400000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1187016684.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
290816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
5160000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000006.00000002.2339516938.0000000005160000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5160000
|
Size: |
475136
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
2D10000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.2337872709.0000000002D10000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
2D10000
|
Size: |
7110656
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
4600000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1187682843.0000000004600000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4600000
|
Size: |
7110656
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3370000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000003.00000002.1429074822.0000000003370000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3370000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3320000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000003.00000002.1429036738.0000000003320000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3320000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
34D0000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1187340104.00000000034D0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
34D0000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
814F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431061574.000000000814F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
814F000
|
Size: |
12288
|
|
720000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2336836619.0000000000720000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
720000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363307643.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
2A1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.1087886563.00000000002A1000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
2A1000
|
Size: |
581632
|
|
3729000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1187368086.0000000003729000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3729000
|
Size: |
4096
|
|
3CAC000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1429623747.0000000003CAC000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3CAC000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
940000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1255483198.0000000000940000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
940000
|
Size: |
4096
|
|
3480000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187312413.0000000003480000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3480000
|
Size: |
274432
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1258116593.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
2A40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2338336549.0000000002A40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A40000
|
Size: |
12288
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366738765.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
33EE000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2337872709.00000000033EE000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
33EE000
|
Size: |
4096
|
|
3005000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1088432558.0000000003005000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3005000
|
Size: |
49152
|
|
720000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108332529.0000000000720000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
720000
|
Size: |
4096
|
|
8146000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431061574.0000000008146000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8146000
|
Size: |
8192
|
|
B1F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076136650.0000000000B1F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B1F000
|
Size: |
94208
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362493470.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
189000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1087729500.0000000000189000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
189000
|
Size: |
28672
|
|
2E13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1102882366.0000000002E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E13000
|
Size: |
200704
|
|
2A40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1256078246.0000000002A40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A40000
|
Size: |
8192
|
|
323A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1188747522.000000000323A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
323A000
|
Size: |
24576
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363875076.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363740591.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
3600000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1187368086.0000000003600000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3600000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362898587.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
B4E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1078155328.0000000000B4E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B4E000
|
Size: |
118784
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362766672.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
599F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2339882306.000000000599F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
599F000
|
Size: |
4096
|
|
132F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1255817803.000000000132F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
132F000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1258025212.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362231817.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
7A0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108392691.00000000007A0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A0000
|
Size: |
4096
|
|
323A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1188833195.000000000323A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
323A000
|
Size: |
4096
|
|
B34000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1078155328.0000000000B34000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B34000
|
Size: |
90112
|
|
19F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.2335985021.000000000019F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
19F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1365834525.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
9CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1255570936.00000000009CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9CE000
|
Size: |
8192
|
|
AE9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2337337273.0000000000AE9000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AE9000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366334232.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
2A00000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2338309928.0000000002A00000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2A00000
|
Size: |
4096
|
|
2E13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1098756891.0000000002E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E13000
|
Size: |
69632
|
|
816B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431061574.000000000816B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
816B000
|
Size: |
8192
|
|
B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.1107852856.00000000000B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B0000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360763171.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
323A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1188975541.000000000323A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
323A000
|
Size: |
24576
|
|
170000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.1108042069.0000000000170000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
170000
|
Size: |
4096
|
|
AF8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088113152.0000000000AF8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AF8000
|
Size: |
106496
|
|
2140000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108600616.0000000002140000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2140000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363008667.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
B11000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075320946.0000000000B11000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B11000
|
Size: |
544768
|
|
C40000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2337276795.0000000000C40000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C40000
|
Size: |
335872
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
3230000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1188833195.0000000003230000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3230000
|
Size: |
36864
|
|
1F1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.1108244613.00000000001F1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1F1000
|
Size: |
12288
|
|
C80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187085148.0000000000C80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C80000
|
Size: |
4096
|
|
3A01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187664397.0000000003A01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3A01000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360227256.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
32A1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.00000000032A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32A1000
|
Size: |
12288
|
|
8170000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431061574.0000000008170000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8170000
|
Size: |
8192
|
|
3240000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1188903140.0000000003240000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3240000
|
Size: |
16384
|
|
950000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1255499057.0000000000950000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
950000
|
Size: |
4096
|
|
B02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075406263.0000000000B02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B02000
|
Size: |
49152
|
|
51D6000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.2339516938.00000000051D6000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
51D6000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1375082382.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366164815.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
364C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1429247693.000000000364C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
364C000
|
Size: |
16384
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366102627.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1257557086.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366580037.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
14C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.2337960762.00000000014C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
14C0000
|
Size: |
335872
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
780000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.1108372145.0000000000780000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
780000
|
Size: |
16384
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1365877443.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1258526440.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1257838714.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1367044182.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366232342.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
34D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1155073557.00000000034D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
34D0000
|
Size: |
163840
|
|
9E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1255609637.00000000009E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E0000
|
Size: |
20480
|
|
835D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431392886.000000000835D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
835D000
|
Size: |
12288
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1257594895.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
81A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431061574.00000000081A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
81A0000
|
Size: |
12288
|
|
31E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1194886515.00000000031E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31E0000
|
Size: |
163840
|
|
819F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1374230766.000000000819F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
819F000
|
Size: |
4096
|
|
381E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1429269901.000000000381E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
381E000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
19F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1255351033.000000000019F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
19F000
|
Size: |
28672
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1359875728.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
170000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2336140127.0000000000170000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
170000
|
Size: |
4096
|
|
7BE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108408435.00000000007BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7BE000
|
Size: |
90112
|
|
2900000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1255907096.0000000002900000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2900000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363611401.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
8A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.2336450560.00000000008A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8A0000
|
Size: |
4096
|
|
2A52000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2338363125.0000000002A52000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2A52000
|
Size: |
4096
|
|
1030000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.2337915272.0000000001030000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1030000
|
Size: |
32768
|
|
81AE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1374230766.00000000081AE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
81AE000
|
Size: |
4096
|
|
1A6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2336057436.00000000001A6000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1A6000
|
Size: |
8192
|
|
8400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431495542.0000000008400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8400000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363510457.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
D50000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.2337546426.0000000000D50000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
D50000
|
Size: |
16384
|
|
3024000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1190986654.0000000003024000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3024000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366806682.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
2200000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108636761.0000000002200000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2200000
|
Size: |
8192
|
|
7BA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2336995225.00000000007BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7BA000
|
Size: |
8192
|
|
36AD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1085257134.00000000036AD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36AD000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
28F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2338094699.00000000028F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
28F0000
|
Size: |
12288
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1365305326.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
1F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1087748638.00000000001F0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F0000
|
Size: |
4096
|
|
3C00000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1187682843.0000000003C00000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3C00000
|
Size: |
10485760
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360976836.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
329F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.000000000329F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
329F000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362805874.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
35FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1190723298.00000000035FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35FE000
|
Size: |
458752
|
|
2200000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2337821135.0000000002200000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2200000
|
Size: |
8192
|
|
81A3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1374230766.00000000081A3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
81A3000
|
Size: |
4096
|
|
9CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088044634.00000000009CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9CE000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360556350.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
13A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2336058691.000000000013A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13A000
|
Size: |
24576
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1359908671.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
367000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1088007928.0000000000367000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
367000
|
Size: |
409600
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366703410.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
32A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.00000000032A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32A6000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1375217995.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
81A5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431061574.00000000081A5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
81A5000
|
Size: |
12288
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360733504.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
328D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1368593131.000000000328D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
328D000
|
Size: |
8192
|
|
371E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1084375317.000000000371E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
371E000
|
Size: |
24576
|
|
7A0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2336943463.00000000007A0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7A0000
|
Size: |
4096
|
|
878E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431533705.000000000878E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
878E000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362463737.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
333E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187259860.000000000333E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
333E000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1359724029.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1258637592.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
2EB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1427963218.0000000002EB0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EB0000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363237558.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
B95000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088266275.0000000000B95000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B95000
|
Size: |
475136
|
|
53DC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2339759834.00000000053DC000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
53DC000
|
Size: |
16384
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360435673.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
3553000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1085940221.0000000003553000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3553000
|
Size: |
507904
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
1A9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2336476221.00000000001A9000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A9000
|
Size: |
61440
|
|
37AD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1429269901.00000000037AD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
37AD000
|
Size: |
458752
|
|
328D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.000000000328D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
328D000
|
Size: |
8192
|
|
3234000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1188747522.0000000003234000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3234000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1257949691.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
4FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2336727789.00000000004FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4FC000
|
Size: |
16384
|
|
37A9000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1429269901.00000000037A9000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
37A9000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360365029.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
2E00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187145574.0000000002E00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
4096
|
|
2DC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187131625.0000000002DC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DC0000
|
Size: |
4096
|
|
D6E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1255709815.0000000000D6E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D6E000
|
Size: |
94208
|
|
323E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187239454.000000000323E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
323E000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363461883.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
2144000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2337696029.0000000002144000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2144000
|
Size: |
4096
|
|
890000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1255430764.0000000000890000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
890000
|
Size: |
4096
|
|
36F9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1085671212.00000000036F9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36F9000
|
Size: |
4096
|
|
31E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428473528.00000000031E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31E0000
|
Size: |
4096
|
|
3200000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1088137439.0000000003200000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3200000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
376E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1086268312.000000000376E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
376E000
|
Size: |
24576
|
|
300E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428127306.000000000300E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
300E000
|
Size: |
8192
|
|
940000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.2336623030.0000000000940000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
940000
|
Size: |
4096
|
|
D3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1255667048.0000000000D3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D3E000
|
Size: |
8192
|
|
3306000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.0000000003306000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3306000
|
Size: |
20480
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362723094.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1258443801.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1374858629.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1195466322.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
221184
|
|
3520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1199612976.0000000003520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3520000
|
Size: |
163840
|
|
8141000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1372499971.0000000008141000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8141000
|
Size: |
4096
|
|
2E13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1098994451.0000000002E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E13000
|
Size: |
225280
|
|
28E0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2338056346.00000000028E0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
28E0000
|
Size: |
4096
|
|
890000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.2336341470.0000000000890000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
890000
|
Size: |
4096
|
|
1C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.1108172885.00000000001C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1C0000
|
Size: |
4096
|
|
819B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431061574.000000000819B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
819B000
|
Size: |
12288
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362618183.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
5252000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.2339516938.0000000005252000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5252000
|
Size: |
282624
|
|
8136000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1372499971.0000000008136000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8136000
|
Size: |
8192
|
|
27652000
|
system
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2335765535.0000000027652000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
27652000
|
Size: |
4096
|
|
B74000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1078850207.0000000000B74000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B74000
|
Size: |
28672
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1204741245.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
225280
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1361017566.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
2E13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1098902307.0000000002E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E13000
|
Size: |
200704
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360645614.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
2A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1087866043.00000000002A0000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2A0000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1367144942.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1359692637.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
B73000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1078767478.0000000000B73000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B73000
|
Size: |
32768
|
|
2E13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1090879564.0000000002E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E13000
|
Size: |
225280
|
|
7B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108408435.00000000007B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B0000
|
Size: |
32768
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366907978.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
3430000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1085940221.0000000003430000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3430000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366378851.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
3430000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1086774009.0000000003430000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3430000
|
Size: |
1187840
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362435515.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
CFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2337475466.0000000000CFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CFC000
|
Size: |
16384
|
|
32F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1087941270.000000000032F000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
32F000
|
Size: |
147456
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1359299186.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
36A9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1084375317.00000000036A9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36A9000
|
Size: |
4096
|
|
8165000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431061574.0000000008165000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8165000
|
Size: |
8192
|
|
8B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2337210765.00000000008B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8B0000
|
Size: |
32768
|
|
14C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1255834129.00000000014C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
14C0000
|
Size: |
335872
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363431163.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
960000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.2336783967.0000000000960000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
960000
|
Size: |
4096
|
|
3323000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1088137439.0000000003323000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3323000
|
Size: |
507904
|
|
3228000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.0000000003228000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3228000
|
Size: |
4096
|
|
7BE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2336995225.00000000007BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7BE000
|
Size: |
135168
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360944691.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
36FD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1087484426.00000000036FD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36FD000
|
Size: |
458752
|
|
180000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.1108056052.0000000000180000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
180000
|
Size: |
4096
|
|
8148000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1372499971.0000000008148000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8148000
|
Size: |
4096
|
|
36A9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1085257134.00000000036A9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36A9000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366411151.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1367006993.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1361107272.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
3292000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1368593131.0000000003292000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3292000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366493779.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362174158.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
354000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1087941270.0000000000354000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
354000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366773621.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
2904000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2338133286.0000000002904000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2904000
|
Size: |
4096
|
|
2CE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187114927.0000000002CE0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CE0000
|
Size: |
4096
|
|
190000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.1108075171.0000000000190000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
190000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1365977350.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
3240000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1188647810.0000000003240000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3240000
|
Size: |
16384
|
|
71F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108317398.000000000071F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
71F000
|
Size: |
4096
|
|
367000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1074926818.0000000000367000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
367000
|
Size: |
409600
|
|
2904000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1255907096.0000000002904000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2904000
|
Size: |
4096
|
|
3236000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1188875659.0000000003236000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3236000
|
Size: |
20480
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362943337.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1365942714.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
3017000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1088454192.0000000003017000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3017000
|
Size: |
20480
|
|
1704000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088407970.0000000001704000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1704000
|
Size: |
8192
|
|
3456000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2337872709.0000000003456000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3456000
|
Size: |
10485760
|
|
31D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428452779.00000000031D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31D0000
|
Size: |
16384
|
|
3951000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1429269901.0000000003951000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3951000
|
Size: |
458752
|
|
371E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1085257134.000000000371E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
371E000
|
Size: |
24576
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1190962777.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
65536
|
|
323B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1188808176.000000000323B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
323B000
|
Size: |
20480
|
|
1A6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1255371150.00000000001A6000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1A6000
|
Size: |
8192
|
|
589E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2339849529.000000000589E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
589E000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366617986.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1375040855.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
32F5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.00000000032F5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32F5000
|
Size: |
12288
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362203794.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428433229.00000000030C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C0000
|
Size: |
4096
|
|
34D1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1190723298.00000000034D1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
34D1000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2E13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1105547000.0000000002E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E13000
|
Size: |
225280
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366536227.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
2A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1074772650.00000000002A0000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2A0000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1367114471.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
B95000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075833247.0000000000B95000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B95000
|
Size: |
475136
|
|
1A9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.2336139005.00000000001A9000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A9000
|
Size: |
61440
|
|
36AD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1084825798.00000000036AD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36AD000
|
Size: |
458752
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1365799533.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
35D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1085671212.00000000035D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
35D0000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1365714494.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1258412078.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
884F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431619254.000000000884F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
884F000
|
Size: |
4096
|
|
7B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2336995225.00000000007B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B0000
|
Size: |
32768
|
|
322A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.000000000322A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
322A000
|
Size: |
28672
|
|
7BA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108408435.00000000007BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7BA000
|
Size: |
8192
|
|
818C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1374230766.000000000818C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
818C000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1359268022.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
B4E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088197209.0000000000B4E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B4E000
|
Size: |
118784
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366010605.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
9F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1255626566.00000000009F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9F0000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1258190179.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
323A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1188930760.000000000323A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
323A000
|
Size: |
24576
|
|
16DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088384617.00000000016DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
16DF000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366976681.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360584746.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
3580000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1084375317.0000000003580000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3580000
|
Size: |
1196032
|
|
90A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1255465186.000000000090A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
90A000
|
Size: |
24576
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360796764.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
1A9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1255389785.00000000001A9000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A9000
|
Size: |
61440
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360838078.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
2144000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108600616.0000000002144000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2144000
|
Size: |
4096
|
|
B11000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075406263.0000000000B11000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B11000
|
Size: |
544768
|
|
5D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108276844.00000000005D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D0000
|
Size: |
20480
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366653162.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
394D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1429269901.000000000394D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
394D000
|
Size: |
4096
|
|
372D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1187368086.000000000372D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
372D000
|
Size: |
458752
|
|
3470000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1429157072.0000000003470000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
3470000
|
Size: |
94208
|
|
38CD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1187368086.00000000038CD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
38CD000
|
Size: |
4096
|
|
8189000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431061574.0000000008189000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8189000
|
Size: |
12288
|
|
3000000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187175340.0000000003000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3000000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
AE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088113152.0000000000AE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AE0000
|
Size: |
24576
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1359186887.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363040020.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
D89000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2337601001.0000000000D89000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D89000
|
Size: |
77824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2E13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1105390470.0000000002E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E13000
|
Size: |
135168
|
|
2E13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1090810459.0000000002E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E13000
|
Size: |
200704
|
|
B6D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1078262881.0000000000B6D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B6D000
|
Size: |
57344
|
|
376E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1085671212.000000000376E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
376E000
|
Size: |
24576
|
|
32A1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1368593131.00000000032A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32A1000
|
Size: |
12288
|
|
81AC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1374230766.00000000081AC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
81AC000
|
Size: |
4096
|
|
1700000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088407970.0000000001700000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1700000
|
Size: |
8192
|
|
B6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1078155328.0000000000B6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B6C000
|
Size: |
61440
|
|
C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2335919138.00000000000C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C0000
|
Size: |
4096
|
|
3024000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1195508000.0000000003024000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3024000
|
Size: |
4096
|
|
33E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1084654751.00000000033E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33E0000
|
Size: |
1187840
|
|
D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.1108008926.00000000000D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
D0000
|
Size: |
4096
|
|
3246000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.0000000003246000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3246000
|
Size: |
12288
|
|
5D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2336778991.00000000005D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D0000
|
Size: |
20480
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363114764.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
33C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1429113436.00000000033C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33C0000
|
Size: |
94208
|
|
376E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1087484426.000000000376E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
376E000
|
Size: |
24576
|
|
3503000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1084654751.0000000003503000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3503000
|
Size: |
507904
|
|
3680000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1429269901.0000000003680000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3680000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366195981.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
329F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1368593131.000000000329F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
329F000
|
Size: |
4096
|
|
B6C000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1088222478.0000000000B6C000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
B6C000
|
Size: |
20480
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363705944.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
347F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187296421.000000000347F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
347F000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1364083317.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
2E13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1102971174.0000000002E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E13000
|
Size: |
225280
|
|
2786C000
|
system
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2335765535.000000002786C000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
2786C000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1365760144.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
1F1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2336688395.00000000001F1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1F1000
|
Size: |
12288
|
|
2E13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1105326023.0000000002E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E13000
|
Size: |
69632
|
|
3010000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428201548.0000000003010000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3010000
|
Size: |
4096
|
|
8153000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431061574.0000000008153000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8153000
|
Size: |
24576
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360673274.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1365337643.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
3279000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.0000000003279000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3279000
|
Size: |
36864
|
|
2050000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.1108526762.0000000002050000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2050000
|
Size: |
925696
|
|
25A67600000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2337230531.0000025A67600000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
25A67600000
|
Size: |
221184
|
|
780000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2336889986.0000000000780000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
780000
|
Size: |
16384
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1361878983.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
9BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088044634.00000000009BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9BE000
|
Size: |
8192
|
|
322E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1188930760.000000000322E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
322E000
|
Size: |
28672
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1258271777.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
13A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108023496.000000000013A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13A000
|
Size: |
24576
|
|
36FD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1085671212.00000000036FD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36FD000
|
Size: |
458752
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1374820782.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
190000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2336291216.0000000000190000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
190000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1361734999.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363771239.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
52DC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2339730133.00000000052DC000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
52DC000
|
Size: |
16384
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1359768296.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
191000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000006.00000000.1255331525.0000000000191000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
191000
|
Size: |
57344
|
|
D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2335986014.00000000000D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
D0000
|
Size: |
4096
|
|
9E5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2337117012.00000000009E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E5000
|
Size: |
12288
|
|
1A6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108135416.00000000001A6000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1A6000
|
Size: |
8192
|
|
337E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187279608.000000000337E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
337E000
|
Size: |
8192
|
|
2FCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1427981811.0000000002FCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FCE000
|
Size: |
8192
|
|
950000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.2336691657.0000000000950000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
950000
|
Size: |
4096
|
|
3234000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1188975541.0000000003234000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3234000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1195599066.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363934029.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
823E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1371779259.000000000823E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
823E000
|
Size: |
618496
|
|
D60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2337601001.0000000000D60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D60000
|
Size: |
32768
|
|
CFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1255646557.0000000000CFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CFC000
|
Size: |
16384
|
|
D6A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2337601001.0000000000D6A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D6A000
|
Size: |
8192
|
|
23E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1087770382.000000000023E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
23E000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362652901.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1374998922.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1258155641.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
AE8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088113152.0000000000AE8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AE8000
|
Size: |
61440
|
|
2E13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1098827390.0000000002E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E13000
|
Size: |
135168
|
|
3580000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1084825798.0000000003580000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3580000
|
Size: |
1196032
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1361813339.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362579890.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
3017000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1088382698.0000000003017000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3017000
|
Size: |
20480
|
|
1A6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2336431342.00000000001A6000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1A6000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1361649777.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
35D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1087484426.00000000035D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
35D0000
|
Size: |
1196032
|
|
379E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1187368086.000000000379E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
379E000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2D2C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1256100264.0000000002D2C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2D2C000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2D2C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2338363125.0000000002D2C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2D2C000
|
Size: |
53248
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1258238447.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
3101000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187224133.0000000003101000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3101000
|
Size: |
4096
|
|
191000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000006.00000002.2335916452.0000000000191000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
191000
|
Size: |
57344
|
|
2E30000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1427928795.0000000002E30000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
2E30000
|
Size: |
274432
|
|
2A1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1074790635.00000000002A1000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
2A1000
|
Size: |
581632
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360400791.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
4D46000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1187682843.0000000004D46000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4D46000
|
Size: |
10485760
|
|
C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.1107993515.00000000000C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C0000
|
Size: |
4096
|
|
B6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1078767478.0000000000B6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B6C000
|
Size: |
20480
|
|
9E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2337117012.00000000009E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9E0000
|
Size: |
16384
|
|
191000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000002.00000000.1108095978.0000000000191000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
191000
|
Size: |
57344
|
|
36F9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1086268312.00000000036F9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36F9000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1367499074.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360466874.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1257720648.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1364391083.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366134643.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
1E0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2336636846.00000000001E0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1E0000
|
Size: |
4096
|
|
813B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1372499971.000000000813B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
813B000
|
Size: |
8192
|
|
3553000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1085544747.0000000003553000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3553000
|
Size: |
507904
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1257496665.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362000383.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1361843547.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
35D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1086268312.00000000035D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
35D0000
|
Size: |
1196032
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362975972.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
3400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1090482040.0000000003400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3400000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3114000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2338363125.0000000003114000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3114000
|
Size: |
4096
|
|
814E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1372499971.000000000814E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
814E000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
32BC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.00000000032BC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32BC000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
36AD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1084375317.00000000036AD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36AD000
|
Size: |
458752
|
|
B6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076233949.0000000000B6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B6C000
|
Size: |
4096
|
|
3233000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.0000000003233000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3233000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
33E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1084228634.00000000033E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33E0000
|
Size: |
1187840
|
|
3220000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.0000000003220000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3220000
|
Size: |
24576
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1365373325.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
352D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1090482040.000000000352D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
352D000
|
Size: |
458752
|
|
1030000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1255796217.0000000001030000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1030000
|
Size: |
32768
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360614730.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362691057.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
77E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108355256.000000000077E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
77E000
|
Size: |
8192
|
|
C19000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088331591.0000000000C19000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C19000
|
Size: |
73728
|
|
575E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2339790021.000000000575E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
575E000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362385824.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
32F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1074843379.000000000032F000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
32F000
|
Size: |
147456
|
|
32B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1368593131.00000000032B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32B3000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363171499.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
35FA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1190723298.00000000035FA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35FA000
|
Size: |
4096
|
|
970000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2336873693.0000000000970000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
970000
|
Size: |
4096
|
|
290000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1087846710.0000000000290000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
290000
|
Size: |
24576
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1258597437.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
81B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1374230766.00000000081B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
81B1000
|
Size: |
4096
|
|
B43000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076233949.0000000000B43000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B43000
|
Size: |
163840
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362058498.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
28E0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1255877508.00000000028E0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
28E0000
|
Size: |
4096
|
|
102F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1255776411.000000000102F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
102F000
|
Size: |
4096
|
|
27C54000
|
system
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2335765535.0000000027C54000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
27C54000
|
Size: |
4096
|
|
30AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428378187.00000000030AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
30AE000
|
Size: |
8192
|
|
27592000
|
system
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2335765535.0000000027592000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
27592000
|
Size: |
4096
|
|
190000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.2335772445.0000000000190000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
190000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1257456431.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
8133000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431061574.0000000008133000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8133000
|
Size: |
12288
|
|
3250000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.0000000003250000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3250000
|
Size: |
163840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2BF8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1427909271.0000000002BF8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2BF8000
|
Size: |
32768
|
|
17B0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088467268.00000000017B0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
17B0000
|
Size: |
290816
|
|
36F9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1087484426.00000000036F9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36F9000
|
Size: |
4096
|
|
4CDE000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1187682843.0000000004CDE000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4CDE000
|
Size: |
4096
|
|
1D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108210252.00000000001D0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D0000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366296189.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
83DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431466834.00000000083DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83DF000
|
Size: |
4096
|
|
12DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088365179.00000000012DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12DE000
|
Size: |
8192
|
|
33E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1085120732.00000000033E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33E0000
|
Size: |
1187840
|
|
2A52000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1256100264.0000000002A52000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2A52000
|
Size: |
4096
|
|
4FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108260553.00000000004FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4FC000
|
Size: |
16384
|
|
3430000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1085544747.0000000003430000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3430000
|
Size: |
1187840
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366837351.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1361055704.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1257895607.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
B74000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088246503.0000000000B74000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B74000
|
Size: |
4096
|
|
323A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1188699573.000000000323A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
323A000
|
Size: |
24576
|
|
2E02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187145574.0000000002E02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E02000
|
Size: |
20480
|
|
1A9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.1108149204.00000000001A9000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A9000
|
Size: |
61440
|
|
3503000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1085120732.0000000003503000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3503000
|
Size: |
507904
|
|
191000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000002.00000002.2336346314.0000000000191000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
191000
|
Size: |
57344
|
|
19F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2336396806.000000000019F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
19F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
32CD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.00000000032CD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32CD000
|
Size: |
16384
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362029009.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1359800530.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366450838.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
585F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2339822123.000000000585F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
585F000
|
Size: |
4096
|
|
2E13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1090692353.0000000002E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E13000
|
Size: |
69632
|
|
51FB000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.2339516938.00000000051FB000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
51FB000
|
Size: |
12288
|
|
329C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1368593131.000000000329C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
329C000
|
Size: |
8192
|
|
4094000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1429623747.0000000004094000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4094000
|
Size: |
4096
|
|
3300000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.0000000003300000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3300000
|
Size: |
12288
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360497561.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
306E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428312509.000000000306E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
306E000
|
Size: |
8192
|
|
B27000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1078155328.0000000000B27000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B27000
|
Size: |
32768
|
|
329C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.000000000329C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
329C000
|
Size: |
8192
|
|
812A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1367360274.000000000812A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
812A000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
34D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1105245735.00000000034D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
34D0000
|
Size: |
163840
|
|
5746000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1187682843.0000000005746000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
5746000
|
Size: |
6332416
|
|
2E13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1102740277.0000000002E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E13000
|
Size: |
69632
|
|
2BBB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1427881611.0000000002BBB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2BBB000
|
Size: |
20480
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362261647.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
2310000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2337872709.0000000002310000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
2310000
|
Size: |
10485760
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1258064756.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
8175000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431061574.0000000008175000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8175000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1365150576.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
38D1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1187368086.00000000038D1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
38D1000
|
Size: |
458752
|
|
36A9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1084825798.00000000036A9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36A9000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1367078100.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
C2B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1078716581.0000000000C2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C2B000
|
Size: |
471040
|
|
87CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431555888.00000000087CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
87CF000
|
Size: |
4096
|
|
190000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1255311377.0000000000190000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
190000
|
Size: |
4096
|
|
3200000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1098390769.0000000003200000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3200000
|
Size: |
163840
|
|
3020000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428219788.0000000003020000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3020000
|
Size: |
16384
|
|
32A9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1368593131.00000000032A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32A9000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362118936.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
D6A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1255709815.0000000000D6A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D6A000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366262376.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362342125.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1364004779.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360262582.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
3E56000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2337872709.0000000003E56000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3E56000
|
Size: |
6332416
|
|
366F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1190723298.000000000366F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
366F000
|
Size: |
24576
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1361562428.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1365262776.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366943103.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360525931.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1364768295.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
32EB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.00000000032EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32EB000
|
Size: |
4096
|
|
9DB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088044634.00000000009DB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9DB000
|
Size: |
20480
|
|
39C2000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1429269901.00000000039C2000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
39C2000
|
Size: |
40960
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360903862.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
960000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1255514585.0000000000960000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
960000
|
Size: |
4096
|
|
B4E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1078767478.0000000000B4E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B4E000
|
Size: |
118784
|
|
C7B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187069616.0000000000C7B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7B000
|
Size: |
20480
|
|
32B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.00000000032B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32B3000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1258560305.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
980000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2336998693.0000000000980000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
980000
|
Size: |
4096
|
|
814B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431061574.000000000814B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
814B000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1258492915.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
3942000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1187368086.0000000003942000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3942000
|
Size: |
40960
|
|
3024000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1195527230.0000000003024000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3024000
|
Size: |
4096
|
|
2050000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2337451852.0000000002050000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2050000
|
Size: |
925696
|
|
B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2335780244.00000000000B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B0000
|
Size: |
4096
|
|
301E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187191686.000000000301E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
301E000
|
Size: |
12288
|
|
81B6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1374230766.00000000081B6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
81B6000
|
Size: |
8192
|
|
35E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1087993576.000000000035E000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
35E000
|
Size: |
36864
|
|
34D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1102659253.00000000034D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
34D0000
|
Size: |
163840
|
|
9F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2337265557.00000000009F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
9F0000
|
Size: |
4096
|
|
880000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1255409679.0000000000880000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
880000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1365913435.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
8192000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1374230766.0000000008192000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8192000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366069515.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
970000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1255534344.0000000000970000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
970000
|
Size: |
4096
|
|
32D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.00000000032D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32D3000
|
Size: |
12288
|
|
2900000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2338133286.0000000002900000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2900000
|
Size: |
8192
|
|
354000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1074843379.0000000000354000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
354000
|
Size: |
40960
|
|
839E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431424656.000000000839E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
839E000
|
Size: |
8192
|
|
81AE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431061574.00000000081AE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
81AE000
|
Size: |
53248
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1367209203.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362842492.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1359239806.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
3553000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1086774009.0000000003553000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3553000
|
Size: |
507904
|
|
1E0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108228910.00000000001E0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1E0000
|
Size: |
4096
|
|
980000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1255552682.0000000000980000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
980000
|
Size: |
4096
|
|
9D1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.2337052491.00000000009D1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
9D1000
|
Size: |
12288
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362533993.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
3446000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1188444639.0000000003446000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3446000
|
Size: |
512000
|
|
C0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088313128.0000000000C0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C0A000
|
Size: |
57344
|
|
BB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075368928.0000000000BB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BB5000
|
Size: |
4096
|
|
32CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32CA000
|
Size: |
4096
|
|
3520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1258715432.0000000003520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3520000
|
Size: |
163840
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1365185942.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
CA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187100635.0000000000CA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CA0000
|
Size: |
4096
|
|
230F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108673215.000000000230F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
230F000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1362088792.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1204821193.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
2E13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1090751525.0000000002E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E13000
|
Size: |
135168
|
|
B1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088113152.0000000000B1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B1A000
|
Size: |
53248
|
|
3520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1202153639.0000000003520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3520000
|
Size: |
163840
|
|
3A92000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1429623747.0000000003A92000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3A92000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1361909051.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
3012000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187191686.0000000003012000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3012000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363345544.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
9FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088044634.00000000009FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9FC000
|
Size: |
16384
|
|
1C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2336517865.00000000001C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1C0000
|
Size: |
4096
|
|
3529000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1090482040.0000000003529000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3529000
|
Size: |
4096
|
|
2B12000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2338363125.0000000002B12000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2B12000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366040946.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1257629779.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
3005000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1088360596.0000000003005000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3005000
|
Size: |
49152
|
|
82E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431364064.00000000082E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82E0000
|
Size: |
4096
|
|
322E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1188699573.000000000322E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
322E000
|
Size: |
28672
|
|
90A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2336527026.000000000090A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
90A000
|
Size: |
24576
|
|
280000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1087811989.0000000000280000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
280000
|
Size: |
4096
|
|
880000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.2336232792.0000000000880000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
880000
|
Size: |
4096
|
|
359D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1429197548.000000000359D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
359D000
|
Size: |
12288
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363646851.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
D60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1255709815.0000000000D60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D60000
|
Size: |
32768
|
|
3311000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.0000000003311000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3311000
|
Size: |
57344
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1361700055.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
32E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.00000000032E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32E0000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1359940613.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
D6E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2337601001.0000000000D6E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D6E000
|
Size: |
94208
|
|
B6D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076202649.0000000000B6D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B6D000
|
Size: |
57344
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1364243068.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1365406421.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
8A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1255448658.00000000008A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8A0000
|
Size: |
4096
|
|
2910000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.2338197750.0000000002910000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2910000
|
Size: |
925696
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1359364525.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
27E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1087795459.000000000027E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
27E000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363804791.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1258305309.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
3503000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1084228634.0000000003503000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3503000
|
Size: |
507904
|
|
32A9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.00000000032A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32A9000
|
Size: |
4096
|
|
32FB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.00000000032FB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32FB000
|
Size: |
12288
|
|
362000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1074892492.0000000000362000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
362000
|
Size: |
8192
|
|
9D1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1255591160.00000000009D1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
9D1000
|
Size: |
12288
|
|
B27000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1078767478.0000000000B27000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B27000
|
Size: |
65536
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363076976.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
32C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.00000000032C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32C2000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1367625649.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363962832.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1258368244.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
81A8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1374230766.00000000081A8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
81A8000
|
Size: |
4096
|
|
359E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1090482040.000000000359E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
359E000
|
Size: |
24576
|
|
2E13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1102808664.0000000002E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E13000
|
Size: |
135168
|
|
19F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.1108117622.000000000019F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
19F000
|
Size: |
28672
|
|
8220000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431344611.0000000008220000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8220000
|
Size: |
4096
|
|
61E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000000.1108298701.000000000061E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61E000
|
Size: |
8192
|
|
35E000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1074892492.000000000035E000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
35E000
|
Size: |
8192
|
|
2910000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1255954676.0000000002910000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2910000
|
Size: |
925696
|
|
8199000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1374230766.0000000008199000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8199000
|
Size: |
4096
|
|
35DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1429216573.00000000035DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35DE000
|
Size: |
8192
|
|
1790000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088444752.0000000001790000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1790000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1359654790.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360307701.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
8B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.1108465084.00000000008B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8B0000
|
Size: |
32768
|
|
8153000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1372499971.0000000008153000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8153000
|
Size: |
4096
|
|
C40000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000000.1108485875.0000000000C40000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C40000
|
Size: |
335872
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
180000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2336233447.0000000000180000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
180000
|
Size: |
4096
|
|
B12000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075833247.0000000000B12000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B12000
|
Size: |
339968
|
|
3580000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1085257134.0000000003580000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3580000
|
Size: |
1196032
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363563780.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1363400227.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
D50000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1255686573.0000000000D50000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
D50000
|
Size: |
16384
|
|
2140000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2337696029.0000000002140000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2140000
|
Size: |
8192
|
|
1800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1088500340.0000000001800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1800000
|
Size: |
8192
|
|
1D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2336578185.00000000001D0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D0000
|
Size: |
4096
|
|
2E13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1105462836.0000000002E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E13000
|
Size: |
200704
|
|
39D2000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1429623747.00000000039D2000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
39D2000
|
Size: |
4096
|
|
3292000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1428490368.0000000003292000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3292000
|
Size: |
8192
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1359841717.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1364337157.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1257676055.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1366873132.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
880E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1431598595.000000000880E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
880E000
|
Size: |
8192
|
|
32A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1368593131.00000000032A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32A6000
|
Size: |
8192
|
|
AE6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.2337337273.0000000000AE6000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
AE6000
|
Size: |
4096
|
|
36FD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1086268312.00000000036FD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36FD000
|
Size: |
458752
|
|
B65000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075504466.0000000000B65000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B65000
|
Size: |
671744
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1364161989.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
B96000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1075290891.0000000000B96000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B96000
|
Size: |
131072
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1374894719.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
B2E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1076287942.0000000000B2E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B2E000
|
Size: |
86016
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1257984485.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1365231433.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360703130.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
8192
|
|
C3C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1187051850.0000000000C3C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C3C000
|
Size: |
16384
|
|
3323000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1188444639.0000000003323000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3323000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
30C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1360869607.00000000030C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30C1000
|
Size: |
4096
|
|
371E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1084825798.000000000371E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
371E000
|
Size: |
24576
|
|