8304000
|
heap
|
page read and write
|
 |
|
|
Name: |
00000005.00000002.3383686166.0000000008304000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8304000
|
Size: |
159744
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
82A6000
|
heap
|
page read and write
|
 |
|
|
Name: |
00000005.00000002.3383234275.00000000082A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
82A6000
|
Size: |
122880
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
URLs found in memory or binary data |
Networking |
|
|
2B83000
|
heap
|
page read and write
|
 |
|
|
Name: |
00000005.00000002.3354236670.0000000002B83000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B83000
|
Size: |
253952
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
832C000
|
heap
|
page read and write
|
 |
|
|
Name: |
00000005.00000002.3383686166.000000000832C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
832C000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
1CDD977000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016160844.0000001CDD977000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDD977000
|
Size: |
24576
|
|
2A50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3353493196.0000000002A50000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A50000
|
Size: |
4096
|
|
1E6B21B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1063776151.000001E6B21B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E6B21B0000
|
Size: |
4096
|
|
5B07000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3371052055.0000000005B07000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5B07000
|
Size: |
4096
|
|
1E697F90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016900726.000001E697F90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697F90000
|
Size: |
4096
|
|
2AE0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3354117918.0000000002AE0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2AE0000
|
Size: |
4096
|
|
7FF9368D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1066865881.00007FF9368D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF9368D0000
|
Size: |
65536
|
|
6F20000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377077820.0000000006F20000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
6F20000
|
Size: |
4096
|
|
1E69BB18000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69BB18000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69BB18000
|
Size: |
6545408
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2DE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3356144782.0000000002DE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DE0000
|
Size: |
32768
|
|
80A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3381958608.00000000080A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
80A0000
|
Size: |
4096
|
|
1E6B21D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1063879880.000001E6B21D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E6B21D5000
|
Size: |
241664
|
|
1E699870000
|
heap
|
page readonly
|
|
|
|
Name: |
00000002.00000002.1017065857.000001E699870000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
1E699870000
|
Size: |
4096
|
|
1E699E50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017361007.000001E699E50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E699E50000
|
Size: |
454656
|
|
2E20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3356553774.0000000002E20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E20000
|
Size: |
4096
|
|
2E99000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3356954166.0000000002E99000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E99000
|
Size: |
16384
|
|
7FF9367E6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1066207146.00007FF9367E6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF9367E6000
|
Size: |
24576
|
|
7FF936A50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1070421208.00007FF936A50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936A50000
|
Size: |
16384
|
|
1B262513000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815499087.000001B262513000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262513000
|
Size: |
12288
|
|
1E697E85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016641154.000001E697E85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697E85000
|
Size: |
8192
|
|
1B267B02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815888533.000001B267B02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267B02000
|
Size: |
4096
|
|
724A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377683667.000000000724A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
724A000
|
Size: |
49152
|
|
2A60000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3353556911.0000000002A60000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A60000
|
Size: |
4096
|
|
1B267950000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1203242318.000001B267950000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267950000
|
Size: |
8192
|
|
2A90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3353730581.0000000002A90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A90000
|
Size: |
4096
|
|
2E80000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3356855288.0000000002E80000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2E80000
|
Size: |
65536
|
|
1E69A6BB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69A6BB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69A6BB000
|
Size: |
102400
|
|
7580000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3380247331.0000000007580000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7580000
|
Size: |
65536
|
|
1B267A55000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815670292.000001B267A55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267A55000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2DD4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3355875168.0000000002DD4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DD4000
|
Size: |
36864
|
|
2DDD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3355936247.0000000002DDD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2DDD000
|
Size: |
12288
|
|
1E6AA000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1050074809.000001E6AA000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E6AA000000
|
Size: |
2560000
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1B267921000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1266092937.000001B267921000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267921000
|
Size: |
4096
|
|
8640000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3384662646.0000000008640000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
8640000
|
Size: |
36864
|
|
2A20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2231797888.0000000002A20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A20000
|
Size: |
4096
|
|
7FF9367E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1066167271.00007FF9367E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF9367E0000
|
Size: |
8192
|
|
7FF936940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1068359474.00007FF936940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936940000
|
Size: |
65536
|
|
1E697E83000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016641154.000001E697E83000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697E83000
|
Size: |
4096
|
|
1B262400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815178508.000001B262400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262400000
|
Size: |
73728
|
|
1E69A984000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69A984000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69A984000
|
Size: |
2912256
|
|
1E69ADBD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69ADBD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69ADBD000
|
Size: |
876544
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1B263240000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814162675.000001B263240000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B263240000
|
Size: |
4096
|
|
1B267A62000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815718399.000001B267A62000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267A62000
|
Size: |
188416
|
|
FD087E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000008.00000002.2814854388.0000000FD087E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FD087E000
|
Size: |
4096
|
|
1B262517000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815499087.000001B262517000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262517000
|
Size: |
8192
|
|
1B267C70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814306012.000001B267C70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267C70000
|
Size: |
4096
|
|
8270000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3383234275.0000000008270000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8270000
|
Size: |
8192
|
|
1E6B20D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1063604522.000001E6B20D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E6B20D0000
|
Size: |
24576
|
|
A254000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3384952891.000000000A254000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
A254000
|
Size: |
4907008
|
|
53EE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357849866.00000000053EE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53EE000
|
Size: |
339968
|
|
1B267CC0000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1204594124.000001B267CC0000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
1B267CC0000
|
Size: |
4096
|
|
1E69ADA4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69ADA4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69ADA4000
|
Size: |
61440
|
|
1B262490000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815311811.000001B262490000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262490000
|
Size: |
8192
|
|
2E90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3356954166.0000000002E90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E90000
|
Size: |
32768
|
|
1B267C30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2810293105.000001B267C30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267C30000
|
Size: |
4096
|
|
5961000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3371052055.0000000005961000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5961000
|
Size: |
36864
|
|
8E54000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3384952891.0000000008E54000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
8E54000
|
Size: |
10485760
|
|
7FF93673D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1065988866.00007FF93673D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FF93673D000
|
Size: |
12288
|
|
1E6AA299000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1050074809.000001E6AA299000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E6AA299000
|
Size: |
1507328
|
|
2D70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3355597893.0000000002D70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D70000
|
Size: |
4096
|
|
7570000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3380138303.0000000007570000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7570000
|
Size: |
65536
|
|
7530000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3379708861.0000000007530000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7530000
|
Size: |
65536
|
|
73D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3379122436.00000000073D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
73D0000
|
Size: |
61440
|
|
1B267900000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2813925690.000001B267900000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267900000
|
Size: |
4096
|
|
1E699E24000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017361007.000001E699E24000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E699E24000
|
Size: |
8192
|
|
863E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3384632855.000000000863E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
863E000
|
Size: |
8192
|
|
4950000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3357825096.0000000004950000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
4950000
|
Size: |
4096
|
|
1E699E11000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017271160.000001E699E11000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E699E11000
|
Size: |
24576
|
|
47DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357519087.00000000047DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
47DF000
|
Size: |
4096
|
|
715E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377595821.000000000715E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
715E000
|
Size: |
8192
|
|
4AB6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357849866.0000000004AB6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4AB6000
|
Size: |
9658368
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
1B267989000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1203090818.000001B267989000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267989000
|
Size: |
28672
|
|
1E69AECD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69AECD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69AECD000
|
Size: |
1032192
|
|
1E6A9FA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1050074809.000001E6A9FA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E6A9FA0000
|
Size: |
376832
|
|
71E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377683667.00000000071E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
71E9000
|
Size: |
4096
|
|
1E697E3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016641154.000001E697E3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697E3D000
|
Size: |
36864
|
|
1E699860000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017046321.000001E699860000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E699860000
|
Size: |
20480
|
|
2DB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3355680547.0000000002DB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DB0000
|
Size: |
16384
|
|
2AA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3353790370.0000000002AA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AA0000
|
Size: |
24576
|
|
6BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000011.00000002.2232355874.00000000006BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
17
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BE000
|
Size: |
8192
|
|
80C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3382053466.00000000080C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
80C0000
|
Size: |
49152
|
|
2D50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3355566943.0000000002D50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D50000
|
Size: |
4096
|
|
1E6B225E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1063879880.000001E6B225E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E6B225E000
|
Size: |
36864
|
|
702000
|
heap
|
page read and write
|
|
|
|
Name: |
00000011.00000002.2232415888.0000000000702000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
17
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
702000
|
Size: |
20480
|
|
1B262494000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815311811.000001B262494000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262494000
|
Size: |
40960
|
|
7FF936A10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1069970185.00007FF936A10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936A10000
|
Size: |
65536
|
|
7257000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377683667.0000000007257000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7257000
|
Size: |
77824
|
|
2B4F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3354236670.0000000002B4F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B4F000
|
Size: |
155648
|
|
1B26242B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815228644.000001B26242B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B26242B000
|
Size: |
81920
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
489D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357613226.000000000489D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
489D000
|
Size: |
12288
|
|
1B267A70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1203216246.000001B267A70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267A70000
|
Size: |
4096
|
|
7FF936950000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1068471403.00007FF936950000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936950000
|
Size: |
65536
|
|
2D30000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3355530233.0000000002D30000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D30000
|
Size: |
4096
|
|
2D20000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3355512871.0000000002D20000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D20000
|
Size: |
4096
|
|
1B267B06000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815888533.000001B267B06000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267B06000
|
Size: |
4096
|
|
1B26245B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815282720.000001B26245B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B26245B000
|
Size: |
65536
|
|
467E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357082695.000000000467E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
467E000
|
Size: |
8192
|
|
AE47000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3434958472.000000000AE47000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
AE47000
|
Size: |
4096
|
|
FCFE8B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2814740491.0000000FCFE8B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FCFE8B000
|
Size: |
20480
|
|
7DF486450000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1065758749.00007DF486450000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7DF486450000
|
Size: |
4096
|
|
1CDD87E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016118254.0000001CDD87E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDD87E000
|
Size: |
8192
|
|
7510000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3379479133.0000000007510000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7510000
|
Size: |
65536
|
|
5B0D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3371052055.0000000005B0D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5B0D000
|
Size: |
1302528
|
|
1CDD6FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016058232.0000001CDD6FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDD6FE000
|
Size: |
8192
|
|
1B262473000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814473607.000001B262473000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262473000
|
Size: |
4096
|
|
1B262F00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814323770.000001B262F00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B262F00000
|
Size: |
4096
|
|
1E69A01C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69A01C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69A01C000
|
Size: |
1671168
|
|
2D10000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3355496126.0000000002D10000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D10000
|
Size: |
4096
|
|
1B267A2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815630981.000001B267A2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267A2F000
|
Size: |
65536
|
|
7FF936AC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1071174069.00007FF936AC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936AC0000
|
Size: |
16384
|
|
1CDDA37000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016220302.0000001CDDA37000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDDA37000
|
Size: |
36864
|
|
1B262D13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814432732.000001B262D13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262D13000
|
Size: |
28672
|
|
1E697E90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016859168.000001E697E90000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697E90000
|
Size: |
4096
|
|
27D8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3353413085.00000000027D8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
27D8000
|
Size: |
32768
|
|
630000
|
heap
|
page read and write
|
|
|
|
Name: |
00000011.00000002.2232300725.0000000000630000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
17
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
630000
|
Size: |
4096
|
|
FD0477000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2814769638.0000000FD0477000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FD0477000
|
Size: |
36864
|
|
1B262502000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2813961712.000001B262502000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262502000
|
Size: |
40960
|
|
1E6B229E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1065274347.000001E6B229E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E6B229E000
|
Size: |
8192
|
|
6E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000011.00000002.2232415888.00000000006E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
17
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6E0000
|
Size: |
24576
|
|
1B263480000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814027092.000001B263480000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B263480000
|
Size: |
4096
|
|
1E69AE99000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69AE99000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69AE99000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2E6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3356762651.0000000002E6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E6E000
|
Size: |
8192
|
|
80E9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3382291221.00000000080E9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
80E9000
|
Size: |
28672
|
|
4910000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357754365.0000000004910000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4910000
|
Size: |
4096
|
|
1B267A43000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815630981.000001B267A43000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267A43000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
1E698010000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016944531.000001E698010000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E698010000
|
Size: |
12288
|
|
7FF936A70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1070626402.00007FF936A70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936A70000
|
Size: |
36864
|
|
1E697DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016499667.000001E697DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697DA5000
|
Size: |
466944
|
|
7520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3379580446.0000000007520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7520000
|
Size: |
61440
|
|
7FF936980000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1068823092.00007FF936980000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936980000
|
Size: |
65536
|
|
2CFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2231967593.0000000002CFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2CFE000
|
Size: |
8192
|
|
7FF936A20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1070109979.00007FF936A20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936A20000
|
Size: |
65536
|
|
1E6998B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017080528.000001E6998B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E6998B0000
|
Size: |
20480
|
|
8660000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3384783894.0000000008660000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8660000
|
Size: |
8192
|
|
1E697FD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016928998.000001E697FD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697FD0000
|
Size: |
4096
|
|
2AA7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3353790370.0000000002AA7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AA7000
|
Size: |
16384
|
|
1E699DB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017253318.000001E699DB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E699DB0000
|
Size: |
4096
|
|
4920000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357777614.0000000004920000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4920000
|
Size: |
4096
|
|
1B262529000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815530721.000001B262529000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262529000
|
Size: |
4096
|
|
1B2623A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815159095.000001B2623A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B2623A0000
|
Size: |
4096
|
|
80F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3382419168.00000000080F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
80F0000
|
Size: |
65536
|
|
8090000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3381905729.0000000008090000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8090000
|
Size: |
4096
|
|
1B267ADD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815812119.000001B267ADD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267ADD000
|
Size: |
20480
|
|
7550000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3379928517.0000000007550000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7550000
|
Size: |
65536
|
|
7FF936AA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1070968558.00007FF936AA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936AA0000
|
Size: |
65536
|
|
8130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3382520689.0000000008130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8130000
|
Size: |
16384
|
|
48DC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357646036.00000000048DC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
48DC000
|
Size: |
16384
|
|
1E69ADB4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69ADB4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69ADB4000
|
Size: |
32768
|
|
7FF936930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1068161773.00007FF936930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936930000
|
Size: |
65536
|
|
1E6998F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017130080.000001E6998F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E6998F0000
|
Size: |
65536
|
|
7FF936990000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1068918548.00007FF936990000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936990000
|
Size: |
65536
|
|
6F30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377101833.0000000006F30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6F30000
|
Size: |
36864
|
|
1CDE88D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016435750.0000001CDE88D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDE88D000
|
Size: |
12288
|
|
1CDD36E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016000818.0000001CDD36E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDD36E000
|
Size: |
8192
|
|
4961000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357849866.0000000004961000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4961000
|
Size: |
380928
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1B267AF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815873341.000001B267AF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267AF4000
|
Size: |
8192
|
|
827B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3383234275.000000000827B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
827B000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
471E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357245247.000000000471E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
471E000
|
Size: |
8192
|
|
1E69A533000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69A533000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69A533000
|
Size: |
12288
|
|
1B262370000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815139873.000001B262370000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262370000
|
Size: |
4096
|
|
2C10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000011.00000002.2232584392.0000000002C10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
17
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C10000
|
Size: |
12288
|
|
7FF936915000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1067418875.00007FF936915000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936915000
|
Size: |
4096
|
|
FD0F7B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2814932510.0000000FD0F7B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FD0F7B000
|
Size: |
20480
|
|
1B2624FF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815449417.000001B2624FF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B2624FF000
|
Size: |
8192
|
|
1E6B2268000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1063879880.000001E6B2268000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E6B2268000
|
Size: |
94208
|
|
1E6B222C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1063879880.000001E6B222C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E6B222C000
|
Size: |
167936
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
1B267922000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2813906704.000001B267922000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267922000
|
Size: |
4096
|
|
7FF93674B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1066054829.00007FF93674B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF93674B000
|
Size: |
8192
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3356389489.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
4096
|
|
1B262D1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1251505023.000001B262D1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262D1A000
|
Size: |
4096
|
|
86F0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3384856259.00000000086F0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
86F0000
|
Size: |
24576
|
|
1B262413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815203372.000001B262413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262413000
|
Size: |
94208
|
|
8500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3384403035.0000000008500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8500000
|
Size: |
65536
|
|
74ED000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3379342633.00000000074ED000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
74ED000
|
Size: |
12288
|
|
2A80000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3353676582.0000000002A80000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A80000
|
Size: |
4096
|
|
5C4E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3371052055.0000000005C4E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5C4E000
|
Size: |
1523712
|
|
82C6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3383234275.00000000082C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
82C6000
|
Size: |
4096
|
|
1CDDAB9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016241456.0000001CDDAB9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDDAB9000
|
Size: |
28672
|
|
80D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3382218234.00000000080D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
80D0000
|
Size: |
16384
|
|
1B262D00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814418709.000001B262D00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262D00000
|
Size: |
4096
|
|
1E698030000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016981433.000001E698030000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E698030000
|
Size: |
16384
|
|
6D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000011.00000002.2232397472.00000000006D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
17
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6D0000
|
Size: |
4096
|
|
1B268000000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814448763.000001B268000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B268000000
|
Size: |
4096
|
|
1B262C00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815545862.000001B262C00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262C00000
|
Size: |
4096
|
|
721A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377683667.000000000721A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
721A000
|
Size: |
8192
|
|
2B10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3354236670.0000000002B10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B10000
|
Size: |
36864
|
|
1CDE78F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016395571.0000001CDE78F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDE78F000
|
Size: |
4096
|
|
1CDDDBB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016377637.0000001CDDDBB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDDDBB000
|
Size: |
20480
|
|
2B88000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2231875603.0000000002B88000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B88000
|
Size: |
24576
|
|
2D90000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3355624030.0000000002D90000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
2D90000
|
Size: |
4096
|
|
1CDD67E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016037711.0000001CDD67E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDD67E000
|
Size: |
8192
|
|
1B267AE9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815812119.000001B267AE9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267AE9000
|
Size: |
20480
|
|
1E6AA27B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1050074809.000001E6AA27B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E6AA27B000
|
Size: |
4096
|
|
7FB7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3381293482.0000000007FB7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7FB7000
|
Size: |
36864
|
|
FD107E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000008.00000002.2814959654.0000000FD107E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FD107E000
|
Size: |
4096
|
|
1E6B229A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1065192951.000001E6B229A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E6B229A000
|
Size: |
8192
|
|
75E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3380922023.00000000075E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
75E0000
|
Size: |
65536
|
|
7FF936960000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1068609561.00007FF936960000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936960000
|
Size: |
65536
|
|
2A70000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3353623165.0000000002A70000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A70000
|
Size: |
4096
|
|
84B0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3384264961.00000000084B0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
84B0000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
59C8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3371052055.00000000059C8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
59C8000
|
Size: |
1200128
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
276D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2231720382.000000000276D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
276D000
|
Size: |
12288
|
|
1E6B20B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1063604522.000001E6B20B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E6B20B0000
|
Size: |
12288
|
|
1B262502000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815449417.000001B262502000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262502000
|
Size: |
8192
|
|
1E699940000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017158461.000001E699940000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E699940000
|
Size: |
4096
|
|
481E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357558124.000000000481E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
481E000
|
Size: |
8192
|
|
7FF936740000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1066054829.00007FF936740000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936740000
|
Size: |
40960
|
|
2D40000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3355548109.0000000002D40000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D40000
|
Size: |
4096
|
|
1E697D90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016499667.000001E697D90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697D90000
|
Size: |
40960
|
|
2E05000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3356440297.0000000002E05000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2E05000
|
Size: |
45056
|
|
1E6B22A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1065322390.000001E6B22A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E6B22A6000
|
Size: |
4096
|
|
1B262506000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815449417.000001B262506000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262506000
|
Size: |
24576
|
|
FD0C7E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000008.00000002.2814907233.0000000FD0C7E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FD0C7E000
|
Size: |
4096
|
|
FD077E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2814823850.0000000FD077E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FD077E000
|
Size: |
8192
|
|
1B267AF1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815859131.000001B267AF1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267AF1000
|
Size: |
4096
|
|
7223000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377683667.0000000007223000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7223000
|
Size: |
155648
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
URLs found in memory or binary data |
Networking |
|
|
1B267A80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1203040185.000001B267A80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267A80000
|
Size: |
8192
|
|
1B2624FF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2813961712.000001B2624FF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B2624FF000
|
Size: |
8192
|
|
75D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3380815750.00000000075D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
75D0000
|
Size: |
65536
|
|
7FC0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3381439466.0000000007FC0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FC0000
|
Size: |
40960
|
|
8254000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3382935508.0000000008254000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8254000
|
Size: |
40960
|
|
251AD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3444973722.00000000251AD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
251AD000
|
Size: |
12288
|
|
479E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357466988.000000000479E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
479E000
|
Size: |
8192
|
|
1E69AC4C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69AC4C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69AC4C000
|
Size: |
1339392
|
|
2F10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2232026467.0000000002F10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F10000
|
Size: |
20480
|
|
808E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3381831325.000000000808E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
808E000
|
Size: |
8192
|
|
49BF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357849866.00000000049BF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
49BF000
|
Size: |
999424
|
|
2B80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2231875603.0000000002B80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B80000
|
Size: |
24576
|
|
2DE9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3356144782.0000000002DE9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DE9000
|
Size: |
16384
|
|
1E699DC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017271160.000001E699DC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E699DC0000
|
Size: |
270336
|
|
1B267920000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1223283550.000001B267920000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267920000
|
Size: |
4096
|
|
1B267F80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2809753018.000001B267F80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267F80000
|
Size: |
4096
|
|
1CDE90A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016458012.0000001CDE90A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDE90A000
|
Size: |
24576
|
|
1B267EF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814257238.000001B267EF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267EF0000
|
Size: |
4096
|
|
2CE0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3355441618.0000000002CE0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2CE0000
|
Size: |
4096
|
|
7FE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3381697556.0000000007FE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FE0000
|
Size: |
12288
|
|
1B267C00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814100476.000001B267C00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267C00000
|
Size: |
8192
|
|
7560000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3380034135.0000000007560000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7560000
|
Size: |
65536
|
|
6C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000011.00000002.2232378086.00000000006C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
17
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6C0000
|
Size: |
24576
|
|
6F40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377101833.0000000006F40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6F40000
|
Size: |
270336
|
|
71EB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377683667.00000000071EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
71EB000
|
Size: |
94208
|
|
2CD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000011.00000002.2232184234.00000000002CD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
17
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2CD000
|
Size: |
12288
|
|
75B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3380601390.00000000075B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
75B0000
|
Size: |
65536
|
|
7FF9369D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1069288506.00007FF9369D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF9369D0000
|
Size: |
65536
|
|
1E697E57000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016641154.000001E697E57000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697E57000
|
Size: |
36864
|
|
3CD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000011.00000002.2232229632.00000000003CD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
17
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3CD000
|
Size: |
12288
|
|
1B267910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2812355016.000001B267910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267910000
|
Size: |
4096
|
|
2E70000
|
heap
|
page readonly
|
|
|
|
Name: |
00000005.00000002.3356817633.0000000002E70000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
2E70000
|
Size: |
4096
|
|
7FF936920000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1067955014.00007FF936920000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FF936920000
|
Size: |
57344
|
|
2AD0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3354056468.0000000002AD0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2AD0000
|
Size: |
4096
|
|
1CDDC3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016303035.0000001CDDC3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDDC3E000
|
Size: |
8192
|
|
1CDD8FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016135666.0000001CDD8FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDD8FC000
|
Size: |
16384
|
|
1CDDCBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016338109.0000001CDDCBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDDCBE000
|
Size: |
8192
|
|
1B267CC0000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1204610626.000001B267CC0000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
1B267CC0000
|
Size: |
4096
|
|
726B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377683667.000000000726B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
726B000
|
Size: |
217088
|
|
2AC0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3354005758.0000000002AC0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2AC0000
|
Size: |
4096
|
|
1E697E21000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016641154.000001E697E21000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697E21000
|
Size: |
81920
|
|
2DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3355819504.0000000002DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DD0000
|
Size: |
12288
|
|
1E6B20A7000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1058358787.000001E6B20A7000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1E6B20A7000
|
Size: |
4096
|
|
1E699E4E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017361007.000001E699E4E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E699E4E000
|
Size: |
4096
|
|
1B2624A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815311811.000001B2624A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B2624A0000
|
Size: |
57344
|
|
1CDDB39000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016258969.0000001CDDB39000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDDB39000
|
Size: |
28672
|
|
1E69A1BB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69A1BB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69A1BB000
|
Size: |
3530752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
2E02000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3356410727.0000000002E02000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E02000
|
Size: |
12288
|
|
1B267950000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2812304413.000001B267950000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267950000
|
Size: |
4096
|
|
1B26248E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815311811.000001B26248E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B26248E000
|
Size: |
4096
|
|
1B262D04000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814371739.000001B262D04000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262D04000
|
Size: |
16384
|
|
2B6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2231847202.0000000002B6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B6E000
|
Size: |
8192
|
|
879C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3384910192.000000000879C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
879C000
|
Size: |
16384
|
|
1E69AEAC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69AEAC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69AEAC000
|
Size: |
4096
|
|
1B262C15000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815574099.000001B262C15000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262C15000
|
Size: |
4096
|
|
1B267C10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2810707933.000001B267C10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267C10000
|
Size: |
4096
|
|
1B262BC1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814008172.000001B262BC1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B262BC1000
|
Size: |
4096
|
|
1E697E3B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016641154.000001E697E3B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697E3B000
|
Size: |
4096
|
|
73E0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3379228862.00000000073E0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
73E0000
|
Size: |
4096
|
|
5989000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3371052055.0000000005989000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5989000
|
Size: |
176128
|
|
1B267991000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1203090818.000001B267991000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267991000
|
Size: |
28672
|
|
7FF936912000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1067418875.00007FF936912000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936912000
|
Size: |
8192
|
|
2DFA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3356364988.0000000002DFA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2DFA000
|
Size: |
4096
|
|
74AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3379316922.00000000074AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
74AE000
|
Size: |
8192
|
|
FD22FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815048128.0000000FD22FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FD22FE000
|
Size: |
8192
|
|
2A10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2231771530.0000000002A10000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A10000
|
Size: |
4096
|
|
2DD3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3355850247.0000000002DD3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2DD3000
|
Size: |
4096
|
|
705000
|
heap
|
page read and write
|
|
|
|
Name: |
00000011.00000003.2232105975.0000000000705000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
17
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
705000
|
Size: |
8192
|
|
1E699C9D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017175991.000001E699C9D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E699C9D000
|
Size: |
520192
|
|
4930000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357801454.0000000004930000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4930000
|
Size: |
4096
|
|
1B267C10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2810619604.000001B267C10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267C10000
|
Size: |
4096
|
|
FD057E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000008.00000002.2814798327.0000000FD057E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FD057E000
|
Size: |
4096
|
|
2D00000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3355478750.0000000002D00000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D00000
|
Size: |
4096
|
|
1E6B2211000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1063879880.000001E6B2211000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E6B2211000
|
Size: |
16384
|
|
7FD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3381555259.0000000007FD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FD0000
|
Size: |
65536
|
|
1B262C02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815545862.000001B262C02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262C02000
|
Size: |
4096
|
|
1E697E49000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016641154.000001E697E49000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697E49000
|
Size: |
4096
|
|
7F790000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3445189619.000000007F790000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7F790000
|
Size: |
4096
|
|
6E8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000011.00000002.2232415888.00000000006E8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
17
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6E8000
|
Size: |
45056
|
|
1E6B22BB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1065322390.000001E6B22BB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E6B22BB000
|
Size: |
53248
|
|
8D60000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3384952891.0000000008D60000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
8D60000
|
Size: |
475136
|
|
250EC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3444710770.00000000250EC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
250EC000
|
Size: |
16384
|
|
1CDD7FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016102047.0000001CDD7FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDD7FE000
|
Size: |
8192
|
|
1CDD97E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016160844.0000001CDD97E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDD97E000
|
Size: |
8192
|
|
1B267A22000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815590838.000001B267A22000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267A22000
|
Size: |
49152
|
|
1E69AE94000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69AE94000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69AE94000
|
Size: |
8192
|
|
1B2624AE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814519483.000001B2624AE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B2624AE000
|
Size: |
57344
|
|
1B267A91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815718399.000001B267A91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267A91000
|
Size: |
241664
|
|
1B262360000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815119024.000001B262360000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262360000
|
Size: |
4096
|
|
1E6B22AC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1065322390.000001E6B22AC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E6B22AC000
|
Size: |
57344
|
|
7FF9369F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1069473767.00007FF9369F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF9369F0000
|
Size: |
65536
|
|
71D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377683667.00000000071D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
71D0000
|
Size: |
65536
|
|
7FF936732000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1065813920.00007FF936732000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936732000
|
Size: |
4096
|
|
7FF936730000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1065813920.00007FF936730000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936730000
|
Size: |
4096
|
|
1B267AE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815812119.000001B267AE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267AE3000
|
Size: |
20480
|
|
1B267CC0000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1204574185.000001B267CC0000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
1B267CC0000
|
Size: |
4096
|
|
1E69B118000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69B118000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69B118000
|
Size: |
10485760
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
8339000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3383686166.0000000008339000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8339000
|
Size: |
135168
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
7FF9369C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1069189376.00007FF9369C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF9369C0000
|
Size: |
65536
|
|
1B2679F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814085090.000001B2679F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B2679F0000
|
Size: |
4096
|
|
2D3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2231999651.0000000002D3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D3E000
|
Size: |
8192
|
|
1E699830000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017026141.000001E699830000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E699830000
|
Size: |
4096
|
|
1E69AEB8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69AEB8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69AEB8000
|
Size: |
12288
|
|
1B267960000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1203284943.000001B267960000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267960000
|
Size: |
4096
|
|
1B267EB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2810123272.000001B267EB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267EB0000
|
Size: |
4096
|
|
82DA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3383234275.00000000082DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
82DA000
|
Size: |
4096
|
|
7FF936AB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1071078916.00007FF936AB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936AB0000
|
Size: |
32768
|
|
1E699E27000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017361007.000001E699E27000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E699E27000
|
Size: |
151552
|
|
FD197E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000008.00000002.2815019626.0000000FD197E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FD197E000
|
Size: |
4096
|
|
1E699E18000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017361007.000001E699E18000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E699E18000
|
Size: |
45056
|
|
7FF9368EA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1067073645.00007FF9368EA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF9368EA000
|
Size: |
24576
|
|
7FF9369B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1069106185.00007FF9369B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF9369B0000
|
Size: |
65536
|
|
7FF936900000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1067340741.00007FF936900000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FF936900000
|
Size: |
45056
|
|
FD237E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000008.00000002.2815077676.0000000FD237E000.00000002.00000001.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FD237E000
|
Size: |
4096
|
|
804E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3381761450.000000000804E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
804E000
|
Size: |
8192
|
|
1E6B2280000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1063879880.000001E6B2280000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E6B2280000
|
Size: |
102400
|
|
7FF936A40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1070314677.00007FF936A40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936A40000
|
Size: |
65536
|
|
82CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3383234275.00000000082CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
82CE000
|
Size: |
8192
|
|
5AF4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3371052055.0000000005AF4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5AF4000
|
Size: |
28672
|
|
7500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3379374811.0000000007500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7500000
|
Size: |
65536
|
|
1B2679F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1203713670.000001B2679F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B2679F0000
|
Size: |
4096
|
|
FD187C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2814986497.0000000FD187C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FD187C000
|
Size: |
16384
|
|
4688000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357127999.0000000004688000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4688000
|
Size: |
16384
|
|
1B267920000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1203090818.000001B267920000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267920000
|
Size: |
425984
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1B267B00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815888533.000001B267B00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267B00000
|
Size: |
4096
|
|
7FF9368F0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1067313199.00007FF9368F0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FF9368F0000
|
Size: |
4096
|
|
1E698015000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016944531.000001E698015000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E698015000
|
Size: |
24576
|
|
856C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3384513282.000000000856C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
856C000
|
Size: |
16384
|
|
2CF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3355460335.0000000002CF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2CF0000
|
Size: |
4096
|
|
67E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000011.00000002.2232323071.000000000067E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
17
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
67E000
|
Size: |
8192
|
|
1B267C20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2810496345.000001B267C20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267C20000
|
Size: |
4096
|
|
1E69A537000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69A537000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69A537000
|
Size: |
208896
|
|
746E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3379288183.000000000746E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
746E000
|
Size: |
8192
|
|
1CDD77B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016075349.0000001CDD77B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDD77B000
|
Size: |
20480
|
|
82CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3383234275.00000000082CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
82CA000
|
Size: |
4096
|
|
FD0B79000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2814881204.0000000FD0B79000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FD0B79000
|
Size: |
28672
|
|
1CDD2E5000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1015978918.0000001CDD2E5000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDD2E5000
|
Size: |
45056
|
|
8273000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3383234275.0000000008273000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8273000
|
Size: |
12288
|
|
7FF936816000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1066648995.00007FF936816000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FF936816000
|
Size: |
86016
|
|
4900000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3357683849.0000000004900000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
4900000
|
Size: |
12288
|
|
1B262440000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815255117.000001B262440000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262440000
|
Size: |
106496
|
|
7FF936A80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1070690759.00007FF936A80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936A80000
|
Size: |
65536
|
|
1E697E88000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016641154.000001E697E88000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697E88000
|
Size: |
28672
|
|
7FF936970000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1068719447.00007FF936970000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936970000
|
Size: |
65536
|
|
1E69AD94000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69AD94000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69AD94000
|
Size: |
61440
|
|
75A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3380479393.00000000075A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
75A0000
|
Size: |
65536
|
|
1E6B20A0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1058358787.000001E6B20A0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1E6B20A0000
|
Size: |
20480
|
|
1E69AEAA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69AEAA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69AEAA000
|
Size: |
4096
|
|
1B267ACE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815718399.000001B267ACE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267ACE000
|
Size: |
4096
|
|
85AB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3384552415.00000000085AB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
85AB000
|
Size: |
20480
|
|
1E69A6D5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69A6D5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69A6D5000
|
Size: |
2424832
|
|
2AB0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3353946269.0000000002AB0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2AB0000
|
Size: |
4096
|
|
7FF9369E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1069385255.00007FF9369E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF9369E0000
|
Size: |
65536
|
|
1B267C50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814115965.000001B267C50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267C50000
|
Size: |
4096
|
|
1CDD9BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016199648.0000001CDD9BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDD9BE000
|
Size: |
8192
|
|
72A9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377683667.00000000072A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
72A9000
|
Size: |
155648
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
719F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377658528.000000000719F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
719F000
|
Size: |
4096
|
|
1E699E07000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017271160.000001E699E07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E699E07000
|
Size: |
36864
|
|
1E698035000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016981433.000001E698035000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E698035000
|
Size: |
40960
|
|
7FF936A60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1070463303.00007FF936A60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936A60000
|
Size: |
65536
|
|
1E699F91000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E699F91000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E699F91000
|
Size: |
557056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8650000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3384725159.0000000008650000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8650000
|
Size: |
32768
|
|
1E6B1F90000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1057363458.000001E6B1F90000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1E6B1F90000
|
Size: |
4096
|
|
7FF9369A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1069019005.00007FF9369A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF9369A0000
|
Size: |
65536
|
|
1E699880000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017080528.000001E699880000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E699880000
|
Size: |
4096
|
|
7FF936A90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1070853473.00007FF936A90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936A90000
|
Size: |
65536
|
|
1B262D09000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814371739.000001B262D09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262D09000
|
Size: |
4096
|
|
1B267AD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815718399.000001B267AD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267AD0000
|
Size: |
49152
|
|
1CDD3EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016016702.0000001CDD3EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDD3EE000
|
Size: |
8192
|
|
2B1B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3354236670.0000000002B1B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B1B000
|
Size: |
159744
|
|
1E6B21CC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1063879880.000001E6B21CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E6B21CC000
|
Size: |
32768
|
|
9854000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3384952891.0000000009854000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
9854000
|
Size: |
10485760
|
|
7FF936917000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1067418875.00007FF936917000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936917000
|
Size: |
4096
|
|
4905000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3357683849.0000000004905000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
4905000
|
Size: |
16384
|
|
7FF936733000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1065881911.00007FF936733000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FF936733000
|
Size: |
4096
|
|
1B2624BD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815434440.000001B2624BD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B2624BD000
|
Size: |
4096
|
|
1B267A5B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815670292.000001B267A5B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267A5B000
|
Size: |
24576
|
|
1B267940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814145133.000001B267940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267940000
|
Size: |
4096
|
|
7540000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3379824921.0000000007540000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7540000
|
Size: |
65536
|
|
2B3F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000011.00000002.2232540749.0000000002B3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
17
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B3F000
|
Size: |
4096
|
|
1E69AEBC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69AEBC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69AEBC000
|
Size: |
16384
|
|
704000
|
heap
|
page read and write
|
|
|
|
Name: |
00000011.00000003.2231331446.0000000000704000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
17
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
704000
|
Size: |
4096
|
|
7590000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3380363256.0000000007590000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7590000
|
Size: |
65536
|
|
8290000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3383234275.0000000008290000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8290000
|
Size: |
4096
|
|
1E69AFCB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69AFCB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69AFCB000
|
Size: |
1355776
|
|
2DC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3355744225.0000000002DC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC0000
|
Size: |
20480
|
|
1B2638A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2813943474.000001B2638A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B2638A0000
|
Size: |
4096
|
|
2A50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2231821758.0000000002A50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A50000
|
Size: |
20480
|
|
80B0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3381998577.00000000080B0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
80B0000
|
Size: |
12288
|
|
279C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3353324577.000000000279C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
279C000
|
Size: |
16384
|
|
2AF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3354175575.0000000002AF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AF0000
|
Size: |
12288
|
|
1CDE98B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016478361.0000001CDE98B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDE98B000
|
Size: |
20480
|
|
1B262BF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814275017.000001B262BF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B262BF0000
|
Size: |
4096
|
|
8680000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3384811818.0000000008680000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
8680000
|
Size: |
4096
|
|
1E697E37000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016641154.000001E697E37000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697E37000
|
Size: |
4096
|
|
7FF936A00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1069568050.00007FF936A00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936A00000
|
Size: |
65536
|
|
1E6B22A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1065322390.000001E6B22A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E6B22A2000
|
Size: |
12288
|
|
7FF936850000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1066769089.00007FF936850000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FF936850000
|
Size: |
61440
|
|
8235000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3382713087.0000000008235000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8235000
|
Size: |
36864
|
|
6F00000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377006967.0000000006F00000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
6F00000
|
Size: |
4096
|
|
1B262D1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1260020577.000001B262D1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262D1A000
|
Size: |
4096
|
|
1B262478000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814473607.000001B262478000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262478000
|
Size: |
12288
|
|
6F10000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377053678.0000000006F10000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
6F10000
|
Size: |
4096
|
|
2DA0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3355652463.0000000002DA0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
2DA0000
|
Size: |
4096
|
|
1B267A50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815670292.000001B267A50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267A50000
|
Size: |
8192
|
|
1B26247C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815311811.000001B26247C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B26247C000
|
Size: |
4096
|
|
7FF936A30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1070218596.00007FF936A30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936A30000
|
Size: |
65536
|
|
80E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3382291221.00000000080E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
80E0000
|
Size: |
32768
|
|
1E697D9B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016499667.000001E697D9B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697D9B000
|
Size: |
36864
|
|
1E69A926000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69A926000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69A926000
|
Size: |
380928
|
|
1E6AA289000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1050074809.000001E6AA289000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E6AA289000
|
Size: |
8192
|
|
1E6B221A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1063879880.000001E6B221A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E6B221A000
|
Size: |
69632
|
|
8250000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3382935508.0000000008250000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8250000
|
Size: |
12288
|
|
2A3E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000011.00000002.2232491468.0000000002A3E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
17
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2A3E000
|
Size: |
8192
|
|
1B267A00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815590838.000001B267A00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B267A00000
|
Size: |
122880
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF9367EC000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1066528943.00007FF9367EC000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FF9367EC000
|
Size: |
61440
|
|
2516F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3444926302.000000002516F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2516F000
|
Size: |
4096
|
|
1B267964000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1203284943.000001B267964000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267964000
|
Size: |
4096
|
|
1E697E39000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016641154.000001E697E39000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697E39000
|
Size: |
4096
|
|
8260000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3383101310.0000000008260000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8260000
|
Size: |
65536
|
|
1B2624B4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815413314.000001B2624B4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B2624B4000
|
Size: |
32768
|
|
8150000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3382689795.0000000008150000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8150000
|
Size: |
4096
|
|
84F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3384294740.00000000084F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
84F0000
|
Size: |
65536
|
|
1E699F80000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1017541392.000001E699F80000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1E699F80000
|
Size: |
4096
|
|
8140000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3382563869.0000000008140000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8140000
|
Size: |
65536
|
|
72E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3379072958.00000000072E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
72E1000
|
Size: |
8192
|
|
4750000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357407388.0000000004750000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4750000
|
Size: |
16384
|
|
1E69A51B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69A51B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69A51B000
|
Size: |
32768
|
|
1CDE80F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016415908.0000001CDE80F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDE80F000
|
Size: |
4096
|
|
1CDDBBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016276649.0000001CDDBBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDDBBE000
|
Size: |
8192
|
|
1E69A526000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69A526000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69A526000
|
Size: |
8192
|
|
46DC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357190210.00000000046DC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
46DC000
|
Size: |
16384
|
|
2BC8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3354236670.0000000002BC8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2BC8000
|
Size: |
290816
|
|
75C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3380714112.00000000075C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
75C0000
|
Size: |
65536
|
|
1E69A6B9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69A6B9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69A6B9000
|
Size: |
4096
|
|
1B2678A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814290616.000001B2678A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B2678A0000
|
Size: |
4096
|
|
762B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3381024254.000000000762B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
762B000
|
Size: |
20480
|
|
1E697F70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016879378.000001E697F70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697F70000
|
Size: |
16384
|
|
2B77000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3354236670.0000000002B77000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B77000
|
Size: |
12288
|
|
8690000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3384832591.0000000008690000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
8690000
|
Size: |
4096
|
|
8240000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3382779930.0000000008240000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8240000
|
Size: |
65536
|
|
2DF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3356327976.0000000002DF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DF0000
|
Size: |
4096
|
|
71E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377683667.00000000071E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
71E1000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1B267C60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814130275.000001B267C60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B267C60000
|
Size: |
4096
|
|
1E69A56C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017565035.000001E69A56C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E69A56C000
|
Size: |
1355776
|
|
7FF9368E1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1067073645.00007FF9368E1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF9368E1000
|
Size: |
32768
|
|
85FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3384601896.00000000085FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
85FE000
|
Size: |
8192
|
|
27AD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2231746158.00000000027AD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
27AD000
|
Size: |
12288
|
|
1B262340000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.2815099656.000001B262340000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262340000
|
Size: |
12288
|
|
485E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357586536.000000000485E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
485E000
|
Size: |
8192
|
|
720A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3377683667.000000000720A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
720A000
|
Size: |
4096
|
|
1B262D02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.2814371739.000001B262D02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B262D02000
|
Size: |
4096
|
|
1CDDD3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016360697.0000001CDDD3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1CDDD3E000
|
Size: |
8192
|
|
251EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3445058915.00000000251EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
251EF000
|
Size: |
4096
|
|
2DC8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3355744225.0000000002DC8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC8000
|
Size: |
8192
|
|
7FF936734000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1065905223.00007FF936734000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FF936734000
|
Size: |
36864
|
|
2CBF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.2231938250.0000000002CBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2CBF000
|
Size: |
4096
|
|
1E697E18000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1016499667.000001E697E18000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E697E18000
|
Size: |
24576
|
|
2B43000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3354236670.0000000002B43000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B43000
|
Size: |
45056
|
|
2512D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3444856872.000000002512D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2512D000
|
Size: |
12288
|
|
4720000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3357291224.0000000004720000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4720000
|
Size: |
65536
|
|
742E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3379261437.000000000742E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
742E000
|
Size: |
8192
|
|
1E6A9F91000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1050074809.000001E6A9F91000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E6A9F91000
|
Size: |
53248
|
|