2EF1000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000000.00000002.1352896146.0000000002EF1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EF1000
|
Size: |
2629632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected XWorm |
Stealing of Sensitive Information, Remote Access Functionality |
|
Sample uses string decryption to hide its real strings |
AV Detection |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Yara signature match |
System Summary |
|
|
33CA000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000000.00000002.1352896146.00000000033CA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33CA000
|
Size: |
2031616
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected XWorm |
Stealing of Sensitive Information, Remote Access Functionality |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Yara signature match |
System Summary |
|
|
882000
|
unkown
|
page readonly
|
 |
|
|
Name: |
00000000.00000000.1293410990.0000000000882000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
882000
|
Size: |
2707456
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected PureLog Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
|
5B60000
|
trusted library section
|
page read and write
|
 |
|
|
Name: |
00000000.00000002.1371797489.0000000005B60000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
5B60000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected PureLog Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
|
402000
|
remote allocation
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.2544268428.0000000000402000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
402000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected XWorm |
Stealing of Sensitive Information, Remote Access Functionality |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Yara signature match |
System Summary |
|
|
2CE3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1790170775.0000000002CE3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CE3000
|
Size: |
8192
|
|
F00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1785366032.0000000000F00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F00000
|
Size: |
4096
|
|
1280000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1351825827.0000000001280000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1280000
|
Size: |
65536
|
|
1155000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624561583.0000000001155000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1155000
|
Size: |
8192
|
|
26C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1724042879.00000000026C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26C0000
|
Size: |
65536
|
|
2BE0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.1789998430.0000000002BE0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2BE0000
|
Size: |
4096
|
|
E6C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624147193.0000000000E6C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E6C000
|
Size: |
16384
|
|
558E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1791807285.000000000558E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
558E000
|
Size: |
8192
|
|
591E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1371683932.000000000591E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
591E000
|
Size: |
8192
|
|
14B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1626005642.00000000014B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14B0000
|
Size: |
8192
|
|
56CE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1791868640.00000000056CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
56CE000
|
Size: |
8192
|
|
146F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1625932778.000000000146F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
146F000
|
Size: |
4096
|
|
6250000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1579561012.0000000006250000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6250000
|
Size: |
12288
|
|
F57000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1785687055.0000000000F57000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F57000
|
Size: |
16384
|
|
1240000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351675467.0000000001240000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1240000
|
Size: |
4096
|
|
61E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559611087.00000000061E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
61E0000
|
Size: |
36864
|
|
27DE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1724315233.00000000027DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
27DE000
|
Size: |
8192
|
|
15B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1626969610.00000000015B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
15B0000
|
Size: |
16384
|
|
300B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1627403463.000000000300B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
300B000
|
Size: |
4096
|
|
1050000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546098653.0000000001050000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1050000
|
Size: |
4096
|
|
2CF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1790261442.0000000002CF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CF0000
|
Size: |
16384
|
|
2E3C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1627075086.0000000002E3C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E3C000
|
Size: |
16384
|
|
14F8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557307653.00000000014F8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
14F8000
|
Size: |
32768
|
|
135C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351847039.000000000135C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
135C000
|
Size: |
16384
|
|
571F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1371639613.000000000571F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
571F000
|
Size: |
4096
|
|
3BB1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2554842532.0000000003BB1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3BB1000
|
Size: |
20480
|
|
5A1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559236806.0000000005A1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A1E000
|
Size: |
8192
|
|
174F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557723476.000000000174F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
174F000
|
Size: |
4096
|
|
256D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1722939667.000000000256D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
256D000
|
Size: |
4096
|
|
47E8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1750368980.00000000047E8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
47E8000
|
Size: |
8192
|
|
541E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369463106.000000000541E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
541E000
|
Size: |
8192
|
|
5A8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1631211795.0000000005A8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A8E000
|
Size: |
8192
|
|
5C2C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1633707774.0000000005C2C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5C2C000
|
Size: |
16384
|
|
12B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624712284.00000000012B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12B3000
|
Size: |
53248
|
|
1054000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546138356.0000000001054000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1054000
|
Size: |
4096
|
|
14CD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1626167862.00000000014CD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14CD000
|
Size: |
4096
|
|
26D9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1724130442.00000000026D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
26D9000
|
Size: |
4096
|
|
57EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1630653727.00000000057EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
57EE000
|
Size: |
8192
|
|
3380000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1563068758.0000000003380000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3380000
|
Size: |
65536
|
|
50CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2556165246.00000000050CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
50CE000
|
Size: |
8192
|
|
53DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369436813.00000000053DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
53DE000
|
Size: |
8192
|
|
1270000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351812820.0000000001270000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1270000
|
Size: |
4096
|
|
52D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2557166601.00000000052D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52D0000
|
Size: |
8192
|
|
18A4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1559062361.00000000018A4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
18A4000
|
Size: |
4096
|
|
5D29000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1633863381.0000000005D29000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5D29000
|
Size: |
28672
|
|
2590000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1723178600.0000000002590000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2590000
|
Size: |
4096
|
|
5610000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1751112493.0000000005610000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5610000
|
Size: |
16384
|
|
14E7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1626336650.00000000014E7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14E7000
|
Size: |
4096
|
|
60D9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579305393.00000000060D9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D9000
|
Size: |
20480
|
|
61F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559611087.00000000061F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
61F0000
|
Size: |
32768
|
|
18F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1561714816.00000000018F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
18F0000
|
Size: |
4096
|
|
B05000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721553921.0000000000B05000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B05000
|
Size: |
12288
|
|
35BB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352896146.00000000035BB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
35BB000
|
Size: |
614400
|
|
14FB000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1626480106.00000000014FB000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14FB000
|
Size: |
4096
|
|
3EF1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1359226142.0000000003EF1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3EF1000
|
Size: |
491520
|
|
1814000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557742746.0000000001814000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1814000
|
Size: |
8192
|
|
1233000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351651974.0000000001233000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1233000
|
Size: |
40960
|
|
C68000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721701019.0000000000C68000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C68000
|
Size: |
184320
|
|
15A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1626813175.00000000015A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
15A0000
|
Size: |
20480
|
|
94B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2544417525.000000000094B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
94B000
|
Size: |
20480
|
|
9D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2544604091.00000000009D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D0000
|
Size: |
8192
|
|
10E5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351522221.00000000010E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10E5000
|
Size: |
12288
|
|
EF0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1722731501.0000000000EF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EF0000
|
Size: |
12288
|
|
D40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2544762997.0000000000D40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D40000
|
Size: |
4096
|
|
7F7B0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2559789266.000000007F7B0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7F7B0000
|
Size: |
4096
|
|
9C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2544502853.00000000009C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C0000
|
Size: |
16384
|
|
137B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351847039.000000000137B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
137B000
|
Size: |
81920
|
|
10C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1789610377.00000000010C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10C0000
|
Size: |
12288
|
|
12F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624712284.00000000012F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12F4000
|
Size: |
282624
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
5E89000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1372385279.0000000005E89000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5E89000
|
Size: |
28672
|
|
5BD6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1632170623.0000000005BD6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5BD6000
|
Size: |
12288
|
|
5E40000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1579224050.0000000005E40000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5E40000
|
Size: |
4096
|
|
1247000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1351707173.0000000001247000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1247000
|
Size: |
4096
|
|
6310000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1579599726.0000000006310000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6310000
|
Size: |
65536
|
|
2CBE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1790051617.0000000002CBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2CBE000
|
Size: |
8192
|
|
1822000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557742746.0000000001822000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1822000
|
Size: |
8192
|
|
29EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546638237.00000000029EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
29EE000
|
Size: |
8192
|
|
1210000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351570835.0000000001210000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1210000
|
Size: |
8192
|
|
7F480000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1635539453.000000007F480000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7F480000
|
Size: |
4096
|
|
5BD3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1632170623.0000000005BD3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5BD3000
|
Size: |
8192
|
|
2B5C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1789775930.0000000002B5C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B5C000
|
Size: |
16384
|
|
4418000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1578621437.0000000004418000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4418000
|
Size: |
4096
|
|
381F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1749698521.000000000381F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
381F000
|
Size: |
4096
|
|
400000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2544268428.0000000000400000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
4096
|
|
D3C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2544715513.0000000000D3C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D3C000
|
Size: |
16384
|
|
4A7F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1750459024.0000000004A7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4A7F000
|
Size: |
4096
|
|
12D8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1789700198.00000000012D8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
12D8000
|
Size: |
4096
|
|
F04000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1785461211.0000000000F04000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F04000
|
Size: |
4096
|
|
F9B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1785687055.0000000000F9B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F9B000
|
Size: |
208896
|
|
3399000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1563190937.0000000003399000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3399000
|
Size: |
4096
|
|
107E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351473935.000000000107E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
107E000
|
Size: |
8192
|
|
1348000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624712284.0000000001348000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1348000
|
Size: |
8192
|
|
5A9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559295572.0000000005A9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A9E000
|
Size: |
8192
|
|
27EC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1724367910.00000000027EC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27EC000
|
Size: |
16384
|
|
1890000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1558670867.0000000001890000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1890000
|
Size: |
8192
|
|
127E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624712284.000000000127E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
127E000
|
Size: |
106496
|
|
2976000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2546482035.0000000002976000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2976000
|
Size: |
8192
|
|
2960000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546353706.0000000002960000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2960000
|
Size: |
8192
|
|
2D68000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1627038033.0000000002D68000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D68000
|
Size: |
4096
|
|
5F10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1634887816.0000000005F10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F10000
|
Size: |
262144
|
|
2A50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546782869.0000000002A50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A50000
|
Size: |
65536
|
|
582E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1630695395.000000000582E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
582E000
|
Size: |
8192
|
|
5F9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579265161.0000000005F9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5F9E000
|
Size: |
8192
|
|
5600000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1751014124.0000000005600000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5600000
|
Size: |
4096
|
|
1060000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546180215.0000000001060000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1060000
|
Size: |
16384
|
|
10B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1789523528.00000000010B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10B0000
|
Size: |
65536
|
|
3F88000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1359226142.0000000003F88000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3F88000
|
Size: |
1654784
|
|
2963000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546376221.0000000002963000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2963000
|
Size: |
40960
|
|
43DF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1578621437.00000000043DF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
43DF000
|
Size: |
4096
|
|
15A7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1626813175.00000000015A7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
15A7000
|
Size: |
12288
|
|
5D80000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1372338172.0000000005D80000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5D80000
|
Size: |
65536
|
|
AE0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721472419.0000000000AE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AE0000
|
Size: |
16384
|
|
D6E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1784863954.0000000000D6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D6E000
|
Size: |
8192
|
|
1570000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557412152.0000000001570000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1570000
|
Size: |
16384
|
|
1590000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1626813175.0000000001590000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1590000
|
Size: |
4096
|
|
1510000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1626526217.0000000001510000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1510000
|
Size: |
4096
|
|
B00000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721553921.0000000000B00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B00000
|
Size: |
16384
|
|
EBE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1785152930.0000000000EBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EBE000
|
Size: |
8192
|
|
3390000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1563190937.0000000003390000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3390000
|
Size: |
20480
|
|
1270000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624712284.0000000001270000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1270000
|
Size: |
24576
|
|
14F7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1626449582.00000000014F7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14F7000
|
Size: |
4096
|
|
3330000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1562398622.0000000003330000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
3330000
|
Size: |
4096
|
|
5760000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1751240590.0000000005760000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5760000
|
Size: |
4096
|
|
7F740000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1751799847.000000007F740000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7F740000
|
Size: |
4096
|
|
5A5D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559265226.0000000005A5D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A5D000
|
Size: |
12288
|
|
4ECE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1750552724.0000000004ECE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4ECE000
|
Size: |
8192
|
|
26D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1724130442.00000000026D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
26D0000
|
Size: |
20480
|
|
14C4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1626130327.00000000014C4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14C4000
|
Size: |
4096
|
|
589B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1578957529.000000000589B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
589B000
|
Size: |
8192
|
|
2CC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1790079707.0000000002CC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CC0000
|
Size: |
4096
|
|
CE5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721701019.0000000000CE5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE5000
|
Size: |
282624
|
|
1310000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351847039.0000000001310000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1310000
|
Size: |
278528
|
|
27E1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1724367910.00000000027E1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27E1000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
FE3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1785687055.0000000000FE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FE3000
|
Size: |
24576
|
|
A00000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721438711.0000000000A00000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A00000
|
Size: |
4096
|
|
D68000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2544794400.0000000000D68000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D68000
|
Size: |
86016
|
|
188E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1558648415.000000000188E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
188E000
|
Size: |
8192
|
|
5897000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1578957529.0000000005897000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5897000
|
Size: |
12288
|
|
5B5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1371775306.0000000005B5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5B5E000
|
Size: |
8192
|
|
2970000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546440275.0000000002970000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2970000
|
Size: |
4096
|
|
2F5F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1627231388.0000000002F5F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F5F000
|
Size: |
4096
|
|
4159000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1629162678.0000000004159000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4159000
|
Size: |
196608
|
|
5BC9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1631264119.0000000005BC9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5BC9000
|
Size: |
20480
|
|
1838000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557742746.0000000001838000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1838000
|
Size: |
4096
|
|
14E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1626294566.00000000014E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14E0000
|
Size: |
4096
|
|
54A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1370836193.00000000054A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
54A0000
|
Size: |
32768
|
|
B18000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1293706814.0000000000B18000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B18000
|
Size: |
274432
|
|
5F90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1372548254.0000000005F90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F90000
|
Size: |
28672
|
|
2BDE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1789967957.0000000002BDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2BDE000
|
Size: |
8192
|
|
1053000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2546119744.0000000001053000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1053000
|
Size: |
4096
|
|
1020000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1789220159.0000000001020000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1020000
|
Size: |
4096
|
|
1037000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.1789327110.0000000001037000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1037000
|
Size: |
4096
|
|
26B7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1723728185.00000000026B7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26B7000
|
Size: |
12288
|
|
53E9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2557927955.00000000053E9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
53E9000
|
Size: |
28672
|
|
F0D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.1785536780.0000000000F0D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
F0D000
|
Size: |
4096
|
|
8E4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1351296193.00000000008E4000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8E4000
|
Size: |
4096
|
|
57F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559156143.00000000057F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57F0000
|
Size: |
4096
|
|
3FD8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1629162678.0000000003FD8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3FD8000
|
Size: |
4096
|
|
5890000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1578957529.0000000005890000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5890000
|
Size: |
20480
|
|
1030000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351458561.0000000001030000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1030000
|
Size: |
8192
|
|
CF7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2544633751.0000000000CF7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CF7000
|
Size: |
36864
|
|
54D0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1371164599.00000000054D0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
54D0000
|
Size: |
4096
|
|
EF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1785300865.0000000000EF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
EF0000
|
Size: |
8192
|
|
12D1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351847039.00000000012D1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12D1000
|
Size: |
151552
|
|
2EBB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1790412616.0000000002EBB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EBB000
|
Size: |
4096
|
|
FD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624251178.0000000000FD0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FD0000
|
Size: |
4096
|
|
613C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579465588.000000000613C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
613C000
|
Size: |
16384
|
|
133A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624712284.000000000133A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
133A000
|
Size: |
28672
|
|
61DD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559576655.00000000061DD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61DD000
|
Size: |
12288
|
|
5A80000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1792056715.0000000005A80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A80000
|
Size: |
4096
|
|
5460000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1369554874.0000000005460000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5460000
|
Size: |
4096
|
|
2EBD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1790412616.0000000002EBD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EBD000
|
Size: |
32768
|
|
2E50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1627120504.0000000002E50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E50000
|
Size: |
20480
|
|
25FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1723327385.00000000025FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
25FE000
|
Size: |
8192
|
|
2E11000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1790412616.0000000002E11000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E11000
|
Size: |
692224
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
510C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2556483096.000000000510C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
510C000
|
Size: |
16384
|
|
2CE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1790170775.0000000002CE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CE0000
|
Size: |
4096
|
|
5940000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1751709513.0000000005940000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5940000
|
Size: |
32768
|
|
5E5D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559476338.0000000005E5D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5E5D000
|
Size: |
12288
|
|
D20000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1784293770.0000000000D20000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D20000
|
Size: |
4096
|
|
2AA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546997782.0000000002AA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AA0000
|
Size: |
4096
|
|
F4A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1785687055.0000000000F4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F4A000
|
Size: |
16384
|
|
10B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624307707.00000000010B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10B0000
|
Size: |
8192
|
|
1040000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546073064.0000000001040000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1040000
|
Size: |
8192
|
|
54C0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1371093941.00000000054C0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
54C0000
|
Size: |
24576
|
|
5489000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369591960.0000000005489000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5489000
|
Size: |
24576
|
|
5E10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1634361396.0000000005E10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5E10000
|
Size: |
20480
|
|
1560000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1626585693.0000000001560000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1560000
|
Size: |
65536
|
|
18CA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1561470584.00000000018CA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
18CA000
|
Size: |
4096
|
|
1A80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1562297908.0000000001A80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A80000
|
Size: |
16384
|
|
5BE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1633370256.0000000005BE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5BE0000
|
Size: |
16384
|
|
9BC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1781350681.00000000009BC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9BC000
|
Size: |
16384
|
|
882000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1351296193.0000000000882000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
882000
|
Size: |
360448
|
|
5D5C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559438448.0000000005D5C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5D5C000
|
Size: |
16384
|
|
F55000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1785687055.0000000000F55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F55000
|
Size: |
4096
|
|
2A4C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546748009.0000000002A4C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A4C000
|
Size: |
16384
|
|
5E3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579201353.0000000005E3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5E3E000
|
Size: |
8192
|
|
59DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559206679.00000000059DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59DE000
|
Size: |
8192
|
|
F28000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1785687055.0000000000F28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F28000
|
Size: |
86016
|
|
2E59000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1627120504.0000000002E59000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E59000
|
Size: |
4096
|
|
18C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1561239761.00000000018C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
18C0000
|
Size: |
4096
|
|
5A5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1371748231.0000000005A5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A5E000
|
Size: |
8192
|
|
125F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624688086.000000000125F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
125F000
|
Size: |
4096
|
|
129E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351847039.000000000129E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
129E000
|
Size: |
151552
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
2EEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352814065.0000000002EEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2EEE000
|
Size: |
8192
|
|
12A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624712284.00000000012A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12A6000
|
Size: |
12288
|
|
1140000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624410315.0000000001140000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1140000
|
Size: |
12288
|
|
5AF0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1579112622.0000000005AF0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5AF0000
|
Size: |
4096
|
|
60F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579436901.00000000060F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60F0000
|
Size: |
16384
|
|
5830000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1751304440.0000000005830000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5830000
|
Size: |
65536
|
|
18B3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1560872425.00000000018B3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
18B3000
|
Size: |
40960
|
|
55A0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1630510711.00000000055A0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
55A0000
|
Size: |
4096
|
|
5D3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579181092.0000000005D3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5D3E000
|
Size: |
8192
|
|
10AC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546242355.00000000010AC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10AC000
|
Size: |
16384
|
|
FCF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1785687055.0000000000FCF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FCF000
|
Size: |
69632
|
|
4D4D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2555884377.0000000004D4D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D4D000
|
Size: |
12288
|
|
798000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721379875.0000000000798000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
798000
|
Size: |
32768
|
|
2D07000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1790297566.0000000002D07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D07000
|
Size: |
4096
|
|
1252000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351766350.0000000001252000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1252000
|
Size: |
4096
|
|
2CE6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1790170775.0000000002CE6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CE6000
|
Size: |
12288
|
|
5B60000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1792233633.0000000005B60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B60000
|
Size: |
262144
|
|
2A60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546873788.0000000002A60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A60000
|
Size: |
57344
|
|
13CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352139424.00000000013CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13CE000
|
Size: |
8192
|
|
598E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1631174364.000000000598E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
598E000
|
Size: |
8192
|
|
3E88000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1791205395.0000000003E88000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E88000
|
Size: |
4096
|
|
53CE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1750917191.00000000053CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
53CE000
|
Size: |
8192
|
|
3F61000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1629162678.0000000003F61000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3F61000
|
Size: |
20480
|
|
60E6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579356845.00000000060E6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60E6000
|
Size: |
12288
|
|
193E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1561763130.000000000193E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
193E000
|
Size: |
8192
|
|
56EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1630607875.00000000056EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
56EE000
|
Size: |
8192
|
|
D70000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1784902113.0000000000D70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D70000
|
Size: |
8192
|
|
10BD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351491331.00000000010BD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10BD000
|
Size: |
12288
|
|
18DB000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1561642345.00000000018DB000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
18DB000
|
Size: |
4096
|
|
54CE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1750958302.00000000054CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
54CE000
|
Size: |
8192
|
|
5BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1632170623.0000000005BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5BD0000
|
Size: |
4096
|
|
2CD0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.1790141021.0000000002CD0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2CD0000
|
Size: |
4096
|
|
2560000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1722844725.0000000002560000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2560000
|
Size: |
4096
|
|
1356000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351847039.0000000001356000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1356000
|
Size: |
12288
|
|
EC0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1785260649.0000000000EC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EC0000
|
Size: |
4096
|
|
57AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559110228.00000000057AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
57AE000
|
Size: |
8192
|
|
298B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2546593359.000000000298B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
298B000
|
Size: |
4096
|
|
DFA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2544794400.0000000000DFA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DFA000
|
Size: |
282624
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
7FD80000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.1792571708.000000007FD80000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FD80000
|
Size: |
4096
|
|
29F0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2546663790.00000000029F0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
29F0000
|
Size: |
40960
|
|
39D9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1749698521.00000000039D9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
39D9000
|
Size: |
196608
|
|
2980000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546529195.0000000002980000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2980000
|
Size: |
4096
|
|
5ADE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559324193.0000000005ADE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5ADE000
|
Size: |
8192
|
|
B4E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721636627.0000000000B4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B4E000
|
Size: |
8192
|
|
5480000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369591960.0000000005480000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5480000
|
Size: |
4096
|
|
1066000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546180215.0000000001066000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1066000
|
Size: |
8192
|
|
553E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1578933494.000000000553E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
553E000
|
Size: |
8192
|
|
53A8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1578907131.00000000053A8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53A8000
|
Size: |
8192
|
|
69C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721265112.000000000069C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
69C000
|
Size: |
16384
|
|
CF8000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1784005756.0000000000CF8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CF8000
|
Size: |
32768
|
|
2B70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1789823263.0000000002B70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B70000
|
Size: |
20480
|
|
332E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1562344897.000000000332E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
332E000
|
Size: |
8192
|
|
2587000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1723101812.0000000002587000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2587000
|
Size: |
4096
|
|
F03000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.1785427081.0000000000F03000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
F03000
|
Size: |
4096
|
|
2640000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1723490390.0000000002640000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2640000
|
Size: |
4096
|
|
103B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.1789350600.000000000103B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
103B000
|
Size: |
4096
|
|
13D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352293372.00000000013D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D0000
|
Size: |
20480
|
|
AF0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721516453.0000000000AF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AF0000
|
Size: |
8192
|
|
18AD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1560815242.00000000018AD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
18AD000
|
Size: |
4096
|
|
2CC9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1790079707.0000000002CC9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CC9000
|
Size: |
20480
|
|
29A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546614438.00000000029A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29A0000
|
Size: |
4096
|
|
CD6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721701019.0000000000CD6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD6000
|
Size: |
57344
|
|
5606000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1751014124.0000000005606000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5606000
|
Size: |
12288
|
|
183A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557742746.000000000183A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
183A000
|
Size: |
69632
|
|
1050000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1789374709.0000000001050000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1050000
|
Size: |
4096
|
|
4EF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1750670724.0000000004EF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4EF0000
|
Size: |
4096
|
|
5759000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1751192633.0000000005759000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5759000
|
Size: |
28672
|
|
10B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546280511.00000000010B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10B0000
|
Size: |
16384
|
|
2563000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1722870566.0000000002563000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2563000
|
Size: |
4096
|
|
2BAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2547016052.0000000002BAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2BAE000
|
Size: |
8192
|
|
153E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557354323.000000000153E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
153E000
|
Size: |
8192
|
|
268E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1723546046.000000000268E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
268E000
|
Size: |
8192
|
|
D2B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721701019.0000000000D2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D2B000
|
Size: |
20480
|
|
5B5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559381864.0000000005B5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5B5E000
|
Size: |
8192
|
|
105D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2546160918.000000000105D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
105D000
|
Size: |
4096
|
|
1440000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352426841.0000000001440000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1440000
|
Size: |
16384
|
|
17CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557742746.00000000017CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17CE000
|
Size: |
282624
|
|
542E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2558524168.000000000542E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
542E000
|
Size: |
8192
|
|
3878000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1749698521.0000000003878000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3878000
|
Size: |
4096
|
|
C60000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721701019.0000000000C60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C60000
|
Size: |
24576
|
|
C97000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721701019.0000000000C97000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C97000
|
Size: |
229376
|
|
14D3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1626226011.00000000014D3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14D3000
|
Size: |
40960
|
|
3FF8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1629162678.0000000003FF8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3FF8000
|
Size: |
4096
|
|
1250000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351745631.0000000001250000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1250000
|
Size: |
4096
|
|
12CF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1789677538.00000000012CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12CF000
|
Size: |
4096
|
|
F13000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1785619379.0000000000F13000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F13000
|
Size: |
40960
|
|
2DA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352548315.0000000002DA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DA0000
|
Size: |
53248
|
|
11EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351554949.00000000011EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
11EF000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1631137759.0000000005930000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5930000
|
Size: |
4096
|
|
4EF9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1750670724.0000000004EF9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4EF9000
|
Size: |
20480
|
|
1A60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1562219773.0000000001A60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A60000
|
Size: |
4096
|
|
556E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2558966288.000000000556E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
556E000
|
Size: |
8192
|
|
124A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1351727843.000000000124A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
124A000
|
Size: |
4096
|
|
102A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.1789274609.000000000102A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
102A000
|
Size: |
4096
|
|
5B50000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.1792118267.0000000005B50000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5B50000
|
Size: |
65536
|
|
18A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1558698443.00000000018A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
18A0000
|
Size: |
4096
|
|
5F9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559550027.0000000005F9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5F9E000
|
Size: |
8192
|
|
1027000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.1789246611.0000000001027000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1027000
|
Size: |
4096
|
|
5800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559178177.0000000005800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5800000
|
Size: |
8192
|
|
1290000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351847039.0000000001290000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1290000
|
Size: |
49152
|
|
141C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352333101.000000000141C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
141C000
|
Size: |
16384
|
|
2D09000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1790297566.0000000002D09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D09000
|
Size: |
4096
|
|
570E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1791898147.000000000570E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
570E000
|
Size: |
8192
|
|
DA0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1784987939.0000000000DA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA0000
|
Size: |
16384
|
|
1470000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1625969497.0000000001470000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1470000
|
Size: |
4096
|
|
1575000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557412152.0000000001575000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1575000
|
Size: |
12288
|
|
6320000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579686395.0000000006320000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6320000
|
Size: |
266240
|
|
F5C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1785687055.0000000000F5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F5C000
|
Size: |
253952
|
|
2B77000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1789823263.0000000002B77000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B77000
|
Size: |
12288
|
|
3EA8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1791205395.0000000003EA8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3EA8000
|
Size: |
4096
|
|
D60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2544794400.0000000000D60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D60000
|
Size: |
28672
|
|
18A3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1559033037.00000000018A3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
18A3000
|
Size: |
4096
|
|
56AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1630563007.00000000056AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
56AE000
|
Size: |
8192
|
|
3BB9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2554842532.0000000003BB9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3BB9000
|
Size: |
118784
|
|
2580000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1723039805.0000000002580000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2580000
|
Size: |
4096
|
|
F20000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1785687055.0000000000F20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F20000
|
Size: |
24576
|
|
D3C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721701019.0000000000D3C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3C000
|
Size: |
12288
|
|
11CF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1789646349.00000000011CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
11CF000
|
Size: |
4096
|
|
54B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1371045056.00000000054B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
54B0000
|
Size: |
4096
|
|
538F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1750884945.000000000538F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
538F000
|
Size: |
4096
|
|
12C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624712284.00000000012C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12C1000
|
Size: |
200704
|
|
2E57000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1627120504.0000000002E57000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E57000
|
Size: |
4096
|
|
592E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1630818395.000000000592E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
592E000
|
Size: |
8192
|
|
5AAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579067149.0000000005AAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5AAE000
|
Size: |
8192
|
|
5D30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1633996318.0000000005D30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D30000
|
Size: |
4096
|
|
3858000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1749698521.0000000003858000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3858000
|
Size: |
4096
|
|
1580000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1626767463.0000000001580000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1580000
|
Size: |
4096
|
|
1030000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1789301471.0000000001030000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1030000
|
Size: |
4096
|
|
1758000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557742746.0000000001758000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1758000
|
Size: |
16384
|
|
2690000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1723653010.0000000002690000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2690000
|
Size: |
65536
|
|
4FEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369097883.0000000004FEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4FEE000
|
Size: |
8192
|
|
113E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624375621.000000000113E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
113E000
|
Size: |
8192
|
|
5E9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579244017.0000000005E9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5E9E000
|
Size: |
8192
|
|
2972000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546460686.0000000002972000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2972000
|
Size: |
4096
|
|
7FD10000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1580027790.000000007FD10000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FD10000
|
Size: |
4096
|
|
337C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1562876267.000000000337C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
337C000
|
Size: |
16384
|
|
548F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1791780120.000000000548F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
548F000
|
Size: |
4096
|
|
2CF8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352519435.0000000002CF8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CF8000
|
Size: |
8192
|
|
154E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352486117.000000000154E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
154E000
|
Size: |
8192
|
|
2D00000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1790297566.0000000002D00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D00000
|
Size: |
20480
|
|
1818000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557742746.0000000001818000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1818000
|
Size: |
4096
|
|
1570000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1626680628.0000000001570000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1570000
|
Size: |
65536
|
|
18C7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1561374279.00000000018C7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
18C7000
|
Size: |
4096
|
|
10FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624341599.00000000010FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10FE000
|
Size: |
8192
|
|
55CE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1791839559.00000000055CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
55CE000
|
Size: |
8192
|
|
3EE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1791205395.0000000003EE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3EE0000
|
Size: |
4096
|
|
5A90000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.1792083324.0000000005A90000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5A90000
|
Size: |
12288
|
|
4470000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1578621437.0000000004470000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4470000
|
Size: |
4096
|
|
2D90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352548315.0000000002D90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D90000
|
Size: |
4096
|
|
4009000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1791205395.0000000004009000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4009000
|
Size: |
192512
|
|
109E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1789403115.000000000109E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
109E000
|
Size: |
8192
|
|
1940000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1561853491.0000000001940000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1940000
|
Size: |
65536
|
|
1150000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624561583.0000000001150000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1150000
|
Size: |
16384
|
|
12B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624712284.00000000012B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12B0000
|
Size: |
4096
|
|
2F61000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1627403463.0000000002F61000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F61000
|
Size: |
692224
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
566E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559054867.000000000566E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
566E000
|
Size: |
8192
|
|
258A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1723150739.000000000258A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
258A000
|
Size: |
4096
|
|
300D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1627403463.000000000300D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
300D000
|
Size: |
49152
|
|
57D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559137401.00000000057D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57D0000
|
Size: |
4096
|
|
14C3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1626095343.00000000014C3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14C3000
|
Size: |
4096
|
|
9B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2544472210.00000000009B0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9B0000
|
Size: |
4096
|
|
1257000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1351783372.0000000001257000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1257000
|
Size: |
4096
|
|
38B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1749698521.00000000038B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
38B0000
|
Size: |
4096
|
|
BEC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351402824.0000000000BEC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BEC000
|
Size: |
16384
|
|
26A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1723728185.00000000026A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26A0000
|
Size: |
4096
|
|
1008000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1785687055.0000000001008000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1008000
|
Size: |
28672
|
|
117C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557169366.000000000117C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
117C000
|
Size: |
16384
|
|
1370000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1789730663.0000000001370000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1370000
|
Size: |
16384
|
|
1791000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557742746.0000000001791000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1791000
|
Size: |
245760
|
|
2B60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1789823263.0000000002B60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B60000
|
Size: |
4096
|
|
1278000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624712284.0000000001278000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1278000
|
Size: |
16384
|
|
2A00000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2546725486.0000000002A00000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2A00000
|
Size: |
4096
|
|
597C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1791969145.000000000597C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
597C000
|
Size: |
16384
|
|
E4E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2544794400.0000000000E4E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E4E000
|
Size: |
36864
|
|
D5B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721701019.0000000000D5B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D5B000
|
Size: |
16384
|
|
5CFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579156117.0000000005CFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5CFE000
|
Size: |
8192
|
|
4ED0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1750604883.0000000004ED0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
4ED0000
|
Size: |
4096
|
|
3E11000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1791205395.0000000003E11000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E11000
|
Size: |
20480
|
|
10D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351507159.00000000010D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10D0000
|
Size: |
12288
|
|
60E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579356845.00000000060E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60E0000
|
Size: |
4096
|
|
595C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1371715282.000000000595C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
595C000
|
Size: |
16384
|
|
F3E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1785687055.0000000000F3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F3E000
|
Size: |
45056
|
|
11F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557270689.00000000011F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11F0000
|
Size: |
8192
|
|
1420000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352406962.0000000001420000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1420000
|
Size: |
4096
|
|
1785000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557742746.0000000001785000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1785000
|
Size: |
45056
|
|
4F0E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1791741612.0000000004F0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F0E000
|
Size: |
8192
|
|
2DB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352637723.0000000002DB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DB0000
|
Size: |
65536
|
|
D89000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2544794400.0000000000D89000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D89000
|
Size: |
16384
|
|
2A70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546951728.0000000002A70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A70000
|
Size: |
4096
|
|
25B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1723270992.00000000025B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
25B0000
|
Size: |
4096
|
|
505D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1630377844.000000000505D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
505D000
|
Size: |
12288
|
|
1299000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624712284.0000000001299000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1299000
|
Size: |
49152
|
|
2DE0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1352711944.0000000002DE0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2DE0000
|
Size: |
4096
|
|
2564000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1722911486.0000000002564000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2564000
|
Size: |
4096
|
|
5C5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559409721.0000000005C5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5C5E000
|
Size: |
8192
|
|
528E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1750850078.000000000528E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
528E000
|
Size: |
8192
|
|
497D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1750405109.000000000497D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
497D000
|
Size: |
12288
|
|
125B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1351800185.000000000125B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
125B000
|
Size: |
4096
|
|
1223000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1351605022.0000000001223000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1223000
|
Size: |
4096
|
|
2BB1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2547039696.0000000002BB1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BB1000
|
Size: |
192512
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1220000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351583656.0000000001220000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1220000
|
Size: |
4096
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579305393.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
4096
|
|
880000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1293394141.0000000000880000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
880000
|
Size: |
4096
|
|
D94000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2544794400.0000000000D94000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D94000
|
Size: |
4096
|
|
263C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1723445936.000000000263C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
263C000
|
Size: |
16384
|
|
11E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557240381.00000000011E0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11E0000
|
Size: |
4096
|
|
1242000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351692565.0000000001242000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1242000
|
Size: |
4096
|
|
2A73000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546951728.0000000002A73000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A73000
|
Size: |
8192
|
|
5BFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579131912.0000000005BFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5BFF000
|
Size: |
4096
|
|
14F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1626419666.00000000014F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14F0000
|
Size: |
4096
|
|
559E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1630479437.000000000559E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
559E000
|
Size: |
8192
|
|
3397000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1563190937.0000000003397000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3397000
|
Size: |
4096
|
|
13BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546328888.00000000013BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13BE000
|
Size: |
8192
|
|
D51000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721701019.0000000000D51000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D51000
|
Size: |
36864
|
|
26D7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1724130442.00000000026D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
26D7000
|
Size: |
4096
|
|
155E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1626553881.000000000155E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
155E000
|
Size: |
8192
|
|
175E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557742746.000000000175E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
175E000
|
Size: |
155648
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
27F1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1724367910.00000000027F1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27F1000
|
Size: |
7827456
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2C00000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.1790025350.0000000002C00000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2C00000
|
Size: |
4096
|
|
EF8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351420585.0000000000EF8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EF8000
|
Size: |
32768
|
|
5E90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1372415355.0000000005E90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5E90000
|
Size: |
278528
|
|
552E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2558835170.000000000552E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
552E000
|
Size: |
8192
|
|
259B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1723243398.000000000259B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
259B000
|
Size: |
4096
|
|
18D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1561524706.00000000018D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
18D0000
|
Size: |
4096
|
|
1950000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1562069495.0000000001950000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1950000
|
Size: |
12288
|
|
565C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1751155214.000000000565C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
565C000
|
Size: |
16384
|
|
4BB8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2555568591.0000000004BB8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4BB8000
|
Size: |
4096
|
|
4599000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1578621437.0000000004599000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4599000
|
Size: |
200704
|
|
297A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2546508670.000000000297A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
297A000
|
Size: |
4096
|
|
581E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1371659973.000000000581E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
581E000
|
Size: |
8192
|
|
545E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1369510211.000000000545E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
545E000
|
Size: |
8192
|
|
1750000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1557742746.0000000001750000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1750000
|
Size: |
24576
|
|
26B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1723728185.00000000026B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26B0000
|
Size: |
20480
|
|
5770000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1751272874.0000000005770000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5770000
|
Size: |
12288
|
|
5A79000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1792006407.0000000005A79000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A79000
|
Size: |
28672
|
|
2520000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1722772766.0000000002520000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2520000
|
Size: |
4096
|
|
26BB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1723728185.00000000026BB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26BB000
|
Size: |
8192
|
|
2E0F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1790392700.0000000002E0F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E0F000
|
Size: |
4096
|
|
D96000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2544794400.0000000000D96000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D96000
|
Size: |
405504
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
14EA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1626372174.00000000014EA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14EA000
|
Size: |
4096
|
|
10A0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.1789433709.00000000010A0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
10A0000
|
Size: |
65536
|
|
122D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1351634782.000000000122D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
122D000
|
Size: |
4096
|
|
3174000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352896146.0000000003174000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3174000
|
Size: |
2445312
|
|
14C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1626043829.00000000014C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14C0000
|
Size: |
4096
|
|
33A1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1564775056.00000000033A1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33A1000
|
Size: |
7942144
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
15AB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1626813175.00000000015AB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
15AB000
|
Size: |
8192
|
|
F68000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624189252.0000000000F68000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F68000
|
Size: |
32768
|
|
4030000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1629162678.0000000004030000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4030000
|
Size: |
4096
|
|
37E1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1749698521.00000000037E1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37E1000
|
Size: |
20480
|
|
2BE1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2547039696.0000000002BE1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BE1000
|
Size: |
5427200
|
|
52E0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2557565082.00000000052E0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
52E0000
|
Size: |
4096
|
|
524E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1750815221.000000000524E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
524E000
|
Size: |
8192
|
|
12C4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351847039.00000000012C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12C4000
|
Size: |
49152
|
|
5E00000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1634254439.0000000005E00000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5E00000
|
Size: |
65536
|
|
2B7B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1789823263.0000000002B7B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B7B000
|
Size: |
8192
|
|
2550000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1722799043.0000000002550000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2550000
|
Size: |
8192
|
|
F50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351440163.0000000000F50000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F50000
|
Size: |
4096
|
|
63DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559734093.00000000063DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63DE000
|
Size: |
8192
|
|
56AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559082309.00000000056AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
56AE000
|
Size: |
8192
|
|
1224000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351620705.0000000001224000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1224000
|
Size: |
4096
|
|
DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1784987939.0000000000DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA5000
|
Size: |
12288
|
|
2573000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1722978770.0000000002573000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2573000
|
Size: |
40960
|
|
52CD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2556725224.00000000052CD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52CD000
|
Size: |
12288
|
|
18D7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.1561602713.00000000018D7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
18D7000
|
Size: |
4096
|
|
6239000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579495328.0000000006239000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6239000
|
Size: |
28672
|
|
1A5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1562168691.0000000001A5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1A5E000
|
Size: |
8192
|
|
4E8E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1750492902.0000000004E8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E8E000
|
Size: |
8192
|
|
5490000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1370767784.0000000005490000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5490000
|
Size: |
49152
|
|
102E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546049672.000000000102E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
102E000
|
Size: |
8192
|
|
60E3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579356845.00000000060E3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60E3000
|
Size: |
8192
|
|
10E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351522221.00000000010E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10E0000
|
Size: |
16384
|
|
5880000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1578957529.0000000005880000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5880000
|
Size: |
4096
|
|
9C5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2544502853.00000000009C5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C5000
|
Size: |
16384
|
|
1360000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1624712284.0000000001360000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1360000
|
Size: |
61440
|
|
43A1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1578621437.00000000043A1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
43A1000
|
Size: |
20480
|
|
5603000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1751014124.0000000005603000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5603000
|
Size: |
8192
|
|
D7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2544794400.0000000000D7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D7E000
|
Size: |
40960
|
|
3E4F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1791205395.0000000003E4F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E4F000
|
Size: |
4096
|
|
7EEE0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1372597240.000000007EEE0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7EEE0000
|
Size: |
4096
|
|
3F9F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1629162678.0000000003F9F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3F9F000
|
Size: |
4096
|
|
4F00000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1750758335.0000000004F00000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
4F00000
|
Size: |
4096
|
|
4438000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1578621437.0000000004438000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4438000
|
Size: |
4096
|
|
2982000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2546552728.0000000002982000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2982000
|
Size: |
4096
|
|
5B1D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559351796.0000000005B1D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5B1D000
|
Size: |
12288
|
|
13D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1352293372.00000000013D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D7000
|
Size: |
12288
|
|
514E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1750783059.000000000514E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
514E000
|
Size: |
8192
|
|
5D40000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.1634042429.0000000005D40000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5D40000
|
Size: |
12288
|
|
C4F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1721670899.0000000000C4F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C4F000
|
Size: |
4096
|
|
5E9C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2559506778.0000000005E9C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5E9C000
|
Size: |
16384
|
|
2597000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1723206892.0000000002597000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2597000
|
Size: |
4096
|
|
5840000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1751400688.0000000005840000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5840000
|
Size: |
262144
|
|
2987000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2546573705.0000000002987000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2987000
|
Size: |
4096
|
|
5BC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1631264119.0000000005BC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5BC0000
|
Size: |
4096
|
|
580E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.1791926787.000000000580E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
580E000
|
Size: |
8192
|
|
12F7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1351847039.00000000012F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12F7000
|
Size: |
94208
|
|
5AEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579091074.0000000005AEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5AEE000
|
Size: |
8192
|
|
6240000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.1579528663.0000000006240000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6240000
|
Size: |
4096
|
|