3A40000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1033597823.0000000003A40000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3A40000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
2C40000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000003.00000002.3362772946.0000000002C40000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
2C40000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
2EE0000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000003.00000002.3363106058.0000000002EE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EE0000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
49F0000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000005.00000002.3366385136.00000000049F0000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
49F0000
|
Size: |
417792
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3780000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.3364674637.0000000003780000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3780000
|
Size: |
6426624
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
400000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1033133393.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
290816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
5350000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1034080368.0000000005350000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
5350000
|
Size: |
6426624
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3040000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000003.00000002.3364472057.0000000003040000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3040000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214261709.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
650000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3363642627.0000000000650000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
650000
|
Size: |
4096
|
|
2B36000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.0000000002B36000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2B36000
|
Size: |
8192
|
|
37C6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.00000000037C6000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
37C6000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3A0D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915624085.0000000003A0D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A0D000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
4006000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.0000000004006000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4006000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213179524.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
64E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3364018433.000000000064E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
64E000
|
Size: |
139264
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
500000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.3363376193.0000000000500000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
500000
|
Size: |
4096
|
|
5C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3363858177.00000000005C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C0000
|
Size: |
20480
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213148035.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1040069263.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3DB8000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3364674637.0000000003DB8000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3DB8000
|
Size: |
4096
|
|
7F9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364131819.00000000007F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F9000
|
Size: |
90112
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1211609482.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1211681285.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213582126.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
3634000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.0000000003634000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3634000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216804107.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
2284000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3364469203.0000000002284000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2284000
|
Size: |
4096
|
|
38E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.917243212.00000000038E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38E0000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
10A4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.906359614.00000000010A4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10A4000
|
Size: |
90112
|
|
910000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.945179517.0000000000910000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
910000
|
Size: |
32768
|
|
25BC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.00000000025BC000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
25BC000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217659334.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
19A73990000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336527429.0000019A73990000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19A73990000
|
Size: |
8192
|
|
7CE8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007CE8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CE8000
|
Size: |
4096
|
|
EAE000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.905279743.0000000000EAE000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
EAE000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214755115.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3090000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1046952905.0000000003090000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3090000
|
Size: |
159744
|
|
7CE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007CE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CE3000
|
Size: |
16384
|
|
2F56000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1033858628.0000000002F56000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F56000
|
Size: |
24576
|
|
63E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3363538247.000000000063E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63E000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215070535.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
AE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.917908294.0000000000AE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AE0000
|
Size: |
24576
|
|
30F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3364576703.00000000030F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F0000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214459620.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216149791.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217775742.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.942047254.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
3C7C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.0000000003C7C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3C7C000
|
Size: |
16384
|
|
EB7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.905330325.0000000000EB7000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EB7000
|
Size: |
552960
|
|
33732000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1334592778.0000000033732000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
33732000
|
Size: |
4096
|
|
32AB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1035701452.00000000032AB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32AB000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
120000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.3362942902.0000000000120000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
120000
|
Size: |
4096
|
|
10FF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.909351737.00000000010FF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10FF000
|
Size: |
12288
|
|
1116000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918992126.0000000001116000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1116000
|
Size: |
589824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217629382.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
83DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3367431449.00000000083DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83DF000
|
Size: |
4096
|
|
2F6B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000002F6B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F6B000
|
Size: |
176128
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215490282.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216660014.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
22E2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.00000000022E2000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
22E2000
|
Size: |
4096
|
|
37CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1033531435.00000000037CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
37CF000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214812144.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
ED0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1033248719.0000000000ED0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ED0000
|
Size: |
4096
|
|
4A58000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3366385136.0000000004A58000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4A58000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216861676.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
21E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364507791.00000000021E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21E0000
|
Size: |
12288
|
|
2FDD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000002FDD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FDD000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217421180.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
4E28000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.0000000004E28000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4E28000
|
Size: |
4096
|
|
3740000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916725943.0000000003740000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3740000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.1106925336.00000000001E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1E0000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1109877584.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110591379.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217950511.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.939078623.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
190000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3363282825.0000000000190000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
190000
|
Size: |
4096
|
|
55E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000000.945017614.000000000055E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
55E000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110557880.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3A40000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1002356684.0000000003A40000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A40000
|
Size: |
159744
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217390582.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
10AB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.909351737.00000000010AB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10AB000
|
Size: |
65536
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213700058.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217150775.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1218037157.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
A7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.917827010.0000000000A7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A7E000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213948464.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3A09000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916463274.0000000003A09000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A09000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1056238507.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3A09000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916051501.0000000003A09000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A09000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1056448801.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
180000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.944882684.0000000000180000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
180000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213508337.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110725955.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
19A755BE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1286406204.0000019A755BE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19A755BE000
|
Size: |
12288
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1218152381.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217570013.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
2FAB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000002FAB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FAB000
|
Size: |
8192
|
|
3A0D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915203201.0000000003A0D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A0D000
|
Size: |
458752
|
|
3A0D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916463274.0000000003A0D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A0D000
|
Size: |
458752
|
|
3310000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.0000000003310000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3310000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
20AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1107441460.00000000020AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
20AE000
|
Size: |
8192
|
|
4A71000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3366385136.0000000004A71000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4A71000
|
Size: |
4096
|
|
7CDF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007CDF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CDF000
|
Size: |
12288
|
|
1068000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918813911.0000000001068000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1068000
|
Size: |
192512
|
|
3700000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.921630428.0000000003700000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3700000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
19A7380F000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.1336343639.0000019A7380F000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
19A7380F000
|
Size: |
4096
|
|
6C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1107260602.00000000006C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6C0000
|
Size: |
20480
|
|
2F56000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1033898330.0000000002F56000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F56000
|
Size: |
24576
|
|
19A737A0000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.1336343639.0000019A737A0000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
19A737A0000
|
Size: |
409600
|
|
34A2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.00000000034A2000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
34A2000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110645493.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216968066.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
2FDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1033362137.0000000002FDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FDE000
|
Size: |
8192
|
|
510000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1107034064.0000000000510000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
510000
|
Size: |
4096
|
|
7CD8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1228882846.0000000007CD8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CD8000
|
Size: |
4096
|
|
1095000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.906070772.0000000001095000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1095000
|
Size: |
335872
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214568558.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
5F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1107061683.00000000005F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5F0000
|
Size: |
4096
|
|
321B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1033423958.000000000321B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
321B000
|
Size: |
512000
|
|
C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.944819936.00000000000C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C0000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1212398984.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
500000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000000.944994862.0000000000500000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
500000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110039546.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214940984.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
6C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3363975837.00000000006C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6C0000
|
Size: |
16384
|
|
4A7F000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3366385136.0000000004A7F000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4A7F000
|
Size: |
8192
|
|
60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.3362606740.0000000000060000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
60000
|
Size: |
4096
|
|
30E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3364537664.00000000030E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30E0000
|
Size: |
16384
|
|
6C6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3363975837.00000000006C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6C6000
|
Size: |
8192
|
|
33DF4000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1334592778.0000000033DF4000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
33DF4000
|
Size: |
8192
|
|
4B04000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.0000000004B04000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4B04000
|
Size: |
8192
|
|
3A8C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.0000000003A8C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3A8C000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1231158305.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
185E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.919063491.000000000185E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
185E000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1212497406.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3872000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.0000000003872000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3872000
|
Size: |
4096
|
|
3E0E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.0000000003E0E000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3E0E000
|
Size: |
8192
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.939168509.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
3F50000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1034080368.0000000003F50000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3F50000
|
Size: |
10485760
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214289962.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
DF0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.918620608.0000000000DF0000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
DF0000
|
Size: |
4096
|
|
6F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.3362769174.000000000006F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214971022.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
140000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.3363046361.0000000000140000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
140000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214541648.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
1AA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3363091552.00000000001AA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1AA000
|
Size: |
24576
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213311595.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
F20000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1033319303.0000000000F20000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
F20000
|
Size: |
278528
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217232800.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
1A0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3363360665.00000000001A0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1A0000
|
Size: |
4096
|
|
6A0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1107236749.00000000006A0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6A0000
|
Size: |
4096
|
|
72721FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336287270.00000072721FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
72721FE000
|
Size: |
8192
|
|
64E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000000.945110438.000000000064E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
64E000
|
Size: |
90112
|
|
3DCD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1033636351.0000000003DCD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3DCD000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214063913.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
F10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1033293125.0000000000F10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F10000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.935183900.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
10AA000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.918880279.00000000010AA000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
10AA000
|
Size: |
4096
|
|
684000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1107191196.0000000000684000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
684000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217804510.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
3863000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916725943.0000000003863000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3863000
|
Size: |
507904
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
3589000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3364782266.0000000003589000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3589000
|
Size: |
4096
|
|
3449000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1035701452.0000000003449000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3449000
|
Size: |
24576
|
|
2280000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000000.945250244.0000000002280000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2280000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214694285.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
19A752D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1284990415.0000019A752D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19A752D0000
|
Size: |
4096
|
|
7D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364131819.00000000007D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D0000
|
Size: |
32768
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215283450.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217050765.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3863000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915073225.0000000003863000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3863000
|
Size: |
507904
|
|
3C9E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1033636351.0000000003C9E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3C9E000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
180000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.3363239108.0000000000180000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
180000
|
Size: |
4096
|
|
79000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.3362880392.0000000000079000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
79000
|
Size: |
61440
|
|
7CFA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007CFA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CFA000
|
Size: |
12288
|
|
4A61000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3366385136.0000000004A61000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4A61000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.3362599932.0000000000060000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
60000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039927147.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
212992
|
|
160000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.944851930.0000000000160000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
160000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214783806.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
2F4D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1033774966.0000000002F4D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F4D000
|
Size: |
40960
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215130459.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
E3C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1033170585.0000000000E3C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E3C000
|
Size: |
16384
|
|
3A09000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915203201.0000000003A09000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A09000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216116943.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
120000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.1106827810.0000000000120000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
120000
|
Size: |
4096
|
|
8D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.1107371770.00000000008D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8D0000
|
Size: |
32768
|
|
560000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3363620498.0000000000560000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
560000
|
Size: |
8192
|
|
2FAB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1219421044.0000000002FAB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FAB000
|
Size: |
8192
|
|
500000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3363557031.0000000000500000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
500000
|
Size: |
4096
|
|
910000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.3364257539.0000000000910000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
910000
|
Size: |
32768
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217480911.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
E7F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.918702064.0000000000E7F000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E7F000
|
Size: |
147456
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1212533889.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
372D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3364782266.000000000372D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
372D000
|
Size: |
4096
|
|
358D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3364782266.000000000358D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
358D000
|
Size: |
458752
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1211842785.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1035932265.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
65536
|
|
2F9E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000002F9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F9E000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
640000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000000.945110438.0000000000640000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
640000
|
Size: |
32768
|
|
3E20000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3364674637.0000000003E20000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3E20000
|
Size: |
10485760
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214726139.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3A09000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916847109.0000000003A09000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A09000
|
Size: |
4096
|
|
2380000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3364674637.0000000002380000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
2380000
|
Size: |
10485760
|
|
72729FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336316083.00000072729FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
72729FF000
|
Size: |
4096
|
|
2F40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000002F40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F40000
|
Size: |
24576
|
|
4A7D000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3366385136.0000000004A7D000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4A7D000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1218632091.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
1AA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1106898253.00000000001AA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1AA000
|
Size: |
24576
|
|
7CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364080552.00000000007CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7CF000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215863446.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216888958.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110353148.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3C29000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1033636351.0000000003C29000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3C29000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214373887.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
31F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3364603232.00000000031F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31F0000
|
Size: |
94208
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216994910.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
9DB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.917696460.00000000009DB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9DB000
|
Size: |
20480
|
|
7CCB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1228882846.0000000007CCB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CCB000
|
Size: |
8192
|
|
7DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1107308086.00000000007DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7DE000
|
Size: |
90112
|
|
21B0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364470857.00000000021B0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
21B0000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1231122343.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1211719383.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
7CD6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007CD6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CD6000
|
Size: |
8192
|
|
3460000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3364782266.0000000003460000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3460000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7CB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1218372635.0000000007CB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CB0000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4820000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3364674637.0000000004820000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
4820000
|
Size: |
7282688
|
|
3405000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.921890284.0000000003405000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3405000
|
Size: |
49152
|
|
2FC5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000002FC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FC5000
|
Size: |
16384
|
|
19A75403000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336814809.0000019A75403000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19A75403000
|
Size: |
16384
|
|
7CC6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1228882846.0000000007CC6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CC6000
|
Size: |
8192
|
|
2FE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000002FE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FE3000
|
Size: |
4096
|
|
19A75300000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336766191.0000019A75300000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19A75300000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215934369.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.935445534.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.926942988.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
217088
|
|
38CC000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.00000000038CC000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
38CC000
|
Size: |
4096
|
|
3740000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915506186.0000000003740000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3740000
|
Size: |
1187840
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215223289.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
560000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000000.945033444.0000000000560000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
560000
|
Size: |
8192
|
|
2F97000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000002F97000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F97000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217449906.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
19A739C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336552547.0000019A739C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19A739C0000
|
Size: |
4096
|
|
19A73A12000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336571492.0000019A73A12000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19A73A12000
|
Size: |
24576
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217598840.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
CA1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.3364332876.0000000000CA1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
CA1000
|
Size: |
311296
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
76000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3362821669.0000000000076000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
76000
|
Size: |
8192
|
|
6B0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3363927336.00000000006B0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6B0000
|
Size: |
12288
|
|
2290000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.945330106.0000000002290000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2290000
|
Size: |
925696
|
|
160000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.3363143558.0000000000160000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
160000
|
Size: |
4096
|
|
4198000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.0000000004198000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4198000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
EA4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.905221992.0000000000EA4000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EA4000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
19A75501000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336989775.0000019A75501000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19A75501000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216215043.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
7CDB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007CDB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CDB000
|
Size: |
8192
|
|
2CC8000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.0000000002CC8000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2CC8000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4FBA000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.0000000004FBA000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4FBA000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.926868473.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
23A2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.00000000023A2000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23A2000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214839337.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
1F1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.944948980.00000000001F1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1F1000
|
Size: |
12288
|
|
19A755A5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1286447103.0000019A755A5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19A755A5000
|
Size: |
4096
|
|
4972000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.0000000004972000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4972000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7D05000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007D05000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D05000
|
Size: |
4096
|
|
22E2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1107604886.00000000022E2000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
22E2000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217832705.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215647318.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
38E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915203201.00000000038E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38E0000
|
Size: |
1196032
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1109952341.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217318928.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
3A7E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916051501.0000000003A7E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A7E000
|
Size: |
24576
|
|
7D3B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007D3B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D3B000
|
Size: |
4096
|
|
79000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.944774767.0000000000079000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
79000
|
Size: |
61440
|
|
19A75417000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336814809.0000019A75417000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19A75417000
|
Size: |
4096
|
|
3740000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916332446.0000000003740000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3740000
|
Size: |
1187840
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1231083441.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
684000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3363740142.0000000000684000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
684000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215779454.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
9FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.917696460.00000000009FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9FC000
|
Size: |
16384
|
|
76000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3362819092.0000000000076000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
76000
|
Size: |
8192
|
|
3863000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916332446.0000000003863000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3863000
|
Size: |
507904
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217861205.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
7FC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3367387749.0000000007FC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7FC0000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215462740.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1231038381.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
2D40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363049863.0000000002D40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D40000
|
Size: |
16384
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215405967.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
21F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.1107514066.00000000021F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
21F0000
|
Size: |
925696
|
|
3DD1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1033636351.0000000003DD1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3DD1000
|
Size: |
458752
|
|
CA0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.945197145.0000000000CA0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
CA0000
|
Size: |
315392
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
640000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3364018433.0000000000640000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
640000
|
Size: |
32768
|
|
DF1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.905169729.0000000000DF1000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
DF1000
|
Size: |
581632
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1211759930.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1218239064.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214234645.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
337F2000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1334592778.00000000337F2000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
337F2000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110405739.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
6290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366898896.0000000006290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6290000
|
Size: |
12288
|
|
3A0D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916051501.0000000003A0D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A0D000
|
Size: |
458752
|
|
1E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.3363142114.00000000001E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1E0000
|
Size: |
4096
|
|
590000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000000.945067806.0000000000590000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
590000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213848953.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
3030000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000003030000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3030000
|
Size: |
61440
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214008880.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
19A75412000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336814809.0000019A75412000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19A75412000
|
Size: |
4096
|
|
38E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916051501.00000000038E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38E0000
|
Size: |
1196032
|
|
CA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.917950311.0000000000CA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CA0000
|
Size: |
8192
|
|
4132000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.0000000004132000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4132000
|
Size: |
8192
|
|
3A40000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.938907484.0000000003A40000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A40000
|
Size: |
159744
|
|
33D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1035701452.00000000033D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33D4000
|
Size: |
4096
|
|
1EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000000.944932490.00000000001EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1EE000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216261525.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
1094000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.905791293.0000000001094000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1094000
|
Size: |
536576
|
|
7D28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007D28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D28000
|
Size: |
4096
|
|
DF1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.918643208.0000000000DF1000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
DF1000
|
Size: |
581632
|
|
23FC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.00000000023FC000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
23FC000
|
Size: |
4096
|
|
7CE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1228882846.0000000007CE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CE3000
|
Size: |
4096
|
|
3A0D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916847109.0000000003A0D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A0D000
|
Size: |
458752
|
|
7CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1107284020.00000000007CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7CF000
|
Size: |
4096
|
|
7D2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007D2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D2D000
|
Size: |
24576
|
|
10C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.906413316.00000000010C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10C0000
|
Size: |
225280
|
|
7D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1107308086.00000000007D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D0000
|
Size: |
32768
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1231002710.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
61000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000005.00000000.1106741568.0000000000061000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
61000
|
Size: |
57344
|
|
3731000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3364782266.0000000003731000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3731000
|
Size: |
458752
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217080032.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
6F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.1106759411.000000000006F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3501000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1033500261.0000000003501000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3501000
|
Size: |
4096
|
|
A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.3362940638.00000000000A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A0000
|
Size: |
4096
|
|
5988000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1034080368.0000000005988000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
5988000
|
Size: |
4096
|
|
9CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.917696460.00000000009CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9CF000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216834339.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.944805164.00000000000B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B0000
|
Size: |
4096
|
|
3958000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.0000000003958000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3958000
|
Size: |
4096
|
|
61000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000002.00000002.3362713228.0000000000061000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
61000
|
Size: |
57344
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214641584.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
DF0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.905130752.0000000000DF0000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
DF0000
|
Size: |
4096
|
|
44BC000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.00000000044BC000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
44BC000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1212431776.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
2284000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000000.945250244.0000000002284000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2284000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217921401.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213227768.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
590000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3363758379.0000000000590000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
590000
|
Size: |
4096
|
|
AC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.917878126.0000000000AC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AC0000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213551963.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214036212.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
301F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.000000000301F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
301F000
|
Size: |
12288
|
|
7DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364131819.00000000007DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7DE000
|
Size: |
94208
|
|
3823000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.921630428.0000000003823000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3823000
|
Size: |
507904
|
|
2D44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039975605.0000000002D44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D44000
|
Size: |
4096
|
|
76000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1106782373.0000000000076000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
76000
|
Size: |
8192
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.935568361.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
217088
|
|
3740000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.917110339.0000000003740000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3740000
|
Size: |
1187840
|
|
60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.944573949.0000000000060000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
60000
|
Size: |
4096
|
|
2FBF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000002FBF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FBF000
|
Size: |
16384
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217260447.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
2CC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3362864582.0000000002CC0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CC0000
|
Size: |
4096
|
|
10FF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.908630012.00000000010FF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10FF000
|
Size: |
12288
|
|
7E60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3367371001.0000000007E60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7E60000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215159130.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3B00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1033636351.0000000003B00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3B00000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3A09000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.917243212.0000000003A09000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A09000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214404191.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
76000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000000.944760662.0000000000076000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
76000
|
Size: |
8192
|
|
7CDE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1228882846.0000000007CDE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CDE000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4950000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1034080368.0000000004950000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4950000
|
Size: |
10485760
|
|
19A73A0F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336571492.0000019A73A0F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19A73A0F000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1218067358.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3014000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000003014000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3014000
|
Size: |
12288
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1218124568.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
2F52000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1033810666.0000000002F52000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F52000
|
Size: |
20480
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.942208984.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
217088
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214431971.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
2F5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1033636749.0000000002F5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F5C000
|
Size: |
20480
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216421098.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
670000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.1107166509.0000000000670000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
670000
|
Size: |
16384
|
|
90F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000000.945162154.000000000090F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
90F000
|
Size: |
4096
|
|
570000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.3363688076.0000000000570000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
570000
|
Size: |
16384
|
|
2FB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000002FB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FB1000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1218180207.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
2FA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1219421044.0000000002FA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FA0000
|
Size: |
4096
|
|
2C38000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3362714568.0000000002C38000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C38000
|
Size: |
32768
|
|
1136000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.905878153.0000000001136000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1136000
|
Size: |
4096
|
|
130000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.3362990545.0000000000130000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
130000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217177634.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.939249958.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
217088
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214898967.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213817828.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
2FC5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1219421044.0000000002FC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FC5000
|
Size: |
16384
|
|
3E42000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1033636351.0000000003E42000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3E42000
|
Size: |
40960
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1212288042.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
38E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916463274.00000000038E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38E0000
|
Size: |
1196032
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.942123838.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
4FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1106979983.00000000004FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4FC000
|
Size: |
16384
|
|
C60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.1107390842.0000000000C60000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C60000
|
Size: |
315392
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
9BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.917696460.00000000009BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9BF000
|
Size: |
4096
|
|
2FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000002FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF4000
|
Size: |
16384
|
|
3AEA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.0000000003AEA000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3AEA000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1218094860.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
A30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.917800779.0000000000A30000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A30000
|
Size: |
4096
|
|
33D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1035701452.00000000033D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33D8000
|
Size: |
458752
|
|
300B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.000000000300B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
300B000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217687332.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
29A4000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.00000000029A4000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
29A4000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214092980.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
E7B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1033193520.0000000000E7B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E7B000
|
Size: |
20480
|
|
2EE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039404452.0000000002EE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EE0000
|
Size: |
159744
|
|
3A0D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.917243212.0000000003A0D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A0D000
|
Size: |
458752
|
|
7DA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1107308086.00000000007DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7DA000
|
Size: |
8192
|
|
72709FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336210104.00000072709FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
72709FC000
|
Size: |
16384
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215102980.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213610135.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110289098.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3863000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915899021.0000000003863000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3863000
|
Size: |
507904
|
|
3417000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.921851181.0000000003417000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3417000
|
Size: |
20480
|
|
839E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3367409800.000000000839E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
839E000
|
Size: |
8192
|
|
79000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.3362879236.0000000000079000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
79000
|
Size: |
61440
|
|
19A75414000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336814809.0000019A75414000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19A75414000
|
Size: |
8192
|
|
3405000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.921820506.0000000003405000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3405000
|
Size: |
49152
|
|
1060000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918813911.0000000001060000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1060000
|
Size: |
24576
|
|
61000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000005.00000002.3362719355.0000000000061000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
61000
|
Size: |
57344
|
|
EA4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.918702064.0000000000EA4000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EA4000
|
Size: |
40960
|
|
2F51000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1033703387.0000000002F51000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F51000
|
Size: |
4096
|
|
338E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3364716715.000000000338E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
338E000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214514965.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
19A75421000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336814809.0000019A75421000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19A75421000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213757431.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1109915673.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
8D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.3364372832.00000000008D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8D0000
|
Size: |
32768
|
|
3863000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.917110339.0000000003863000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3863000
|
Size: |
507904
|
|
190000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000000.944897002.0000000000190000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
190000
|
Size: |
4096
|
|
4C96000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.0000000004C96000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4C96000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1109835393.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3A7E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915203201.0000000003A7E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A7E000
|
Size: |
24576
|
|
21AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000000.945232588.00000000021AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
21AF000
|
Size: |
4096
|
|
79000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.1106805324.0000000000079000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
79000
|
Size: |
61440
|
|
301B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.000000000301B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
301B000
|
Size: |
8192
|
|
680000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3363740142.0000000000680000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
680000
|
Size: |
8192
|
|
2F4B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1033858628.0000000002F4B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F4B000
|
Size: |
28672
|
|
33CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3364745410.00000000033CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33CE000
|
Size: |
8192
|
|
3A3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1033576105.0000000003A3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3A3E000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110244691.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215434831.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3A7E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916463274.0000000003A7E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A7E000
|
Size: |
24576
|
|
64A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3364018433.000000000064A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
64A000
|
Size: |
8192
|
|
570000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.945048186.0000000000570000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
570000
|
Size: |
16384
|
|
680000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1107191196.0000000000680000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
680000
|
Size: |
8192
|
|
3A2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.923734916.0000000003A2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3A2D000
|
Size: |
458752
|
|
19A739EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336571492.0000019A739EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19A739EA000
|
Size: |
16384
|
|
3CA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.917669010.00000000003CA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3CA000
|
Size: |
24576
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215343259.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
2F56000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1033943643.0000000002F56000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F56000
|
Size: |
24576
|
|
7CD1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1228882846.0000000007CD1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CD1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217538721.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
2F56000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1033662860.0000000002F56000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F56000
|
Size: |
24576
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216301260.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3090000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110793594.0000000003090000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3090000
|
Size: |
159744
|
|
2F57000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1033753999.0000000002F57000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F57000
|
Size: |
20480
|
|
3A40000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.941901767.0000000003A40000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A40000
|
Size: |
159744
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217890859.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
10A3000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.918880279.00000000010A3000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
10A3000
|
Size: |
20480
|
|
3412000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1033461515.0000000003412000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3412000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.926797596.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213638434.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216735454.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214206289.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213472411.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3F4F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1034059495.0000000003F4F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3F4F000
|
Size: |
4096
|
|
29CB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3362617364.00000000029CB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
29CB000
|
Size: |
20480
|
|
6A0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3363857832.00000000006A0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6A0000
|
Size: |
4096
|
|
EB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1033209914.0000000000EB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EB0000
|
Size: |
4096
|
|
7DB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3367349131.0000000007DB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DB0000
|
Size: |
4096
|
|
2D10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3362888361.0000000002D10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D10000
|
Size: |
4096
|
|
3A9E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.923734916.0000000003A9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3A9E000
|
Size: |
24576
|
|
3A7E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915624085.0000000003A7E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A7E000
|
Size: |
24576
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110135555.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
2FB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1219421044.0000000002FB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FB1000
|
Size: |
4096
|
|
4FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3363485090.00000000004FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4FC000
|
Size: |
16384
|
|
2FD2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1219421044.0000000002FD2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FD2000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
19A739E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336571492.0000019A739E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19A739E0000
|
Size: |
32768
|
|
7D3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007D3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D3D000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
72719FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336261844.00000072719FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
72719FE000
|
Size: |
8192
|
|
10DA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.909351737.00000000010DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10DA000
|
Size: |
118784
|
|
37A2000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3364782266.00000000037A2000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
37A2000
|
Size: |
40960
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.941983422.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215722180.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
EB7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.918764106.0000000000EB7000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EB7000
|
Size: |
552960
|
|
3417000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.921906743.0000000003417000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3417000
|
Size: |
20480
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215979156.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
1F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.1106953881.00000000001F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1F0000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213355725.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
D10000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918582818.0000000000D10000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
D10000
|
Size: |
290816
|
|
2F51000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1033898330.0000000002F51000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F51000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.938999894.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215905160.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
19A75500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1285640952.0000019A75500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19A75500000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215751079.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
810000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364131819.0000000000810000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
810000
|
Size: |
4096
|
|
650000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1107137474.0000000000650000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
650000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110436984.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
2FBF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1219421044.0000000002FBF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FBF000
|
Size: |
16384
|
|
7CFF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007CFF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CFF000
|
Size: |
12288
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216584709.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
6F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.3362772341.000000000006F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6F000
|
Size: |
28672
|
|
32A0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3364652727.00000000032A0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
32A0000
|
Size: |
94208
|
|
19A739FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336571492.0000019A739FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19A739FC000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
3200000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1033379832.0000000003200000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3200000
|
Size: |
4096
|
|
10FF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918918733.00000000010FF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10FF000
|
Size: |
8192
|
|
10E7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.905965819.00000000010E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10E7000
|
Size: |
782336
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
1116000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.906070772.0000000001116000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1116000
|
Size: |
589824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213786332.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.934816961.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
19A752C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336737595.0000019A752C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19A752C0000
|
Size: |
12288
|
|
3740000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915073225.0000000003740000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3740000
|
Size: |
1187840
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217123143.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215185714.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213920418.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1212362757.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
510000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3363412053.0000000000510000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
510000
|
Size: |
4096
|
|
3C2D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1033636351.0000000003C2D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3C2D000
|
Size: |
458752
|
|
3A29000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.923734916.0000000003A29000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3A29000
|
Size: |
4096
|
|
1F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.3363196407.00000000001F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1F0000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216021294.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
2FEC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.0000000002FEC000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2FEC000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214487541.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
140000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.1106876303.0000000000140000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
140000
|
Size: |
4096
|
|
ABE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.917857562.0000000000ABE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
ABE000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217206197.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
341E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1033461515.000000000341E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
341E000
|
Size: |
12288
|
|
2FEE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000002FEE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FEE000
|
Size: |
12288
|
|
170000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.944866595.0000000000170000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
170000
|
Size: |
4096
|
|
3384C000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1334592778.000000003384C000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
3384C000
|
Size: |
4096
|
|
3090000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1043589795.0000000003090000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3090000
|
Size: |
159744
|
|
3863000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915506186.0000000003863000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3863000
|
Size: |
507904
|
|
5F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3363474610.00000000005F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5F0000
|
Size: |
4096
|
|
7D2B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007D2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D2B000
|
Size: |
4096
|
|
7D35000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007D35000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D35000
|
Size: |
16384
|
|
11A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.909290432.00000000011A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11A6000
|
Size: |
466944
|
|
641000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.3363591817.0000000000641000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
641000
|
Size: |
12288
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1109994028.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
25BC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1107604886.00000000025BC000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
25BC000
|
Size: |
53248
|
|
2D20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3362983982.0000000002D20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D20000
|
Size: |
4096
|
|
3A7E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916847109.0000000003A7E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A7E000
|
Size: |
24576
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217510444.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
10AB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.906467192.00000000010AB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10AB000
|
Size: |
86016
|
|
2D44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1039993732.0000000002D44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D44000
|
Size: |
4096
|
|
19A73811000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.1336343639.0000019A73811000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
19A73811000
|
Size: |
4096
|
|
EB2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.905279743.0000000000EB2000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
EB2000
|
Size: |
8192
|
|
61000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000002.00000000.944724817.0000000000061000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
61000
|
Size: |
57344
|
|
64A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000000.945110438.000000000064A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
64A000
|
Size: |
8192
|
|
7D21000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007D21000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D21000
|
Size: |
12288
|
|
F00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1033266048.0000000000F00000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F00000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214149370.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
19A7380D000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.1336343639.0000019A7380D000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
19A7380D000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217022632.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
6F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.944743038.000000000006F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6F000
|
Size: |
28672
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110319893.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
20B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3363239789.000000000020B000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
20B000
|
Size: |
4096
|
|
2D44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1035959393.0000000002D44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D44000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110172197.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
63E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1107090228.000000000063E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63E000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1230971243.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
7DA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364131819.00000000007DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7DA000
|
Size: |
8192
|
|
21AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1107472614.00000000021AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
21AF000
|
Size: |
4096
|
|
2F56000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1033703387.0000000002F56000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F56000
|
Size: |
24576
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216691158.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
1117000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.905741619.0000000001117000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1117000
|
Size: |
131072
|
|
432A000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.000000000432A000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
432A000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
33A0C000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1334592778.0000000033A0C000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
33A0C000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1218006878.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
12A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3363095400.000000000012A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12A000
|
Size: |
24576
|
|
38E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915624085.00000000038E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38E0000
|
Size: |
1196032
|
|
47E0000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.00000000047E0000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
47E0000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1212463627.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
35FE000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3364782266.00000000035FE000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
35FE000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1033437509.0000000003400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3400000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1A0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000000.944917298.00000000001A0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1A0000
|
Size: |
4096
|
|
19A7540F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336814809.0000019A7540F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19A7540F000
|
Size: |
8192
|
|
3202000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1033379832.0000000003202000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3202000
|
Size: |
20480
|
|
3740000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915899021.0000000003740000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3740000
|
Size: |
1187840
|
|
EAE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918747935.0000000000EAE000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
EAE000
|
Size: |
36864
|
|
1F1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.3363413056.00000000001F1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1F1000
|
Size: |
12288
|
|
A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.944790782.00000000000A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A0000
|
Size: |
4096
|
|
19A73A0B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336571492.0000019A73A0B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19A73A0B000
|
Size: |
4096
|
|
CA4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.917950311.0000000000CA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CA4000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215030987.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
37B2000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.00000000037B2000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
37B2000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217716910.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
4C4C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3366591530.0000000004C4C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4C4C000
|
Size: |
16384
|
|
E7F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.905221992.0000000000E7F000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E7F000
|
Size: |
147456
|
|
7CC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007CC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CC3000
|
Size: |
12288
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.925728900.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213978525.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
2D80000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3364674637.0000000002D80000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
2D80000
|
Size: |
10485760
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216179389.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214866493.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214346366.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
3A09000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915624085.0000000003A09000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A09000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110082593.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
670000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.3363690313.0000000000670000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
670000
|
Size: |
16384
|
|
2290000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.3364537955.0000000002290000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2290000
|
Size: |
925696
|
|
2280000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3364469203.0000000002280000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2280000
|
Size: |
8192
|
|
2F5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1033835926.0000000002F5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F5C000
|
Size: |
20480
|
|
3025000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000003025000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3025000
|
Size: |
16384
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215589702.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
19A739EF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336571492.0000019A739EF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19A739EF000
|
Size: |
40960
|
|
2F48000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000002F48000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F48000
|
Size: |
12288
|
|
641000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.1107114781.0000000000641000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
641000
|
Size: |
12288
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215676405.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216485630.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.3363047643.00000000000C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C0000
|
Size: |
4096
|
|
21F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.3364539139.00000000021F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
21F0000
|
Size: |
925696
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213667503.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
514C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.000000000514C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
514C000
|
Size: |
16384
|
|
2E5A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3364677712.0000000002E5A000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2E5A000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213889371.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216939000.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1230928271.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216766618.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214317553.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
130000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.1106851323.0000000000130000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
130000
|
Size: |
4096
|
|
2F4D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000002F4D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F4D000
|
Size: |
94208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217746765.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
4FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000000.944964562.00000000004FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4FC000
|
Size: |
16384
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215311159.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
19A75400000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336792447.0000019A75400000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19A75400000
|
Size: |
4096
|
|
19A738A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336497725.0000019A738A0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19A738A0000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1056160232.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
217088
|
|
63F0000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1034080368.00000000063F0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
63F0000
|
Size: |
7282688
|
|
3A7E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.917243212.0000000003A7E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A7E000
|
Size: |
24576
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110518662.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
19A7540A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336814809.0000019A7540A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19A7540A000
|
Size: |
4096
|
|
5602000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.0000000005602000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5602000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1217978362.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
500000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.1107012576.0000000000500000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
500000
|
Size: |
4096
|
|
2FBC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000002FBC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FBC000
|
Size: |
4096
|
|
10A4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.908630012.00000000010A4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10A4000
|
Size: |
172032
|
|
2FD2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000002FD2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FD2000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216530802.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
7DC1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1228391588.0000000007DC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7DC1000
|
Size: |
618496
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215000420.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
1C5F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.919101793.0000000001C5F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1C5F000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110687852.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215373492.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216079292.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
38E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916847109.00000000038E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38E0000
|
Size: |
1196032
|
|
2FEA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000002FEA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FEA000
|
Size: |
4096
|
|
10DA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.908630012.00000000010DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10DA000
|
Size: |
118784
|
|
30F8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1033423958.00000000030F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F8000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1109765889.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
170000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.3363195168.0000000000170000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
170000
|
Size: |
4096
|
|
2FBC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1219421044.0000000002FBC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FBC000
|
Size: |
4096
|
|
72711FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.1336235412.00000072711FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
72711FE000
|
Size: |
8192
|
|
3801000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1033557073.0000000003801000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3801000
|
Size: |
8192
|
|
C90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.917935609.0000000000C90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C90000
|
Size: |
4096
|
|
4FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3363306975.00000000004FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4FC000
|
Size: |
16384
|
|
19A752D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1285034691.0000019A752D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19A752D0000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1218486128.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
C61000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.3364410451.0000000000C61000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C61000
|
Size: |
311296
|
|
10DA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918918733.00000000010DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10DA000
|
Size: |
118784
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1212328669.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
3000000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3363225227.0000000003000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3000000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1216049632.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
D00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918494033.0000000000D00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D00000
|
Size: |
8192
|
|
109E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918813911.000000000109E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
109E000
|
Size: |
20480
|
|
4AD4000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.3366385136.0000000004AD4000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4AD4000
|
Size: |
200704
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110470724.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
12A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000000.944836239.000000000012A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12A000
|
Size: |
24576
|
|
21E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.1107492643.00000000021E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21E0000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215535084.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
5C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000000.945082988.00000000005C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C0000
|
Size: |
20480
|
|
2F4B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1033662860.0000000002F4B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F4B000
|
Size: |
28672
|
|
B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.3363001595.00000000000B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B0000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1213728202.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
7CF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007CF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CF4000
|
Size: |
12288
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1212581516.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
7D19000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3366993078.0000000007D19000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D19000
|
Size: |
16384
|
|
4B4C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.3366570332.0000000004B4C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4B4C000
|
Size: |
16384
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214176780.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.1106721063.0000000000060000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
60000
|
Size: |
4096
|
|
19A755C4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1286406204.0000019A755C4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19A755C4000
|
Size: |
24576
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1214122307.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215827609.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
52DE000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.00000000052DE000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
52DE000
|
Size: |
8192
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1110207323.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1215254605.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|
59F0000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1034080368.00000000059F0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
59F0000
|
Size: |
10485760
|
|
F20000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.934046828.0000000000F20000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
F20000
|
Size: |
159744
|
|
3E74000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3365180467.0000000003E74000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3E74000
|
Size: |
8192
|
|
3900000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.923734916.0000000003900000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3900000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
30F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1109801453.00000000030F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F1000
|
Size: |
4096
|
|