2C20000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
0000000B.00000002.2480573811.0000000002C20000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
2C20000
|
Size: |
5902336
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3230000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
0000000C.00000002.2477977050.0000000003230000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
3230000
|
Size: |
278528
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
7FE0000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1977517644.0000000007FE0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
7FE0000
|
Size: |
278528
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3FA0000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1974135087.0000000003FA0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3FA0000
|
Size: |
5902336
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
36E0000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
0000000C.00000002.2480569793.00000000036E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36E0000
|
Size: |
278528
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
400000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1973374982.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
290816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
D90000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
0000000D.00000002.2479760210.0000000000D90000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
D90000
|
Size: |
520192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3730000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
0000000C.00000002.2480693049.0000000003730000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3730000
|
Size: |
278528
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
1E9F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249785313.0000000001E9F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1E9F000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154723331.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
812E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2163218248.000000000812E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
812E000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
40B3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236411873.00000000040B3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40B3000
|
Size: |
507904
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153689390.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
7B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.2046631517.00000000007B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7B0000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050706748.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
FB0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.2048084314.0000000000FB0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
FB0000
|
Size: |
4096
|
|
1749000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226754273.0000000001749000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1749000
|
Size: |
585728
|
|
3377000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2164331811.0000000003377000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3377000
|
Size: |
16384
|
|
3D72000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2481556246.0000000003D72000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3D72000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2151266572.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
C90000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.2048030581.0000000000C90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C90000
|
Size: |
32768
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153729015.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152816242.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
F50000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2478926888.0000000000F50000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F50000
|
Size: |
16384
|
|
4130000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1233270608.0000000004130000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4130000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1890678798.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
135168
|
|
3F90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236411873.0000000003F90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F90000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
87BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483925342.00000000087BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
87BE000
|
Size: |
8192
|
|
8220000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483734059.0000000008220000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8220000
|
Size: |
4096
|
|
13CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249519579.00000000013CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13CF000
|
Size: |
4096
|
|
1710000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1896843764.0000000001710000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1710000
|
Size: |
364544
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154839874.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2155439096.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
1381000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2480988705.0000000001381000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1381000
|
Size: |
360448
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
3C40000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.2480573811.0000000003C40000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3C40000
|
Size: |
10485760
|
|
998000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2478532669.0000000000998000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
998000
|
Size: |
4096
|
|
3D2D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1973737395.0000000003D2D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3D2D000
|
Size: |
458752
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154017989.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
1FA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249817478.0000000001FA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1FA0000
|
Size: |
4096
|
|
3AFE000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.2480956841.0000000003AFE000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3AFE000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154341473.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153552950.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2163007745.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
AA0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2477970936.0000000000AA0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AA0000
|
Size: |
4096
|
|
35C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2480425973.00000000035C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C0000
|
Size: |
4096
|
|
14D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249587671.00000000014D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14D0000
|
Size: |
20480
|
|
891F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2484063856.000000000891F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
891F000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153071382.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153048576.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153000777.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
8141000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483382696.0000000008141000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8141000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154811700.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2173242948.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
174A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222363025.000000000174A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
174A000
|
Size: |
131072
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1893682878.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
208896
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2157324793.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
361B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1941555692.000000000361B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
361B000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
25202F81000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000E.00000002.2277153493.0000025202F81000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
25202F81000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2157191303.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
40B3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1234071411.00000000040B3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40B3000
|
Size: |
507904
|
|
7F2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1221776368.00000000007F2000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7F2000
|
Size: |
8192
|
|
F4E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2480496139.0000000000F4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F4E000
|
Size: |
8192
|
|
42CE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236584479.00000000042CE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42CE000
|
Size: |
24576
|
|
77A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.2046602401.000000000077A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
77A000
|
Size: |
24576
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2160764839.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
E1B000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2479760210.0000000000E1B000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
E1B000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
F80000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2479100838.0000000000F80000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
F80000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154221600.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
3ED1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1973737395.0000000003ED1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3ED1000
|
Size: |
458752
|
|
3605000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1880761940.0000000003605000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3605000
|
Size: |
49152
|
|
FD9000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2480913444.0000000000FD9000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FD9000
|
Size: |
61440
|
|
3313000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1974161994.0000000003313000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3313000
|
Size: |
20480
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2157246470.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
1724000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222582703.0000000001724000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1724000
|
Size: |
737280
|
|
4259000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1233722510.0000000004259000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4259000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2161557361.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
3332000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2164208325.0000000003332000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3332000
|
Size: |
131072
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153457806.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152576526.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
33DF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.00000000033DF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33DF000
|
Size: |
61440
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2157412222.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2173330321.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050652983.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
700000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2477837500.0000000000700000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
700000
|
Size: |
4096
|
|
FF0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2480949154.0000000000FF0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FF0000
|
Size: |
36864
|
|
32D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478311592.00000000032D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32D0000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2160284483.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
3C40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249909811.0000000003C40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3C40000
|
Size: |
8192
|
|
4374000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2481556246.0000000004374000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4374000
|
Size: |
4096
|
|
425D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1233270608.000000000425D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
425D000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
4130000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236584479.0000000004130000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4130000
|
Size: |
1196032
|
|
3302000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1974010695.0000000003302000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3302000
|
Size: |
24576
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2173211410.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
335D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2164331811.000000000335D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
335D000
|
Size: |
4096
|
|
2B20000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2480150177.0000000002B20000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2B20000
|
Size: |
925696
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154915614.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050543549.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
170A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226811201.000000000170A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
170A000
|
Size: |
4096
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1890747153.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
200704
|
|
10BA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1896726206.00000000010BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10BA000
|
Size: |
8192
|
|
EFC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2478843198.0000000000EFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EFC000
|
Size: |
16384
|
|
FC1000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000D.00000002.2480784780.0000000000FC1000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FC1000
|
Size: |
57344
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152139928.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
3A00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1882227177.0000000003A00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3A00000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
16FB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226811201.00000000016FB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16FB000
|
Size: |
57344
|
|
25204ECE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.2227451065.0000025204ECE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
25204ECE000
|
Size: |
4096
|
|
3ECD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1973737395.0000000003ECD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3ECD000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2161825073.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
8148000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483382696.0000000008148000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8148000
|
Size: |
4096
|
|
FCF000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2479293448.0000000000FCF000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FCF000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
33C0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1890531004.00000000033C0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33C0000
|
Size: |
151552
|
|
FCF000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2480847853.0000000000FCF000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FCF000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
B0A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1896231744.0000000000B0A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B0A000
|
Size: |
24576
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152872256.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
2F72000
|
system
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2275649544.0000000002F72000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
2F72000
|
Size: |
8192
|
|
4259000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1232828153.0000000004259000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4259000
|
Size: |
4096
|
|
25202F84000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000E.00000002.2277153493.0000025202F84000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
25202F84000
|
Size: |
4096
|
|
33B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.00000000033B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33B0000
|
Size: |
40960
|
|
32B4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981522238.00000000032B4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32B4000
|
Size: |
4096
|
|
842F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483872257.000000000842F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
842F000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2156052281.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2162188721.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2151155773.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
252030C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277346551.00000252030C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
252030C0000
|
Size: |
32768
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2162890826.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
4130000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1233722510.0000000004130000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4130000
|
Size: |
1196032
|
|
16DB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249666426.00000000016DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16DB000
|
Size: |
65536
|
|
3362000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2164179895.0000000003362000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3362000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152417671.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050603535.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
731000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1221648969.0000000000731000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
731000
|
Size: |
581632
|
|
3400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1973598857.0000000003400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3400000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2162105361.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
252030F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277346551.00000252030F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
252030F0000
|
Size: |
4096
|
|
339C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.000000000339C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
339C000
|
Size: |
16384
|
|
FD9000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.2048143507.0000000000FD9000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FD9000
|
Size: |
61440
|
|
3D29000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1973737395.0000000003D29000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3D29000
|
Size: |
4096
|
|
3304000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1974111651.0000000003304000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3304000
|
Size: |
36864
|
|
35CF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1973800098.00000000035CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35CF000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3304000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.0000000003304000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3304000
|
Size: |
81920
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153093885.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2163409965.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
40B3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1232685826.00000000040B3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40B3000
|
Size: |
507904
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050241563.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2049990560.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050163341.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2163062520.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152330454.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
FC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.2048095796.0000000000FC0000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FC0000
|
Size: |
4096
|
|
3200000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1973502262.0000000003200000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3200000
|
Size: |
4096
|
|
335D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.000000000335D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
335D000
|
Size: |
4096
|
|
C50000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2479232751.0000000000C50000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
C50000
|
Size: |
12288
|
|
330D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1974070837.000000000330D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
330D000
|
Size: |
24576
|
|
690E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483271202.000000000690E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
690E000
|
Size: |
8192
|
|
28BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2481181856.00000000028BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
28BE000
|
Size: |
8192
|
|
33C5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.00000000033C5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33C5000
|
Size: |
8192
|
|
FD6000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1896654491.0000000000FD6000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
FD6000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152540153.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
4259000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1233270608.0000000004259000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4259000
|
Size: |
4096
|
|
3574000
|
system
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2275649544.0000000003574000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
3574000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153333084.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152974395.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
3313000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1973990871.0000000003313000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3313000
|
Size: |
20480
|
|
3624000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1941649900.0000000003624000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3624000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152920903.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
BF6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2478995700.0000000000BF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BF6000
|
Size: |
8192
|
|
4259000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1234254451.0000000004259000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4259000
|
Size: |
4096
|
|
8172000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2172625705.0000000008172000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8172000
|
Size: |
4096
|
|
36C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2480495699.00000000036C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
36C0000
|
Size: |
4096
|
|
AFC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2478778600.0000000000AFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AFC000
|
Size: |
16384
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2173148131.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154386299.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
3402000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1973598857.0000000003402000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3402000
|
Size: |
20480
|
|
2BFC000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.2048307666.0000000002BFC000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2BFC000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3B9E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1882227177.0000000003B9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3B9E000
|
Size: |
24576
|
|
B90000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2478538747.0000000000B90000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B90000
|
Size: |
4096
|
|
33C0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1941602283.00000000033C0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33C0000
|
Size: |
151552
|
|
13DB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249519579.00000000013DB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13DB000
|
Size: |
20480
|
|
3B2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1882227177.0000000003B2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3B2D000
|
Size: |
458752
|
|
2790000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2481047792.0000000002790000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2790000
|
Size: |
925696
|
|
63C0000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1974135087.00000000063C0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
63C0000
|
Size: |
4599808
|
|
13BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249519579.00000000013BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13BF000
|
Size: |
4096
|
|
10B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1896726206.00000000010B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10B0000
|
Size: |
32768
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2157154579.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153192565.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1893413219.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
69632
|
|
7D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2478292795.00000000007D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7D0000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153651517.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
1FD0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249849423.0000000001FD0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
1FD0000
|
Size: |
290816
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154081338.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154408721.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
2FF8000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2477883848.0000000002FF8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FF8000
|
Size: |
32768
|
|
1828000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249768291.0000000001828000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1828000
|
Size: |
4096
|
|
A80000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2477776349.0000000000A80000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A80000
|
Size: |
4096
|
|
C9E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2479373273.0000000000C9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9E000
|
Size: |
94208
|
|
A90000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2477880428.0000000000A90000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A90000
|
Size: |
4096
|
|
3250000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1973532859.0000000003250000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3250000
|
Size: |
4096
|
|
3600000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1973628662.0000000003600000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3600000
|
Size: |
45056
|
|
6650000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483130862.0000000006650000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6650000
|
Size: |
4096
|
|
4130000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1247330086.0000000004130000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4130000
|
Size: |
1196032
|
|
2BFC000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2481319174.0000000002BFC000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2BFC000
|
Size: |
53248
|
|
3F8C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2481556246.0000000003F8C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3F8C000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
425D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236584479.000000000425D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
425D000
|
Size: |
458752
|
|
B60000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1896307195.0000000000B60000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B60000
|
Size: |
4096
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1890832243.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
208896
|
|
14E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249606440.00000000014E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14E0000
|
Size: |
4096
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1893478968.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
135168
|
|
59AF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2482863513.00000000059AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59AF000
|
Size: |
4096
|
|
7F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2478459188.00000000007F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7F0000
|
Size: |
4096
|
|
40B3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1237331720.00000000040B3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40B3000
|
Size: |
507904
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154197578.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1883016443.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
208896
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2157074186.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
32C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478222129.00000000032C0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32C0000
|
Size: |
4096
|
|
3D9E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1973737395.0000000003D9E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3D9E000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3399000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.0000000003399000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3399000
|
Size: |
4096
|
|
33D5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.00000000033D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33D5000
|
Size: |
36864
|
|
730000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1249132960.0000000000730000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
730000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1976820330.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
65536
|
|
3370000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2164331811.0000000003370000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3370000
|
Size: |
16384
|
|
7E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2478375599.00000000007E0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E0000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153217001.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
425D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1233722510.000000000425D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
425D000
|
Size: |
458752
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2162982894.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
16FB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1248735991.00000000016FB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16FB000
|
Size: |
57344
|
|
1749000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1223235698.0000000001749000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1749000
|
Size: |
917504
|
|
3176000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2481319174.0000000003176000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3176000
|
Size: |
8192
|
|
33BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1973583472.00000000033BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33BE000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2155800992.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2162935757.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
2C14000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1897091075.0000000002C14000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C14000
|
Size: |
4096
|
|
2790000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.2048202447.0000000002790000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2790000
|
Size: |
925696
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2162812581.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
4640000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.2480573811.0000000004640000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
4640000
|
Size: |
10485760
|
|
10BA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2479552228.00000000010BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10BA000
|
Size: |
8192
|
|
3389000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2166874902.0000000003389000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3389000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2162426025.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
3605000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1880687457.0000000003605000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3605000
|
Size: |
49152
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050735387.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2159554335.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
FB0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2480689079.0000000000FB0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
FB0000
|
Size: |
4096
|
|
FCF000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.2048120390.0000000000FCF000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FCF000
|
Size: |
28672
|
|
3612000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1973644593.0000000003612000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3612000
|
Size: |
24576
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2160405762.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
28D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.2048274849.00000000028D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28D0000
|
Size: |
8192
|
|
3850000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.2480893342.0000000003850000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
3850000
|
Size: |
94208
|
|
2910000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2481282460.0000000002910000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2910000
|
Size: |
12288
|
|
3F90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1233583373.0000000003F90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F90000
|
Size: |
1187840
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2162866955.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
E8D000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2479760210.0000000000E8D000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
E8D000
|
Size: |
241664
|
|
2F8C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1973436783.0000000002F8C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F8C000
|
Size: |
16384
|
|
252030CA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277346551.00000252030CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
252030CA000
|
Size: |
61440
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2161869813.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
10BE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1896726206.00000000010BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10BE000
|
Size: |
94208
|
|
25204B20000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277496825.0000025204B20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25204B20000
|
Size: |
12288
|
|
7F7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1221801565.00000000007F7000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7F7000
|
Size: |
401408
|
|
7E4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1249309933.00000000007E4000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7E4000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050124313.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153491155.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050377332.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2162465137.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
2FCC000
|
system
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2275649544.0000000002FCC000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
2FCC000
|
Size: |
4096
|
|
3DCC000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2481556246.0000000003DCC000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3DCC000
|
Size: |
8192
|
|
3F90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1233135933.0000000003F90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F90000
|
Size: |
1187840
|
|
BE1000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1896404865.0000000000BE1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BE1000
|
Size: |
12288
|
|
4130000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1234254451.0000000004130000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4130000
|
Size: |
1196032
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152843657.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
87FF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483953435.00000000087FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
87FF000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2162958886.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
252030F3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277346551.00000252030F3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
252030F3000
|
Size: |
28672
|
|
F50000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1896487891.0000000000F50000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F50000
|
Size: |
16384
|
|
7F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.2047435443.00000000007F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7F0000
|
Size: |
4096
|
|
1749000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249718205.0000000001749000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1749000
|
Size: |
585728
|
|
3F42000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1973737395.0000000003F42000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3F42000
|
Size: |
40960
|
|
3617000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1880795283.0000000003617000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3617000
|
Size: |
20480
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2151312258.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
3C31000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.2480956841.0000000003C31000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3C31000
|
Size: |
458752
|
|
3384000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.0000000003384000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3384000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
FD6000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2479377558.0000000000FD6000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
FD6000
|
Size: |
8192
|
|
815E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2172625705.000000000815E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
815E000
|
Size: |
20480
|
|
3C44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249909811.0000000003C44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3C44000
|
Size: |
8192
|
|
16FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1223235698.00000000016FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16FC000
|
Size: |
131072
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1882795316.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
135168
|
|
338E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2166874902.000000000338E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
338E000
|
Size: |
12288
|
|
3377000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.0000000003377000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3377000
|
Size: |
16384
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153991357.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
A90000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1896180094.0000000000A90000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A90000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2162031339.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
7C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.2046715133.00000000007C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7C0000
|
Size: |
4096
|
|
33C0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1893243488.00000000033C0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33C0000
|
Size: |
151552
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2151669839.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
38FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1973689638.00000000038FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
38FF000
|
Size: |
4096
|
|
7D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.2047285695.00000000007D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7D0000
|
Size: |
4096
|
|
83AD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483816174.00000000083AD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83AD000
|
Size: |
12288
|
|
394C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1976565386.000000000394C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
394C000
|
Size: |
24576
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154363693.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
FC1000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000D.00000000.2048107162.0000000000FC1000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FC1000
|
Size: |
57344
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2158633823.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
318C000
|
system
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2275649544.000000000318C000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
318C000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
25204D00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277554371.0000025204D00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
25204D00000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154451473.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2161694454.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
7BF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1221738999.00000000007BF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7BF000
|
Size: |
147456
|
|
330D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1974010695.000000000330D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
330D000
|
Size: |
24576
|
|
E2B000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2479760210.0000000000E2B000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
E2B000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050682975.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
36C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1980811483.00000000036C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
36C0000
|
Size: |
147456
|
|
C9A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2479373273.0000000000C9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9A000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153584336.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
361A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1941633539.000000000361A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
361A000
|
Size: |
4096
|
|
3340000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1886353097.0000000003340000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3340000
|
Size: |
147456
|
|
FD6000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2480876349.0000000000FD6000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
FD6000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2161614751.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2161992879.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153862121.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
E12000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2479760210.0000000000E12000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
E12000
|
Size: |
4096
|
|
814E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483382696.000000000814E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
814E000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2161916068.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1886662148.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
69632
|
|
170A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1248735991.000000000170A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
170A000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2162066031.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
5040000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.2480573811.0000000005040000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
5040000
|
Size: |
4599808
|
|
10E8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2479552228.00000000010E8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10E8000
|
Size: |
20480
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981638782.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
42CE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1233270608.00000000042CE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42CE000
|
Size: |
24576
|
|
38DB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1976565386.00000000038DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
38DB000
|
Size: |
458752
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152746532.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
F8E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2480564086.0000000000F8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F8E000
|
Size: |
8192
|
|
730000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1221632856.0000000000730000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
730000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2155079783.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
25204C00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277526214.0000025204C00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
25204C00000
|
Size: |
4096
|
|
42CE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1232828153.00000000042CE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42CE000
|
Size: |
24576
|
|
7EE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249400575.00000000007EE000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7EE000
|
Size: |
36864
|
|
B50000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2478220864.0000000000B50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B50000
|
Size: |
20480
|
|
F70000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1896514238.0000000000F70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F70000
|
Size: |
8192
|
|
586F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2482779222.000000000586F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
586F000
|
Size: |
4096
|
|
40B3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1233135933.00000000040B3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40B3000
|
Size: |
507904
|
|
88DE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2484034965.00000000088DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
88DE000
|
Size: |
8192
|
|
A80000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1896087916.0000000000A80000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A80000
|
Size: |
4096
|
|
3B29000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1882227177.0000000003B29000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3B29000
|
Size: |
4096
|
|
B50000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1896281995.0000000000B50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B50000
|
Size: |
20480
|
|
6F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2477712468.00000000006F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6F0000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2155905862.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
336D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.000000000336D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
336D000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153141983.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
37AE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1976565386.00000000037AE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
37AE000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2151354468.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
2A3C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2481319174.0000000002A3C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2A3C000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154115467.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
3CA2000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.2480956841.0000000003CA2000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3CA2000
|
Size: |
40960
|
|
45C0000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1974135087.00000000045C0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
45C0000
|
Size: |
10485760
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2161780991.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
2C10000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1897091075.0000000002C10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C10000
|
Size: |
8192
|
|
4FC0000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1974135087.0000000004FC0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4FC0000
|
Size: |
10485760
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050303587.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2155964074.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
700000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.2046191455.0000000000700000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
700000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2162913570.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152475335.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
38D7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1976565386.00000000038D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
38D7000
|
Size: |
4096
|
|
25203040000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277296061.0000025203040000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25203040000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152374535.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
3A89000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.2480956841.0000000003A89000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3A89000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152504633.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
32B4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1976845034.00000000032B4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32B4000
|
Size: |
4096
|
|
BD1000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.2047990939.0000000000BD1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BD1000
|
Size: |
12288
|
|
E37000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2479760210.0000000000E37000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
E37000
|
Size: |
12288
|
|
336D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2164331811.000000000336D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
336D000
|
Size: |
4096
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1890613080.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
69632
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152709569.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
28D4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2481212332.00000000028D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28D4000
|
Size: |
4096
|
|
330D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1974244202.000000000330D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
330D000
|
Size: |
24576
|
|
33CB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.00000000033CB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33CB000
|
Size: |
8192
|
|
7E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.2047309414.00000000007E0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7E0000
|
Size: |
4096
|
|
FC1000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000B.00000000.1896584256.0000000000FC1000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FC1000
|
Size: |
57344
|
|
8159000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2172625705.0000000008159000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8159000
|
Size: |
4096
|
|
32B4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981543714.00000000032B4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32B4000
|
Size: |
4096
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1886913366.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
208896
|
|
3220000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1973518727.0000000003220000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3220000
|
Size: |
4096
|
|
8169000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483382696.0000000008169000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8169000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2160140409.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
16D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222655895.00000000016D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16D4000
|
Size: |
327680
|
|
816E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483382696.000000000816E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
816E000
|
Size: |
8192
|
|
FD6000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.2048132274.0000000000FD6000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
FD6000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2151938720.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
816B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2172625705.000000000816B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
816B000
|
Size: |
4096
|
|
3900000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1985520430.0000000003900000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3900000
|
Size: |
147456
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2161957716.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
59C0000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1974135087.00000000059C0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
59C0000
|
Size: |
10485760
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2161737229.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
3CB2000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2481556246.0000000003CB2000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3CB2000
|
Size: |
4096
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1882647625.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
69632
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154748671.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
25203020000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277260269.0000025203020000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25203020000
|
Size: |
4096
|
|
FC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1896560105.0000000000FC0000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FC0000
|
Size: |
4096
|
|
BE1000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2478711765.0000000000BE1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BE1000
|
Size: |
12288
|
|
FC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2479151846.0000000000FC0000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FC0000
|
Size: |
4096
|
|
3370000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.0000000003370000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3370000
|
Size: |
16384
|
|
16EB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1223517244.00000000016EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16EB000
|
Size: |
69632
|
|
B70000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2478382491.0000000000B70000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B70000
|
Size: |
4096
|
|
425D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1232828153.000000000425D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
425D000
|
Size: |
458752
|
|
42CE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1234254451.00000000042CE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42CE000
|
Size: |
24576
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050479008.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050016510.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
EE05DFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277094784.000000EE05DFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EE05DFE000
|
Size: |
8192
|
|
2FBB000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2477791948.0000000002FBB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FBB000
|
Size: |
20480
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2161393775.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
3302000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1974180647.0000000003302000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3302000
|
Size: |
24576
|
|
1380000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2479926635.0000000001380000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1380000
|
Size: |
36864
|
|
BF0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1896431086.0000000000BF0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
BF0000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153284759.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
1749000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222655895.0000000001749000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1749000
|
Size: |
585728
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154978586.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
353E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2480245288.000000000353E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
353E000
|
Size: |
8192
|
|
1EDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249801332.0000000001EDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1EDE000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152671035.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
33CF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.00000000033CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33CF000
|
Size: |
16384
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2162360207.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
2EB2000
|
system
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2275649544.0000000002EB2000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
2EB2000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050411374.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
3701000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1973674631.0000000003701000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3701000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152034183.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
6F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.2046130018.00000000006F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6F0000
|
Size: |
4096
|
|
992000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2478532669.0000000000992000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
992000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2160610467.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2157541101.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
3309000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1974131300.0000000003309000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3309000
|
Size: |
20480
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2151981961.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153907689.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154773138.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154496275.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
2FE4000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2481319174.0000000002FE4000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2FE4000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152194833.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
25204E01000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277740032.0000025204E01000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
25204E01000
|
Size: |
4096
|
|
25204EAE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.2227496176.0000025204EAE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
25204EAE000
|
Size: |
4096
|
|
887F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2484007752.000000000887F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
887F000
|
Size: |
4096
|
|
425D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1234254451.000000000425D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
425D000
|
Size: |
458752
|
|
883E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483980456.000000000883E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
883E000
|
Size: |
8192
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1882931985.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
196608
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2161653672.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
2050000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249880631.0000000002050000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2050000
|
Size: |
8192
|
|
2922000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.2048307666.0000000002922000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2922000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2160716834.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
425D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1247330086.000000000425D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
425D000
|
Size: |
458752
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152782749.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050092375.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154164484.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
EE065FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277130213.000000EE065FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EE065FE000
|
Size: |
8192
|
|
3384000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2164331811.0000000003384000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3384000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
BD1000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2478849362.0000000000BD1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BD1000
|
Size: |
12288
|
|
3F90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1234071411.0000000003F90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F90000
|
Size: |
1187840
|
|
C3E000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2479153605.0000000000C3E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
C3E000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153262430.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
8430000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483898278.0000000008430000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8430000
|
Size: |
4096
|
|
EE04DFC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2276989040.000000EE04DFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EE04DFC000
|
Size: |
16384
|
|
10B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2479552228.00000000010B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10B0000
|
Size: |
32768
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050506165.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
77A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2478042113.000000000077A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
77A000
|
Size: |
24576
|
|
1769000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222448483.0000000001769000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1769000
|
Size: |
4096
|
|
16A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249625651.00000000016A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16A0000
|
Size: |
24576
|
|
25203070000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277322000.0000025203070000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25203070000
|
Size: |
4096
|
|
3617000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1880717983.0000000003617000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3617000
|
Size: |
20480
|
|
4557000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1974135087.0000000004557000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4557000
|
Size: |
4096
|
|
16F9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1223537513.00000000016F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16F9000
|
Size: |
12288
|
|
BF0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2478995700.0000000000BF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BF0000
|
Size: |
16384
|
|
330D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1974218292.000000000330D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
330D000
|
Size: |
24576
|
|
1380000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.2048170108.0000000001380000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1380000
|
Size: |
364544
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2162293462.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
3C00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1973737395.0000000003C00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3C00000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2155215409.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
1711000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2480003790.0000000001711000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1711000
|
Size: |
360448
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2155045718.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
4130000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1232828153.0000000004130000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4130000
|
Size: |
1196032
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152287719.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
252030DC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277346551.00000252030DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
252030DC000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152613098.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
16A8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249625651.00000000016A8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16A8000
|
Size: |
180224
|
|
8230000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483760826.0000000008230000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8230000
|
Size: |
4096
|
|
B80000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2478464422.0000000000B80000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B80000
|
Size: |
4096
|
|
32B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478128493.00000000032B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32B0000
|
Size: |
16384
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153309403.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
F90000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.2048071239.0000000000F90000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F90000
|
Size: |
16384
|
|
335E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2164179895.000000000335E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
335E000
|
Size: |
4096
|
|
E10000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.2479760210.0000000000E10000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
E10000
|
Size: |
4096
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1893587992.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
200704
|
|
3F50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1974092468.0000000003F50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F50000
|
Size: |
278528
|
|
25204D03000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277579793.0000025204D03000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
25204D03000
|
Size: |
16384
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2151426255.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2173270965.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
B90000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1896382752.0000000000B90000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B90000
|
Size: |
4096
|
|
3320000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.0000000003320000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3320000
|
Size: |
204800
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
FF0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.2048157139.0000000000FF0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FF0000
|
Size: |
36864
|
|
B40000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1896257712.0000000000B40000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B40000
|
Size: |
4096
|
|
C9A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.2048030581.0000000000C9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9A000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050569086.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
25204D15000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277579793.0000025204D15000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
25204D15000
|
Size: |
12288
|
|
7F7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1249419421.00000000007F7000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7F7000
|
Size: |
401408
|
|
25204D0F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277579793.0000025204D0F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
25204D0F000
|
Size: |
20480
|
|
330D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1974050902.000000000330D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
330D000
|
Size: |
24576
|
|
42CE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1247330086.00000000042CE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42CE000
|
Size: |
24576
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2049887338.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
AA0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1896204839.0000000000AA0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AA0000
|
Size: |
4096
|
|
8146000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483382696.0000000008146000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8146000
|
Size: |
4096
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1886738850.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
135168
|
|
3790000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2480782117.0000000003790000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3790000
|
Size: |
16384
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154880653.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
836C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483789420.000000000836C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
836C000
|
Size: |
16384
|
|
7C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2478215691.00000000007C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7C0000
|
Size: |
4096
|
|
16C3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222483615.00000000016C3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16C3000
|
Size: |
40960
|
|
2C10000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2480427076.0000000002C10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C10000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153167150.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
3F90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1237331720.0000000003F90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F90000
|
Size: |
1187840
|
|
522C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2482704135.000000000522C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
522C000
|
Size: |
16384
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2163549406.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
DB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249482822.0000000000DB0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DB0000
|
Size: |
4096
|
|
512F000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2482653712.000000000512F000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
512F000
|
Size: |
4096
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1886817228.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
196608
|
|
16D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222483615.00000000016D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16D2000
|
Size: |
491520
|
|
B70000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1896330725.0000000000B70000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B70000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2049845923.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
2B20000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1896924429.0000000002B20000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2B20000
|
Size: |
925696
|
|
7EE000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1221776368.00000000007EE000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7EE000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152445912.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
16FB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249685986.00000000016FB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16FB000
|
Size: |
57344
|
|
170A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249685986.000000000170A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
170A000
|
Size: |
4096
|
|
BF0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2478780785.0000000000BF0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
BF0000
|
Size: |
4096
|
|
3F90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1232685826.0000000003F90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F90000
|
Size: |
1187840
|
|
532F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2482731060.000000000532F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
532F000
|
Size: |
4096
|
|
710000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2477953255.0000000000710000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
710000
|
Size: |
4096
|
|
813C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483382696.000000000813C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
813C000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050772628.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
F0C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2480424498.0000000000F0C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F0C000
|
Size: |
16384
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1995093665.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
204800
|
|
83EE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483844437.00000000083EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83EE000
|
Size: |
8192
|
|
29E2000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2481319174.00000000029E2000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
29E2000
|
Size: |
8192
|
|
28D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2481212332.00000000028D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28D0000
|
Size: |
8192
|
|
694E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483325224.000000000694E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
694E000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2160335425.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
3800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1880417121.0000000003800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3800000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
13FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249519579.00000000013FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13FD000
|
Size: |
12288
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050208174.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
7B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2478124684.00000000007B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7B0000
|
Size: |
4096
|
|
EFC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1896459664.0000000000EFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EFC000
|
Size: |
16384
|
|
B60000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2478307939.0000000000B60000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B60000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154648485.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
C9E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.2048030581.0000000000C9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9E000
|
Size: |
94208
|
|
8172000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483382696.0000000008172000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8172000
|
Size: |
16384
|
|
D4A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249461553.0000000000D4A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
24576
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2161506237.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
33BB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.00000000033BB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33BB000
|
Size: |
16384
|
|
7BF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1249309933.00000000007BF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7BF000
|
Size: |
147456
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050343760.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050039710.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2162151437.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
362E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1941649900.000000000362E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
362E000
|
Size: |
12288
|
|
28D4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.2048274849.00000000028D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28D4000
|
Size: |
4096
|
|
7E4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1221738999.00000000007E4000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7E4000
|
Size: |
40960
|
|
252030EC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277346551.00000252030EC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
252030EC000
|
Size: |
4096
|
|
3900000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050874803.0000000003900000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3900000
|
Size: |
147456
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2162495980.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
B40000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2478143306.0000000000B40000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B40000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2173299742.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
AFC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.2047604489.0000000000AFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AFC000
|
Size: |
16384
|
|
16EB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1248735991.00000000016EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16EB000
|
Size: |
24576
|
|
EE055FD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277043282.000000EE055FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EE055FD000
|
Size: |
12288
|
|
817C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483382696.000000000817C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
817C000
|
Size: |
20480
|
|
16DB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1248811285.00000000016DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16DB000
|
Size: |
65536
|
|
2C14000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2480427076.0000000002C14000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C14000
|
Size: |
4096
|
|
37A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2480832276.00000000037A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
37A0000
|
Size: |
94208
|
|
1380000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1896812791.0000000001380000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1380000
|
Size: |
36864
|
|
31D7000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.2480573811.00000000031D7000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
31D7000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152948348.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154140108.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1995163263.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
25204970000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.2226267985.0000025204970000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
25204970000
|
Size: |
4096
|
|
B0A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2478064102.0000000000B0A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B0A000
|
Size: |
24576
|
|
2910000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.2048297016.0000000002910000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2910000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153619363.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
3900000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1990431581.0000000003900000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3900000
|
Size: |
147456
|
|
BE0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2478926828.0000000000BE0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
BE0000
|
Size: |
4096
|
|
FCF000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1896610984.0000000000FCF000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FCF000
|
Size: |
28672
|
|
25204EC4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.2227466861.0000025204EC4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
25204EC4000
|
Size: |
24576
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2155175886.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
3330000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1973550018.0000000003330000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3330000
|
Size: |
4096
|
|
170B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226754273.000000000170B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
170B000
|
Size: |
57344
|
|
36F2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1973800098.00000000036F2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
36F2000
|
Size: |
512000
|
|
10BE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2479552228.00000000010BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10BE000
|
Size: |
167936
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153818639.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
25202F20000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000E.00000002.2277153493.0000025202F20000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
25202F20000
|
Size: |
356352
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2173177814.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
FC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2480739557.0000000000FC0000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FC0000
|
Size: |
4096
|
|
8165000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2172625705.0000000008165000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8165000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153116621.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
32F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.00000000032F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32F0000
|
Size: |
24576
|
|
25204970000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.2226864565.0000025204970000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
25204970000
|
Size: |
4096
|
|
F70000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.2479009124.0000000000F70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F70000
|
Size: |
8192
|
|
25204970000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.2226219823.0000025204970000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
25204970000
|
Size: |
4096
|
|
362E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1941555692.000000000362E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
362E000
|
Size: |
12288
|
|
B80000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1896353027.0000000000B80000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B80000
|
Size: |
4096
|
|
3960000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.2480956841.0000000003960000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3960000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153239418.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
25204EBE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000003.2227466861.0000025204EBE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
25204EBE000
|
Size: |
12288
|
|
FD9000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1896695974.0000000000FD9000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FD9000
|
Size: |
61440
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2156152394.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
FC1000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000B.00000002.2479227527.0000000000FC1000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FC1000
|
Size: |
57344
|
|
3619000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1973644593.0000000003619000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3619000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2156241717.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
16EB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226811201.00000000016EB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16EB000
|
Size: |
61440
|
|
357E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2480310303.000000000357E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
357E000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2155555925.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2480374639.00000000035BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35BE000
|
Size: |
8192
|
|
C90000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2479373273.0000000000C90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C90000
|
Size: |
32768
|
|
3923000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1880417121.0000000003923000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3923000
|
Size: |
507904
|
|
2922000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2481319174.0000000002922000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2922000
|
Size: |
4096
|
|
32F8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.00000000032F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32F8000
|
Size: |
40960
|
|
4259000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1247330086.0000000004259000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4259000
|
Size: |
4096
|
|
25204D21000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000E.00000002.2277579793.0000025204D21000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
14
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
25204D21000
|
Size: |
4096
|
|
4506000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2481556246.0000000004506000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4506000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152245210.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154292726.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
710000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000000.2046208886.0000000000710000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
710000
|
Size: |
4096
|
|
576F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2482754320.000000000576F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
576F000
|
Size: |
4096
|
|
8153000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483382696.0000000008153000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8153000
|
Size: |
24576
|
|
16D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222402674.00000000016D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16D2000
|
Size: |
491520
|
|
3A6F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249895650.0000000003A6F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3A6F000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153519671.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
4259000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236584479.0000000004259000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4259000
|
Size: |
4096
|
|
BE0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.2048005945.0000000000BE0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
BE0000
|
Size: |
4096
|
|
CB9000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2479373273.0000000000CB9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB9000
|
Size: |
81920
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
3240000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.2480573811.0000000003240000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3240000
|
Size: |
10485760
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2155005938.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
FD9000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.2479470356.0000000000FD9000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FD9000
|
Size: |
61440
|
|
814B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483382696.000000000814B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
814B000
|
Size: |
8192
|
|
42CE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1233722510.00000000042CE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42CE000
|
Size: |
24576
|
|
39FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1973705634.00000000039FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
39FE000
|
Size: |
8192
|
|
1FC0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1249832532.0000000001FC0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
1FC0000
|
Size: |
16384
|
|
17D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1223483519.00000000017D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17D8000
|
Size: |
331776
|
|
BF0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000000.2048018120.0000000000BF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BF0000
|
Size: |
20480
|
|
33A3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2478431645.00000000033A3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33A3000
|
Size: |
12288
|
|
34FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2480180276.00000000034FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
34FE000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152896953.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
3A01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1973720895.0000000003A01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3A01000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2152642241.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
3C2D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.2480956841.0000000003C2D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3C2D000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153753143.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
DFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249502242.0000000000DFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DFE000
|
Size: |
8192
|
|
40B3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1233583373.00000000040B3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40B3000
|
Size: |
507904
|
|
58AE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2482804094.00000000058AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
58AE000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2153025639.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
8192
|
|
2FCB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1973472115.0000000002FCB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FCB000
|
Size: |
20480
|
|
F80000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1896536307.0000000000F80000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
F80000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050452923.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2158854470.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050062854.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1981476560.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
200704
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2157110789.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
F90000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.2480633537.0000000000F90000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F90000
|
Size: |
16384
|
|
337E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1973565489.000000000337E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
337E000
|
Size: |
8192
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154316644.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
C60000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.2479298806.0000000000C60000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
C60000
|
Size: |
4096
|
|
731000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.1249155479.0000000000731000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
731000
|
Size: |
581632
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2050275429.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|
8130000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2483382696.0000000008130000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8130000
|
Size: |
32768
|
|
3A8D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.2480956841.0000000003A8D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3A8D000
|
Size: |
458752
|
|
330D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1974180647.000000000330D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
330D000
|
Size: |
24576
|
|
35C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.2154677640.00000000035C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
35C1000
|
Size: |
4096
|
|