4D70000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000007.00000002.3524390177.0000000004D70000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4D70000
|
Size: |
294912
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3960000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.1179237070.0000000003960000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3960000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
2D00000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000004.00000002.3520886355.0000000002D00000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
2D00000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
6A00000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.1179905667.0000000006A00000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
6A00000
|
Size: |
5013504
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
5320000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000003.00000002.3522440046.0000000005320000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
5320000
|
Size: |
5013504
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
4A00000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000004.00000002.3522573170.0000000004A00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A00000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
30D0000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000004.00000002.3522458525.00000000030D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30D0000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
400000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.1178881371.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
286720
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
330000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3520738648.0000000000330000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
330000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354375436.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4BE7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1181668479.0000000004BE7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BE7000
|
Size: |
458752
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1097602106.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
40C3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075227775.00000000040C3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40C3000
|
Size: |
507904
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
3FF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076711139.0000000003FF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3FF0000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
346000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3520936107.0000000000346000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
346000
|
Size: |
8192
|
|
3150000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3522516649.0000000003150000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3150000
|
Size: |
16384
|
|
6000000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1179905667.0000000006000000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
6000000
|
Size: |
10485760
|
|
3822000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.0000000003822000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3822000
|
Size: |
4096
|
|
157B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1083647577.000000000157B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
157B000
|
Size: |
24576
|
|
7946000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1179905667.0000000007946000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
7946000
|
Size: |
7286784
|
|
2570000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3522547112.0000000002570000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2570000
|
Size: |
925696
|
|
32E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1079677436.000000000032E000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
32E000
|
Size: |
36864
|
|
CFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3521436951.0000000000CFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CFC000
|
Size: |
16384
|
|
432E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076866992.000000000432E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
432E000
|
Size: |
24576
|
|
694C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.000000000694C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
694C000
|
Size: |
4096
|
|
40C3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075593254.00000000040C3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40C3000
|
Size: |
507904
|
|
42BD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076866992.00000000042BD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42BD000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
3EA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3521314089.00000000003EA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3EA000
|
Size: |
24576
|
|
2EB6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.0000000002EB6000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2EB6000
|
Size: |
4096
|
|
2E77000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1179911176.0000000002E77000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E77000
|
Size: |
28672
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357855362.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356146467.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356737410.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
21281EBF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1470835712.0000021281EBF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21281EBF000
|
Size: |
40960
|
|
750000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3521590080.0000000000750000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
750000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357580411.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354799447.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
910000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3521132132.0000000000910000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
910000
|
Size: |
4096
|
|
8F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1100273395.00000000008F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8F0000
|
Size: |
4096
|
|
2F09000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002F09000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F09000
|
Size: |
4096
|
|
1573000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1063473948.0000000001573000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1573000
|
Size: |
491520
|
|
730000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3521497038.0000000000730000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
730000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357795825.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
3C2D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1179284677.0000000003C2D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3C2D000
|
Size: |
458752
|
|
1548000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1083057024.0000000001548000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1548000
|
Size: |
180224
|
|
7FB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525710027.0000000007FB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7FB0000
|
Size: |
4096
|
|
5FE0000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.0000000005FE0000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5FE0000
|
Size: |
8192
|
|
4C2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3522736997.0000000004C2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C2E000
|
Size: |
8192
|
|
4F2D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3522765804.0000000004F2D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4F2D000
|
Size: |
4096
|
|
2EE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1360105087.0000000002EE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EE3000
|
Size: |
12288
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354979563.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
E54000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1118703922.0000000000E54000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E54000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356517500.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
A00000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1246966096.0000000000A00000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A00000
|
Size: |
16384
|
|
E61000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3521965027.0000000000E61000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
E61000
|
Size: |
4096
|
|
1E4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1085492878.0000000001E4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1E4E000
|
Size: |
8192
|
|
3F20000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3522440046.0000000003F20000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3F20000
|
Size: |
10485760
|
|
2E82000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1179603440.0000000002E82000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E82000
|
Size: |
24576
|
|
2F01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002F01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F01000
|
Size: |
8192
|
|
E30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100757249.0000000000E30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E30000
|
Size: |
32768
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355709401.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
6FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1246358114.00000000006FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6FC000
|
Size: |
16384
|
|
2424000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1247534006.0000000002424000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2424000
|
Size: |
4096
|
|
4200000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1179905667.0000000004200000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4200000
|
Size: |
10485760
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358380513.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
3400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1179095445.0000000003400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3400000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4DBB000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3524390177.0000000004DBB000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4DBB000
|
Size: |
8192
|
|
DB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3521588216.0000000000DB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DB0000
|
Size: |
8192
|
|
9D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1100382000.00000000009D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
9D0000
|
Size: |
4096
|
|
DC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100657315.0000000000DC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DC0000
|
Size: |
20480
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1094678764.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354947789.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354643346.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
2E67000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002E67000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E67000
|
Size: |
65536
|
|
349000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1246205472.0000000000349000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
349000
|
Size: |
61440
|
|
15C5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1063574666.00000000015C5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
15C5000
|
Size: |
712704
|
|
3420000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1147635727.0000000003420000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3420000
|
Size: |
12288
|
|
15EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1084828347.00000000015EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
15EA000
|
Size: |
561152
|
|
3690000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.0000000003690000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3690000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1359290322.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
349000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3521103134.0000000000349000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
349000
|
Size: |
61440
|
|
2F4F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002F4F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F4F000
|
Size: |
65536
|
|
3200000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1179059399.0000000003200000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3200000
|
Size: |
4096
|
|
3960000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1147607291.0000000003960000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3960000
|
Size: |
163840
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356568951.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
2270000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1085526513.0000000002270000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2270000
|
Size: |
4096
|
|
3417000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1078841157.0000000003417000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3417000
|
Size: |
20480
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354829576.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
21283760000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1420016675.0000021283760000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21283760000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355291826.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354740270.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
140F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1082017752.000000000140F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
140F000
|
Size: |
4096
|
|
490C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1179236653.000000000490C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
490C000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357914231.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357095936.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
2EC9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1360105087.0000000002EC9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EC9000
|
Size: |
12288
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1090728309.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354705857.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
42DE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075347109.00000000042DE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42DE000
|
Size: |
24576
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355776248.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
3417000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1078712012.0000000003417000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3417000
|
Size: |
20480
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1186417760.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
217088
|
|
2EC9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002EC9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EC9000
|
Size: |
12288
|
|
3A29000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1081790903.0000000003A29000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3A29000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357208286.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
33F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1246167735.000000000033F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
33F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1097440505.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355813858.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
15EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1064784964.00000000015EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
15EA000
|
Size: |
561152
|
|
7ECB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525314217.0000000007ECB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7ECB000
|
Size: |
8192
|
|
DB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3521588216.0000000000DB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DB4000
|
Size: |
4096
|
|
1039000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1081945172.0000000001039000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1039000
|
Size: |
28672
|
|
740000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1246564540.0000000000740000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
740000
|
Size: |
4096
|
|
4140000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075718422.0000000004140000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4140000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7F30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525314217.0000000007F30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F30000
|
Size: |
8192
|
|
2424000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522470215.0000000002424000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2424000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1350578832.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
21283A21000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1471004495.0000021283A21000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21283A21000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1350861804.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
ACA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1247095215.0000000000ACA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ACA000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354557969.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
ACA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522110572.0000000000ACA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ACA000
|
Size: |
8192
|
|
7ED1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525314217.0000000007ED1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7ED1000
|
Size: |
4096
|
|
1D02000
|
system
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1469430724.0000000001D02000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
1D02000
|
Size: |
4096
|
|
E3A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3521807574.0000000000E3A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E3A000
|
Size: |
8192
|
|
1E1C000
|
system
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1469430724.0000000001E1C000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
1E1C000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1094829700.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
9E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3521360755.00000000009E0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E0000
|
Size: |
4096
|
|
380000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3521261292.0000000000380000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
380000
|
Size: |
4096
|
|
3E42000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1179284677.0000000003E42000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3E42000
|
Size: |
40960
|
|
9E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100396310.00000000009E0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E0000
|
Size: |
4096
|
|
3501000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1179139644.0000000003501000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3501000
|
Size: |
4096
|
|
2F70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1178998283.0000000002F70000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F70000
|
Size: |
4096
|
|
2F13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002F13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F13000
|
Size: |
12288
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355529345.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357141771.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355495849.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
87E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1246758903.000000000087E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
87E000
|
Size: |
8192
|
|
42A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3521361736.000000000042A000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
42A000
|
Size: |
4096
|
|
349000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3520982281.0000000000349000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
349000
|
Size: |
61440
|
|
21283A17000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1471004495.0000021283A17000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21283A17000
|
Size: |
4096
|
|
3FFC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.0000000003FFC000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3FFC000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1366647524.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
324000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1062968843.0000000000324000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
324000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1351361246.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
21281EE3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1421673386.0000021281EE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21281EE3000
|
Size: |
28672
|
|
4F4C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3524590273.0000000004F4C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4F4C000
|
Size: |
16384
|
|
1100000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1100832545.0000000001100000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1100000
|
Size: |
32768
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355465424.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
336C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.000000000336C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
336C000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
23C4000
|
system
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1469430724.00000000023C4000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
23C4000
|
Size: |
4096
|
|
21281D70000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000E.00000002.1470659278.0000021281D70000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
21281D70000
|
Size: |
159744
|
|
7F19000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525314217.0000000007F19000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F19000
|
Size: |
12288
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354008491.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
1490000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1100847387.0000000001490000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1490000
|
Size: |
331776
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
167C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1078069489.000000000167C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
167C000
|
Size: |
16384
|
|
830000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3521626691.0000000000830000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
830000
|
Size: |
4096
|
|
370000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3521212871.0000000000370000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
370000
|
Size: |
4096
|
|
3910000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1179205605.0000000003910000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3910000
|
Size: |
274432
|
|
7EFF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525314217.0000000007EFF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7EFF000
|
Size: |
12288
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1353862364.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
42DE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075718422.00000000042DE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42DE000
|
Size: |
24576
|
|
3A2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1081790903.0000000003A2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3A2D000
|
Size: |
458752
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358410571.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
7F28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1365726183.0000000007F28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F28000
|
Size: |
8192
|
|
67BA000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.00000000067BA000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
67BA000
|
Size: |
8192
|
|
2F34000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002F34000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F34000
|
Size: |
8192
|
|
4190000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076105980.0000000004190000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4190000
|
Size: |
1196032
|
|
426D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075718422.000000000426D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
426D000
|
Size: |
458752
|
|
7F32000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1365726183.0000000007F32000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F32000
|
Size: |
8192
|
|
7F2B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525314217.0000000007F2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F2B000
|
Size: |
8192
|
|
4C00000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1179905667.0000000004C00000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4C00000
|
Size: |
10485760
|
|
4001000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1179784675.0000000004001000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4001000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355321924.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
A20000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3521900923.0000000000A20000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A20000
|
Size: |
4096
|
|
349000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1100241321.0000000000349000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
349000
|
Size: |
61440
|
|
2A30000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1100916843.0000000002A30000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2A30000
|
Size: |
925696
|
|
330000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1099997413.0000000000330000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
330000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354468134.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
330000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1246111525.0000000000330000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
330000
|
Size: |
4096
|
|
2FF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1062968843.00000000002FF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2FF000
|
Size: |
147456
|
|
9D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3521310139.00000000009D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
9D0000
|
Size: |
4096
|
|
2EF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1360105087.0000000002EF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EF0000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356300445.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355743009.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
141B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1082017752.000000000141B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
141B000
|
Size: |
20480
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355228793.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358531817.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356890688.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
DD0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3521729426.0000000000DD0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
DD0000
|
Size: |
16384
|
|
2E82000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1179520831.0000000002E82000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E82000
|
Size: |
24576
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358090726.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
492A5FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1470614277.000000492A5FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
492A5FE000
|
Size: |
8192
|
|
2ED9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1360105087.0000000002ED9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ED9000
|
Size: |
8192
|
|
528C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.000000000528C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
528C000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
900000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1100287086.0000000000900000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
900000
|
Size: |
4096
|
|
7F35000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525314217.0000000007F35000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F35000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354435859.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357943808.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
2A20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100903150.0000000002A20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A20000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357378706.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
7F3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525314217.0000000007F3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F3D000
|
Size: |
49152
|
|
3B46000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.0000000003B46000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3B46000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1353553360.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355189481.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
E3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100757249.0000000000E3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E3E000
|
Size: |
90112
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1353393001.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
E62000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1118738233.0000000000E62000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
E62000
|
Size: |
4096
|
|
6304000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.0000000006304000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
6304000
|
Size: |
8192
|
|
ACE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1247095215.0000000000ACE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ACE000
|
Size: |
90112
|
|
332000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1063008263.0000000000332000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
332000
|
Size: |
8192
|
|
270000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1078576811.0000000000270000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
270000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358290587.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
432E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076466285.000000000432E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
432E000
|
Size: |
24576
|
|
890000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1246825366.0000000000890000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
890000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356861628.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
2E7D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1179963375.0000000002E7D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E7D000
|
Size: |
4096
|
|
324000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1078798442.0000000000324000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
324000
|
Size: |
40960
|
|
380E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1179174306.000000000380E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
380E000
|
Size: |
8192
|
|
7F40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1365726183.0000000007F40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F40000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358899670.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
3FA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075227775.0000000003FA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3FA0000
|
Size: |
1187840
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358680233.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
2F90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1090174159.0000000002F90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2F90000
|
Size: |
163840
|
|
2F80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1179018708.0000000002F80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F80000
|
Size: |
4096
|
|
4FB2000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.0000000004FB2000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4FB2000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358590226.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1366738969.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358349945.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4C58000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1181668479.0000000004C58000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C58000
|
Size: |
24576
|
|
E5E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1118703922.0000000000E5E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E5E000
|
Size: |
20480
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1350995732.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
2CC8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3520838043.0000000002CC8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2CC8000
|
Size: |
32768
|
|
3DD1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1179284677.0000000003DD1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3DD1000
|
Size: |
458752
|
|
4929DFD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1470588246.0000004929DFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4929DFD000
|
Size: |
12288
|
|
2EAC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1178921355.0000000002EAC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2EAC000
|
Size: |
16384
|
|
3EA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1246331565.00000000003EA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3EA000
|
Size: |
24576
|
|
380000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1246271207.0000000000380000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
380000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358649351.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
21283BC4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1421511162.0000021283BC4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21283BC4000
|
Size: |
24576
|
|
167C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1069013708.000000000167C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
167C000
|
Size: |
135168
|
|
2F1F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002F1F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F1F000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356822585.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
2E7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1179747882.0000000002E7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E7E000
|
Size: |
20480
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1366792306.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
2EB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002EB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EB5000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3A9E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1081790903.0000000003A9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3A9E000
|
Size: |
24576
|
|
21281E40000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1470759178.0000021281E40000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21281E40000
|
Size: |
4096
|
|
AC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1247095215.0000000000AC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AC0000
|
Size: |
32768
|
|
168A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1064877102.000000000168A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
168A000
|
Size: |
73728
|
|
6172000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.0000000006172000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
6172000
|
Size: |
4096
|
|
85BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525750662.00000000085BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
85BE000
|
Size: |
8192
|
|
2E94000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002E94000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E94000
|
Size: |
131072
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
360000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1246232984.0000000000360000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
360000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355419455.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
97A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100323087.000000000097A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
97A000
|
Size: |
24576
|
|
2DD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1181986212.0000000002DD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DD4000
|
Size: |
4096
|
|
21281DA4000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000E.00000002.1470659278.0000021281DA4000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
21281DA4000
|
Size: |
4096
|
|
4190000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076866992.0000000004190000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4190000
|
Size: |
1196032
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1353456283.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357823880.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
22C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1085561866.00000000022C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22C0000
|
Size: |
8192
|
|
2E88000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1179789545.0000000002E88000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E88000
|
Size: |
20480
|
|
270000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1062876656.0000000000270000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
270000
|
Size: |
4096
|
|
3520000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3522440046.0000000003520000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3520000
|
Size: |
10485760
|
|
4F31000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3522765804.0000000004F31000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4F31000
|
Size: |
458752
|
|
1699000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1069035936.0000000001699000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1699000
|
Size: |
16384
|
|
E30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3521807574.0000000000E30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E30000
|
Size: |
32768
|
|
4BB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1192804358.0000000004BB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4BB0000
|
Size: |
159744
|
|
5600000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1179905667.0000000005600000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
5600000
|
Size: |
10485760
|
|
740000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3521551237.0000000000740000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
740000
|
Size: |
4096
|
|
21281EE0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1421673386.0000021281EE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21281EE0000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358710104.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
21281EDC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1421673386.0000021281EDC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21281EDC000
|
Size: |
4096
|
|
2F20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1178959681.0000000002F20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F20000
|
Size: |
4096
|
|
31DA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.00000000031DA000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
31DA000
|
Size: |
4096
|
|
40C3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1074822954.00000000040C3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40C3000
|
Size: |
507904
|
|
2E82000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1179911176.0000000002E82000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E82000
|
Size: |
24576
|
|
3900000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1081790903.0000000003900000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3900000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
8F6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3521763675.00000000008F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F6000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1353811244.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1094747412.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
7F38000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1365726183.0000000007F38000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F38000
|
Size: |
4096
|
|
2662000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.0000000002662000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2662000
|
Size: |
4096
|
|
293C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.000000000293C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
293C000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354500067.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
6266000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3522440046.0000000006266000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
6266000
|
Size: |
7286784
|
|
2DD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1186560325.0000000002DD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DD4000
|
Size: |
4096
|
|
DD0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1100709217.0000000000DD0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
DD0000
|
Size: |
16384
|
|
4269000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075347109.0000000004269000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4269000
|
Size: |
4096
|
|
9C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1100366133.00000000009C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
9C0000
|
Size: |
4096
|
|
E3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3521807574.0000000000E3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E3E000
|
Size: |
90112
|
|
346000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3521032011.0000000000346000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
346000
|
Size: |
8192
|
|
169B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1078139078.000000000169B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
169B000
|
Size: |
8192
|
|
1500000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1082936368.0000000001500000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1500000
|
Size: |
24576
|
|
1674000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1085146578.0000000001674000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1674000
|
Size: |
32768
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354586613.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
2E20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521076597.0000000002E20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E20000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354077815.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195383474.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
221184
|
|
2EEB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1178939897.0000000002EEB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2EEB000
|
Size: |
20480
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355898608.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
9F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3521396656.00000000009F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9F0000
|
Size: |
4096
|
|
1490000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1082473551.0000000001490000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1490000
|
Size: |
4096
|
|
AC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522110572.0000000000AC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AC0000
|
Size: |
32768
|
|
21283B01000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1471155081.0000021283B01000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21283B01000
|
Size: |
4096
|
|
331000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000000.1100156771.0000000000331000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
331000
|
Size: |
57344
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1181963283.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
65536
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357767303.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
7F2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1365726183.0000000007F2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F2F000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354263562.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357709455.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355067659.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354042099.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1353917884.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
7F1C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1365726183.0000000007F1C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F1C000
|
Size: |
4096
|
|
4920000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3522440046.0000000004920000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
4920000
|
Size: |
10485760
|
|
720000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3521441197.0000000000720000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
720000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1097513849.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195508951.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
13FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1082017752.00000000013FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13FF000
|
Size: |
4096
|
|
D41000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3521494411.0000000000D41000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
D41000
|
Size: |
12288
|
|
6C70000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.0000000006C70000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
6C70000
|
Size: |
8192
|
|
6496000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.0000000006496000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
6496000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358206359.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
3202000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1179059399.0000000003202000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3202000
|
Size: |
20480
|
|
3700000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1078029327.0000000003700000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3700000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
750000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1246592512.0000000000750000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
750000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1366902577.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
2A30000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3522231525.0000000002A30000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2A30000
|
Size: |
925696
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355633819.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
30B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1185837409.00000000030B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30B0000
|
Size: |
159744
|
|
8EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1246848210.00000000008EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8EE000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1359160435.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
21283900000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1470967887.0000021283900000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21283900000
|
Size: |
4096
|
|
34FE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.00000000034FE000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
34FE000
|
Size: |
8192
|
|
299F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100881598.000000000299F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
299F000
|
Size: |
4096
|
|
7F3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1365726183.0000000007F3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F3E000
|
Size: |
4096
|
|
F51000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3522390292.0000000000F51000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F51000
|
Size: |
327680
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354770859.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1083533292.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
331000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000007.00000000.1246141351.0000000000331000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
331000
|
Size: |
57344
|
|
2F59000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1366185304.0000000002F59000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F59000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358738852.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
1491000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3522069152.0000000001491000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1491000
|
Size: |
327680
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
337000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1080264256.0000000000337000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
337000
|
Size: |
401408
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1352048719.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1366834831.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358234397.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4113000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075979388.0000000004113000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4113000
|
Size: |
507904
|
|
7ED6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525314217.0000000007ED6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7ED6000
|
Size: |
12288
|
|
2EDE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1360105087.0000000002EDE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EDE000
|
Size: |
12288
|
|
3DCD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1179284677.0000000003DCD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3DCD000
|
Size: |
4096
|
|
4A50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3522614101.0000000004A50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A50000
|
Size: |
90112
|
|
3405000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1078682089.0000000003405000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3405000
|
Size: |
49152
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356705633.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355667682.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1095074314.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
221184
|
|
5866000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3522440046.0000000005866000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
5866000
|
Size: |
10485760
|
|
256F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1247664105.000000000256F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
256F000
|
Size: |
4096
|
|
4A2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1179236653.0000000004A2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4A2F000
|
Size: |
512000
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357681320.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4C60000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3522765804.0000000004C60000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4C60000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2E77000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1179520831.0000000002E77000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E77000
|
Size: |
28672
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354124052.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
A9C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522055637.0000000000A9C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A9C000
|
Size: |
16384
|
|
2F40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1178979584.0000000002F40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F40000
|
Size: |
4096
|
|
4DE0000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3524390177.0000000004DE0000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4DE0000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355261011.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
157B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1078119432.000000000157B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
157B000
|
Size: |
24576
|
|
E3A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100757249.0000000000E3A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E3A000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354858952.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356205929.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358000757.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
426D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075347109.000000000426D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
426D000
|
Size: |
458752
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1353953343.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4113000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076348829.0000000004113000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4113000
|
Size: |
507904
|
|
7EFA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525314217.0000000007EFA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7EFA000
|
Size: |
12288
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357454241.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4113000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076711139.0000000004113000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4113000
|
Size: |
507904
|
|
4140000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075347109.0000000004140000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4140000
|
Size: |
1196032
|
|
4DE2000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3524390177.0000000004DE2000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4DE2000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356482674.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
2E82000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1180012685.0000000002E82000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E82000
|
Size: |
24576
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358832566.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356930613.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1085105351.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
221184
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356392725.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
15EB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1063445264.00000000015EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
15EB000
|
Size: |
131072
|
|
7EDB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525314217.0000000007EDB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7EDB000
|
Size: |
8192
|
|
4D89000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3522765804.0000000004D89000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4D89000
|
Size: |
4096
|
|
370000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1246250285.0000000000370000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
370000
|
Size: |
4096
|
|
7EF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525314217.0000000007EF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7EF4000
|
Size: |
12288
|
|
6F46000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1179905667.0000000006F46000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
6F46000
|
Size: |
10485760
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357253485.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
2420000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1247534006.0000000002420000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2420000
|
Size: |
8192
|
|
21283A0F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1471004495.0000021283A0F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21283A0F000
|
Size: |
16384
|
|
3E6A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.0000000003E6A000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3E6A000
|
Size: |
8192
|
|
224E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1085509100.000000000224E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
224E000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355598157.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
6FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3521398440.00000000006FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6FC000
|
Size: |
16384
|
|
271000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1062913498.0000000000271000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
271000
|
Size: |
581632
|
|
85FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525774324.00000000085FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
85FF000
|
Size: |
4096
|
|
2460000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522516778.0000000002460000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2460000
|
Size: |
12288
|
|
A20000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1247039308.0000000000A20000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A20000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357413227.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358767480.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358061975.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
5B2A000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.0000000005B2A000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5B2A000
|
Size: |
4096
|
|
7F46000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1365726183.0000000007F46000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F46000
|
Size: |
8192
|
|
2E88000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1179472236.0000000002E88000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E88000
|
Size: |
20480
|
|
7F22000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1365726183.0000000007F22000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F22000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358029406.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
1FDC000
|
system
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1469430724.0000000001FDC000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
1FDC000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2F2A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002F2A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F2A000
|
Size: |
4096
|
|
2DD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1186462527.0000000002DD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DD4000
|
Size: |
4096
|
|
7EAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525288589.0000000007EAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7EAE000
|
Size: |
8192
|
|
8F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1246898361.00000000008F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F0000
|
Size: |
20480
|
|
1E0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1085474375.0000000001E0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1E0E000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355038229.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
277C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.000000000277C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
277C000
|
Size: |
4096
|
|
42B9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076866992.00000000042B9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42B9000
|
Size: |
4096
|
|
DAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100540642.0000000000DAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DAE000
|
Size: |
8192
|
|
2E79000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002E79000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E79000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358498080.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
A00000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3521858447.0000000000A00000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A00000
|
Size: |
16384
|
|
2E79000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1179716952.0000000002E79000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E79000
|
Size: |
36864
|
|
30B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3522424386.00000000030B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30B0000
|
Size: |
4096
|
|
331000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000007.00000002.3520880982.0000000000331000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
331000
|
Size: |
57344
|
|
730000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1246484886.0000000000730000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
730000
|
Size: |
4096
|
|
341A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1147635727.000000000341A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
341A000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2ECF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002ECF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ECF000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
42BD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076105980.00000000042BD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42BD000
|
Size: |
458752
|
|
2ED9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002ED9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ED9000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355383748.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
21281EB9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1470835712.0000021281EB9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21281EB9000
|
Size: |
20480
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354914779.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
1540000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1083057024.0000000001540000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1540000
|
Size: |
24576
|
|
426D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1074961422.000000000426D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
426D000
|
Size: |
458752
|
|
2E82000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1179655914.0000000002E82000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E82000
|
Size: |
24576
|
|
910000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1100304727.0000000000910000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
910000
|
Size: |
4096
|
|
160A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1063514862.000000000160A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
160A000
|
Size: |
4096
|
|
42DE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1074961422.00000000042DE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42DE000
|
Size: |
24576
|
|
346000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100209995.0000000000346000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
346000
|
Size: |
8192
|
|
DF0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100737304.0000000000DF0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
DF0000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355559935.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
CFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100437460.0000000000CFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CFC000
|
Size: |
16384
|
|
2C8B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3520737634.0000000002C8B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C8B000
|
Size: |
20480
|
|
271000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.1078600980.0000000000271000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
271000
|
Size: |
581632
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356004340.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
3412000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1179118369.0000000003412000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3412000
|
Size: |
32768
|
|
830000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1246676567.0000000000830000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
830000
|
Size: |
4096
|
|
418E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.000000000418E000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
418E000
|
Size: |
4096
|
|
33F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1100184352.000000000033F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
33F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354161328.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355008860.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
7EC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525314217.0000000007EC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7EC3000
|
Size: |
20480
|
|
21283A0A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1471004495.0000021283A0A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21283A0A000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1366605926.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
21283760000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1420084576.0000021283760000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21283760000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355935969.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
39B4000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.00000000039B4000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
39B4000
|
Size: |
8192
|
|
7BF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525129486.0000000007BF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7BF0000
|
Size: |
4096
|
|
1100000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3522004584.0000000001100000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1100000
|
Size: |
32768
|
|
4DFE000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3522765804.0000000004DFE000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4DFE000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3FF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076348829.0000000003FF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3FF0000
|
Size: |
1187840
|
|
15EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1068934772.00000000015EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
15EA000
|
Size: |
561152
|
|
21281DA6000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000E.00000002.1470659278.0000021281DA6000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
21281DA6000
|
Size: |
4096
|
|
7EDE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525314217.0000000007EDE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7EDE000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1084823752.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1366870507.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
2ECF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1360105087.0000000002ECF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ECF000
|
Size: |
8192
|
|
4FA2000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3522765804.0000000004FA2000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4FA2000
|
Size: |
40960
|
|
BC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3522347227.0000000000BC0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BC0000
|
Size: |
32768
|
|
3C29000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1179284677.0000000003C29000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3C29000
|
Size: |
4096
|
|
3823000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1078029327.0000000003823000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3823000
|
Size: |
507904
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354528301.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358560828.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
3C00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1085581349.0000000003C00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3C00000
|
Size: |
8192
|
|
2D80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3520980962.0000000002D80000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D80000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358118642.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
2E60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002E60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E60000
|
Size: |
20480
|
|
2290000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1085544447.0000000002290000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
2290000
|
Size: |
16384
|
|
50CC000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.00000000050CC000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
50CC000
|
Size: |
4096
|
|
8F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3521027848.00000000008F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8F0000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357306601.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
3405000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1078764408.0000000003405000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3405000
|
Size: |
49152
|
|
42BD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076466285.00000000042BD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42BD000
|
Size: |
458752
|
|
44B2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.00000000044B2000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
44B2000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357737792.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
21281EE3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1470922793.0000021281EE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21281EE3000
|
Size: |
28672
|
|
2722000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.0000000002722000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2722000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355862521.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4D8D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3522765804.0000000004D8D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4D8D000
|
Size: |
458752
|
|
2EF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002EF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EF0000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
7FC8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1363347959.0000000007FC8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7FC8000
|
Size: |
614400
|
|
F50000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1247447195.0000000000F50000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F50000
|
Size: |
331776
|
|
6628000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.0000000006628000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
6628000
|
Size: |
4096
|
|
370E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1179156356.000000000370E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
370E000
|
Size: |
8192
|
|
4DC4000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3524390177.0000000004DC4000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4DC4000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
42B9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076466285.00000000042B9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42B9000
|
Size: |
4096
|
|
346000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1246187381.0000000000346000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
346000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356037973.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358178708.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1350705234.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1353638534.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
3FA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075593254.0000000003FA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3FA0000
|
Size: |
1187840
|
|
DB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100568064.0000000000DB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DB0000
|
Size: |
8192
|
|
21283870000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1470943881.0000021283870000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21283870000
|
Size: |
12288
|
|
49295FB000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1470562760.00000049295FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
49295FB000
|
Size: |
20480
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354295013.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
890000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3521726217.0000000000890000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
890000
|
Size: |
4096
|
|
4B00000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3522655843.0000000004B00000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
4B00000
|
Size: |
90112
|
|
2EFB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002EFB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EFB000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
1689000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1085428283.0000000001689000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1689000
|
Size: |
73728
|
|
2D24000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.0000000002D24000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2D24000
|
Size: |
4096
|
|
6EDE000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1179905667.0000000006EDE000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
6EDE000
|
Size: |
4096
|
|
9FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1246920543.00000000009FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9FF000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357972116.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
5CBC000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.0000000005CBC000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5CBC000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3960000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1094612716.0000000003960000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3960000
|
Size: |
163840
|
|
1DC2000
|
system
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1469430724.0000000001DC2000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
1DC2000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355350925.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
2F3F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002F3F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F3F000
|
Size: |
12288
|
|
DC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3521687973.0000000000DC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DC0000
|
Size: |
20480
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354614587.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
7F3B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1365726183.0000000007F3B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F3B000
|
Size: |
8192
|
|
2F3A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002F3A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F3A000
|
Size: |
12288
|
|
4BB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1190415692.0000000004BB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4BB0000
|
Size: |
159744
|
|
3C9E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1179284677.0000000003C9E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3C9E000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2DD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521027549.0000000002DD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DD0000
|
Size: |
16384
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358262053.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
97A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3521181256.000000000097A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
97A000
|
Size: |
24576
|
|
9F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100419027.00000000009F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9F0000
|
Size: |
4096
|
|
2B20000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3522440046.0000000002B20000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
2B20000
|
Size: |
10485760
|
|
337000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1063037312.0000000000337000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
337000
|
Size: |
401408
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357653180.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356615001.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
293C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1247837765.000000000293C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
293C000
|
Size: |
53248
|
|
A40000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522001659.0000000000A40000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A40000
|
Size: |
4096
|
|
7EB7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1359045723.0000000007EB7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7EB7000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5806000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.0000000005806000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5806000
|
Size: |
4096
|
|
5E4E000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.0000000005E4E000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5E4E000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358321090.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
2EBE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002EBE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EBE000
|
Size: |
4096
|
|
2EE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002EE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EE3000
|
Size: |
12288
|
|
7EE8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525314217.0000000007EE8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7EE8000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1186639989.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
14DD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1082594034.00000000014DD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
14DD000
|
Size: |
12288
|
|
21283BA6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1421599735.0000021283BA6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21283BA6000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357481794.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358439156.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
1689000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1078069489.0000000001689000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1689000
|
Size: |
81920
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357054402.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356266197.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
7EE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525314217.0000000007EE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7EE3000
|
Size: |
16384
|
|
D41000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1100479321.0000000000D41000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
D41000
|
Size: |
12288
|
|
7F05000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525314217.0000000007F05000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F05000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354407666.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354887404.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
492ADFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1470637629.000000492ADFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
492ADFE000
|
Size: |
8192
|
|
32E000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1063008263.000000000032E000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
32E000
|
Size: |
8192
|
|
2F0C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002F0C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F0C000
|
Size: |
4096
|
|
A30000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3521955578.0000000000A30000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
A30000
|
Size: |
12288
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358798274.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355140874.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4BB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1249408290.0000000004BB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4BB0000
|
Size: |
159744
|
|
3C04000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1085581349.0000000003C04000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3C04000
|
Size: |
8192
|
|
2570000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1247719925.0000000002570000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2570000
|
Size: |
925696
|
|
5674000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.0000000005674000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5674000
|
Size: |
4096
|
|
ACE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522110572.0000000000ACE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ACE000
|
Size: |
94208
|
|
6ADE000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.0000000006ADE000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
6ADE000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1083621438.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
21283A03000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1471004495.0000021283A03000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21283A03000
|
Size: |
16384
|
|
2420000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522470215.0000000002420000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2420000
|
Size: |
8192
|
|
1574000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1063640126.0000000001574000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1574000
|
Size: |
331776
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357520517.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
3F50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1085932643.0000000003F50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F50000
|
Size: |
290816
|
|
33F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3520956890.000000000033F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
33F000
|
Size: |
28672
|
|
4E37000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3524390177.0000000004E37000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4E37000
|
Size: |
90112
|
|
3CD8000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.0000000003CD8000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3CD8000
|
Size: |
4096
|
|
57FE000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3522440046.00000000057FE000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
57FE000
|
Size: |
4096
|
|
9C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3521262752.00000000009C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
9C0000
|
Size: |
4096
|
|
DB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100568064.0000000000DB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DB4000
|
Size: |
4096
|
|
1581000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1068934772.0000000001581000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1581000
|
Size: |
57344
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356423487.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
8060000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3525729882.0000000008060000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8060000
|
Size: |
4096
|
|
4269000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075718422.0000000004269000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4269000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357608457.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
BC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1247359312.0000000000BC0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BC0000
|
Size: |
32768
|
|
4BE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1181668479.0000000004BE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BE3000
|
Size: |
4096
|
|
167C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1064902750.000000000167C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
167C000
|
Size: |
57344
|
|
360000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3521153439.0000000000360000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
360000
|
Size: |
4096
|
|
331000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000002.3520833195.0000000000331000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
331000
|
Size: |
57344
|
|
8F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3521763675.00000000008F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F0000
|
Size: |
16384
|
|
2FCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1179039419.0000000002FCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FCE000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356674656.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
21283BBE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1421511162.0000021283BBE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21283BBE000
|
Size: |
8192
|
|
3FA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1074822954.0000000003FA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3FA0000
|
Size: |
1187840
|
|
21283A00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1470987753.0000021283A00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21283A00000
|
Size: |
4096
|
|
14E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1082748650.00000000014E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14E0000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354233456.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
6E02000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.0000000006E02000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
6E02000
|
Size: |
8192
|
|
4DD4000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3524390177.0000000004DD4000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4DD4000
|
Size: |
4096
|
|
DF0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3521765506.0000000000DF0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
DF0000
|
Size: |
4096
|
|
42B9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076105980.00000000042B9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42B9000
|
Size: |
4096
|
|
4900000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3522546835.0000000004900000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4900000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358619145.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
33F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3520895385.000000000033F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
33F000
|
Size: |
28672
|
|
9B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1100347674.00000000009B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
9B0000
|
Size: |
4096
|
|
21283760000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.1420927539.0000021283760000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21283760000
|
Size: |
4096
|
|
21281E60000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1470780405.0000021281E60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21281E60000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354337987.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
5072000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3523265081.0000000005072000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5072000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1090569888.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356361795.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
143D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1082017752.000000000143D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
143D000
|
Size: |
12288
|
|
D3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100461485.0000000000D3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D3E000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357550110.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356070199.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
881000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3521684742.0000000000881000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
881000
|
Size: |
12288
|
|
3B00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1179284677.0000000003B00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3B00000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
D50000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100503903.0000000000D50000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D50000
|
Size: |
4096
|
|
1581000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1064784964.0000000001581000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1581000
|
Size: |
401408
|
|
4140000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1074961422.0000000004140000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4140000
|
Size: |
1196032
|
|
2662000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1247837765.0000000002662000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2662000
|
Size: |
4096
|
|
720000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1246427306.0000000000720000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
720000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1090647864.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
3FF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075979388.0000000003FF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3FF0000
|
Size: |
1187840
|
|
AE9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522110572.0000000000AE9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AE9000
|
Size: |
90112
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2F0E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002F0E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F0E000
|
Size: |
12288
|
|
21281E90000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1470810745.0000021281E90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21281E90000
|
Size: |
4096
|
|
10FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1100813467.00000000010FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10FF000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356100015.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
21281EB0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1470835712.0000021281EB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21281EB0000
|
Size: |
32768
|
|
169C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1085456278.000000000169C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
169C000
|
Size: |
4096
|
|
2EDE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002EDE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EDE000
|
Size: |
12288
|
|
2E7D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1179603440.0000000002E7D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E7D000
|
Size: |
4096
|
|
D50000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3521538674.0000000000D50000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D50000
|
Size: |
4096
|
|
4269000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1074961422.0000000004269000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4269000
|
Size: |
4096
|
|
3960000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1097361561.0000000003960000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3960000
|
Size: |
163840
|
|
4BE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3522705332.0000000004BE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4BE0000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1355969376.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
2A20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3522177047.0000000002A20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A20000
|
Size: |
8192
|
|
432E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076105980.000000000432E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
432E000
|
Size: |
24576
|
|
21281ECC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.1470835712.0000021281ECC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21281ECC000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
9B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3521222330.00000000009B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
9B0000
|
Size: |
4096
|
|
900000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3521077711.0000000000900000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
900000
|
Size: |
4096
|
|
390F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1179190026.000000000390F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
390F000
|
Size: |
4096
|
|
2E82000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1179963375.0000000002E82000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E82000
|
Size: |
24576
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1350641437.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1356780504.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
4096
|
|
881000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1246798519.0000000000881000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
881000
|
Size: |
12288
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358469479.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4ABA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1181668479.0000000004ABA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4ABA000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2FF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1078798442.00000000002FF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2FF000
|
Size: |
147456
|
|
15EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1063640126.00000000015EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
15EA000
|
Size: |
561152
|
|
2F44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3521131461.0000000002F44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F44000
|
Size: |
20480
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1090809309.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
221184
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354199933.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1097704523.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
221184
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1354674808.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4320000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3522655360.0000000004320000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4320000
|
Size: |
8192
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1357884593.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
4190000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076466285.0000000004190000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4190000
|
Size: |
1196032
|
|
4901000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1358147867.0000000004901000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4901000
|
Size: |
8192
|
|
330000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3520713140.0000000000330000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
330000
|
Size: |
4096
|
|
2460000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1247645054.0000000002460000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2460000
|
Size: |
8192
|
|