400000
|
remote allocation
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1789475310.0000000000400000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
290816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
6F0000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000004.00000002.2563154374.00000000006F0000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
6F0000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
DB0000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000004.00000002.2564178771.0000000000DB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
DB0000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
5910000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1839152030.0000000005910000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
5910000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
D60000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000004.00000002.2564124185.0000000000D60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
D60000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
2E70000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000003.00000002.2564572270.0000000002E70000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
2E70000
|
Size: |
5222400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
1880000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1791238666.0000000001880000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
1880000
|
Size: |
5222400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
145F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1789923535.000000000145F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
145F000
|
Size: |
4096
|
|
A7A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1790353169.0000000000A7A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A7A000
|
Size: |
24576
|
|
EFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2563324017.0000000000EFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EFC000
|
Size: |
16384
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961777725.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B8F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2563217237.0000000000B8F000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B8F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
6276000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331725965.0000000006276000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6276000
|
Size: |
8192
|
|
B1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000B1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B1A000
|
Size: |
36864
|
|
148D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326939138.000000000148D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
148D000
|
Size: |
12288
|
|
4892000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1792254365.0000000004892000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4892000
|
Size: |
4096
|
|
816F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2568978641.000000000816F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
816F000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960054708.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
FE5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326790707.0000000000FE5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FE5000
|
Size: |
12288
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962963035.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
5A3C000
|
system
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2567659913.0000000005A3C000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
5A3C000
|
Size: |
819200
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1964019079.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000B2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B2D000
|
Size: |
12288
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960747471.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
4AAE000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.2564592537.0000000004AAE000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4AAE000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
524B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1330846274.000000000524B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
524B000
|
Size: |
20480
|
|
BEA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709066186.0000000000BEA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BEA000
|
Size: |
24576
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963164778.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959235176.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
1FAEAFA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2081099015.000001FAEAFA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1FAEAFA0000
|
Size: |
32768
|
|
12F7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326834638.00000000012F7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12F7000
|
Size: |
36864
|
|
128C000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.2563931581.000000000128C000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
128C000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961078843.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
791A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1332857527.000000000791A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
791A000
|
Size: |
118784
|
|
56C6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1330918657.00000000056C6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56C6000
|
Size: |
16384
|
|
A85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1790751687.0000000000A85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A85000
|
Size: |
24576
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963960718.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
3BF9000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1791238666.0000000003BF9000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3BF9000
|
Size: |
5689344
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1958883257.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
5C60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331565779.0000000005C60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5C60000
|
Size: |
65536
|
|
1746000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1789941757.0000000001746000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
1746000
|
Size: |
8192
|
|
116E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2563770174.000000000116E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
116E000
|
Size: |
16384
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963137100.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
1230000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.2563931581.0000000001230000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
1230000
|
Size: |
331776
|
|
16D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327299759.00000000016D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16D0000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959740071.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
5648000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2565056026.0000000005648000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5648000
|
Size: |
8192
|
|
8D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563232778.00000000008D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D0000
|
Size: |
4096
|
|
4710000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1803831345.0000000004710000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4710000
|
Size: |
159744
|
|
7ABC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2566567250.0000000007ABC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7ABC000
|
Size: |
20480
|
|
B99000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1709046928.0000000000B99000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B99000
|
Size: |
61440
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961044163.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960296334.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
1060000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709196239.0000000001060000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1060000
|
Size: |
20480
|
|
16A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327279513.00000000016A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16A0000
|
Size: |
4096
|
|
169F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327263211.000000000169F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
169F000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962136541.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
2B05C000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2079258002.000000002B05C000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
2B05C000
|
Size: |
819200
|
|
4179000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1329764588.0000000004179000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4179000
|
Size: |
3149824
|
|
1FAECB03000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2081250288.000001FAECB03000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1FAECB03000
|
Size: |
16384
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959482490.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
4C52000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.2564592537.0000000004C52000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4C52000
|
Size: |
40960
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1957803067.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
7A8B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2566567250.0000000007A8B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A8B000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
17C8000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1789941757.00000000017C8000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
17C8000
|
Size: |
16384
|
|
F20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2563407362.0000000000F20000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F20000
|
Size: |
4096
|
|
1100000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709280268.0000000001100000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1100000
|
Size: |
4096
|
|
7AAA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1975650068.0000000007AAA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AAA000
|
Size: |
8192
|
|
F0A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1304055335.0000000000F0A000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F0A000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
58D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331453721.00000000058D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
58D0000
|
Size: |
65536
|
|
B38000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000B38000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B38000
|
Size: |
12288
|
|
4660000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.2564283606.0000000004660000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
4660000
|
Size: |
94208
|
|
83073FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2080869456.00000083073FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83073FE000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960873455.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
5850000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331313703.0000000005850000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5850000
|
Size: |
65536
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1958330777.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
A8B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1790663468.0000000000A8B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A8B000
|
Size: |
20480
|
|
45B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2564233566.00000000045B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
45B0000
|
Size: |
94208
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959271055.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
2AD82000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2079258002.000000002AD82000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
2AD82000
|
Size: |
4096
|
|
16F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327394855.00000000016F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16F0000
|
Size: |
40960
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959119955.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959881738.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961279882.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963863805.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
105E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2563495855.000000000105E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
105E000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963690358.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1958837395.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
62A7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331786294.00000000062A7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
62A7000
|
Size: |
57344
|
|
10E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2563711636.00000000010E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
10E0000
|
Size: |
16384
|
|
1FAECB10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2081250288.000001FAECB10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1FAECB10000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959951653.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
4F3C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2565056026.0000000004F3C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4F3C000
|
Size: |
819200
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963284161.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
2D7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2564420639.0000000002D7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D7F000
|
Size: |
4096
|
|
1FAECB13000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2081250288.000001FAECB13000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1FAECB13000
|
Size: |
16384
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963544446.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963775765.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
16ED000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1327377216.00000000016ED000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
16ED000
|
Size: |
4096
|
|
B33000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000B33000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B33000
|
Size: |
8192
|
|
C70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563946296.0000000000C70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C70000
|
Size: |
16384
|
|
1FAEAFD3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2031873798.000001FAEAFD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1FAEAFD3000
|
Size: |
28672
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961009897.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
A10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563288861.0000000000A10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A10000
|
Size: |
4096
|
|
31C2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327895831.00000000031C2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31C2000
|
Size: |
4911104
|
|
AF6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1968840124.0000000000AF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AF6000
|
Size: |
12288
|
|
5AA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331510431.0000000005AA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5AA0000
|
Size: |
8192
|
|
58E0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1331480671.00000000058E0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
58E0000
|
Size: |
4096
|
|
1FAECCCE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2031644744.000001FAECCCE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1FAECCCE000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963429620.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960193770.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
1282000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.2563931581.0000000001282000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
1282000
|
Size: |
4096
|
|
5CA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331661984.0000000005CA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5CA0000
|
Size: |
65536
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962374898.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
58B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331410933.00000000058B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
58B0000
|
Size: |
65536
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959666904.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
BD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1789663577.0000000000BD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BD0000
|
Size: |
4096
|
|
B99000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2563262264.0000000000B99000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B99000
|
Size: |
61440
|
|
1310000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326858587.0000000001310000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1310000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961743333.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
489E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2564464005.000000000489E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
489E000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962229723.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962710173.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
7FDF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2566807977.0000000007FDF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7FDF000
|
Size: |
4096
|
|
ACB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1965484572.0000000000ACB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ACB000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
10A0000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2563660968.00000000010A0000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10A0000
|
Size: |
12288
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1796935142.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
217088
|
|
7B30000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1333394173.0000000007B30000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
7B30000
|
Size: |
569344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
31BD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327895831.00000000031BD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31BD000
|
Size: |
16384
|
|
5762000
|
system
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2567659913.0000000005762000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
5762000
|
Size: |
4096
|
|
135E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1789906207.000000000135E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
135E000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959986128.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960830605.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1976343400.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
2BA4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2564347070.0000000002BA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2BA4000
|
Size: |
4096
|
|
B20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2563112074.0000000000B20000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B20000
|
Size: |
4096
|
|
AF1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1968840124.0000000000AF1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AF1000
|
Size: |
4096
|
|
7A60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1964371083.0000000007A60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A60000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2D80000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1709485370.0000000002D80000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2D80000
|
Size: |
925696
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961443331.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
BCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1789646291.0000000000BCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BCE000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1976307034.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
7902000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1332857527.0000000007902000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7902000
|
Size: |
36864
|
|
B25000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000B25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B25000
|
Size: |
12288
|
|
7AE0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1333256846.0000000007AE0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7AE0000
|
Size: |
65536
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963398834.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
12A8000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.2563931581.00000000012A8000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
12A8000
|
Size: |
12288
|
|
31F9000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1791238666.00000000031F9000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
31F9000
|
Size: |
10485760
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959386735.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
19D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327648999.00000000019D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
19D0000
|
Size: |
4096
|
|
182E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327626176.000000000182E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
182E000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1792454606.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
65536
|
|
7ABE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1333146210.0000000007ABE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7ABE000
|
Size: |
8192
|
|
8F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1792474084.00000000008F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F4000
|
Size: |
4096
|
|
F20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1709134323.0000000000F20000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F20000
|
Size: |
4096
|
|
AD5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1965675532.0000000000AD5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AD5000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960400764.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
77CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1332474299.00000000077CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77CE000
|
Size: |
28672
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960673863.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
809E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2566873310.000000000809E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
809E000
|
Size: |
8192
|
|
7C2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1333706746.0000000007C2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7C2E000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962997880.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
3381000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.2564572270.0000000003381000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3381000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963109392.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B80000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1708984243.0000000000B80000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B80000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960020673.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
AC6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1965484572.0000000000AC6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AC6000
|
Size: |
4096
|
|
ADF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000ADF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ADF000
|
Size: |
8192
|
|
6260000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331689308.0000000006260000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6260000
|
Size: |
4096
|
|
174D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1789941757.000000000174D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
174D000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962197338.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
56C1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1330918657.00000000056C1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56C1000
|
Size: |
16384
|
|
B4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B4A000
|
Size: |
53248
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960975574.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
56BE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1330918657.00000000056BE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56BE000
|
Size: |
8192
|
|
7AA5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1975650068.0000000007AA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AA5000
|
Size: |
4096
|
|
5178000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1330812585.0000000005178000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5178000
|
Size: |
4096
|
|
136D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326898015.000000000136D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
136D000
|
Size: |
12288
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962885007.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
67B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563037971.000000000067B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
67B000
|
Size: |
20480
|
|
1717000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1327563218.0000000001717000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1717000
|
Size: |
4096
|
|
1491000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326939138.0000000001491000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1491000
|
Size: |
20480
|
|
83083FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2080909619.00000083083FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83083FE000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962912032.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
113E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2563770174.000000000113E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
113E000
|
Size: |
94208
|
|
1700000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327444810.0000000001700000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1700000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961918436.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
129C000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.2563931581.000000000129C000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
129C000
|
Size: |
8192
|
|
13AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326918668.00000000013AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13AE000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959192281.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959774411.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
F30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709150592.0000000000F30000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F30000
|
Size: |
4096
|
|
8F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1797257267.00000000008F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F4000
|
Size: |
4096
|
|
B86E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1334508807.000000000B86E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B86E000
|
Size: |
8192
|
|
B80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1789629443.0000000000B80000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B80000
|
Size: |
4096
|
|
2B4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2564287076.0000000002B4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B4E000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960508396.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
132F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709349502.000000000132F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
132F000
|
Size: |
4096
|
|
1418000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326939138.0000000001418000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1418000
|
Size: |
385024
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960608639.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
1416000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326939138.0000000001416000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1416000
|
Size: |
4096
|
|
56F3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331094442.00000000056F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
56F3000
|
Size: |
12288
|
|
F38000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1789730108.0000000000F38000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F38000
|
Size: |
110592
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
B20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1708956532.0000000000B20000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B20000
|
Size: |
4096
|
|
B30000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1708970283.0000000000B30000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B30000
|
Size: |
4096
|
|
7AA8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2566567250.0000000007AA8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AA8000
|
Size: |
8192
|
|
1FAEAE41000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2080947822.000001FAEAE41000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
1FAEAE41000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959444613.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
6148000
|
system
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2567659913.0000000006148000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
6148000
|
Size: |
8192
|
|
E42000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1303968425.0000000000E42000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E42000
|
Size: |
815104
|
|
161E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1789941757.000000000161E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
161E000
|
Size: |
24576
|
|
1330000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1709364432.0000000001330000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1330000
|
Size: |
36864
|
|
13D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326939138.00000000013D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13D0000
|
Size: |
36864
|
|
5C90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331626938.0000000005C90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C90000
|
Size: |
12288
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1806636525.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
7AB2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2566567250.0000000007AB2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AB2000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1964490281.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
6B8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563124498.00000000006B8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6B8000
|
Size: |
32768
|
|
316E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327813700.000000000316E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
316E000
|
Size: |
8192
|
|
BAAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1334634477.000000000BAAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BAAE000
|
Size: |
8192
|
|
1FAECCA6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2031788278.000001FAECCA6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1FAECCA6000
|
Size: |
4096
|
|
7A9E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1975650068.0000000007A9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A9E000
|
Size: |
16384
|
|
19E7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327672667.00000000019E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19E7000
|
Size: |
32768
|
|
1480000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1789941757.0000000001480000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
1480000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1964047191.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962453003.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
A85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1790725992.0000000000A85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A85000
|
Size: |
24576
|
|
56AB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1330918657.00000000056AB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56AB000
|
Size: |
69632
|
|
48F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2564530231.00000000048F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
48F0000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959310672.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960229534.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
4A3D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.2564592537.0000000004A3D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A3D000
|
Size: |
458752
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963026076.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
1FAEAFD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2031873798.000001FAEAFD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1FAEAFD0000
|
Size: |
4096
|
|
ABA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000ABA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ABA000
|
Size: |
8192
|
|
F30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1789730108.0000000000F30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F30000
|
Size: |
24576
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1958709633.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
80DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2566892771.00000000080DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
80DF000
|
Size: |
4096
|
|
56CD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1330918657.00000000056CD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56CD000
|
Size: |
69632
|
|
7D2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1333810880.0000000007D2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7D2E000
|
Size: |
8192
|
|
A85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1790353169.0000000000A85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A85000
|
Size: |
24576
|
|
F55000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1789730108.0000000000F55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F55000
|
Size: |
8192
|
|
54B6000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2565056026.00000000054B6000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
54B6000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7A7B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2566567250.0000000007A7B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A7B000
|
Size: |
8192
|
|
10E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1709259661.00000000010E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
10E0000
|
Size: |
16384
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961315122.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
7A81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2566567250.0000000007A81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A81000
|
Size: |
4096
|
|
B3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000B3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B3D000
|
Size: |
40960
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962274956.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
A60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000A60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A60000
|
Size: |
24576
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963488052.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1976376678.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
2AE9C000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2079258002.000000002AE9C000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
2AE9C000
|
Size: |
4096
|
|
147E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326939138.000000000147E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
147E000
|
Size: |
20480
|
|
5A1C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331493746.0000000005A1C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A1C000
|
Size: |
16384
|
|
478D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2564334370.000000000478D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
478D000
|
Size: |
12288
|
|
8306BFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2080839768.0000008306BFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8306BFC000
|
Size: |
16384
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960089144.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
EFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709083647.0000000000EFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EFC000
|
Size: |
16384
|
|
7370000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331838813.0000000007370000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7370000
|
Size: |
32768
|
|
7AF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1333343269.0000000007AF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7AF0000
|
Size: |
65536
|
|
1FAEADF0000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2080947822.000001FAEADF0000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
1FAEADF0000
|
Size: |
270336
|
|
F30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2563432637.0000000000F30000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F30000
|
Size: |
4096
|
|
534D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1330867387.000000000534D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
534D000
|
Size: |
12288
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963747140.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960942340.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
2BA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2564347070.0000000002BA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2BA0000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959153415.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
4BDD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.2564592537.0000000004BDD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4BDD000
|
Size: |
4096
|
|
56A4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1330918657.00000000056A4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56A4000
|
Size: |
16384
|
|
1010000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2563461793.0000000001010000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1010000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961553034.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
1706000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1327488303.0000000001706000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1706000
|
Size: |
8192
|
|
BEA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2563289268.0000000000BEA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BEA000
|
Size: |
24576
|
|
1060000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2563526197.0000000001060000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1060000
|
Size: |
16384
|
|
58C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331441779.00000000058C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
58C0000
|
Size: |
4096
|
|
6279000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331752734.0000000006279000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6279000
|
Size: |
69632
|
|
27F9000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1791238666.00000000027F9000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
27F9000
|
Size: |
10485760
|
|
73E2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331910191.00000000073E2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
73E2000
|
Size: |
1572864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1320000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326879795.0000000001320000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1320000
|
Size: |
8192
|
|
2AE42000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2079258002.000000002AE42000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
2AE42000
|
Size: |
8192
|
|
1830000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1791203964.0000000001830000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1830000
|
Size: |
8192
|
|
5FB6000
|
system
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2567659913.0000000005FB6000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
5FB6000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4BE1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.2564592537.0000000004BE1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4BE1000
|
Size: |
458752
|
|
2B444000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2079258002.000000002B444000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
2B444000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1066000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2563526197.0000000001066000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1066000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959553971.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963602120.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959845125.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
1702000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327466754.0000000001702000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1702000
|
Size: |
4096
|
|
1D91000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1791238666.0000000001D91000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
1D91000
|
Size: |
4096
|
|
1485000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326939138.0000000001485000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1485000
|
Size: |
12288
|
|
A81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1790632134.0000000000A81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A81000
|
Size: |
20480
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961860731.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961111549.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
306E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327793911.000000000306E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
306E000
|
Size: |
8192
|
|
1071000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1709215991.0000000001071000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1071000
|
Size: |
12288
|
|
B80000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2563167291.0000000000B80000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B80000
|
Size: |
4096
|
|
13DA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326939138.00000000013DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13DA000
|
Size: |
8192
|
|
116C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1862239491.000000000116C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
116C000
|
Size: |
24576
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959704173.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
1130000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709300027.0000000001130000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1130000
|
Size: |
32768
|
|
5710000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331146243.0000000005710000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5710000
|
Size: |
16384
|
|
47CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2564364382.00000000047CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
47CE000
|
Size: |
8192
|
|
77C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1332474299.00000000077C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77C0000
|
Size: |
53248
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1957973778.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
AD9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000AD9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AD9000
|
Size: |
12288
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963053598.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962855774.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
A85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1790421634.0000000000A85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A85000
|
Size: |
24576
|
|
2C70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2564393125.0000000002C70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C70000
|
Size: |
12288
|
|
1720000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327597851.0000000001720000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1720000
|
Size: |
12288
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962587167.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
4171000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1329764588.0000000004171000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4171000
|
Size: |
28672
|
|
801E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2566831686.000000000801E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
801E000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960908692.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
2BA4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709420710.0000000002BA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2BA4000
|
Size: |
4096
|
|
8308BFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2080927547.0000008308BFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8308BFE000
|
Size: |
8192
|
|
5740000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331208197.0000000005740000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5740000
|
Size: |
65536
|
|
5700000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331118886.0000000005700000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5700000
|
Size: |
65536
|
|
7F6C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2568929197.0000000007F6C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7F6C000
|
Size: |
16384
|
|
171B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1327578908.000000000171B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
171B000
|
Size: |
4096
|
|
AD5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000AD5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AD5000
|
Size: |
4096
|
|
2B0C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2564250682.0000000002B0C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B0C000
|
Size: |
16384
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1957883494.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
1FAECC01000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2081358257.000001FAECC01000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1FAECC01000
|
Size: |
4096
|
|
7A99000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1975650068.0000000007A99000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A99000
|
Size: |
4096
|
|
1731000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1789941757.0000000001731000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
1731000
|
Size: |
16384
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959049169.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1964077372.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
4710000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1801339341.0000000004710000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4710000
|
Size: |
159744
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959347542.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B9AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1334578468.000000000B9AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B9AE000
|
Size: |
8192
|
|
5C95000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331626938.0000000005C95000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C95000
|
Size: |
40960
|
|
113A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709300027.000000000113A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
113A000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962059828.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
10DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709246072.00000000010DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10DE000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1964134494.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
5870000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1331341854.0000000005870000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5870000
|
Size: |
65536
|
|
A85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1790443891.0000000000A85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A85000
|
Size: |
24576
|
|
F00000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1709100203.0000000000F00000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F00000
|
Size: |
4096
|
|
7AB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1975650068.0000000007AB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AB1000
|
Size: |
8192
|
|
7A86000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2566567250.0000000007A86000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A86000
|
Size: |
12288
|
|
16E3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1327335510.00000000016E3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
16E3000
|
Size: |
4096
|
|
1FAEC850000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2030479229.000001FAEC850000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1FAEC850000
|
Size: |
4096
|
|
1FAEC9B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2081196808.000001FAEC9B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1FAEC9B0000
|
Size: |
12288
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960157473.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
1FAEAFB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2081099015.000001FAEAFB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1FAEAFB0000
|
Size: |
40960
|
|
73BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331883413.00000000073BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
73BE000
|
Size: |
8192
|
|
1FAEAFAA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2081099015.000001FAEAFAA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1FAEAFAA000
|
Size: |
20480
|
|
805F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2566853570.000000000805F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
805F000
|
Size: |
4096
|
|
7A93000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2566567250.0000000007A93000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A93000
|
Size: |
24576
|
|
16C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2564192142.00000000016C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
16C0000
|
Size: |
360448
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
15AD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1789941757.00000000015AD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
15AD000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1797463970.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
1FAECA00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2081215290.000001FAECA00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1FAECA00000
|
Size: |
4096
|
|
16E4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327351545.00000000016E4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16E4000
|
Size: |
4096
|
|
4896000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1792254365.0000000004896000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4896000
|
Size: |
458752
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1976210882.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
7AC0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1333175267.0000000007AC0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
7AC0000
|
Size: |
69632
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959090558.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
7360000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331818024.0000000007360000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7360000
|
Size: |
28672
|
|
7D6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1333850028.0000000007D6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7D6E000
|
Size: |
8192
|
|
2B8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2564314283.0000000002B8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B8E000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963928929.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
A10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1796174429.0000000000A10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
A10000
|
Size: |
159744
|
|
1010000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709167303.0000000001010000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1010000
|
Size: |
4096
|
|
7DAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1333889927.0000000007DAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7DAE000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960263116.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963516221.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963340159.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963894305.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
56F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331094442.00000000056F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
56F0000
|
Size: |
4096
|
|
7AAD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2566567250.0000000007AAD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AAD000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961950023.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
15A9000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1789941757.00000000015A9000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
15A9000
|
Size: |
4096
|
|
5C50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331536518.0000000005C50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5C50000
|
Size: |
65536
|
|
485D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2564432959.000000000485D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
485D000
|
Size: |
12288
|
|
47E9000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.2564572270.00000000047E9000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
47E9000
|
Size: |
10485760
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963804987.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
1FAEAFBD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2081099015.000001FAEAFBD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1FAEAFBD000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962817371.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959631434.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
4C62000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2565056026.0000000004C62000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4C62000
|
Size: |
4096
|
|
16E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327318366.00000000016E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
16E0000
|
Size: |
8192
|
|
77E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2566471148.00000000077E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
77E0000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
45BC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1789792221.00000000045BC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
45BC000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960784951.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
AEC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1965675532.0000000000AEC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AEC000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
1FAECCC4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2031672870.000001FAECCC4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1FAECCC4000
|
Size: |
24576
|
|
4D22000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2565056026.0000000004D22000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4D22000
|
Size: |
8192
|
|
5822000
|
system
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2567659913.0000000005822000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
5822000
|
Size: |
8192
|
|
481C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2564395847.000000000481C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
481C000
|
Size: |
16384
|
|
B81000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000000.1708997811.0000000000B81000.00000020.00000001.01000000.0000000A.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
B81000
|
Size: |
57344
|
|
5780000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331236908.0000000005780000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5780000
|
Size: |
4096
|
|
A85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1790684993.0000000000A85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A85000
|
Size: |
24576
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960474266.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1964628775.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
1FAECB21000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2081250288.000001FAECB21000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1FAECB21000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961823423.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
5E24000
|
system
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2567659913.0000000005E24000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
5E24000
|
Size: |
8192
|
|
56E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331067589.00000000056E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56E0000
|
Size: |
65536
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962673591.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961251337.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
F10000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2563378363.0000000000F10000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F10000
|
Size: |
4096
|
|
1FAEAFD3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2081176075.000001FAEAFD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1FAEAFD3000
|
Size: |
28672
|
|
770000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563202570.0000000000770000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
770000
|
Size: |
4096
|
|
B96E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1334555769.000000000B96E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B96E000
|
Size: |
8192
|
|
12FF000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.2563931581.00000000012FF000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
12FF000
|
Size: |
32768
|
|
113E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709300027.000000000113E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
113E000
|
Size: |
94208
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962751579.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1957843566.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1958961027.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B07000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000B07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B07000
|
Size: |
12288
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963459000.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
19E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327672667.00000000019E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19E0000
|
Size: |
20480
|
|
B10000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2563038764.0000000000B10000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B10000
|
Size: |
4096
|
|
3010000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1327753495.0000000003010000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
3010000
|
Size: |
4096
|
|
1FAECB0E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2081250288.000001FAECB0E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1FAECB0E000
|
Size: |
4096
|
|
A8A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000A8A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A8A000
|
Size: |
192512
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4769000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1792254365.0000000004769000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4769000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2BA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709420710.0000000002BA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2BA0000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961614316.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961685335.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
1120000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1789874726.0000000001120000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1120000
|
Size: |
4096
|
|
3DE9000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.2564572270.0000000003DE9000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3DE9000
|
Size: |
10485760
|
|
5C70000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1331596688.0000000005C70000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5C70000
|
Size: |
65536
|
|
56A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1330918657.00000000056A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56A0000
|
Size: |
12288
|
|
1100000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2563742807.0000000001100000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1100000
|
Size: |
4096
|
|
AEC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000AEC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AEC000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962168637.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
7BE0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1333632862.0000000007BE0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7BE0000
|
Size: |
40960
|
|
E40000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1303948460.0000000000E40000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E40000
|
Size: |
4096
|
|
1080000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2563630793.0000000001080000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1080000
|
Size: |
4096
|
|
48D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2564492848.00000000048D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
48D0000
|
Size: |
4096
|
|
33E9000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.2564572270.00000000033E9000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
33E9000
|
Size: |
10485760
|
|
1FAEAEF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2081063042.000001FAEAEF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1FAEAEF0000
|
Size: |
8192
|
|
3020000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327773683.0000000003020000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3020000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960710618.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960122998.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963369612.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
13DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326939138.00000000013DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13DE000
|
Size: |
155648
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
170A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1327512510.000000000170A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
170A000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962779758.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
5720000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331181560.0000000005720000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5720000
|
Size: |
65536
|
|
B60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563917813.0000000000B60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B60000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959810443.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
F58000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1789730108.0000000000F58000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F58000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961152404.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963255487.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
8F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563259270.00000000008F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F0000
|
Size: |
16384
|
|
2C70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709453501.0000000002C70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C70000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963227206.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1976268713.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B96000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2563235919.0000000000B96000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B96000
|
Size: |
8192
|
|
7379000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331838813.0000000007379000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7379000
|
Size: |
4096
|
|
5690000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1330886343.0000000005690000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5690000
|
Size: |
65536
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1806556135.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
217088
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959001700.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
105E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709180058.000000000105E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
105E000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960541784.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962094846.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
3000000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1327726576.0000000003000000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
3000000
|
Size: |
65536
|
|
B30000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2563138783.0000000000B30000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B30000
|
Size: |
4096
|
|
A7C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000A7C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A7C000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
1040000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1789854834.0000000001040000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1040000
|
Size: |
16384
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1957742898.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
58A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331398716.00000000058A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
58A0000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961650092.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
1159000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1862239491.0000000001159000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1159000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962322303.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
1710000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327531625.0000000001710000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1710000
|
Size: |
4096
|
|
806F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2568958839.000000000806F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
806F000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963572782.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
F9A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326770075.0000000000F9A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F9A000
|
Size: |
24576
|
|
78E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1332857527.00000000078E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
78E0000
|
Size: |
135168
|
|
A7C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1790593785.0000000000A7C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A7C000
|
Size: |
36864
|
|
1FAECCBE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2031672870.000001FAECCBE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1FAECCBE000
|
Size: |
8192
|
|
73C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331910191.00000000073C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
73C0000
|
Size: |
24576
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963718655.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
FE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326790707.0000000000FE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FE0000
|
Size: |
16384
|
|
5324000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2565056026.0000000005324000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5324000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963081818.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
17D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1791061682.00000000017D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
17D0000
|
Size: |
274432
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1962507862.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
4907000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1792254365.0000000004907000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4907000
|
Size: |
24576
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960575056.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961184400.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1964106650.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
1FAECB00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2081232614.000001FAECB00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1FAECB00000
|
Size: |
4096
|
|
C8B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563967183.0000000000C8B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C8B000
|
Size: |
815104
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961369394.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
1169000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1862239491.0000000001169000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1169000
|
Size: |
8192
|
|
1080000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709232357.0000000001080000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1080000
|
Size: |
4096
|
|
1FAEC850000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2029722889.000001FAEC850000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1FAEC850000
|
Size: |
4096
|
|
5715000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331146243.0000000005715000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5715000
|
Size: |
45056
|
|
1130000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2563770174.0000000001130000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1130000
|
Size: |
32768
|
|
A7A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1790684993.0000000000A7A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A7A000
|
Size: |
24576
|
|
AD9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1965675532.0000000000AD9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AD9000
|
Size: |
12288
|
|
B10000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1708884710.0000000000B10000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B10000
|
Size: |
4096
|
|
6270000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331701194.0000000006270000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6270000
|
Size: |
20480
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963198058.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
1330000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2564156818.0000000001330000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1330000
|
Size: |
36864
|
|
B03000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000B03000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B03000
|
Size: |
4096
|
|
1FAEAF20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2081080587.000001FAEAF20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1FAEAF20000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1964201933.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
8307BFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2080889667.0000008307BFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8307BFE000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1976414853.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
57A2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331276678.00000000057A2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
57A2000
|
Size: |
57344
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959593688.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
1071000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2563579849.0000000001071000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1071000
|
Size: |
12288
|
|
16FD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1327418286.00000000016FD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
16FD000
|
Size: |
4096
|
|
B96000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709032115.0000000000B96000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B96000
|
Size: |
8192
|
|
4910000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.2564592537.0000000004910000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4910000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
10B0000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2563684740.00000000010B0000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10B0000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963631601.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963989219.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961220851.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
EFB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1789679742.0000000000EFB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EFB000
|
Size: |
20480
|
|
1405000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1326939138.0000000001405000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1405000
|
Size: |
57344
|
|
51E9000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.2564572270.00000000051E9000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
51E9000
|
Size: |
5689344
|
|
5890000
|
trusted library section
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1331369748.0000000005890000.00000002.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page readonly
|
Base address: |
5890000
|
Size: |
65536
|
|
B81000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000002.2563189862.0000000000B81000.00000020.00000001.01000000.0000000A.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
B81000
|
Size: |
57344
|
|
1158000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2563770174.0000000001158000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1158000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
113A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.2563770174.000000000113A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
113A000
|
Size: |
8192
|
|
2D80000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2564445389.0000000002D80000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2D80000
|
Size: |
925696
|
|
3171000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327895831.0000000003171000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3171000
|
Size: |
303104
|
|
A8B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1790334100.0000000000A8B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A8B000
|
Size: |
20480
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1960439634.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1958670080.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
F10000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1709117873.0000000000F10000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F10000
|
Size: |
4096
|
|
B8F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1709016209.0000000000B8F000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B8F000
|
Size: |
28672
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963311941.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959517095.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1959917236.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
F00000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.2563348114.0000000000F00000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F00000
|
Size: |
4096
|
|
14B7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327207436.00000000014B7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14B7000
|
Size: |
28672
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963834285.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1961517331.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
16C1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.1709378622.00000000016C1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
16C1000
|
Size: |
356352
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
8F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1797356101.00000000008F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F4000
|
Size: |
4096
|
|
A67000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000A67000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A67000
|
Size: |
77824
|
|
4A39000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.2564592537.0000000004A39000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A39000
|
Size: |
4096
|
|
5C4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331524514.0000000005C4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5C4E000
|
Size: |
8192
|
|
2D7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.1709470399.0000000002D7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D7F000
|
Size: |
4096
|
|
4710000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1857412838.0000000004710000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4710000
|
Size: |
159744
|
|
B1C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1789607328.0000000000B1C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B1C000
|
Size: |
16384
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1958928542.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
1FAEAED0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2081042953.000001FAEAED0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1FAEAED0000
|
Size: |
4096
|
|
7A70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2566567250.0000000007A70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A70000
|
Size: |
32768
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1963660560.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
8192
|
|
4900000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2564558918.0000000004900000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4900000
|
Size: |
4096
|
|
1712000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327547540.0000000001712000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1712000
|
Size: |
4096
|
|
5790000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1331248429.0000000005790000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5790000
|
Size: |
65536
|
|
1DF9000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1791238666.0000000001DF9000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
1DF9000
|
Size: |
10485760
|
|
57A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1331276678.00000000057A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
57A0000
|
Size: |
4096
|
|
1FAEAFCC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2031873798.000001FAEAFCC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1FAEAFCC000
|
Size: |
4096
|
|
1FAEC850000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000007.00000003.2029786106.000001FAEC850000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1FAEC850000
|
Size: |
4096
|
|
14BF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1327207436.00000000014BF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14BF000
|
Size: |
65536
|
|
ADF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1965675532.0000000000ADF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ADF000
|
Size: |
8192
|
|
1FAEAE3D000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2080947822.000001FAEAE3D000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
1FAEAE3D000
|
Size: |
12288
|
|
131F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1789891261.000000000131F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
131F000
|
Size: |
4096
|
|
46DF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1789792221.00000000046DF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
46DF000
|
Size: |
512000
|
|
B61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1958767045.0000000000B61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B61000
|
Size: |
4096
|
|
B0D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2563320507.0000000000B0D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B0D000
|
Size: |
12288
|
|