459000
|
unkown
|
page readonly
|
 |
|
|
Name: |
00000000.00000002.3738169004.0000000000459000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
459000
|
Size: |
102400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected UAC Bypass using CMSTP |
Exploits |
|
Yara detected Keylogger Generic |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
|
Yara signature match |
System Summary |
|
Public key (encryption) found |
Cryptography |
|
|
7EE000
|
heap
|
page read and write
|
 |
|
|
Name: |
00000000.00000002.3738421997.00000000007EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7EE000
|
Size: |
217088
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
841000
|
heap
|
page read and write
|
 |
|
|
Name: |
00000000.00000003.3733647696.0000000000841000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
841000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
URLs found in memory or binary data |
Networking |
|
|
842000
|
heap
|
page read and write
|
 |
|
|
Name: |
00000000.00000002.3738510764.0000000000842000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
842000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
URLs found in memory or binary data |
Networking |
|
|
24BF000
|
stack
|
page read and write
|
 |
|
|
Name: |
00000000.00000002.3738682489.00000000024BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
24BF000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
459000
|
unkown
|
page readonly
|
 |
|
|
Name: |
00000000.00000000.1285674449.0000000000459000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
459000
|
Size: |
102400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected UAC Bypass using CMSTP |
Exploits |
|
Yara detected Keylogger Generic |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
|
Yara signature match |
System Summary |
|
|
832000
|
heap
|
page read and write
|
 |
|
|
Name: |
00000000.00000003.3733562013.0000000000832000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
832000
|
Size: |
126976
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Remcos RAT |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
URLs found in memory or binary data |
Networking |
|
|
9DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738617678.00000000009DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9DF000
|
Size: |
4096
|
|
869000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1362520022.0000000000869000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
869000
|
Size: |
12288
|
|
655000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738290361.0000000000655000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
655000
|
Size: |
12288
|
|
87B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3734280713.000000000087B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
87B000
|
Size: |
24576
|
|
3B91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3733756427.0000000003B91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3B91000
|
Size: |
5242880
|
|
2AAF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738786284.0000000002AAF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2AAF000
|
Size: |
4096
|
|
600000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738277854.0000000000600000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
600000
|
Size: |
4096
|
|
790000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738363403.0000000000790000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
790000
|
Size: |
32768
|
|
9C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738051635.000000000009C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9C000
|
Size: |
16384
|
|
873000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738550380.0000000000873000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
873000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2AEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738803462.0000000002AEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2AEE000
|
Size: |
8192
|
|
660000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738319347.0000000000660000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
660000
|
Size: |
36864
|
|
670000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738319347.0000000000670000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
670000
|
Size: |
32768
|
|
472000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1285698449.0000000000472000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
472000
|
Size: |
4096
|
|
650000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738290361.0000000000650000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
650000
|
Size: |
16384
|
|
478000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1285712779.0000000000478000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
478000
|
Size: |
36864
|
|
5FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738260717.00000000005FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5FE000
|
Size: |
8192
|
|
2C2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738841521.0000000002C2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C2E000
|
Size: |
8192
|
|
823000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3734246344.0000000000823000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
823000
|
Size: |
49152
|
|
2D2F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738858794.0000000002D2F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D2F000
|
Size: |
4096
|
|
79A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738363403.000000000079A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79A000
|
Size: |
16384
|
|
832000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3734246344.0000000000832000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
832000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
URLs found in memory or binary data |
Networking |
|
|
329E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3739014845.000000000329E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
329E000
|
Size: |
8192
|
|
2D6C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738873532.0000000002D6C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D6C000
|
Size: |
16384
|
|
2FFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738936595.0000000002FFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FFE000
|
Size: |
8192
|
|
23BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738666320.00000000023BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
23BE000
|
Size: |
8192
|
|
33B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3733686848.00000000033B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33B1000
|
Size: |
24576
|
|
855000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3733647696.0000000000855000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
855000
|
Size: |
45056
|
|
33B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3739047022.00000000033B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33B0000
|
Size: |
4096
|
|
7EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738421997.00000000007EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7EA000
|
Size: |
8192
|
|
2520000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738733458.0000000002520000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2520000
|
Size: |
4096
|
|
29AC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738768078.00000000029AC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
29AC000
|
Size: |
16384
|
|
873000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1362316352.0000000000873000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
873000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2E6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738891224.0000000002E6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E6E000
|
Size: |
8192
|
|
7DC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738403631.00000000007DC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7DC000
|
Size: |
16384
|
|
832000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1362316352.0000000000832000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
832000
|
Size: |
126976
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
ADF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738632736.0000000000ADF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
ADF000
|
Size: |
4096
|
|
45BA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3734296209.00000000045BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
45BA000
|
Size: |
5246976
|
|
1F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738090820.00000000001F0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F0000
|
Size: |
4096
|
|
870000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1362316352.0000000000870000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
870000
|
Size: |
4096
|
|
19C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738074313.000000000019C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
19C000
|
Size: |
16384
|
|
24FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738698932.00000000024FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
24FC000
|
Size: |
16384
|
|
472000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738187453.0000000000472000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
472000
|
Size: |
8192
|
|
339F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3739031503.000000000339F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
339F000
|
Size: |
4096
|
|
3B95000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3732295007.0000000003B95000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3B95000
|
Size: |
5242880
|
|
870000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1362520022.0000000000870000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
870000
|
Size: |
4096
|
|
315F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738989102.000000000315F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
315F000
|
Size: |
4096
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1285619174.0000000000400000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
401000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1285635925.0000000000401000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
401000
|
Size: |
360448
|
|
87B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3733720244.000000000087B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
87B000
|
Size: |
32768
|
|
862000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738550380.0000000000862000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
862000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
262F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738750388.000000000262F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
262F000
|
Size: |
4096
|
|
869000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738550380.0000000000869000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
869000
|
Size: |
12288
|
|
870000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738550380.0000000000870000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
870000
|
Size: |
4096
|
|
869000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1362316352.0000000000869000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
869000
|
Size: |
12288
|
|
2EBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738905257.0000000002EBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2EBE000
|
Size: |
8192
|
|
2500000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738716933.0000000002500000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2500000
|
Size: |
4096
|
|
832000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738490042.0000000000832000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
832000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
URLs found in memory or binary data |
Networking |
|
|
40A5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3732648852.00000000040A5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
40A5000
|
Size: |
5242880
|
|
2BEF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738822431.0000000002BEF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2BEF000
|
Size: |
4096
|
|
855000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1362316352.0000000000855000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
855000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
475000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738187453.0000000000475000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
475000
|
Size: |
8192
|
|
2FBF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738920916.0000000002FBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FBF000
|
Size: |
4096
|
|
855000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3733562013.0000000000855000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
855000
|
Size: |
45056
|
|
823000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3733562013.0000000000823000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
823000
|
Size: |
8192
|
|
401000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.3738123669.0000000000401000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
401000
|
Size: |
360448
|
|
832000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3733735918.0000000000832000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
832000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
478000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.3738215753.0000000000478000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
478000
|
Size: |
36864
|
|
33C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3739047022.00000000033C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33C0000
|
Size: |
16384
|
|
33C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3733686848.00000000033C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33C0000
|
Size: |
16384
|
|
560000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738232199.0000000000560000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
560000
|
Size: |
4096
|
|
860000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1362520022.0000000000860000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
860000
|
Size: |
28672
|
|
305B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738952691.000000000305B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
305B000
|
Size: |
4096
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.3738110729.0000000000400000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
237B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738649515.000000000237B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
237B000
|
Size: |
20480
|
|
873000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1362520022.0000000000873000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
873000
|
Size: |
32768
|
|
7E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738421997.00000000007E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E0000
|
Size: |
32768
|
|
5AC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738245211.00000000005AC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5AC000
|
Size: |
16384
|
|
855000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738510764.0000000000855000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
855000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
826000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.3733562013.0000000000826000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
826000
|
Size: |
24576
|
|
3050000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.3738952691.0000000003050000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3050000
|
Size: |
20480
|
|