2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3062881030.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3241735776.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3201362620.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
2DC759D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797625397.000002DC759D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC759D0000
|
Size: |
4096
|
|
2A904FD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2910880542.0000002A904FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A904FD000
|
Size: |
12288
|
|
2DC776C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3118317291.000002DC776C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776C7000
|
Size: |
20480
|
|
2DC75853000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797249656.000002DC75853000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC75853000
|
Size: |
49152
|
|
1DE3EBC9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912320575.000001DE3EBC9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBC9000
|
Size: |
45056
|
|
1DE3EBD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912202158.000001DE3EBD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBD4000
|
Size: |
12288
|
|
2DC7761E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2896844722.000002DC7761E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7761E000
|
Size: |
20480
|
|
24E44230000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4796620775.0000024E44230000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24E44230000
|
Size: |
12288
|
|
1C742F69000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911365811.000001C742F69000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F69000
|
Size: |
24576
|
|
2DC7763D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2885355698.000002DC7763D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7763D000
|
Size: |
45056
|
|
2DC776C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3150108134.000002DC776C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776C7000
|
Size: |
20480
|
|
1DE3EBB9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912515415.000001DE3EBB9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBB9000
|
Size: |
36864
|
|
1DE3EC0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912066208.000001DE3EC0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EC0A000
|
Size: |
16384
|
|
2DC757C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797249656.000002DC757C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC757C7000
|
Size: |
344064
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3362620701.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3342438281.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
FA632FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797195418.000000FA632FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA632FF000
|
Size: |
4096
|
|
2DC7763D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908140740.000002DC7763D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7763D000
|
Size: |
45056
|
|
1DE3EBAF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912738405.000001DE3EBAF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBAF000
|
Size: |
24576
|
|
2DC775FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2884841446.000002DC775FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775FE000
|
Size: |
24576
|
|
1C742F1E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2909577160.000001C742F1E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F1E000
|
Size: |
12288
|
|
2DC776E0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4798120503.000002DC776E0000.00000004.00000001.00040000.00000007.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2DC776E0000
|
Size: |
4096
|
|
2DC777C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3170562763.000002DC777C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777C2000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
FA629FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4796720986.000000FA629FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA629FE000
|
Size: |
8192
|
|
2DC777C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3094773668.000002DC777C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777C2000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC77638000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2882912106.000002DC77638000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77638000
|
Size: |
65536
|
|
1DE3EC06000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915792192.000001DE3EC06000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EC06000
|
Size: |
12288
|
|
2DC777DF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3052192276.000002DC777DF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777DF000
|
Size: |
20480
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3221613532.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
1C742F84000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2909441350.000001C742F84000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F84000
|
Size: |
4096
|
|
2DC775FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2889032662.000002DC775FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775FE000
|
Size: |
24576
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3105181490.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
2DC777BF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3052609280.000002DC777BF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777BF000
|
Size: |
4096
|
|
FA622FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4796411824.000000FA622FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA622FF000
|
Size: |
4096
|
|
2DC776C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3160362781.000002DC776C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776C7000
|
Size: |
20480
|
|
2DC77629000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2896844722.000002DC77629000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77629000
|
Size: |
24576
|
|
2DC777BE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4798158941.000002DC777BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777BE000
|
Size: |
12288
|
|
2DC775E4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797656158.000002DC775E4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775E4000
|
Size: |
8192
|
|
1C742F39000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2908691703.000001C742F39000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F39000
|
Size: |
176128
|
|
2DC777F8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3052192276.000002DC777F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777F8000
|
Size: |
32768
|
|
2720000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2964196437.0000000002720000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2720000
|
Size: |
12288
|
|
1DE3EBB3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915573025.000001DE3EBB3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBB3000
|
Size: |
8192
|
|
2DC777C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4798244065.000002DC777C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777C2000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC7763D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2899471953.000002DC7763D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7763D000
|
Size: |
45056
|
|
1DE3EBCF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915655823.000001DE3EBCF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBCF000
|
Size: |
20480
|
|
2DC77623000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2885355698.000002DC77623000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77623000
|
Size: |
4096
|
|
63001FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4796271366.00000063001FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63001FE000
|
Size: |
8192
|
|
2DC777D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3160330808.000002DC777D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777D2000
|
Size: |
32768
|
|
2DC775FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2911531532.000002DC775FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775FE000
|
Size: |
24576
|
|
2DC77629000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797656158.000002DC77629000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77629000
|
Size: |
126976
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
FA631FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797155085.000000FA631FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA631FE000
|
Size: |
8192
|
|
2DC759C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797564160.000002DC759C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC759C0000
|
Size: |
12288
|
|
24E44170000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4796580576.0000024E44170000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24E44170000
|
Size: |
4096
|
|
2DC75690000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797227788.000002DC75690000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC75690000
|
Size: |
4096
|
|
2B8C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2964311331.0000000002B8C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B8C000
|
Size: |
16384
|
|
2DC777D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3129534252.000002DC777D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777D2000
|
Size: |
32768
|
|
264C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2964068710.000000000264C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
264C000
|
Size: |
16384
|
|
1DE3EBDA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915710190.000001DE3EBDA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBDA000
|
Size: |
36864
|
|
1C742EA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911026332.000001C742EA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742EA4000
|
Size: |
401408
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2DC7763D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2907687850.000002DC7763D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7763D000
|
Size: |
45056
|
|
FA62BFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4796818694.000000FA62BFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA62BFE000
|
Size: |
8192
|
|
2DC77629000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2907458998.000002DC77629000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77629000
|
Size: |
24576
|
|
2DC776CC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3041957386.000002DC776CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776CC000
|
Size: |
12288
|
|
1DE3EBC2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912368321.000001DE3EBC2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBC2000
|
Size: |
28672
|
|
2DC757C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3190991710.000002DC757C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC757C7000
|
Size: |
344064
|
|
2DC77618000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2907458998.000002DC77618000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77618000
|
Size: |
16384
|
|
1DE3EB30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915302378.000001DE3EB30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EB30000
|
Size: |
12288
|
|
FA62FFD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797012066.000000FA62FFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA62FFD000
|
Size: |
12288
|
|
2DC77814000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3052069491.000002DC77814000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77814000
|
Size: |
8192
|
|
2DC775EC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2889032662.000002DC775EC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775EC000
|
Size: |
49152
|
|
1DE3EC0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912221889.000001DE3EC0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EC0A000
|
Size: |
16384
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3074710251.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
1C742F10000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2909526860.000001C742F10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F10000
|
Size: |
53248
|
|
1C742CD0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2910960714.000001C742CD0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742CD0000
|
Size: |
4096
|
|
1C742F7D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911421743.000001C742F7D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F7D000
|
Size: |
8192
|
|
FA62FED000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797012066.000000FA62FED000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA62FED000
|
Size: |
8192
|
|
2DC775F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2902203904.000002DC775F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775F1000
|
Size: |
28672
|
|
2A8FFFF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2910659832.0000002A8FFFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A8FFFF000
|
Size: |
4096
|
|
2DC775F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2911531532.000002DC775F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775F1000
|
Size: |
28672
|
|
2DCE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2964373406.0000000002DCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DCE000
|
Size: |
8192
|
|
2A8FBF9000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2910605210.0000002A8FBF9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A8FBF9000
|
Size: |
28672
|
|
6106FFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2914233101.0000006106FFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6106FFE000
|
Size: |
8192
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3272079485.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3342367708.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC7763D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2894881251.000002DC7763D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7763D000
|
Size: |
45056
|
|
2DC776C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3180810303.000002DC776C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776C7000
|
Size: |
20480
|
|
24E444A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4797036492.0000024E444A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24E444A0000
|
Size: |
4096
|
|
1DE3EBA1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915475542.000001DE3EBA1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBA1000
|
Size: |
8192
|
|
1DE3EC06000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912406673.000001DE3EC06000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EC06000
|
Size: |
12288
|
|
1C742F69000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2908751993.000001C742F69000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F69000
|
Size: |
24576
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3392981681.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3261902470.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC775D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797656158.000002DC775D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775D0000
|
Size: |
49152
|
|
2DC7765D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908255445.000002DC7765D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7765D000
|
Size: |
4096
|
|
2DC7765B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2899387497.000002DC7765B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7765B000
|
Size: |
12288
|
|
1C742F69000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2908631662.000001C742F69000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F69000
|
Size: |
24576
|
|
1C742F80000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911469293.000001C742F80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F80000
|
Size: |
4096
|
|
1DE3EBE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912066208.000001DE3EBE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBE3000
|
Size: |
126976
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3180660057.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
1DE3EE60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915873964.000001DE3EE60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EE60000
|
Size: |
12288
|
|
2DC7761F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2883941803.000002DC7761F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7761F000
|
Size: |
36864
|
|
2DC77635000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908735806.000002DC77635000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77635000
|
Size: |
28672
|
|
2DC7763C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2883941803.000002DC7763C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7763C000
|
Size: |
49152
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3190975803.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3372725473.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
1C742F2A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2909386884.000001C742F2A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F2A000
|
Size: |
12288
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3231763501.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
1C742F28000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2908853166.000001C742F28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F28000
|
Size: |
20480
|
|
2DC77697000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797656158.000002DC77697000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77697000
|
Size: |
118784
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC7763D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908202956.000002DC7763D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7763D000
|
Size: |
45056
|
|
1C742F16000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2909718735.000001C742F16000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F16000
|
Size: |
4096
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3170538804.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
1DE3EC06000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912767580.000001DE3EC06000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EC06000
|
Size: |
12288
|
|
1DE3EE64000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915873964.000001DE3EE64000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EE64000
|
Size: |
16384
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3251766468.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3041721789.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC776C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4798072453.000002DC776C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776C8000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC7765D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908359431.000002DC7765D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7765D000
|
Size: |
4096
|
|
2DC7765B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2907376296.000002DC7765B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7765B000
|
Size: |
12288
|
|
2DC777F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3052192276.000002DC777F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777F0000
|
Size: |
28672
|
|
2DC77618000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2889032662.000002DC77618000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77618000
|
Size: |
16384
|
|
2DC7765D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2911370742.000002DC7765D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7765D000
|
Size: |
4096
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3362652248.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
2DC777D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3139770705.000002DC777D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777D2000
|
Size: |
32768
|
|
1C742F16000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911126987.000001C742F16000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F16000
|
Size: |
4096
|
|
2DC7761E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2907458998.000002DC7761E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7761E000
|
Size: |
20480
|
|
1DE3EBC8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912540207.000001DE3EBC8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBC8000
|
Size: |
4096
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3139744658.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
2DC7761F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2883172066.000002DC7761F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7761F000
|
Size: |
36864
|
|
2DC777D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3084761547.000002DC777D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777D2000
|
Size: |
32768
|
|
2DC777B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4798158941.000002DC777B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777B1000
|
Size: |
24576
|
|
282C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2964214973.000000000282C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
282C000
|
Size: |
16384
|
|
2DC777D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3118264691.000002DC777D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777D2000
|
Size: |
32768
|
|
6106EFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2914176764.0000006106EFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6106EFE000
|
Size: |
8192
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3170509748.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
1C742F94000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2908555950.000001C742F94000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F94000
|
Size: |
16384
|
|
2DC776C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3064740210.000002DC776C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776C7000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC7761E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2907876671.000002DC7761E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7761E000
|
Size: |
20480
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3312246347.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
6106DFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2914055126.0000006106DFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6106DFE000
|
Size: |
8192
|
|
1C742F2D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2908631662.000001C742F2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F2D000
|
Size: |
225280
|
|
1DE3EC0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912767580.000001DE3EC0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EC0A000
|
Size: |
16384
|
|
1DE3EBBA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915600456.000001DE3EBBA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBBA000
|
Size: |
20480
|
|
2DC777D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3064681121.000002DC777D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777D2000
|
Size: |
32768
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3041852753.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
1C742F21000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2908853166.000001C742F21000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F21000
|
Size: |
24576
|
|
24E4430D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4796620775.0000024E4430D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24E4430D000
|
Size: |
4096
|
|
26CE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2964142572.00000000026CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
26CE000
|
Size: |
8192
|
|
2DC7763D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908359431.000002DC7763D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7763D000
|
Size: |
45056
|
|
2DC777CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3052192276.000002DC777CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777CF000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC75788000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797249656.000002DC75788000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC75788000
|
Size: |
245760
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
1DE3EB97000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915302378.000001DE3EB97000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EB97000
|
Size: |
32768
|
|
2DC77691000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797656158.000002DC77691000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77691000
|
Size: |
8192
|
|
2DC777C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3150026045.000002DC777C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777C2000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC77635000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908140740.000002DC77635000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77635000
|
Size: |
28672
|
|
1C742F1E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2909526860.000001C742F1E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F1E000
|
Size: |
12288
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3382853076.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
2DC75860000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797535651.000002DC75860000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC75860000
|
Size: |
16384
|
|
2DC7581C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3190991710.000002DC7581C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7581C000
|
Size: |
180224
|
|
2DC776CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4798100431.000002DC776CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776CE000
|
Size: |
4096
|
|
2DC775ED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2884422606.000002DC775ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775ED000
|
Size: |
45056
|
|
2DC775EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2911531532.000002DC775EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775EA000
|
Size: |
12288
|
|
FA61CFB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4796268810.000000FA61CFB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA61CFB000
|
Size: |
20480
|
|
2DC7767B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908438050.000002DC7767B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7767B000
|
Size: |
12288
|
|
1DE3EBAC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915540531.000001DE3EBAC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBAC000
|
Size: |
12288
|
|
FA625FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4796471964.000000FA625FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA625FE000
|
Size: |
8192
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3118143082.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
1C742F94000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2908419188.000001C742F94000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F94000
|
Size: |
16384
|
|
1DE3EB9F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912897201.000001DE3EB9F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EB9F000
|
Size: |
16384
|
|
2DC777C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3084761547.000002DC777C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777C2000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC777BF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3041973580.000002DC777BF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777BF000
|
Size: |
110592
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC7761E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797656158.000002DC7761E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7761E000
|
Size: |
20480
|
|
2DC7761E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2911531532.000002DC7761E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7761E000
|
Size: |
20480
|
|
2DC77790000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4798143006.000002DC77790000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77790000
|
Size: |
4096
|
|
2DC777F5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3062881030.000002DC777F5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777F5000
|
Size: |
45056
|
|
2DC777C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3139770705.000002DC777C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777C2000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC77618000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2911531532.000002DC77618000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77618000
|
Size: |
16384
|
|
1C742F09000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911026332.000001C742F09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F09000
|
Size: |
4096
|
|
1C742D90000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2910993524.000001C742D90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742D90000
|
Size: |
8192
|
|
2DC77629000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2907876671.000002DC77629000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77629000
|
Size: |
24576
|
|
2DC7763D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908074231.000002DC7763D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7763D000
|
Size: |
45056
|
|
1DE3EBF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915737821.000001DE3EBF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBF0000
|
Size: |
49152
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3332243461.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
1C742F0D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2909718735.000001C742F0D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F0D000
|
Size: |
12288
|
|
2DC757AA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3190991710.000002DC757AA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC757AA000
|
Size: |
106496
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2DC776C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3052651553.000002DC776C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776C7000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6106AFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2913783787.0000006106AFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6106AFE000
|
Size: |
8192
|
|
2A903FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2910845642.0000002A903FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A903FE000
|
Size: |
8192
|
|
2DC775FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2907876671.000002DC775FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775FE000
|
Size: |
24576
|
|
2DC77695000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797656158.000002DC77695000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77695000
|
Size: |
4096
|
|
2A905FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2910936382.0000002A905FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A905FE000
|
Size: |
8192
|
|
63002FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4796319695.00000063002FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63002FD000
|
Size: |
12288
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3084737200.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
1C742F1E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911181041.000001C742F1E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F1E000
|
Size: |
12288
|
|
2DC777D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3180683521.000002DC777D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777D2000
|
Size: |
32768
|
|
FA628FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4796673581.000000FA628FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA628FF000
|
Size: |
4096
|
|
1C742F1D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2909502236.000001C742F1D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F1D000
|
Size: |
16384
|
|
2A901FD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2910713820.0000002A901FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A901FD000
|
Size: |
12288
|
|
1C742F53000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911291257.000001C742F53000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F53000
|
Size: |
49152
|
|
24E44258000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4796620775.0000024E44258000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24E44258000
|
Size: |
245760
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2DC77629000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2911531532.000002DC77629000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77629000
|
Size: |
24576
|
|
2DC75760000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797249656.000002DC75760000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC75760000
|
Size: |
12288
|
|
FA62DFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4796874328.000000FA62DFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA62DFE000
|
Size: |
8192
|
|
6106CFD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2914007124.0000006106CFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6106CFD000
|
Size: |
12288
|
|
1DE3EBE6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915737821.000001DE3EBE6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBE6000
|
Size: |
32768
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3231737892.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2B2E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2964291636.0000000002B2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B2E000
|
Size: |
8192
|
|
810000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2963629276.0000000000810000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
810000
|
Size: |
4096
|
|
FA61DFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4796368163.000000FA61DFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA61DFE000
|
Size: |
8192
|
|
1DE3EBD5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915655823.000001DE3EBD5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBD5000
|
Size: |
8192
|
|
2DC777C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3074749019.000002DC777C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777C2000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC7765D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797656158.000002DC7765D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7765D000
|
Size: |
4096
|
|
2DC777DA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3041852753.000002DC777DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777DA000
|
Size: |
4096
|
|
24E44234000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4796620775.0000024E44234000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24E44234000
|
Size: |
143360
|
|
6106BFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2913838252.0000006106BFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6106BFE000
|
Size: |
8192
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3149919502.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3190958220.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC7763D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2907403692.000002DC7763D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7763D000
|
Size: |
45056
|
|
2DC77637000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2885355698.000002DC77637000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77637000
|
Size: |
8192
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3312213881.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
1DE3ED30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915844468.000001DE3ED30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3ED30000
|
Size: |
4096
|
|
2DC776C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3107887978.000002DC776C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776C7000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1C743000000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911559675.000001C743000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C743000000
|
Size: |
4096
|
|
C2E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2963917493.0000000000C2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C2E000
|
Size: |
8192
|
|
1C742F30000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2909386884.000001C742F30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F30000
|
Size: |
36864
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3129452527.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
2DC776C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3094822440.000002DC776C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776C7000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3261929134.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
61068F9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2913610375.00000061068F9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61068F9000
|
Size: |
28672
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3128391911.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3094745795.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
1DE3EC06000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912066208.000001DE3EC06000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EC06000
|
Size: |
12288
|
|
2DC777C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3105265769.000002DC777C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777C2000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC776C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3139823857.000002DC776C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776C7000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3292237675.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC775E7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797656158.000002DC775E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775E7000
|
Size: |
69632
|
|
2DC77635000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2911531532.000002DC77635000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77635000
|
Size: |
77824
|
|
2DC7761B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2883172066.000002DC7761B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7761B000
|
Size: |
4096
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3221585079.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
FA61CEC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4796268810.000000FA61CEC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA61CEC000
|
Size: |
8192
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3160282522.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
1C742F94000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2909695301.000001C742F94000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F94000
|
Size: |
16384
|
|
1C743034000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911590367.000001C743034000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C743034000
|
Size: |
16384
|
|
1DE3EC0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912406673.000001DE3EC0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EC0A000
|
Size: |
16384
|
|
1DE3EBEE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912221889.000001DE3EBEE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBEE000
|
Size: |
81920
|
|
2DC77629000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2902203904.000002DC77629000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77629000
|
Size: |
24576
|
|
292F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2964234307.000000000292F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
292F000
|
Size: |
4096
|
|
2DC77618000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2907876671.000002DC77618000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77618000
|
Size: |
16384
|
|
2DC7763D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908574525.000002DC7763D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7763D000
|
Size: |
45056
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3094716063.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
E6F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2964044615.0000000000E6F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E6F000
|
Size: |
4096
|
|
2DC7761D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2883941803.000002DC7761D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7761D000
|
Size: |
4096
|
|
2DC77679000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2911502285.000002DC77679000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77679000
|
Size: |
20480
|
|
24E44297000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4796620775.0000024E44297000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24E44297000
|
Size: |
479232
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3393008139.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
1C742F52000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2908751993.000001C742F52000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F52000
|
Size: |
73728
|
|
1C742F3B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911249134.000001C742F3B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F3B000
|
Size: |
94208
|
|
2DC75764000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797249656.000002DC75764000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC75764000
|
Size: |
143360
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3282050537.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
61071FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2914701047.00000061071FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61071FE000
|
Size: |
8192
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3382830762.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
3FC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2963519625.00000000003FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3FC000
|
Size: |
16384
|
|
1DE3EBB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912664540.000001DE3EBB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBB5000
|
Size: |
16384
|
|
2DC75853000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3190991710.000002DC75853000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC75853000
|
Size: |
49152
|
|
2DC77635000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2907687850.000002DC77635000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77635000
|
Size: |
28672
|
|
1DE3EC06000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912221889.000001DE3EC06000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EC06000
|
Size: |
12288
|
|
24E444D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4797083134.0000024E444D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24E444D4000
|
Size: |
16384
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3372679162.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC775FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797656158.000002DC775FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775FE000
|
Size: |
24576
|
|
2DC7765D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2911531532.000002DC7765D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7765D000
|
Size: |
4096
|
|
FA626FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4796563169.000000FA626FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA626FE000
|
Size: |
8192
|
|
5C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2963595810.00000000005C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C0000
|
Size: |
4096
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3180636395.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC77618000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2902203904.000002DC77618000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77618000
|
Size: |
16384
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3322211392.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3139714402.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC775FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2902203904.000002DC775FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775FE000
|
Size: |
24576
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3302235152.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
1C742F85000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2908555950.000001C742F85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F85000
|
Size: |
8192
|
|
390000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2963442220.0000000000390000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
390000
|
Size: |
4096
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3104997716.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3211431486.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
1DE3EBA3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912840224.000001DE3EBA3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBA3000
|
Size: |
49152
|
|
1DE3EB58000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915302378.000001DE3EB58000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EB58000
|
Size: |
241664
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3251743239.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
1C742F94000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2908304839.000001C742F94000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F94000
|
Size: |
16384
|
|
1C743030000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911590367.000001C743030000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C743030000
|
Size: |
12288
|
|
2A900FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2910686217.0000002A900FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A900FE000
|
Size: |
8192
|
|
FA630FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797106755.000000FA630FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA630FE000
|
Size: |
8192
|
|
2DC7765D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908574525.000002DC7765D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7765D000
|
Size: |
4096
|
|
1DE3EB34000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915302378.000001DE3EB34000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EB34000
|
Size: |
143360
|
|
24E44330000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4796991278.0000024E44330000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24E44330000
|
Size: |
8192
|
|
2DC759C4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797564160.000002DC759C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC759C4000
|
Size: |
28672
|
|
2DC777D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3074749019.000002DC777D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777D2000
|
Size: |
32768
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3302207225.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
24E46130000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4797184477.0000024E46130000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24E46130000
|
Size: |
4096
|
|
2C8D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2964328997.0000000002C8D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C8D000
|
Size: |
12288
|
|
2DC7765D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908463582.000002DC7765D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7765D000
|
Size: |
4096
|
|
2DC7763D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908463582.000002DC7763D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7763D000
|
Size: |
45056
|
|
2DC776C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3084802758.000002DC776C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776C7000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC7761E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2889032662.000002DC7761E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7761E000
|
Size: |
20480
|
|
637FDFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4796516456.000000637FDFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
637FDFE000
|
Size: |
8192
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3241761964.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
1DE3EA00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915188151.000001DE3EA00000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EA00000
|
Size: |
4096
|
|
FA62EFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4796920522.000000FA62EFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA62EFC000
|
Size: |
16384
|
|
2DC7763D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2911370742.000002DC7763D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7763D000
|
Size: |
45056
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3150003308.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
1C742F84000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2908304839.000001C742F84000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F84000
|
Size: |
20480
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3064648121.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
FA627FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4796624287.000000FA627FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA627FC000
|
Size: |
16384
|
|
1C742F0C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2909646554.000001C742F0C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F0C000
|
Size: |
16384
|
|
2DC777C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3129534252.000002DC777C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777C2000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC776C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3129575890.000002DC776C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776C7000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1DE3EBEF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912406673.000001DE3EBEF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBEF000
|
Size: |
73728
|
|
637F569000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4796466276.000000637F569000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
637F569000
|
Size: |
28672
|
|
1C742F6F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2908304839.000001C742F6F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F6F000
|
Size: |
73728
|
|
1C742F69000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2909794830.000001C742F69000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F69000
|
Size: |
24576
|
|
2DC77635000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2907403692.000002DC77635000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77635000
|
Size: |
24576
|
|
2DC777C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3118264691.000002DC777C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777C2000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1DE3EBBF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912587537.000001DE3EBBF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBBF000
|
Size: |
12288
|
|
1C742F1B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2909577160.000001C742F1B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F1B000
|
Size: |
8192
|
|
9F4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2963782664.00000000009F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9F4000
|
Size: |
225280
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3160313122.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
24E444D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4797083134.0000024E444D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24E444D0000
|
Size: |
12288
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3084711452.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
974000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2963675612.0000000000974000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
974000
|
Size: |
24576
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3322236310.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3292265921.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
2DC775FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2884422606.000002DC775FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775FE000
|
Size: |
24576
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3282080658.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
2DC777A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4798158941.000002DC777A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777A0000
|
Size: |
4096
|
|
2DC777C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3160330808.000002DC777C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777C2000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC777C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3180683521.000002DC777C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777C2000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
D6E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2964019281.0000000000D6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D6E000
|
Size: |
8192
|
|
1C742F27000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2908805109.000001C742F27000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F27000
|
Size: |
24576
|
|
2DC7763D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908255445.000002DC7763D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7763D000
|
Size: |
45056
|
|
2A902FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2910822539.0000002A902FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A902FE000
|
Size: |
8192
|
|
63000FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4796232300.00000063000FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63000FE000
|
Size: |
8192
|
|
1C742F69000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2908691703.000001C742F69000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F69000
|
Size: |
24576
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3211451610.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
268E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2964095657.000000000268E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
268E000
|
Size: |
8192
|
|
1C742F85000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2908419188.000001C742F85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F85000
|
Size: |
16384
|
|
2DC77618000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2884422606.000002DC77618000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77618000
|
Size: |
12288
|
|
1C742F0A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2909718735.000001C742F0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F0A000
|
Size: |
8192
|
|
1DE40A80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915938828.000001DE40A80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE40A80000
|
Size: |
4096
|
|
1C742F30000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2908853166.000001C742F30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F30000
|
Size: |
36864
|
|
FA62EEB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4796920522.000000FA62EEB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA62EEB000
|
Size: |
16384
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3332209694.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC777C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3064681121.000002DC777C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777C2000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
FA62AFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4796773353.000000FA62AFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FA62AFE000
|
Size: |
8192
|
|
2DC777C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3052609280.000002DC777C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777C2000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC777AE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4798158941.000002DC777AE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777AE000
|
Size: |
8192
|
|
1C742F84000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911469293.000001C742F84000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F84000
|
Size: |
4096
|
|
2DC776C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3074780715.000002DC776C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776C7000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC775FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2907458998.000002DC775FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775FE000
|
Size: |
24576
|
|
63004FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4796425352.00000063004FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63004FF000
|
Size: |
4096
|
|
1C742F18000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911159767.000001C742F18000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F18000
|
Size: |
12288
|
|
1C742EA0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911026332.000001C742EA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742EA0000
|
Size: |
12288
|
|
1C742F30000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911228090.000001C742F30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F30000
|
Size: |
36864
|
|
1DE3EBD7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912183707.000001DE3EBD7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBD7000
|
Size: |
49152
|
|
2DC777D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3094773668.000002DC777D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777D2000
|
Size: |
32768
|
|
2DC776B5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797656158.000002DC776B5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776B5000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
1C742F7F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2909441350.000001C742F7F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F7F000
|
Size: |
8192
|
|
2DC7765B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908114236.000002DC7765B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7765B000
|
Size: |
12288
|
|
2DC7767B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908654176.000002DC7767B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7767B000
|
Size: |
12288
|
|
2DC7765D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908735806.000002DC7765D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7765D000
|
Size: |
4096
|
|
9F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2963782664.00000000009F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9F0000
|
Size: |
8192
|
|
2DC77618000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2896844722.000002DC77618000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77618000
|
Size: |
16384
|
|
2DC77638000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2883717337.000002DC77638000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77638000
|
Size: |
65536
|
|
1C742F28000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911181041.000001C742F28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F28000
|
Size: |
8192
|
|
2DC777D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3105265769.000002DC777D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777D2000
|
Size: |
32768
|
|
56D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2963567782.000000000056D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
56D000
|
Size: |
12288
|
|
2DC77635000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908463582.000002DC77635000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77635000
|
Size: |
28672
|
|
2DC77667000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797656158.000002DC77667000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77667000
|
Size: |
167936
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
BEE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2963880943.0000000000BEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BEE000
|
Size: |
8192
|
|
2DC7763D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908735806.000002DC7763D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7763D000
|
Size: |
45056
|
|
2DC7767B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908231876.000002DC7767B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7767B000
|
Size: |
12288
|
|
2DC776C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3170600121.000002DC776C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776C7000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DC7765B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2907617794.000002DC7765B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7765B000
|
Size: |
12288
|
|
1DE3EBAA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2913016541.000001DE3EBAA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBAA000
|
Size: |
20480
|
|
61069FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2913675319.00000061069FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61069FE000
|
Size: |
8192
|
|
2DC77618000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2884841446.000002DC77618000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77618000
|
Size: |
12288
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3352529455.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3352559664.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
970000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2963675612.0000000000970000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
970000
|
Size: |
12288
|
|
2DC77635000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2908255445.000002DC77635000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77635000
|
Size: |
28672
|
|
D2F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2963951173.0000000000D2F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D2F000
|
Size: |
4096
|
|
2DC777D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4798244065.000002DC777D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777D2000
|
Size: |
32768
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3201191687.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
1DE3EBCF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912540207.000001DE3EBCF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBCF000
|
Size: |
20480
|
|
2DC775F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2907876671.000002DC775F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775F1000
|
Size: |
28672
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3118210511.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
2DC775ED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2884841446.000002DC775ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775ED000
|
Size: |
45056
|
|
2CCD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2964350661.0000000002CCD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2CCD000
|
Size: |
12288
|
|
2DC777D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3150026045.000002DC777D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777D2000
|
Size: |
32768
|
|
2A8FEFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2910625089.0000002A8FEFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A8FEFE000
|
Size: |
8192
|
|
1DE3EBC4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915627140.000001DE3EBC4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBC4000
|
Size: |
16384
|
|
2DC7581C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797249656.000002DC7581C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7581C000
|
Size: |
180224
|
|
1DE3EBC4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912587537.000001DE3EBC4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBC4000
|
Size: |
16384
|
|
1DE3EBBA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2912664540.000001DE3EBBA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBBA000
|
Size: |
20480
|
|
2DC775FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2896844722.000002DC775FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775FE000
|
Size: |
24576
|
|
2DC776C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3041994981.000002DC776C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC776C7000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
63003FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.4796371134.00000063003FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63003FE000
|
Size: |
8192
|
|
1DE3EAC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915258788.000001DE3EAC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EAC0000
|
Size: |
8192
|
|
1C742F17000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.2909620634.000001C742F17000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F17000
|
Size: |
16384
|
|
2DC775F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2896844722.000002DC775F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775F1000
|
Size: |
28672
|
|
2DC777EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3074731679.000002DC777EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777EA000
|
Size: |
45056
|
|
270E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2964178136.000000000270E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
270E000
|
Size: |
8192
|
|
2DC777D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3170562763.000002DC777D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC777D2000
|
Size: |
32768
|
|
1C742F94000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.2911529131.000001C742F94000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C742F94000
|
Size: |
16384
|
|
2DC77635000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2899471953.000002DC77635000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77635000
|
Size: |
24576
|
|
2DC775F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2907458998.000002DC775F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC775F1000
|
Size: |
28672
|
|
2DC7761E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2902203904.000002DC7761E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7761E000
|
Size: |
20480
|
|
1DE3EBA9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915475542.000001DE3EBA9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EBA9000
|
Size: |
4096
|
|
2DC77635000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2894881251.000002DC77635000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77635000
|
Size: |
24576
|
|
9BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2963757057.00000000009BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9BE000
|
Size: |
8192
|
|
2DC77808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.3272049826.000002DC77808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77808000
|
Size: |
8192
|
|
2DC7765C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2892510139.000002DC7765C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC7765C000
|
Size: |
8192
|
|
1DE3EC0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2915792192.000001DE3EC0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DE3EC0A000
|
Size: |
16384
|
|
2A2E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2964275128.0000000002A2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A2E000
|
Size: |
8192
|
|
2DC77618000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.4797656158.000002DC77618000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC77618000
|
Size: |
20480
|
|