5710000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
0000000C.00000002.3666779868.0000000005710000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5710000
|
Size: |
299008
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3F50000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.1425846454.0000000003F50000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3F50000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
4F10000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
0000000B.00000002.3664924343.0000000004F10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4F10000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
400000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.1420312107.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
290816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
4EC0000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
0000000B.00000002.3664866008.0000000004EC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4EC0000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3FA0000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.1425884986.0000000003FA0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3FA0000
|
Size: |
2654208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
25D0000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000009.00000002.3664817618.00000000025D0000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
25D0000
|
Size: |
2654208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3220000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
0000000B.00000002.3663223364.0000000003220000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
3220000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
57D7000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.3666779868.00000000057D7000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
57D7000
|
Size: |
8192
|
|
13A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1491971522.00000000013A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13A0000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1594809091.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
956000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1190908840.0000000000956000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
956000
|
Size: |
729088
|
|
3D2D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1424280577.0000000003D2D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3D2D000
|
Size: |
458752
|
|
3338000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.0000000003338000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3338000
|
Size: |
61440
|
|
8595000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.0000000008595000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8595000
|
Size: |
20480
|
|
3B9E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1332437774.0000000003B9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3B9E000
|
Size: |
24576
|
|
16191E72000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1712906374.0000016191E72000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16191E72000
|
Size: |
4096
|
|
16191E40000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1712906374.0000016191E40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16191E40000
|
Size: |
24576
|
|
FF0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1491756635.0000000000FF0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FF0000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598883115.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
33AE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.00000000033AE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33AE000
|
Size: |
8192
|
|
16191CCD000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.1712824409.0000016191CCD000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
16191CCD000
|
Size: |
8192
|
|
3669000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1203694946.0000000003669000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3669000
|
Size: |
4096
|
|
8521000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1606205047.0000000008521000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8521000
|
Size: |
4096
|
|
16191E76000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1712906374.0000016191E76000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16191E76000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599060229.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597423419.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
67E2000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3665802951.00000000067E2000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
67E2000
|
Size: |
4096
|
|
36A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1346667856.000000000036A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
36A000
|
Size: |
24576
|
|
334E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1423911123.000000000334E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
334E000
|
Size: |
20480
|
|
4B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1346712825.00000000004B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4B0000
|
Size: |
4096
|
|
2FF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1422924763.0000000002FF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF0000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598441547.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1594653768.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597087476.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
1951000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1492069900.0000000001951000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1951000
|
Size: |
380928
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
5C1000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000C.00000000.1491555396.00000000005C1000.00000020.00000001.01000000.00000007.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
5C1000
|
Size: |
57344
|
|
942000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1193642270.0000000000942000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
942000
|
Size: |
118784
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599352422.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
512A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1426469265.000000000512A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
512A000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
37A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3664793960.00000000037A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
37A0000
|
Size: |
16384
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595700344.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
3350000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1201571321.0000000003350000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3350000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1332939439.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
266240
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596122073.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
3349000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.0000000003349000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3349000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
33A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1202639691.00000000033A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33A0000
|
Size: |
1187840
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1593921427.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
36C4000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3665096491.00000000036C4000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
36C4000
|
Size: |
4096
|
|
34C3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1203526211.00000000034C3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
34C3000
|
Size: |
507904
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
E40000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000002.3663384268.0000000000E40000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E40000
|
Size: |
4096
|
|
16191E47000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1712906374.0000016191E47000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16191E47000
|
Size: |
86016
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1343443925.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
16193AC4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1663057777.0000016193AC4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16193AC4000
|
Size: |
24576
|
|
2374000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1347016000.0000000002374000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2374000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595431752.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
2F10000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1492163713.0000000002F10000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2F10000
|
Size: |
925696
|
|
50D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1438386398.00000000050D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
50D0000
|
Size: |
176128
|
|
60C09FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1712809025.00000060C09FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60C09FE000
|
Size: |
8192
|
|
341B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1388900042.000000000341B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
341B000
|
Size: |
139264
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3F42000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1424280577.0000000003F42000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3F42000
|
Size: |
40960
|
|
52C8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1426469265.00000000052C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52C8000
|
Size: |
24576
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598334714.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
2370000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1347016000.0000000002370000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2370000
|
Size: |
8192
|
|
42A7000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1425884986.00000000042A7000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
42A7000
|
Size: |
6955008
|
|
856B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.000000000856B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
856B000
|
Size: |
4096
|
|
5D9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3663798395.00000000005D9000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5D9000
|
Size: |
61440
|
|
33CE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.00000000033CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33CE000
|
Size: |
8192
|
|
3B2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1332437774.0000000003B2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3B2D000
|
Size: |
458752
|
|
3473000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1202192706.0000000003473000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3473000
|
Size: |
507904
|
|
8513000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599632989.0000000008513000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8513000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596420181.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
2EA0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3664815661.0000000002EA0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2EA0000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596369149.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595644396.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595226600.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
5CF000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1491580006.00000000005CF000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5CF000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
30C2000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3665096491.00000000030C2000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
30C2000
|
Size: |
4096
|
|
15C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000002.3664649622.00000000015C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
15C0000
|
Size: |
36864
|
|
85A4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.00000000085A4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
85A4000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
384F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1423883986.000000000384F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
384F000
|
Size: |
4096
|
|
33A1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1600868346.00000000033A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33A1000
|
Size: |
4096
|
|
942000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1193527850.0000000000942000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
942000
|
Size: |
118784
|
|
8B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1346875963.00000000008B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8B0000
|
Size: |
16384
|
|
DFF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1189741178.0000000000DFF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
DFF000
|
Size: |
147456
|
|
5CF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3663704781.00000000005CF000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5CF000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596146653.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
3F50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1343353718.0000000003F50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F50000
|
Size: |
188416
|
|
8D0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664052076.00000000008D0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8D0000
|
Size: |
4096
|
|
16193903000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1713102661.0000016193903000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16193903000
|
Size: |
16384
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1593893417.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3663488455.00000000004D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4D0000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598028271.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
33FF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.00000000033FF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33FF000
|
Size: |
12288
|
|
3501000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1423246588.0000000003501000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3501000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597834671.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
3800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1330876090.0000000003800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3800000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3347000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1423176757.0000000003347000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3347000
|
Size: |
28672
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1594871283.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
16191E80000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1713028878.0000016191E80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16191E80000
|
Size: |
8192
|
|
361D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1201257470.000000000361D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
361D000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595671048.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
9A9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1190588100.00000000009A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A9000
|
Size: |
4096
|
|
11C32000
|
system
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1711286037.0000000011C32000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
11C32000
|
Size: |
4096
|
|
33C2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1604401529.00000000033C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33C2000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
1390000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000002.3664150636.0000000001390000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1390000
|
Size: |
16384
|
|
16193900000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1713088937.0000016193900000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16193900000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596214002.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598665866.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
3E9E000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3665096491.0000000003E9E000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3E9E000
|
Size: |
4096
|
|
7FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1205086274.00000000007FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7FC000
|
Size: |
16384
|
|
3300000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663444716.0000000003300000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3300000
|
Size: |
4096
|
|
1200000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1491771748.0000000001200000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1200000
|
Size: |
4096
|
|
942000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1205744727.0000000000942000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
942000
|
Size: |
118784
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1337242477.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
258048
|
|
D20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1206274663.0000000000D20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D20000
|
Size: |
8192
|
|
300000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1346648633.0000000000300000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
300000
|
Size: |
4096
|
|
5D6000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3663222025.00000000005D6000.00000004.00000001.01000000.00000007.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5D6000
|
Size: |
8192
|
|
5C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000002.3663021359.00000000005C0000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5C0000
|
Size: |
4096
|
|
6008000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3665802951.0000000006008000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
6008000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599033746.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
A2E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1194602133.0000000000A2E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A2E000
|
Size: |
471040
|
|
16193921000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1713102661.0000016193921000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16193921000
|
Size: |
4096
|
|
13A4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1491971522.00000000013A4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13A4000
|
Size: |
4096
|
|
853D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1606205047.000000000853D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
853D000
|
Size: |
8192
|
|
3710000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1336581654.0000000003710000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3710000
|
Size: |
188416
|
|
3352000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1423176757.0000000003352000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3352000
|
Size: |
24576
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599086962.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599323172.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
D70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1206395783.0000000000D70000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
D70000
|
Size: |
4096
|
|
966000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1193527850.0000000000966000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
966000
|
Size: |
16384
|
|
8544000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.0000000008544000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8544000
|
Size: |
45056
|
|
8569000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.0000000008569000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8569000
|
Size: |
4096
|
|
3A00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1332437774.0000000003A00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3A00000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2E9F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1492125131.0000000002E9F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E9F000
|
Size: |
4096
|
|
E2E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1206705484.0000000000E2E000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
E2E000
|
Size: |
36864
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1340923668.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
E30000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1491654963.0000000000E30000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E30000
|
Size: |
4096
|
|
EBA000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3663490099.0000000000EBA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EBA000
|
Size: |
24576
|
|
1CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1204842921.00000000001CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CE000
|
Size: |
8192
|
|
841000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3663911319.0000000000841000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
841000
|
Size: |
12288
|
|
A09000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1206094105.0000000000A09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A09000
|
Size: |
151552
|
|
D71000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.1206459064.0000000000D71000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
D71000
|
Size: |
581632
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598983310.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
64BE000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3665802951.00000000064BE000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
64BE000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597456219.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
EBA000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1491711321.0000000000EBA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EBA000
|
Size: |
24576
|
|
2D9E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1492108289.0000000002D9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D9E000
|
Size: |
8192
|
|
91C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1191642845.000000000091C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91C000
|
Size: |
258048
|
|
5F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3663854957.00000000005F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5F0000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1343516824.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1332874727.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
53FD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3665348862.00000000053FD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
53FD000
|
Size: |
458752
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595076128.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
366D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1202955655.000000000366D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
366D000
|
Size: |
458752
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1594904809.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
3330000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.0000000003330000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3330000
|
Size: |
24576
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1343637486.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
3417000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1331084196.0000000003417000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3417000
|
Size: |
20480
|
|
1210000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000002.3663760915.0000000001210000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1210000
|
Size: |
4096
|
|
E37000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1206742589.0000000000E37000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E37000
|
Size: |
409600
|
|
DFF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1206579755.0000000000DFF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
DFF000
|
Size: |
147456
|
|
2EC4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1206817864.0000000002EC4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EC4000
|
Size: |
8192
|
|
6B06000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3665802951.0000000006B06000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
6B06000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1337014696.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
E32000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1189879705.0000000000E32000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
E32000
|
Size: |
8192
|
|
33AA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1600868346.00000000033AA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33AA000
|
Size: |
12288
|
|
1200000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000002.3663708082.0000000001200000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1200000
|
Size: |
4096
|
|
E40000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1491671000.0000000000E40000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E40000
|
Size: |
4096
|
|
33D3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.00000000033D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33D3000
|
Size: |
12288
|
|
16191D60000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1712889423.0000016191D60000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16191D60000
|
Size: |
4096
|
|
13E9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3664344965.00000000013E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13E9000
|
Size: |
90112
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
4C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3663435057.00000000004C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C0000
|
Size: |
20480
|
|
361D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1201702637.000000000361D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
361D000
|
Size: |
458752
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595017802.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
5CF000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000002.3663187230.00000000005CF000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5CF000
|
Size: |
28672
|
|
28D7000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.3664817618.00000000028D7000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
28D7000
|
Size: |
6955008
|
|
D30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1206342922.0000000000D30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D30000
|
Size: |
4096
|
|
FBC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1491738271.0000000000FBC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FBC000
|
Size: |
16384
|
|
16193680000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1662449192.0000016193680000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16193680000
|
Size: |
4096
|
|
3352000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1423764425.0000000003352000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3352000
|
Size: |
24576
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598478230.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
4D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1346746060.00000000004D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4D0000
|
Size: |
4096
|
|
23D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664627616.00000000023D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23D0000
|
Size: |
8192
|
|
3669000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1204234183.0000000003669000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3669000
|
Size: |
4096
|
|
8B8E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667999137.0000000008B8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8B8E000
|
Size: |
8192
|
|
1619390F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1713102661.000001619390F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1619390F000
|
Size: |
8192
|
|
1230000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3663875528.0000000001230000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1230000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1594231073.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595791553.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1608390905.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
34F0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1202318293.00000000034F0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
34F0000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599234914.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
4DC0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3664820158.0000000004DC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC0000
|
Size: |
4096
|
|
2EA0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1492138741.0000000002EA0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2EA0000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599772065.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1440904513.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
241664
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597653135.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
559D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3665348862.000000000559D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
559D000
|
Size: |
4096
|
|
3540000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1202955655.0000000003540000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3540000
|
Size: |
1196032
|
|
859B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.000000000859B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
859B000
|
Size: |
20480
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598591999.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
4A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3663328882.00000000004A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4A0000
|
Size: |
4096
|
|
1220000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1491871921.0000000001220000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1220000
|
Size: |
4096
|
|
3404000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.0000000003404000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3404000
|
Size: |
12288
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597396699.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
581C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3666944204.000000000581C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
581C000
|
Size: |
16384
|
|
39E8000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3665096491.00000000039E8000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39E8000
|
Size: |
8192
|
|
1361000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1491932423.0000000001361000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1361000
|
Size: |
12288
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595885471.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1343726744.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
266240
|
|
8520000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.0000000008520000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8520000
|
Size: |
4096
|
|
33F9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.00000000033F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33F9000
|
Size: |
12288
|
|
E81000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1346978178.0000000000E81000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E81000
|
Size: |
380928
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
3850000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1423913856.0000000003850000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3850000
|
Size: |
274432
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596096206.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
366D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1204234183.000000000366D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
366D000
|
Size: |
458752
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596551087.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
5783000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.3666779868.0000000005783000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5783000
|
Size: |
4096
|
|
2F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3663127803.00000000002F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2F0000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597273305.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
114B000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3663642251.000000000114B000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
114B000
|
Size: |
4096
|
|
E30000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000002.3663330735.0000000000E30000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E30000
|
Size: |
4096
|
|
4678000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3665096491.0000000004678000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4678000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
32F4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1431747748.00000000032F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32F4000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597327209.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599188620.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
3473000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1201571321.0000000003473000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3473000
|
Size: |
507904
|
|
5622000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3665802951.0000000005622000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5622000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596932409.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
18E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1204799420.000000000018E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
18E000
|
Size: |
8192
|
|
E24000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1206579755.0000000000E24000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E24000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
3352000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1424301022.0000000003352000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3352000
|
Size: |
24576
|
|
1370000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3664095112.0000000001370000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1370000
|
Size: |
4096
|
|
16193680000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1661850723.0000016193680000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16193680000
|
Size: |
4096
|
|
3002000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3665096491.0000000003002000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3002000
|
Size: |
4096
|
|
AF0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3664369272.0000000000AF0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AF0000
|
Size: |
36864
|
|
E2E000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1189879705.0000000000E2E000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
E2E000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597699967.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
16191CCA000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.1712824409.0000016191CCA000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
16191CCA000
|
Size: |
8192
|
|
8530000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.0000000008530000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8530000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597035904.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595254584.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
340A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.000000000340A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
340A000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599992912.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
44E6000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3665096491.00000000044E6000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
44E6000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598796323.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
5D6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1346799051.00000000005D6000.00000004.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5D6000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596334498.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
32F4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1431728381.00000000032F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32F4000
|
Size: |
4096
|
|
8FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1346915281.00000000008FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
90112
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596498875.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598115676.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
16191E60000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1712906374.0000016191E60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16191E60000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595730503.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596837500.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
8538000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1606205047.0000000008538000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8538000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596070980.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1594711754.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1332759559.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
591C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3666965414.000000000591C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
591C000
|
Size: |
16384
|
|
3620000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1423274277.0000000003620000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3620000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597542573.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
8AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1346864779.00000000008AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8AE000
|
Size: |
8192
|
|
38EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1424099896.00000000038EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
38EE000
|
Size: |
8192
|
|
AEF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1346954581.0000000000AEF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AEF000
|
Size: |
4096
|
|
16193AA6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1663087803.0000016193AA6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16193AA6000
|
Size: |
4096
|
|
518E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3665245845.000000000518E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
518E000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596900341.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
33D1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.00000000033D1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33D1000
|
Size: |
4096
|
|
5CF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1346788657.00000000005CF000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5CF000
|
Size: |
28672
|
|
33DB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.00000000033DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33DB000
|
Size: |
4096
|
|
3349000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1423881529.0000000003349000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3349000
|
Size: |
36864
|
|
16193916000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1713102661.0000016193916000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16193916000
|
Size: |
8192
|
|
E81000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3664418443.0000000000E81000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E81000
|
Size: |
380928
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
33B8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.00000000033B8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33B8000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
3358000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.0000000003358000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3358000
|
Size: |
188416
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5C1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000009.00000002.3663644492.00000000005C1000.00000020.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
5C1000
|
Size: |
57344
|
|
90F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1193527850.000000000090F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
90F000
|
Size: |
172032
|
|
16193912000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1713102661.0000016193912000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16193912000
|
Size: |
8192
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1341026026.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
3619000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1201257470.0000000003619000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3619000
|
Size: |
4096
|
|
5F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1346823155.00000000005F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5F0000
|
Size: |
4096
|
|
90F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1191338663.000000000090F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
90F000
|
Size: |
86016
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597590198.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
56E2000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3665802951.00000000056E2000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
56E2000
|
Size: |
4096
|
|
5E76000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3665802951.0000000005E76000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5E76000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1431677781.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
241664
|
|
3391000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1600748500.0000000003391000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3391000
|
Size: |
4096
|
|
341A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1388978857.000000000341A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
341A000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1332819922.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
131072
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599485470.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
989000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1205921075.0000000000989000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
989000
|
Size: |
520192
|
|
13CA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3664344965.00000000013CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13CA000
|
Size: |
8192
|
|
13A4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3664211768.00000000013A4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13A4000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595174901.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
3300000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1206942113.0000000003300000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3300000
|
Size: |
290816
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1608531515.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
2EC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1206817864.0000000002EC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EC0000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596643279.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
916000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1194652287.0000000000916000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
916000
|
Size: |
65536
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595399576.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595336719.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1594683198.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1333021362.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
258048
|
|
5020000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3665062381.0000000005020000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5020000
|
Size: |
94208
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1341330691.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
258048
|
|
343E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1388900042.000000000343E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
343E000
|
Size: |
8192
|
|
4F70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3665007305.0000000004F70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4F70000
|
Size: |
94208
|
|
2F00000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1492150649.0000000002F00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F00000
|
Size: |
8192
|
|
3396000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1600748500.0000000003396000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3396000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1608322603.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
423F000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1425884986.000000000423F000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
423F000
|
Size: |
4096
|
|
2FF8000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663168625.0000000002FF8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FF8000
|
Size: |
32768
|
|
8F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1346915281.00000000008F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F0000
|
Size: |
32768
|
|
16193800000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1713075233.0000016193800000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16193800000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1594934141.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
632C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3665802951.000000000632C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
632C000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597964132.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
3700000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1423325230.0000000003700000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3700000
|
Size: |
4096
|
|
8290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667456160.0000000008290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8290000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
966000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1193642270.0000000000966000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
966000
|
Size: |
16384
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598306806.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
841000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1346843785.0000000000841000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
841000
|
Size: |
12288
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1594838986.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596446690.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
50D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1493502202.00000000050D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
50D0000
|
Size: |
176128
|
|
24E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1347066771.00000000024E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
24E0000
|
Size: |
925696
|
|
853A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.000000000853A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
853A000
|
Size: |
8192
|
|
368E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1202318293.000000000368E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
368E000
|
Size: |
24576
|
|
942000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1194652287.0000000000942000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
942000
|
Size: |
118784
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1594581429.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
3358000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1423145235.0000000003358000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3358000
|
Size: |
20480
|
|
33AA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.00000000033AA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33AA000
|
Size: |
12288
|
|
15BF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1492044056.00000000015BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15BF000
|
Size: |
4096
|
|
2370000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664549797.0000000002370000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2370000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598166969.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
8592000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.0000000008592000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8592000
|
Size: |
8192
|
|
8FA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1346915281.00000000008FA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FA000
|
Size: |
8192
|
|
3405000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1331129516.0000000003405000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3405000
|
Size: |
49152
|
|
509A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1421604729.000000000509A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
509A000
|
Size: |
512000
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597366019.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
1210000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1491785832.0000000001210000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1210000
|
Size: |
4096
|
|
D9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1204597335.00000000000D9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D9000
|
Size: |
28672
|
|
3619000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1202318293.0000000003619000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3619000
|
Size: |
4096
|
|
3540000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1203694946.0000000003540000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3540000
|
Size: |
1196032
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598279033.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
53F9000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3665348862.00000000053F9000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
53F9000
|
Size: |
4096
|
|
300000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3663170537.0000000000300000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
300000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599264078.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
2EC0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3664894069.0000000002EC0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2EC0000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1594989777.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
33A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1203991453.00000000033A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33A0000
|
Size: |
1187840
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598857682.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
374E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1423768878.000000000374E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
374E000
|
Size: |
8192
|
|
34C3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1203991453.00000000034C3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
34C3000
|
Size: |
507904
|
|
514E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3665180829.000000000514E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
514E000
|
Size: |
8192
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1343845296.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
258048
|
|
2F5C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1422677718.0000000002F5C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F5C000
|
Size: |
16384
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597765455.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595616543.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
34F0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1201257470.00000000034F0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
34F0000
|
Size: |
1196032
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599008325.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
135E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1491918336.000000000135E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
135E000
|
Size: |
8192
|
|
334D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1423271549.000000000334D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
334D000
|
Size: |
4096
|
|
11D4C000
|
system
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1711286037.0000000011D4C000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
11D4C000
|
Size: |
4096
|
|
33BD000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1604401529.00000000033BD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33BD000
|
Size: |
8192
|
|
2F00000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3664921669.0000000002F00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F00000
|
Size: |
12288
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596472564.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
1246000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3663936008.0000000001246000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1246000
|
Size: |
8192
|
|
3352000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1423271549.0000000003352000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3352000
|
Size: |
24576
|
|
5D6000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1491599710.00000000005D6000.00000004.00000001.01000000.00000007.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5D6000
|
Size: |
8192
|
|
83E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1346833514.000000000083E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83E000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598830273.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
8535000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.0000000008535000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8535000
|
Size: |
8192
|
|
36DE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1204234183.00000000036DE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36DE000
|
Size: |
24576
|
|
23D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1347043168.00000000023D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23D0000
|
Size: |
8192
|
|
16193680000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1661897061.0000016193680000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16193680000
|
Size: |
4096
|
|
3D9E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1424280577.0000000003D9E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3D9E000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
13CE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3664344965.00000000013CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13CE000
|
Size: |
94208
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595368566.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
966000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1194652287.0000000000966000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
966000
|
Size: |
16384
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596779314.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
2F10000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000002.3664951916.0000000002F10000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2F10000
|
Size: |
925696
|
|
916000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1205744727.0000000000916000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
916000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599141614.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597501789.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598222678.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1608571967.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
2374000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664549797.0000000002374000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2374000
|
Size: |
4096
|
|
366D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1203694946.000000000366D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
366D000
|
Size: |
458752
|
|
3002000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1492232105.0000000003002000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3002000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597895616.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1608456127.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
8588000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.0000000008588000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8588000
|
Size: |
12288
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598908287.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
852B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1606205047.000000000852B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
852B000
|
Size: |
8192
|
|
90A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1205430241.000000000090A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
90A000
|
Size: |
16384
|
|
3923000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1330876090.0000000003923000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3923000
|
Size: |
507904
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1593816827.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
24E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3664671080.00000000024E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
24E0000
|
Size: |
925696
|
|
4F60000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3664979968.0000000004F60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F60000
|
Size: |
4096
|
|
3F50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1340805182.0000000003F50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F50000
|
Size: |
188416
|
|
850000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3663937198.0000000000850000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
850000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595561966.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
33C8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1604401529.00000000033C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33C8000
|
Size: |
4096
|
|
13A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3664211768.00000000013A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13A0000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596699475.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1341233916.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
266240
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1337157531.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
266240
|
|
8B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3663992015.00000000008B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8B0000
|
Size: |
16384
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598761317.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
2E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1346205189.00000000002E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2E0000
|
Size: |
4096
|
|
3ECD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1424280577.0000000003ECD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3ECD000
|
Size: |
4096
|
|
16193ACE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1663040389.0000016193ACE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16193ACE000
|
Size: |
4096
|
|
903000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1190988131.0000000000903000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
903000
|
Size: |
339968
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1440999698.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4F77000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1421604729.0000000004F77000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F77000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3C00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1424280577.0000000003C00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3C00000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
129F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1206783807.000000000129F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
129F000
|
Size: |
4096
|
|
60C01FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1712792878.00000060C01FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60C01FE000
|
Size: |
8192
|
|
855A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.000000000855A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
855A000
|
Size: |
12288
|
|
3F50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1388952006.0000000003F50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F50000
|
Size: |
188416
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598195061.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1593864605.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
1220000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3663816845.0000000001220000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1220000
|
Size: |
4096
|
|
3390000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.0000000003390000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3390000
|
Size: |
8192
|
|
5774000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.3666779868.0000000005774000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5774000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599384624.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
857F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.000000000857F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
857F000
|
Size: |
20480
|
|
34F0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1201702637.00000000034F0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
34F0000
|
Size: |
1196032
|
|
938000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664098402.0000000000938000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
938000
|
Size: |
16384
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596029142.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
989000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1190988131.0000000000989000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
989000
|
Size: |
520192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597244338.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3663387510.00000000004B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4B0000
|
Size: |
4096
|
|
3412000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1423171281.0000000003412000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3412000
|
Size: |
32768
|
|
3D0C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3665096491.0000000003D0C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3D0C000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598524186.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
1230000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1491889180.0000000001230000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1230000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1608363059.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
3202000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1422963861.0000000003202000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3202000
|
Size: |
20480
|
|
33A4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.00000000033A4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33A4000
|
Size: |
16384
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1431839128.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
8F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1190685661.00000000008F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F3000
|
Size: |
49152
|
|
36DE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1202955655.00000000036DE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36DE000
|
Size: |
24576
|
|
5D9000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1491638380.00000000005D9000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5D9000
|
Size: |
61440
|
|
334D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1424157386.000000000334D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
334D000
|
Size: |
4096
|
|
50D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1435978755.00000000050D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
50D0000
|
Size: |
176128
|
|
1D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1204942480.00000000001D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D0000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597936694.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
5780000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.3666779868.0000000005780000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5780000
|
Size: |
8192
|
|
3619000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1201702637.0000000003619000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3619000
|
Size: |
4096
|
|
98A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1190371946.000000000098A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
98A000
|
Size: |
131072
|
|
3358000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1424043962.0000000003358000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3358000
|
Size: |
20480
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598567260.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
34C3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1202639691.00000000034C3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
34C3000
|
Size: |
507904
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595534522.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
3400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1423086646.0000000003400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3400000
|
Size: |
45056
|
|
1619390A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1713102661.000001619390A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1619390A000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596670872.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
24DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1347056025.00000000024DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
24DF000
|
Size: |
4096
|
|
343E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1388992036.000000000343E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
343E000
|
Size: |
8192
|
|
3750000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1431217648.0000000003750000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3750000
|
Size: |
176128
|
|
6650000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3665802951.0000000006650000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
6650000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595760665.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
1951000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000002.3664706268.0000000001951000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1951000
|
Size: |
380928
|
|
5612000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3665348862.0000000005612000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
5612000
|
Size: |
40960
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595821809.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1336935955.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
361D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1202318293.000000000361D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
361D000
|
Size: |
458752
|
|
169E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1206801330.000000000169E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
169E000
|
Size: |
8192
|
|
3352000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1424096982.0000000003352000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3352000
|
Size: |
24576
|
|
3417000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1331147488.0000000003417000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3417000
|
Size: |
20480
|
|
5C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3663604136.00000000005C0000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5C0000
|
Size: |
4096
|
|
8D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1205430241.00000000008D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D0000
|
Size: |
24576
|
|
32F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663386102.00000000032F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32F0000
|
Size: |
16384
|
|
3669000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1202955655.0000000003669000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3669000
|
Size: |
4096
|
|
573C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3665802951.000000000573C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
573C000
|
Size: |
4096
|
|
546E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3665348862.000000000546E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
546E000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
32F4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1426705929.00000000032F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32F4000
|
Size: |
4096
|
|
1390000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1491957708.0000000001390000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1390000
|
Size: |
16384
|
|
5C1000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000C.00000002.3663130624.00000000005C1000.00000020.00000001.01000000.00000007.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
5C1000
|
Size: |
57344
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1594617667.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599165222.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
3D29000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1424280577.0000000003D29000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3D29000
|
Size: |
4096
|
|
368E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1201702637.000000000368E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
368E000
|
Size: |
24576
|
|
3350000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1201107015.0000000003350000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3350000
|
Size: |
1187840
|
|
16193660000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1713044643.0000016193660000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16193660000
|
Size: |
4096
|
|
368E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1201257470.000000000368E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
368E000
|
Size: |
24576
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598958175.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
E37000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1189997202.0000000000E37000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E37000
|
Size: |
409600
|
|
3856000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3665096491.0000000003856000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3856000
|
Size: |
4096
|
|
3540000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1204234183.0000000003540000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3540000
|
Size: |
1196032
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1337084539.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
4C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1346729740.00000000004C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C0000
|
Size: |
20480
|
|
5D9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1346808232.00000000005D9000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5D9000
|
Size: |
61440
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1594535539.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598250599.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599417697.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
5D9000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000002.3663279563.00000000005D9000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5D9000
|
Size: |
61440
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598729793.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
E50000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1491687171.0000000000E50000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E50000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595201096.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1341121098.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
36A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3663220207.000000000036A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
36A000
|
Size: |
24576
|
|
3352000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1424157386.0000000003352000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3352000
|
Size: |
24576
|
|
5257000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1426469265.0000000005257000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5257000
|
Size: |
458752
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596241779.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
3473000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1201107015.0000000003473000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3473000
|
Size: |
507904
|
|
902000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1190436109.0000000000902000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
902000
|
Size: |
557056
|
|
3ED1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1424280577.0000000003ED1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3ED1000
|
Size: |
458752
|
|
5764000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.3666779868.0000000005764000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5764000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597867469.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595588827.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
3750000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3664765334.0000000003750000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3750000
|
Size: |
4096
|
|
33F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.00000000033F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33F0000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596583235.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1594962188.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
3408000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.0000000003408000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3408000
|
Size: |
4096
|
|
8532000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1606205047.0000000008532000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8532000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595306983.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598697250.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
4030000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3665096491.0000000004030000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4030000
|
Size: |
8192
|
|
5C1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000009.00000000.1346777105.00000000005C1000.00000020.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
5C1000
|
Size: |
57344
|
|
5253000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1426469265.0000000005253000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5253000
|
Size: |
4096
|
|
7CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1205086274.00000000007CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7CE000
|
Size: |
8192
|
|
311C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3665096491.000000000311C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
311C000
|
Size: |
4096
|
|
E50000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000002.3663434378.0000000000E50000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E50000
|
Size: |
4096
|
|
55A1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3665348862.00000000055A1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
55A1000
|
Size: |
458752
|
|
4A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1346699383.00000000004A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4A0000
|
Size: |
4096
|
|
3390000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1600868346.0000000003390000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3390000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595146361.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
2E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3663006900.00000000002E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2E0000
|
Size: |
4096
|
|
D71000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1189517043.0000000000D71000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
D71000
|
Size: |
581632
|
|
16193790000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1713058570.0000016193790000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16193790000
|
Size: |
12288
|
|
1361000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000002.3664036240.0000000001361000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1361000
|
Size: |
12288
|
|
902000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1190685661.0000000000902000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
902000
|
Size: |
557056
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597167379.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
33B8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1600868346.00000000033B8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33B8000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
33A4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1600868346.00000000033A4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33A4000
|
Size: |
16384
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599292256.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
D70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1189478777.0000000000D70000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
D70000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598641779.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
90E000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1205671897.000000000090E000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
90E000
|
Size: |
16384
|
|
7BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1205086274.00000000007BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7BE000
|
Size: |
8192
|
|
13C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3664344965.00000000013C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13C0000
|
Size: |
32768
|
|
13CA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1491999558.00000000013CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13CA000
|
Size: |
8192
|
|
33E4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.00000000033E4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33E4000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
2FBB000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663018438.0000000002FBB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FBB000
|
Size: |
20480
|
|
3405000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1331065451.0000000003405000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3405000
|
Size: |
49152
|
|
5C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1491528485.00000000005C0000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5C0000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597122985.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
3B7A000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3665096491.0000000003B7A000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3B7A000
|
Size: |
4096
|
|
16191CA0000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.1712824409.0000016191CA0000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
16191CA0000
|
Size: |
114688
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596173889.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
11CF2000
|
system
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1711286037.0000000011CF2000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
11CF2000
|
Size: |
4096
|
|
619A000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3665802951.000000000619A000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
619A000
|
Size: |
4096
|
|
140000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1204678052.0000000000140000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
140000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595933177.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596612195.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
122F4000
|
system
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1711286037.00000000122F4000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
122F4000
|
Size: |
4096
|
|
342B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1388992036.000000000342B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
342B000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
6974000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3665802951.0000000006974000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
6974000
|
Size: |
8192
|
|
FBC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3663542978.0000000000FBC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FBC000
|
Size: |
16384
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596394693.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597299476.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
85B2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.00000000085B2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
85B2000
|
Size: |
32768
|
|
FF0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000002.3663600582.0000000000FF0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FF0000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596979639.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
1240000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3663936008.0000000001240000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1240000
|
Size: |
16384
|
|
33AE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1600868346.00000000033AE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33AE000
|
Size: |
8192
|
|
6C98000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3665802951.0000000006C98000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
6C98000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
36DE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1203694946.00000000036DE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36DE000
|
Size: |
24576
|
|
E24000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1189741178.0000000000E24000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E24000
|
Size: |
40960
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597007738.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
16191E79000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1712906374.0000016191E79000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16191E79000
|
Size: |
12288
|
|
33A1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.00000000033A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33A1000
|
Size: |
4096
|
|
1F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1205037216.00000000001F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F0000
|
Size: |
20480
|
|
858F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.000000000858F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
858F000
|
Size: |
4096
|
|
1240000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1491902151.0000000001240000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1240000
|
Size: |
20480
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595498928.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
8510000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667557307.0000000008510000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8510000
|
Size: |
4096
|
|
4E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3663544499.00000000004E0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E0000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595280757.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
5CE4000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3665802951.0000000005CE4000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5CE4000
|
Size: |
4096
|
|
966000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1205744727.0000000000966000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
966000
|
Size: |
16384
|
|
5C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1346767625.00000000005C0000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5C0000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1599114547.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
33A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1203526211.00000000033A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33A0000
|
Size: |
1187840
|
|
92A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1194652287.000000000092A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
92A000
|
Size: |
61440
|
|
8526000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1606205047.0000000008526000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8526000
|
Size: |
8192
|
|
60BF1FB000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1712752363.00000060BF1FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60BF1FB000
|
Size: |
20480
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1426684226.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
65536
|
|
4354000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3665096491.0000000004354000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4354000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595117626.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
968000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1193766638.0000000000968000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
968000
|
Size: |
8192
|
|
4E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1346756478.00000000004E0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E0000
|
Size: |
4096
|
|
AF0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1346966346.0000000000AF0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AF0000
|
Size: |
36864
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596525172.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596270794.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
13CE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1491999558.00000000013CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13CE000
|
Size: |
90112
|
|
32A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663328203.00000000032A0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32A0000
|
Size: |
4096
|
|
2FD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1422854715.0000000002FD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FD0000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598066803.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
8D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1205430241.00000000008D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D7000
|
Size: |
180224
|
|
3B29000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1332437774.0000000003B29000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3B29000
|
Size: |
4096
|
|
2F9A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1422832363.0000000002F9A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F9A000
|
Size: |
24576
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1597198304.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
8D0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1346888290.00000000008D0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8D0000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598616770.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
2F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1346235503.00000000002F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2F0000
|
Size: |
4096
|
|
341E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.000000000341E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
341E000
|
Size: |
40960
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1594496199.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
8620000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667977081.0000000008620000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8620000
|
Size: |
4096
|
|
575B000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.3666779868.000000000575B000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
575B000
|
Size: |
4096
|
|
3350000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1202192706.0000000003350000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3350000
|
Size: |
1187840
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1594463961.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
5D6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3663756179.00000000005D6000.00000004.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5D6000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596731401.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
46C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3663276193.000000000046C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
46C000
|
Size: |
16384
|
|
60BF9FD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1712776462.00000060BF9FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60BF9FD000
|
Size: |
12288
|
|
16193ABE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.1663057777.0000016193ABE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16193ABE000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1593985582.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
2EB0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3664864863.0000000002EB0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2EB0000
|
Size: |
12288
|
|
3A01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1424228756.0000000003A01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3A01000
|
Size: |
8192
|
|
15C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000C.00000000.1492056312.00000000015C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
15C0000
|
Size: |
36864
|
|
850000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1346855022.0000000000850000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
850000
|
Size: |
4096
|
|
8560000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.0000000008560000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8560000
|
Size: |
12288
|
|
3347000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1424096982.0000000003347000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3347000
|
Size: |
28672
|
|
13C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1491999558.00000000013C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13C0000
|
Size: |
32768
|
|
8FA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664098402.00000000008FA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FA000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1596299003.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
8565000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.0000000008565000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8565000
|
Size: |
12288
|
|
286F000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.3664817618.000000000286F000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
286F000
|
Size: |
4096
|
|
16193A01000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1713218692.0000016193A01000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16193A01000
|
Size: |
4096
|
|
1370000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000000.1491945320.0000000001370000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1370000
|
Size: |
4096
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595047648.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
39EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1424137179.00000000039EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
39EF000
|
Size: |
4096
|
|
7DB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1205086274.00000000007DB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7DB000
|
Size: |
20480
|
|
3200000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1422963861.0000000003200000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3200000
|
Size: |
4096
|
|
85A2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3667580696.00000000085A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
85A2000
|
Size: |
4096
|
|
46C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1346684420.000000000046C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
46C000
|
Size: |
16384
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598933601.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
52D0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3665348862.00000000052D0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
52D0000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1598000434.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
8BCF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3668021315.0000000008BCF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8BCF000
|
Size: |
4096
|
|
33D8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3663511619.00000000033D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33D8000
|
Size: |
8192
|
|
8F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664098402.00000000008F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F0000
|
Size: |
32768
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595467109.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
8192
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1595983695.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
8FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664098402.00000000008FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8FE000
|
Size: |
233472
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1608424769.0000000004DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC1000
|
Size: |
4096
|
|
41C2000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.3665096491.00000000041C2000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
41C2000
|
Size: |
4096
|
|