7f9b90048000
|
|
page read and write
|
|
|
|
Name: |
5488.1.00007f9b90043000.00007f9b90048000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f9b90048000
|
Size: |
20480
|
|
7f9c95b33000
|
|
page read and write
|
|
|
|
Name: |
5488.1.00007f9c95b31000.00007f9c95b33000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f9c95b33000
|
Size: |
8192
|
|
55a271a9b000
|
|
page read and write
|
|
|
|
Name: |
5488.1.000055a271a91000.000055a271a9b000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
55a271a9b000
|
Size: |
40960
|
|
55a271aa4000
|
|
page read and write
|
|
|
|
Name: |
5488.1.000055a271a9b000.000055a271aa4000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
55a271aa4000
|
Size: |
36864
|
|
7f9c94ec7000
|
|
page read and write
|
|
|
|
Name: |
5488.1.00007f9c94ec5000.00007f9c94ec7000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f9c94ec7000
|
Size: |
8192
|
|
7f9b9003c000
|
|
page execute read
|
|
|
|
Name: |
5488.1.00007f9b90017000.00007f9b9003c000.r-x.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page execute read
|
Base address: |
7f9b9003c000
|
Size: |
151552
|
|
55a274a20000
|
|
page read and write
|
|
|
|
Name: |
5488.1.000055a2748f2000.000055a274a20000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
55a274a20000
|
Size: |
1236992
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
7f9c95b0f000
|
|
page read and write
|
|
|
|
Name: |
5488.1.00007f9c95b0e000.00007f9c95b0f000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f9c95b0f000
|
Size: |
4096
|
|
7ffd6f431000
|
|
page read and write
|
|
|
|
Name: |
5488.1.00007ffd6f410000.00007ffd6f431000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7ffd6f431000
|
Size: |
135168
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
7ffd6f4c6000
|
|
page execute read
|
|
|
|
Name: |
5488.1.00007ffd6f4c5000.00007ffd6f4c6000.r-x.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page execute read
|
Base address: |
7ffd6f4c6000
|
Size: |
4096
|
|
7f9c95494000
|
|
page read and write
|
|
|
|
Name: |
5488.1.00007f9c95490000.00007f9c95494000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f9c95494000
|
Size: |
16384
|
|
7f9c954b7000
|
|
page read and write
|
|
|
|
Name: |
5488.1.00007f9c954b3000.00007f9c954b7000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f9c954b7000
|
Size: |
16384
|
|
7f9b90055000
|
|
page read and write
|
|
|
|
Name: |
5488.1.00007f9b90048000.00007f9b90055000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f9b90055000
|
Size: |
53248
|
|
55a27184a000
|
|
page execute read
|
|
|
|
Name: |
5488.1.000055a271699000.000055a27184a000.r-x.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page execute read
|
Base address: |
55a27184a000
|
Size: |
1773568
|
|
55a273aa2000
|
|
page execute and read and write
|
|
|
|
Name: |
5488.1.000055a271aa4000.000055a273aa2000.rwx.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page execute and read and write
|
Base address: |
55a273aa2000
|
Size: |
33546240
|
|
7f9c95623000
|
|
page read and write
|
|
|
|
Name: |
5488.1.00007f9c95621000.00007f9c95623000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f9c95623000
|
Size: |
8192
|
|
7f9c95b78000
|
|
page read and write
|
|
|
|
Name: |
5488.1.00007f9c95b77000.00007f9c95b78000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f9c95b78000
|
Size: |
4096
|
|
55a273ab9000
|
|
page read and write
|
|
|
|
Name: |
5488.1.000055a273aa3000.000055a273ab9000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
55a273ab9000
|
Size: |
90112
|
|
7f9c8ffff000
|
|
page read and write
|
|
|
|
Name: |
5488.1.00007f9c8f7ff000.00007f9c8ffff000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f9c8ffff000
|
Size: |
8388608
|
|
7f9c94e35000
|
|
page read and write
|
|
|
|
Name: |
5488.1.00007f9c9462e000.00007f9c94e35000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f9c94e35000
|
Size: |
8417280
|
|
7f9c95229000
|
|
page read and write
|
|
|
|
Name: |
5488.1.00007f9c95227000.00007f9c95229000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f9c95229000
|
Size: |
8192
|
|
7f9c90021000
|
|
page read and write
|
|
|
|
Name: |
5488.1.00007f9c90000000.00007f9c90021000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f9c90021000
|
Size: |
135168
|
|
7f9c95805000
|
|
page read and write
|
|
|
|
Name: |
5488.1.00007f9c95802000.00007f9c95805000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f9c95805000
|
Size: |
12288
|
|
7f9c9462d000
|
|
page read and write
|
|
|
|
Name: |
5488.1.00007f9c945ac000.00007f9c9462d000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f9c9462d000
|
Size: |
528384
|
|
7f9c959e6000
|
|
page read and write
|
|
|
|
Name: |
5488.1.00007f9c959e4000.00007f9c959e6000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f9c959e6000
|
Size: |
8192
|
|