402000
|
remote allocation
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.2460869421.0000000000402000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
402000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Telegram RAT |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected VIP Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
28E1000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000002.00000002.2463181774.00000000028E1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28E1000
|
Size: |
327680
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
URLs found in memory or binary data |
Networking |
|
|
4449000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000001.00000002.1237026255.0000000004449000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4449000
|
Size: |
831488
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Telegram RAT |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected VIP Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
B3DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1239862770.000000000B3DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B3DE000
|
Size: |
8192
|
|
A7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2461264651.0000000000A7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A7E000
|
Size: |
8192
|
|
6430000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2467947501.0000000006430000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6430000
|
Size: |
4096
|
|
4D43000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466417144.0000000004D43000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D43000
|
Size: |
8192
|
|
28BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463089382.00000000028BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
28BE000
|
Size: |
8192
|
|
49DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466352185.00000000049DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
49DE000
|
Size: |
8192
|
|
8B60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1239214105.0000000008B60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8B60000
|
Size: |
294912
|
|
1440000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235427922.0000000001440000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1440000
|
Size: |
16384
|
|
882000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000000.1203824616.0000000000882000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
882000
|
Size: |
806912
|
|
2BFB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235602653.0000000002BFB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2BFB000
|
Size: |
20480
|
|
2B76000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002B76000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B76000
|
Size: |
4096
|
|
2B7A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002B7A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B7A000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
1003000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1234809157.0000000001003000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1003000
|
Size: |
4096
|
|
5CD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238267635.0000000005CD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5CD0000
|
Size: |
12288
|
|
56B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238174747.00000000056B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56B0000
|
Size: |
40960
|
|
51E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237814399.00000000051E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
51E0000
|
Size: |
65536
|
|
6500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2468312697.0000000006500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6500000
|
Size: |
32768
|
|
5E76000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467042515.0000000005E76000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5E76000
|
Size: |
4096
|
|
5FA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2461126354.00000000005FA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5FA000
|
Size: |
24576
|
|
3C41000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237026255.0000000003C41000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C41000
|
Size: |
28672
|
|
1020000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1234881801.0000000001020000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1020000
|
Size: |
4096
|
|
4D71000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466464350.0000000004D71000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4D71000
|
Size: |
16384
|
|
4D5B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466464350.0000000004D5B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4D5B000
|
Size: |
8192
|
|
295C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.000000000295C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
295C000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
C55000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2461979989.0000000000C55000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
C55000
|
Size: |
4096
|
|
3B16000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003B16000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B16000
|
Size: |
8192
|
|
51C0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1237725772.00000000051C0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
51C0000
|
Size: |
65536
|
|
3A2E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003A2E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3A2E000
|
Size: |
12288
|
|
C5B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2462062134.0000000000C5B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
C5B000
|
Size: |
4096
|
|
1037000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1234959686.0000000001037000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1037000
|
Size: |
4096
|
|
626E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467474107.000000000626E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
626E000
|
Size: |
8192
|
|
3BA2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003BA2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3BA2000
|
Size: |
8192
|
|
2985000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002985000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2985000
|
Size: |
4096
|
|
10A8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235078587.00000000010A8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10A8000
|
Size: |
16384
|
|
28C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463120696.00000000028C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28C0000
|
Size: |
65536
|
|
C80000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2462132497.0000000000C80000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
C80000
|
Size: |
65536
|
|
2A40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002A40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A40000
|
Size: |
4096
|
|
10E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235078587.00000000010E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10E1000
|
Size: |
180224
|
|
2A79000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002A79000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A79000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5420000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1237980985.0000000005420000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5420000
|
Size: |
4096
|
|
8C7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1239338243.0000000008C7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8C7E000
|
Size: |
8192
|
|
AD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2461374123.0000000000AD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AD0000
|
Size: |
16384
|
|
2BBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235587176.0000000002BBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2BBE000
|
Size: |
8192
|
|
2958000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002958000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2958000
|
Size: |
4096
|
|
4D82000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466464350.0000000004D82000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4D82000
|
Size: |
49152
|
|
63DD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467644234.00000000063DD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63DD000
|
Size: |
12288
|
|
2A2D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002A2D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A2D000
|
Size: |
61440
|
|
2C41000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235685460.0000000002C41000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C41000
|
Size: |
286720
|
|
10DF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235078587.00000000010DF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10DF000
|
Size: |
4096
|
|
1060000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1234994776.0000000001060000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1060000
|
Size: |
65536
|
|
5390000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1237847064.0000000005390000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5390000
|
Size: |
65536
|
|
4D5E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466464350.0000000004D5E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4D5E000
|
Size: |
45056
|
|
63E0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2467704691.00000000063E0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
63E0000
|
Size: |
65536
|
|
3C58000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003C58000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C58000
|
Size: |
8192
|
|
541B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237959404.000000000541B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
541B000
|
Size: |
20480
|
|
D49000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462192429.0000000000D49000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D49000
|
Size: |
4096
|
|
60AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467433973.00000000060AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60AE000
|
Size: |
8192
|
|
102A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1234924866.000000000102A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
102A000
|
Size: |
4096
|
|
63D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467644234.00000000063D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63D0000
|
Size: |
49152
|
|
101D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1234867261.000000000101D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
101D000
|
Size: |
4096
|
|
2BB2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002BB2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BB2000
|
Size: |
139264
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
110E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235078587.000000000110E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
110E000
|
Size: |
8192
|
|
CF7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1234674887.0000000000CF7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CF7000
|
Size: |
36864
|
|
6400000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2467804036.0000000006400000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6400000
|
Size: |
65536
|
|
5CEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467001346.0000000005CEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5CEE000
|
Size: |
8192
|
|
3A76000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003A76000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3A76000
|
Size: |
20480
|
|
394D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.000000000394D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
394D000
|
Size: |
4096
|
|
5E7C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467042515.0000000005E7C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5E7C000
|
Size: |
8192
|
|
1450000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1235515460.0000000001450000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1450000
|
Size: |
4096
|
|
566D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238043123.000000000566D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
566D000
|
Size: |
12288
|
|
D82000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462644823.0000000000D82000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D82000
|
Size: |
53248
|
|
2A71000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002A71000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A71000
|
Size: |
4096
|
|
2BF2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002BF2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BF2000
|
Size: |
8192
|
|
63AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467515635.00000000063AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63AE000
|
Size: |
8192
|
|
8BAC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1239214105.0000000008BAC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8BAC000
|
Size: |
4096
|
|
103B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1234970341.000000000103B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
103B000
|
Size: |
4096
|
|
3AA8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003AA8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3AA8000
|
Size: |
8192
|
|
FDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1234767724.0000000000FDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FDE000
|
Size: |
8192
|
|
298D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.000000000298D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
298D000
|
Size: |
4096
|
|
51B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237710184.00000000051B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
51B0000
|
Size: |
4096
|
|
3B39000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003B39000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B39000
|
Size: |
4096
|
|
2932000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002932000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2932000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
27A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463000204.00000000027A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27A0000
|
Size: |
4096
|
|
948000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000000.1203918463.0000000000948000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
948000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
7410000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1239105558.0000000007410000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7410000
|
Size: |
40960
|
|
129E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235394173.000000000129E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
129E000
|
Size: |
8192
|
|
39F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.00000000039F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
39F0000
|
Size: |
20480
|
|
1026000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1234910794.0000000001026000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1026000
|
Size: |
8192
|
|
5141000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237509326.0000000005141000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5141000
|
Size: |
16384
|
|
5E5E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467042515.0000000005E5E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5E5E000
|
Size: |
81920
|
|
C57000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2462026854.0000000000C57000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
C57000
|
Size: |
4096
|
|
397D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.000000000397D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
397D000
|
Size: |
8192
|
|
2B63000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002B63000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B63000
|
Size: |
4096
|
|
117E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235362320.000000000117E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
117E000
|
Size: |
135168
|
|
2C89000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235685460.0000000002C89000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C89000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
63B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467535104.00000000063B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63B0000
|
Size: |
65536
|
|
2995000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002995000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2995000
|
Size: |
4096
|
|
B29E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1239821850.000000000B29E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B29E000
|
Size: |
8192
|
|
3B2E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003B2E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B2E000
|
Size: |
12288
|
|
64C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2468120492.00000000064C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
64C0000
|
Size: |
65536
|
|
2AC5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002AC5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AC5000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
E20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1234708573.0000000000E20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E20000
|
Size: |
8192
|
|
5190000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237684871.0000000005190000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5190000
|
Size: |
8192
|
|
3BA7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003BA7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3BA7000
|
Size: |
8192
|
|
512B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237509326.000000000512B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
512B000
|
Size: |
69632
|
|
64B4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2468061186.00000000064B4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
64B4000
|
Size: |
32768
|
|
3B9C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003B9C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B9C000
|
Size: |
8192
|
|
1022000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1234897419.0000000001022000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1022000
|
Size: |
4096
|
|
51D2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237754649.00000000051D2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
51D2000
|
Size: |
40960
|
|
63C6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467577721.00000000063C6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63C6000
|
Size: |
8192
|
|
2BEC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002BEC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BEC000
|
Size: |
16384
|
|
C40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2461762968.0000000000C40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C40000
|
Size: |
4096
|
|
294B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.000000000294B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
294B000
|
Size: |
8192
|
|
4D40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466417144.0000000004D40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D40000
|
Size: |
4096
|
|
53B0000
|
trusted library section
|
page readonly
|
|
|
|
Name: |
00000001.00000002.1237878158.00000000053B0000.00000002.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page readonly
|
Base address: |
53B0000
|
Size: |
65536
|
|
5DEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467023585.0000000005DEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5DEE000
|
Size: |
8192
|
|
6410000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467853097.0000000006410000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6410000
|
Size: |
65536
|
|
3903000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003903000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3903000
|
Size: |
12288
|
|
10A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235078587.00000000010A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10A0000
|
Size: |
28672
|
|
C23000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2461559752.0000000000C23000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
C23000
|
Size: |
4096
|
|
5BAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466963450.0000000005BAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5BAE000
|
Size: |
8192
|
|
64D0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2468174720.00000000064D0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
64D0000
|
Size: |
65536
|
|
D76000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462644823.0000000000D76000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D76000
|
Size: |
16384
|
|
2AB6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002AB6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AB6000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
54C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238011340.00000000054C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
54C0000
|
Size: |
65536
|
|
9DA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1234660219.00000000009DA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9DA000
|
Size: |
24576
|
|
64E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2468222990.00000000064E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
64E0000
|
Size: |
8192
|
|
2ABE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235569975.0000000002ABE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2ABE000
|
Size: |
8192
|
|
7300000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238821251.0000000007300000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7300000
|
Size: |
65536
|
|
4ED0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466785315.0000000004ED0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4ED0000
|
Size: |
4096
|
|
394F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.000000000394F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
394F000
|
Size: |
8192
|
|
5AAF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466946515.0000000005AAF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5AAF000
|
Size: |
4096
|
|
4D20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466376663.0000000004D20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4D20000
|
Size: |
49152
|
|
2BA7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002BA7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BA7000
|
Size: |
4096
|
|
4D50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466464350.0000000004D50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4D50000
|
Size: |
20480
|
|
52BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466886833.00000000052BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52BE000
|
Size: |
8192
|
|
5CD5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238267635.0000000005CD5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5CD5000
|
Size: |
8192
|
|
2C94000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235685460.0000000002C94000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C94000
|
Size: |
4902912
|
|
C30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2461674307.0000000000C30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C30000
|
Size: |
45056
|
|
6540000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2468380212.0000000006540000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6540000
|
Size: |
4096
|
|
8D7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1239357073.0000000008D7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8D7F000
|
Size: |
4096
|
|
1032000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1234946664.0000000001032000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1032000
|
Size: |
4096
|
|
64F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2468275540.00000000064F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
64F0000
|
Size: |
40960
|
|
39C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.00000000039C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
39C0000
|
Size: |
4096
|
|
4D7D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466464350.0000000004D7D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4D7D000
|
Size: |
16384
|
|
26F8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462910309.00000000026F8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26F8000
|
Size: |
4096
|
|
5670000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238058982.0000000005670000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5670000
|
Size: |
65536
|
|
3BAE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003BAE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3BAE000
|
Size: |
8192
|
|
4E2D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466763999.0000000004E2D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4E2D000
|
Size: |
12288
|
|
53C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237910844.00000000053C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
53C0000
|
Size: |
8192
|
|
C2D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2461634597.0000000000C2D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
C2D000
|
Size: |
4096
|
|
C90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462192429.0000000000C90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C90000
|
Size: |
28672
|
|
5FAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467411915.0000000005FAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5FAE000
|
Size: |
8192
|
|
10C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235078587.00000000010C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10C7000
|
Size: |
49152
|
|
62AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467492842.00000000062AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
62AE000
|
Size: |
8192
|
|
3A4C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003A4C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3A4C000
|
Size: |
4096
|
|
2981000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002981000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2981000
|
Size: |
4096
|
|
2C30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235666961.0000000002C30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C30000
|
Size: |
4096
|
|
1070000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235013787.0000000001070000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1070000
|
Size: |
65536
|
|
D3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462192429.0000000000D3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3D000
|
Size: |
4096
|
|
1000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1234795312.0000000001000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1000000
|
Size: |
8192
|
|
4D6E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466464350.0000000004D6E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4D6E000
|
Size: |
4096
|
|
2B7F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002B7F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B7F000
|
Size: |
118784
|
|
C98000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462192429.0000000000C98000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C98000
|
Size: |
135168
|
|
5124000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237509326.0000000005124000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5124000
|
Size: |
16384
|
|
2BA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002BA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BA0000
|
Size: |
12288
|
|
6E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238343925.0000000006E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6E00000
|
Size: |
24576
|
|
400000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2460869421.0000000000400000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
4096
|
|
A80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2461303141.0000000000A80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A80000
|
Size: |
8192
|
|
C42000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2461804031.0000000000C42000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C42000
|
Size: |
4096
|
|
39C2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.00000000039C2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
39C2000
|
Size: |
4096
|
|
7200000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238783801.0000000007200000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7200000
|
Size: |
86016
|
|
2BFC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002BFC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BFC000
|
Size: |
24576
|
|
3C70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003C70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C70000
|
Size: |
12288
|
|
513E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237509326.000000000513E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
513E000
|
Size: |
8192
|
|
63CA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467577721.00000000063CA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63CA000
|
Size: |
24576
|
|
2A4D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002A4D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A4D000
|
Size: |
81920
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
C4A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2461898622.0000000000C4A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
C4A000
|
Size: |
8192
|
|
7310000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1238854169.0000000007310000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7310000
|
Size: |
65536
|
|
4C48000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237466246.0000000004C48000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4C48000
|
Size: |
4096
|
|
1090000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235046186.0000000001090000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1090000
|
Size: |
65536
|
|
C3D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2461724568.0000000000C3D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
C3D000
|
Size: |
4096
|
|
1111000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235078587.0000000001111000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1111000
|
Size: |
184320
|
|
E90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462744399.0000000000E90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E90000
|
Size: |
4096
|
|
2B6C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002B6C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B6C000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
3A4A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003A4A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3A4A000
|
Size: |
4096
|
|
C46000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2461848253.0000000000C46000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
C46000
|
Size: |
8192
|
|
3909000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003909000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3909000
|
Size: |
192512
|
|
1004000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1234821338.0000000001004000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1004000
|
Size: |
4096
|
|
5C90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238198995.0000000005C90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C90000
|
Size: |
147456
|
|
5F2D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467367528.0000000005F2D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5F2D000
|
Size: |
12288
|
|
1460000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235531720.0000000001460000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1460000
|
Size: |
20480
|
|
5160000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237654845.0000000005160000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5160000
|
Size: |
65536
|
|
D21000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462192429.0000000000D21000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D21000
|
Size: |
102400
|
|
FF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1234784991.0000000000FF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
FF0000
|
Size: |
8192
|
|
6450000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2468015084.0000000006450000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6450000
|
Size: |
65536
|
|
EAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1234739028.0000000000EAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EAE000
|
Size: |
8192
|
|
8D80000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1239372445.0000000008D80000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
8D80000
|
Size: |
69632
|
|
4DDD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237485868.0000000004DDD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4DDD000
|
Size: |
12288
|
|
29A1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.00000000029A1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29A1000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5DF5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238307358.0000000005DF5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5DF5000
|
Size: |
40960
|
|
B39E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1239844447.000000000B39E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B39E000
|
Size: |
8192
|
|
C20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2461500329.0000000000C20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C20000
|
Size: |
8192
|
|
2AE6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002AE6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AE6000
|
Size: |
380928
|
|
1467000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235531720.0000000001467000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1467000
|
Size: |
32768
|
|
27A4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463000204.00000000027A4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27A4000
|
Size: |
49152
|
|
51DD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237754649.00000000051DD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
51DD000
|
Size: |
12288
|
|
3B37000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003B37000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B37000
|
Size: |
4096
|
|
2A96000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002A96000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A96000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7360000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238930807.0000000007360000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
7360000
|
Size: |
561152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
4D6A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466464350.0000000004D6A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4D6A000
|
Size: |
4096
|
|
51D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237754649.00000000051D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
51D0000
|
Size: |
4096
|
|
D7C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462644823.0000000000D7C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D7C000
|
Size: |
16384
|
|
EB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462773742.0000000000EB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EB0000
|
Size: |
16384
|
|
6930000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2468404520.0000000006930000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6930000
|
Size: |
8192
|
|
960000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2461222082.0000000000960000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
960000
|
Size: |
4096
|
|
8F7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2461173530.00000000008F7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8F7000
|
Size: |
36864
|
|
2A42000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002A42000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A42000
|
Size: |
4096
|
|
AD5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2461374123.0000000000AD5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AD5000
|
Size: |
12288
|
|
2790000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462941840.0000000002790000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2790000
|
Size: |
65536
|
|
38E1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.00000000038E1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
38E1000
|
Size: |
32768
|
|
2A6F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002A6F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A6F000
|
Size: |
4096
|
|
28D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463164677.00000000028D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28D0000
|
Size: |
4096
|
|
2BE7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002BE7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BE7000
|
Size: |
12288
|
|
3C49000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237026255.0000000003C49000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C49000
|
Size: |
4096
|
|
514D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237509326.000000000514D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
514D000
|
Size: |
69632
|
|
77DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1239197094.00000000077DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
77DE000
|
Size: |
8192
|
|
52FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466907252.00000000052FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52FE000
|
Size: |
8192
|
|
3965000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003965000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3965000
|
Size: |
12288
|
|
616E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467455131.000000000616E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
616E000
|
Size: |
8192
|
|
2991000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002991000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2991000
|
Size: |
4096
|
|
1158000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235078587.0000000001158000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1158000
|
Size: |
16384
|
|
1080000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235030058.0000000001080000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1080000
|
Size: |
16384
|
|
6440000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2467966527.0000000006440000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6440000
|
Size: |
65536
|
|
10D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235078587.00000000010D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10D4000
|
Size: |
32768
|
|
F40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462876001.0000000000F40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F40000
|
Size: |
16384
|
|
755F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1239158052.000000000755F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
755F000
|
Size: |
4096
|
|
D40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1234692070.0000000000D40000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D40000
|
Size: |
4096
|
|
6420000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2467901753.0000000006420000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6420000
|
Size: |
65536
|
|
53D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237928227.00000000053D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53D0000
|
Size: |
65536
|
|
2AA8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002AA8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AA8000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
B51E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1239899674.000000000B51E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B51E000
|
Size: |
8192
|
|
1430000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235408065.0000000001430000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1430000
|
Size: |
65536
|
|
5680000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238091594.0000000005680000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5680000
|
Size: |
65536
|
|
5E7A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467042515.0000000005E7A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5E7A000
|
Size: |
4096
|
|
3ABE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003ABE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3ABE000
|
Size: |
12288
|
|
2B58000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002B58000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B58000
|
Size: |
4096
|
|
5146000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237509326.0000000005146000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5146000
|
Size: |
16384
|
|
299D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.000000000299D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
299D000
|
Size: |
4096
|
|
B61F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1239921172.000000000B61F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B61F000
|
Size: |
4096
|
|
6530000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2468344825.0000000006530000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6530000
|
Size: |
36864
|
|
1010000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1234850713.0000000001010000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1010000
|
Size: |
40960
|
|
5120000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237509326.0000000005120000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5120000
|
Size: |
12288
|
|
3B8B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003B8B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B8B000
|
Size: |
12288
|
|
3CB6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003CB6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3CB6000
|
Size: |
20480
|
|
2C23000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235638194.0000000002C23000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C23000
|
Size: |
12288
|
|
4D56000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466464350.0000000004D56000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4D56000
|
Size: |
8192
|
|
1148000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235078587.0000000001148000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1148000
|
Size: |
8192
|
|
5C80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238198995.0000000005C80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C80000
|
Size: |
4096
|
|
5CAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466982689.0000000005CAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5CAE000
|
Size: |
8192
|
|
5690000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1238120320.0000000005690000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5690000
|
Size: |
65536
|
|
C10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2461459397.0000000000C10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C10000
|
Size: |
8192
|
|
CC6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462192429.0000000000CC6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC6000
|
Size: |
368640
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
27B0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2463062720.00000000027B0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
27B0000
|
Size: |
4096
|
|
5F6F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467391214.0000000005F6F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5F6F000
|
Size: |
4096
|
|
2A7E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002A7E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A7E000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
F3C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462837399.0000000000F3C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F3C000
|
Size: |
16384
|
|
2C20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235638194.0000000002C20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C20000
|
Size: |
4096
|
|
3A18000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003A18000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3A18000
|
Size: |
8192
|
|
54B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1237997308.00000000054B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
54B0000
|
Size: |
4096
|
|
5030000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2466839603.0000000005030000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5030000
|
Size: |
4096
|
|
CC4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462192429.0000000000CC4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC4000
|
Size: |
4096
|
|
10AE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235078587.00000000010AE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10AE000
|
Size: |
98304
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
3BB9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003BB9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3BB9000
|
Size: |
8192
|
|
63C4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467577721.00000000063C4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63C4000
|
Size: |
4096
|
|
2954000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002954000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2954000
|
Size: |
4096
|
|
1150000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235078587.0000000001150000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1150000
|
Size: |
8192
|
|
29C8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.00000000029C8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29C8000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
C52000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2461942826.0000000000C52000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C52000
|
Size: |
4096
|
|
527E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466861130.000000000527E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
527E000
|
Size: |
8192
|
|
2C0A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002C0A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C0A000
|
Size: |
16384
|
|
C70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462097162.0000000000C70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C70000
|
Size: |
4096
|
|
2A48000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002A48000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A48000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
C24000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2461597206.0000000000C24000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
C24000
|
Size: |
8192
|
|
EFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462810223.0000000000EFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EFE000
|
Size: |
8192
|
|
446000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2460869421.0000000000446000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
446000
|
Size: |
4096
|
|
3B73000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003B73000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B73000
|
Size: |
8192
|
|
3C8A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003C8A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C8A000
|
Size: |
4096
|
|
2A6B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002A6B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A6B000
|
Size: |
8192
|
|
5E78000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467042515.0000000005E78000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5E78000
|
Size: |
4096
|
|
56A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238149290.00000000056A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56A0000
|
Size: |
28672
|
|
3B93000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003B93000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B93000
|
Size: |
8192
|
|
38EB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.00000000038EB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
38EB000
|
Size: |
8192
|
|
ACF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2461339485.0000000000ACF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
ACF000
|
Size: |
4096
|
|
880000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000000.1203803043.0000000000880000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
880000
|
Size: |
4096
|
|
1141000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235078587.0000000001141000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1141000
|
Size: |
12288
|
|
4DED000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466740981.0000000004DED000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4DED000
|
Size: |
12288
|
|
779E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1239179114.000000000779E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
779E000
|
Size: |
8192
|
|
64B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2468061186.00000000064B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
64B0000
|
Size: |
12288
|
|
6E22000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238343925.0000000006E22000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6E22000
|
Size: |
1572864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2A73000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002A73000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A73000
|
Size: |
4096
|
|
63F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467751977.00000000063F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F0000
|
Size: |
65536
|
|
CBA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2462192429.0000000000CBA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CBA000
|
Size: |
12288
|
|
5DF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467042515.0000000005DF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5DF0000
|
Size: |
389120
|
|
3C8C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003C8C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C8C000
|
Size: |
4096
|
|
7320000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238888805.0000000007320000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7320000
|
Size: |
65536
|
|
ED0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1234752498.0000000000ED0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ED0000
|
Size: |
20480
|
|
2BAC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002BAC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BAC000
|
Size: |
12288
|
|
5DF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1238307358.0000000005DF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5DF0000
|
Size: |
12288
|
|
1030000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1234935763.0000000001030000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1030000
|
Size: |
4096
|
|
1050000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1234983378.0000000001050000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1050000
|
Size: |
4096
|
|
4D76000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466464350.0000000004D76000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4D76000
|
Size: |
16384
|
|
2C05000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002C05000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C05000
|
Size: |
12288
|
|
2C0F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002C0F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C0F000
|
Size: |
512000
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
2B5C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002B5C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B5C000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
2C00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235619381.0000000002C00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C00000
|
Size: |
65536
|
|
500D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466814675.000000000500D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
500D000
|
Size: |
12288
|
|
29EA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.00000000029EA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29EA000
|
Size: |
270336
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
SQL strings found in memory and binary data |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
3B67000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003B67000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B67000
|
Size: |
20480
|
|
E6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1234724853.0000000000E6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E6E000
|
Size: |
8192
|
|
59AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2466925858.00000000059AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59AE000
|
Size: |
8192
|
|
2999000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002999000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2999000
|
Size: |
4096
|
|
745E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1239136907.000000000745E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
745E000
|
Size: |
8192
|
|
5E55000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2467042515.0000000005E55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5E55000
|
Size: |
8192
|
|
2949000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002949000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2949000
|
Size: |
4096
|
|
3BB4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2465251923.0000000003BB4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3BB4000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1445000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1235427922.0000000001445000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1445000
|
Size: |
45056
|
|
100D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1234835273.000000000100D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
100D000
|
Size: |
4096
|
|
2989000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002989000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2989000
|
Size: |
4096
|
|
293E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.000000000293E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
293E000
|
Size: |
40960
|
|
2BF5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2463181774.0000000002BF5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BF5000
|
Size: |
4096
|
|
64E7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2468222990.00000000064E7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
64E7000
|
Size: |
36864
|
|
B4DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1239884072.000000000B4DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B4DE000
|
Size: |
8192
|
|