5670000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000006.00000002.3363348707.0000000005670000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5670000
|
Size: |
299008
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
74E0000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.1023946734.00000000074E0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
74E0000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
800000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000004.00000002.3361296976.0000000000800000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
800000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
2300000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000003.00000002.3361032659.0000000002300000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
2300000
|
Size: |
4710400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
7B0000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000004.00000002.3361185942.00000000007B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B0000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
400000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.1017720914.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
290816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
110000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000004.00000002.3359220364.0000000000110000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
110000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3FE0000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.1021306624.0000000003FE0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3FE0000
|
Size: |
4710400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194067404.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
1300000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3360332450.0000000001300000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1300000
|
Size: |
4096
|
|
4254000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362363098.0000000004254000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4254000
|
Size: |
8192
|
|
48F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3359108111.000000000048F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
48F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
12A1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3360059388.00000000012A1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
12A1000
|
Size: |
12288
|
|
180000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3359330566.0000000000180000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
180000
|
Size: |
4096
|
|
48FC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361395202.00000000048FC000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
48FC000
|
Size: |
16384
|
|
480000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.942565679.0000000000480000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
480000
|
Size: |
4096
|
|
145A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1089121474.000000000145A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
145A000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195358683.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
46B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1021941402.000000000046B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
46B000
|
Size: |
28672
|
|
B20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.918433730.0000000000B20000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B20000
|
Size: |
4096
|
|
499000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3359195519.0000000000499000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
499000
|
Size: |
61440
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197470378.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
4FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1207548491.00000000004FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4FE000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193757151.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
4D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1207607707.00000000004D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D8000
|
Size: |
4096
|
|
3402000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017920542.0000000003402000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3402000
|
Size: |
20480
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196109146.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3250000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017813486.0000000003250000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3250000
|
Size: |
4096
|
|
610000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3360230218.0000000000610000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
610000
|
Size: |
32768
|
|
76F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.00000000076F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76F4000
|
Size: |
12288
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196472954.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
7FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918267893.00000000007FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7FC000
|
Size: |
16384
|
|
3A4D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916499951.0000000003A4D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A4D000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
3A49000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.917961819.0000000003A49000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A49000
|
Size: |
4096
|
|
3ABE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.917961819.0000000003ABE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3ABE000
|
Size: |
24576
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.932846147.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
135168
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196986522.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
F6D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918809788.0000000000F6D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F6D000
|
Size: |
40960
|
|
3ADA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361395202.0000000003ADA000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3ADA000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3359084104.00000000000A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A0000
|
Size: |
4096
|
|
56D4000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3363348707.00000000056D4000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
56D4000
|
Size: |
4096
|
|
A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.942355382.00000000000A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A0000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194420745.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
9D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1032975229.00000000009D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9D0000
|
Size: |
172032
|
|
3C0C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362363098.0000000003C0C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3C0C000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1210790295.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
99000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918216329.0000000000099000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
99000
|
Size: |
28672
|
|
11A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3359168278.000000000011A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
11A000
|
Size: |
24576
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193043876.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196738076.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
DA0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1088763059.0000000000DA0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
DA0000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194736388.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
D72000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3361658075.0000000000D72000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
D72000
|
Size: |
40960
|
|
103A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3359553738.000000000103A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
103A000
|
Size: |
24576
|
|
1450000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1089121474.0000000001450000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1450000
|
Size: |
32768
|
|
301C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362363098.000000000301C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
301C000
|
Size: |
4096
|
|
471000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1021991344.0000000000471000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
471000
|
Size: |
4096
|
|
3780000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.917648133.0000000003780000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3780000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942493067.00000000001C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C0000
|
Size: |
20480
|
|
1250000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1088929639.0000000001250000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1250000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194009976.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
2099D679000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.1314805597.000002099D679000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
2099D679000
|
Size: |
4096
|
|
5A467FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1314726833.0000005A467FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A467FE000
|
Size: |
8192
|
|
CDE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.886123492.0000000000CDE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CDE000
|
Size: |
679936
|
|
1140000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1088825540.0000000001140000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1140000
|
Size: |
4096
|
|
76FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.00000000076FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76FD000
|
Size: |
12288
|
|
FFD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.919141137.0000000000FFD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FFD000
|
Size: |
90112
|
|
53C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.000000000053C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
53C000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194556021.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
190000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3359391902.0000000000190000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
190000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194175297.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195015832.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
56E0000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3363348707.00000000056E0000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
56E0000
|
Size: |
12288
|
|
2F62000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1089426792.0000000002F62000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2F62000
|
Size: |
4096
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.923737204.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
135168
|
|
3A4D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.917342166.0000000003A4D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A4D000
|
Size: |
458752
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195909795.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
496000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942606821.0000000000496000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
496000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195222087.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3A4D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.917961819.0000000003A4D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A4D000
|
Size: |
458752
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.928896540.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
233472
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1037870199.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196176864.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
2E70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3361183087.0000000002E70000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2E70000
|
Size: |
925696
|
|
160000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.942413913.0000000000160000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
160000
|
Size: |
4096
|
|
1320000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3360456009.0000000001320000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1320000
|
Size: |
16384
|
|
2099F315000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1315086379.000002099F315000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2099F315000
|
Size: |
12288
|
|
27FD000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3361032659.00000000027FD000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
27FD000
|
Size: |
10485760
|
|
3C00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1019775022.0000000003C00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3C00000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1150000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1088845502.0000000001150000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1150000
|
Size: |
4096
|
|
76A4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.00000000076A4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76A4000
|
Size: |
49152
|
|
2D24000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361079748.0000000002D24000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D24000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197496103.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
AF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918393712.0000000000AF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AF0000
|
Size: |
8192
|
|
3920000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915648029.0000000003920000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3920000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
920000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3361586972.0000000000920000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
920000
|
Size: |
94208
|
|
6B9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1018580969.00000000006B9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B9000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1090842270.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196710880.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
323C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1089426792.000000000323C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
323C000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
9A5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1024300581.00000000009A5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A5000
|
Size: |
4096
|
|
476000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1022610317.0000000000476000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
476000
|
Size: |
24576
|
|
DFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362311302.0000000000DFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DFE000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196514190.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1192641412.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
470000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942553243.0000000000470000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
470000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1038082669.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
F9C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.919096042.0000000000F9C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F9C000
|
Size: |
286720
|
|
2099F030000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1264815298.000002099F030000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2099F030000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197853812.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
7D6F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3365066703.0000000007D6F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7D6F000
|
Size: |
4096
|
|
3617000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.921826637.0000000003617000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3617000
|
Size: |
20480
|
|
D90000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1088738650.0000000000D90000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
D90000
|
Size: |
4096
|
|
90000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3358984257.0000000000090000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
90000
|
Size: |
4096
|
|
55B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.000000000055B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
55B000
|
Size: |
16384
|
|
38E8000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362363098.00000000038E8000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
38E8000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1090807776.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
1DCA4000
|
system
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1313448559.000000001DCA4000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
1DCA4000
|
Size: |
8192
|
|
9D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091828242.00000000009D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9D0000
|
Size: |
172032
|
|
496000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3359164615.0000000000496000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
496000
|
Size: |
8192
|
|
47C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1022358805.000000000047C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
47C000
|
Size: |
20480
|
|
1150000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3359749471.0000000001150000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1150000
|
Size: |
4096
|
|
2099D67B000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.1314805597.000002099D67B000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
2099D67B000
|
Size: |
4096
|
|
2099F300000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1315070797.000002099F300000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2099F300000
|
Size: |
4096
|
|
546000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.0000000000546000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
546000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091361879.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.936585007.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
200704
|
|
38A3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916351738.00000000038A3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38A3000
|
Size: |
507904
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
509000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1207548491.0000000000509000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
509000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197202576.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
4CD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1207607707.00000000004CD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD000
|
Size: |
8192
|
|
3B29000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.923429419.0000000003B29000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3B29000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195463092.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197095277.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
1450000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3360676106.0000000001450000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1450000
|
Size: |
32768
|
|
7BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918267893.00000000007BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7BF000
|
Size: |
4096
|
|
7DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1018580969.00000000007DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7DC000
|
Size: |
512000
|
|
B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3359115473.00000000000B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B0000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193669642.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3F90000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361395202.0000000003F90000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3F90000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2FFB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017780603.0000000002FFB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FFB000
|
Size: |
20480
|
|
8E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.942736432.00000000008E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8E0000
|
Size: |
32768
|
|
150000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.942399980.0000000000150000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
150000
|
Size: |
4096
|
|
3A49000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916499951.0000000003A49000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A49000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197718691.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
2210000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.942830143.0000000002210000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2210000
|
Size: |
925696
|
|
18E1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3361002496.00000000018E1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
18E1000
|
Size: |
348160
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
470000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3359747196.0000000000470000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
470000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195682085.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
2099F310000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1315086379.000002099F310000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2099F310000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195629984.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3920000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915112106.0000000003920000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3920000
|
Size: |
1196032
|
|
1E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.942507571.00000000001E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1E0000
|
Size: |
16384
|
|
2E70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1089332246.0000000002E70000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2E70000
|
Size: |
925696
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091660241.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
4D52000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362363098.0000000004D52000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4D52000
|
Size: |
8192
|
|
476000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1022491391.0000000000476000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
476000
|
Size: |
24576
|
|
1003000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.887870763.0000000001003000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1003000
|
Size: |
176128
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196082137.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3ABE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915648029.0000000003ABE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3ABE000
|
Size: |
24576
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1198413839.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
C71000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3360494650.0000000000C71000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C71000
|
Size: |
348160
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196801903.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.932932040.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
200704
|
|
42B4000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361395202.00000000042B4000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
42B4000
|
Size: |
8192
|
|
3ABE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916068351.0000000003ABE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3ABE000
|
Size: |
24576
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1192727416.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195157424.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
5A46FFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1314751551.0000005A46FFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A46FFE000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194122038.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
87C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1024300581.000000000087C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
87C000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
40C2000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362363098.00000000040C2000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
40C2000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
F69000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918809788.0000000000F69000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F69000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196641609.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
517000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.0000000000517000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
517000
|
Size: |
12288
|
|
DA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918809788.0000000000DA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA0000
|
Size: |
24576
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193699397.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1210918479.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
160000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3359255386.0000000000160000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
160000
|
Size: |
4096
|
|
CD0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.918625075.0000000000CD0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
CD0000
|
Size: |
16384
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091328199.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197663891.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
1046000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.919141137.0000000001046000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1046000
|
Size: |
294912
|
|
503000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1207548491.0000000000503000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
503000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
768F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1198178368.000000000768F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
768F000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
33AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017884818.00000000033AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33AE000
|
Size: |
8192
|
|
4DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1207607707.00000000004DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC000
|
Size: |
12288
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197255700.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
CD7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.887673457.0000000000CD7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD7000
|
Size: |
667648
|
|
F58000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918809788.0000000000F58000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F58000
|
Size: |
61440
|
|
440000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359711765.0000000000440000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
440000
|
Size: |
4096
|
|
BE3000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.885649375.0000000000BE3000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
BE3000
|
Size: |
8192
|
|
4A2E000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362363098.0000000004A2E000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4A2E000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196138021.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
BAF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.918506495.0000000000BAF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BAF000
|
Size: |
151552
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194501258.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091218700.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196414851.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
48F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1088655588.000000000048F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
48F000
|
Size: |
28672
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194394080.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193945367.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
2099D783000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1314942353.000002099D783000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2099D783000
|
Size: |
24576
|
|
2099F321000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1315086379.000002099F321000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2099F321000
|
Size: |
4096
|
|
2210000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3360782495.0000000002210000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2210000
|
Size: |
925696
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195280598.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196565934.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
1550000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1089184499.0000000001550000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1550000
|
Size: |
32768
|
|
1A1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3359452812.00000000001A1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A1000
|
Size: |
12288
|
|
1170000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1088900696.0000000001170000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1170000
|
Size: |
4096
|
|
1310000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3360394724.0000000001310000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1310000
|
Size: |
12288
|
|
12B0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3360123990.00000000012B0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
12B0000
|
Size: |
4096
|
|
3360000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017842246.0000000003360000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3360000
|
Size: |
4096
|
|
3ABE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.917342166.0000000003ABE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3ABE000
|
Size: |
24576
|
|
61E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942675268.000000000061E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
61E000
|
Size: |
90112
|
|
D80000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1088719087.0000000000D80000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
D80000
|
Size: |
4096
|
|
4EDD000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1021306624.0000000004EDD000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4EDD000
|
Size: |
10485760
|
|
3780000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916809030.0000000003780000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3780000
|
Size: |
1187840
|
|
1140000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3359691388.0000000001140000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1140000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194527900.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196829856.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
4B5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.00000000004B5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B5000
|
Size: |
86016
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1090941851.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
43E6000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362363098.00000000043E6000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
43E6000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
43F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359663223.000000000043F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
43F000
|
Size: |
4096
|
|
2104000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3360618641.0000000002104000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2104000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195408679.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3D29000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1019775022.0000000003D29000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3D29000
|
Size: |
4096
|
|
1550000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3360956062.0000000001550000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1550000
|
Size: |
32768
|
|
1F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1024552866.00000000001F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F4000
|
Size: |
4096
|
|
D8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359138372.00000000000D8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D8000
|
Size: |
32768
|
|
1E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359512295.00000000001E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E0000
|
Size: |
4096
|
|
87E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918364215.000000000087E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
87E000
|
Size: |
8192
|
|
578C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3363599959.000000000578C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
578C000
|
Size: |
16384
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193642920.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
1479000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3360676106.0000000001479000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1479000
|
Size: |
77824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091153009.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3F50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1021149604.0000000003F50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F50000
|
Size: |
278528
|
|
1D6FC000
|
system
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1313448559.000000001D6FC000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
1D6FC000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196959436.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
3701000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1019290848.0000000003701000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3701000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194664259.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194583909.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
4474000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1021306624.0000000004474000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4474000
|
Size: |
4096
|
|
76BB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.00000000076BB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76BB000
|
Size: |
12288
|
|
2104000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942790046.0000000002104000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2104000
|
Size: |
4096
|
|
2099F4CE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1265977107.000002099F4CE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2099F4CE000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195812399.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
2099D780000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1266079504.000002099D780000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2099D780000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197825896.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194928418.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
79E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3365039831.00000000079E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79E0000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196773240.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193864626.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197607997.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
499000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3360060964.0000000000499000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
499000
|
Size: |
61440
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195124465.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3920000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.917961819.0000000003920000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3920000
|
Size: |
1196032
|
|
496000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1088675916.0000000000496000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
496000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194870601.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
7690000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.0000000007690000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7690000
|
Size: |
16384
|
|
3948000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361395202.0000000003948000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3948000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1B0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3359479516.00000000001B0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1B0000
|
Size: |
4096
|
|
38A3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915906521.00000000038A3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38A3000
|
Size: |
507904
|
|
870000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3361472203.0000000000870000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
870000
|
Size: |
94208
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1090875346.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
35C4000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362363098.00000000035C4000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
35C4000
|
Size: |
8192
|
|
76E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.00000000076E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76E0000
|
Size: |
16384
|
|
610000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942675268.0000000000610000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
610000
|
Size: |
32768
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197391180.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
56BB000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3363348707.00000000056BB000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
56BB000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196932659.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3FA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.986671239.0000000003FA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3FA0000
|
Size: |
172032
|
|
1D5E2000
|
system
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1313448559.000000001D5E2000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
1D5E2000
|
Size: |
4096
|
|
BCE000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3361658075.0000000000BCE000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
BCE000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196366590.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197282534.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
3780000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915517154.0000000003780000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3780000
|
Size: |
1187840
|
|
DA8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918809788.0000000000DA8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA8000
|
Size: |
1765376
|
|
7CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918267893.00000000007CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7CF000
|
Size: |
4096
|
|
481000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000000.942577995.0000000000481000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
481000
|
Size: |
57344
|
|
142F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3360579532.000000000142F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
142F000
|
Size: |
4096
|
|
44DD000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1021306624.00000000044DD000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
44DD000
|
Size: |
10485760
|
|
45D8000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361395202.00000000045D8000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
45D8000
|
Size: |
4096
|
|
2D24000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1089251711.0000000002D24000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D24000
|
Size: |
4096
|
|
37B6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361395202.00000000037B6000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
37B6000
|
Size: |
8192
|
|
58DD000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1021306624.00000000058DD000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
58DD000
|
Size: |
4538368
|
|
C70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.942752122.0000000000C70000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
C70000
|
Size: |
352256
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.942370182.00000000000B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B0000
|
Size: |
4096
|
|
4D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.00000000004D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D8000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195187346.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
BDF000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.885649375.0000000000BDF000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
BDF000
|
Size: |
8192
|
|
480000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1088611389.0000000000480000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
480000
|
Size: |
4096
|
|
79CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3365010558.00000000079CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
79CE000
|
Size: |
8192
|
|
7698000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.0000000007698000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7698000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091517563.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
142F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1089102698.000000000142F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
142F000
|
Size: |
4096
|
|
170000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3359287746.0000000000170000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
170000
|
Size: |
4096
|
|
34FD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.887780357.00000000034FD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
34FD000
|
Size: |
1003520
|
|
B20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.885531457.0000000000B20000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B20000
|
Size: |
4096
|
|
47C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1021909870.000000000047C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
47C000
|
Size: |
20480
|
|
2100000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942790046.0000000002100000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2100000
|
Size: |
8192
|
|
476A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361395202.000000000476A000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
476A000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194898494.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
BAF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.885605869.0000000000BAF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BAF000
|
Size: |
151552
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1210856568.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3606000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.919339441.0000000003606000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3606000
|
Size: |
1159168
|
|
A30000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3361658075.0000000000A30000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
A30000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
536000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.0000000000536000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
536000
|
Size: |
8192
|
|
8DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942722576.00000000008DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8DF000
|
Size: |
4096
|
|
31FD000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3361032659.00000000031FD000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
31FD000
|
Size: |
10485760
|
|
1B0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942480729.00000000001B0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1B0000
|
Size: |
4096
|
|
481000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000006.00000000.1088634236.0000000000481000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
481000
|
Size: |
57344
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194786924.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091550967.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.933052777.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
233472
|
|
476000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1022548716.0000000000476000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
476000
|
Size: |
24576
|
|
3F30000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362363098.0000000003F30000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3F30000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
31DC000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362363098.00000000031DC000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
31DC000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1192985435.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
61A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942675268.000000000061A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
61A000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194955688.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
48F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.942593208.000000000048F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
48F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
496000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3359994936.0000000000496000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
496000
|
Size: |
8192
|
|
B00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918415446.0000000000B00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B00000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193729332.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
3920000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.917342166.0000000003920000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3920000
|
Size: |
1196032
|
|
159D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.919252258.000000000159D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
159D000
|
Size: |
12288
|
|
4C9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1207607707.00000000004C9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C9000
|
Size: |
4096
|
|
B59000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3361658075.0000000000B59000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
B59000
|
Size: |
4096
|
|
2099F401000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1315216878.000002099F401000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2099F401000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193917300.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
2099D77B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1266079504.000002099D77B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2099D77B000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197880737.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
38A3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.914983615.00000000038A3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38A3000
|
Size: |
507904
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193521937.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
5C60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364307878.0000000005C60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5C60000
|
Size: |
12288
|
|
489C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362363098.000000000489C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
489C000
|
Size: |
16384
|
|
1300000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1089057953.0000000001300000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1300000
|
Size: |
4096
|
|
190000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359359617.0000000000190000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
190000
|
Size: |
4096
|
|
1E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3359621323.00000000001E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1E0000
|
Size: |
16384
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197336282.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
100000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918233961.0000000000100000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
100000
|
Size: |
4096
|
|
9A9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1024300581.00000000009A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9A9000
|
Size: |
458752
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193971734.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
5EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942652778.00000000005EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5EE000
|
Size: |
8192
|
|
3FA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.932674283.0000000003FA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3FA0000
|
Size: |
172032
|
|
4CD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.00000000004CD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CD000
|
Size: |
8192
|
|
46D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.000000000046D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
46D000
|
Size: |
94208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193839230.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
12B0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1088990308.00000000012B0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
12B0000
|
Size: |
4096
|
|
2D6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1089294922.0000000002D6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D6E000
|
Size: |
8192
|
|
7B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1028264416.00000000007B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B0000
|
Size: |
172032
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197986426.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194204856.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
113C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3359623042.000000000113C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
113C000
|
Size: |
16384
|
|
950000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918378155.0000000000950000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
950000
|
Size: |
24576
|
|
31A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.919283892.00000000031A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31A0000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195433540.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
2794000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3361032659.0000000002794000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
2794000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194038775.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195866285.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
1170000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3359891290.0000000001170000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1170000
|
Size: |
4096
|
|
2099F30E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1315086379.000002099F30E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2099F30E000
|
Size: |
4096
|
|
477000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1022108091.0000000000477000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
477000
|
Size: |
20480
|
|
3F42000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1019775022.0000000003F42000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3F42000
|
Size: |
40960
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1090776627.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196857725.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
3A49000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915648029.0000000003A49000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A49000
|
Size: |
4096
|
|
145E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1089121474.000000000145E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
145E000
|
Size: |
94208
|
|
4EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1207607707.00000000004EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EE000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
7702000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.0000000007702000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7702000
|
Size: |
4096
|
|
2099F140000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1315036431.000002099F140000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2099F140000
|
Size: |
12288
|
|
39FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1019529672.00000000039FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
39FF000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1090979142.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
440000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942539956.0000000000440000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
440000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091184888.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1198043117.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197635746.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1210743593.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
3612000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017998130.0000000003612000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3612000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193482629.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
2F62000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361395202.0000000002F62000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2F62000
|
Size: |
4096
|
|
B5D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3361658075.0000000000B5D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
B5D000
|
Size: |
458752
|
|
3A49000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.917342166.0000000003A49000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A49000
|
Size: |
4096
|
|
F7B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918809788.0000000000F7B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F7B000
|
Size: |
4096
|
|
541000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.0000000000541000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
541000
|
Size: |
8192
|
|
12D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1089012346.00000000012D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
12D0000
|
Size: |
16384
|
|
12E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3360267886.00000000012E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12E0000
|
Size: |
12288
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197960125.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193812514.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
3A49000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915112106.0000000003A49000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A49000
|
Size: |
4096
|
|
3780000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915906521.0000000003780000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3780000
|
Size: |
1187840
|
|
476000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1021991344.0000000000476000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
476000
|
Size: |
24576
|
|
3ECD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1019775022.0000000003ECD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3ECD000
|
Size: |
4096
|
|
145A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3360676106.000000000145A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
145A000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091472191.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194258616.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091250701.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091626285.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
1250000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3359947568.0000000001250000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1250000
|
Size: |
4096
|
|
3756000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362363098.0000000003756000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3756000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194339051.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
190000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942454984.0000000000190000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
190000
|
Size: |
4096
|
|
2099F303000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1315086379.000002099F303000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2099F303000
|
Size: |
16384
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.923675765.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
69632
|
|
31B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.886817920.00000000031B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31B3000
|
Size: |
679936
|
|
6B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3361110712.00000000006B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B0000
|
Size: |
4096
|
|
4EE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.00000000004EE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4EE000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.928740195.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
200704
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194094278.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193889953.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
8E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3360433474.00000000008E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8E0000
|
Size: |
32768
|
|
76CC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.00000000076CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76CC000
|
Size: |
4096
|
|
83D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918343104.000000000083D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83D000
|
Size: |
12288
|
|
3605000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.921685148.0000000003605000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3605000
|
Size: |
49152
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1198292830.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194311111.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
3624000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1018692596.0000000003624000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3624000
|
Size: |
20480
|
|
9D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1035366036.00000000009D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9D0000
|
Size: |
172032
|
|
BD5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.885605869.0000000000BD5000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BD5000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
BD5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.918506495.0000000000BD5000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BD5000
|
Size: |
40960
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194637739.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3A4D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916068351.0000000003A4D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A4D000
|
Size: |
458752
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.936032721.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
69632
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1192611730.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
103A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1088781933.000000000103A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
103A000
|
Size: |
24576
|
|
2099D720000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1314923338.000002099D720000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2099D720000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195982895.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
1031000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.887467285.0000000001031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1031000
|
Size: |
598016
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196054339.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
1325000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3360456009.0000000001325000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1325000
|
Size: |
12288
|
|
3A4D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915648029.0000000003A4D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A4D000
|
Size: |
458752
|
|
150000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3359203626.0000000000150000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
150000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196275110.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3D2D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1019775022.0000000003D2D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3D2D000
|
Size: |
458752
|
|
362A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1018692596.000000000362A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
362A000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091441393.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197443877.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
2099D650000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.1314805597.000002099D650000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
2099D650000
|
Size: |
122880
|
|
3920000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916499951.0000000003920000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3920000
|
Size: |
1196032
|
|
470A000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362363098.000000000470A000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
470A000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
F7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918809788.0000000000F7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F7E000
|
Size: |
118784
|
|
76F9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.00000000076F9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76F9000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195941748.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
1160000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3359817188.0000000001160000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1160000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1037795725.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
233472
|
|
129E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3359999307.000000000129E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
129E000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197550955.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
2099F312000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1315086379.000002099F312000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2099F312000
|
Size: |
8192
|
|
2FB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.886948332.0000000002FB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FB4000
|
Size: |
1331200
|
|
307C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361395202.000000000307C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
307C000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197691608.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193015870.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
38FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1019409988.00000000038FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
38FE000
|
Size: |
8192
|
|
3400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017920542.0000000003400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3400000
|
Size: |
4096
|
|
4122000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361395202.0000000004122000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4122000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1192560289.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196670300.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
12A1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1088968891.00000000012A1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
12A1000
|
Size: |
12288
|
|
2F02000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362363098.0000000002F02000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
2F02000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193454287.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1192668174.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091580526.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
1E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918251092.00000000001E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1E0000
|
Size: |
8192
|
|
3617000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017998130.0000000003617000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3617000
|
Size: |
12288
|
|
7DB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918267893.00000000007DB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7DB000
|
Size: |
20480
|
|
3C6C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361395202.0000000003C6C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3C6C000
|
Size: |
4096
|
|
1F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359598433.00000000001F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F0000
|
Size: |
16384
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193206183.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3B9E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.923429419.0000000003B9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3B9E000
|
Size: |
24576
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.932766204.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
69632
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197418029.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197229289.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
11A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942385385.000000000011A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
11A000
|
Size: |
24576
|
|
48B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.000000000048B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
48B000
|
Size: |
167936
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1210825620.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
180000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942440842.0000000000180000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
180000
|
Size: |
4096
|
|
7680000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.0000000007680000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7680000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195840623.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197798719.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
481000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000006.00000002.3359080259.0000000000481000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
481000
|
Size: |
57344
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195488810.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
FE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.919141137.0000000000FE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FE3000
|
Size: |
73728
|
|
D80000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3359280996.0000000000D80000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
D80000
|
Size: |
4096
|
|
323C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361395202.000000000323C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
323C000
|
Size: |
53248
|
|
3370000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.927837370.0000000003370000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3370000
|
Size: |
172032
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.923852964.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
200704
|
|
2099D750000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1314942353.000002099D750000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2099D750000
|
Size: |
20480
|
|
4E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.00000000004E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E1000
|
Size: |
8192
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.936780180.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
233472
|
|
4A8E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361395202.0000000004A8E000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4A8E000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195589670.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.928495959.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
135168
|
|
76EF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.00000000076EF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76EF000
|
Size: |
4096
|
|
3280000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017827245.0000000003280000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3280000
|
Size: |
4096
|
|
76E8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.00000000076E8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76E8000
|
Size: |
12288
|
|
CFD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3361658075.0000000000CFD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
CFD000
|
Size: |
4096
|
|
1D8BC000
|
system
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1313448559.000000001D8BC000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
1D8BC000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7704000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.0000000007704000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7704000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195254597.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
7695000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.0000000007695000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7695000
|
Size: |
8192
|
|
499000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1088697531.0000000000499000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
499000
|
Size: |
61440
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197042318.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
4446000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361395202.0000000004446000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4446000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196207038.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196011428.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
145E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3360676106.000000000145E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
145E000
|
Size: |
94208
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.923981629.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
233472
|
|
3ABE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916499951.0000000003ABE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3ABE000
|
Size: |
24576
|
|
48F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3359927066.000000000048F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
48F000
|
Size: |
28672
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091070573.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
CDE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.887096330.0000000000CDE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CDE000
|
Size: |
679936
|
|
B21000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.885549515.0000000000B21000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
B21000
|
Size: |
581632
|
|
46B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1022491391.000000000046B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
46B000
|
Size: |
28672
|
|
2D20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1089251711.0000000002D20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D20000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196320034.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
61A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3360230218.000000000061A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
61A000
|
Size: |
8192
|
|
2099D757000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1314942353.000002099D757000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2099D757000
|
Size: |
73728
|
|
481000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000002.3359866188.0000000000481000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
481000
|
Size: |
57344
|
|
471000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1022548716.0000000000471000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
471000
|
Size: |
4096
|
|
2099D783000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1266079504.000002099D783000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2099D783000
|
Size: |
24576
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197148206.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194610631.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197015183.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
472000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1022220249.0000000000472000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
472000
|
Size: |
20480
|
|
46D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1022143484.000000000046D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
46D000
|
Size: |
40960
|
|
76C6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.00000000076C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76C6000
|
Size: |
12288
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1024507135.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
65536
|
|
38A3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.917648133.00000000038A3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38A3000
|
Size: |
507904
|
|
38A3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916809030.00000000038A3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38A3000
|
Size: |
507904
|
|
3230000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017796175.0000000003230000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3230000
|
Size: |
4096
|
|
4DB2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361395202.0000000004DB2000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4DB2000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1028946708.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
229376
|
|
220F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942817145.000000000220F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
220F000
|
Size: |
4096
|
|
129E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1088949333.000000000129E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
129E000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197522902.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
5AC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942636268.00000000005AC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5AC000
|
Size: |
16384
|
|
3D9E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1019775022.0000000003D9E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3D9E000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197933699.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193785108.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.928359984.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
69632
|
|
CE0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918771207.0000000000CE0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
CE0000
|
Size: |
290816
|
|
3780000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916351738.0000000003780000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3780000
|
Size: |
1187840
|
|
B21000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.918457185.0000000000B21000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
B21000
|
Size: |
581632
|
|
D90000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3359350680.0000000000D90000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
D90000
|
Size: |
4096
|
|
170000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.942428447.0000000000170000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
170000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197121537.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
3605000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.921802107.0000000003605000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3605000
|
Size: |
49152
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1210887160.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
768B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.000000000768B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
768B000
|
Size: |
8192
|
|
3BFD000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3361032659.0000000003BFD000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3BFD000
|
Size: |
4538368
|
|
2099F4C4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1265999963.000002099F4C4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2099F4C4000
|
Size: |
24576
|
|
BE8000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.918558833.0000000000BE8000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BE8000
|
Size: |
892928
|
|
480000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.3359804317.0000000000480000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
480000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091407370.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
199F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.919269766.000000000199F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
199F000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195383984.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3920000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916068351.0000000003920000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3920000
|
Size: |
1196032
|
|
3A49000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.916068351.0000000003A49000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A49000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196904720.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
1A1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.942467396.00000000001A1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A1000
|
Size: |
12288
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193072879.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
BDF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.918542871.0000000000BDF000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
BDF000
|
Size: |
36864
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195767703.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
2099F4B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1266037292.000002099F4B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2099F4B0000
|
Size: |
8192
|
|
2099D677000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.1314805597.000002099D677000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
2099D677000
|
Size: |
4096
|
|
4578000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362363098.0000000004578000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4578000
|
Size: |
4096
|
|
3A4D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915112106.0000000003A4D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A4D000
|
Size: |
458752
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193097872.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
769D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.000000000769D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
769D000
|
Size: |
8192
|
|
3617000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.921752783.0000000003617000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3617000
|
Size: |
20480
|
|
9B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3358976281.000000000009B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9B000
|
Size: |
20480
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197308913.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
3FA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.935830619.0000000003FA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3FA0000
|
Size: |
172032
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1029093758.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
2099F030000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1264761732.000002099F030000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2099F030000
|
Size: |
4096
|
|
1F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1028998004.00000000001F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F4000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194365599.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193607952.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197578814.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
3780000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.914983615.0000000003780000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3780000
|
Size: |
1187840
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1090907052.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3ED1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.1019775022.0000000003ED1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3ED1000
|
Size: |
458752
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197174806.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
5A47FFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1314785605.0000005A47FFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A47FFE000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197068542.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
43E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.942524834.000000000043E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
43E000
|
Size: |
8192
|
|
5A477FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1314768237.0000005A477FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A477FE000
|
Size: |
8192
|
|
76C2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.00000000076C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
76C2000
|
Size: |
8192
|
|
476000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1021941402.0000000000476000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
476000
|
Size: |
24576
|
|
2E6F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1089315290.0000000002E6F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E6F000
|
Size: |
4096
|
|
1034000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.919141137.0000000001034000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1034000
|
Size: |
69632
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091693956.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
860000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3361387759.0000000000860000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
860000
|
Size: |
16384
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194817056.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195741393.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194148990.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1196236855.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
E60000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3359482578.0000000000E60000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
E60000
|
Size: |
4096
|
|
BE8000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.885673807.0000000000BE8000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BE8000
|
Size: |
892928
|
|
33EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017903375.00000000033EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
33EE000
|
Size: |
8192
|
|
5AC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3360139030.00000000005AC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5AC000
|
Size: |
16384
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195333474.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197906824.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
2FBC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017762828.0000000002FBC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FBC000
|
Size: |
16384
|
|
1320000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1089080293.0000000001320000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1320000
|
Size: |
20480
|
|
DA0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3359421326.0000000000DA0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
DA0000
|
Size: |
4096
|
|
DBD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362262797.0000000000DBD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DBD000
|
Size: |
12288
|
|
50D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.000000000050D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
50D000
|
Size: |
4096
|
|
3A7A000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3362363098.0000000003A7A000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3A7A000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197745936.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
1079000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.887578509.0000000001079000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1079000
|
Size: |
450560
|
|
4DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.00000000004DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DC000
|
Size: |
12288
|
|
7686000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3364416525.0000000007686000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7686000
|
Size: |
8192
|
|
5737000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3363348707.0000000005737000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5737000
|
Size: |
40960
|
|
1F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1029017628.00000000001F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F4000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194284638.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
1003000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.887405023.0000000001003000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1003000
|
Size: |
389120
|
|
4E1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1207607707.00000000004E1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E1000
|
Size: |
8192
|
|
480000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3358965913.0000000000480000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
480000
|
Size: |
4096
|
|
56C4000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000006.00000002.3363348707.00000000056C4000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
56C4000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
148D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3360676106.000000000148D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
148D000
|
Size: |
16384
|
|
90000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.942216941.0000000000090000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
90000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193151474.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
18E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1089201840.00000000018E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
18E0000
|
Size: |
352256
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193124540.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
468000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.0000000000468000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
468000
|
Size: |
12288
|
|
440000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3359690005.0000000000440000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
440000
|
Size: |
4096
|
|
3A01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1019617576.0000000003A01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3A01000
|
Size: |
8192
|
|
2099D710000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1314904023.000002099D710000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2099D710000
|
Size: |
4096
|
|
3A00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.923429419.0000000003A00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3A00000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2099F200000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1315053143.000002099F200000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2099F200000
|
Size: |
4096
|
|
101F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.919141137.000000000101F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
101F000
|
Size: |
61440
|
|
523000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.0000000000523000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
523000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194232357.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091295810.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195564823.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
5A45FFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1314701802.0000005A45FFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A45FFC000
|
Size: |
16384
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193177865.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.921429523.0000000003800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3800000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195305514.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
499000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.942619408.0000000000499000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
499000
|
Size: |
61440
|
|
61E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3360230218.000000000061E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
61E000
|
Size: |
139264
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
12E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1089035894.00000000012E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12E0000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1091107143.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3600000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.1017979874.0000000003600000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3600000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3413000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.936125906.0000000003413000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3413000
|
Size: |
135168
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194843457.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
1160000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000000.1088865033.0000000001160000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1160000
|
Size: |
4096
|
|
113C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000006.00000000.1088804036.000000000113C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
113C000
|
Size: |
16384
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1193573130.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
2099F010000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1315022023.000002099F010000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2099F010000
|
Size: |
4096
|
|
460000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.0000000000460000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
460000
|
Size: |
24576
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197771822.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
1430000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3360623512.0000000001430000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1430000
|
Size: |
4096
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1197363272.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
1DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359426767.00000000001DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1DE000
|
Size: |
8192
|
|
3ABE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915112106.0000000003ABE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3ABE000
|
Size: |
24576
|
|
3B2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.923429419.0000000003B2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3B2D000
|
Size: |
458752
|
|
511000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3359764476.0000000000511000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
511000
|
Size: |
12288
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194474592.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
A1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1024300581.0000000000A1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A1A000
|
Size: |
24576
|
|
12D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000006.00000002.3360203845.00000000012D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
12D0000
|
Size: |
16384
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1194447371.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
8192
|
|
31A4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.919283892.00000000031A4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31A4000
|
Size: |
8192
|
|
D01000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3361658075.0000000000D01000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
D01000
|
Size: |
458752
|
|
2D20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361079748.0000000002D20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D20000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195539914.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
2099D76D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1314942353.000002099D76D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2099D76D000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
3624000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3361395202.0000000003624000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3624000
|
Size: |
8192
|
|
1C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3359551550.00000000001C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C0000
|
Size: |
20480
|
|
588C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000006.00000002.3363642543.000000000588C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
6
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
588C000
|
Size: |
16384
|
|
2099F030000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1265360200.000002099F030000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2099F030000
|
Size: |
4096
|
|
2099F4BE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1265999963.000002099F4BE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2099F4BE000
|
Size: |
8192
|
|
6B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.1195515197.00000000006B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B1000
|
Size: |
4096
|
|
3923000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.921429523.0000000003923000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3923000
|
Size: |
507904
|
|
2100000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3360618641.0000000002100000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2100000
|
Size: |
8192
|
|
38A3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.915517154.00000000038A3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38A3000
|
Size: |
507904
|
|