F02000
|
unkown
|
page readonly
|
 |
|
|
Name: |
00000000.00000000.1289812590.0000000000F02000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F02000
|
Size: |
94208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Njrat |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
May infect USB drives |
Spreading |
Replication Through Removable Media
|
Yara signature match |
System Summary |
|
|
1597000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751449361.0000000001597000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1597000
|
Size: |
352256
|
|
4680000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332500657.0000000004680000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4680000
|
Size: |
40960
|
|
77A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328436767.000000000077A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77A000
|
Size: |
118784
|
|
734000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1331932186.0000000000734000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
734000
|
Size: |
45056
|
|
1D5C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752094151.0000000001D5C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1D5C000
|
Size: |
16384
|
|
76F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329839429.000000000076F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76F000
|
Size: |
28672
|
|
7A9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328402201.00000000007A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A9000
|
Size: |
8192
|
|
1D60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752115370.0000000001D60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D60000
|
Size: |
20480
|
|
1C70000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3751977000.0000000001C70000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1C70000
|
Size: |
40960
|
|
1530000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3751417233.0000000001530000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1530000
|
Size: |
4096
|
|
78D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330928495.000000000078D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
78D000
|
Size: |
8192
|
|
16AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751656181.00000000016AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
16AE000
|
Size: |
8192
|
|
609D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752744065.000000000609D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
609D000
|
Size: |
12288
|
|
775000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330995919.0000000000775000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
775000
|
Size: |
16384
|
|
741000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331651848.0000000000741000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
741000
|
Size: |
81920
|
|
46E8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752220072.00000000046E8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
46E8000
|
Size: |
225280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
36CE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752141392.00000000036CE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36CE000
|
Size: |
323584
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
779000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330897341.0000000000779000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
779000
|
Size: |
90112
|
|
795000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329231012.0000000000795000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
795000
|
Size: |
32768
|
|
7A9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329277477.00000000007A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A9000
|
Size: |
163840
|
|
5F5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752654161.0000000005F5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5F5E000
|
Size: |
8192
|
|
1B60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751873795.0000000001B60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B60000
|
Size: |
20480
|
|
7C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328558740.00000000007C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C0000
|
Size: |
12288
|
|
77A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331252597.000000000077A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77A000
|
Size: |
77824
|
|
7C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328598042.00000000007C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C0000
|
Size: |
12288
|
|
4BBF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332518004.0000000004BBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4BBF000
|
Size: |
4096
|
|
65E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753024326.00000000065E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
65E0000
|
Size: |
65536
|
|
7A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329937622.00000000007A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A0000
|
Size: |
45056
|
|
1FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1331711182.00000000001FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1FB000
|
Size: |
20480
|
|
4D4B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331126629.0000000004D4B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D4B000
|
Size: |
8192
|
|
7A9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331159196.00000000007A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A9000
|
Size: |
24576
|
|
78F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330656153.000000000078F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
78F000
|
Size: |
131072
|
|
142D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751070777.000000000142D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
142D000
|
Size: |
12288
|
|
7CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328558740.00000000007CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CE000
|
Size: |
12288
|
|
76D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329989090.000000000076D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76D000
|
Size: |
8192
|
|
7AD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332243578.00000000007AD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AD000
|
Size: |
8192
|
|
14EC000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3751258769.00000000014EC000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14EC000
|
Size: |
4096
|
|
7CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329021579.00000000007CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CE000
|
Size: |
12288
|
|
776000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328493455.0000000000776000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
776000
|
Size: |
299008
|
|
7CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329764872.00000000007CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CF000
|
Size: |
282624
|
|
815000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331542775.0000000000815000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
815000
|
Size: |
12288
|
|
14E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751214877.00000000014E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14E0000
|
Size: |
8192
|
|
77A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331180828.000000000077A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77A000
|
Size: |
77824
|
|
615E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752800960.000000000615E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
615E000
|
Size: |
8192
|
|
150C000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3751349348.000000000150C000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
150C000
|
Size: |
4096
|
|
4CBF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332543696.0000000004CBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4CBF000
|
Size: |
4096
|
|
629D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752858818.000000000629D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
629D000
|
Size: |
12288
|
|
77A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330078877.000000000077A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77A000
|
Size: |
77824
|
|
731000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331588191.0000000000731000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
731000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
46C1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752220072.00000000046C1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
46C1000
|
Size: |
28672
|
|
60DD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752762880.00000000060DD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60DD000
|
Size: |
12288
|
|
775000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329885048.0000000000775000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
775000
|
Size: |
4096
|
|
4D48000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330602768.0000000004D48000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D48000
|
Size: |
20480
|
|
7810000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753111260.0000000007810000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7810000
|
Size: |
4096
|
|
1510000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751361221.0000000001510000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1510000
|
Size: |
4096
|
|
778000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332049695.0000000000778000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
778000
|
Size: |
4096
|
|
7CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331089598.00000000007CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CE000
|
Size: |
274432
|
|
812000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331542775.0000000000812000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
812000
|
Size: |
4096
|
|
79D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328301623.000000000079D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79D000
|
Size: |
77824
|
|
720000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1331932186.0000000000720000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
720000
|
Size: |
36864
|
|
172D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751689444.000000000172D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
172D000
|
Size: |
12288
|
|
FAA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3750968405.0000000000FAA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FAA000
|
Size: |
24576
|
|
7CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328598042.00000000007CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CE000
|
Size: |
12288
|
|
768000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328266975.0000000000768000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
768000
|
Size: |
294912
|
|
68E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1331867765.000000000068E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
68E000
|
Size: |
8192
|
|
1517000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3751389064.0000000001517000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1517000
|
Size: |
4096
|
|
78F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329872582.000000000078F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
78F000
|
Size: |
57344
|
|
767000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328493455.0000000000767000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
767000
|
Size: |
8192
|
|
4D47000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330613639.0000000004D47000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D47000
|
Size: |
4096
|
|
1430000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751086198.0000000001430000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1430000
|
Size: |
4096
|
|
611B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752784871.000000000611B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
611B000
|
Size: |
20480
|
|
741000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1331975930.0000000000741000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
741000
|
Size: |
81920
|
|
649E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752965780.000000000649E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
649E000
|
Size: |
8192
|
|
4D49000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330613639.0000000004D49000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D49000
|
Size: |
16384
|
|
4570000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332487594.0000000004570000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4570000
|
Size: |
4096
|
|
13E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751057017.00000000013E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13E0000
|
Size: |
8192
|
|
78D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329937622.000000000078D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
78D000
|
Size: |
8192
|
|
4D3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329827920.0000000004D3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D3D000
|
Size: |
8192
|
|
790000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329242928.0000000000790000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
790000
|
Size: |
20480
|
|
1CC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751999610.0000000001CC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1CC0000
|
Size: |
4096
|
|
1B50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751852413.0000000001B50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B50000
|
Size: |
65536
|
|
4D4C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332588799.0000000004D4C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D4C000
|
Size: |
4096
|
|
755000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331633639.0000000000755000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
755000
|
Size: |
90112
|
|
8910000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753237910.0000000008910000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8910000
|
Size: |
233472
|
|
150A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3751337144.000000000150A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
150A000
|
Size: |
4096
|
|
81A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331074100.000000000081A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
81A000
|
Size: |
20480
|
|
773000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332028475.0000000000773000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
773000
|
Size: |
8192
|
|
72A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1331932186.000000000072A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
72A000
|
Size: |
28672
|
|
15F2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751449361.00000000015F2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
15F2000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
36C1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752141392.00000000036C1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36C1000
|
Size: |
49152
|
|
776000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331180828.0000000000776000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
776000
|
Size: |
12288
|
|
81E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331142219.000000000081E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
81E000
|
Size: |
4096
|
|
186E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751799294.000000000186E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
186E000
|
Size: |
8192
|
|
76B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329904812.000000000076B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76B000
|
Size: |
16384
|
|
79D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328558740.000000000079D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79D000
|
Size: |
139264
|
|
14FA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3751291308.00000000014FA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14FA000
|
Size: |
4096
|
|
14D2000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3751187688.00000000014D2000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14D2000
|
Size: |
8192
|
|
58FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752423868.00000000058FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
58FC000
|
Size: |
16384
|
|
B0C2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753449179.000000000B0C2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
B0C2000
|
Size: |
593920
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
776000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329754178.0000000000776000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
776000
|
Size: |
12288
|
|
2AF6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332422337.0000000002AF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AF6000
|
Size: |
36864
|
|
1300000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751042216.0000000001300000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1300000
|
Size: |
4096
|
|
818000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331507596.0000000000818000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
818000
|
Size: |
4096
|
|
79F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328374800.000000000079F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79F000
|
Size: |
8192
|
|
4D3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330462153.0000000004D3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D3D000
|
Size: |
65536
|
|
64DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752989913.00000000064DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
64DE000
|
Size: |
8192
|
|
7AC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330009882.00000000007AC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AC000
|
Size: |
143360
|
|
1500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751306761.0000000001500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1500000
|
Size: |
4096
|
|
B066000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753449179.000000000B066000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
B066000
|
Size: |
249856
|
|
5AFE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752590166.0000000005AFE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5AFE000
|
Size: |
8192
|
|
81E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331507596.000000000081E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
81E000
|
Size: |
4096
|
|
1502000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3751320973.0000000001502000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1502000
|
Size: |
4096
|
|
79D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331055940.000000000079D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79D000
|
Size: |
32768
|
|
778000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329163688.0000000000778000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
778000
|
Size: |
364544
|
|
4D32000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329705136.0000000004D32000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D32000
|
Size: |
24576
|
|
162E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751449361.000000000162E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
162E000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
796000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330928495.0000000000796000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
796000
|
Size: |
102400
|
|
1610000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751449361.0000000001610000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1610000
|
Size: |
8192
|
|
1570000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751449361.0000000001570000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1570000
|
Size: |
24576
|
|
4D3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332577804.0000000004D3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D3D000
|
Size: |
8192
|
|
7A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328374800.00000000007A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A2000
|
Size: |
16384
|
|
79E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329859506.000000000079E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79E000
|
Size: |
53248
|
|
14C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751167527.00000000014C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
14C0000
|
Size: |
8192
|
|
690000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1331882976.0000000000690000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
690000
|
Size: |
8192
|
|
AD61000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753449179.000000000AD61000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
AD61000
|
Size: |
806912
|
|
1485000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751135458.0000000001485000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1485000
|
Size: |
12288
|
|
76DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753095548.00000000076DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
76DE000
|
Size: |
8192
|
|
4F3000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1331728796.00000000004F3000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F3000
|
Size: |
20480
|
|
8974000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753237910.0000000008974000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8974000
|
Size: |
8192
|
|
940000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332369688.0000000000940000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
940000
|
Size: |
4096
|
|
12F6000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751023791.00000000012F6000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12F6000
|
Size: |
40960
|
|
7A5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330979520.00000000007A5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A5000
|
Size: |
40960
|
|
4EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1331728796.00000000004EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4EE000
|
Size: |
8192
|
|
811000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330590898.0000000000811000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
811000
|
Size: |
57344
|
|
7AD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329021579.00000000007AD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AD000
|
Size: |
73728
|
|
4D3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329705136.0000000004D3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D3D000
|
Size: |
8192
|
|
1480000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751135458.0000000001480000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1480000
|
Size: |
16384
|
|
1760000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751751360.0000000001760000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1760000
|
Size: |
16384
|
|
815000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332295169.0000000000815000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
815000
|
Size: |
12288
|
|
79D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329209952.000000000079D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79D000
|
Size: |
212992
|
|
2A8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332392218.0000000002A8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A8E000
|
Size: |
8192
|
|
792000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329937622.0000000000792000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
792000
|
Size: |
45056
|
|
4D3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330502893.0000000004D3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D3D000
|
Size: |
65536
|
|
791000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329254053.0000000000791000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
791000
|
Size: |
16384
|
|
741000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331588191.0000000000741000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
741000
|
Size: |
172032
|
|
1750000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751729942.0000000001750000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1750000
|
Size: |
24576
|
|
773000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329989090.0000000000773000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
773000
|
Size: |
8192
|
|
2AF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332422337.0000000002AF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AF0000
|
Size: |
16384
|
|
B154000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753449179.000000000B154000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
B154000
|
Size: |
1908736
|
|
8B70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753312936.0000000008B70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8B70000
|
Size: |
217088
|
|
1512000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751375906.0000000001512000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1512000
|
Size: |
4096
|
|
F00000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1289758730.0000000000F00000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F00000
|
Size: |
4096
|
|
778000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329885048.0000000000778000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
778000
|
Size: |
4096
|
|
81B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329740518.000000000081B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
81B000
|
Size: |
16384
|
|
76C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330961792.000000000076C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76C000
|
Size: |
53248
|
|
797000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328422637.0000000000797000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
797000
|
Size: |
24576
|
|
645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1331823289.0000000000645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
645000
|
Size: |
12288
|
|
1578000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751449361.0000000001578000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1578000
|
Size: |
16384
|
|
4D31000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329916611.0000000004D31000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D31000
|
Size: |
4096
|
|
796000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329096219.0000000000796000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
796000
|
Size: |
28672
|
|
7AB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328598042.00000000007AB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AB000
|
Size: |
81920
|
|
77B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332158684.000000000077B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77B000
|
Size: |
73728
|
|
7AD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328402201.00000000007AD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AD000
|
Size: |
12288
|
|
1613000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751449361.0000000001613000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1613000
|
Size: |
4096
|
|
14EA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3751243611.00000000014EA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14EA000
|
Size: |
4096
|
|
7C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328493455.00000000007C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C0000
|
Size: |
12288
|
|
7AF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330517641.00000000007AF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AF000
|
Size: |
458752
|
|
4D3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330549858.0000000004D3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D3D000
|
Size: |
65536
|
|
AE27000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753449179.000000000AE27000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
AE27000
|
Size: |
2351104
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
7CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328493455.00000000007CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CE000
|
Size: |
12288
|
|
7D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332258369.00000000007D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D0000
|
Size: |
266240
|
|
7A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332201223.00000000007A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A2000
|
Size: |
12288
|
|
6A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1331896089.00000000006A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A0000
|
Size: |
4096
|
|
14DA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3751200947.00000000014DA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14DA000
|
Size: |
8192
|
|
7A5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330066625.00000000007A5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A5000
|
Size: |
16384
|
|
79A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329254053.000000000079A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79A000
|
Size: |
12288
|
|
58BB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752402480.00000000058BB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
58BB000
|
Size: |
20480
|
|
796000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332181555.0000000000796000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
796000
|
Size: |
28672
|
|
14F7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3751273017.00000000014F7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14F7000
|
Size: |
4096
|
|
758000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1331975930.0000000000758000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
758000
|
Size: |
77824
|
|
157E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751449361.000000000157E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
157E000
|
Size: |
98304
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
7AC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330038199.00000000007AC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AC000
|
Size: |
143360
|
|
4D49000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331011714.0000000004D49000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D49000
|
Size: |
16384
|
|
7A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328346889.00000000007A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A6000
|
Size: |
20480
|
|
1C6F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751922949.0000000001C6F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1C6F000
|
Size: |
4096
|
|
7AC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329937622.00000000007AC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AC000
|
Size: |
143360
|
|
5E5D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752604143.0000000005E5D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5E5D000
|
Size: |
12288
|
|
62A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752876694.00000000062A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
62A0000
|
Size: |
217088
|
|
65F0000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753048138.00000000065F0000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
65F0000
|
Size: |
4096
|
|
91F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332341530.000000000091F000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
91F000
|
Size: |
4096
|
|
4D10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332567106.0000000004D10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D10000
|
Size: |
4096
|
|
7AB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329810605.00000000007AB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AB000
|
Size: |
147456
|
|
4D38000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329635917.0000000004D38000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D38000
|
Size: |
28672
|
|
4D11000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330462153.0000000004D11000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D11000
|
Size: |
139264
|
|
78D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753134182.00000000078D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
78D8000
|
Size: |
16384
|
|
779000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328329875.0000000000779000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
779000
|
Size: |
147456
|
|
14E2000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3751228574.00000000014E2000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
14E2000
|
Size: |
24576
|
|
8B60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753312936.0000000008B60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8B60000
|
Size: |
36864
|
|
65DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753007198.00000000065DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
65DE000
|
Size: |
8192
|
|
7A9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330038199.00000000007A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A9000
|
Size: |
8192
|
|
151B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3751402406.000000000151B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
151B000
|
Size: |
4096
|
|
1450000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751117724.0000000001450000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1450000
|
Size: |
4096
|
|
18AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751819863.00000000018AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
18AE000
|
Size: |
8192
|
|
1540000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751433332.0000000001540000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1540000
|
Size: |
4096
|
|
7CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329115043.00000000007CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CF000
|
Size: |
8192
|
|
4FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1331728796.00000000004FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4FE000
|
Size: |
8192
|
|
76B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331030322.000000000076B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76B000
|
Size: |
4096
|
|
814000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329728546.0000000000814000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
814000
|
Size: |
45056
|
|
560000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1331803383.0000000000560000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
560000
|
Size: |
4096
|
|
456E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332474301.000000000456E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
456E000
|
Size: |
8192
|
|
4D3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329916611.0000000004D3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D3D000
|
Size: |
8192
|
|
1B3C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751836122.0000000001B3C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1B3C000
|
Size: |
16384
|
|
625D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752841796.000000000625D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
625D000
|
Size: |
12288
|
|
7AB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328317695.00000000007AB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AB000
|
Size: |
20480
|
|
767000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329163688.0000000000767000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
767000
|
Size: |
16384
|
|
778000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329839429.0000000000778000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
778000
|
Size: |
4096
|
|
640000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1331823289.0000000000640000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
640000
|
Size: |
16384
|
|
4FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1331728796.00000000004FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4FB000
|
Size: |
4096
|
|
43DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332459658.00000000043DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
43DE000
|
Size: |
8192
|
|
813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331228639.0000000000813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
813000
|
Size: |
24576
|
|
773000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331030322.0000000000773000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
773000
|
Size: |
8192
|
|
4D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329648299.0000000004D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D4A000
|
Size: |
4096
|
|
5F9C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752700221.0000000005F9C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5F9C000
|
Size: |
16384
|
|
59FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752574109.00000000059FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59FD000
|
Size: |
12288
|
|
7894000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753134182.0000000007894000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7894000
|
Size: |
266240
|
|
BDBD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3754966795.000000000BDBD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
BDBD000
|
Size: |
16384
|
|
1730000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.3751709172.0000000001730000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1730000
|
Size: |
12288
|
|
4420000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1331469111.0000000004420000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4420000
|
Size: |
4096
|
|
779000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329659294.0000000000779000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
779000
|
Size: |
679936
|
|
4D30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330549858.0000000004D30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D30000
|
Size: |
12288
|
|
1440000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751102697.0000000001440000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1440000
|
Size: |
4096
|
|
7A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330009882.00000000007A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A0000
|
Size: |
45056
|
|
7A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332217171.00000000007A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A6000
|
Size: |
12288
|
|
B0A4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753449179.000000000B0A4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
B0A4000
|
Size: |
114688
|
|
15EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3751449361.00000000015EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
15EE000
|
Size: |
12288
|
|
7A1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1328361752.00000000007A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A1000
|
Size: |
20480
|
|
8BA7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753312936.0000000008BA7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8BA7000
|
Size: |
253952
|
|
819000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330914564.0000000000819000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
819000
|
Size: |
24576
|
|
4D3F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329618385.0000000004D3F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D3F000
|
Size: |
49152
|
|
7A9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329021579.00000000007A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A9000
|
Size: |
8192
|
|
4D3F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1330578084.0000000004D3F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D3F000
|
Size: |
57344
|
|
6FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1331913806.00000000006FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6FE000
|
Size: |
8192
|
|
79D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329790141.000000000079D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79D000
|
Size: |
204800
|
|
785B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3753134182.000000000785B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
785B000
|
Size: |
159744
|
|
81E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1332321430.000000000081E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
81E000
|
Size: |
4096
|
|
57BD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3752357448.00000000057BD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
57BD000
|
Size: |
12288
|
|
7C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1329021579.00000000007C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C0000
|
Size: |
12288
|
|