402000
|
remote allocation
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.2491666628.0000000000402000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
402000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Telegram RAT |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected VIP Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
2881000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000000.00000002.1244570435.0000000002881000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2881000
|
Size: |
1372160
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
Yara detected Costura Assembly Loader |
Data Obfuscation |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
3881000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000000.00000002.1256541372.0000000003881000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3881000
|
Size: |
294912
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Telegram RAT |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected VIP Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
5B30000
|
trusted library section
|
page read and write
|
 |
|
|
Name: |
00000000.00000002.1259287660.0000000005B30000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
5B30000
|
Size: |
389120
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Costura Assembly Loader |
Data Obfuscation |
|
|
2B71000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000002.00000002.2495497502.0000000002B71000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B71000
|
Size: |
315392
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
URLs found in memory or binary data |
Networking |
|
|
38D9000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000000.00000002.1256541372.00000000038D9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
38D9000
|
Size: |
1105920
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Telegram RAT |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected VIP Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4F5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257088108.0000000004F5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F5E000
|
Size: |
8192
|
|
2BC7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BC7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BC7000
|
Size: |
4096
|
|
2DA2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DA2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DA2000
|
Size: |
12288
|
|
2E8A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E8A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E8A000
|
Size: |
57344
|
|
29D3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.00000000029D3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29D3000
|
Size: |
4096
|
|
2CCA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CCA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CCA000
|
Size: |
12288
|
|
ACE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243225199.0000000000ACE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ACE000
|
Size: |
98304
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
3CCA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003CCA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3CCA000
|
Size: |
20480
|
|
2D26000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D26000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D26000
|
Size: |
4096
|
|
2A22000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A22000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A22000
|
Size: |
4096
|
|
392000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1232124004.0000000000392000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
392000
|
Size: |
1232896
|
|
2E99000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E99000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E99000
|
Size: |
12288
|
|
CC3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1243783027.0000000000CC3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
CC3000
|
Size: |
4096
|
|
29D1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.00000000029D1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29D1000
|
Size: |
4096
|
|
2D95000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D95000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D95000
|
Size: |
4096
|
|
2D32000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002D32000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D32000
|
Size: |
172032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2B2E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B2E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B2E000
|
Size: |
4096
|
|
2EC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002EC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EC0000
|
Size: |
4096
|
|
2BD6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002BD6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BD6000
|
Size: |
12288
|
|
5960000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1258047856.0000000005960000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5960000
|
Size: |
28672
|
|
584E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1258006443.000000000584E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
584E000
|
Size: |
8192
|
|
2C23000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C23000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C23000
|
Size: |
4096
|
|
2BAE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BAE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BAE000
|
Size: |
4096
|
|
CE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243942346.0000000000CE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
CE0000
|
Size: |
4096
|
|
CE6000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1243977074.0000000000CE6000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
CE6000
|
Size: |
8192
|
|
CF7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1244023755.0000000000CF7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
CF7000
|
Size: |
4096
|
|
E22000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2493430459.0000000000E22000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E22000
|
Size: |
4096
|
|
6480000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2502136791.0000000006480000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6480000
|
Size: |
65536
|
|
DFF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2493430459.0000000000DFF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DFF000
|
Size: |
24576
|
|
65A2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2502920327.00000000065A2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
65A2000
|
Size: |
8192
|
|
2ADA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002ADA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2ADA000
|
Size: |
4096
|
|
2C1B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C1B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C1B000
|
Size: |
4096
|
|
2A28000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A28000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A28000
|
Size: |
4096
|
|
2D82000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D82000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D82000
|
Size: |
4096
|
|
2D7A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002D7A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D7A000
|
Size: |
28672
|
|
D50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2493430459.0000000000D50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D50000
|
Size: |
28672
|
|
AC8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243225199.0000000000AC8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AC8000
|
Size: |
16384
|
|
2D74000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D74000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D74000
|
Size: |
4096
|
|
2A8F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A8F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A8F000
|
Size: |
4096
|
|
685A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2503929813.000000000685A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
685A000
|
Size: |
40960
|
|
2ACA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002ACA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2ACA000
|
Size: |
45056
|
|
2D07000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D07000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D07000
|
Size: |
4096
|
|
2CF1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CF1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CF1000
|
Size: |
20480
|
|
2AD8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AD8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AD8000
|
Size: |
4096
|
|
2BE4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BE4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BE4000
|
Size: |
4096
|
|
2C87000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C87000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C87000
|
Size: |
4096
|
|
5C8D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2500706157.0000000005C8D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C8D000
|
Size: |
20480
|
|
2EED000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002EED000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EED000
|
Size: |
299008
|
|
D22000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2492850194.0000000000D22000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
D22000
|
Size: |
4096
|
|
4E10000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1257044353.0000000004E10000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
4E10000
|
Size: |
4096
|
|
FF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244228445.0000000000FF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FF0000
|
Size: |
16384
|
|
D8B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2493430459.0000000000D8B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D8B000
|
Size: |
16384
|
|
2E08000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E08000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E08000
|
Size: |
4096
|
|
2C72000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C72000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C72000
|
Size: |
4096
|
|
2E59000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002E59000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E59000
|
Size: |
94208
|
|
2D7A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D7A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D7A000
|
Size: |
4096
|
|
2A58000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A58000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A58000
|
Size: |
4096
|
|
2CA2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CA2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CA2000
|
Size: |
4096
|
|
2BCE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BCE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BCE000
|
Size: |
4096
|
|
2E06000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E06000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E06000
|
Size: |
4096
|
|
2F64000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F64000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F64000
|
Size: |
12288
|
|
CDD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1243909457.0000000000CDD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
CDD000
|
Size: |
4096
|
|
2BE6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BE6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BE6000
|
Size: |
4096
|
|
2DC7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DC7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DC7000
|
Size: |
4096
|
|
3BDA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003BDA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3BDA000
|
Size: |
4096
|
|
68DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2503993802.00000000068DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
68DE000
|
Size: |
4096
|
|
2B13000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B13000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B13000
|
Size: |
4096
|
|
2EF3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EF3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EF3000
|
Size: |
12288
|
|
2B5E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B5E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B5E000
|
Size: |
4096
|
|
2B24000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B24000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B24000
|
Size: |
4096
|
|
2DEB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002DEB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DEB000
|
Size: |
4096
|
|
2CEF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CEF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CEF000
|
Size: |
4096
|
|
6490000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2502203738.0000000006490000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6490000
|
Size: |
65536
|
|
2E9D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E9D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E9D000
|
Size: |
4096
|
|
2D1E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D1E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D1E000
|
Size: |
4096
|
|
E1E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2493430459.0000000000E1E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E1E000
|
Size: |
4096
|
|
2C1A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002C1A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C1A000
|
Size: |
4096
|
|
52EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257236089.00000000052EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52EE000
|
Size: |
8192
|
|
2D78000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D78000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D78000
|
Size: |
4096
|
|
2D84000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D84000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D84000
|
Size: |
65536
|
|
2EDC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EDC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EDC000
|
Size: |
4096
|
|
2E04000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E04000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E04000
|
Size: |
4096
|
|
2B15000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B15000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B15000
|
Size: |
24576
|
|
2D2D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002D2D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D2D000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2F62000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F62000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F62000
|
Size: |
4096
|
|
5A70000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1258814818.0000000005A70000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5A70000
|
Size: |
65536
|
|
6534000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2502660926.0000000006534000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6534000
|
Size: |
28672
|
|
CD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2492355630.0000000000CD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD0000
|
Size: |
4096
|
|
5AE0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1259040700.0000000005AE0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5AE0000
|
Size: |
65536
|
|
59A0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1258184372.00000000059A0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
59A0000
|
Size: |
397312
|
|
3DA8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003DA8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3DA8000
|
Size: |
12288
|
|
5B10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1259176534.0000000005B10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5B10000
|
Size: |
36864
|
|
5BD0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1259457551.0000000005BD0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5BD0000
|
Size: |
49152
|
|
5A2F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1258317910.0000000005A2F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5A2F000
|
Size: |
4096
|
|
2B64000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B64000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B64000
|
Size: |
4096
|
|
29AE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495108836.00000000029AE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29AE000
|
Size: |
45056
|
|
2EEA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EEA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EEA000
|
Size: |
16384
|
|
2D54000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D54000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D54000
|
Size: |
4096
|
|
2F27000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F27000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F27000
|
Size: |
118784
|
|
29E8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.00000000029E8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29E8000
|
Size: |
98304
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
CCD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1243831392.0000000000CCD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
CCD000
|
Size: |
4096
|
|
6848000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2503700565.0000000006848000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6848000
|
Size: |
12288
|
|
2A56000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A56000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A56000
|
Size: |
4096
|
|
3E97000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003E97000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E97000
|
Size: |
8192
|
|
3E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E40000
|
Size: |
8192
|
|
2D99000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D99000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D99000
|
Size: |
4096
|
|
2F4B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F4B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F4B000
|
Size: |
4096
|
|
2E7E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E7E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E7E000
|
Size: |
4096
|
|
2D5C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D5C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D5C000
|
Size: |
4096
|
|
2F01000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F01000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F01000
|
Size: |
4096
|
|
3DD9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003DD9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3DD9000
|
Size: |
16384
|
|
D32000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2493091612.0000000000D32000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
D32000
|
Size: |
4096
|
|
2B09000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B09000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B09000
|
Size: |
4096
|
|
2AA4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AA4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AA4000
|
Size: |
4096
|
|
3E3B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003E3B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E3B000
|
Size: |
8192
|
|
3F4E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003F4E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3F4E000
|
Size: |
4096
|
|
2D3F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D3F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D3F000
|
Size: |
12288
|
|
2D4E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D4E000
|
Size: |
12288
|
|
2EE2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EE2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EE2000
|
Size: |
4096
|
|
2C98000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C98000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C98000
|
Size: |
4096
|
|
2BBF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002BBF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BBF000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
D98000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2493430459.0000000000D98000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D98000
|
Size: |
417792
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
5B00000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1259130597.0000000005B00000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5B00000
|
Size: |
65536
|
|
2B3F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B3F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B3F000
|
Size: |
4096
|
|
2E8E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002E8E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E8E000
|
Size: |
12288
|
|
2B49000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B49000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B49000
|
Size: |
4096
|
|
2EA7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EA7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EA7000
|
Size: |
49152
|
|
65A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2502920327.00000000065A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
65A0000
|
Size: |
4096
|
|
2E22000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002E22000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E22000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
512D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257150900.000000000512D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
512D000
|
Size: |
12288
|
|
2C64000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C64000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C64000
|
Size: |
4096
|
|
B55000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243225199.0000000000B55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B55000
|
Size: |
20480
|
|
2DA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DA0000
|
Size: |
4096
|
|
594E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1258028949.000000000594E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
594E000
|
Size: |
8192
|
|
E42000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2493430459.0000000000E42000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E42000
|
Size: |
53248
|
|
2B31000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B31000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B31000
|
Size: |
45056
|
|
29E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.00000000029E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29E0000
|
Size: |
28672
|
|
64A0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2502280355.00000000064A0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
64A0000
|
Size: |
65536
|
|
2E28000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002E28000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E28000
|
Size: |
188416
|
|
2B60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B60000
|
Size: |
4096
|
|
2F18000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F18000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F18000
|
Size: |
4096
|
|
1010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2494869493.0000000001010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1010000
|
Size: |
65536
|
|
2C85000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C85000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C85000
|
Size: |
4096
|
|
2D7E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D7E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D7E000
|
Size: |
4096
|
|
2B8F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B8F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B8F000
|
Size: |
4096
|
|
2D76000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D76000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D76000
|
Size: |
4096
|
|
2700000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244319036.0000000002700000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2700000
|
Size: |
65536
|
|
65E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2503341743.00000000065E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
65E0000
|
Size: |
40960
|
|
4F9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257107151.0000000004F9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F9E000
|
Size: |
8192
|
|
2CF6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002CF6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CF6000
|
Size: |
4096
|
|
2F6B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F6B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F6B000
|
Size: |
36864
|
|
2AC3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AC3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AC3000
|
Size: |
4096
|
|
2B9E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B9E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B9E000
|
Size: |
4096
|
|
2CB5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CB5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CB5000
|
Size: |
4096
|
|
2EBC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002EBC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EBC000
|
Size: |
4096
|
|
2BAC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BAC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BAC000
|
Size: |
4096
|
|
2D3B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D3B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D3B000
|
Size: |
4096
|
|
2BDA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BDA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BDA000
|
Size: |
4096
|
|
3C82000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003C82000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C82000
|
Size: |
12288
|
|
2B0B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B0B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B0B000
|
Size: |
4096
|
|
50ED000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2499821083.00000000050ED000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
50ED000
|
Size: |
12288
|
|
5306000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2500043485.0000000005306000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5306000
|
Size: |
8192
|
|
446000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2491666628.0000000000446000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
446000
|
Size: |
4096
|
|
2E82000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E82000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E82000
|
Size: |
4096
|
|
2D72000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D72000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D72000
|
Size: |
4096
|
|
52AF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257215235.00000000052AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52AF000
|
Size: |
4096
|
|
2BE9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BE9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BE9000
|
Size: |
53248
|
|
2BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BD0000
|
Size: |
4096
|
|
6594000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2502876429.0000000006594000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6594000
|
Size: |
36864
|
|
2D39000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D39000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D39000
|
Size: |
4096
|
|
2EFD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EFD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EFD000
|
Size: |
4096
|
|
2DD2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002DD2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DD2000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
2C9A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C9A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C9A000
|
Size: |
4096
|
|
3F64000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003F64000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3F64000
|
Size: |
12288
|
|
5304000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2500043485.0000000005304000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5304000
|
Size: |
4096
|
|
2E55000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E55000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E55000
|
Size: |
4096
|
|
3E52000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003E52000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E52000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5C99000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2500706157.0000000005C99000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C99000
|
Size: |
102400
|
|
2F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F50000
|
Size: |
61440
|
|
2A3F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A3F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A3F000
|
Size: |
4096
|
|
2D4C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D4C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D4C000
|
Size: |
4096
|
|
3EA4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003EA4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3EA4000
|
Size: |
4096
|
|
2C0E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002C0E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C0E000
|
Size: |
4096
|
|
5B1A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1259176534.0000000005B1A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5B1A000
|
Size: |
24576
|
|
2A03000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A03000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A03000
|
Size: |
4096
|
|
F9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2494617455.0000000000F9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F9E000
|
Size: |
8192
|
|
2DCB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DCB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DCB000
|
Size: |
4096
|
|
FD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244160318.0000000000FD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
FD0000
|
Size: |
65536
|
|
2A14000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A14000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A14000
|
Size: |
28672
|
|
CFB000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1244045306.0000000000CFB000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
CFB000
|
Size: |
4096
|
|
D26000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2492910374.0000000000D26000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
D26000
|
Size: |
8192
|
|
2DE2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002DE2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DE2000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
2D28000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D28000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D28000
|
Size: |
4096
|
|
D3B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2493355261.0000000000D3B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
D3B000
|
Size: |
4096
|
|
2D0D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D0D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D0D000
|
Size: |
4096
|
|
2CD8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CD8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CD8000
|
Size: |
4096
|
|
5A60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1258646373.0000000005A60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5A60000
|
Size: |
53248
|
|
2C9C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C9C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C9C000
|
Size: |
4096
|
|
2D27000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002D27000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D27000
|
Size: |
4096
|
|
5A20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1258317910.0000000005A20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5A20000
|
Size: |
49152
|
|
2C16000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002C16000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C16000
|
Size: |
4096
|
|
2B67000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B67000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B67000
|
Size: |
53248
|
|
3B71000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003B71000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B71000
|
Size: |
36864
|
|
29D9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.00000000029D9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29D9000
|
Size: |
4096
|
|
56C0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257606169.00000000056C0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
56C0000
|
Size: |
1081344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
CD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243851668.0000000000CD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
CD0000
|
Size: |
53248
|
|
2F04000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F04000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F04000
|
Size: |
53248
|
|
2A0F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A0F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A0F000
|
Size: |
16384
|
|
2EA3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EA3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EA3000
|
Size: |
4096
|
|
2A87000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A87000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A87000
|
Size: |
4096
|
|
CF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2492406749.0000000000CF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
CF0000
|
Size: |
8192
|
|
3E68000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003E68000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E68000
|
Size: |
12288
|
|
2B8D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B8D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B8D000
|
Size: |
4096
|
|
AF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243225199.0000000000AF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AF4000
|
Size: |
53248
|
|
2C11000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C11000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C11000
|
Size: |
28672
|
|
2EE8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EE8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EE8000
|
Size: |
4096
|
|
2ABF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002ABF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2ABF000
|
Size: |
4096
|
|
53EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257257062.00000000053EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
53EE000
|
Size: |
8192
|
|
2DF8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DF8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DF8000
|
Size: |
36864
|
|
D30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244102534.0000000000D30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D30000
|
Size: |
16384
|
|
2E02000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E02000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E02000
|
Size: |
4096
|
|
559F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257297887.000000000559F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
559F000
|
Size: |
4096
|
|
2D05000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D05000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D05000
|
Size: |
4096
|
|
2F47000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F47000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F47000
|
Size: |
4096
|
|
3E46000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003E46000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E46000
|
Size: |
4096
|
|
2B0D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B0D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B0D000
|
Size: |
4096
|
|
2A26000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A26000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A26000
|
Size: |
4096
|
|
5BF0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1259488841.0000000005BF0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
5BF0000
|
Size: |
323584
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3BD7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003BD7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3BD7000
|
Size: |
8192
|
|
D03000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2492498945.0000000000D03000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
D03000
|
Size: |
4096
|
|
2DC9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DC9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DC9000
|
Size: |
4096
|
|
3C08000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003C08000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C08000
|
Size: |
12288
|
|
2C21000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C21000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C21000
|
Size: |
4096
|
|
2A6D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A6D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A6D000
|
Size: |
94208
|
|
2BC9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BC9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BC9000
|
Size: |
4096
|
|
7370000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2504161044.0000000007370000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7370000
|
Size: |
8192
|
|
2C43000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C43000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C43000
|
Size: |
45056
|
|
29DB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.00000000029DB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29DB000
|
Size: |
16384
|
|
3D12000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003D12000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3D12000
|
Size: |
12288
|
|
3FA1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003FA1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3FA1000
|
Size: |
8192
|
|
5C70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1259707977.0000000005C70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C70000
|
Size: |
233472
|
|
2CD2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CD2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CD2000
|
Size: |
4096
|
|
2D43000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D43000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D43000
|
Size: |
4096
|
|
2DB6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DB6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DB6000
|
Size: |
4096
|
|
645D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2501793890.000000000645D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
645D000
|
Size: |
12288
|
|
2DB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DB0000
|
Size: |
4096
|
|
5E50000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1259819610.0000000005E50000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5E50000
|
Size: |
131072
|
|
2E3C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E3C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E3C000
|
Size: |
4096
|
|
2EB6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002EB6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EB6000
|
Size: |
12288
|
|
2D25000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002D25000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D25000
|
Size: |
4096
|
|
2CBB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CBB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CBB000
|
Size: |
12288
|
|
2AE2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AE2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AE2000
|
Size: |
4096
|
|
2D3D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D3D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D3D000
|
Size: |
4096
|
|
2AD6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AD6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AD6000
|
Size: |
4096
|
|
56B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257588492.00000000056B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
56B0000
|
Size: |
4096
|
|
2A09000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A09000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A09000
|
Size: |
4096
|
|
2CF9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CF9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CF9000
|
Size: |
36864
|
|
2C53000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C53000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C53000
|
Size: |
4096
|
|
2870000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1244503801.0000000002870000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2870000
|
Size: |
4096
|
|
2AC7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AC7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AC7000
|
Size: |
4096
|
|
2EFF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EFF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EFF000
|
Size: |
4096
|
|
2B28000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B28000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B28000
|
Size: |
4096
|
|
2BF9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BF9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BF9000
|
Size: |
86016
|
|
3BEF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003BEF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3BEF000
|
Size: |
16384
|
|
5990000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1258149184.0000000005990000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5990000
|
Size: |
65536
|
|
3F76000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003F76000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3F76000
|
Size: |
4096
|
|
2A52000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A52000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A52000
|
Size: |
4096
|
|
2CF4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002CF4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CF4000
|
Size: |
4096
|
|
2EA5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EA5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EA5000
|
Size: |
4096
|
|
5CC1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2500973210.0000000005CC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5CC1000
|
Size: |
20480
|
|
2E10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E10000
|
Size: |
49152
|
|
2EBA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EBA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EBA000
|
Size: |
4096
|
|
644E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2501745170.000000000644E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
644E000
|
Size: |
8192
|
|
2E81000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002E81000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E81000
|
Size: |
16384
|
|
2DCF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DCF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DCF000
|
Size: |
4096
|
|
29BA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495108836.00000000029BA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29BA000
|
Size: |
4096
|
|
2A24000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A24000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A24000
|
Size: |
4096
|
|
2BC1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BC1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BC1000
|
Size: |
4096
|
|
2DB8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DB8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DB8000
|
Size: |
4096
|
|
B40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2492180046.0000000000B40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B40000
|
Size: |
8192
|
|
2BA6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BA6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BA6000
|
Size: |
4096
|
|
5A30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1258389211.0000000005A30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5A30000
|
Size: |
65536
|
|
2DCD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002DCD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DCD000
|
Size: |
4096
|
|
2EF7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EF7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EF7000
|
Size: |
4096
|
|
2EC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EC0000
|
Size: |
49152
|
|
2E25000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E25000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E25000
|
Size: |
4096
|
|
2720000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244345853.0000000002720000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2720000
|
Size: |
24576
|
|
E3A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2493430459.0000000000E3A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E3A000
|
Size: |
20480
|
|
5C10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2500320922.0000000005C10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C10000
|
Size: |
20480
|
|
FE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244191426.0000000000FE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
FE0000
|
Size: |
65536
|
|
2E80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E80000
|
Size: |
4096
|
|
2CEB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CEB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CEB000
|
Size: |
4096
|
|
1138000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2494954491.0000000001138000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1138000
|
Size: |
4096
|
|
2B45000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B45000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B45000
|
Size: |
4096
|
|
CC4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243805580.0000000000CC4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
CC4000
|
Size: |
4096
|
|
2A05000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A05000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A05000
|
Size: |
4096
|
|
2E0E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E0E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E0E000
|
Size: |
4096
|
|
3B99000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003B99000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B99000
|
Size: |
180224
|
|
2EB8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EB8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EB8000
|
Size: |
4096
|
|
62CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2501622527.00000000062CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
62CE000
|
Size: |
8192
|
|
2A91000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A91000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A91000
|
Size: |
4096
|
|
2C55000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C55000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C55000
|
Size: |
4096
|
|
2CA4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CA4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CA4000
|
Size: |
4096
|
|
57E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257969490.00000000057E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
57E0000
|
Size: |
65536
|
|
2E59000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E59000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E59000
|
Size: |
12288
|
|
5F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243052079.00000000005F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F0000
|
Size: |
8192
|
|
5970000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1258070721.0000000005970000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5970000
|
Size: |
65536
|
|
2EB6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EB6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EB6000
|
Size: |
4096
|
|
29C1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495108836.00000000029C1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29C1000
|
Size: |
16384
|
|
264E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244259599.000000000264E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
264E000
|
Size: |
8192
|
|
2A60000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2495453861.0000000002A60000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2A60000
|
Size: |
4096
|
|
2E44000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E44000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E44000
|
Size: |
57344
|
|
526E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257195573.000000000526E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
526E000
|
Size: |
8192
|
|
2CDB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CDB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CDB000
|
Size: |
4096
|
|
65F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2503451244.00000000065F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
65F0000
|
Size: |
32768
|
|
3FA4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003FA4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3FA4000
|
Size: |
12288
|
|
5FCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2501282644.0000000005FCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5FCE000
|
Size: |
8192
|
|
2AC1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AC1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AC1000
|
Size: |
4096
|
|
65D7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2503252422.00000000065D7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
65D7000
|
Size: |
36864
|
|
2B62000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B62000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B62000
|
Size: |
4096
|
|
2BA4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BA4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BA4000
|
Size: |
4096
|
|
2D7C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D7C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D7C000
|
Size: |
4096
|
|
2E7C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002E7C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E7C000
|
Size: |
12288
|
|
2EC5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002EC5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EC5000
|
Size: |
12288
|
|
2E27000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E27000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E27000
|
Size: |
4096
|
|
64C0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2502404262.00000000064C0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
64C0000
|
Size: |
65536
|
|
2A5C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A5C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A5C000
|
Size: |
4096
|
|
2BE5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002BE5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BE5000
|
Size: |
4096
|
|
5AD0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1258990808.0000000005AD0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5AD0000
|
Size: |
65536
|
|
2B95000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B95000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B95000
|
Size: |
4096
|
|
57C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1242967785.000000000057C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
57C000
|
Size: |
16384
|
|
2A54000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A54000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A54000
|
Size: |
4096
|
|
2CE9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CE9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CE9000
|
Size: |
4096
|
|
2C1F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C1F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C1F000
|
Size: |
4096
|
|
3CFC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003CFC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3CFC000
|
Size: |
4096
|
|
5AF0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1259088299.0000000005AF0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5AF0000
|
Size: |
65536
|
|
2E1D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E1D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E1D000
|
Size: |
4096
|
|
FDC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2494650525.0000000000FDC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FDC000
|
Size: |
16384
|
|
6858000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2503700565.0000000006858000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6858000
|
Size: |
4096
|
|
5E8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2501168134.0000000005E8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5E8E000
|
Size: |
8192
|
|
2BE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BE0000
|
Size: |
4096
|
|
D20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2492796863.0000000000D20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
D20000
|
Size: |
4096
|
|
2ECD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002ECD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2ECD000
|
Size: |
4096
|
|
2D6D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002D6D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D6D000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2BCB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BCB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BCB000
|
Size: |
4096
|
|
65B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2503071142.00000000065B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
65B0000
|
Size: |
40960
|
|
11E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495037379.00000000011E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
11E0000
|
Size: |
49152
|
|
64B0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2502368438.00000000064B0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
64B0000
|
Size: |
8192
|
|
FF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2494760655.0000000000FF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FF0000
|
Size: |
4096
|
|
2A89000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A89000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A89000
|
Size: |
4096
|
|
282F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244451858.000000000282F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
282F000
|
Size: |
4096
|
|
3C9E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003C9E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C9E000
|
Size: |
4096
|
|
D2A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2493031392.0000000000D2A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
D2A000
|
Size: |
8192
|
|
2EBE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EBE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EBE000
|
Size: |
4096
|
|
2CEE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002CEE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CEE000
|
Size: |
8192
|
|
2B26000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B26000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B26000
|
Size: |
4096
|
|
2EBE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002EBE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EBE000
|
Size: |
4096
|
|
AB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243205645.0000000000AB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
AB0000
|
Size: |
8192
|
|
2A3D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A3D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A3D000
|
Size: |
4096
|
|
E40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2493430459.0000000000E40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E40000
|
Size: |
4096
|
|
CE2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243960564.0000000000CE2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
CE2000
|
Size: |
4096
|
|
2E3A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E3A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E3A000
|
Size: |
4096
|
|
2D2A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D2A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D2A000
|
Size: |
4096
|
|
2DD3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DD3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DD3000
|
Size: |
4096
|
|
4FB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2499778514.0000000004FB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4FB0000
|
Size: |
4096
|
|
2C40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C40000
|
Size: |
8192
|
|
2BDC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BDC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BDC000
|
Size: |
4096
|
|
2BAA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BAA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BAA000
|
Size: |
4096
|
|
A70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243185137.0000000000A70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A70000
|
Size: |
4096
|
|
2CD6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CD6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CD6000
|
Size: |
4096
|
|
3DA5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003DA5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3DA5000
|
Size: |
8192
|
|
2E84000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E84000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E84000
|
Size: |
4096
|
|
2B3D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B3D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B3D000
|
Size: |
4096
|
|
97D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243120709.000000000097D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
97D000
|
Size: |
12288
|
|
2BB3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BB3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BB3000
|
Size: |
53248
|
|
2C66000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C66000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C66000
|
Size: |
12288
|
|
2A37000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A37000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A37000
|
Size: |
4096
|
|
2B93000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B93000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B93000
|
Size: |
4096
|
|
2E86000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E86000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E86000
|
Size: |
4096
|
|
2DB2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DB2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DB2000
|
Size: |
4096
|
|
D37000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2493279908.0000000000D37000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
D37000
|
Size: |
4096
|
|
2AE7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AE7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AE7000
|
Size: |
36864
|
|
2CF2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002CF2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CF2000
|
Size: |
4096
|
|
2CFC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002CFC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CFC000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2CB3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CB3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CB3000
|
Size: |
4096
|
|
2D1F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002D1F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D1F000
|
Size: |
8192
|
|
2A39000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A39000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A39000
|
Size: |
4096
|
|
6B4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2504022893.0000000006B4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6B4E000
|
Size: |
8192
|
|
6D00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2504105041.0000000006D00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6D00000
|
Size: |
4096
|
|
2EE6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EE6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EE6000
|
Size: |
4096
|
|
2D2C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D2C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D2C000
|
Size: |
49152
|
|
2F4D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F4D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F4D000
|
Size: |
4096
|
|
2DCD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DCD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DCD000
|
Size: |
4096
|
|
2E42000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E42000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E42000
|
Size: |
4096
|
|
2CDD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CDD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CDD000
|
Size: |
45056
|
|
2CA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CA0000
|
Size: |
4096
|
|
29AB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495108836.00000000029AB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29AB000
|
Size: |
8192
|
|
3E58000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003E58000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E58000
|
Size: |
4096
|
|
5226000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257171260.0000000005226000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5226000
|
Size: |
40960
|
|
2D1C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D1C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D1C000
|
Size: |
4096
|
|
2A43000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A43000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A43000
|
Size: |
8192
|
|
2E8B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002E8B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E8B000
|
Size: |
8192
|
|
2B2A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B2A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B2A000
|
Size: |
4096
|
|
CC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243758475.0000000000CC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
CC0000
|
Size: |
12288
|
|
2B58000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B58000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B58000
|
Size: |
4096
|
|
CBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243716297.0000000000CBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CBE000
|
Size: |
8192
|
|
2A0D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A0D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A0D000
|
Size: |
4096
|
|
2EB4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EB4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EB4000
|
Size: |
4096
|
|
E3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244126956.0000000000E3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E3E000
|
Size: |
8192
|
|
2EDE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EDE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EDE000
|
Size: |
12288
|
|
2D0F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D0F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D0F000
|
Size: |
4096
|
|
2C19000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C19000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C19000
|
Size: |
4096
|
|
2BF7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BF7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BF7000
|
Size: |
4096
|
|
6530000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2502660926.0000000006530000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6530000
|
Size: |
12288
|
|
AC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243225199.0000000000AC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AC0000
|
Size: |
24576
|
|
2DBA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DBA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DBA000
|
Size: |
49152
|
|
2A8B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A8B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A8B000
|
Size: |
4096
|
|
57D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257930201.00000000057D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
57D0000
|
Size: |
65536
|
|
29A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495108836.00000000029A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29A0000
|
Size: |
20480
|
|
555E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2500220355.000000000555E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
555E000
|
Size: |
8192
|
|
6550000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2502764036.0000000006550000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6550000
|
Size: |
65536
|
|
2D03000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D03000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D03000
|
Size: |
4096
|
|
CEA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1243992480.0000000000CEA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
CEA000
|
Size: |
4096
|
|
2C5B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C5B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C5B000
|
Size: |
32768
|
|
2CED000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CED000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CED000
|
Size: |
4096
|
|
3C6C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003C6C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C6C000
|
Size: |
4096
|
|
2AB9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AB9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AB9000
|
Size: |
12288
|
|
2F21000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F21000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F21000
|
Size: |
4096
|
|
2A98000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A98000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A98000
|
Size: |
36864
|
|
2C34000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C34000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C34000
|
Size: |
4096
|
|
2729000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244345853.0000000002729000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2729000
|
Size: |
12288
|
|
B3F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243225199.0000000000B3F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B3F000
|
Size: |
77824
|
|
2B47000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B47000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B47000
|
Size: |
4096
|
|
2C38000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C38000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C38000
|
Size: |
4096
|
|
2E5D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E5D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E5D000
|
Size: |
4096
|
|
610E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2501424219.000000000610E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
610E000
|
Size: |
8192
|
|
2E1F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E1F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E1F000
|
Size: |
4096
|
|
2A5A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A5A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A5A000
|
Size: |
4096
|
|
2F23000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F23000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F23000
|
Size: |
12288
|
|
2BB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BB0000
|
Size: |
4096
|
|
3E8D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003E8D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E8D000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2B97000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B97000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B97000
|
Size: |
24576
|
|
2C77000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C77000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C77000
|
Size: |
53248
|
|
4C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1232252280.00000000004C0000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
4C0000
|
Size: |
184320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
2E15000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002E15000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E15000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
2F45000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F45000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F45000
|
Size: |
4096
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2499951130.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
53248
|
|
2DD8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002DD8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DD8000
|
Size: |
4096
|
|
11F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495079053.00000000011F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11F0000
|
Size: |
20480
|
|
D20000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1244067319.0000000000D20000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
D20000
|
Size: |
65536
|
|
3E74000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003E74000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E74000
|
Size: |
4096
|
|
2BD2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BD2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BD2000
|
Size: |
28672
|
|
2A8D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A8D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A8D000
|
Size: |
4096
|
|
2B1C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B1C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B1C000
|
Size: |
28672
|
|
4C6D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2499740780.0000000004C6D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C6D000
|
Size: |
12288
|
|
2BA8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BA8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BA8000
|
Size: |
4096
|
|
2E9F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E9F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E9F000
|
Size: |
4096
|
|
2DF6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DF6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DF6000
|
Size: |
4096
|
|
5C60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1259663354.0000000005C60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5C60000
|
Size: |
65536
|
|
565D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2500263886.000000000565D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
565D000
|
Size: |
12288
|
|
F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2494570554.0000000000F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F50000
|
Size: |
4096
|
|
2A01000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A01000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A01000
|
Size: |
4096
|
|
5980000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1258108098.0000000005980000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5980000
|
Size: |
65536
|
|
B32000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243225199.0000000000B32000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B32000
|
Size: |
49152
|
|
2E86000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002E86000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E86000
|
Size: |
4096
|
|
2C6C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C6C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C6C000
|
Size: |
4096
|
|
7C9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2492004946.00000000007C9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7C9000
|
Size: |
28672
|
|
2A4D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495385843.0000000002A4D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A4D000
|
Size: |
12288
|
|
5CEF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2501009313.0000000005CEF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5CEF000
|
Size: |
20480
|
|
2A1C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A1C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A1C000
|
Size: |
4096
|
|
2DF4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002DF4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DF4000
|
Size: |
122880
|
|
2D58000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D58000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D58000
|
Size: |
4096
|
|
3D7A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003D7A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3D7A000
|
Size: |
4096
|
|
5A2D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1258317910.0000000005A2D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5A2D000
|
Size: |
4096
|
|
2A2A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A2A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A2A000
|
Size: |
40960
|
|
D10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2492689774.0000000000D10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
D10000
|
Size: |
45056
|
|
2D60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D60000
|
Size: |
69632
|
|
2C26000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C26000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C26000
|
Size: |
53248
|
|
2A85000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A85000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A85000
|
Size: |
4096
|
|
D0D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2492648757.0000000000D0D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
D0D000
|
Size: |
4096
|
|
2BCC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002BCC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BCC000
|
Size: |
32768
|
|
B30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2492111049.0000000000B30000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B30000
|
Size: |
4096
|
|
D35000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2493171919.0000000000D35000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
D35000
|
Size: |
4096
|
|
5A40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1258432996.0000000005A40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5A40000
|
Size: |
65536
|
|
2C3A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C3A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C3A000
|
Size: |
12288
|
|
2A53000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495405844.0000000002A53000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A53000
|
Size: |
8192
|
|
5C56000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2500427236.0000000005C56000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C56000
|
Size: |
49152
|
|
2C2A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002C2A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C2A000
|
Size: |
4096
|
|
AE7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243225199.0000000000AE7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AE7000
|
Size: |
49152
|
|
2C1E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002C1E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C1E000
|
Size: |
4096
|
|
2E38000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E38000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E38000
|
Size: |
4096
|
|
D1D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2492746194.0000000000D1D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
D1D000
|
Size: |
4096
|
|
2A50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495405844.0000000002A50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A50000
|
Size: |
4096
|
|
2B5C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B5C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B5C000
|
Size: |
4096
|
|
2E93000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002E93000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E93000
|
Size: |
102400
|
|
2A41000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A41000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A41000
|
Size: |
4096
|
|
29D5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.00000000029D5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29D5000
|
Size: |
4096
|
|
3DF1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003DF1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3DF1000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2CB7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CB7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CB7000
|
Size: |
4096
|
|
3DC4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003DC4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3DC4000
|
Size: |
4096
|
|
8FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243080197.00000000008FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8FB000
|
Size: |
20480
|
|
2BE1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002BE1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BE1000
|
Size: |
4096
|
|
2C1D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C1D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C1D000
|
Size: |
4096
|
|
29CD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495108836.00000000029CD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29CD000
|
Size: |
16384
|
|
497E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1256960281.000000000497E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
497E000
|
Size: |
8192
|
|
2AA2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AA2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AA2000
|
Size: |
4096
|
|
2C55000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002C55000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C55000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2C70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C70000
|
Size: |
4096
|
|
B70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2492241254.0000000000B70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B70000
|
Size: |
16384
|
|
2AA8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AA8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AA8000
|
Size: |
4096
|
|
2A3B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A3B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A3B000
|
Size: |
4096
|
|
2F49000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F49000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F49000
|
Size: |
4096
|
|
B02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243225199.0000000000B02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B02000
|
Size: |
192512
|
|
549E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257276844.000000000549E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
549E000
|
Size: |
8192
|
|
2B5A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B5A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B5A000
|
Size: |
4096
|
|
2A35000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A35000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A35000
|
Size: |
4096
|
|
2C78000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002C78000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C78000
|
Size: |
442368
|
|
2C8A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C8A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C8A000
|
Size: |
36864
|
|
1000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2494792130.0000000001000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1000000
|
Size: |
65536
|
|
D58000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2493430459.0000000000D58000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D58000
|
Size: |
90112
|
|
2A1E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A1E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A1E000
|
Size: |
4096
|
|
2EFB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EFB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EFB000
|
Size: |
4096
|
|
2D9D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D9D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D9D000
|
Size: |
8192
|
|
2EBC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EBC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EBC000
|
Size: |
4096
|
|
2DD1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DD1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DD1000
|
Size: |
4096
|
|
2DF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002DF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DF0000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
2E88000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E88000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E88000
|
Size: |
4096
|
|
52EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2499911636.00000000052EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52EE000
|
Size: |
8192
|
|
5A80000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1258866394.0000000005A80000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
5A80000
|
Size: |
286720
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
E0C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2493430459.0000000000E0C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E0C000
|
Size: |
57344
|
|
2AC5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AC5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AC5000
|
Size: |
4096
|
|
60CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2501331992.00000000060CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60CF000
|
Size: |
4096
|
|
2DB4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DB4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DB4000
|
Size: |
4096
|
|
6460000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2501985838.0000000006460000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6460000
|
Size: |
65536
|
|
614E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2501469594.000000000614E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
614E000
|
Size: |
8192
|
|
D96000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2493430459.0000000000D96000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D96000
|
Size: |
4096
|
|
2E0A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E0A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E0A000
|
Size: |
4096
|
|
5C63000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2500427236.0000000005C63000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C63000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2BE9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002BE9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BE9000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2AE4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AE4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AE4000
|
Size: |
8192
|
|
2ECF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002ECF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2ECF000
|
Size: |
49152
|
|
2AF1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AF1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AF1000
|
Size: |
94208
|
|
2E53000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E53000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E53000
|
Size: |
4096
|
|
985000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243143448.0000000000985000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
985000
|
Size: |
12288
|
|
2C57000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C57000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C57000
|
Size: |
12288
|
|
2AAC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AAC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AAC000
|
Size: |
4096
|
|
509E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257127312.000000000509E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
509E000
|
Size: |
8192
|
|
64D0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2502550561.00000000064D0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
64D0000
|
Size: |
65536
|
|
FE0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2494706632.0000000000FE0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
FE0000
|
Size: |
65536
|
|
65D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2503252422.00000000065D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
65D0000
|
Size: |
8192
|
|
2AA6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AA6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AA6000
|
Size: |
4096
|
|
2BC3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BC3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BC3000
|
Size: |
12288
|
|
6C4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2504055887.0000000006C4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6C4E000
|
Size: |
8192
|
|
2DD6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DD6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DD6000
|
Size: |
126976
|
|
2ABD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002ABD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2ABD000
|
Size: |
4096
|
|
2A07000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A07000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A07000
|
Size: |
4096
|
|
AF7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2492051101.0000000000AF7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AF7000
|
Size: |
36864
|
|
2C2E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002C2E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C2E000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2A93000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A93000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A93000
|
Size: |
16384
|
|
4E5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257066183.0000000004E5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E5E000
|
Size: |
8192
|
|
2E2B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E2B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E2B000
|
Size: |
49152
|
|
2D45000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D45000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D45000
|
Size: |
24576
|
|
980000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243143448.0000000000980000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
980000
|
Size: |
16384
|
|
530A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2500043485.000000000530A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
530A000
|
Size: |
24576
|
|
3E81000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003E81000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E81000
|
Size: |
8192
|
|
2CA6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CA6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CA6000
|
Size: |
49152
|
|
2EF9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EF9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EF9000
|
Size: |
4096
|
|
38CD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1256541372.00000000038CD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
38CD000
|
Size: |
45056
|
|
512D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2499856830.000000000512D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
512D000
|
Size: |
12288
|
|
2E1C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002E1C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E1C000
|
Size: |
12288
|
|
D04000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2492591957.0000000000D04000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
D04000
|
Size: |
8192
|
|
2EEF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EEF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EEF000
|
Size: |
12288
|
|
2658000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244283103.0000000002658000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2658000
|
Size: |
8192
|
|
2C12000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002C12000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C12000
|
Size: |
4096
|
|
11D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2494984019.00000000011D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
11D0000
|
Size: |
65536
|
|
5D05000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2501090535.0000000005D05000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D05000
|
Size: |
4096
|
|
684F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2503700565.000000000684F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
684F000
|
Size: |
8192
|
|
2A20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A20000
|
Size: |
4096
|
|
2B4C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B4C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B4C000
|
Size: |
4096
|
|
630E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2501653257.000000000630E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
630E000
|
Size: |
8192
|
|
2C0F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C0F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C0F000
|
Size: |
4096
|
|
2EA1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EA1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EA1000
|
Size: |
4096
|
|
2BA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BA0000
|
Size: |
12288
|
|
2D20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D20000
|
Size: |
4096
|
|
2B41000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B41000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B41000
|
Size: |
4096
|
|
5CB3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2500706157.0000000005CB3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5CB3000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2C26000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002C26000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C26000
|
Size: |
4096
|
|
2A5E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A5E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A5E000
|
Size: |
4096
|
|
5EA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1259888588.0000000005EA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5EA0000
|
Size: |
303104
|
|
618E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2501538035.000000000618E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
618E000
|
Size: |
8192
|
|
2DA6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DA6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DA6000
|
Size: |
28672
|
|
4CFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1256984587.0000000004CFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4CFE000
|
Size: |
8192
|
|
2D5D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002D5D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D5D000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2D80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D80000
|
Size: |
4096
|
|
5F8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2501203719.0000000005F8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5F8E000
|
Size: |
8192
|
|
2F68000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F68000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F68000
|
Size: |
4096
|
|
93E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243100180.000000000093E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
93E000
|
Size: |
8192
|
|
29A6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495108836.00000000029A6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29A6000
|
Size: |
8192
|
|
D7F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2493430459.0000000000D7F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D7F000
|
Size: |
45056
|
|
634E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2501691600.000000000634E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
634E000
|
Size: |
8192
|
|
5E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243010456.00000000005E0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5E0000
|
Size: |
4096
|
|
2B11000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B11000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B11000
|
Size: |
4096
|
|
D6F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2493430459.0000000000D6F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D6F000
|
Size: |
4096
|
|
2C3E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C3E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C3E000
|
Size: |
4096
|
|
2B91000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B91000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B91000
|
Size: |
4096
|
|
2D22000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D22000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D22000
|
Size: |
12288
|
|
2BE2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BE2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BE2000
|
Size: |
4096
|
|
29D2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495108836.00000000029D2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29D2000
|
Size: |
49152
|
|
2E0C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E0C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E0C000
|
Size: |
4096
|
|
286C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244471674.000000000286C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
286C000
|
Size: |
16384
|
|
3DEC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003DEC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3DEC000
|
Size: |
4096
|
|
2E57000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E57000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E57000
|
Size: |
4096
|
|
6470000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2502062310.0000000006470000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6470000
|
Size: |
65536
|
|
2EC9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002EC9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EC9000
|
Size: |
135168
|
|
2F60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F60000
|
Size: |
4096
|
|
2E29000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E29000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E29000
|
Size: |
4096
|
|
2C94000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C94000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C94000
|
Size: |
12288
|
|
2D0B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D0B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D0B000
|
Size: |
4096
|
|
2D9B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D9B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D9B000
|
Size: |
4096
|
|
2A63000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A63000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A63000
|
Size: |
36864
|
|
6630000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2503548843.0000000006630000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6630000
|
Size: |
45056
|
|
2A46000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A46000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A46000
|
Size: |
45056
|
|
2B0F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B0F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B0F000
|
Size: |
4096
|
|
2E3E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E3E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E3E000
|
Size: |
12288
|
|
2D01000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002D01000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
81920
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
65A5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2502920327.00000000065A5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
65A5000
|
Size: |
45056
|
|
5310000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2500162565.0000000005310000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5310000
|
Size: |
4096
|
|
5A50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1258606696.0000000005A50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5A50000
|
Size: |
65536
|
|
2ADC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002ADC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2ADC000
|
Size: |
4096
|
|
D00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2492449154.0000000000D00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
D00000
|
Size: |
8192
|
|
2CB9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CB9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CB9000
|
Size: |
4096
|
|
B69000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1243225199.0000000000B69000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B69000
|
Size: |
352256
|
|
2EE4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002EE4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EE4000
|
Size: |
4096
|
|
390000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1232107809.0000000000390000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
390000
|
Size: |
4096
|
|
2F1E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F1E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F1E000
|
Size: |
8192
|
|
2D52000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D52000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D52000
|
Size: |
4096
|
|
4DFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257017780.0000000004DFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4DFE000
|
Size: |
8192
|
|
2C51000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C51000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C51000
|
Size: |
4096
|
|
2BDE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002BDE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BDE000
|
Size: |
4096
|
|
2D85000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002D85000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D85000
|
Size: |
212992
|
|
2F1A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F1A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F1A000
|
Size: |
4096
|
|
6810000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2503625977.0000000006810000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6810000
|
Size: |
4096
|
|
B75000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2492241254.0000000000B75000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B75000
|
Size: |
12288
|
|
2C74000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C74000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C74000
|
Size: |
4096
|
|
2C6A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C6A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C6A000
|
Size: |
4096
|
|
2D23000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002D23000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D23000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2C4F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C4F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C4F000
|
Size: |
4096
|
|
5BC5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1259423831.0000000005BC5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5BC5000
|
Size: |
36864
|
|
5C74000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2500591390.0000000005C74000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C74000
|
Size: |
73728
|
|
2CCE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CCE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CCE000
|
Size: |
12288
|
|
2C6E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C6E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C6E000
|
Size: |
4096
|
|
2F16000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F16000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F16000
|
Size: |
4096
|
|
400000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2491666628.0000000000400000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
4096
|
|
2B4E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B4E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B4E000
|
Size: |
36864
|
|
3E5E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003E5E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E5E000
|
Size: |
8192
|
|
2B75000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B75000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B75000
|
Size: |
94208
|
|
5B20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1259242649.0000000005B20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5B20000
|
Size: |
65536
|
|
29C6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495108836.00000000029C6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29C6000
|
Size: |
16384
|
|
2B6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495475499.0000000002B6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B6E000
|
Size: |
8192
|
|
2D97000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D97000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D97000
|
Size: |
4096
|
|
6566000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2502839586.0000000006566000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6566000
|
Size: |
4096
|
|
2CF7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CF7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CF7000
|
Size: |
4096
|
|
5C40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1259621526.0000000005C40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5C40000
|
Size: |
65536
|
|
1020000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2494925671.0000000001020000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1020000
|
Size: |
16384
|
|
2AAA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AAA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AAA000
|
Size: |
4096
|
|
29BE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495108836.00000000029BE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29BE000
|
Size: |
4096
|
|
6450000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2501793890.0000000006450000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6450000
|
Size: |
49152
|
|
2B43000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B43000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B43000
|
Size: |
4096
|
|
55A0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1257317175.00000000055A0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
55A0000
|
Size: |
1097728
|
|
2AAF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AAF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AAF000
|
Size: |
36864
|
|
2D5A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D5A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D5A000
|
Size: |
4096
|
|
2D09000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D09000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D09000
|
Size: |
4096
|
|
2C22000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2495497502.0000000002C22000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C22000
|
Size: |
4096
|
|
2A60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A60000
|
Size: |
8192
|
|
2CBF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CBF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CBF000
|
Size: |
32768
|
|
3ED0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003ED0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3ED0000
|
Size: |
20480
|
|
65C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2503151391.00000000065C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
65C0000
|
Size: |
65536
|
|
2E5F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E5F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E5F000
|
Size: |
122880
|
|
3E4D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2498157143.0000000003E4D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E4D000
|
Size: |
4096
|
|
2F1C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F1C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F1C000
|
Size: |
4096
|
|
2D11000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D11000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D11000
|
Size: |
40960
|
|
2DAE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002DAE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DAE000
|
Size: |
4096
|
|
5C20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2500320922.0000000005C20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C20000
|
Size: |
4096
|
|
2E21000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002E21000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E21000
|
Size: |
12288
|
|
2D5E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D5E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D5E000
|
Size: |
4096
|
|
29D7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.00000000029D7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29D7000
|
Size: |
4096
|
|
2CC8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CC8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CC8000
|
Size: |
4096
|
|
2F14000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F14000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F14000
|
Size: |
4096
|
|
2CD4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002CD4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CD4000
|
Size: |
4096
|
|
2A0B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002A0B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A0B000
|
Size: |
4096
|
|
628E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2501591521.000000000628E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
628E000
|
Size: |
8192
|
|
2C36000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C36000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C36000
|
Size: |
4096
|
|
2F12000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002F12000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F12000
|
Size: |
4096
|
|
2B2C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002B2C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B2C000
|
Size: |
4096
|
|
2AE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002AE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AE0000
|
Size: |
4096
|
|
2D56000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002D56000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D56000
|
Size: |
4096
|
|
CF2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244008004.0000000000CF2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
CF2000
|
Size: |
4096
|
|
2C9E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002C9E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C9E000
|
Size: |
4096
|
|
2ADE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1244570435.0000000002ADE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2ADE000
|
Size: |
4096
|
|