2DB0000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000005.00000002.2538655521.0000000002DB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DB0000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
400000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1543853019.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
286720
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3130000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000004.00000002.2539481222.0000000003130000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3130000
|
Size: |
5591040
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
A00000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000005.00000002.2538448915.0000000000A00000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
A00000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
46B0000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000005.00000002.2539408783.00000000046B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
46B0000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3BA0000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1545176733.0000000003BA0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3BA0000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
4CF0000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000007.00000002.2541345735.0000000004CF0000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4CF0000
|
Size: |
348160
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3BF0000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1545227326.0000000003BF0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3BF0000
|
Size: |
5591040
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
2E2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1545106141.0000000002E2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E2D000
|
Size: |
24576
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1750716555.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741665035.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
3E1D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1311492942.0000000003E1D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E1D000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
7A22000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.0000000007A22000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A22000
|
Size: |
8192
|
|
2EBE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002EBE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EBE000
|
Size: |
16384
|
|
23AE5F0A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861299902.0000023AE5F0A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AE5F0A000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741726974.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1455785100.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
69632
|
|
3CF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1311919242.0000000003CF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3CF0000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
8B9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1632913676.00000000008B9000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8B9000
|
Size: |
61440
|
|
610000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2538618952.0000000000610000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
610000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736622293.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
4D47000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2541345735.0000000004D47000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4D47000
|
Size: |
8192
|
|
79E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1747935015.00000000079E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79E3000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737356393.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
11A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1314865957.00000000011A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11A0000
|
Size: |
20480
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1735873000.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
3E6D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1313750921.0000000003E6D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E6D000
|
Size: |
458752
|
|
2E3F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002E3F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E3F000
|
Size: |
208896
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
C39000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1314735911.0000000000C39000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C39000
|
Size: |
28672
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737584764.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741231989.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
100F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1314753341.000000000100F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
100F000
|
Size: |
4096
|
|
79E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.00000000079E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79E0000
|
Size: |
8192
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1430768504.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
69632
|
|
B8C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1543940700.0000000000B8C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B8C000
|
Size: |
16384
|
|
3E69000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1313750921.0000000003E69000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E69000
|
Size: |
4096
|
|
FFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1462683977.0000000000FFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FFE000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741998751.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2E00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538714668.0000000002E00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
16384
|
|
3B42000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1544662726.0000000003B42000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3B42000
|
Size: |
40960
|
|
F80000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2538671973.0000000000F80000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F80000
|
Size: |
4096
|
|
820000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2538983765.0000000000820000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
820000
|
Size: |
4096
|
|
3219000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1544513646.0000000003219000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3219000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736875500.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738906669.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
137F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1305133502.000000000137F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
137F000
|
Size: |
118784
|
|
4E7C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2540263212.0000000004E7C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4E7C000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737749506.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738728734.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
3AD1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1544662726.0000000003AD1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3AD1000
|
Size: |
458752
|
|
4A04000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1547537202.0000000004A04000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4A04000
|
Size: |
24576
|
|
620000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1632566699.0000000000620000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
620000
|
Size: |
4096
|
|
23AE5D80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1814588442.0000023AE5D80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AE5D80000
|
Size: |
4096
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1456219975.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
253952
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1740951407.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
798000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538417502.0000000000798000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
798000
|
Size: |
32768
|
|
23AE5F03000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861299902.0000023AE5F03000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AE5F03000
|
Size: |
16384
|
|
2440000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1633095345.0000000002440000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2440000
|
Size: |
8192
|
|
FA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1462647412.0000000000FA0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FA0000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736415604.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
23AE60AA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1817604717.0000023AE60AA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AE60AA000
|
Size: |
8192
|
|
2ED1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002ED1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ED1000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
28BC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539938484.00000000028BC000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
28BC000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1350000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1302913519.0000000001350000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1350000
|
Size: |
94208
|
|
5748000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2540263212.0000000005748000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5748000
|
Size: |
4096
|
|
3C73000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1312209297.0000000003C73000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C73000
|
Size: |
507904
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
4BAE000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.2539750371.0000000004BAE000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4BAE000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3CC3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1313147572.0000000003CC3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3CC3000
|
Size: |
507904
|
|
2E7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002E7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E7E000
|
Size: |
4096
|
|
4D60000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2541345735.0000000004D60000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4D60000
|
Size: |
4096
|
|
1360000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1462795801.0000000001360000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1360000
|
Size: |
8192
|
|
FB0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1462668268.0000000000FB0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
FB0000
|
Size: |
4096
|
|
2EBB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002EBB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EBB000
|
Size: |
4096
|
|
7A36000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.0000000007A36000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A36000
|
Size: |
16384
|
|
392D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1544662726.000000000392D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
392D000
|
Size: |
458752
|
|
610000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1632547562.0000000000610000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
610000
|
Size: |
4096
|
|
4B39000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.2539750371.0000000004B39000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4B39000
|
Size: |
4096
|
|
7A19000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.0000000007A19000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A19000
|
Size: |
20480
|
|
23AE60C4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1817562853.0000023AE60C4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AE60C4000
|
Size: |
24576
|
|
3E19000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1311492942.0000000003E19000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E19000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1743239185.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
3B50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1312209297.0000000003B50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B50000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3E1D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1311919242.0000000003E1D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E1D000
|
Size: |
458752
|
|
C70000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1435248905.0000000000C70000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
C70000
|
Size: |
188416
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737848164.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
24F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2539765755.00000000024F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
24F0000
|
Size: |
925696
|
|
2E33000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1545349551.0000000002E33000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E33000
|
Size: |
20480
|
|
101B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1314753341.000000000101B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
101B000
|
Size: |
20480
|
|
687000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1301885397.0000000000687000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
687000
|
Size: |
409600
|
|
EB0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000000.1462521519.0000000000EB0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EB0000
|
Size: |
4096
|
|
7730000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541684339.0000000007730000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7730000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738211209.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1456097782.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
266240
|
|
79FA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.00000000079FA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79FA000
|
Size: |
12288
|
|
A50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538502469.0000000000A50000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A50000
|
Size: |
4096
|
|
BCB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1544069770.0000000000BCB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BCB000
|
Size: |
20480
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1554809627.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2E90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1744179247.0000000002E90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E90000
|
Size: |
16384
|
|
4866000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1547537202.0000000004866000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4866000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
23AE5F00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861271449.0000023AE5F00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AE5F00000
|
Size: |
4096
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1459338476.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
135168
|
|
23AE4560000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861089882.0000023AE4560000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AE4560000
|
Size: |
12288
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738455732.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
8B9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2539182608.00000000008B9000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8B9000
|
Size: |
61440
|
|
1310000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2538837216.0000000001310000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1310000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741634004.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1739931032.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738937283.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
3E8E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1312420544.0000000003E8E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E8E000
|
Size: |
24576
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1430830566.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
135168
|
|
800000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1632791104.0000000000800000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
800000
|
Size: |
4096
|
|
369C000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.2539481222.000000000369C000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
369C000
|
Size: |
4096
|
|
3601000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1544641230.0000000003601000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3601000
|
Size: |
8192
|
|
139E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1315072731.000000000139E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
139E000
|
Size: |
4096
|
|
2444000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539638814.0000000002444000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2444000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741818181.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
8B9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000000.1462501727.00000000008B9000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8B9000
|
Size: |
61440
|
|
4D52000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.2539750371.0000000004D52000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4D52000
|
Size: |
40960
|
|
8A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2539047216.00000000008A0000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8A0000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1735573270.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
600000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2538591166.0000000000600000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
600000
|
Size: |
4096
|
|
1447000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1315171974.0000000001447000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1447000
|
Size: |
163840
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1739312597.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
7A32000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.0000000007A32000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A32000
|
Size: |
12288
|
|
4840000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1634886555.0000000004840000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4840000
|
Size: |
184320
|
|
7A40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.0000000007A40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A40000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738075824.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737200243.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
16C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000000.1462984455.00000000016C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
16C0000
|
Size: |
40960
|
|
134B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1314954706.000000000134B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
134B000
|
Size: |
16384
|
|
1301000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2538814573.0000000001301000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1301000
|
Size: |
12288
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737652650.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
23AE45A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861116140.0000023AE45A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AE45A0000
|
Size: |
36864
|
|
399E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1544662726.000000000399E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
399E000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2E82000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1744179247.0000000002E82000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E82000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
37A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1315260248.00000000037A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
37A0000
|
Size: |
286720
|
|
23AE5F10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861299902.0000023AE5F10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AE5F10000
|
Size: |
16384
|
|
2E96000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1744179247.0000000002E96000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E96000
|
Size: |
16384
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1739347732.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742826778.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
5E3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2538535313.00000000005E3000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5E3000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742155281.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1740485102.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
CAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1544322327.0000000000CAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CAE000
|
Size: |
8192
|
|
79BE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1743127417.00000000079BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79BE000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
75E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2538730048.000000000075E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
75E000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736715982.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
1364000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1462795801.0000000001364000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1364000
|
Size: |
4096
|
|
41C4000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1545227326.00000000041C4000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
41C4000
|
Size: |
5005312
|
|
8AF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1632870764.00000000008AF000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8AF000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1743358354.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
3BA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1507095848.0000000003BA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3BA0000
|
Size: |
188416
|
|
2440000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539638814.0000000002440000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2440000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738662880.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737980740.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
14CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1462928613.00000000014CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
14CE000
|
Size: |
8192
|
|
3729000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1430569512.0000000003729000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3729000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738176411.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2E2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1545426383.0000000002E2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E2D000
|
Size: |
24576
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736906736.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
4CE1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.2539750371.0000000004CE1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4CE1000
|
Size: |
458752
|
|
3000000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1544419149.0000000003000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3000000
|
Size: |
4096
|
|
811E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2544079360.000000000811E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
811E000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742028169.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
5C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1314522721.00000000005C0000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5C0000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741574739.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738872782.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741387256.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
3D40000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1312842801.0000000003D40000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D40000
|
Size: |
1196032
|
|
2E10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002E10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E10000
|
Size: |
20480
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742467687.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
8A1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000007.00000000.1632823762.00000000008A1000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
8A1000
|
Size: |
57344
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742977111.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
13C9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1302323517.00000000013C9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13C9000
|
Size: |
131072
|
|
7D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2538838446.00000000007D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D0000
|
Size: |
16384
|
|
6C54FFB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1860733640.0000006C54FFB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6C54FFB000
|
Size: |
20480
|
|
5C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1301665461.00000000005C0000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
5C0000
|
Size: |
4096
|
|
498F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1547537202.000000000498F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
498F000
|
Size: |
4096
|
|
3217000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1428879673.0000000003217000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3217000
|
Size: |
20480
|
|
32EC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539938484.00000000032EC000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
32EC000
|
Size: |
4096
|
|
630000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1632593166.0000000000630000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
630000
|
Size: |
4096
|
|
8AF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2539111842.00000000008AF000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8AF000
|
Size: |
28672
|
|
7BFD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2543434511.0000000007BFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7BFD000
|
Size: |
12288
|
|
1333000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1302459055.0000000001333000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1333000
|
Size: |
49152
|
|
2CA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1632455914.00000000002CA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2CA000
|
Size: |
24576
|
|
1301000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000000.1462724226.0000000001301000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1301000
|
Size: |
12288
|
|
F3A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2538617107.0000000000F3A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F3A000
|
Size: |
24576
|
|
4CDD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.2539750371.0000000004CDD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4CDD000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737553264.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2E82000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002E82000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E82000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742623210.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
8A1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000004.00000002.2538417281.00000000008A1000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
8A1000
|
Size: |
57344
|
|
379E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1430569512.000000000379E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
379E000
|
Size: |
24576
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742722758.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
8B6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539155194.00000000008B6000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8B6000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741845770.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
A0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539249260.0000000000A0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A0E000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742399433.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738801168.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742276548.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
4F2C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2541940742.0000000004F2C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4F2C000
|
Size: |
16384
|
|
2E2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1545477239.0000000002E2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E2D000
|
Size: |
24576
|
|
3D40000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1313750921.0000000003D40000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D40000
|
Size: |
1196032
|
|
809E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2543925927.000000000809E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
809E000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1739892562.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1739846758.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
8AF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2538448928.00000000008AF000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8AF000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3040000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2539336012.0000000003040000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
3040000
|
Size: |
925696
|
|
3C73000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1311779312.0000000003C73000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C73000
|
Size: |
507904
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1735504225.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
674000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1301764902.0000000000674000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
674000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
3B50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1311779312.0000000003B50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B50000
|
Size: |
1187840
|
|
3CF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1312420544.0000000003CF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3CF0000
|
Size: |
1196032
|
|
800000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2538929876.0000000000800000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
800000
|
Size: |
4096
|
|
ED0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2538589311.0000000000ED0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ED0000
|
Size: |
4096
|
|
3030000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1463095575.0000000003030000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3030000
|
Size: |
8192
|
|
79FE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.00000000079FE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79FE000
|
Size: |
16384
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742593347.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
34FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1544588032.00000000034FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
34FE000
|
Size: |
8192
|
|
F70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2538645868.0000000000F70000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F70000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1739502178.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
F70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000000.1462597589.0000000000F70000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F70000
|
Size: |
4096
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1456006081.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
200704
|
|
7AB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2543363095.0000000007AB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7AB0000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736814561.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
79D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.00000000079D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79D6000
|
Size: |
4096
|
|
A5A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1632953153.0000000000A5A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A5A000
|
Size: |
8192
|
|
1350000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1305133502.0000000001350000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1350000
|
Size: |
172032
|
|
3205000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1428963556.0000000003205000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3205000
|
Size: |
49152
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1430947696.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
266240
|
|
2EA4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1744179247.0000000002EA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EA4000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
7A04000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.0000000007A04000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A04000
|
Size: |
4096
|
|
A79000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539274982.0000000000A79000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A79000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
7D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1632729697.00000000007D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D0000
|
Size: |
20480
|
|
C50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1544231529.0000000000C50000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C50000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737228815.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736007101.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741169408.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
8B9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2538505026.00000000008B9000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8B9000
|
Size: |
61440
|
|
3EDE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1313287039.0000000003EDE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3EDE000
|
Size: |
24576
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1739664614.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1459426577.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
200704
|
|
B70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538535122.0000000000B70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B70000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742369300.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742060334.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738413143.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
139E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1311086467.000000000139E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
139E000
|
Size: |
135168
|
|
770000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2538783370.0000000000770000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
770000
|
Size: |
4096
|
|
23AE42B0000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.1860900296.0000023AE42B0000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
23AE42B0000
|
Size: |
540672
|
|
FA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2538727759.0000000000FA0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FA0000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1735473491.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2E96000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002E96000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E96000
|
Size: |
16384
|
|
B84000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1554665766.0000000000B84000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B84000
|
Size: |
4096
|
|
3D40000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1313287039.0000000003D40000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D40000
|
Size: |
1196032
|
|
3BA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1455389755.0000000003BA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3BA0000
|
Size: |
188416
|
|
F90000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2538699638.0000000000F90000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F90000
|
Size: |
4096
|
|
4D50000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2541345735.0000000004D50000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4D50000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738495763.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
3800000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1544662726.0000000003800000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3800000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3E69000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1313287039.0000000003E69000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E69000
|
Size: |
4096
|
|
23EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539586957.00000000023EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
23EF000
|
Size: |
4096
|
|
2EDC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002EDC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EDC000
|
Size: |
4096
|
|
75E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1632637088.000000000075E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
75E000
|
Size: |
8192
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1459227232.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
69632
|
|
5A6C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2540263212.0000000005A6C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5A6C000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741472955.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
1B0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1315224504.0000000001B0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1B0E000
|
Size: |
8192
|
|
3600000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1430569512.0000000003600000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3600000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2EB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1746304036.0000000002EB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EB5000
|
Size: |
4096
|
|
A5E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539274982.0000000000A5E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A5E000
|
Size: |
94208
|
|
8AF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000000.1462452190.00000000008AF000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8AF000
|
Size: |
28672
|
|
A5E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1632953153.0000000000A5E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A5E000
|
Size: |
94208
|
|
2EC5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002EC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EC5000
|
Size: |
12288
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742246735.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
B50000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2539426458.0000000000B50000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B50000
|
Size: |
40960
|
|
23AE5E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861247050.0000023AE5E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AE5E00000
|
Size: |
4096
|
|
3CC3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1313596666.0000000003CC3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3CC3000
|
Size: |
507904
|
|
3BA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1313596666.0000000003BA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3BA0000
|
Size: |
1187840
|
|
1A50000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2539218063.0000000001A50000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A50000
|
Size: |
397312
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737258885.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737685611.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2EEB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002EEB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EEB000
|
Size: |
12288
|
|
3040000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000000.1463114485.0000000003040000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
3040000
|
Size: |
925696
|
|
35FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1544616121.00000000035FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35FF000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1739221478.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
8A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2538345970.00000000008A0000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8A0000
|
Size: |
4096
|
|
146F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1310985046.000000000146F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
146F000
|
Size: |
339968
|
|
7E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2538894190.00000000007E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7E0000
|
Size: |
16384
|
|
64F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1314588794.000000000064F000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
64F000
|
Size: |
147456
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1739275531.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
620000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2538647175.0000000000620000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
620000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1740872935.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1735941895.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
79D1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1747935015.00000000079D1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79D1000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736938667.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737388054.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
137F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1315072731.000000000137F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
137F000
|
Size: |
118784
|
|
1342000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1302459055.0000000001342000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1342000
|
Size: |
552960
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737322958.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
EC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000000.1462542851.0000000000EC0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EC0000
|
Size: |
4096
|
|
4840000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1561491694.0000000004840000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4840000
|
Size: |
188416
|
|
8A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1632807182.00000000008A0000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8A0000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738144459.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
7C3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2543519528.0000000007C3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7C3E000
|
Size: |
8192
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1455879537.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
135168
|
|
3BA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1459129825.0000000003BA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3BA0000
|
Size: |
188416
|
|
23AE45AA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861116140.0000023AE45AA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AE45AA000
|
Size: |
57344
|
|
674000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1314588794.0000000000674000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
674000
|
Size: |
40960
|
|
8A1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000007.00000002.2539078649.00000000008A1000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
8A1000
|
Size: |
57344
|
|
49FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2539718023.00000000049FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
49FC000
|
Size: |
16384
|
|
2EF6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002EF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EF6000
|
Size: |
12288
|
|
EC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2538561240.0000000000EC0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EC0000
|
Size: |
4096
|
|
1350000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2538892262.0000000001350000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1350000
|
Size: |
4096
|
|
761000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1632657230.0000000000761000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
761000
|
Size: |
12288
|
|
B84000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1547827802.0000000000B84000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B84000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1739747734.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
4DC3000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2541345735.0000000004DC3000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4DC3000
|
Size: |
446464
|
|
13C6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2538981592.00000000013C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13C6000
|
Size: |
20480
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737878276.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737055172.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738696474.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2E2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1544975451.0000000002E2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E2D000
|
Size: |
24576
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1740109031.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
770000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1632689356.0000000000770000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
770000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741906743.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
13C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1302633325.00000000013C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13C8000
|
Size: |
516096
|
|
240000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1632337848.0000000000240000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
240000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1740990357.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742186799.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737782415.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2E29000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1545304425.0000000002E29000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E29000
|
Size: |
20480
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737165438.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
4993000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1547537202.0000000004993000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4993000
|
Size: |
458752
|
|
2E2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1545372255.0000000002E2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E2D000
|
Size: |
24576
|
|
4700000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2539469087.0000000004700000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4700000
|
Size: |
94208
|
|
2CA4000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539938484.0000000002CA4000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2CA4000
|
Size: |
4096
|
|
1357000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1311021657.0000000001357000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1357000
|
Size: |
65536
|
|
3217000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1428989434.0000000003217000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3217000
|
Size: |
20480
|
|
1F0F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1315243730.0000000001F0F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1F0F000
|
Size: |
4096
|
|
810000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2538952773.0000000000810000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
810000
|
Size: |
12288
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737911909.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2E7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1744179247.0000000002E7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E7E000
|
Size: |
4096
|
|
3E6D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1313287039.0000000003E6D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E6D000
|
Size: |
458752
|
|
2EFF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002EFF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EFF000
|
Size: |
45056
|
|
630000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2538672690.0000000000630000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
630000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1740838654.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
24242000
|
system
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1857720490.0000000024242000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
24242000
|
Size: |
4096
|
|
1342000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1302363422.0000000001342000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1342000
|
Size: |
552960
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1739047429.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2444000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1633095345.0000000002444000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2444000
|
Size: |
4096
|
|
B80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538562705.0000000000B80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B80000
|
Size: |
16384
|
|
1364000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2538918741.0000000001364000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1364000
|
Size: |
4096
|
|
134F000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1315036075.000000000134F000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
134F000
|
Size: |
16384
|
|
3704000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.2539481222.0000000003704000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3704000
|
Size: |
5005312
|
|
13E8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1302423791.00000000013E8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13E8000
|
Size: |
4096
|
|
139D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1311021657.000000000139D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
139D000
|
Size: |
139264
|
|
14C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1315201060.00000000014C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14C1000
|
Size: |
4096
|
|
5BFE000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2540263212.0000000005BFE000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5BFE000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736845213.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1735903259.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
46B5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1544284167.00000000046B5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
46B5000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
815F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2544157053.000000000815F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
815F000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742217439.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
1310000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1462741727.0000000001310000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1310000
|
Size: |
4096
|
|
79DB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.00000000079DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79DB000
|
Size: |
8192
|
|
26FC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539938484.00000000026FC000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
26FC000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742340258.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
415C000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1545227326.000000000415C000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
415C000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741200126.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2CA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2538476986.00000000002CA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2CA000
|
Size: |
24576
|
|
2E24000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1545259929.0000000002E24000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E24000
|
Size: |
36864
|
|
12FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1462705522.00000000012FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12FC000
|
Size: |
16384
|
|
23AE44C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861038048.0000023AE44C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AE44C0000
|
Size: |
8192
|
|
16C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2539180456.00000000016C0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
16C0000
|
Size: |
40960
|
|
139A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2538981592.000000000139A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
139A000
|
Size: |
8192
|
|
79C6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1747935015.00000000079C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79C6000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737486944.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
3E1D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1312420544.0000000003E1D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E1D000
|
Size: |
458752
|
|
79D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.00000000079D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79D8000
|
Size: |
4096
|
|
1390000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1462830813.0000000001390000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1390000
|
Size: |
32768
|
|
2EE5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002EE5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EE5000
|
Size: |
12288
|
|
2E17000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002E17000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E17000
|
Size: |
45056
|
|
79F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.00000000079F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79F4000
|
Size: |
8192
|
|
1280000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1314937869.0000000001280000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1280000
|
Size: |
8192
|
|
24F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1633146561.00000000024F0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
24F0000
|
Size: |
925696
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736364687.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
3E8E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1311492942.0000000003E8E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E8E000
|
Size: |
24576
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742780981.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
119E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1314848667.000000000119E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
119E000
|
Size: |
8192
|
|
EE0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1633032870.0000000000EE0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EE0000
|
Size: |
397312
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
6C56FFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1860877571.0000006C56FFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6C56FFE000
|
Size: |
8192
|
|
6C55FFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1860835145.0000006C55FFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6C55FFE000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738346015.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
3C73000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1311287966.0000000003C73000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C73000
|
Size: |
507904
|
|
6C557FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1860782040.0000006C557FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6C557FE000
|
Size: |
8192
|
|
23AE45CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861116140.0000023AE45CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AE45CF000
|
Size: |
4096
|
|
5424000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2540263212.0000000005424000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
5424000
|
Size: |
4096
|
|
67E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1314669269.000000000067E000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
67E000
|
Size: |
36864
|
|
103C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1314753341.000000000103C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
103C000
|
Size: |
16384
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736581441.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
CEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1544385497.0000000000CEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CEE000
|
Size: |
8192
|
|
7A2E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.0000000007A2E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A2E000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742122358.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1750560181.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737814575.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
23EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1633079020.00000000023EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
23EF000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736068771.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
FB0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2538749070.0000000000FB0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
FB0000
|
Size: |
4096
|
|
79E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.00000000079E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79E3000
|
Size: |
24576
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736684475.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
16BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1462963885.00000000016BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
16BF000
|
Size: |
4096
|
|
2E90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002E90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E90000
|
Size: |
16384
|
|
9CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1632934507.00000000009CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9CF000
|
Size: |
4096
|
|
3212000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1544513646.0000000003212000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3212000
|
Size: |
24576
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1735838368.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
3030000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2539304404.0000000003030000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3030000
|
Size: |
8192
|
|
4D6E000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2541345735.0000000004D6E000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4D6E000
|
Size: |
8192
|
|
687000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1314687032.0000000000687000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
687000
|
Size: |
409600
|
|
7CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1632707036.00000000007CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7CE000
|
Size: |
8192
|
|
1343000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1302633325.0000000001343000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1343000
|
Size: |
335872
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738989100.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
4D6C000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.2541345735.0000000004D6C000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
4D6C000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737004052.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
3002000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1544419149.0000000003002000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3002000
|
Size: |
20480
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741138201.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741051671.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
5C1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.1314540530.00000000005C1000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
5C1000
|
Size: |
581632
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1735976289.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
347E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539938484.000000000347E000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
347E000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4A10000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.2539750371.0000000004A10000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A10000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
23AE6000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1816402158.0000023AE6000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AE6000000
|
Size: |
4096
|
|
2E22000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1544975451.0000000002E22000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E22000
|
Size: |
28672
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737619552.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2E22000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1545372255.0000000002E22000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E22000
|
Size: |
28672
|
|
1395000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1302571835.0000000001395000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1395000
|
Size: |
724992
|
|
2EAA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1746304036.0000000002EAA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EAA000
|
Size: |
4096
|
|
A50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539274982.0000000000A50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A50000
|
Size: |
32768
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741787910.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741967844.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538593885.0000000002C90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C90000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736037421.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
67E000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1301817874.000000000067E000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
67E000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738043203.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
11F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1314905305.00000000011F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11F0000
|
Size: |
4096
|
|
3E19000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1312420544.0000000003E19000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E19000
|
Size: |
4096
|
|
47A0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.2539524025.00000000047A0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
47A0000
|
Size: |
94208
|
|
1330000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000000.1462757654.0000000001330000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1330000
|
Size: |
16384
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742885031.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741021952.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
24E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539734678.00000000024E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24E0000
|
Size: |
12288
|
|
139E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1462830813.000000000139E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
139E000
|
Size: |
94208
|
|
C60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1544257750.0000000000C60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C60000
|
Size: |
4096
|
|
23AE60CE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1817540944.0000023AE60CE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AE60CE000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741261768.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1435924965.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
262144
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1554546934.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
253952
|
|
ED0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000000.1462563950.0000000000ED0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ED0000
|
Size: |
4096
|
|
2E36000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539938484.0000000002E36000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2E36000
|
Size: |
16384
|
|
1390000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2538981592.0000000001390000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1390000
|
Size: |
32768
|
|
87C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539013117.000000000087C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
87C000
|
Size: |
16384
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1436026583.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
258048
|
|
5E0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2538535313.00000000005E0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
5E0000
|
Size: |
4096
|
|
8A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000000.1462403338.00000000008A0000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
8A0000
|
Size: |
4096
|
|
710000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1632611522.0000000000710000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
710000
|
Size: |
4096
|
|
250000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1632407076.0000000000250000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
250000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742914792.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
260000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2538446561.0000000000260000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
260000
|
Size: |
4096
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1435840418.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
200704
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738528393.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
23AE45D2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861116140.0000023AE45D2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AE45D2000
|
Size: |
24576
|
|
23AE45BC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861116140.0000023AE45BC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AE45BC000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
79E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1747935015.00000000079E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79E9000
|
Size: |
4096
|
|
2D90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538627967.0000000002D90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D90000
|
Size: |
4096
|
|
25E2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539938484.00000000025E2000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
25E2000
|
Size: |
4096
|
|
80DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2543996152.00000000080DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
80DF000
|
Size: |
4096
|
|
8A1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000004.00000000.1462428290.00000000008A1000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
8A1000
|
Size: |
57344
|
|
3800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1315295072.0000000003800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3800000
|
Size: |
8192
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1431019468.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
258048
|
|
13C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1315119404.00000000013C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13C8000
|
Size: |
516096
|
|
23AE5F21000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861299902.0000023AE5F21000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AE5F21000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742435427.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737422434.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
321A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1507230092.000000000321A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
321A000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1750676172.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
3ACD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1544662726.0000000003ACD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3ACD000
|
Size: |
4096
|
|
3EDE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1312842801.0000000003EDE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3EDE000
|
Size: |
24576
|
|
1356000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1315036075.0000000001356000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1356000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741082520.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2451C000
|
system
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1857720490.000000002451C000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
2451C000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2EAF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1746304036.0000000002EAF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EAF000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
23AE5F17000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861299902.0000023AE5F17000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AE5F17000
|
Size: |
4096
|
|
3205000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1428850425.0000000003205000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3205000
|
Size: |
49152
|
|
2EA4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002EA4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EA4000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
7A28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.0000000007A28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A28000
|
Size: |
8192
|
|
1330000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2538864231.0000000001330000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1330000
|
Size: |
16384
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736652628.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
24E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1633129197.00000000024E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24E0000
|
Size: |
8192
|
|
7C90000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2543650057.0000000007C90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C90000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1739400936.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
23AE5F0E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861299902.0000023AE5F0E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AE5F0E000
|
Size: |
4096
|
|
682000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1301817874.0000000000682000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
682000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1740021686.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742652373.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738593911.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741936936.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1435746923.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
135168
|
|
47D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1544284167.00000000047D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
47D8000
|
Size: |
512000
|
|
7C7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2543601829.0000000007C7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7C7F000
|
Size: |
4096
|
|
4E22000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2540263212.0000000004E22000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4E22000
|
Size: |
4096
|
|
24302000
|
system
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1857720490.0000000024302000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
24302000
|
Size: |
4096
|
|
75B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538347771.000000000075B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
75B000
|
Size: |
20480
|
|
2E24000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002E24000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E24000
|
Size: |
77824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738379586.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
55B6000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2540263212.00000000055B6000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
55B6000
|
Size: |
16384
|
|
7D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2538838446.00000000007D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D6000
|
Size: |
8192
|
|
5C1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1301692551.00000000005C1000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
5C1000
|
Size: |
581632
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741696914.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
8B6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2538480394.00000000008B6000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8B6000
|
Size: |
8192
|
|
8B6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1632892715.00000000008B6000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8B6000
|
Size: |
8192
|
|
48CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2539636547.00000000048CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
48CE000
|
Size: |
8192
|
|
240000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2538341635.0000000000240000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
240000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738839246.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1739594828.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1581770966.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
14E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2539143146.00000000014E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14E0000
|
Size: |
20480
|
|
26A2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539938484.00000000026A2000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
26A2000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742501450.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
1080000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1314827193.0000000001080000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1080000
|
Size: |
4096
|
|
3B50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1545120169.0000000003B50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B50000
|
Size: |
274432
|
|
3200000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1544476347.0000000003200000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3200000
|
Size: |
45056
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1459657631.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
258048
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741511129.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
7A3B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.0000000007A3B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A3B000
|
Size: |
8192
|
|
7CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2538814312.00000000007CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7CE000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741292323.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1735384821.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738560763.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736467542.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
250000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2538415093.0000000000250000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
250000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742091016.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738244923.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1750603777.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
805F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2543834269.000000000805F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
805F000
|
Size: |
4096
|
|
79CC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1747935015.00000000079CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79CC000
|
Size: |
4096
|
|
139D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1305133502.000000000139D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
139D000
|
Size: |
12288
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1430886696.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
196608
|
|
1318000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1314954706.0000000001318000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1318000
|
Size: |
176128
|
|
3E8E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1311919242.0000000003E8E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E8E000
|
Size: |
24576
|
|
3929000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1544662726.0000000003929000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3929000
|
Size: |
4096
|
|
11EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1314888582.00000000011EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
11EE000
|
Size: |
8192
|
|
1357000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1302998908.0000000001357000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1357000
|
Size: |
86016
|
|
137F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1311021657.000000000137F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
137F000
|
Size: |
118784
|
|
801E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2543762344.000000000801E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
801E000
|
Size: |
8192
|
|
F80000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000000.1462615096.0000000000F80000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F80000
|
Size: |
4096
|
|
F3A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1462580180.0000000000F3A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F3A000
|
Size: |
24576
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737290414.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1750492167.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
25E2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1633226913.00000000025E2000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
25E2000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1739162943.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
3E6D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1312842801.0000000003E6D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E6D000
|
Size: |
458752
|
|
23AE60BE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1817562853.0000023AE60BE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AE60BE000
|
Size: |
8192
|
|
7AC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2543409392.0000000007AC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7AC0000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741603807.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741876634.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2FC8000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539938484.0000000002FC8000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2FC8000
|
Size: |
4096
|
|
136C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1302954599.000000000136C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
136C000
|
Size: |
196608
|
|
64F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1301764902.000000000064F000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
64F000
|
Size: |
147456
|
|
3E19000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1311919242.0000000003E19000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E19000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741325328.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2E8D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002E8D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E8D000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742681616.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742563788.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
3400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1428570664.0000000003400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3400000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
372D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1430569512.000000000372D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
372D000
|
Size: |
458752
|
|
2F5F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1463077573.0000000002F5F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F5F000
|
Size: |
4096
|
|
139E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1305212388.000000000139E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
139E000
|
Size: |
8192
|
|
3523000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1428570664.0000000003523000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3523000
|
Size: |
507904
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1435673361.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
69632
|
|
24904000
|
system
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1857720490.0000000024904000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
24904000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742311399.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1739544334.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2EF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2538745385.0000000002EF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2EF0000
|
Size: |
12288
|
|
79C3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.00000000079C3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79C3000
|
Size: |
12288
|
|
3301000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1544557687.0000000003301000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3301000
|
Size: |
4096
|
|
1310000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1314954706.0000000001310000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1310000
|
Size: |
24576
|
|
23AE45CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861116140.0000023AE45CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AE45CA000
|
Size: |
8192
|
|
4D62000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2540263212.0000000004D62000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4D62000
|
Size: |
4096
|
|
2D90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1553764914.0000000002D90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D90000
|
Size: |
188416
|
|
79C6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1747200148.00000000079C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79C6000
|
Size: |
147456
|
|
600000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1632527392.0000000000600000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
600000
|
Size: |
4096
|
|
23AE6001000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861436714.0000023AE6001000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AE6001000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1739451297.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
761000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2538757896.0000000000761000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
761000
|
Size: |
12288
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737454658.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
3CC3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1312697296.0000000003CC3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3CC3000
|
Size: |
507904
|
|
2E8D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1744179247.0000000002E8D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E8D000
|
Size: |
4096
|
|
503C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2540263212.000000000503C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
503C000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
23AE5D80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1813588467.0000023AE5D80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23AE5D80000
|
Size: |
4096
|
|
14E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1462945834.00000000014E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14E0000
|
Size: |
20480
|
|
3BA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1313147572.0000000003BA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3BA0000
|
Size: |
1187840
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742534649.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
7A3E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2541803746.0000000007A3E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7A3E000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736540601.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1740683371.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1735439885.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741542292.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1742857100.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
536F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2541974948.000000000536F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
536F000
|
Size: |
4096
|
|
1260000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1314922456.0000000001260000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1260000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1740916836.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737718116.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
EB0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.2538533442.0000000000EB0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EB0000
|
Size: |
4096
|
|
1350000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1462780025.0000000001350000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1350000
|
Size: |
4096
|
|
490E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.2539669630.000000000490E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
490E000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736747724.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741357389.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1739631707.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
3EDE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1313750921.0000000003EDE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3EDE000
|
Size: |
24576
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738107745.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
B50000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1633013496.0000000000B50000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B50000
|
Size: |
40960
|
|
23AE43D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861009761.0000023AE43D0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AE43D0000
|
Size: |
4096
|
|
3B50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1311287966.0000000003B50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B50000
|
Size: |
1187840
|
|
C20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1544167087.0000000000C20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C20000
|
Size: |
4096
|
|
9CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539217933.00000000009CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9CF000
|
Size: |
4096
|
|
3E69000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1312842801.0000000003E69000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E69000
|
Size: |
4096
|
|
3BA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1312697296.0000000003BA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3BA0000
|
Size: |
1187840
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736781959.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2E2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1545204558.0000000002E2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E2D000
|
Size: |
24576
|
|
A50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1632953153.0000000000A50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A50000
|
Size: |
32768
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1741758147.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1737518911.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
6C567FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1860856903.0000006C567FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6C567FE000
|
Size: |
8192
|
|
4840000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1578267231.0000000004840000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4840000
|
Size: |
188416
|
|
139E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2538981592.000000000139E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
139E000
|
Size: |
159744
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1740632117.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
139A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1462830813.000000000139A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
139A000
|
Size: |
8192
|
|
2E28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1545426383.0000000002E28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E28000
|
Size: |
4096
|
|
8B6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000004.00000000.1462477777.00000000008B6000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
8B6000
|
Size: |
8192
|
|
3CC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2538503696.00000000003CC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3CC000
|
Size: |
16384
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738315443.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
FFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1314753341.0000000000FFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FFF000
|
Size: |
4096
|
|
12FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2538777303.00000000012FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12FC000
|
Size: |
16384
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1740552635.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2435C000
|
system
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1857720490.000000002435C000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
2435C000
|
Size: |
4096
|
|
A5A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2539274982.0000000000A5A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A5A000
|
Size: |
8192
|
|
79D8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1747935015.00000000079D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79D8000
|
Size: |
4096
|
|
3CF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1311492942.0000000003CF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3CF0000
|
Size: |
1196032
|
|
28BC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1633226913.00000000028BC000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
28BC000
|
Size: |
53248
|
|
23AE433C000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.1860900296.0000023AE433C000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
23AE433C000
|
Size: |
12288
|
|
79DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1747935015.00000000079DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
79DE000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
C00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1544136490.0000000000C00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C00000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1750642675.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
1A51000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000000.1463010824.0000000001A51000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A51000
|
Size: |
393216
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
322C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1507230092.000000000322C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
322C000
|
Size: |
12288
|
|
EE0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.2539454475.0000000000EE0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EE0000
|
Size: |
397312
|
|
260000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1632430798.0000000000260000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
260000
|
Size: |
4096
|
|
23AE44F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1861071348.0000023AE44F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23AE44F0000
|
Size: |
4096
|
|
7E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1632763883.00000000007E0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7E0000
|
Size: |
16384
|
|
F90000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000000.1462631993.0000000000F90000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F90000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736970977.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738627452.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1459557858.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
266240
|
|
4B3D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.2539750371.0000000004B3D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
4B3D000
|
Size: |
458752
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1738767951.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1581692178.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
253952
|
|
3804000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1315295072.0000000003804000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3804000
|
Size: |
8192
|
|
3CC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1632505485.00000000003CC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3CC000
|
Size: |
16384
|
|
2E28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1545106141.0000000002E28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E28000
|
Size: |
4096
|
|
710000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.2538699806.0000000000710000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
710000
|
Size: |
4096
|
|
2E33000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1544886145.0000000002E33000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E33000
|
Size: |
20480
|
|
B84000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1554634641.0000000000B84000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B84000
|
Size: |
4096
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1547799629.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
65536
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1740767143.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|
1360000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.2538918741.0000000001360000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1360000
|
Size: |
8192
|
|
2C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000003.1736103999.0000000002C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C91000
|
Size: |
4096
|
|