
|
Size: |
372736
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
35EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395524213.00000000035EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35EA000
|
Size: |
4096
|
|
5997000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1414875674.0000000005997000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5997000
|
Size: |
28672
|
|
4CD3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1499660680.0000000004CD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD3000
|
Size: |
172032
|
|
55BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1508079727.00000000055BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
55BE000
|
Size: |
8192
|
|
2CBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419624299.0000000002CBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2CBE000
|
Size: |
8192
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495114438.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
16384
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496683273.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
4DA3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004DA3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DA3000
|
Size: |
12288
|
|
35CC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397793020.00000000035CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35CC000
|
Size: |
32768
|
|
2AC6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416011136.0000000002AC6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AC6000
|
Size: |
102400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495999527.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494074002.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
10001000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3832957939.0000000010001000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
10001000
|
Size: |
77824
|
|
95C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1486498619.00000000095C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
95C0000
|
Size: |
36864
|
|
4CEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419877918.0000000004CEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4CEE000
|
Size: |
8192
|
|
F75000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3830123677.0000000000F75000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F75000
|
Size: |
81920
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
4CBC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1498338649.0000000004CBC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CBC000
|
Size: |
20480
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1505652165.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
36864
|
|
3045000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491182581.0000000003045000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3045000
|
Size: |
4096
|
|
34C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507523770.00000000034C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
34C0000
|
Size: |
20480
|
|
4CDA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1501030471.0000000004CDA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CDA000
|
Size: |
69632
|
|
2A55000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419313882.0000000002A55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A55000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
364F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393067688.000000000364F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
364F000
|
Size: |
16384
|
|
4CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496916876.0000000004CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB1000
|
Size: |
40960
|
|
3045000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1492272690.0000000003045000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3045000
|
Size: |
4096
|
|
4FA0000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1398567841.0000000004FA0000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
4FA0000
|
Size: |
4096
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1493537290.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
4CC5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497833873.0000000004CC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC5000
|
Size: |
40960
|
|
59D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420672548.00000000059D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59D5000
|
Size: |
49152
|
|
3357000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1396624494.0000000003357000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3357000
|
Size: |
8192
|
|
6B4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463361876.0000000006B4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6B4E000
|
Size: |
8192
|
|
3168000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1487530212.0000000003168000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3168000
|
Size: |
86016
|
|
4E60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507863073.0000000004E60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E60000
|
Size: |
8192
|
|
339E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507441962.000000000339E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
339E000
|
Size: |
8192
|
|
4CED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1501030471.0000000004CED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CED000
|
Size: |
286720
|
|
6A2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394737314.0000000006A2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A2D000
|
Size: |
4096
|
|
4CDA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1500562014.0000000004CDA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CDA000
|
Size: |
45056
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1492945555.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
365A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393564509.000000000365A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
365A000
|
Size: |
86016
|
|
41B000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1486569287.000000000041B000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
41B000
|
Size: |
36864
|
|
5280000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507974912.0000000005280000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5280000
|
Size: |
4096
|
|
29E8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419101115.00000000029E8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29E8000
|
Size: |
122880
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5B53000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1411953947.0000000005B53000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B53000
|
Size: |
61440
|
|
95B0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1486354875.00000000095B0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
95B0000
|
Size: |
32768
|
|
4DA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004DA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DA0000
|
Size: |
8192
|
|
D60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3829713282.0000000000D60000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D60000
|
Size: |
4096
|
|
3611000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393726007.0000000003611000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3611000
|
Size: |
4096
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491087858.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
35C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397685625.00000000035C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C0000
|
Size: |
12288
|
|
3140000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1487469390.0000000003140000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3140000
|
Size: |
8192
|
|
598C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1413372095.000000000598C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
598C000
|
Size: |
172032
|
|
2AD7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453419928.0000000002AD7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AD7000
|
Size: |
12288
|
|
800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1399600141.0000000000800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
800000
|
Size: |
16384
|
|
6B2E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395098614.0000000006B2E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6B2E000
|
Size: |
4096
|
|
4CBC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1498192496.0000000004CBC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CBC000
|
Size: |
20480
|
|
2A21000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416714730.0000000002A21000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A21000
|
Size: |
4096
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491478752.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
364F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1392883986.000000000364F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
364F000
|
Size: |
16384
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1492073039.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
2F80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1486364134.0000000002F80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F80000
|
Size: |
4096
|
|
317D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507309918.000000000317D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
317D000
|
Size: |
159744
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6D7B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463667557.0000000006D7B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6D7B000
|
Size: |
20480
|
|
52AF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1487961515.00000000052AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52AF000
|
Size: |
4096
|
|
35E6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397885394.00000000035E6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35E6000
|
Size: |
4096
|
|
2A58000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1396042257.0000000002A58000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A58000
|
Size: |
8192
|
|
3168000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507309918.0000000003168000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3168000
|
Size: |
49152
|
|
59E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1414900615.00000000059E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59E1000
|
Size: |
36864
|
|
4CB6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506763973.0000000004CB6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB6000
|
Size: |
12288
|
|
74AD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1465426883.00000000074AD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
74AD000
|
Size: |
12288
|
|
4D51000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506162305.0000000004D51000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D51000
|
Size: |
143360
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495836008.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
5600000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494378865.0000000005600000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5600000
|
Size: |
4096
|
|
5A91000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1456271424.0000000005A91000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5A91000
|
Size: |
28672
|
|
35E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395294992.00000000035E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35E3000
|
Size: |
16384
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496802695.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
5B63000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412288473.0000000005B63000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B63000
|
Size: |
32768
|
|
4CEA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497248029.0000000004CEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CEA000
|
Size: |
114688
|
|
2A07000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1417787735.0000000002A07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A07000
|
Size: |
77824
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494103587.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
4D0D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004D0D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4D0D000
|
Size: |
90112
|
|
75DD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1465624851.00000000075DD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
75DD000
|
Size: |
12288
|
|
4CBD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495836008.0000000004CBD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CBD000
|
Size: |
61440
|
|
5942000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412979362.0000000005942000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5942000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3974000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3831416913.0000000003974000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3974000
|
Size: |
36864
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496278669.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
118784
|
|
59D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412922558.00000000059D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59D7000
|
Size: |
20480
|
|
35D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1392133583.00000000035D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35D5000
|
Size: |
49152
|
|
4CB9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495039232.0000000004CB9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB9000
|
Size: |
53248
|
|
2A44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419248296.0000000002A44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A44000
|
Size: |
16384
|
|
3641000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398178631.0000000003641000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3641000
|
Size: |
53248
|
|
2EB1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454125827.0000000002EB1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EB1000
|
Size: |
16384
|
|
342F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1487721551.000000000342F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
342F000
|
Size: |
4096
|
|
5EEC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420873172.0000000005EEC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5EEC000
|
Size: |
16384
|
|
6F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1399521927.00000000006F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6F0000
|
Size: |
20480
|
|
4EB9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004EB9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4EB9000
|
Size: |
8192
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497719224.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
36864
|
|
3084000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1484388991.0000000003084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3084000
|
Size: |
4096
|
|
4CC5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490494628.0000000004CC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC5000
|
Size: |
4096
|
|
2A9F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415166032.0000000002A9F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A9F000
|
Size: |
118784
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4DFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507809392.0000000004DFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4DFE000
|
Size: |
8192
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1493311090.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
833E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1468855119.000000000833E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
833E000
|
Size: |
8192
|
|
7660000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1466160591.0000000007660000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7660000
|
Size: |
65536
|
|
2AC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415166032.0000000002AC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AC3000
|
Size: |
8192
|
|
3612000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1392985229.0000000003612000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3612000
|
Size: |
245760
|
|
35ED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393775989.00000000035ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35ED000
|
Size: |
24576
|
|
3618000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1389518839.0000000003618000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3618000
|
Size: |
65536
|
|
5B6B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412249395.0000000005B6B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B6B000
|
Size: |
327680
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
34CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490008328.00000000034CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
34CA000
|
Size: |
20480
|
|
363B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1389478037.000000000363B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
363B000
|
Size: |
20480
|
|
2A4B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1396268255.0000000002A4B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A4B000
|
Size: |
12288
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506879070.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
225280
|
|
4F20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416690979.0000000004F20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F20000
|
Size: |
4096
|
|
6C2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463536293.0000000006C2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6C2E000
|
Size: |
8192
|
|
4DA7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004DA7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DA7000
|
Size: |
20480
|
|
4CB6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506611737.0000000004CB6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB6000
|
Size: |
12288
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496591970.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
135168
|
|
35ED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395524213.00000000035ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35ED000
|
Size: |
24576
|
|
4D51000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506238207.0000000004D51000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D51000
|
Size: |
151552
|
|
4CEA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496889658.0000000004CEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CEA000
|
Size: |
36864
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494268888.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
2AC6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415656383.0000000002AC6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AC6000
|
Size: |
102400
|
|
4CDA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1505368080.0000000004CDA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CDA000
|
Size: |
69632
|
|
35F9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397916173.00000000035F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35F9000
|
Size: |
4096
|
|
2A2D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3831080499.0000000002A2D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A2D000
|
Size: |
12288
|
|
6A21000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395695720.0000000006A21000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A21000
|
Size: |
4096
|
|
4D51000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1504786160.0000000004D51000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D51000
|
Size: |
143360
|
|
735C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393529207.000000000735C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
735C000
|
Size: |
65536
|
|
2C50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419605558.0000000002C50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C50000
|
Size: |
4096
|
|
365A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1392883986.000000000365A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
365A000
|
Size: |
86016
|
|
35FB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397962996.00000000035FB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35FB000
|
Size: |
49152
|
|
6E3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1399554791.0000000006E3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6E3E000
|
Size: |
8192
|
|
2ABE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415656383.0000000002ABE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ABE000
|
Size: |
8192
|
|
4FA0000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1398598668.0000000004FA0000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
4FA0000
|
Size: |
4096
|
|
3560000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397396829.0000000003560000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3560000
|
Size: |
4096
|
|
2E55000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1454036206.0000000002E55000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2E55000
|
Size: |
45056
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1502112821.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
36864
|
|
6DFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463733521.0000000006DFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6DFF000
|
Size: |
4096
|
|
4D15000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506162305.0000000004D15000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D15000
|
Size: |
122880
|
|
5B63000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1411953947.0000000005B63000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B63000
|
Size: |
360448
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
93F0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1482681372.00000000093F0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
93F0000
|
Size: |
1802240
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
59B6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412723196.00000000059B6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59B6000
|
Size: |
208896
|
|
80D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1467360844.00000000080D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
80D0000
|
Size: |
8192
|
|
3D30000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3832537828.0000000003D30000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3D30000
|
Size: |
106496
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found strings which match to known social media urls |
Networking |
|
URLs found in memory or binary data |
Networking |
|
|
34A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1396880793.00000000034A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
34A0000
|
Size: |
8192
|
|
2ABE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416011136.0000000002ABE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ABE000
|
Size: |
8192
|
|
360B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395480325.000000000360B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
360B000
|
Size: |
4096
|
|
365A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398178631.000000000365A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
365A000
|
Size: |
86016
|
|
F8B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3830123677.0000000000F8B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F8B000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
4CB9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490317567.0000000004CB9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB9000
|
Size: |
8192
|
|
3084000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1485891285.0000000003084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3084000
|
Size: |
4096
|
|
80A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1466729316.00000000080A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
80A0000
|
Size: |
4096
|
|
4CD7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1499746117.0000000004CD7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD7000
|
Size: |
155648
|
|
318F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1484496655.000000000318F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
318F000
|
Size: |
4096
|
|
741B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1464551335.000000000741B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
741B000
|
Size: |
122880
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
360F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398015284.000000000360F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
360F000
|
Size: |
8192
|
|
4CF2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1503823384.0000000004CF2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CF2000
|
Size: |
143360
|
|
6A20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1399465785.0000000006A20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A20000
|
Size: |
4096
|
|
2CD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416612603.0000000002CD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CD0000
|
Size: |
4096
|
|
10000000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3832933072.0000000010000000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
10000000
|
Size: |
4096
|
|
2A55000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1395300658.0000000002A55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A55000
|
Size: |
69632
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1492323417.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
4CED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506437465.0000000004CED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CED000
|
Size: |
20480
|
|
45E000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.1506972386.000000000045E000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
45E000
|
Size: |
4096
|
|
2EE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1485376149.0000000002EE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EE0000
|
Size: |
20480
|
|
2CE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419643403.0000000002CE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CE0000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DB4000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507129427.0000000002DB4000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DB4000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2AC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415349360.0000000002AC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AC3000
|
Size: |
8192
|
|
4CA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416246260.0000000004CA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CA0000
|
Size: |
4096
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497499737.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
16384
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491212280.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
355E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397335386.000000000355E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
355E000
|
Size: |
8192
|
|
601B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1456271424.000000000601B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
601B000
|
Size: |
10080256
|
|
4CC5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490380463.0000000004CC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC5000
|
Size: |
4096
|
|
34C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506811582.00000000034C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
34C7000
|
Size: |
4096
|
|
5B57000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412359367.0000000005B57000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B57000
|
Size: |
32768
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1493478835.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
EBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3829818205.0000000000EBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EBE000
|
Size: |
8192
|
|
4CD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507722395.0000000004CD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD4000
|
Size: |
24576
|
|
3084000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1484825036.0000000003084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3084000
|
Size: |
4096
|
|
4CD7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497912251.0000000004CD7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD7000
|
Size: |
12288
|
|
4CC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490380463.0000000004CC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC0000
|
Size: |
8192
|
|
35E8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393775989.00000000035E8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35E8000
|
Size: |
12288
|
|
7610000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1465818642.0000000007610000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7610000
|
Size: |
65536
|
|
4D0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1499824437.0000000004D0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D0A000
|
Size: |
77824
|
|
7620000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1465882256.0000000007620000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7620000
|
Size: |
65536
|
|
4FA0000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1398533916.0000000004FA0000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
4FA0000
|
Size: |
4096
|
|
6BEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463512772.0000000006BEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BEE000
|
Size: |
8192
|
|
4CD3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1502839344.0000000004CD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD3000
|
Size: |
28672
|
|
593E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420286391.000000000593E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
593E000
|
Size: |
4096
|
|
4E3F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507838081.0000000004E3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E3F000
|
Size: |
4096
|
|
5B63000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412083401.0000000005B63000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B63000
|
Size: |
360448
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1492658501.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490153964.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
110592
|
|
59AA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420604663.00000000059AA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59AA000
|
Size: |
12288
|
|
4CC5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490317567.0000000004CC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC5000
|
Size: |
4096
|
|
364F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393564509.000000000364F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
364F000
|
Size: |
16384
|
|
59D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1414616369.00000000059D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59D5000
|
Size: |
86016
|
|
4CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1498224917.0000000004CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB1000
|
Size: |
32768
|
|
2AB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453386455.0000000002AB0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AB0000
|
Size: |
4096
|
|
362F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1389518839.000000000362F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
362F000
|
Size: |
49152
|
|
35FA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394527287.00000000035FA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35FA000
|
Size: |
61440
|
|
4A3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454370157.0000000004A3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4A3E000
|
Size: |
8192
|
|
2E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453974417.0000000002E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E40000
|
Size: |
4096
|
|
80B0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1466827167.00000000080B0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
80B0000
|
Size: |
32768
|
|
3570000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397468580.0000000003570000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3570000
|
Size: |
28672
|
|
3084000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1486362666.0000000003084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3084000
|
Size: |
4096
|
|
2A54000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1395682653.0000000002A54000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A54000
|
Size: |
4096
|
|
35EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395294992.00000000035EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35EA000
|
Size: |
4096
|
|
5FED000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420926330.0000000005FED000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5FED000
|
Size: |
12288
|
|
7680000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1466297447.0000000007680000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7680000
|
Size: |
65536
|
|
4CC5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490809973.0000000004CC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC5000
|
Size: |
4096
|
|
6BAF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463485622.0000000006BAF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BAF000
|
Size: |
4096
|
|
4CC5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490582366.0000000004CC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC5000
|
Size: |
4096
|
|
2A75000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1395343486.0000000002A75000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A75000
|
Size: |
36864
|
|
78C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453344990.000000000078C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
78C000
|
Size: |
16384
|
|
4CDE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1493987855.0000000004CDE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CDE000
|
Size: |
61440
|
|
6BDF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394943038.0000000006BDF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6BDF000
|
Size: |
4096
|
|
4EC1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004EC1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4EC1000
|
Size: |
110592
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6A33000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394771587.0000000006A33000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A33000
|
Size: |
12288
|
|
6A38000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1399522271.0000000006A38000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A38000
|
Size: |
12288
|
|
398A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398416684.000000000398A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
398A000
|
Size: |
20480
|
|
59E2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420672548.00000000059E2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59E2000
|
Size: |
32768
|
|
6E3D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463766960.0000000006E3D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6E3D000
|
Size: |
12288
|
|
2EA9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454125827.0000000002EA9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EA9000
|
Size: |
4096
|
|
365A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393947295.000000000365A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
365A000
|
Size: |
86016
|
|
2E6C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1484895928.0000000002E6C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E6C000
|
Size: |
16384
|
|
2A38000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419151714.0000000002A38000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A38000
|
Size: |
32768
|
|
F96000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3830123677.0000000000F96000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F96000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
59D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1414741977.00000000059D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59D5000
|
Size: |
86016
|
|
361F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398060521.000000000361F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
361F000
|
Size: |
4096
|
|
2A49000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415166032.0000000002A49000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A49000
|
Size: |
339968
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
83C1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1469005987.00000000083C1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
83C1000
|
Size: |
8790016
|
|
35A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394460515.00000000035A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35A2000
|
Size: |
57344
|
|
E76000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3829754394.0000000000E76000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E76000
|
Size: |
12288
|
|
3641000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393564509.0000000003641000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3641000
|
Size: |
53248
|
|
7340000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1464433368.0000000007340000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7340000
|
Size: |
36864
|
|
4CD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1498094792.0000000004CD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD4000
|
Size: |
12288
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491001619.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
229376
|
|
59A1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420556536.00000000059A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59A1000
|
Size: |
32768
|
|
35D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395609435.00000000035D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35D5000
|
Size: |
49152
|
|
29B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3830922662.00000000029B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29B0000
|
Size: |
4096
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496089678.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1493945402.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
74C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1465497277.00000000074C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
74C0000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
81AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1468721072.00000000081AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
81AE000
|
Size: |
8192
|
|
570E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420178263.000000000570E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
570E000
|
Size: |
8192
|
|
5C3B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1456271424.0000000005C3B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5C3B000
|
Size: |
2273280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
74D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1465529513.00000000074D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
74D0000
|
Size: |
16384
|
|
4DEA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004DEA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DEA000
|
Size: |
28672
|
|
6180000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1399439689.0000000006180000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6180000
|
Size: |
4096
|
|
4DDB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004DDB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DDB000
|
Size: |
8192
|
|
3084000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1486058834.0000000003084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3084000
|
Size: |
4096
|
|
2D3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453742513.0000000002D3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D3E000
|
Size: |
8192
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1493885400.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
4CB6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506662355.0000000004CB6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB6000
|
Size: |
12288
|
|
4CDA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1500060538.0000000004CDA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CDA000
|
Size: |
184320
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1493755407.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
34D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1396987135.00000000034D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
34D0000
|
Size: |
16384
|
|
5EBB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1399338936.0000000005EBB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5EBB000
|
Size: |
20480
|
|
7C7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453364859.00000000007C7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7C7000
|
Size: |
36864
|
|
2DD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1399398727.00000000002DD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DD000
|
Size: |
12288
|
|
6E7A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463799549.0000000006E7A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6E7A000
|
Size: |
24576
|
|
2ABE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415513226.0000000002ABE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ABE000
|
Size: |
8192
|
|
4CEC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497112547.0000000004CEC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CEC000
|
Size: |
53248
|
|
32EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1486900045.00000000032EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
32EE000
|
Size: |
8192
|
|
5FFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1399389312.0000000005FFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5FFE000
|
Size: |
8192
|
|
4DDE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004DDE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DDE000
|
Size: |
12288
|
|
593D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1413204087.000000000593D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
593D000
|
Size: |
8192
|
|
71FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1464353996.00000000071FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
71FE000
|
Size: |
8192
|
|
71BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1464295244.00000000071BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
71BE000
|
Size: |
8192
|
|
2B6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3831228724.0000000002B6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B6E000
|
Size: |
8192
|
|
5600000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494399376.0000000005600000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5600000
|
Size: |
4096
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1492343488.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
2E24000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453893359.0000000002E24000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E24000
|
Size: |
36864
|
|
58A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398810609.00000000058A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
58A0000
|
Size: |
4096
|
|
360B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1392133583.000000000360B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
360B000
|
Size: |
274432
|
|
2ED0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454308872.0000000002ED0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ED0000
|
Size: |
32768
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497324950.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
2A7B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1395367438.0000000002A7B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A7B000
|
Size: |
12288
|
|
4CC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490317567.0000000004CC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC0000
|
Size: |
8192
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497135041.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
2A5B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1396042257.0000000002A5B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A5B000
|
Size: |
40960
|
|
2A6B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1396153384.0000000002A6B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A6B000
|
Size: |
40960
|
|
5B6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1414937150.0000000005B6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B6C000
|
Size: |
323584
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4CC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490582366.0000000004CC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC0000
|
Size: |
8192
|
|
4CD3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506340566.0000000004CD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD3000
|
Size: |
28672
|
|
3582000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397468580.0000000003582000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3582000
|
Size: |
45056
|
|
4F14000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004F14000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4F14000
|
Size: |
3731456
|
|
3084000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1485911967.0000000003084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3084000
|
Size: |
4096
|
|
6B2A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395098614.0000000006B2A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6B2A000
|
Size: |
4096
|
|
93D2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1482620249.00000000093D2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
93D2000
|
Size: |
12288
|
|
76B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1466501169.00000000076B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
76B0000
|
Size: |
65536
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494148558.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
6F3F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1399575992.0000000006F3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6F3F000
|
Size: |
4096
|
|
9732000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1486890424.0000000009732000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9732000
|
Size: |
8192
|
|
3120000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1487408927.0000000003120000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3120000
|
Size: |
4096
|
|
2ABE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412778416.0000000002ABE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ABE000
|
Size: |
8192
|
|
3615000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393726007.0000000003615000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3615000
|
Size: |
36864
|
|
3640000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393235855.0000000003640000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3640000
|
Size: |
57344
|
|
599E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1414810898.000000000599E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
599E000
|
Size: |
57344
|
|
E70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3829754394.0000000000E70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E70000
|
Size: |
16384
|
|
59A9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1414843789.00000000059A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59A9000
|
Size: |
12288
|
|
4CDA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506437465.0000000004CDA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CDA000
|
Size: |
45056
|
|
5B16000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412053397.0000000005B16000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B16000
|
Size: |
155648
|
|
75F0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1465717382.00000000075F0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
75F0000
|
Size: |
8192
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495114438.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
2ABE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415166032.0000000002ABE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ABE000
|
Size: |
8192
|
|
6A30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394687319.0000000006A30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A30000
|
Size: |
49152
|
|
6A36000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394713950.0000000006A36000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A36000
|
Size: |
24576
|
|
2BAB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453457219.0000000002BAB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2BAB000
|
Size: |
12288
|
|
6BEB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394943038.0000000006BEB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6BEB000
|
Size: |
4096
|
|
4CD3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1505148160.0000000004CD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD3000
|
Size: |
28672
|
|
2AC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415513226.0000000002AC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AC3000
|
Size: |
8192
|
|
595F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1414616369.000000000595F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
595F000
|
Size: |
192512
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2EAC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454125827.0000000002EAC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EAC000
|
Size: |
8192
|
|
34A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507499950.00000000034A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
34A0000
|
Size: |
4096
|
|
2A4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1395985726.0000000002A4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A4A000
|
Size: |
16384
|
|
5B32000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412189104.0000000005B32000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B32000
|
Size: |
40960
|
|
35F9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393145079.00000000035F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35F9000
|
Size: |
69632
|
|
4C2F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419797482.0000000004C2F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C2F000
|
Size: |
4096
|
|
2A9F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415513226.0000000002A9F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A9F000
|
Size: |
118784
|
|
5664000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398624951.0000000005664000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5664000
|
Size: |
4096
|
|
2A66000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1395269795.0000000002A66000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A66000
|
Size: |
98304
|
|
4CB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495670894.0000000004CB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB5000
|
Size: |
73728
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496916876.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1493073382.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
35B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393320147.00000000035B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35B1000
|
Size: |
32768
|
|
3084000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1485440391.0000000003084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3084000
|
Size: |
4096
|
|
29E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419101115.00000000029E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29E0000
|
Size: |
28672
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1505060950.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
36864
|
|
386E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398296507.000000000386E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
386E000
|
Size: |
8192
|
|
2EAB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1484972693.0000000002EAB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2EAB000
|
Size: |
20480
|
|
5071000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1484683903.0000000005071000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5071000
|
Size: |
229376
|
|
6A2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395695720.0000000006A2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A2F000
|
Size: |
4096
|
|
3900000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398346242.0000000003900000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3900000
|
Size: |
4096
|
|
3084000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1485946906.0000000003084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3084000
|
Size: |
4096
|
|
7690000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1466358661.0000000007690000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7690000
|
Size: |
65536
|
|
5B12000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1414937150.0000000005B12000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B12000
|
Size: |
20480
|
|
315D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507287828.000000000315D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
315D000
|
Size: |
12288
|
|
318F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1486406178.000000000318F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
318F000
|
Size: |
4096
|
|
8150000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1468277299.0000000008150000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
8150000
|
Size: |
8192
|
|
FF7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3830664589.0000000000FF7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FF7000
|
Size: |
16384
|
|
2AC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416011136.0000000002AC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AC3000
|
Size: |
8192
|
|
360C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1392883986.000000000360C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
360C000
|
Size: |
270336
|
|
3160000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507309918.0000000003160000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3160000
|
Size: |
24576
|
|
6A2C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394771587.0000000006A2C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A2C000
|
Size: |
4096
|
|
49FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454348288.00000000049FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
49FE000
|
Size: |
8192
|
|
4AED000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004AED000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4AED000
|
Size: |
1015808
|
|
2A4E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1395462892.0000000002A4E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A4E000
|
Size: |
28672
|
|
6B23000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395098614.0000000006B23000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6B23000
|
Size: |
4096
|
|
362E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394297419.000000000362E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
362E000
|
Size: |
73728
|
|
759E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1465593213.000000000759E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
759E000
|
Size: |
8192
|
|
3D80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3832826537.0000000003D80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3D80000
|
Size: |
4096
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1493249410.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
45C000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1484482842.000000000045C000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
45C000
|
Size: |
24576
|
|
80C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1466882115.00000000080C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
80C0000
|
Size: |
49152
|
|
365A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1392985229.000000000365A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
365A000
|
Size: |
86016
|
|
4F0F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420082830.0000000004F0F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F0F000
|
Size: |
4096
|
|
51AE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1487922074.00000000051AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
51AE000
|
Size: |
8192
|
|
3084000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1485757784.0000000003084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3084000
|
Size: |
4096
|
|
475000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3828986225.0000000000475000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
475000
|
Size: |
8192
|
|
3084000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1486005775.0000000003084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3084000
|
Size: |
4096
|
|
5071000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1484300423.0000000005071000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5071000
|
Size: |
65536
|
|
296F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1418985153.000000000296F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
296F000
|
Size: |
4096
|
|
4CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494686011.0000000004CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CE4000
|
Size: |
4096
|
|
755E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1465572731.000000000755E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
755E000
|
Size: |
8192
|
|
4D33000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1500849717.0000000004D33000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D33000
|
Size: |
266240
|
|
35F9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393775989.00000000035F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35F9000
|
Size: |
69632
|
|
2A6B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1396042257.0000000002A6B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A6B000
|
Size: |
40960
|
|
8140000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1468126663.0000000008140000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8140000
|
Size: |
4096
|
|
2B2F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3831164791.0000000002B2F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B2F000
|
Size: |
4096
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1484911709.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1493674946.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1493407848.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491715129.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
4CB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506763973.0000000004CB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB0000
|
Size: |
16384
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497499737.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
2AC6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412778416.0000000002AC6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AC6000
|
Size: |
102400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
3045000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491640624.0000000003045000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3045000
|
Size: |
4096
|
|
5A99000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1456271424.0000000005A99000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5A99000
|
Size: |
299008
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1493832205.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495836008.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
69632
|
|
23BB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1418754883.00000000023BB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
23BB000
|
Size: |
20480
|
|
364F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393947295.000000000364F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
364F000
|
Size: |
16384
|
|
2A65000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1395389944.0000000002A65000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A65000
|
Size: |
4096
|
|
35CC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1392133583.00000000035CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35CC000
|
Size: |
32768
|
|
73FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1464551335.00000000073FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
73FD000
|
Size: |
12288
|
|
4A50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454401692.0000000004A50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A50000
|
Size: |
65536
|
|
2AC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415656383.0000000002AC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AC3000
|
Size: |
8192
|
|
9700000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1486573822.0000000009700000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9700000
|
Size: |
4096
|
|
5B6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412359367.0000000005B6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B6C000
|
Size: |
323584
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6DD9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394860697.0000000006DD9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6DD9000
|
Size: |
8192
|
|
395E000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3831416913.000000000395E000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
395E000
|
Size: |
4096
|
|
4CB9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495114438.0000000004CB9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB9000
|
Size: |
53248
|
|
CFB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3829679242.0000000000CFB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CFB000
|
Size: |
20480
|
|
4CF1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496457781.0000000004CF1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CF1000
|
Size: |
28672
|
|
35F9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395294992.00000000035F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35F9000
|
Size: |
4096
|
|
5B6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412476327.0000000005B6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B6C000
|
Size: |
323584
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
364F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1392985229.000000000364F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
364F000
|
Size: |
16384
|
|
3020000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507223497.0000000003020000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3020000
|
Size: |
4096
|
|
478000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3828986225.0000000000478000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
478000
|
Size: |
36864
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496683273.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
135168
|
|
4CF2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1498536019.0000000004CF2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CF2000
|
Size: |
73728
|
|
751E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1465553316.000000000751E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
751E000
|
Size: |
8192
|
|
732C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1399638201.000000000732C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
732C000
|
Size: |
16384
|
|
38E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1399448667.000000000038E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
38E000
|
Size: |
8192
|
|
4CB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506611737.0000000004CB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB0000
|
Size: |
16384
|
|
4CBC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507645116.0000000004CBC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CBC000
|
Size: |
20480
|
|
6CAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463586481.0000000006CAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6CAE000
|
Size: |
8192
|
|
35E5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395641307.00000000035E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35E5000
|
Size: |
8192
|
|
3CC0000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3832025820.0000000003CC0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3CC0000
|
Size: |
344064
|
|
30D0000
|
heap
|
page readonly
|
|
|
|
Name: |
0000000A.00000002.1487282048.00000000030D0000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
30D0000
|
Size: |
4096
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491865213.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
5666000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398624951.0000000005666000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5666000
|
Size: |
32768
|
|
4CB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506715529.0000000004CB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB0000
|
Size: |
16384
|
|
4CD5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495971572.0000000004CD5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD5000
|
Size: |
73728
|
|
2A38000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416714730.0000000002A38000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A38000
|
Size: |
32768
|
|
4C38000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1486161891.0000000004C38000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C38000
|
Size: |
12288
|
|
4CF5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1498302842.0000000004CF5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CF5000
|
Size: |
36864
|
|
81B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1468753436.00000000081B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
81B0000
|
Size: |
65536
|
|
10016000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3832957939.0000000010016000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
10016000
|
Size: |
8192
|
|
6D70000
|
trusted library allocation
|
page execute
|
|
|
|
Name: |
00000000.00000003.1393452216.0000000006D70000.00000010.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute
|
Base address: |
6D70000
|
Size: |
4096
|
|
6ACC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463254404.0000000006ACC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6ACC000
|
Size: |
16384
|
|
2A5A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1396015206.0000000002A5A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A5A000
|
Size: |
45056
|
|
2A7B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416011136.0000000002A7B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A7B000
|
Size: |
135168
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
6F7B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463946139.0000000006F7B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6F7B000
|
Size: |
20480
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1492246480.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
2ED9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454308872.0000000002ED9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ED9000
|
Size: |
12288
|
|
5070000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1487871958.0000000005070000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5070000
|
Size: |
4096
|
|
76A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1466432613.00000000076A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
76A0000
|
Size: |
65536
|
|
4CF2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1499058837.0000000004CF2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CF2000
|
Size: |
98304
|
|
590C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420234064.000000000590C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
590C000
|
Size: |
16384
|
|
4B2F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419774034.0000000004B2F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4B2F000
|
Size: |
4096
|
|
35E7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393145079.00000000035E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35E7000
|
Size: |
16384
|
|
4D04000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1498963709.0000000004D04000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D04000
|
Size: |
40960
|
|
6DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394860697.0000000006DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6DD0000
|
Size: |
8192
|
|
2A2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419151714.0000000002A2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A2F000
|
Size: |
32768
|
|
2A4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419248296.0000000002A4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A4A000
|
Size: |
12288
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1484868402.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
65536
|
|
2C6F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3831274213.0000000002C6F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C6F000
|
Size: |
4096
|
|
51EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507888480.00000000051EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
51EE000
|
Size: |
8192
|
|
3480000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1487825590.0000000003480000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3480000
|
Size: |
8192
|
|
3612000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1389518839.0000000003612000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3612000
|
Size: |
8192
|
|
6B2C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395098614.0000000006B2C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6B2C000
|
Size: |
4096
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497135041.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
196608
|
|
360B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397994282.000000000360B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
360B000
|
Size: |
4096
|
|
59AF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1414741977.00000000059AF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59AF000
|
Size: |
4096
|
|
2A63000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1396153384.0000000002A63000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A63000
|
Size: |
8192
|
|
3040000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507266468.0000000003040000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3040000
|
Size: |
16384
|
|
349E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507471477.000000000349E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
349E000
|
Size: |
8192
|
|
2865000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1418901897.0000000002865000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2865000
|
Size: |
20480
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1493795545.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
2A9F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415349360.0000000002A9F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A9F000
|
Size: |
118784
|
|
77F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1399574016.000000000077F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
77F000
|
Size: |
4096
|
|
307A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1486895682.000000000307A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
307A000
|
Size: |
24576
|
|
4CDC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494686011.0000000004CDC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CDC000
|
Size: |
4096
|
|
3614000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1389256448.0000000003614000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3614000
|
Size: |
180224
|
|
2BDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419579839.0000000002BDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2BDE000
|
Size: |
8192
|
|
2AC6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415349360.0000000002AC6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AC6000
|
Size: |
102400
|
|
4CBC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1498407989.0000000004CBC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CBC000
|
Size: |
20480
|
|
5270000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507951930.0000000005270000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5270000
|
Size: |
4096
|
|
2A7C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419451051.0000000002A7C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A7C000
|
Size: |
131072
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
E40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3829734190.0000000000E40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E40000
|
Size: |
4096
|
|
5BBA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420832485.0000000005BBA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5BBA000
|
Size: |
4096
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1492043651.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
7337000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394547465.0000000007337000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7337000
|
Size: |
151552
|
|
4CA3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416246260.0000000004CA3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CA3000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
26F9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1418776502.00000000026F9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
26F9000
|
Size: |
28672
|
|
4CCD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494686011.0000000004CCD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCD000
|
Size: |
8192
|
|
2A57000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1395462892.0000000002A57000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A57000
|
Size: |
57344
|
|
5B5F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412083401.0000000005B5F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B5F000
|
Size: |
12288
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496278669.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
336C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1483968070.000000000336C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
336C000
|
Size: |
4096
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506089987.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
36864
|
|
6F3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463917142.0000000006F3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6F3E000
|
Size: |
8192
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495753795.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
6F98000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463978429.0000000006F98000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6F98000
|
Size: |
229376
|
|
598F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420473590.000000000598F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
598F000
|
Size: |
32768
|
|
32AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1486852583.00000000032AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
32AF000
|
Size: |
4096
|
|
4D15000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1503115278.0000000004D15000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D15000
|
Size: |
122880
|
|
3641000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393947295.0000000003641000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3641000
|
Size: |
53248
|
|
2E52000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454021321.0000000002E52000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E52000
|
Size: |
12288
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497324950.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
102400
|
|
593B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412979362.000000000593B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
593B000
|
Size: |
16384
|
|
4E08000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004E08000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E08000
|
Size: |
651264
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
3084000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1484956920.0000000003084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3084000
|
Size: |
4096
|
|
3CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1399469643.00000000003CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3CF000
|
Size: |
4096
|
|
F57000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3830123677.0000000000F57000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F57000
|
Size: |
114688
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
URLs found in memory or binary data |
Networking |
|
|
2A6D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415656383.0000000002A6D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A6D000
|
Size: |
192512
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491794747.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
5B6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412288473.0000000005B6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B6C000
|
Size: |
323584
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4D2D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420036726.0000000004D2D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D2D000
|
Size: |
12288
|
|
3944000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398369648.0000000003944000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3944000
|
Size: |
8192
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1504567762.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
36864
|
|
2A07000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419151714.0000000002A07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A07000
|
Size: |
77824
|
|
4DF4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004DF4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DF4000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495670894.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
16384
|
|
566F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398624951.000000000566F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
566F000
|
Size: |
4096
|
|
4CC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507668158.0000000004CC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC3000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
7640000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1466031541.0000000007640000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7640000
|
Size: |
65536
|
|
6C6D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463560162.0000000006C6D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6C6D000
|
Size: |
12288
|
|
3621000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398082699.0000000003621000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3621000
|
Size: |
28672
|
|
4CEF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490809973.0000000004CEF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CEF000
|
Size: |
4096
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1492292473.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
76C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1466612526.00000000076C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
76C0000
|
Size: |
65536
|
|
4CED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1504958324.0000000004CED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CED000
|
Size: |
20480
|
|
3609000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393898800.0000000003609000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3609000
|
Size: |
4096
|
|
3DCF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398511958.0000000003DCF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3DCF000
|
Size: |
4096
|
|
35E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397849899.00000000035E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35E3000
|
Size: |
8192
|
|
4CFA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1498880960.0000000004CFA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CFA000
|
Size: |
81920
|
|
5B3C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1411953947.0000000005B3C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B3C000
|
Size: |
53248
|
|
5A10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416208148.0000000005A10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A10000
|
Size: |
319488
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
713E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1464243765.000000000713E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
713E000
|
Size: |
8192
|
|
3045000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491518717.0000000003045000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3045000
|
Size: |
4096
|
|
3615000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398039712.0000000003615000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3615000
|
Size: |
36864
|
|
4D06000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497429696.0000000004D06000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D06000
|
Size: |
20480
|
|
362E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1389419771.000000000362E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
362E000
|
Size: |
73728
|
|
2A52000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1396042257.0000000002A52000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A52000
|
Size: |
8192
|
|
3940000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398369648.0000000003940000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3940000
|
Size: |
8192
|
|
2D9B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507129427.0000000002D9B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D9B000
|
Size: |
8192
|
|
2ABE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415349360.0000000002ABE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ABE000
|
Size: |
8192
|
|
361E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393389215.000000000361E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
361E000
|
Size: |
8192
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1492154129.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
4CEA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496654578.0000000004CEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CEA000
|
Size: |
32768
|
|
303C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1486847795.000000000303C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
303C000
|
Size: |
16384
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496390734.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
159744
|
|
7242000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1464384612.0000000007242000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7242000
|
Size: |
4096
|
|
4CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497135041.0000000004CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB1000
|
Size: |
53248
|
|
737D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1464551335.000000000737D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
737D000
|
Size: |
172032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
365A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1392133583.000000000365A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
365A000
|
Size: |
86016
|
|
3628000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1389341913.0000000003628000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3628000
|
Size: |
98304
|
|
2ABE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419451051.0000000002ABE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ABE000
|
Size: |
8192
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496089678.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
106496
|
|
1010000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3830764880.0000000001010000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1010000
|
Size: |
32768
|
|
4CDC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494988359.0000000004CDC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CDC000
|
Size: |
4096
|
|
2DBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453799544.0000000002DBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DBE000
|
Size: |
8192
|
|
4CC8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1489951680.0000000004CC8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC8000
|
Size: |
102400
|
|
35CC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395294992.00000000035CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35CC000
|
Size: |
32768
|
|
4C60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1487251820.0000000004C60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C60000
|
Size: |
8192
|
|
2E23000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1453872416.0000000002E23000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2E23000
|
Size: |
4096
|
|
595E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1413204087.000000000595E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
595E000
|
Size: |
360448
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
360C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1389742182.000000000360C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
360C000
|
Size: |
24576
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497034981.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
163840
|
|
820000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1399636748.0000000000820000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
820000
|
Size: |
24576
|
|
351E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397288479.000000000351E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
351E000
|
Size: |
8192
|
|
59AF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1414616369.00000000059AF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59AF000
|
Size: |
4096
|
|
318F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1487678069.000000000318F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
318F000
|
Size: |
4096
|
|
2A6E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1396207697.0000000002A6E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A6E000
|
Size: |
28672
|
|
5600000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495460017.0000000005600000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5600000
|
Size: |
167936
|
|
6F80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463978429.0000000006F80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6F80000
|
Size: |
69632
|
|
35E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395587767.00000000035E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35E3000
|
Size: |
16384
|
|
4DA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507786309.0000000004DA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DA0000
|
Size: |
4096
|
|
4CD3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1498008906.0000000004CD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD3000
|
Size: |
16384
|
|
6A33000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394832276.0000000006A33000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A33000
|
Size: |
12288
|
|
4CED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1505368080.0000000004CED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CED000
|
Size: |
286720
|
|
4C90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507568647.0000000004C90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C90000
|
Size: |
4096
|
|
30C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1487158030.00000000030C0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C0000
|
Size: |
4096
|
|
317E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1487530212.000000000317E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
317E000
|
Size: |
20480
|
|
813D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1468024985.000000000813D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
813D000
|
Size: |
12288
|
|
4CEF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1493987855.0000000004CEF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CEF000
|
Size: |
4096
|
|
5653000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398568680.0000000005653000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5653000
|
Size: |
12288
|
|
4CB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506662355.0000000004CB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB0000
|
Size: |
16384
|
|
2E2D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1453918054.0000000002E2D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2E2D000
|
Size: |
8192
|
|
4CC5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1500166746.0000000004CC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC5000
|
Size: |
40960
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506922059.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
593B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416155899.000000000593B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
593B000
|
Size: |
8192
|
|
34D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1396987135.00000000034D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
34D5000
|
Size: |
16384
|
|
4CDE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490809973.0000000004CDE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CDE000
|
Size: |
61440
|
|
5B53000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412476327.0000000005B53000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B53000
|
Size: |
16384
|
|
335A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1396624494.000000000335A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
335A000
|
Size: |
24576
|
|
2A6B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1395389944.0000000002A6B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A6B000
|
Size: |
40960
|
|
38AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398323630.00000000038AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
38AE000
|
Size: |
8192
|
|
6A33000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395695720.0000000006A33000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A33000
|
Size: |
12288
|
|
2AC6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415166032.0000000002AC6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AC6000
|
Size: |
102400
|
|
4CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496683273.0000000004CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB1000
|
Size: |
36864
|
|
2B2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453457219.0000000002B2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B2F000
|
Size: |
212992
|
|
75E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1465652381.00000000075E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
75E0000
|
Size: |
65536
|
|
33C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1396797713.00000000033C0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33C0000
|
Size: |
4096
|
|
3626000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1389819818.0000000003626000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3626000
|
Size: |
8192
|
|
120F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3830889970.000000000120F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
120F000
|
Size: |
4096
|
|
4CB6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506715529.0000000004CB6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB6000
|
Size: |
12288
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496390734.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
3987000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398416684.0000000003987000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3987000
|
Size: |
8192
|
|
83BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1468912955.00000000083BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83BE000
|
Size: |
8192
|
|
35ED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395294992.00000000035ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35ED000
|
Size: |
24576
|
|
35D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397822101.00000000035D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35D5000
|
Size: |
49152
|
|
598F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1414616369.000000000598F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
598F000
|
Size: |
118784
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1500166746.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
24576
|
|
2E50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454004066.0000000002E50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E50000
|
Size: |
4096
|
|
325A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1396282892.000000000325A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
325A000
|
Size: |
24576
|
|
4DAF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004DAF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DAF000
|
Size: |
36864
|
|
362C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1389690229.000000000362C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
362C000
|
Size: |
8192
|
|
4D0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1499980898.0000000004D0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D0A000
|
Size: |
77824
|
|
6A2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394771587.0000000006A2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A2F000
|
Size: |
4096
|
|
5600000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398536410.0000000005600000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5600000
|
Size: |
4096
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491334135.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
2A51000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419292376.0000000002A51000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A51000
|
Size: |
8192
|
|
4CC6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490076803.0000000004CC6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC6000
|
Size: |
86016
|
|
4C80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416393769.0000000004C80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C80000
|
Size: |
4096
|
|
358E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397468580.000000000358E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
358E000
|
Size: |
77824
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1492404633.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
4CEA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496478934.0000000004CEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CEA000
|
Size: |
28672
|
|
3080000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1487069024.0000000003080000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3080000
|
Size: |
16384
|
|
2AA7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412778416.0000000002AA7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AA7000
|
Size: |
86016
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4CF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490636620.0000000004CF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CF0000
|
Size: |
8192
|
|
74B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1465467266.00000000074B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
74B0000
|
Size: |
20480
|
|
4CC5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1502112821.0000000004CC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC5000
|
Size: |
40960
|
|
2A53000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415513226.0000000002A53000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A53000
|
Size: |
299008
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495536940.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
2B21000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453457219.0000000002B21000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B21000
|
Size: |
49152
|
|
2A6B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419400874.0000000002A6B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A6B000
|
Size: |
8192
|
|
4D30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416342999.0000000004D30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D30000
|
Size: |
4096
|
|
3084000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1485838323.0000000003084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3084000
|
Size: |
4096
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1492564011.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
374F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3831393112.000000000374F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
374F000
|
Size: |
4096
|
|
4C6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419815724.0000000004C6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C6E000
|
Size: |
8192
|
|
593D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415908342.000000000593D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
593D000
|
Size: |
8192
|
|
360B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393775989.000000000360B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
360B000
|
Size: |
4096
|
|
5660000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398624951.0000000005660000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5660000
|
Size: |
4096
|
|
400000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1484482842.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
344064
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
3622000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1389798984.0000000003622000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3622000
|
Size: |
24576
|
|
560D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420143385.000000000560D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
560D000
|
Size: |
12288
|
|
FFE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3830664589.0000000000FFE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FFE000
|
Size: |
8192
|
|
5B53000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412189104.0000000005B53000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B53000
|
Size: |
49152
|
|
3084000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1486340523.0000000003084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3084000
|
Size: |
4096
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491313495.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
2E39000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453939531.0000000002E39000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E39000
|
Size: |
16384
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496916876.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
155648
|
|
6BD4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394943038.0000000006BD4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6BD4000
|
Size: |
4096
|
|
5B10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420780545.0000000005B10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B10000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2B7D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453457219.0000000002B7D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B7D000
|
Size: |
184320
|
|
4CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497969047.0000000004CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB1000
|
Size: |
65536
|
|
5942000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1413204087.0000000005942000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5942000
|
Size: |
12288
|
|
364F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393235855.000000000364F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
364F000
|
Size: |
16384
|
|
3483000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1486200909.0000000003483000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3483000
|
Size: |
4096
|
|
93C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1482620249.00000000093C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
93C0000
|
Size: |
4096
|
|
547F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1508001426.000000000547F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
547F000
|
Size: |
4096
|
|
360B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393145079.000000000360B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
360B000
|
Size: |
4096
|
|
2F30000
|
heap
|
page readonly
|
|
|
|
Name: |
00000009.00000002.1486085374.0000000002F30000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
2F30000
|
Size: |
4096
|
|
3190000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1484459786.0000000003190000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3190000
|
Size: |
163840
|
|
4CED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1500562014.0000000004CED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CED000
|
Size: |
20480
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491690269.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
2FE8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1486515922.0000000002FE8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FE8000
|
Size: |
77824
|
|
5998000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420535127.0000000005998000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5998000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
9FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3829643721.00000000009FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9FC000
|
Size: |
16384
|
|
34C9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506811582.00000000034C9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
34C9000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found strings which match to known social media urls |
Networking |
|
URLs found in memory or binary data |
Networking |
|
|
2EC0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1454286671.0000000002EC0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2EC0000
|
Size: |
61440
|
|
4DCF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004DCF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DCF000
|
Size: |
45056
|
|
5D3F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1399018750.0000000005D3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5D3F000
|
Size: |
4096
|
|
364E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3831362054.000000000364E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
364E000
|
Size: |
8192
|
|
6B65000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1463393995.0000000006B65000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
6B65000
|
Size: |
8192
|
|
580F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420201481.000000000580F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
580F000
|
Size: |
4096
|
|
2A1F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1417787735.0000000002A1F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A1F000
|
Size: |
4096
|
|
5280000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1484386355.0000000005280000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5280000
|
Size: |
1085440
|
|
4D51000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1503115278.0000000004D51000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D51000
|
Size: |
143360
|
|
35ED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397916173.00000000035ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35ED000
|
Size: |
24576
|
|
2E30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453939531.0000000002E30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E30000
|
Size: |
32768
|
|
717F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1464268337.000000000717F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
717F000
|
Size: |
4096
|
|
593C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420286391.000000000593C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
593C000
|
Size: |
4096
|
|
2F20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1485533297.0000000002F20000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F20000
|
Size: |
4096
|
|
6D68000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394899035.0000000006D68000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6D68000
|
Size: |
8192
|
|
5600000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494486963.0000000005600000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5600000
|
Size: |
4096
|
|
4CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496505033.0000000004CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB1000
|
Size: |
32768
|
|
2DAF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507129427.0000000002DAF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DAF000
|
Size: |
16384
|
|
2AC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412778416.0000000002AC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AC3000
|
Size: |
8192
|
|
4CC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490494628.0000000004CC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC0000
|
Size: |
8192
|
|
5650000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398568680.0000000005650000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5650000
|
Size: |
4096
|
|
348D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1486260216.000000000348D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
348D000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2A63000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1417043151.0000000002A63000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A63000
|
Size: |
40960
|
|
35B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394460515.00000000035B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35B1000
|
Size: |
32768
|
|
2A6F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1417043151.0000000002A6F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A6F000
|
Size: |
49152
|
|
3D16000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3832025820.0000000003D16000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3D16000
|
Size: |
8192
|
|
595E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412979362.000000000595E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
595E000
|
Size: |
360448
|
|
6A2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395046762.0000000006A2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A2F000
|
Size: |
4096
|
|
4CF2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1500482430.0000000004CF2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CF2000
|
Size: |
86016
|
|
7330000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1464409349.0000000007330000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
7330000
|
Size: |
4096
|
|
2CED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412232597.0000000002CED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CED000
|
Size: |
8192
|
|
362F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1389690229.000000000362F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
362F000
|
Size: |
49152
|
|
362C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1389518839.000000000362C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
362C000
|
Size: |
8192
|
|
743A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1464551335.000000000743A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
743A000
|
Size: |
20480
|
|
3084000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1484888226.0000000003084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3084000
|
Size: |
4096
|
|
4CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1498061183.0000000004CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB1000
|
Size: |
65536
|
|
4CC1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1489951680.0000000004CC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC1000
|
Size: |
8192
|
|
474000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.1506972386.0000000000474000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
474000
|
Size: |
36864
|
|
55FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1508107924.00000000055FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
55FF000
|
Size: |
4096
|
|
2E20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453854006.0000000002E20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E20000
|
Size: |
12288
|
|
4D24000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004D24000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4D24000
|
Size: |
503808
|
|
2A51000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1417285140.0000000002A51000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A51000
|
Size: |
8192
|
|
2AF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453457219.0000000002AF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AF0000
|
Size: |
36864
|
|
6D61000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394899035.0000000006D61000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6D61000
|
Size: |
8192
|
|
29AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419078907.00000000029AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
29AE000
|
Size: |
8192
|
|
2EA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454125827.0000000002EA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EA0000
|
Size: |
16384
|
|
4DA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1485323254.0000000004DA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DA0000
|
Size: |
167936
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1499190864.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
135168
|
|
2F7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1486292405.0000000002F7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F7E000
|
Size: |
8192
|
|
2860000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1418901897.0000000002860000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2860000
|
Size: |
16384
|
|
59DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412755422.00000000059DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59DC000
|
Size: |
53248
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1492429711.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
4D51000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1503823384.0000000004D51000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D51000
|
Size: |
143360
|
|
4D33000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1505200043.0000000004D33000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D33000
|
Size: |
266240
|
|
4CF3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497283593.0000000004CF3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CF3000
|
Size: |
98304
|
|
595E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420286391.000000000595E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
595E000
|
Size: |
4096
|
|
5910000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420256637.0000000005910000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5910000
|
Size: |
176128
|
|
2E90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454090133.0000000002E90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E90000
|
Size: |
20480
|
|
4CBC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1498224917.0000000004CBC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CBC000
|
Size: |
20480
|
|
3360000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1487112414.0000000003360000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3360000
|
Size: |
12288
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495999527.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
16384
|
|
3620000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393361810.0000000003620000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3620000
|
Size: |
40960
|
|
6DBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463704128.0000000006DBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6DBE000
|
Size: |
8192
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1493158423.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
6A33000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1399465785.0000000006A33000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A33000
|
Size: |
12288
|
|
5600000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494535424.0000000005600000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5600000
|
Size: |
4096
|
|
456000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1484482842.0000000000456000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
456000
|
Size: |
8192
|
|
4CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1498407989.0000000004CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB1000
|
Size: |
36864
|
|
4CB9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1505652165.0000000004CB9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB9000
|
Size: |
90112
|
|
1020000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3830764880.0000000001020000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1020000
|
Size: |
32768
|
|
522E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507916922.000000000522E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
522E000
|
Size: |
8192
|
|
7830000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1399701127.0000000007830000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7830000
|
Size: |
8192
|
|
7650000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1466094245.0000000007650000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7650000
|
Size: |
65536
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494686011.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
16384
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491830166.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
2A57000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1395682653.0000000002A57000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A57000
|
Size: |
57344
|
|
6D3D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463626803.0000000006D3D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6D3D000
|
Size: |
12288
|
|
4CC1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497719224.0000000004CC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC1000
|
Size: |
57344
|
|
2A1F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419151714.0000000002A1F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A1F000
|
Size: |
4096
|
|
3045000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1492801713.0000000003045000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3045000
|
Size: |
4096
|
|
45F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419751602.00000000045F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
45F0000
|
Size: |
4096
|
|
2B72000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453457219.0000000002B72000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B72000
|
Size: |
40960
|
|
6EBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463837130.0000000006EBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6EBE000
|
Size: |
8192
|
|
3030000
|
heap
|
page readonly
|
|
|
|
Name: |
00000008.00000002.1507246847.0000000003030000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
3030000
|
Size: |
4096
|
|
2AC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453404138.0000000002AC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AC0000
|
Size: |
8192
|
|
59D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1413372095.00000000059D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59D5000
|
Size: |
8192
|
|
35F9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395524213.00000000035F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35F9000
|
Size: |
4096
|
|
2840000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1418863980.0000000002840000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2840000
|
Size: |
8192
|
|
2FFC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1486515922.0000000002FFC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FFC000
|
Size: |
28672
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496505033.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
135168
|
|
2AC6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415513226.0000000002AC6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AC6000
|
Size: |
102400
|
|
4BE8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004BE8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4BE8000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6A25000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395046762.0000000006A25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A25000
|
Size: |
20480
|
|
2A40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415166032.0000000002A40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A40000
|
Size: |
32768
|
|
5942000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420286391.0000000005942000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5942000
|
Size: |
12288
|
|
348D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1486200909.000000000348D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
348D000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4CE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494898369.0000000004CE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CE4000
|
Size: |
4096
|
|
35B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397685625.00000000035B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35B1000
|
Size: |
32768
|
|
2D97000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507129427.0000000002D97000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D97000
|
Size: |
4096
|
|
7460000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1465385073.0000000007460000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7460000
|
Size: |
4096
|
|
5600000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494462040.0000000005600000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5600000
|
Size: |
4096
|
|
F9C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3830123677.0000000000F9C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F9C000
|
Size: |
4096
|
|
734A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1464433368.000000000734A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
734A000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2D7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453772012.0000000002D7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D7E000
|
Size: |
8192
|
|
837E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1468884961.000000000837E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
837E000
|
Size: |
8192
|
|
4CF2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506238207.0000000004CF2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CF2000
|
Size: |
143360
|
|
6B31000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395098614.0000000006B31000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6B31000
|
Size: |
8192
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1492184419.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
51B9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490698055.00000000051B9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
51B9000
|
Size: |
724992
|
|
2DD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453818625.0000000002DD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DD0000
|
Size: |
4096
|
|
335F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507418968.000000000335F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
335F000
|
Size: |
4096
|
|
5B12000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412167626.0000000005B12000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B12000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6B25000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395098614.0000000006B25000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6B25000
|
Size: |
16384
|
|
3D1C000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3832025820.0000000003D1C000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3D1C000
|
Size: |
24576
|
|
3084000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1484795355.0000000003084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3084000
|
Size: |
4096
|
|
360B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393898800.000000000360B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
360B000
|
Size: |
4096
|
|
4A80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454423688.0000000004A80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4A80000
|
Size: |
4096
|
|
3628000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393564509.0000000003628000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3628000
|
Size: |
8192
|
|
722C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1399605406.000000000722C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
722C000
|
Size: |
16384
|
|
7360000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1464551335.0000000007360000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7360000
|
Size: |
20480
|
|
3578000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397468580.0000000003578000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3578000
|
Size: |
36864
|
|
2AD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453419928.0000000002AD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AD0000
|
Size: |
20480
|
|
2FE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1486515922.0000000002FE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FE0000
|
Size: |
24576
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496591970.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496505033.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
4D6F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1487364207.0000000004D6F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D6F000
|
Size: |
4096
|
|
5FBF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1399368607.0000000005FBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5FBF000
|
Size: |
4096
|
|
3E12000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3832852176.0000000003E12000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3E12000
|
Size: |
8192
|
|
35A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393320147.00000000035A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35A2000
|
Size: |
57344
|
|
2AC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419451051.0000000002AC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AC3000
|
Size: |
8192
|
|
35ED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1392133583.00000000035ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35ED000
|
Size: |
24576
|
|
3175000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507309918.0000000003175000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3175000
|
Size: |
28672
|
|
362C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398107677.000000000362C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
362C000
|
Size: |
8192
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491366177.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
4CBC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1498753378.0000000004CBC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CBC000
|
Size: |
20480
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1493609372.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
5B2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412138748.0000000005B2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B2F000
|
Size: |
53248
|
|
4CC1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506089987.0000000004CC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC1000
|
Size: |
57344
|
|
7670000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1466227724.0000000007670000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7670000
|
Size: |
65536
|
|
2E10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453836507.0000000002E10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E10000
|
Size: |
8192
|
|
2A49000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1417596371.0000000002A49000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A49000
|
Size: |
16384
|
|
2A9F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416011136.0000000002A9F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A9F000
|
Size: |
118784
|
|
2CEC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419643403.0000000002CEC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CEC000
|
Size: |
12288
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494326858.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
2BAF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453457219.0000000002BAF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2BAF000
|
Size: |
262144
|
|
2E80000
|
heap
|
page readonly
|
|
|
|
Name: |
00000005.00000002.1454072269.0000000002E80000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
2E80000
|
Size: |
4096
|
|
35A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1397685625.00000000035A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35A2000
|
Size: |
57344
|
|
4CC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1505060950.0000000004CC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC3000
|
Size: |
49152
|
|
311E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1487372845.000000000311E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
311E000
|
Size: |
8192
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494035954.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
5B2A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1412476327.0000000005B2A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B2A000
|
Size: |
20480
|
|
2AFA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453457219.0000000002AFA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AFA000
|
Size: |
155648
|
|
F9E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3830123677.0000000000F9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F9E000
|
Size: |
8192
|
|
58C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398830770.00000000058C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
58C0000
|
Size: |
4096
|
|
F93000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3830123677.0000000000F93000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F93000
|
Size: |
4096
|
|
4CD3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1500392922.0000000004CD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD3000
|
Size: |
16384
|
|
2CFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1453721553.0000000002CFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2CFE000
|
Size: |
8192
|
|
4CD5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497429696.0000000004CD5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD5000
|
Size: |
86016
|
|
376E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398274506.000000000376E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
376E000
|
Size: |
8192
|
|
365A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393235855.000000000365A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
365A000
|
Size: |
86016
|
|
4CD3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506137636.0000000004CD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD3000
|
Size: |
28672
|
|
2A70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419423781.0000000002A70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A70000
|
Size: |
45056
|
|
4CED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507756873.0000000004CED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CED000
|
Size: |
20480
|
|
73E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1399546233.000000000073E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
73E000
|
Size: |
8192
|
|
362F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398136528.000000000362F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
362F000
|
Size: |
69632
|
|
7F000000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1487062614.000000007F000000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7F000000
|
Size: |
4096
|
|
3084000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1485355047.0000000003084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3084000
|
Size: |
4096
|
|
45CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419683010.00000000045CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
45CE000
|
Size: |
8192
|
|
828000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1399636748.0000000000828000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
828000
|
Size: |
40960
|
|
6A3B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1396013905.0000000006A3B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A3B000
|
Size: |
4096
|
|
4D51000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1506365709.0000000004D51000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D51000
|
Size: |
151552
|
|
35D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395294992.00000000035D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35D5000
|
Size: |
49152
|
|
364F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398178631.000000000364F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
364F000
|
Size: |
16384
|
|
3363000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1483915860.0000000003363000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3363000
|
Size: |
8192
|
|
5C3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398925140.0000000005C3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5C3E000
|
Size: |
8192
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507668158.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
8192
|
|
35E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1392133583.00000000035E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35E3000
|
Size: |
32768
|
|
557F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1508038377.000000000557F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
557F000
|
Size: |
4096
|
|
2E4A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1453988706.0000000002E4A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2E4A000
|
Size: |
4096
|
|
6B60000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1463393995.0000000006B60000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
6B60000
|
Size: |
12288
|
|
2A9F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419451051.0000000002A9F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A9F000
|
Size: |
118784
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
595E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415908342.000000000595E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
595E000
|
Size: |
4096
|
|
2A2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416714730.0000000002A2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A2F000
|
Size: |
32768
|
|
60FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1399412334.00000000060FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60FE000
|
Size: |
8192
|
|
4CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496089678.0000000004CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB1000
|
Size: |
90112
|
|
6B35000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395098614.0000000006B35000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6B35000
|
Size: |
8192
|
|
4A40000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1454386290.0000000004A40000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
4A40000
|
Size: |
4096
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497034981.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
4E00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416321792.0000000004E00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E00000
|
Size: |
4096
|
|
6BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394943038.0000000006BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6BD0000
|
Size: |
8192
|
|
3980000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1398416684.0000000003980000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3980000
|
Size: |
20480
|
|
F10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3829845640.0000000000F10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F10000
|
Size: |
28672
|
|
4DE2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004DE2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DE2000
|
Size: |
20480
|
|
3607000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1395480325.0000000003607000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3607000
|
Size: |
8192
|
|
4DBE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004DBE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DBE000
|
Size: |
40960
|
|
4CD3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1504725265.0000000004CD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD3000
|
Size: |
28672
|
|
4F6C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420107123.0000000004F6C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F6C000
|
Size: |
16384
|
|
4EDD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454440882.0000000004EDD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4EDD000
|
Size: |
221184
|
|
2A4D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415349360.0000000002A4D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A4D000
|
Size: |
323584
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
4CB9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1501818595.0000000004CB9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB9000
|
Size: |
32768
|
|
35F9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1392133583.00000000035F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35F9000
|
Size: |
69632
|
|
362A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393067688.000000000362A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
362A000
|
Size: |
147456
|
|
4CFD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1499554603.0000000004CFD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CFD000
|
Size: |
110592
|
|
4CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496278669.0000000004CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB1000
|
Size: |
45056
|
|
96F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1486573822.00000000096F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
96F0000
|
Size: |
4096
|
|
2720000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1418802753.0000000002720000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2720000
|
Size: |
4096
|
|
4CEA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496360688.0000000004CEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CEA000
|
Size: |
16384
|
|
4DBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420063693.0000000004DBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4DBE000
|
Size: |
8192
|
|
3D4B000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3832537828.0000000003D4B000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3D4B000
|
Size: |
36864
|
|
8160000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1468697759.0000000008160000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8160000
|
Size: |
4096
|
|
6BDB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394943038.0000000006BDB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6BDB000
|
Size: |
4096
|
|
5942000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415908342.0000000005942000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5942000
|
Size: |
12288
|
|
4CC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490809973.0000000004CC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC0000
|
Size: |
8192
|
|
4CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1490380463.0000000004CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB1000
|
Size: |
32768
|
|
30F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3831302646.00000000030F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F0000
|
Size: |
4096
|
|
4CB6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507568647.0000000004CB6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB6000
|
Size: |
12288
|
|
4CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495613237.0000000004CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB1000
|
Size: |
36864
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1493717995.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|
34C9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507546960.00000000034C9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
34C9000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found strings which match to known social media urls |
Networking |
|
URLs found in memory or binary data |
Networking |
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1496802695.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
139264
|
|
3160000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1487530212.0000000003160000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3160000
|
Size: |
24576
|
|
29C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1399372389.000000000029C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
29C000
|
Size: |
16384
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495536940.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
16384
|
|
6EFB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463872838.0000000006EFB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6EFB000
|
Size: |
20480
|
|
362C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393564509.000000000362C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
362C000
|
Size: |
81920
|
|
3084000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1485788236.0000000003084000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3084000
|
Size: |
4096
|
|
4FC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416364586.0000000004FC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4FC0000
|
Size: |
4096
|
|
740B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1464551335.000000000740B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
740B000
|
Size: |
28672
|
|
45E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419732653.00000000045E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
45E0000
|
Size: |
4096
|
|
35ED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1393145079.00000000035ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35ED000
|
Size: |
24576
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497833873.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
36864
|
|
96FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1486573822.00000000096FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
96FC000
|
Size: |
4096
|
|
2E97000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454090133.0000000002E97000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E97000
|
Size: |
12288
|
|
2AC6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1419451051.0000000002AC6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AC6000
|
Size: |
102400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
3045000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491118970.0000000003045000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3045000
|
Size: |
4096
|
|
4CDA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1497659294.0000000004CDA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CDA000
|
Size: |
4096
|
|
3044000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491576052.0000000003044000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
8192
|
|
5600000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494437622.0000000005600000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5600000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454053188.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
4096
|
|
283E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1418834858.000000000283E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
283E000
|
Size: |
8192
|
|
400000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1486569287.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
106496
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found strings which match to known social media urls |
Networking |
|
URLs found in memory or binary data |
Networking |
|
|
29E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3830992206.00000000029E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29E0000
|
Size: |
16384
|
|
7330000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1399662459.0000000007330000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7330000
|
Size: |
28672
|
|
336C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1483915860.000000000336C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
336C000
|
Size: |
4096
|
|
3045000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491234821.0000000003045000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3045000
|
Size: |
4096
|
|
7630000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1465952389.0000000007630000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7630000
|
Size: |
65536
|
|
6A2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1394737314.0000000006A2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A2F000
|
Size: |
4096
|
|
4CC1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1505060950.0000000004CC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC1000
|
Size: |
4096
|
|
4CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495753795.0000000004CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD1000
|
Size: |
16384
|
|
2D7C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507100698.0000000002D7C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D7C000
|
Size: |
16384
|
|
4CEE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1498162299.0000000004CEE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CEE000
|
Size: |
61440
|
|
4CB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1507568647.0000000004CB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CB0000
|
Size: |
16384
|
|
73BB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1464551335.00000000073BB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
73BB000
|
Size: |
266240
|
|
5110000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1416190055.0000000005110000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5110000
|
Size: |
4096
|
|
598D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1420473590.000000000598D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
598D000
|
Size: |
4096
|
|
3045000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1491256079.0000000003045000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3045000
|
Size: |
4096
|
|
4CDA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1504958324.0000000004CDA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CDA000
|
Size: |
45056
|
|
4CF2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1499824437.0000000004CF2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CF2000
|
Size: |
45056
|
|
2A9F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1415656383.0000000002A9F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A9F000
|
Size: |
118784
|
|
7600000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1465761523.0000000007600000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7600000
|
Size: |
61440
|
|
2A6F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1417537972.0000000002A6F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A6F000
|
Size: |
49152
|
|
3D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1399491145.00000000003D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3D0000
|
Size: |
4096
|
|
4CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1495670894.0000000004CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCE000
|
Size: |
4096
|
|
4CC5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1504567762.0000000004CC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CC5000
|
Size: |
40960
|
|
2EB6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1454125827.0000000002EB6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EB6000
|
Size: |
40960
|
|
364F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1392133583.000000000364F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
364F000
|
Size: |
16384
|
|
6B0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1463300989.0000000006B0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6B0E000
|
Size: |
8192
|
|
340000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.1399417206.0000000000340000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
340000
|
Size: |
4096
|
|
5281000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1494583558.0000000005281000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5281000
|
Size: |
4096
|
|