2B81000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000003.00000002.3375452065.0000000002B81000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B81000
|
Size: |
688128
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
URLs found in memory or binary data |
Networking |
|
|
44A8000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000000.00000002.954465088.00000000044A8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
44A8000
|
Size: |
2387968
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
2D4E000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000003.00000002.3375452065.0000000002D4E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D4E000
|
Size: |
348160
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
|
2E14000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000003.00000002.3375452065.0000000002E14000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E14000
|
Size: |
311296
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Telegram RAT |
Stealing of Sensitive Information, Remote Access Functionality |
|
URLs found in memory or binary data |
Networking |
|
|
2DDE000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000003.00000002.3375452065.0000000002DDE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DDE000
|
Size: |
122880
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
|
402000
|
remote allocation
|
page execute and read and write
|
 |
|
|
Name: |
00000003.00000002.3373725870.0000000000402000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
402000
|
Size: |
139264
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
3320000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952939180.0000000003320000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3320000
|
Size: |
65536
|
|
3250000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.952611171.0000000003250000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
3250000
|
Size: |
4096
|
|
4FDE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377337608.0000000004FDE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FDE000
|
Size: |
4096
|
|
5B10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.962508321.0000000005B10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B10000
|
Size: |
4096
|
|
30F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952258389.00000000030F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30F0000
|
Size: |
40960
|
|
2CC6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002CC6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CC6000
|
Size: |
8192
|
|
400000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3373725870.0000000000400000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
4096
|
|
797E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.965261358.000000000797E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
797E000
|
Size: |
8192
|
|
12C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375402438.00000000012C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12C0000
|
Size: |
16384
|
|
2CCB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002CCB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CCB000
|
Size: |
4096
|
|
BACE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.966246917.000000000BACE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BACE000
|
Size: |
8192
|
|
DF2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374535393.0000000000DF2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
DF2000
|
Size: |
4096
|
|
11A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375213002.00000000011A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11A0000
|
Size: |
4096
|
|
1330000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951717436.0000000001330000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1330000
|
Size: |
8192
|
|
3220000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952568492.0000000003220000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3220000
|
Size: |
4096
|
|
105E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375161639.000000000105E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
105E000
|
Size: |
8192
|
|
60D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378059457.00000000060D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
60D0000
|
Size: |
348160
|
|
BDCD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.966365140.000000000BDCD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BDCD000
|
Size: |
12288
|
|
7CA2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.965750286.0000000007CA2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7CA2000
|
Size: |
32768
|
|
2D12000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002D12000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D12000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
BBCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.966278281.000000000BBCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BBCE000
|
Size: |
8192
|
|
7B0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.965622473.0000000007B0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7B0E000
|
Size: |
8192
|
|
79B0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.965365648.00000000079B0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
79B0000
|
Size: |
413696
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
32A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952657152.00000000032A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32A0000
|
Size: |
65536
|
|
32D1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952684049.00000000032D1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32D1000
|
Size: |
16384
|
|
59C0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.962195331.00000000059C0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
59C0000
|
Size: |
65536
|
|
E80000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.900869237.0000000000E80000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E80000
|
Size: |
4096
|
|
5140000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3377678782.0000000005140000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5140000
|
Size: |
65536
|
|
5090000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377630708.0000000005090000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5090000
|
Size: |
65536
|
|
570B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377914401.000000000570B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
570B000
|
Size: |
20480
|
|
3C19000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377029386.0000000003C19000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C19000
|
Size: |
122880
|
|
DF5000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3374565953.0000000000DF5000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
DF5000
|
Size: |
4096
|
|
6134000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378059457.0000000006134000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6134000
|
Size: |
86016
|
|
2C32000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002C32000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C32000
|
Size: |
32768
|
|
3BE8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377029386.0000000003BE8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3BE8000
|
Size: |
4096
|
|
7BED000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.965678358.0000000007BED000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7BED000
|
Size: |
12288
|
|
2C44000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002C44000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C44000
|
Size: |
8192
|
|
2DDA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002DDA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DDA000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
5A10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.962436695.0000000005A10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A10000
|
Size: |
4096
|
|
1633000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.952139659.0000000001633000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1633000
|
Size: |
4096
|
|
3BA9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377029386.0000000003BA9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3BA9000
|
Size: |
176128
|
|
3100000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952289970.0000000003100000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3100000
|
Size: |
4096
|
|
5C30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.963041528.0000000005C30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5C30000
|
Size: |
28672
|
|
5ED0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.963396591.0000000005ED0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5ED0000
|
Size: |
12288
|
|
DC3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3374250067.0000000000DC3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
DC3000
|
Size: |
4096
|
|
D5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374072615.0000000000D5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D5E000
|
Size: |
8192
|
|
3310000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952899394.0000000003310000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3310000
|
Size: |
16384
|
|
7980000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.965279103.0000000007980000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
7980000
|
Size: |
69632
|
|
11C0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3375239886.00000000011C0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
11C0000
|
Size: |
65536
|
|
644E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378441856.000000000644E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
644E000
|
Size: |
8192
|
|
65F0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3378692090.00000000065F0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
65F0000
|
Size: |
65536
|
|
14A8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951812367.00000000014A8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14A8000
|
Size: |
49152
|
|
311B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.952472227.000000000311B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
311B000
|
Size: |
4096
|
|
2CCF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002CCF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CCF000
|
Size: |
4096
|
|
2C5F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002C5F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C5F000
|
Size: |
77824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1380000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951749424.0000000001380000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1380000
|
Size: |
16384
|
|
1630000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952124491.0000000001630000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1630000
|
Size: |
8192
|
|
4441000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.954465088.0000000004441000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4441000
|
Size: |
28672
|
|
1460000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951779727.0000000001460000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1460000
|
Size: |
20480
|
|
148E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951812367.000000000148E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
148E000
|
Size: |
102400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
32DD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952684049.00000000032DD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32DD000
|
Size: |
69632
|
|
1385000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951749424.0000000001385000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1385000
|
Size: |
12288
|
|
329C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952637466.000000000329C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
329C000
|
Size: |
16384
|
|
32D6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952684049.00000000032D6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32D6000
|
Size: |
16384
|
|
2C74000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002C74000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C74000
|
Size: |
12288
|
|
15FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952089963.00000000015FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15FE000
|
Size: |
8192
|
|
5C20000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.962988319.0000000005C20000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5C20000
|
Size: |
65536
|
|
628E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378369882.000000000628E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
628E000
|
Size: |
8192
|
|
11E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375308384.00000000011E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
11E0000
|
Size: |
4096
|
|
155B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951994790.000000000155B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
155B000
|
Size: |
36864
|
|
5B7B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.962735964.0000000005B7B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5B7B000
|
Size: |
20480
|
|
5ED5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.963396591.0000000005ED5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5ED5000
|
Size: |
40960
|
|
553D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.958233249.000000000553D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
553D000
|
Size: |
12288
|
|
2D31000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002D31000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D31000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
56FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377894336.00000000056FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
56FE000
|
Size: |
8192
|
|
4FC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377337608.0000000004FC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FC0000
|
Size: |
20480
|
|
163D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.952172096.000000000163D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
163D000
|
Size: |
4096
|
|
4C7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377318312.0000000004C7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C7E000
|
Size: |
8192
|
|
4FF2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377337608.0000000004FF2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FF2000
|
Size: |
49152
|
|
5163000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377781515.0000000005163000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5163000
|
Size: |
8192
|
|
2DFD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002DFD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DFD000
|
Size: |
4096
|
|
2C2A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002C2A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C2A000
|
Size: |
28672
|
|
3315000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952899394.0000000003315000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3315000
|
Size: |
45056
|
|
5A00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.962337797.0000000005A00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5A00000
|
Size: |
65536
|
|
2B6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375422912.0000000002B6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B6E000
|
Size: |
8192
|
|
14C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951812367.00000000014C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14C7000
|
Size: |
352256
|
|
58F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.961087283.00000000058F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
58F0000
|
Size: |
4096
|
|
3C03000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377029386.0000000003C03000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C03000
|
Size: |
8192
|
|
D85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374134137.0000000000D85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D85000
|
Size: |
12288
|
|
A89000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3373901760.0000000000A89000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A89000
|
Size: |
28672
|
|
DE6000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3374485486.0000000000DE6000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
DE6000
|
Size: |
8192
|
|
2CE8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002CE8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CE8000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2CF6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002CF6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CF6000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
15BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952070346.00000000015BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15BE000
|
Size: |
8192
|
|
D60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374104633.0000000000D60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D60000
|
Size: |
8192
|
|
3117000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.952436738.0000000003117000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
3117000
|
Size: |
4096
|
|
32BB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952684049.00000000032BB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32BB000
|
Size: |
69632
|
|
34B8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952994858.00000000034B8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
34B8000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
655B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378476195.000000000655B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
655B000
|
Size: |
16384
|
|
B87000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3373937851.0000000000B87000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B87000
|
Size: |
36864
|
|
515E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377727125.000000000515E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
515E000
|
Size: |
8192
|
|
6630000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3378751715.0000000006630000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6630000
|
Size: |
24576
|
|
32CE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952684049.00000000032CE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32CE000
|
Size: |
8192
|
|
E96000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374675013.0000000000E96000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E96000
|
Size: |
462848
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
DDD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3374402615.0000000000DDD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
DDD000
|
Size: |
4096
|
|
3106000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.952319529.0000000003106000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
3106000
|
Size: |
8192
|
|
5EBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.963297372.0000000005EBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5EBE000
|
Size: |
8192
|
|
77C4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.965054540.00000000077C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77C4000
|
Size: |
241664
|
|
DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374348236.0000000000DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
DD0000
|
Size: |
49152
|
|
2E72000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002E72000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E72000
|
Size: |
32768
|
|
5A13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.962436695.0000000005A13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A13000
|
Size: |
12288
|
|
5C00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.962832246.0000000005C00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5C00000
|
Size: |
65536
|
|
5710000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3377991723.0000000005710000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5710000
|
Size: |
65536
|
|
6620000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378734445.0000000006620000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6620000
|
Size: |
4096
|
|
156A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951994790.000000000156A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
156A000
|
Size: |
86016
|
|
3300000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952858508.0000000003300000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3300000
|
Size: |
65536
|
|
2C7E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002C7E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C7E000
|
Size: |
4096
|
|
4FED000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377337608.0000000004FED000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FED000
|
Size: |
16384
|
|
59F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.962319710.00000000059F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59F0000
|
Size: |
4096
|
|
E60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374675013.0000000000E60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E60000
|
Size: |
28672
|
|
4449000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.954465088.0000000004449000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4449000
|
Size: |
4096
|
|
343E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952979219.000000000343E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
343E000
|
Size: |
8192
|
|
4FE1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377337608.0000000004FE1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FE1000
|
Size: |
16384
|
|
5150000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377727125.0000000005150000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5150000
|
Size: |
53248
|
|
1565000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951994790.0000000001565000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1565000
|
Size: |
16384
|
|
2CDB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002CDB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CDB000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5E0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.963230477.0000000005E0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5E0E000
|
Size: |
8192
|
|
4FC6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377337608.0000000004FC6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FC6000
|
Size: |
8192
|
|
7B4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.965646327.0000000007B4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7B4E000
|
Size: |
8192
|
|
4469000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.954465088.0000000004469000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4469000
|
Size: |
176128
|
|
E68000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374675013.0000000000E68000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E68000
|
Size: |
135168
|
|
5C60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.963207524.0000000005C60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C60000
|
Size: |
8192
|
|
2DC2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002DC2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DC2000
|
Size: |
4096
|
|
6570000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3378595017.0000000006570000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6570000
|
Size: |
4096
|
|
7C2D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.965708242.0000000007C2D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7C2D000
|
Size: |
12288
|
|
2CBE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002CBE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CBE000
|
Size: |
8192
|
|
30FD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.952275300.00000000030FD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
30FD000
|
Size: |
4096
|
|
2CD7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002CD7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CD7000
|
Size: |
12288
|
|
2DD5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002DD5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DD5000
|
Size: |
4096
|
|
1620000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952107627.0000000001620000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1620000
|
Size: |
8192
|
|
F11000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374675013.0000000000F11000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F11000
|
Size: |
8192
|
|
D80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374134137.0000000000D80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D80000
|
Size: |
16384
|
|
6560000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378538841.0000000006560000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6560000
|
Size: |
65536
|
|
65B5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.963593301.00000000065B5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
65B5000
|
Size: |
4096
|
|
11F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375350387.00000000011F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11F0000
|
Size: |
4096
|
|
11E4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375308384.00000000011E4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
11E4000
|
Size: |
49152
|
|
3441000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952994858.0000000003441000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3441000
|
Size: |
479232
|
|
6580000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378611746.0000000006580000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6580000
|
Size: |
57344
|
|
506D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377609302.000000000506D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
506D000
|
Size: |
12288
|
|
F47000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375107366.0000000000F47000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F47000
|
Size: |
98304
|
|
BFCF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.966405119.000000000BFCF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BFCF000
|
Size: |
4096
|
|
612B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378059457.000000000612B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
612B000
|
Size: |
4096
|
|
3B81000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377029386.0000000003B81000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B81000
|
Size: |
32768
|
|
7C6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.965731183.0000000007C6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7C6E000
|
Size: |
8192
|
|
1558000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951994790.0000000001558000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1558000
|
Size: |
8192
|
|
59E0000
|
trusted library section
|
page readonly
|
|
|
|
Name: |
00000000.00000002.962284910.00000000059E0000.00000002.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page readonly
|
Base address: |
59E0000
|
Size: |
61440
|
|
DFB000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3374635250.0000000000DFB000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
DFB000
|
Size: |
4096
|
|
DF7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3374602147.0000000000DF7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
DF7000
|
Size: |
4096
|
|
32B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952684049.00000000032B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32B0000
|
Size: |
32768
|
|
3188000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952534898.0000000003188000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3188000
|
Size: |
4096
|
|
BDD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.966387234.000000000BDD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BDD0000
|
Size: |
4096
|
|
6128000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378059457.0000000006128000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6128000
|
Size: |
8192
|
|
DC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374223165.0000000000DC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
DC0000
|
Size: |
8192
|
|
58E0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.958517988.00000000058E0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
58E0000
|
Size: |
65536
|
|
2D2E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002D2E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D2E000
|
Size: |
4096
|
|
6640000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378777104.0000000006640000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6640000
|
Size: |
8192
|
|
1480000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951812367.0000000001480000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1480000
|
Size: |
49152
|
|
654F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378460112.000000000654F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
654F000
|
Size: |
4096
|
|
2D40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002D40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D40000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
E82000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.900888632.0000000000E82000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E82000
|
Size: |
659456
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
53F0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3377854965.00000000053F0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
53F0000
|
Size: |
4096
|
|
E5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374655691.0000000000E5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E5E000
|
Size: |
8192
|
|
4FCB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377337608.0000000004FCB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FCB000
|
Size: |
8192
|
|
2DB7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002DB7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DB7000
|
Size: |
4096
|
|
6590000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378664327.0000000006590000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6590000
|
Size: |
24576
|
|
2E07000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002E07000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E07000
|
Size: |
16384
|
|
2CD3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002CD3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CD3000
|
Size: |
4096
|
|
4FCE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377337608.0000000004FCE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FCE000
|
Size: |
45056
|
|
638F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378387921.000000000638F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
638F000
|
Size: |
4096
|
|
2C86000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002C86000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C86000
|
Size: |
12288
|
|
174F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952206231.000000000174F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
174F000
|
Size: |
4096
|
|
DE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374431532.0000000000DE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
DE0000
|
Size: |
4096
|
|
194F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952239909.000000000194F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
194F000
|
Size: |
4096
|
|
1467000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951779727.0000000001467000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1467000
|
Size: |
32768
|
|
2E0E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002E0E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E0E000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
77A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.965054540.00000000077A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77A0000
|
Size: |
143360
|
|
115E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375178546.000000000115E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
115E000
|
Size: |
8192
|
|
5C10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.962913667.0000000005C10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5C10000
|
Size: |
65536
|
|
624E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378351108.000000000624E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
624E000
|
Size: |
8192
|
|
6550000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378476195.0000000006550000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6550000
|
Size: |
24576
|
|
151F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951812367.000000000151F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
151F000
|
Size: |
32768
|
|
2E01000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002E01000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E01000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
119E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375195946.000000000119E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
119E000
|
Size: |
8192
|
|
640E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378422874.000000000640E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
640E000
|
Size: |
8192
|
|
137E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951733900.000000000137E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
137E000
|
Size: |
8192
|
|
4FDA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377337608.0000000004FDA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FDA000
|
Size: |
4096
|
|
60CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378041488.00000000060CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60CE000
|
Size: |
8192
|
|
5EC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.963321202.0000000005EC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5EC0000
|
Size: |
65536
|
|
7A40000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.965525980.0000000007A40000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7A40000
|
Size: |
45056
|
|
58FD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.961087283.00000000058FD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
58FD000
|
Size: |
12288
|
|
DE2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374461176.0000000000DE2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
DE2000
|
Size: |
4096
|
|
DCD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3374320456.0000000000DCD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
DCD000
|
Size: |
4096
|
|
317E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952517909.000000000317E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
317E000
|
Size: |
8192
|
|
2CBA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002CBA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CBA000
|
Size: |
8192
|
|
2C82000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002C82000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C82000
|
Size: |
4096
|
|
14C4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951812367.00000000014C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14C4000
|
Size: |
4096
|
|
2B70000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3375438516.0000000002B70000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2B70000
|
Size: |
4096
|
|
5708000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377914401.0000000005708000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5708000
|
Size: |
8192
|
|
79A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.965321190.00000000079A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79A0000
|
Size: |
65536
|
|
FBA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951658057.0000000000FBA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FBA000
|
Size: |
24576
|
|
C0CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.966425993.000000000C0CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C0CE000
|
Size: |
8192
|
|
11D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375274725.00000000011D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
11D0000
|
Size: |
65536
|
|
3240000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.952584552.0000000003240000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
3240000
|
Size: |
65536
|
|
DEA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.3374504271.0000000000DEA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
DEA000
|
Size: |
8192
|
|
5FC0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.963530772.0000000005FC0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5FC0000
|
Size: |
65536
|
|
58D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.958310886.00000000058D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
58D0000
|
Size: |
4096
|
|
BCCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.966311735.000000000BCCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BCCE000
|
Size: |
8192
|
|
3130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952498755.0000000003130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3130000
|
Size: |
4096
|
|
2DBC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002DBC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DBC000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
3110000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952359069.0000000003110000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3110000
|
Size: |
4096
|
|
93DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.965780262.00000000093DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
93DF000
|
Size: |
4096
|
|
32F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952829461.00000000032F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32F0000
|
Size: |
65536
|
|
4FE6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377337608.0000000004FE6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4FE6000
|
Size: |
16384
|
|
3330000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952962466.0000000003330000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3330000
|
Size: |
4096
|
|
184E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952222508.000000000184E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
184E000
|
Size: |
8192
|
|
620D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378327298.000000000620D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
620D000
|
Size: |
12288
|
|
2DCB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002DCB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DCB000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
3C0D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377029386.0000000003C0D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C0D000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
12A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375365729.00000000012A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
12A0000
|
Size: |
65536
|
|
3112000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952388186.0000000003112000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3112000
|
Size: |
4096
|
|
310A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.952336358.000000000310A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
310A000
|
Size: |
8192
|
|
1634000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952154899.0000000001634000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1634000
|
Size: |
4096
|
|
5B20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.962528801.0000000005B20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5B20000
|
Size: |
65536
|
|
6580000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.963593301.0000000006580000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6580000
|
Size: |
4096
|
|
5C40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.963070161.0000000005C40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5C40000
|
Size: |
40960
|
|
7A8E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.965570233.0000000007A8E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7A8E000
|
Size: |
8192
|
|
2C47000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002C47000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C47000
|
Size: |
77824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
DC4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374281662.0000000000DC4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
DC4000
|
Size: |
8192
|
|
5160000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377781515.0000000005160000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5160000
|
Size: |
4096
|
|
3529000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952994858.0000000003529000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3529000
|
Size: |
4292608
|
|
D10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374037288.0000000000D10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D10000
|
Size: |
16384
|
|
E8A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374675013.0000000000E8A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E8A000
|
Size: |
8192
|
|
5706000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377914401.0000000005706000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5706000
|
Size: |
4096
|
|
5700000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377914401.0000000005700000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5700000
|
Size: |
8192
|
|
1640000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952188533.0000000001640000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1640000
|
Size: |
16384
|
|
5890000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.958262139.0000000005890000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5890000
|
Size: |
65536
|
|
5170000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377823051.0000000005170000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5170000
|
Size: |
4096
|
|
2C8A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002C8A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C8A000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6590000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.963593301.0000000006590000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6590000
|
Size: |
40960
|
|
2C3B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002C3B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C3B000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7ACE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.965591892.0000000007ACE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7ACE000
|
Size: |
8192
|
|
2D04000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002D04000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D04000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
63CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3378403422.00000000063CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63CE000
|
Size: |
8192
|
|
5000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377568155.0000000005000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5000000
|
Size: |
65536
|
|
5900000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.962117305.0000000005900000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5900000
|
Size: |
65536
|
|
D0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374002603.0000000000D0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D0E000
|
Size: |
8192
|
|
5B30000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.962594208.0000000005B30000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5B30000
|
Size: |
4096
|
|
14B5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951812367.00000000014B5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14B5000
|
Size: |
49152
|
|
2CC2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3375452065.0000000002CC2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CC2000
|
Size: |
8192
|
|
54FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3377874033.00000000054FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
54FE000
|
Size: |
8192
|
|
3102000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.952305168.0000000003102000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3102000
|
Size: |
4096
|
|
58F2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.961087283.00000000058F2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
58F2000
|
Size: |
40960
|
|
12F7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951680101.00000000012F7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12F7000
|
Size: |
36864
|
|
BF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3373968794.0000000000BF0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BF0000
|
Size: |
4096
|
|
7680000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.963866706.0000000007680000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7680000
|
Size: |
536576
|
|
1320000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.951698322.0000000001320000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1320000
|
Size: |
4096
|
|
DB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.3374195666.0000000000DB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
DB0000
|
Size: |
8192
|
|