33F0000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.1583802234.00000000033F0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
33F0000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
400000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.1583402724.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
286720
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
5A00000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.1584252317.0000000005A00000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
5A00000
|
Size: |
9969664
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3000000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
0000000A.00000002.3680204431.0000000003000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3000000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3060000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
0000000A.00000002.3680275719.0000000003060000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3060000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
2950000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
0000000A.00000002.3678375316.0000000002950000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
2950000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
4310000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000009.00000002.3680107281.0000000004310000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
4310000
|
Size: |
9969664
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
4C40000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
0000000B.00000002.3682147563.0000000004C40000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4C40000
|
Size: |
454656
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
37E2000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680856702.00000000037E2000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
37E2000
|
Size: |
4096
|
|
C66B7FB000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1884752551.000000C66B7FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C66B7FB000
|
Size: |
20480
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773103534.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
37D1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1583834897.00000000037D1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
37D1000
|
Size: |
458752
|
|
2E17000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1475935490.0000000002E17000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E17000
|
Size: |
20480
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769139218.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
3B01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1552392277.0000000003B01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3B01000
|
Size: |
475136
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
750000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499726643.0000000000750000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
750000
|
Size: |
4096
|
|
3BF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229464446.0000000003BF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3BF0000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1478493300.0000000002C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C13000
|
Size: |
135168
|
|
5E30000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3684904695.0000000005E30000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5E30000
|
Size: |
4096
|
|
570000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3678619943.0000000000570000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
570000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770595832.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
560000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3678557761.0000000000560000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
560000
|
Size: |
4096
|
|
271DDC63000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1884959461.00000271DDC63000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
271DDC63000
|
Size: |
32768
|
|
730000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1499710964.0000000000730000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
730000
|
Size: |
16384
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770358706.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
320F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1583717295.000000000320F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
320F000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770641209.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
1DAB2000
|
system
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1883612234.000000001DAB2000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
1DAB2000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771228317.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
33A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1495766783.00000000033A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33A0000
|
Size: |
172032
|
|
3D19000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229464446.0000000003D19000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D19000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769349136.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770172649.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771701686.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
7E5B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3682968158.0000000007E5B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E5B000
|
Size: |
12288
|
|
680000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1665561994.0000000000680000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
680000
|
Size: |
16384
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771110614.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772330015.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667634936.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
2440000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3680170139.0000000002440000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2440000
|
Size: |
925696
|
|
2E1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1552329502.0000000002E1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E1A000
|
Size: |
479232
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3BF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1227138280.0000000003BF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3BF0000
|
Size: |
1196032
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667460947.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
3910000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.3680107281.0000000003910000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3910000
|
Size: |
10485760
|
|
83A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230067289.000000000083A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83A000
|
Size: |
24576
|
|
2C81000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1584194888.0000000002C81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C81000
|
Size: |
20480
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770405763.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
6D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499681232.00000000006D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6D0000
|
Size: |
20480
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769582155.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
6DA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665678803.00000000006DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6DA000
|
Size: |
8192
|
|
271DDC70000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1885096848.00000271DDC70000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
271DDC70000
|
Size: |
4096
|
|
1DB72000
|
system
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1883612234.000000001DB72000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
1DB72000
|
Size: |
4096
|
|
2E17000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1475874504.0000000002E17000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E17000
|
Size: |
20480
|
|
E26000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3679707363.0000000000E26000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
E26000
|
Size: |
8192
|
|
125D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1215555375.000000000125D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
125D000
|
Size: |
131072
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770617386.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
271DDB20000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.1884857689.00000271DDB20000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
271DDB20000
|
Size: |
421888
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769600054.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2F01000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1587177046.0000000002F01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F01000
|
Size: |
65536
|
|
3D8E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1225633384.0000000003D8E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D8E000
|
Size: |
24576
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769312527.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
48E2000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680856702.00000000048E2000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
48E2000
|
Size: |
8192
|
|
570000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1499602568.0000000000570000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
570000
|
Size: |
4096
|
|
E10000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1665780645.0000000000E10000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E10000
|
Size: |
4096
|
|
271DF711000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1885891309.00000271DF711000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
271DF711000
|
Size: |
28672
|
|
E41000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1665847588.0000000000E41000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E41000
|
Size: |
372736
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
DA0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3679804556.0000000000DA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA0000
|
Size: |
12288
|
|
291C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1583466514.000000000291C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
291C000
|
Size: |
16384
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667649197.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1587209872.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769983854.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1768348234.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
E11000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000009.00000000.1499853940.0000000000E11000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
E11000
|
Size: |
57344
|
|
63C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3682857389.00000000063C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63C0000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4CD7000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3682147563.0000000004CD7000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4CD7000
|
Size: |
8192
|
|
2410000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499960846.0000000002410000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2410000
|
Size: |
8192
|
|
5E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1665488462.00000000005E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5E0000
|
Size: |
4096
|
|
3629000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1583834897.0000000003629000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3629000
|
Size: |
4096
|
|
2D9F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680072839.0000000002D9F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D9F000
|
Size: |
4096
|
|
271DDC37000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1884959461.00000271DDC37000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
271DDC37000
|
Size: |
73728
|
|
2C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1491635461.0000000002C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C13000
|
Size: |
135168
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771274455.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
33BC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1586811304.00000000033BC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33BC000
|
Size: |
24576
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771089822.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
271DF8BE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1835338691.00000271DF8BE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
271DF8BE000
|
Size: |
12288
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780888615.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770130914.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
33D0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3680471129.00000000033D0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
33D0000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771018867.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770949356.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
B04000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1215013079.0000000000B04000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B04000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773200226.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2E05000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1475855463.0000000002E05000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E05000
|
Size: |
49152
|
|
43A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3678378722.000000000043A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
43A000
|
Size: |
24576
|
|
33A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1552370200.00000000033A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33A0000
|
Size: |
172032
|
|
970000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1499795920.0000000000970000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
970000
|
Size: |
36864
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772786334.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
420000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1665425803.0000000000420000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
420000
|
Size: |
4096
|
|
7E52000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780053354.0000000007E52000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E52000
|
Size: |
12288
|
|
2F00000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680172216.0000000002F00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F00000
|
Size: |
4096
|
|
2CC8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002CC8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CC8000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667881078.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
6B0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665595999.00000000006B0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6B0000
|
Size: |
4096
|
|
D70000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3679763815.0000000000D70000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
D70000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770451579.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
B17000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1230363632.0000000000B17000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B17000
|
Size: |
409600
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770773546.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
1213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1218624579.0000000001213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1213000
|
Size: |
114688
|
|
64E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665523075.000000000064E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
64E000
|
Size: |
8192
|
|
2C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1495862257.0000000002C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C13000
|
Size: |
69632
|
|
7E4A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3682968158.0000000007E4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E4A000
|
Size: |
8192
|
|
7E0D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1778179314.0000000007E0D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E0D000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3712000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3680471129.0000000003712000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3712000
|
Size: |
40960
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773843752.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667476598.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
410000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1665412897.0000000000410000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
410000
|
Size: |
4096
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772198368.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772377999.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2532000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680302788.0000000002532000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2532000
|
Size: |
4096
|
|
7E08000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1778179314.0000000007E08000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E08000
|
Size: |
4096
|
|
3223000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1475634337.0000000003223000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3223000
|
Size: |
507904
|
|
2E00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1583640095.0000000002E00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
45056
|
|
1213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230830581.0000000001213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1213000
|
Size: |
114688
|
|
2510000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.3680107281.0000000002510000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
2510000
|
Size: |
10485760
|
|
11E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1218624579.00000000011E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11E1000
|
Size: |
32768
|
|
6E01000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1584252317.0000000006E01000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
6E01000
|
Size: |
7405568
|
|
794000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1766506375.0000000000794000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
794000
|
Size: |
479232
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769941036.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
5000000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1584252317.0000000005000000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
5000000
|
Size: |
10485760
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772639568.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
53C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3678443435.000000000053C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
53C000
|
Size: |
16384
|
|
2918000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678305017.0000000002918000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2918000
|
Size: |
32768
|
|
2410000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3679912602.0000000002410000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2410000
|
Size: |
8192
|
|
7E30000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3682968158.0000000007E30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E30000
|
Size: |
8192
|
|
362D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1583834897.000000000362D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
362D000
|
Size: |
458752
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667426012.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
3722000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680856702.0000000003722000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3722000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770511137.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770969488.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773006695.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780663230.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
271DF801000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1886609615.00000271DF801000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
271DF801000
|
Size: |
4096
|
|
50BC000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680856702.00000000050BC000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
50BC000
|
Size: |
8192
|
|
264C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680302788.000000000264C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
264C000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667849117.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
234F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665886214.000000000234F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
234F000
|
Size: |
4096
|
|
29B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1583551250.00000000029B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29B0000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769218624.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
2D37000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002D37000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D37000
|
Size: |
12288
|
|
3184000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1583931638.0000000003184000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3184000
|
Size: |
512000
|
|
11E8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1224691010.00000000011E8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11E8000
|
Size: |
65536
|
|
5EA9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3684924393.0000000005EA9000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5EA9000
|
Size: |
4096
|
|
3100000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1475634337.0000000003100000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3100000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769762161.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773367554.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667769935.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
770000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3679144877.0000000000770000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
770000
|
Size: |
32768
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773081304.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772174564.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2D48000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002D48000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D48000
|
Size: |
16384
|
|
750000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3679081707.0000000000750000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
750000
|
Size: |
4096
|
|
383C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680856702.000000000383C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
383C000
|
Size: |
4096
|
|
3210000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1600166331.0000000003210000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3210000
|
Size: |
167936
|
|
B0E000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1215058420.0000000000B0E000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
B0E000
|
Size: |
8192
|
|
36A1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3680471129.00000000036A1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
36A1000
|
Size: |
458752
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771422579.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
3B76000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1552392277.0000000003B76000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3B76000
|
Size: |
12288
|
|
2C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1491464301.0000000002C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C13000
|
Size: |
69632
|
|
2D21000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002D21000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D21000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
845E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3683325966.000000000845E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
845E000
|
Size: |
8192
|
|
4D11000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.3680107281.0000000004D11000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
4D11000
|
Size: |
10485760
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769636125.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770817309.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
3A50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226945055.0000000003A50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A50000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772153052.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773274247.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
651000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3678976348.0000000000651000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
651000
|
Size: |
12288
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769547578.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2F01000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1594218323.0000000002F01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F01000
|
Size: |
229376
|
|
3160000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3680368325.0000000003160000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
3160000
|
Size: |
94208
|
|
3B73000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1225351651.0000000003B73000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B73000
|
Size: |
507904
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
3B73000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1227848432.0000000003B73000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B73000
|
Size: |
507904
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667900150.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
342D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1478111998.000000000342D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
342D000
|
Size: |
458752
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770429383.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2CE5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002CE5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CE5000
|
Size: |
12288
|
|
E26000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3679991946.0000000000E26000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
E26000
|
Size: |
8192
|
|
C66BFFD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1884795889.000000C66BFFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C66BFFD000
|
Size: |
12288
|
|
324E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1583734579.000000000324E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
324E000
|
Size: |
8192
|
|
550000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1499577232.0000000000550000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
550000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780926405.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
3B73000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226945055.0000000003B73000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B73000
|
Size: |
507904
|
|
2D0E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002D0E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D0E000
|
Size: |
16384
|
|
6399000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1584252317.0000000006399000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
6399000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769963178.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
3BF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226591334.0000000003BF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3BF0000
|
Size: |
1196032
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769193009.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
53C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499560540.000000000053C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
53C000
|
Size: |
16384
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770682480.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780768601.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769274215.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
34FD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3680471129.00000000034FD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
34FD000
|
Size: |
458752
|
|
3560000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680302788.0000000003560000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3560000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2440000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1665927231.0000000002440000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2440000
|
Size: |
925696
|
|
2420000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1499973645.0000000002420000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2420000
|
Size: |
925696
|
|
2D15000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002D15000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D15000
|
Size: |
20480
|
|
7E65000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3682968158.0000000007E65000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E65000
|
Size: |
12288
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773736784.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772861617.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
7E68000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780053354.0000000007E68000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E68000
|
Size: |
8192
|
|
2434000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680106249.0000000002434000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2434000
|
Size: |
4096
|
|
11FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1216558139.00000000011FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11FD000
|
Size: |
204800
|
|
3DE4000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680856702.0000000003DE4000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3DE4000
|
Size: |
4096
|
|
1233000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1224974617.0000000001233000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1233000
|
Size: |
4096
|
|
3BA8000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680302788.0000000003BA8000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3BA8000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769654506.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
3D1D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229464446.0000000003D1D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D1D000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769493990.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
125C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1215838501.000000000125C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
125C000
|
Size: |
638976
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667572452.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
1233000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1224691010.0000000001233000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1233000
|
Size: |
4096
|
|
2C7B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1584219047.0000000002C7B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C7B000
|
Size: |
24576
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771340282.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
3ECC000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680302788.0000000003ECC000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3ECC000
|
Size: |
8192
|
|
2CE0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002CE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CE0000
|
Size: |
12288
|
|
660000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3678775512.0000000000660000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
660000
|
Size: |
4096
|
|
3BF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1228024024.0000000003BF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3BF0000
|
Size: |
1196032
|
|
7DF6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1778179314.0000000007DF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7DF6000
|
Size: |
8192
|
|
99F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3679679185.000000000099F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
99F000
|
Size: |
4096
|
|
96F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499782287.000000000096F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
96F000
|
Size: |
4096
|
|
127C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1215629148.000000000127C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
127C000
|
Size: |
4096
|
|
DD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499812049.0000000000DD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DD4000
|
Size: |
4096
|
|
3884000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680302788.0000000003884000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3884000
|
Size: |
4096
|
|
7E6E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3682968158.0000000007E6E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E6E000
|
Size: |
61440
|
|
DA0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665768173.0000000000DA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA0000
|
Size: |
8192
|
|
6B1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1499657608.00000000006B1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6B1000
|
Size: |
12288
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773128874.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2532000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665999515.0000000002532000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2532000
|
Size: |
4096
|
|
2C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1496034722.0000000002C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C13000
|
Size: |
200704
|
|
11A8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230684292.00000000011A8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11A8000
|
Size: |
184320
|
|
3D8E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229464446.0000000003D8E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D8E000
|
Size: |
24576
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772571898.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
1050000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230590224.0000000001050000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1050000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772437974.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771633005.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
39FC000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680856702.00000000039FC000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
39FC000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1478380235.0000000002C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C13000
|
Size: |
69632
|
|
271DF600000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1885238931.00000271DF600000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
271DF600000
|
Size: |
4096
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770108933.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
DD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3679399257.0000000000DD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DD0000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770567407.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
E10000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1499840173.0000000000E10000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E10000
|
Size: |
4096
|
|
2C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1485584309.0000000002C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C13000
|
Size: |
237568
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772220243.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
3C00000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1584252317.0000000003C00000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3C00000
|
Size: |
10485760
|
|
E1F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3679656655.0000000000E1F000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E1F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2C70000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1584318601.0000000002C70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C70000
|
Size: |
28672
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772910623.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
349E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1478111998.000000000349E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
349E000
|
Size: |
24576
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667491360.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
28DB000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678176606.00000000028DB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
28DB000
|
Size: |
20480
|
|
1010000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230571089.0000000001010000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1010000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667801381.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769564778.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
6A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3679149589.00000000006A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A0000
|
Size: |
16384
|
|
E29000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1499896474.0000000000E29000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E29000
|
Size: |
61440
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771154962.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
3D8E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226591334.0000000003D8E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D8E000
|
Size: |
24576
|
|
1232000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1218624579.0000000001232000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1232000
|
Size: |
28672
|
|
4D98000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680856702.0000000004D98000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4D98000
|
Size: |
4096
|
|
2F01000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1614823572.0000000002F01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F01000
|
Size: |
229376
|
|
58C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3678496578.000000000058C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
58C000
|
Size: |
16384
|
|
2C72000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1584272513.0000000002C72000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C72000
|
Size: |
36864
|
|
E1F000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1665805087.0000000000E1F000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E1F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
5E31000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1766408850.0000000005E31000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5E31000
|
Size: |
471040
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
29E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678561452.00000000029E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29E0000
|
Size: |
4096
|
|
6D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3678967546.00000000006D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6D0000
|
Size: |
20480
|
|
2D42000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002D42000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D42000
|
Size: |
12288
|
|
6AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499645310.00000000006AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6AE000
|
Size: |
8192
|
|
7E60000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3682968158.0000000007E60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E60000
|
Size: |
12288
|
|
429A000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680856702.000000000429A000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
429A000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771469357.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769741581.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
ADF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1230279903.0000000000ADF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ADF000
|
Size: |
147456
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770253672.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2D3E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002D3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D3E000
|
Size: |
8192
|
|
6F9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3679396529.00000000006F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6F9000
|
Size: |
98304
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1478579113.0000000002C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C13000
|
Size: |
200704
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770234720.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
7E4C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780053354.0000000007E4C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E4C000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770214903.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
32CE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680445769.00000000032CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
32CE000
|
Size: |
8192
|
|
3D1D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1228024024.0000000003D1D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D1D000
|
Size: |
458752
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1768423679.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
2C60000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002C60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C60000
|
Size: |
36864
|
|
271DF8C4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1835338691.00000271DF8C4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
271DF8C4000
|
Size: |
24576
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667865839.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
1E174000
|
system
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1883612234.000000001E174000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
1E174000
|
Size: |
4096
|
|
420000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3678379251.0000000000420000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
420000
|
Size: |
4096
|
|
3D1D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1227594920.0000000003D1D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D1D000
|
Size: |
458752
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1665393586.0000000000400000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772886543.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769385826.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
271DF70B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1885891309.00000271DF70B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
271DF70B000
|
Size: |
4096
|
|
5EA5000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1766408850.0000000005EA5000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5EA5000
|
Size: |
12288
|
|
4CDA000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3682147563.0000000004CDA000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4CDA000
|
Size: |
4096
|
|
11E7000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1230783837.00000000011E7000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
11E7000
|
Size: |
4096
|
|
3D19000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1227594920.0000000003D19000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D19000
|
Size: |
4096
|
|
E26000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499881510.0000000000E26000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
E26000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771605065.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
6B0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3679275275.00000000006B0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6B0000
|
Size: |
4096
|
|
770000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499738531.0000000000770000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
770000
|
Size: |
32768
|
|
1170000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230616045.0000000001170000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1170000
|
Size: |
24576
|
|
2CF2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002CF2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CF2000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769420857.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770302430.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
B12000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1215058420.0000000000B12000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
B12000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770321626.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
271DDD50000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1885121292.00000271DDD50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
271DDD50000
|
Size: |
8192
|
|
2C6A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002C6A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C6A000
|
Size: |
28672
|
|
B0E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230342070.0000000000B0E000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B0E000
|
Size: |
36864
|
|
A51000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1214945515.0000000000A51000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
A51000
|
Size: |
581632
|
|
77E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499738531.000000000077E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77E000
|
Size: |
90112
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769293583.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667587312.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770704667.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
3347000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1586811304.0000000003347000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3347000
|
Size: |
4096
|
|
3B73000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1228280110.0000000003B73000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B73000
|
Size: |
507904
|
|
3D1D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1227138280.0000000003D1D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D1D000
|
Size: |
458752
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667678683.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
9A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3679718104.00000000009A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
9A0000
|
Size: |
36864
|
|
2C73000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002C73000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C73000
|
Size: |
90112
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2CFF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002CFF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CFF000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
2C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1478707080.0000000002C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C13000
|
Size: |
237568
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772527928.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
3BF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1227594920.0000000003BF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3BF0000
|
Size: |
1196032
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769846325.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
130E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1224647019.000000000130E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
130E000
|
Size: |
339968
|
|
2F01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1583680963.0000000002F01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F01000
|
Size: |
4096
|
|
3A50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1227423075.0000000003A50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A50000
|
Size: |
1187840
|
|
190000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1499500164.0000000000190000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
190000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770339238.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667663837.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770471355.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1496143898.0000000002C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C13000
|
Size: |
233472
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769458056.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
7E5F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780053354.0000000007E5F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E5F000
|
Size: |
8192
|
|
125C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230830581.000000000125C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
125C000
|
Size: |
638976
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667785634.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769475688.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
323C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680302788.000000000323C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
323C000
|
Size: |
4096
|
|
3D19000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1225633384.0000000003D19000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D19000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773432049.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
6B1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3678843589.00000000006B1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6B1000
|
Size: |
12288
|
|
2D0B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002D0B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D0B000
|
Size: |
4096
|
|
3300000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1478111998.0000000003300000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3300000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7EF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3683287252.0000000007EF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7EF0000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769158601.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
4A74000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680856702.0000000004A74000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4A74000
|
Size: |
4096
|
|
11C4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1215670939.00000000011C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11C4000
|
Size: |
53248
|
|
280C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680302788.000000000280C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
280C000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
E10000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3679525578.0000000000E10000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E10000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769864046.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771183865.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2C3E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678631080.0000000002C3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C3E000
|
Size: |
8192
|
|
4CBB000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3682147563.0000000004CBB000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4CBB000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
970000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3679335850.0000000000970000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
970000
|
Size: |
36864
|
|
2D86000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680302788.0000000002D86000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2D86000
|
Size: |
8192
|
|
11E8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1216589908.00000000011E8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11E8000
|
Size: |
86016
|
|
E41000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1499912475.0000000000E41000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E41000
|
Size: |
372736
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1614898190.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
29E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1583567065.00000000029E0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29E0000
|
Size: |
4096
|
|
7E35000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3682968158.0000000007E35000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E35000
|
Size: |
4096
|
|
33A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1491365083.00000000033A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33A0000
|
Size: |
172032
|
|
E41000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3679803968.0000000000E41000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E41000
|
Size: |
372736
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
7E71000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780053354.0000000007E71000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E71000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772713997.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
3D19000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226591334.0000000003D19000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D19000
|
Size: |
4096
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680145781.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
211000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3678150168.0000000000211000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
211000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770152431.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
280C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665999515.000000000280C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
280C000
|
Size: |
53248
|
|
36F2000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680302788.00000000036F2000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
36F2000
|
Size: |
8192
|
|
2CBD000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002CBD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CBD000
|
Size: |
4096
|
|
1A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3678272419.00000000001A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A0000
|
Size: |
4096
|
|
C66CFFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1884837817.000000C66CFFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C66CFFE000
|
Size: |
8192
|
|
A51000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.1230223944.0000000000A51000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
A51000
|
Size: |
581632
|
|
6A6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3679149589.00000000006A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A6000
|
Size: |
8192
|
|
3D1D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1225633384.0000000003D1D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D1D000
|
Size: |
458752
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770277891.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769690325.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
48A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3678440944.000000000048A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
48A000
|
Size: |
24576
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780849164.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2C7B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1584148223.0000000002C7B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C7B000
|
Size: |
45056
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1768493767.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
2420000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3679950501.0000000002420000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2420000
|
Size: |
925696
|
|
1DBCC000
|
system
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1883612234.000000001DBCC000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
1DBCC000
|
Size: |
4096
|
|
7EE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3683268667.0000000007EE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7EE0000
|
Size: |
4096
|
|
9AD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230120264.00000000009AD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9AD000
|
Size: |
12288
|
|
E11000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000009.00000002.3679593469.0000000000E11000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
E11000
|
Size: |
57344
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770530344.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
9ED000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230146266.00000000009ED000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9ED000
|
Size: |
12288
|
|
3700000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1231064140.0000000003700000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3700000
|
Size: |
8192
|
|
2D52000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002D52000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D52000
|
Size: |
53248
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772762405.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
1233000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230830581.0000000001233000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1233000
|
Size: |
4096
|
|
3F76000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680856702.0000000003F76000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3F76000
|
Size: |
8192
|
|
6C0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3678916672.00000000006C0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6C0000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769921561.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769672511.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
64E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3678916123.000000000064E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
64E000
|
Size: |
8192
|
|
5EA9000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000003.1766408850.0000000005EA9000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5EA9000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770549012.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
651000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1665535384.0000000000651000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
651000
|
Size: |
12288
|
|
660000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3679027645.0000000000660000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
660000
|
Size: |
4096
|
|
6DE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665678803.00000000006DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6DE000
|
Size: |
90112
|
|
F4F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230434908.0000000000F4F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F4F000
|
Size: |
4096
|
|
550000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3678497865.0000000000550000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
550000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771068034.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
4600000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1584252317.0000000004600000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4600000
|
Size: |
10485760
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771292400.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
1228000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1215769886.0000000001228000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1228000
|
Size: |
851968
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772549922.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
4F2A000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680856702.0000000004F2A000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4F2A000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
328E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680422105.000000000328E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
328E000
|
Size: |
8192
|
|
34F9000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3680471129.00000000034F9000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
34F9000
|
Size: |
4096
|
|
7E0B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3682968158.0000000007E0B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E0B000
|
Size: |
8192
|
|
7E2B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3682968158.0000000007E2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E2B000
|
Size: |
8192
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771583865.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
3A50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1227848432.0000000003A50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A50000
|
Size: |
1187840
|
|
3BF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1225633384.0000000003BF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3BF0000
|
Size: |
1196032
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667519324.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
7E76000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780053354.0000000007E76000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E76000
|
Size: |
12288
|
|
F5B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230434908.0000000000F5B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F5B000
|
Size: |
20480
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772459302.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772737155.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
660000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499632434.0000000000660000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
660000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771365732.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
5711000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.3680107281.0000000005711000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
5711000
|
Size: |
7405568
|
|
6DE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3679396529.00000000006DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6DE000
|
Size: |
94208
|
|
6C0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499669031.00000000006C0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6C0000
|
Size: |
4096
|
|
C66C7FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1884818107.000000C66C7FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C66C7FE000
|
Size: |
8192
|
|
3B73000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1227423075.0000000003B73000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B73000
|
Size: |
507904
|
|
7E13000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1778179314.0000000007E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E13000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769528482.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
560000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1499588838.0000000000560000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
560000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769438817.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
143360
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771250552.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
7E7C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780053354.0000000007E7C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E7C000
|
Size: |
4096
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771044478.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771318566.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2C70000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1584148223.0000000002C70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C70000
|
Size: |
28672
|
|
271DF8CE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1835321864.00000271DF8CE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
271DF8CE000
|
Size: |
4096
|
|
77A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3679144877.000000000077A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77A000
|
Size: |
8192
|
|
2990000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1583533221.0000000002990000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2990000
|
Size: |
4096
|
|
3B73000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226128909.0000000003B73000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B73000
|
Size: |
507904
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1594335534.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
1213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1219189834.0000000001213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1213000
|
Size: |
114688
|
|
B04000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1230279903.0000000000B04000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B04000
|
Size: |
40960
|
|
2CDE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002CDE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CDE000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772595007.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
E11000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000B.00000000.1665791945.0000000000E11000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
E11000
|
Size: |
57344
|
|
1D9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1231004164.0000000001D9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1D9E000
|
Size: |
8192
|
|
11D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1215670939.00000000011D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11D3000
|
Size: |
565248
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1614964656.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
4750000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680856702.0000000004750000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4750000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2E05000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1475917109.0000000002E05000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E05000
|
Size: |
49152
|
|
1233000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1219095990.0000000001233000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1233000
|
Size: |
131072
|
|
3D8E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1227138280.0000000003D8E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D8E000
|
Size: |
24576
|
|
29F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1583584869.00000000029F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29F0000
|
Size: |
4096
|
|
11DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230684292.00000000011DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11DC000
|
Size: |
16384
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1594486217.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773028709.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
7E06000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3682968158.0000000007E06000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E06000
|
Size: |
8192
|
|
7DF3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3682968158.0000000007DF3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7DF3000
|
Size: |
12288
|
|
1DD8C000
|
system
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1883612234.000000001DD8C000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
1DD8C000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3D3A000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680302788.0000000003D3A000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3D3A000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
11EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1218624579.00000000011EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11EE000
|
Size: |
114688
|
|
199E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230980992.000000000199E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
199E000
|
Size: |
8192
|
|
3050000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680251339.0000000003050000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3050000
|
Size: |
16384
|
|
3A50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1225351651.0000000003A50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A50000
|
Size: |
1187840
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772478523.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
11A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230684292.00000000011A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11A0000
|
Size: |
24576
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667445439.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
7E0F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3682968158.0000000007E0F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E0F000
|
Size: |
12288
|
|
271DDB93000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.1884857689.00000271DDB93000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
271DDB93000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769116114.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772290590.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
7E63000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780053354.0000000007E63000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E63000
|
Size: |
4096
|
|
4CB2000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3682147563.0000000004CB2000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4CB2000
|
Size: |
8192
|
|
6401000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1584252317.0000000006401000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
6401000
|
Size: |
10485760
|
|
600000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665511947.0000000000600000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
600000
|
Size: |
4096
|
|
43A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499547771.000000000043A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
43A000
|
Size: |
24576
|
|
730000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3679026131.0000000000730000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
730000
|
Size: |
16384
|
|
11E0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1230783837.00000000011E0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
11E0000
|
Size: |
16384
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769252903.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
30B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680320545.00000000030B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30B0000
|
Size: |
94208
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667533305.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
3D19000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1227138280.0000000003D19000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D19000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770192063.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
4D2E000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3682147563.0000000004D2E000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4D2E000
|
Size: |
225280
|
|
369D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3680471129.000000000369D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
369D000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772079737.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
7E01000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1778179314.0000000007E01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E01000
|
Size: |
4096
|
|
3D8E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1228024024.0000000003D8E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D8E000
|
Size: |
24576
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771656763.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
442C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680856702.000000000442C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
442C000
|
Size: |
4096
|
|
410000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3678329850.0000000000410000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
410000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772617654.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
7DE3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773617426.0000000007DE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7DE3000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
72E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499696772.000000000072E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
72E000
|
Size: |
8192
|
|
30AA000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680302788.00000000030AA000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
30AA000
|
Size: |
4096
|
|
600000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3678828909.0000000000600000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
600000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769331213.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
271DDC60000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1884959461.00000271DDC60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
271DDC60000
|
Size: |
4096
|
|
DEC000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3679846903.0000000000DEC000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
DEC000
|
Size: |
16384
|
|
271DF8AF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1835373450.00000271DF8AF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
271DF8AF000
|
Size: |
8192
|
|
2CCD000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002CCD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CCD000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770749370.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772691939.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773053031.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2C02000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1583601955.0000000002C02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C02000
|
Size: |
20480
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770491747.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
271DDC5C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1884959461.00000271DDC5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
271DDC5C000
|
Size: |
4096
|
|
25F2000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680302788.00000000025F2000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
25F2000
|
Size: |
4096
|
|
271DDC30000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1884959461.00000271DDC30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
271DDC30000
|
Size: |
24576
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770380367.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
9F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230178601.00000000009F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9F0000
|
Size: |
4096
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770793284.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
4CB0000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3682147563.0000000004CB0000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4CB0000
|
Size: |
4096
|
|
3000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1593425079.0000000003000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3000000
|
Size: |
167936
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772397947.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667619713.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
77E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3679144877.000000000077E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77E000
|
Size: |
90112
|
|
2F18000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680302788.0000000002F18000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2F18000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1224691010.0000000001213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1213000
|
Size: |
114688
|
|
125C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1224691010.000000000125C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
125C000
|
Size: |
638976
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
580000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3678694069.0000000000580000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
580000
|
Size: |
4096
|
|
E1F000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3679966020.0000000000E1F000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E1F000
|
Size: |
28672
|
|
6DA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3679396529.00000000006DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6DA000
|
Size: |
8192
|
|
3210000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1605035484.0000000003210000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3210000
|
Size: |
167936
|
|
77A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499738531.000000000077A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77A000
|
Size: |
8192
|
|
271DF721000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1885891309.00000271DF721000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
271DF721000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667919027.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
2C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1491746640.0000000002C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C13000
|
Size: |
200704
|
|
271DF70F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1885891309.00000271DF70F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
271DF70F000
|
Size: |
4096
|
|
4CCB000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3682147563.0000000004CCB000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4CCB000
|
Size: |
4096
|
|
3842000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1583834897.0000000003842000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3842000
|
Size: |
40960
|
|
E26000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665818212.0000000000E26000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
E26000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772309988.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
7E6E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780053354.0000000007E6E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E6E000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773220992.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
369E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1583834897.000000000369E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
369E000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
DD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499812049.0000000000DD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DD0000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769511098.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1768403065.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
DD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3679399257.0000000000DD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DD4000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773296855.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769881888.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
125C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1224974617.000000000125C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
125C000
|
Size: |
638976
|
|
271DDB96000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.1884857689.00000271DDB96000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
271DDB96000
|
Size: |
4096
|
|
48A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665440608.000000000048A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
48A000
|
Size: |
24576
|
|
2BF4000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680302788.0000000002BF4000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2BF4000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772836964.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
271DF800000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1834835337.00000271DF800000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
271DF800000
|
Size: |
4096
|
|
3540000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1231024341.0000000003540000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3540000
|
Size: |
290816
|
|
295B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1583513073.000000000295B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
295B000
|
Size: |
20480
|
|
1233000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1218731916.0000000001233000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1233000
|
Size: |
24576
|
|
58C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665453664.000000000058C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
58C000
|
Size: |
16384
|
|
ADF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1215013079.0000000000ADF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ADF000
|
Size: |
147456
|
|
660000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665548822.0000000000660000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
660000
|
Size: |
4096
|
|
9A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1665735553.00000000009A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
9A0000
|
Size: |
36864
|
|
271DF560000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1834298785.00000271DF560000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
271DF560000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772239896.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
F7C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230434908.0000000000F7C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F7C000
|
Size: |
16384
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773245208.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2C7B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1584318601.0000000002C7B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C7B000
|
Size: |
45056
|
|
30D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1484811235.00000000030D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
30D0000
|
Size: |
172032
|
|
3A16000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680302788.0000000003A16000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3A16000
|
Size: |
4096
|
|
1232000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1219189834.0000000001232000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1232000
|
Size: |
4096
|
|
3704000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1231064140.0000000003704000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3704000
|
Size: |
8192
|
|
E11000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000B.00000002.3679929598.0000000000E11000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
E11000
|
Size: |
57344
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3678273389.0000000000400000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
5F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3678775614.00000000005F0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F0000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769714941.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770660806.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
E29000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3679754378.0000000000E29000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E29000
|
Size: |
61440
|
|
3D19000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1228024024.0000000003D19000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D19000
|
Size: |
4096
|
|
334E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1583752612.000000000334E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
334E000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773152710.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
80D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3683305436.00000000080D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
80D0000
|
Size: |
4096
|
|
271DF550000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1885209737.00000271DF550000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
271DF550000
|
Size: |
12288
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769782443.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
6C0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3679332960.00000000006C0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6C0000
|
Size: |
12288
|
|
3A50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1228280110.0000000003A50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A50000
|
Size: |
1187840
|
|
A50000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1230201110.0000000000A50000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A50000
|
Size: |
4096
|
|
2C81000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1584358963.0000000002C81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C81000
|
Size: |
20480
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772810576.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
29D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678499600.00000000029D0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29D0000
|
Size: |
4096
|
|
6D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665678803.00000000006D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6D0000
|
Size: |
32768
|
|
849F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3683347628.000000000849F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
849F000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772983461.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
3500000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1583834897.0000000003500000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3500000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
5E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3678705678.00000000005E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5E0000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772418642.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
7DFB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1778179314.0000000007DFB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7DFB000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770990919.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
271DF700000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1885275512.00000271DF700000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
271DF700000
|
Size: |
4096
|
|
2C00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1583601955.0000000002C00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C00000
|
Size: |
4096
|
|
E29000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1665831840.0000000000E29000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E29000
|
Size: |
61440
|
|
2E12000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1583660570.0000000002E12000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E12000
|
Size: |
32768
|
|
2CDB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002CDB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CDB000
|
Size: |
4096
|
|
E41000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3680042767.0000000000E41000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E41000
|
Size: |
372736
|
|
271DF530000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1885140456.00000271DF530000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
271DF530000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667605447.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
A50000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1214931004.0000000000A50000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A50000
|
Size: |
4096
|
|
11D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1215583651.00000000011D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11D3000
|
Size: |
565248
|
|
2C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1495945331.0000000002C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C13000
|
Size: |
135168
|
|
3350000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1583770226.0000000003350000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3350000
|
Size: |
274432
|
|
310E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1583700157.000000000310E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
310E000
|
Size: |
8192
|
|
271DF703000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1885891309.00000271DF703000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
271DF703000
|
Size: |
16384
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667832314.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
45BE000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680856702.00000000045BE000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
45BE000
|
Size: |
4096
|
|
5C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1665466199.00000000005C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5C0000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771553826.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
1B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3678327896.00000000001B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1B0000
|
Size: |
4096
|
|
234F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499949561.000000000234F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
234F000
|
Size: |
4096
|
|
7E13000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3682968158.0000000007E13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E13000
|
Size: |
24576
|
|
2C7B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1584389957.0000000002C7B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C7B000
|
Size: |
24576
|
|
7E6C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780053354.0000000007E6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E6C000
|
Size: |
4096
|
|
2C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1485386633.0000000002C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C13000
|
Size: |
135168
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771442792.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
6D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3679396529.00000000006D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6D0000
|
Size: |
32768
|
|
3A01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1584195902.0000000003A01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3A01000
|
Size: |
8192
|
|
D6E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665752320.0000000000D6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D6E000
|
Size: |
8192
|
|
4CA9000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.3680107281.0000000004CA9000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
4CA9000
|
Size: |
4096
|
|
4C06000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680856702.0000000004C06000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4C06000
|
Size: |
4096
|
|
6A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665577312.00000000006A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A0000
|
Size: |
20480
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771517244.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772955139.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
334B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1586811304.000000000334B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
334B000
|
Size: |
458752
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667554824.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
2D05000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002D05000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D05000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667505528.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
E1F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1499867370.0000000000E1F000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E1F000
|
Size: |
28672
|
|
2C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1491902696.0000000002C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C13000
|
Size: |
233472
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1594390022.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
2430000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680106249.0000000002430000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2430000
|
Size: |
8192
|
|
5C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3678562519.00000000005C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5C0000
|
Size: |
4096
|
|
271DDC4C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1884959461.00000271DDC4C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
271DDC4C000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
3B00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1584219059.0000000003B00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3B00000
|
Size: |
4096
|
|
11E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1216525219.00000000011E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11E1000
|
Size: |
98304
|
|
2C77000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1584294188.0000000002C77000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C77000
|
Size: |
20480
|
|
2C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1485294461.0000000002C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C13000
|
Size: |
69632
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769828253.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2430000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665900154.0000000002430000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2430000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1770074770.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769900941.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
356E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3680471129.000000000356E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
356E000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772270366.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
37CD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1583834897.00000000037CD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
37CD000
|
Size: |
4096
|
|
E10000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3679887862.0000000000E10000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E10000
|
Size: |
4096
|
|
321E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1586811304.000000000321E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
321E000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
5D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3678627402.00000000005D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5D0000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780952780.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
99F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665723828.000000000099F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
99F000
|
Size: |
4096
|
|
7E59000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780053354.0000000007E59000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E59000
|
Size: |
4096
|
|
33CE000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3680302788.00000000033CE000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
33CE000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772931510.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
3D8E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1227594920.0000000003D8E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D8E000
|
Size: |
24576
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1768846109.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
271DF560000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1834344305.00000271DF560000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
271DF560000
|
Size: |
4096
|
|
2C13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1485476082.0000000002C13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C13000
|
Size: |
200704
|
|
5D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1665477227.00000000005D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5D0000
|
Size: |
4096
|
|
4E6C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3682390068.0000000004E6C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4E6C000
|
Size: |
16384
|
|
12F9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230957617.00000000012F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12F9000
|
Size: |
86016
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1780725124.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1773179306.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771206513.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769367416.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667817204.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
3061000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1583931638.0000000003061000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3061000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
890000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230094417.0000000000890000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
890000
|
Size: |
4096
|
|
1A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1499518537.00000000001A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A0000
|
Size: |
4096
|
|
3D1D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226591334.0000000003D1D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D1D000
|
Size: |
458752
|
|
2D4B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1778362374.0000000002D4B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D4B000
|
Size: |
69632
|
|
F3F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1230434908.0000000000F3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F3F000
|
Size: |
4096
|
|
680000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3679090277.0000000000680000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
680000
|
Size: |
16384
|
|
2CB5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3678707228.0000000002CB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CB5000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7E25000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3682968158.0000000007E25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E25000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1768442192.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
4096
|
|
2DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771495711.0000000002DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA5000
|
Size: |
4096
|
|
3A50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226128909.0000000003A50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A50000
|
Size: |
1187840
|
|
3429000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.1478111998.0000000003429000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3429000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772504494.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
1B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1499534532.00000000001B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1B0000
|
Size: |
4096
|
|
11D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1215838501.00000000011D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11D5000
|
Size: |
339968
|
|
B17000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1215101533.0000000000B17000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B17000
|
Size: |
409600
|
|
190000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3678177697.0000000000190000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
190000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772018127.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
580000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1499617109.0000000000580000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
580000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769810662.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
3210000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1667986717.0000000003210000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3210000
|
Size: |
167936
|
|
2434000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665900154.0000000002434000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2434000
|
Size: |
4096
|
|
125C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1219095990.000000000125C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
125C000
|
Size: |
638976
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771678209.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2F10000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.3680107281.0000000002F10000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
2F10000
|
Size: |
10485760
|
|
E29000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3680020228.0000000000E29000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E29000
|
Size: |
61440
|
|
4108000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680856702.0000000004108000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4108000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1771398315.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
5F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1665499457.00000000005F0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F0000
|
Size: |
4096
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769618760.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3680104272.0000000002DA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA0000
|
Size: |
16384
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1769403316.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|
2DA4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1772665775.0000000002DA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DA4000
|
Size: |
8192
|
|