3EEB000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000001.00000002.1442762830.0000000003EEB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3EEB000
|
Size: |
765952
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Yara detected Amadeys Clipper DLL |
Stealing of Sensitive Information |
|
Contains functionality to start a terminal service |
Remote Access Functionality |
|
Sample uses string decryption to hide its real strings |
AV Detection |
|
|
2DD1000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000001.00000002.1425446365.0000000002DD1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DD1000
|
Size: |
1232896
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Contains functionality to start a terminal service |
Remote Access Functionality |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
Yara detected Costura Assembly Loader |
Data Obfuscation |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
6030000
|
trusted library section
|
page read and write
|
 |
|
|
Name: |
00000001.00000002.1452919295.0000000006030000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
6030000
|
Size: |
536576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Costura Assembly Loader |
Data Obfuscation |
|
|
2F59000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F59000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F59000
|
Size: |
4096
|
|
326E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000326E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
326E000
|
Size: |
4096
|
|
AB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1421696171.0000000000AB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AB1000
|
Size: |
45056
|
|
6000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384696245.0000000006000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6000000
|
Size: |
65536
|
|
3323000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003323000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3323000
|
Size: |
24576
|
|
2FC4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FC4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FC4000
|
Size: |
4096
|
|
332A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000332A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
332A000
|
Size: |
20480
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1404963154.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
20480
|
|
6160000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383761413.0000000006160000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6160000
|
Size: |
65536
|
|
328D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000328D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
328D000
|
Size: |
4096
|
|
A9C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1421696171.0000000000A9C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A9C000
|
Size: |
81920
|
|
5F80000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1451990901.0000000005F80000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
5F80000
|
Size: |
548864
|
|
5940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1388584425.0000000005940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5940000
|
Size: |
53248
|
|
2CB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425282705.0000000002CB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CB0000
|
Size: |
65536
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1402645236.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
12288
|
|
3013000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003013000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
4096
|
|
654000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1420918942.0000000000654000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
654000
|
Size: |
4096
|
|
5F9C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1376708727.0000000005F9C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F9C000
|
Size: |
16384
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391918447.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
49152
|
|
880000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664451198.0000000000880000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
880000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385664327.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
24576
|
|
5F90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384998530.0000000005F90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F90000
|
Size: |
65536
|
|
5F80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1376869318.0000000005F80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F80000
|
Size: |
49152
|
|
31E9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031E9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31E9000
|
Size: |
4096
|
|
5F5A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1451533873.0000000005F5A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F5A000
|
Size: |
24576
|
|
6110000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1453913699.0000000006110000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6110000
|
Size: |
65536
|
|
5FD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387388885.0000000005FD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FD0000
|
Size: |
65536
|
|
5F30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1377351780.0000000005F30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F30000
|
Size: |
65536
|
|
6120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1400500764.0000000006120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6120000
|
Size: |
65536
|
|
3178000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003178000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3178000
|
Size: |
4096
|
|
5950000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1388531711.0000000005950000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5950000
|
Size: |
65536
|
|
2AE6000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1424784484.0000000002AE6000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2AE6000
|
Size: |
8192
|
|
6120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1411174113.0000000006120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6120000
|
Size: |
20480
|
|
60F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370642017.00000000060F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60F0000
|
Size: |
65536
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383879233.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
65536
|
|
3240000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003240000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3240000
|
Size: |
4096
|
|
2CAC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425246961.0000000002CAC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2CAC000
|
Size: |
16384
|
|
4FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3663293528.00000000004FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4FC000
|
Size: |
16384
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1369347562.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
24576
|
|
5F90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386387976.0000000005F90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F90000
|
Size: |
32768
|
|
3042000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003042000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3042000
|
Size: |
4096
|
|
2EFF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002EFF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EFF000
|
Size: |
4096
|
|
6120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1409097534.0000000006120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6120000
|
Size: |
16384
|
|
31F3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031F3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31F3000
|
Size: |
4096
|
|
6014000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1399288352.0000000006014000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6014000
|
Size: |
49152
|
|
3048000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003048000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3048000
|
Size: |
4096
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1369111324.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
24576
|
|
3321000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003321000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3321000
|
Size: |
4096
|
|
5F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1375691880.0000000005F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F50000
|
Size: |
8192
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393196297.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
65536
|
|
63F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1415958919.00000000063F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F0000
|
Size: |
65536
|
|
5970000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387756266.0000000005970000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5970000
|
Size: |
57344
|
|
D2D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1423213314.0000000000D2D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
D2D000
|
Size: |
4096
|
|
6015000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1396435549.0000000006015000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6015000
|
Size: |
12288
|
|
5910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386895319.0000000005910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5910000
|
Size: |
16384
|
|
3167000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003167000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3167000
|
Size: |
57344
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1398703426.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
32768
|
|
575000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.3664044207.0000000000575000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
575000
|
Size: |
16384
|
|
2AE2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1424758612.0000000002AE2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AE2000
|
Size: |
4096
|
|
323C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000323C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
323C000
|
Size: |
4096
|
|
5950000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385401614.0000000005950000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5950000
|
Size: |
65536
|
|
310F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000310F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
310F000
|
Size: |
4096
|
|
59CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1448467726.00000000059CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59CE000
|
Size: |
8192
|
|
3015000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003015000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3015000
|
Size: |
122880
|
|
9C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1420480689.000000000009C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9C000
|
Size: |
16384
|
|
2980000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1424680473.0000000002980000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2980000
|
Size: |
4096
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1397146216.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
16384
|
|
A80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1421696171.0000000000A80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A80000
|
Size: |
24576
|
|
5940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385445687.0000000005940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5940000
|
Size: |
65536
|
|
6030000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371099278.0000000006030000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6030000
|
Size: |
65536
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393648149.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
5910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1447870744.0000000005910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5910000
|
Size: |
65536
|
|
6350000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1382643689.0000000006350000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6350000
|
Size: |
65536
|
|
904000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1367138491.0000000000904000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
904000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393488831.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
600F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371180944.000000000600F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
600F000
|
Size: |
4096
|
|
63A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1382457448.00000000063A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63A0000
|
Size: |
65536
|
|
3236000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003236000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3236000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1392885021.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
65536
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1397396329.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394597853.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
36864
|
|
A88000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1421696171.0000000000A88000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A88000
|
Size: |
77824
|
|
5960000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387803477.0000000005960000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5960000
|
Size: |
65536
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393520194.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
6120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1410390523.0000000006120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6120000
|
Size: |
16384
|
|
5930000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1447962287.0000000005930000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
286720
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
B3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1372030893.0000000000B3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B3D000
|
Size: |
16384
|
|
339E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000339E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
339E000
|
Size: |
4096
|
|
B44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385162739.0000000000B44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B44000
|
Size: |
90112
|
|
323A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000323A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
323A000
|
Size: |
4096
|
|
327F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000327F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
327F000
|
Size: |
20480
|
|
67D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000000.1204484168.000000000067D000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
67D000
|
Size: |
1523712
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1408548869.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
20480
|
|
5940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386698529.0000000005940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5940000
|
Size: |
65536
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1403390496.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
16384
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1400314094.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
65536
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1400426261.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
12288
|
|
D10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1423043182.0000000000D10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
D10000
|
Size: |
12288
|
|
63F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1419419912.00000000063F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F0000
|
Size: |
4096
|
|
3044000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003044000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3044000
|
Size: |
4096
|
|
3148000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003148000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3148000
|
Size: |
4096
|
|
339C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000339C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
339C000
|
Size: |
4096
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1404453472.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
49152
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391770363.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
65536
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384224556.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
65536
|
|
308D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000308D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
308D000
|
Size: |
4096
|
|
3289000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003289000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3289000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1388408730.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
24576
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394945532.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
65536
|
|
5FC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371387980.0000000005FC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FC0000
|
Size: |
65536
|
|
A50000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1421492791.0000000000A50000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
A50000
|
Size: |
4096
|
|
5920000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386789394.0000000005920000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5920000
|
Size: |
65536
|
|
3355000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003355000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3355000
|
Size: |
4096
|
|
30C4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030C4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30C4000
|
Size: |
4096
|
|
63F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1381614752.00000000063F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F0000
|
Size: |
65536
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1369199787.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
45056
|
|
5FA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1376602483.0000000005FA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FA0000
|
Size: |
65536
|
|
60E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370687675.00000000060E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60E0000
|
Size: |
65536
|
|
3357000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003357000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3357000
|
Size: |
8192
|
|
580D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1447776098.000000000580D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
580D000
|
Size: |
12288
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1453466654.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
53248
|
|
6015000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1396498241.0000000006015000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6015000
|
Size: |
12288
|
|
664000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000000.1204484168.0000000000664000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
664000
|
Size: |
98304
|
|
320C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000320C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
320C000
|
Size: |
40960
|
|
934000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664487750.0000000000934000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
934000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
904000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1365217885.0000000000904000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
904000
|
Size: |
8192
|
|
2C5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3665467075.0000000002C5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C5E000
|
Size: |
8192
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1398200389.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
65536
|
|
303C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000303C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
303C000
|
Size: |
4096
|
|
300F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000300F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
300F000
|
Size: |
4096
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1399933205.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
16384
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1399797528.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
65536
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1392089535.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
65536
|
|
331F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000331F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
331F000
|
Size: |
4096
|
|
5F60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371610654.0000000005F60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F60000
|
Size: |
65536
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1369265543.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
20480
|
|
5300000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1446174141.0000000005300000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5300000
|
Size: |
20480
|
|
3117000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003117000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3117000
|
Size: |
4096
|
|
2F62000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F62000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F62000
|
Size: |
28672
|
|
331B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000331B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
331B000
|
Size: |
4096
|
|
2AEA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1424815556.0000000002AEA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2AEA000
|
Size: |
4096
|
|
30F6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030F6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30F6000
|
Size: |
4096
|
|
2FBE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FBE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FBE000
|
Size: |
4096
|
|
2F89000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F89000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F89000
|
Size: |
4096
|
|
6060000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370988570.0000000006060000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6060000
|
Size: |
65536
|
|
3187000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003187000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3187000
|
Size: |
28672
|
|
30FE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030FE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30FE000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393110120.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
5920000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385704836.0000000005920000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5920000
|
Size: |
65536
|
|
32E1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032E1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32E1000
|
Size: |
4096
|
|
2B9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425089769.0000000002B9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B9E000
|
Size: |
8192
|
|
5960000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386610561.0000000005960000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5960000
|
Size: |
65536
|
|
32D7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032D7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32D7000
|
Size: |
4096
|
|
6114000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383924924.0000000006114000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6114000
|
Size: |
16384
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1395000913.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
65536
|
|
6120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1454010217.0000000006120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6120000
|
Size: |
8192
|
|
2FBA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FBA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FBA000
|
Size: |
4096
|
|
5945000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387937371.0000000005945000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5945000
|
Size: |
45056
|
|
6440000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1381005283.0000000006440000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6440000
|
Size: |
61440
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391108753.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
65536
|
|
5F70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1451877492.0000000005F70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F70000
|
Size: |
65536
|
|
33F9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033F9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33F9000
|
Size: |
4096
|
|
526E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1446050595.000000000526E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
526E000
|
Size: |
8192
|
|
6180000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383670413.0000000006180000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6180000
|
Size: |
65536
|
|
2AAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3665397583.0000000002AAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2AAE000
|
Size: |
8192
|
|
6BA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1415518390.0000000006BA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6BA0000
|
Size: |
65536
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394527815.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
3332000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003332000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3332000
|
Size: |
4096
|
|
6140000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1409784979.0000000006140000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6140000
|
Size: |
65536
|
|
6B94000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1415642954.0000000006B94000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6B94000
|
Size: |
49152
|
|
31EF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031EF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31EF000
|
Size: |
4096
|
|
800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1421170360.0000000000800000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
800000
|
Size: |
4096
|
|
32C8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032C8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32C8000
|
Size: |
24576
|
|
5FE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387345868.0000000005FE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FE0000
|
Size: |
65536
|
|
5F40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371709654.0000000005F40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F40000
|
Size: |
65536
|
|
6B90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1416085298.0000000006B90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6B90000
|
Size: |
8192
|
|
2FD5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FD5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FD5000
|
Size: |
4096
|
|
5FB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384906426.0000000005FB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FB0000
|
Size: |
28672
|
|
6180000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1454225673.0000000006180000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6180000
|
Size: |
65536
|
|
5DC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1369819998.0000000005DC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5DC0000
|
Size: |
1232896
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1395135772.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
65536
|
|
5F90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387562919.0000000005F90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F90000
|
Size: |
65536
|
|
3046000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003046000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3046000
|
Size: |
4096
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1398813821.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
65536
|
|
31F6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031F6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31F6000
|
Size: |
4096
|
|
30BE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030BE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30BE000
|
Size: |
4096
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1396355031.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
49152
|
|
33A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33A0000
|
Size: |
4096
|
|
770000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664342175.0000000000770000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
770000
|
Size: |
16384
|
|
2F5E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F5E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F5E000
|
Size: |
12288
|
|
595E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387846963.000000000595E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
595E000
|
Size: |
8192
|
|
5940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391381434.0000000005940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5940000
|
Size: |
4096
|
|
5FBC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371437097.0000000005FBC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FBC000
|
Size: |
16384
|
|
5F88000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371537978.0000000005F88000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F88000
|
Size: |
32768
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1405151888.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
8192
|
|
5FA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384958135.0000000005FA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FA0000
|
Size: |
65536
|
|
286E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3665307741.000000000286E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
286E000
|
Size: |
8192
|
|
6220000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383304746.0000000006220000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6220000
|
Size: |
65536
|
|
5F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386466584.0000000005F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F50000
|
Size: |
65536
|
|
331D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000331D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
331D000
|
Size: |
4096
|
|
64F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1420801074.000000000064F000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
64F000
|
Size: |
4096
|
|
6190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1414586900.0000000006190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6190000
|
Size: |
65536
|
|
750000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664280131.0000000000750000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
750000
|
Size: |
16384
|
|
6000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387241957.0000000006000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6000000
|
Size: |
65536
|
|
6112000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383924924.0000000006112000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6112000
|
Size: |
4096
|
|
5942000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391381434.0000000005942000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5942000
|
Size: |
36864
|
|
32F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32F0000
|
Size: |
4096
|
|
30E3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030E3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30E3000
|
Size: |
4096
|
|
33DC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033DC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33DC000
|
Size: |
8192
|
|
5920000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385538803.0000000005920000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5920000
|
Size: |
65536
|
|
2FC6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FC6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FC6000
|
Size: |
16384
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1392192116.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
65536
|
|
31F1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031F1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31F1000
|
Size: |
4096
|
|
6110000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370574053.0000000006110000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6110000
|
Size: |
65536
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1406931936.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
8192
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1369233823.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
45056
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1403208516.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
16384
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1402507274.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
36864
|
|
31D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31D0000
|
Size: |
4096
|
|
775000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664342175.0000000000775000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
775000
|
Size: |
16384
|
|
6B90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1414359768.0000000006B90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6B90000
|
Size: |
53248
|
|
6140000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1412972925.0000000006140000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6140000
|
Size: |
65536
|
|
63F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1416144811.00000000063F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F0000
|
Size: |
65536
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1400173591.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
8192
|
|
6120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1397532350.0000000006120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6120000
|
Size: |
65536
|
|
2F28000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F28000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F28000
|
Size: |
45056
|
|
2F76000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F76000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F76000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393615218.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
20480
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393553230.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
60A4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384305478.00000000060A4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60A4000
|
Size: |
49152
|
|
5F60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1373349783.0000000005F60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F60000
|
Size: |
65536
|
|
33A6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033A6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33A6000
|
Size: |
4096
|
|
5970000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385312716.0000000005970000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5970000
|
Size: |
65536
|
|
3270000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003270000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3270000
|
Size: |
4096
|
|
6180000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370352727.0000000006180000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6180000
|
Size: |
65536
|
|
309B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000309B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
309B000
|
Size: |
114688
|
|
5F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1392358050.0000000005F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F50000
|
Size: |
24576
|
|
60C1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1405057610.00000000060C1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C1000
|
Size: |
61440
|
|
2F51000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F51000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F51000
|
Size: |
4096
|
|
313E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000313E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
313E000
|
Size: |
4096
|
|
3255000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003255000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3255000
|
Size: |
4096
|
|
3221000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003221000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3221000
|
Size: |
4096
|
|
30E1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030E1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30E1000
|
Size: |
4096
|
|
6160000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370414156.0000000006160000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6160000
|
Size: |
65536
|
|
2AF2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1424863487.0000000002AF2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AF2000
|
Size: |
4096
|
|
2FFB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FFB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FFB000
|
Size: |
28672
|
|
6B90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1416376527.0000000006B90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6B90000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394431345.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
2640000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1424549561.0000000002640000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2640000
|
Size: |
4096
|
|
33D8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033D8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33D8000
|
Size: |
4096
|
|
5F60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1377027865.0000000005F60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F60000
|
Size: |
24576
|
|
6120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1409598843.0000000006120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6120000
|
Size: |
45056
|
|
334D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000334D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
334D000
|
Size: |
4096
|
|
904000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1367167073.0000000000904000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
904000
|
Size: |
4096
|
|
5910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386102936.0000000005910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5910000
|
Size: |
65536
|
|
6070000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384404127.0000000006070000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6070000
|
Size: |
65536
|
|
3202000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003202000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3202000
|
Size: |
4096
|
|
5FA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387519302.0000000005FA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FA0000
|
Size: |
65536
|
|
1DC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3663170690.00000000001DC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1DC000
|
Size: |
16384
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1401604033.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
40960
|
|
3272000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003272000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3272000
|
Size: |
4096
|
|
91B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664487750.000000000091B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91B000
|
Size: |
98304
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1402728248.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
20480
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1400570320.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
65536
|
|
5220000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1367966115.0000000005220000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5220000
|
Size: |
16384
|
|
6190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1414730721.0000000006190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6190000
|
Size: |
32768
|
|
5F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1378004412.0000000005F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F50000
|
Size: |
8192
|
|
B3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1421696171.0000000000B3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B3D000
|
Size: |
270336
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1406141773.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
12288
|
|
6050000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384488186.0000000006050000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6050000
|
Size: |
4096
|
|
32A7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032A7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32A7000
|
Size: |
4096
|
|
3144000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003144000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3144000
|
Size: |
4096
|
|
5CBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1449736958.0000000005CBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5CBE000
|
Size: |
8192
|
|
6100000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384126900.0000000006100000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6100000
|
Size: |
12288
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391880753.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
28672
|
|
3403000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003403000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3403000
|
Size: |
4096
|
|
904000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1367103380.0000000000904000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
904000
|
Size: |
4096
|
|
5980000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386510450.0000000005980000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5980000
|
Size: |
32768
|
|
3074000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003074000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3074000
|
Size: |
20480
|
|
30CB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030CB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30CB000
|
Size: |
12288
|
|
31CC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031CC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31CC000
|
Size: |
4096
|
|
5981000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387685026.0000000005981000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5981000
|
Size: |
8192
|
|
325D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000325D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
325D000
|
Size: |
4096
|
|
307F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000307F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
307F000
|
Size: |
53248
|
|
5F80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387605423.0000000005F80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F80000
|
Size: |
61440
|
|
2D5D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3665499738.0000000002D5D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D5D000
|
Size: |
12288
|
|
63F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1418356986.00000000063F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F0000
|
Size: |
49152
|
|
30F2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030F2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30F2000
|
Size: |
12288
|
|
6150000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383802710.0000000006150000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6150000
|
Size: |
65536
|
|
5F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385243809.0000000005F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F50000
|
Size: |
32768
|
|
2F85000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F85000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F85000
|
Size: |
4096
|
|
8D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664487750.00000000008D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D0000
|
Size: |
24576
|
|
3334000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003334000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3334000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394134775.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
319D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000319D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
319D000
|
Size: |
126976
|
|
6011000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371180944.0000000006011000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6011000
|
Size: |
61440
|
|
323E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000323E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
323E000
|
Size: |
4096
|
|
30DD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030DD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30DD000
|
Size: |
4096
|
|
5940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1392833502.0000000005940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5940000
|
Size: |
65536
|
|
4091000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1442762830.0000000004091000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4091000
|
Size: |
4096
|
|
33DA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033DA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33DA000
|
Size: |
4096
|
|
24E0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1423272813.00000000024E0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
24E0000
|
Size: |
1421312
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara signature match |
System Summary |
|
|
2FE6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FE6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FE6000
|
Size: |
28672
|
|
65D000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000001.00000000.1204429229.000000000065D000.00000008.00000001.01000000.00000006.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
65D000
|
Size: |
20480
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1368569259.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
65536
|
|
5910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386294930.0000000005910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5910000
|
Size: |
20480
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1399602566.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
16384
|
|
2F0B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F0B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F0B000
|
Size: |
106496
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1388010758.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
65536
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387175058.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
20480
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394212972.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
20480
|
|
3197000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003197000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3197000
|
Size: |
4096
|
|
3034000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003034000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3034000
|
Size: |
28672
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394035405.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
304B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000304B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
304B000
|
Size: |
28672
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394255510.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1400007978.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
45056
|
|
5FF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387302449.0000000005FF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FF0000
|
Size: |
65536
|
|
297C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1424648188.000000000297C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
297C000
|
Size: |
16384
|
|
63C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1382361830.00000000063C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63C0000
|
Size: |
65536
|
|
5FB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387473668.0000000005FB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FB0000
|
Size: |
65536
|
|
33D4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033D4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33D4000
|
Size: |
12288
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1404551662.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
65536
|
|
3119000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003119000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3119000
|
Size: |
4096
|
|
5910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386225501.0000000005910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5910000
|
Size: |
65536
|
|
330D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000330D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
330D000
|
Size: |
4096
|
|
61D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383431141.00000000061D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
61D0000
|
Size: |
196608
|
|
6400000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1381216527.0000000006400000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6400000
|
Size: |
65536
|
|
2BFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3665446459.0000000002BFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2BFF000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394095930.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
3274000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003274000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3274000
|
Size: |
12288
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394009594.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
305F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000305F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
305F000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391647974.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
65536
|
|
30B8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030B8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30B8000
|
Size: |
12288
|
|
32CF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032CF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32CF000
|
Size: |
28672
|
|
6119000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383924924.0000000006119000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6119000
|
Size: |
8192
|
|
3153000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003153000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3153000
|
Size: |
28672
|
|
5940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393062353.0000000005940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5940000
|
Size: |
57344
|
|
6140000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1413489263.0000000006140000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6140000
|
Size: |
8192
|
|
2F3A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F3A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F3A000
|
Size: |
4096
|
|
31D4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031D4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31D4000
|
Size: |
4096
|
|
2F01000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F01000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F01000
|
Size: |
4096
|
|
5FC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387430199.0000000005FC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FC0000
|
Size: |
65536
|
|
BBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1422923581.0000000000BBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BBE000
|
Size: |
8192
|
|
6080000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370892216.0000000006080000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6080000
|
Size: |
102400
|
|
5F90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1376708727.0000000005F90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F90000
|
Size: |
36864
|
|
303E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000303E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
303E000
|
Size: |
4096
|
|
6170000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383717168.0000000006170000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6170000
|
Size: |
65536
|
|
2FDF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FDF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FDF000
|
Size: |
4096
|
|
2BD8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425205113.0000000002BD8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BD8000
|
Size: |
8192
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393148327.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
20480
|
|
30C8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030C8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30C8000
|
Size: |
4096
|
|
2F09000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F09000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F09000
|
Size: |
4096
|
|
6250000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383166891.0000000006250000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6250000
|
Size: |
65536
|
|
5980000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385274328.0000000005980000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5980000
|
Size: |
65536
|
|
2B30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425032428.0000000002B30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B30000
|
Size: |
4096
|
|
904000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1366928338.0000000000904000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
904000
|
Size: |
4096
|
|
3341000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003341000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3341000
|
Size: |
36864
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393941705.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
6210000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383347153.0000000006210000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6210000
|
Size: |
65536
|
|
5910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385590191.0000000005910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5910000
|
Size: |
65536
|
|
5FB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1376557881.0000000005FB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FB0000
|
Size: |
28672
|
|
5470000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1446351494.0000000005470000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
5470000
|
Size: |
1384448
|
|
6016000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1396267823.0000000006016000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6016000
|
Size: |
20480
|
|
2FB8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FB8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FB8000
|
Size: |
4096
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1369436182.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
12288
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1413092160.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
65536
|
|
3140000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003140000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3140000
|
Size: |
4096
|
|
6140000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383841287.0000000006140000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6140000
|
Size: |
65536
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1398926548.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
4096
|
|
904000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1367266084.0000000000904000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
904000
|
Size: |
4096
|
|
6122000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383924924.0000000006122000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6122000
|
Size: |
16384
|
|
32D9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032D9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32D9000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391832474.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
53248
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1413366298.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
65536
|
|
944000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664487750.0000000000944000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
944000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
32E5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032E5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32E5000
|
Size: |
40960
|
|
5F70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1378193599.0000000005F70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F70000
|
Size: |
65536
|
|
5F30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371764111.0000000005F30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F30000
|
Size: |
65536
|
|
333C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000333C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
333C000
|
Size: |
16384
|
|
5920000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1388435807.0000000005920000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5920000
|
Size: |
65536
|
|
30C6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030C6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30C6000
|
Size: |
4096
|
|
317A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000317A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
317A000
|
Size: |
4096
|
|
605D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384488186.000000000605D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
605D000
|
Size: |
12288
|
|
905000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1421290091.0000000000905000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
905000
|
Size: |
8192
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394332940.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
65536
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1404191305.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
32768
|
|
6320000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1382746778.0000000006320000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6320000
|
Size: |
65536
|
|
5DBF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1449770530.0000000005DBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5DBF000
|
Size: |
4096
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1404652663.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
16384
|
|
5910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1388099497.0000000005910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5910000
|
Size: |
65536
|
|
3217000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003217000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3217000
|
Size: |
12288
|
|
6190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383628308.0000000006190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6190000
|
Size: |
65536
|
|
5F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1451533873.0000000005F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F50000
|
Size: |
36864
|
|
6100000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1453834631.0000000006100000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6100000
|
Size: |
4096
|
|
30F8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030F8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30F8000
|
Size: |
20480
|
|
32A5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032A5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32A5000
|
Size: |
4096
|
|
6BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1413956569.0000000006BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6BD0000
|
Size: |
36864
|
|
6040000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384533667.0000000006040000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6040000
|
Size: |
57344
|
|
5910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385965783.0000000005910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5910000
|
Size: |
65536
|
|
32C6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032C6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32C6000
|
Size: |
4096
|
|
32C2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032C2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32C2000
|
Size: |
4096
|
|
60A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370851083.00000000060A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60A0000
|
Size: |
65536
|
|
2FC2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FC2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FC2000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391551268.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
28672
|
|
60C8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1403799669.00000000060C8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C8000
|
Size: |
32768
|
|
5EF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1451139783.0000000005EF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5EF0000
|
Size: |
45056
|
|
3146000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003146000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3146000
|
Size: |
4096
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1399002592.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
16384
|
|
30D7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030D7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30D7000
|
Size: |
4096
|
|
32F8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032F8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32F8000
|
Size: |
4096
|
|
3353000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003353000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3353000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394463158.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
305D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000305D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
305D000
|
Size: |
4096
|
|
32A9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032A9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32A9000
|
Size: |
4096
|
|
40ED000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1395294693.00000000040ED000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
40ED000
|
Size: |
892928
|
|
6170000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1454110494.0000000006170000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6170000
|
Size: |
20480
|
|
6300000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1382814229.0000000006300000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6300000
|
Size: |
65536
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1402440093.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
4096
|
|
5F67000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1377027865.0000000005F67000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F67000
|
Size: |
36864
|
|
307A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000307A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
307A000
|
Size: |
12288
|
|
63D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1382013080.00000000063D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63D0000
|
Size: |
65536
|
|
5F80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385037447.0000000005F80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F80000
|
Size: |
65536
|
|
23AB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3665266906.00000000023AB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
23AB000
|
Size: |
20480
|
|
6132000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1410216583.0000000006132000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6132000
|
Size: |
40960
|
|
2F87000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F87000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F87000
|
Size: |
4096
|
|
32AC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032AC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32AC000
|
Size: |
53248
|
|
326C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000326C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
326C000
|
Size: |
4096
|
|
2CC9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425355515.0000000002CC9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CC9000
|
Size: |
12288
|
|
3113000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003113000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3113000
|
Size: |
4096
|
|
60B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370802734.00000000060B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60B0000
|
Size: |
65536
|
|
3176000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003176000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3176000
|
Size: |
4096
|
|
30DB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030DB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30DB000
|
Size: |
4096
|
|
60D0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1453549295.00000000060D0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
60D0000
|
Size: |
65536
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394290742.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
5F40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1375772387.0000000005F40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F40000
|
Size: |
65536
|
|
6165000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1454039920.0000000006165000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6165000
|
Size: |
36864
|
|
6150000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370447003.0000000006150000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6150000
|
Size: |
65536
|
|
33A8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033A8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33A8000
|
Size: |
4096
|
|
D20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1423149792.0000000000D20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
D20000
|
Size: |
53248
|
|
30BC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030BC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30BC000
|
Size: |
4096
|
|
3238000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003238000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3238000
|
Size: |
4096
|
|
31DA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031DA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31DA000
|
Size: |
8192
|
|
2F8D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F8D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F8D000
|
Size: |
4096
|
|
6BA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1414295657.0000000006BA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6BA0000
|
Size: |
65536
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1369408895.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
4096
|
|
61B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1454456400.00000000061B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
61B0000
|
Size: |
81920
|
|
2B50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425056372.0000000002B50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B50000
|
Size: |
16384
|
|
321B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000321B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
321B000
|
Size: |
4096
|
|
63F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1415777807.00000000063F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F0000
|
Size: |
65536
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1399288352.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
12288
|
|
5970000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1392689413.0000000005970000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5970000
|
Size: |
65536
|
|
6360000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1382611266.0000000006360000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6360000
|
Size: |
65536
|
|
5FA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371467604.0000000005FA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FA0000
|
Size: |
53248
|
|
2F03000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F03000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F03000
|
Size: |
4096
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1399235211.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
45056
|
|
6176000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1454110494.0000000006176000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6176000
|
Size: |
40960
|
|
3191000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003191000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3191000
|
Size: |
4096
|
|
6120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1403495035.0000000006120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6120000
|
Size: |
12288
|
|
3195000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003195000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3195000
|
Size: |
4096
|
|
3066000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003066000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3066000
|
Size: |
28672
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1398521501.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
28672
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370774381.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
65536
|
|
321F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000321F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
321F000
|
Size: |
4096
|
|
6127000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383924924.0000000006127000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6127000
|
Size: |
16384
|
|
942000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664487750.0000000000942000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
942000
|
Size: |
4096
|
|
2645000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1366487132.0000000002645000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2645000
|
Size: |
8192
|
|
3208000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003208000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3208000
|
Size: |
4096
|
|
5F10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371944600.0000000005F10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F10000
|
Size: |
65536
|
|
5970000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386574938.0000000005970000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5970000
|
Size: |
36864
|
|
2BA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425116872.0000000002BA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BA0000
|
Size: |
65536
|
|
319B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000319B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
319B000
|
Size: |
4096
|
|
5940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1392044083.0000000005940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5940000
|
Size: |
49152
|
|
94E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1421400303.000000000094E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
94E000
|
Size: |
8192
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393711753.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
65536
|
|
56CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1447720525.00000000056CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
56CF000
|
Size: |
4096
|
|
3111000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003111000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3111000
|
Size: |
4096
|
|
5F70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371566795.0000000005F70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F70000
|
Size: |
49152
|
|
2F34000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F34000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F34000
|
Size: |
4096
|
|
308F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000308F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
308F000
|
Size: |
4096
|
|
B29000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1421696171.0000000000B29000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B29000
|
Size: |
12288
|
|
6390000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1382491254.0000000006390000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6390000
|
Size: |
65536
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394493657.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
20480
|
|
52AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1446082864.00000000052AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52AE000
|
Size: |
8192
|
|
315F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000315F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
315F000
|
Size: |
4096
|
|
953000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664487750.0000000000953000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
953000
|
Size: |
16384
|
|
5F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385118648.0000000005F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F50000
|
Size: |
65536
|
|
2641000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1417798837.0000000002641000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2641000
|
Size: |
241664
|
|
D1D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1423125819.0000000000D1D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
D1D000
|
Size: |
4096
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1399074003.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
65536
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393321144.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1396267823.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
20480
|
|
5F40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1377828565.0000000005F40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F40000
|
Size: |
65536
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1392250286.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
65536
|
|
2FD9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FD9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FD9000
|
Size: |
4096
|
|
22AC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3665226640.00000000022AC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
22AC000
|
Size: |
16384
|
|
3259000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003259000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3259000
|
Size: |
4096
|
|
63F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1416413813.00000000063F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F0000
|
Size: |
65536
|
|
2F8F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F8F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F8F000
|
Size: |
4096
|
|
2FEE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FEE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FEE000
|
Size: |
12288
|
|
2F57000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F57000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F57000
|
Size: |
4096
|
|
6120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1411368229.0000000006120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6120000
|
Size: |
12288
|
|
2F3E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F3E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F3E000
|
Size: |
4096
|
|
5F30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1374237244.0000000005F30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F30000
|
Size: |
65536
|
|
62B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1382850946.00000000062B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
62B0000
|
Size: |
225280
|
|
5950000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1392787954.0000000005950000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5950000
|
Size: |
65536
|
|
33F7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033F7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33F7000
|
Size: |
4096
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1452682901.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
65536
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1396980387.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
20480
|
|
2F78000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F78000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F78000
|
Size: |
49152
|
|
3257000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003257000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3257000
|
Size: |
4096
|
|
3223000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003223000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3223000
|
Size: |
4096
|
|
6240000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383204999.0000000006240000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6240000
|
Size: |
65536
|
|
31F8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031F8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31F8000
|
Size: |
36864
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393880802.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
6030000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384570630.0000000006030000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6030000
|
Size: |
65536
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1396498241.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
16384
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1395245280.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
20480
|
|
6370000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1382573870.0000000006370000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6370000
|
Size: |
65536
|
|
6028000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384612893.0000000006028000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6028000
|
Size: |
32768
|
|
904000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1366803942.0000000000904000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
904000
|
Size: |
4096
|
|
2FD7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FD7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FD7000
|
Size: |
4096
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1398763018.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
49152
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1397049084.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
16384
|
|
305B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000305B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
305B000
|
Size: |
4096
|
|
6120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1399688249.0000000006120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6120000
|
Size: |
20480
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1402322490.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
65536
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1408851359.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
16384
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1396142102.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
16384
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1369166733.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
36864
|
|
3285000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003285000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3285000
|
Size: |
4096
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1392305571.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
65536
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393384615.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
6340000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1382676229.0000000006340000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6340000
|
Size: |
65536
|
|
5940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394397256.0000000005940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5940000
|
Size: |
20480
|
|
3161000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003161000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3161000
|
Size: |
4096
|
|
5920000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386942902.0000000005920000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5920000
|
Size: |
53248
|
|
900000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1421290091.0000000000900000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
900000
|
Size: |
16384
|
|
6330000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1382712599.0000000006330000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6330000
|
Size: |
65536
|
|
19D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1420599287.000000000019D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
19D000
|
Size: |
12288
|
|
5F60000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1451748762.0000000005F60000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5F60000
|
Size: |
65536
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370730021.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
65536
|
|
2FDB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FDB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FDB000
|
Size: |
4096
|
|
62A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1382965556.00000000062A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
62A0000
|
Size: |
65536
|
|
5460000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1368471292.0000000005460000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5460000
|
Size: |
28672
|
|
6100000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370609530.0000000006100000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6100000
|
Size: |
65536
|
|
2643000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1366487132.0000000002643000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2643000
|
Size: |
4096
|
|
904000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1366769635.0000000000904000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
904000
|
Size: |
4096
|
|
5FC9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384856831.0000000005FC9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FC9000
|
Size: |
28672
|
|
5920000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1388055084.0000000005920000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5920000
|
Size: |
65536
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394563208.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
20480
|
|
B25000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1372030893.0000000000B25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B25000
|
Size: |
12288
|
|
63F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1416513571.00000000063F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F0000
|
Size: |
61440
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393009005.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
65536
|
|
63F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1419614142.00000000063F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F0000
|
Size: |
16384
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393825750.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
6110000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1397602006.0000000006110000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6110000
|
Size: |
65536
|
|
2F8B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F8B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F8B000
|
Size: |
4096
|
|
5980000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391187054.0000000005980000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5980000
|
Size: |
12288
|
|
5FF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384733253.0000000005FF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FF0000
|
Size: |
65536
|
|
2AF7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1424889882.0000000002AF7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2AF7000
|
Size: |
4096
|
|
2BC0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1425182132.0000000002BC0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2BC0000
|
Size: |
4096
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1410705999.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
12288
|
|
5FF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371277552.0000000005FF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FF0000
|
Size: |
4096
|
|
6BB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1414154168.0000000006BB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6BB0000
|
Size: |
49152
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391011280.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
36864
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1403282191.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
8192
|
|
5950000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387846963.0000000005950000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5950000
|
Size: |
40960
|
|
6140000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370477120.0000000006140000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6140000
|
Size: |
65536
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1398358373.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
12288
|
|
300B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000300B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
300B000
|
Size: |
4096
|
|
2FDD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FDD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FDD000
|
Size: |
4096
|
|
6120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370542519.0000000006120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6120000
|
Size: |
65536
|
|
5910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386834278.0000000005910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5910000
|
Size: |
65536
|
|
6190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1413682780.0000000006190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6190000
|
Size: |
24576
|
|
33F5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033F5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33F5000
|
Size: |
4096
|
|
6190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1414965530.0000000006190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6190000
|
Size: |
40960
|
|
510000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.3663369097.0000000000510000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
510000
|
Size: |
4096
|
|
32FD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032FD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32FD000
|
Size: |
20480
|
|
6018000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1398521501.0000000006018000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6018000
|
Size: |
32768
|
|
3103000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003103000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3103000
|
Size: |
45056
|
|
60E0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1453635841.00000000060E0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
60E0000
|
Size: |
65536
|
|
33C1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033C1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33C1000
|
Size: |
4096
|
|
D00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1423012502.0000000000D00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
D00000
|
Size: |
8192
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1395098627.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
12288
|
|
3291000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003291000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3291000
|
Size: |
4096
|
|
662000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000000.1204469064.0000000000662000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
662000
|
Size: |
4096
|
|
4ECE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1445915952.0000000004ECE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4ECE000
|
Size: |
8192
|
|
5F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1378369819.0000000005F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F50000
|
Size: |
65536
|
|
5F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1377717866.0000000005F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F50000
|
Size: |
4096
|
|
6BC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1414046892.0000000006BC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6BC0000
|
Size: |
65536
|
|
2F42000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F42000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F42000
|
Size: |
16384
|
|
3005000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003005000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3005000
|
Size: |
12288
|
|
313C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000313C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
313C000
|
Size: |
4096
|
|
5920000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1388855973.0000000005920000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5920000
|
Size: |
36864
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384181405.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
65536
|
|
52EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1446116393.00000000052EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52EE000
|
Size: |
8192
|
|
30E5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030E5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30E5000
|
Size: |
4096
|
|
61B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383580900.00000000061B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
61B0000
|
Size: |
65536
|
|
5940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391723589.0000000005940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5940000
|
Size: |
53248
|
|
6BC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1415344664.0000000006BC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6BC0000
|
Size: |
24576
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1413557091.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
65536
|
|
300D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000300D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
300D000
|
Size: |
4096
|
|
2FE2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FE2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FE2000
|
Size: |
12288
|
|
314A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000314A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
314A000
|
Size: |
32768
|
|
6430000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1381063775.0000000006430000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6430000
|
Size: |
65536
|
|
5F30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1375878434.0000000005F30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F30000
|
Size: |
65536
|
|
5920000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386064341.0000000005920000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5920000
|
Size: |
65536
|
|
3251000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003251000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3251000
|
Size: |
4096
|
|
5940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393247848.0000000005940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5940000
|
Size: |
8192
|
|
5DC0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1449796846.0000000005DC0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
5DC0000
|
Size: |
1232896
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
31CE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031CE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31CE000
|
Size: |
4096
|
|
61A0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1454367302.00000000061A0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
61A0000
|
Size: |
65536
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1403799669.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
28672
|
|
6230000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383261000.0000000006230000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6230000
|
Size: |
65536
|
|
30DF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030DF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30DF000
|
Size: |
4096
|
|
3100000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003100000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3100000
|
Size: |
8192
|
|
30C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30C0000
|
Size: |
4096
|
|
6120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1410769639.0000000006120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6120000
|
Size: |
65536
|
|
5960000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1388500103.0000000005960000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5960000
|
Size: |
4096
|
|
2F26000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F26000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F26000
|
Size: |
4096
|
|
401000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000001.00000000.1204190187.0000000000401000.00000020.00000001.01000000.00000006.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
401000
|
Size: |
2416640
|
|
6260000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383119493.0000000006260000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6260000
|
Size: |
65536
|
|
33A4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033A4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33A4000
|
Size: |
4096
|
|
5F80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1373211212.0000000005F80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F80000
|
Size: |
65536
|
|
5F90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1373134735.0000000005F90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F90000
|
Size: |
65536
|
|
2F55000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F55000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F55000
|
Size: |
4096
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1402098959.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
36864
|
|
2FCB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FCB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FCB000
|
Size: |
36864
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394736333.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
31D2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031D2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31D2000
|
Size: |
4096
|
|
283F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1424586390.000000000283F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
283F000
|
Size: |
4096
|
|
3234000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003234000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3234000
|
Size: |
4096
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1396624976.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
16384
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1368705090.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
45056
|
|
5F00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371987278.0000000005F00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F00000
|
Size: |
65536
|
|
5910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386184368.0000000005910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5910000
|
Size: |
8192
|
|
287C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1424611747.000000000287C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
287C000
|
Size: |
16384
|
|
61D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1454456400.00000000061D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
61D2000
|
Size: |
28672
|
|
CFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1422981920.0000000000CFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CFE000
|
Size: |
8192
|
|
6BE0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1455328633.0000000006BE0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6BE0000
|
Size: |
65536
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000000.1204173981.0000000000400000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
5F40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1378038265.0000000005F40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F40000
|
Size: |
65536
|
|
6120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1409466109.0000000006120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6120000
|
Size: |
40960
|
|
3227000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003227000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3227000
|
Size: |
49152
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393680174.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
20480
|
|
5F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1373404538.0000000005F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F50000
|
Size: |
65536
|
|
6B90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1415893150.0000000006B90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6B90000
|
Size: |
36864
|
|
5960000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391288935.0000000005960000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5960000
|
Size: |
65536
|
|
2F91000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F91000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F91000
|
Size: |
94208
|
|
33C3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033C3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33C3000
|
Size: |
4096
|
|
2FF6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FF6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FF6000
|
Size: |
4096
|
|
5F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387643942.0000000005F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F50000
|
Size: |
65536
|
|
6290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383002357.0000000006290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6290000
|
Size: |
65536
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1397741603.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
65536
|
|
5910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1388335034.0000000005910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5910000
|
Size: |
65536
|
|
296E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3665335584.000000000296E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
296E000
|
Size: |
8192
|
|
5F70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385078639.0000000005F70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F70000
|
Size: |
65536
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1404756052.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
32768
|
|
63F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1416851848.00000000063F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F0000
|
Size: |
61440
|
|
32BA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032BA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32BA000
|
Size: |
4096
|
|
3278000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003278000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3278000
|
Size: |
24576
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385489185.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
65536
|
|
6120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1400754309.0000000006120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6120000
|
Size: |
12288
|
|
32F2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032F2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32F2000
|
Size: |
4096
|
|
32BE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032BE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32BE000
|
Size: |
4096
|
|
306E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000306E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
306E000
|
Size: |
20480
|
|
63E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1381759192.00000000063E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63E0000
|
Size: |
65536
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1396578675.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
20480
|
|
5C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664174646.00000000005C0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C0000
|
Size: |
4096
|
|
32C4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032C4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32C4000
|
Size: |
4096
|
|
30CF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030CF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30CF000
|
Size: |
28672
|
|
5910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387079053.0000000005910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5910000
|
Size: |
16384
|
|
6124000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1411368229.0000000006124000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6124000
|
Size: |
49152
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1403598792.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
65536
|
|
328B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000328B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
328B000
|
Size: |
4096
|
|
31D6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031D6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31D6000
|
Size: |
4096
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1399149215.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
16384
|
|
30C2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030C2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30C2000
|
Size: |
4096
|
|
5910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386980737.0000000005910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5910000
|
Size: |
65536
|
|
5FB8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384906426.0000000005FB8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FB8000
|
Size: |
32768
|
|
6410000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1455076994.0000000006410000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6410000
|
Size: |
131072
|
|
63B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1382416010.00000000063B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63B0000
|
Size: |
65536
|
|
511000
|
remote allocation
|
page execute read
|
|
|
|
Name: |
00000009.00000002.3663418210.0000000000511000.00000020.00000400.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute read
|
Base address: |
511000
|
Size: |
327680
|
|
33AA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033AA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33AA000
|
Size: |
57344
|
|
3003000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003003000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3003000
|
Size: |
4096
|
|
33FD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033FD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33FD000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393420860.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393454943.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393982925.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394701228.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
33DF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033DF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33DF000
|
Size: |
86016
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394918957.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
12288
|
|
2FC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FC0000
|
Size: |
4096
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394850806.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
20480
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1398088208.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
36864
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1402246436.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
61440
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1401892908.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
12288
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1405213069.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
45056
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386035492.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
28672
|
|
5940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387937371.0000000005940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5940000
|
Size: |
16384
|
|
3095000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003095000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3095000
|
Size: |
4096
|
|
5ACF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1448495901.0000000005ACF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5ACF000
|
Size: |
4096
|
|
5906000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1447808227.0000000005906000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5906000
|
Size: |
40960
|
|
3287000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003287000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3287000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1388681425.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
31BE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031BE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31BE000
|
Size: |
53248
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1396065364.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
16384
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1397971841.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
65536
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394176202.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
20480
|
|
30E7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030E7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30E7000
|
Size: |
40960
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393275381.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
3243000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003243000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3243000
|
Size: |
28672
|
|
3253000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003253000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3253000
|
Size: |
4096
|
|
31D8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031D8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31D8000
|
Size: |
4096
|
|
B0F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1372122851.0000000000B0F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B0F000
|
Size: |
24576
|
|
41B4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1389202545.00000000041B4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
41B4000
|
Size: |
3551232
|
|
5F70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1376919976.0000000005F70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F70000
|
Size: |
65536
|
|
540F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1446227406.000000000540F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
540F000
|
Size: |
4096
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1369373393.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
8192
|
|
5936000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1388681425.0000000005936000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5936000
|
Size: |
40960
|
|
32F4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032F4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32F4000
|
Size: |
12288
|
|
2FF8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FF8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FF8000
|
Size: |
4096
|
|
33A2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033A2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33A2000
|
Size: |
4096
|
|
320A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000320A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
320A000
|
Size: |
4096
|
|
6140000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1411247833.0000000006140000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6140000
|
Size: |
40960
|
|
594C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391381434.000000000594C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
594C000
|
Size: |
16384
|
|
2F5B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F5B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F5B000
|
Size: |
4096
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1404843407.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
65536
|
|
5F80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386420277.0000000005F80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F80000
|
Size: |
65536
|
|
3319000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003319000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3319000
|
Size: |
4096
|
|
5EFC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1451139783.0000000005EFC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5EFC000
|
Size: |
16384
|
|
5970000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391224663.0000000005970000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5970000
|
Size: |
65536
|
|
720000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664222750.0000000000720000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
720000
|
Size: |
8192
|
|
5FA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1372760444.0000000005FA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FA0000
|
Size: |
65536
|
|
595B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387846963.000000000595B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
595B000
|
Size: |
8192
|
|
2FF2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FF2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FF2000
|
Size: |
12288
|
|
5F30000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1451287131.0000000005F30000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5F30000
|
Size: |
28672
|
|
6070000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370961285.0000000006070000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6070000
|
Size: |
32768
|
|
5980000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1448384985.0000000005980000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5980000
|
Size: |
65536
|
|
6050000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371027609.0000000006050000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6050000
|
Size: |
65536
|
|
330F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000330F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
330F000
|
Size: |
24576
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1400259280.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
40960
|
|
60F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1453723716.00000000060F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60F0000
|
Size: |
65536
|
|
3115000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003115000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3115000
|
Size: |
4096
|
|
6020000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384612893.0000000006020000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6020000
|
Size: |
4096
|
|
5950000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386653516.0000000005950000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5950000
|
Size: |
65536
|
|
6002000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371180944.0000000006002000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6002000
|
Size: |
49152
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1368357099.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
16384
|
|
8E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1421244145.00000000008E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8E0000
|
Size: |
8192
|
|
5920000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385928609.0000000005920000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5920000
|
Size: |
65536
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1405354769.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
12288
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394768715.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
32768
|
|
2F38000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F38000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F38000
|
Size: |
4096
|
|
3091000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003091000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3091000
|
Size: |
4096
|
|
5950000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391334015.0000000005950000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5950000
|
Size: |
65536
|
|
5F40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1377293617.0000000005F40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F40000
|
Size: |
65536
|
|
3093000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003093000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3093000
|
Size: |
4096
|
|
321D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000321D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
321D000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394061947.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
609C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370892216.000000000609C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
609C000
|
Size: |
16384
|
|
2F40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F40000
|
Size: |
4096
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1397201663.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
20480
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1369290570.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
12288
|
|
31DD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031DD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31DD000
|
Size: |
36864
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393351870.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
5F40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1451386354.0000000005F40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F40000
|
Size: |
65536
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1368618734.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
24576
|
|
3165000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003165000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3165000
|
Size: |
4096
|
|
6190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1414825813.0000000006190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6190000
|
Size: |
49152
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1407253187.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
65536
|
|
5224000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1368010394.0000000005224000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5224000
|
Size: |
8192
|
|
5920000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1388279330.0000000005920000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5920000
|
Size: |
24576
|
|
6BB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1415395505.0000000006BB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6BB0000
|
Size: |
65536
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1394819111.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
16384
|
|
6200000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383387968.0000000006200000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6200000
|
Size: |
65536
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1401064903.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
45056
|
|
A4F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1421457365.0000000000A4F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A4F000
|
Size: |
4096
|
|
5F20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371896269.0000000005F20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F20000
|
Size: |
65536
|
|
5989000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386510450.0000000005989000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5989000
|
Size: |
28672
|
|
6020000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371142587.0000000006020000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6020000
|
Size: |
65536
|
|
6190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1454323172.0000000006190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6190000
|
Size: |
24576
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1398292111.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
16384
|
|
CC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1365275865.0000000000CC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
CC0000
|
Size: |
188416
|
|
2F05000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F05000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F05000
|
Size: |
4096
|
|
5220000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1368010394.0000000005220000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5220000
|
Size: |
12288
|
|
6400000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1454971544.0000000006400000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6400000
|
Size: |
53248
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1402057687.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
4096
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1396435549.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
16384
|
|
CBF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1422954602.0000000000CBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CBF000
|
Size: |
4096
|
|
31E7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031E7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31E7000
|
Size: |
4096
|
|
6060000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384448404.0000000006060000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6060000
|
Size: |
65536
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1400866827.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
65536
|
|
611D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383924924.000000000611D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
611D000
|
Size: |
4096
|
|
62F4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1382850946.00000000062F4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
62F4000
|
Size: |
49152
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1400670878.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
65536
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1397300693.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
36864
|
|
3163000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003163000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3163000
|
Size: |
4096
|
|
63F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1414455080.00000000063F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F0000
|
Size: |
65536
|
|
6BBD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1414154168.0000000006BBD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6BBD000
|
Size: |
12288
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386748888.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
61440
|
|
5210000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1445952672.0000000005210000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5210000
|
Size: |
65536
|
|
32E3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032E3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32E3000
|
Size: |
4096
|
|
33B9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033B9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33B9000
|
Size: |
4096
|
|
B15000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1372030893.0000000000B15000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B15000
|
Size: |
36864
|
|
3097000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003097000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3097000
|
Size: |
4096
|
|
63A0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1454615959.00000000063A0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
63A0000
|
Size: |
323584
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
5FE3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384770154.0000000005FE3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FE3000
|
Size: |
53248
|
|
6310000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1382780840.0000000006310000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6310000
|
Size: |
65536
|
|
31ED000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031ED000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31ED000
|
Size: |
4096
|
|
3303000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003303000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3303000
|
Size: |
20480
|
|
5460000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1446261458.0000000005460000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5460000
|
Size: |
65536
|
|
2F6A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F6A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F6A000
|
Size: |
12288
|
|
315B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000315B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
315B000
|
Size: |
4096
|
|
3204000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003204000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3204000
|
Size: |
12288
|
|
318F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000318F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
318F000
|
Size: |
4096
|
|
6280000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383038372.0000000006280000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6280000
|
Size: |
65536
|
|
2CC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425355515.0000000002CC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CC0000
|
Size: |
24576
|
|
2FA9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FA9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FA9000
|
Size: |
8192
|
|
57C000
|
remote allocation
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3664105276.000000000057C000.00000002.00000400.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page readonly
|
Base address: |
57C000
|
Size: |
24576
|
|
330B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000330B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
330B000
|
Size: |
4096
|
|
5940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391602211.0000000005940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5940000
|
Size: |
16384
|
|
904000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1366981654.0000000000904000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
904000
|
Size: |
4096
|
|
6020000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1452825527.0000000006020000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6020000
|
Size: |
65536
|
|
3059000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003059000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3059000
|
Size: |
4096
|
|
64F000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000001.00000000.1204429229.000000000064F000.00000008.00000001.01000000.00000006.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
64F000
|
Size: |
24576
|
|
2FBC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FBC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FBC000
|
Size: |
4096
|
|
325B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000325B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
325B000
|
Size: |
4096
|
|
5910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385822816.0000000005910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5910000
|
Size: |
65536
|
|
61C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383534257.00000000061C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
61C0000
|
Size: |
45056
|
|
5FE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384770154.0000000005FE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FE0000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393795229.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
2DCF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425421444.0000000002DCF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DCF000
|
Size: |
4096
|
|
5940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391060658.0000000005940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5940000
|
Size: |
49152
|
|
ABD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1421696171.0000000000ABD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ABD000
|
Size: |
405504
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1397932054.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
16384
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391971832.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
57344
|
|
5960000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1392747131.0000000005960000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5960000
|
Size: |
53248
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385902053.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
36864
|
|
3011000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003011000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3011000
|
Size: |
4096
|
|
5F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1377165473.0000000005F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F50000
|
Size: |
65536
|
|
5FE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371299265.0000000005FE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FE0000
|
Size: |
65536
|
|
2F53000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F53000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F53000
|
Size: |
4096
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1369318422.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
40960
|
|
335A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000335A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
335A000
|
Size: |
204800
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Contains functionality to start a terminal service |
Remote Access Functionality |
|
|
6125000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1410390523.0000000006125000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6125000
|
Size: |
45056
|
|
5985000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387685026.0000000005985000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5985000
|
Size: |
45056
|
|
3DD1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1442762830.0000000003DD1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3DD1000
|
Size: |
1040384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3063000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003063000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3063000
|
Size: |
4096
|
|
5FC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384856831.0000000005FC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FC0000
|
Size: |
32768
|
|
6120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1409270195.0000000006120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6120000
|
Size: |
16384
|
|
60E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384146186.00000000060E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60E0000
|
Size: |
65536
|
|
3309000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003309000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3309000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393584236.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
3351000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003351000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3351000
|
Size: |
4096
|
|
32C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32C0000
|
Size: |
4096
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370509843.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
65536
|
|
6380000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1382532333.0000000006380000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6380000
|
Size: |
65536
|
|
6110000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383924924.0000000006110000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6110000
|
Size: |
4096
|
|
2B10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1424939049.0000000002B10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B10000
|
Size: |
4096
|
|
3142000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003142000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3142000
|
Size: |
4096
|
|
D30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1423236821.0000000000D30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D30000
|
Size: |
16384
|
|
5F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371653196.0000000005F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F50000
|
Size: |
65536
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393911272.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
3053000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003053000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3053000
|
Size: |
20480
|
|
5F90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371504093.0000000005F90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F90000
|
Size: |
65536
|
|
561000
|
remote allocation
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3663908216.0000000000561000.00000002.00000400.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page readonly
|
Base address: |
561000
|
Size: |
81920
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Contains functionality to start a terminal service |
Remote Access Functionality |
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1400114026.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
12288
|
|
30D9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000030D9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30D9000
|
Size: |
4096
|
|
5F70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1373300837.0000000005F70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F70000
|
Size: |
65536
|
|
60B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384264386.00000000060B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60B0000
|
Size: |
65536
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393854537.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
16384
|
|
A70000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1421557229.0000000000A70000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
A70000
|
Size: |
4096
|
|
338D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000338D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
338D000
|
Size: |
57344
|
|
334B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000334B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
334B000
|
Size: |
4096
|
|
63F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1415194720.00000000063F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F0000
|
Size: |
36864
|
|
6120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1409337137.0000000006120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6120000
|
Size: |
45056
|
|
3293000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003293000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3293000
|
Size: |
69632
|
|
594E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1388584425.000000000594E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
594E000
|
Size: |
8192
|
|
5F40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1374144908.0000000005F40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F40000
|
Size: |
65536
|
|
52F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1446145409.00000000052F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
4096
|
|
3193000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003193000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3193000
|
Size: |
4096
|
|
33FF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033FF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33FF000
|
Size: |
4096
|
|
65D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1420918942.000000000065D000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
65D000
|
Size: |
8192
|
|
5FD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384822823.0000000005FD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FD0000
|
Size: |
61440
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1398458053.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
65536
|
|
6090000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384305478.0000000006090000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6090000
|
Size: |
4096
|
|
B21000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1421696171.0000000000B21000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B21000
|
Size: |
12288
|
|
6040000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371057704.0000000006040000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6040000
|
Size: |
65536
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1398138630.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
65536
|
|
612C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383924924.000000000612C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
612C000
|
Size: |
4096
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1411295239.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
65536
|
|
5FB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1372708495.0000000005FB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FB0000
|
Size: |
8192
|
|
60C4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1401892908.00000000060C4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C4000
|
Size: |
49152
|
|
2650000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1366487132.0000000002650000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2650000
|
Size: |
192512
|
|
32FA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032FA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32FA000
|
Size: |
4096
|
|
63F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1419499909.00000000063F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F0000
|
Size: |
32768
|
|
317C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000317C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
317C000
|
Size: |
20480
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1402178591.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
16384
|
|
3040000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003040000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3040000
|
Size: |
4096
|
|
2F72000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F72000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F72000
|
Size: |
4096
|
|
33BB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033BB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33BB000
|
Size: |
4096
|
|
33C6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033C6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33C6000
|
Size: |
53248
|
|
5B40000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1448519805.0000000005B40000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
5B40000
|
Size: |
1249280
|
|
2FAC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002FAC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FAC000
|
Size: |
45056
|
|
2AFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3665420185.0000000002AFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2AFE000
|
Size: |
8192
|
|
33BD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033BD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33BD000
|
Size: |
4096
|
|
2F3C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F3C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F3C000
|
Size: |
4096
|
|
324B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000324B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
324B000
|
Size: |
20480
|
|
2B20000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1424963083.0000000002B20000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2B20000
|
Size: |
65536
|
|
32BC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032BC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32BC000
|
Size: |
4096
|
|
2F47000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F47000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F47000
|
Size: |
36864
|
|
2F6E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F6E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F6E000
|
Size: |
12288
|
|
2AFB000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1424914857.0000000002AFB000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2AFB000
|
Size: |
4096
|
|
60CC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1401064903.00000000060CC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60CC000
|
Size: |
16384
|
|
3330000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003330000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3330000
|
Size: |
4096
|
|
5980000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1392609646.0000000005980000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5980000
|
Size: |
53248
|
|
3009000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003009000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3009000
|
Size: |
4096
|
|
2AE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1424736072.0000000002AE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AE0000
|
Size: |
4096
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1391484588.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
65536
|
|
3336000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003336000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3336000
|
Size: |
20480
|
|
33FB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033FB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33FB000
|
Size: |
4096
|
|
5F57000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1392358050.0000000005F57000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F57000
|
Size: |
36864
|
|
2F07000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F07000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F07000
|
Size: |
4096
|
|
612E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383924924.000000000612E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
612E000
|
Size: |
8192
|
|
6190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370322347.0000000006190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6190000
|
Size: |
57344
|
|
5920000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1388777473.0000000005920000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5920000
|
Size: |
65536
|
|
5940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1393766753.0000000005940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5940000
|
Size: |
8192
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1397810428.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
65536
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1369074314.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
4096
|
|
31EB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000031EB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31EB000
|
Size: |
4096
|
|
5960000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1385359918.0000000005960000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5960000
|
Size: |
65536
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1368654391.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
16384
|
|
3225000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003225000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3225000
|
Size: |
4096
|
|
D14000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1423099673.0000000000D14000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
D14000
|
Size: |
4096
|
|
33BF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000033BF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33BF000
|
Size: |
4096
|
|
334F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000334F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
334F000
|
Size: |
4096
|
|
3317000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003317000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3317000
|
Size: |
4096
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384663515.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
61440
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1396216657.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
28672
|
|
3FA7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1442762830.0000000003FA7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3FA7000
|
Size: |
831488
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
3061000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003061000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3061000
|
Size: |
4096
|
|
6170000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1370383223.0000000006170000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6170000
|
Size: |
65536
|
|
4099000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1442762830.0000000004099000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4099000
|
Size: |
393216
|
|
6080000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384360709.0000000006080000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6080000
|
Size: |
61440
|
|
57CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1447749462.00000000057CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
57CF000
|
Size: |
4096
|
|
52F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1369141093.00000000052F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52F0000
|
Size: |
8192
|
|
32DD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032DD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32DD000
|
Size: |
4096
|
|
311C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000311C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
311C000
|
Size: |
126976
|
|
2F36000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F36000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F36000
|
Size: |
4096
|
|
D13000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1423076343.0000000000D13000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
D13000
|
Size: |
4096
|
|
3401000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003401000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3401000
|
Size: |
4096
|
|
6270000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1383079716.0000000006270000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6270000
|
Size: |
65536
|
|
3099000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003099000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3099000
|
Size: |
4096
|
|
904000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1367227605.0000000000904000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
904000
|
Size: |
4096
|
|
3405000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003405000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3405000
|
Size: |
12288
|
|
60C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1399859359.00000000060C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60C0000
|
Size: |
65536
|
|
60D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1397655825.00000000060D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
65536
|
|
29AD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3665363432.00000000029AD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
29AD000
|
Size: |
12288
|
|
32DF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032DF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32DF000
|
Size: |
4096
|
|
2AF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1424839525.0000000002AF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AF0000
|
Size: |
4096
|
|
6016000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1396980387.0000000006016000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6016000
|
Size: |
16384
|
|
6B90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1415642954.0000000006B90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6B90000
|
Size: |
12288
|
|
325F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000325F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
325F000
|
Size: |
49152
|
|
2F74000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000002F74000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F74000
|
Size: |
4096
|
|
6010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1399548817.0000000006010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6010000
|
Size: |
28672
|
|
328F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000328F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
328F000
|
Size: |
4096
|
|
5FD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1371345519.0000000005FD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5FD0000
|
Size: |
65536
|
|
5F80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1378133794.0000000005F80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5F80000
|
Size: |
65536
|
|
2641000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1365189397.0000000002641000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2641000
|
Size: |
65536
|
|
3199000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003199000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3199000
|
Size: |
4096
|
|
315D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.000000000315D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
315D000
|
Size: |
4096
|
|
3182000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.0000000003182000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3182000
|
Size: |
16384
|
|
6015000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1396624976.0000000006015000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6015000
|
Size: |
12288
|
|
32DB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1425446365.00000000032DB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32DB000
|
Size: |
4096
|
|
8D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3664487750.00000000008D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D8000
|
Size: |
262144
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|