2B1A000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000002.00000002.3702479918.0000000002B1A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B1A000
|
Size: |
77824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Telegram RAT |
Stealing of Sensitive Information, Remote Access Functionality |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
3830000
|
direct allocation
|
page read and write
|
 |
|
|
Name: |
00000000.00000002.1238598112.0000000003830000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3830000
|
Size: |
278528
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Telegram RAT |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected VIP Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
402000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.3700812554.0000000000402000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
402000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Telegram RAT |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected VIP Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
2931000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000002.00000002.3702479918.0000000002931000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2931000
|
Size: |
315392
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
URLs found in memory or binary data |
Networking |
|
|
16B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229361645.00000000016B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16B3000
|
Size: |
741376
|
|
2AE4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002AE4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AE4000
|
Size: |
4096
|
|
AE5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701305566.0000000000AE5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AE5000
|
Size: |
4096
|
|
3C17000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003C17000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C17000
|
Size: |
8192
|
|
26F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702090684.00000000026F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26F0000
|
Size: |
4096
|
|
EDE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238165575.0000000000EDE000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
EDE000
|
Size: |
36864
|
|
64C4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706777286.00000000064C4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
64C4000
|
Size: |
36864
|
|
16B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1228900928.00000000016B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16B3000
|
Size: |
741376
|
|
2B92000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002B92000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B92000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
3B84000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003B84000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B84000
|
Size: |
4096
|
|
276E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702266312.000000000276E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
276E000
|
Size: |
8192
|
|
4019000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235607866.0000000004019000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4019000
|
Size: |
4096
|
|
2B89000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002B89000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B89000
|
Size: |
4096
|
|
3D36000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003D36000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3D36000
|
Size: |
4096
|
|
AE7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701305566.0000000000AE7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AE7000
|
Size: |
499712
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
3EC3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1237139316.0000000003EC3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3EC3000
|
Size: |
507904
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
1653000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226130192.0000000001653000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1653000
|
Size: |
397312
|
|
16B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229610006.00000000016B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16B3000
|
Size: |
741376
|
|
1420000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238307741.0000000001420000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1420000
|
Size: |
24576
|
|
2C75000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002C75000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C75000
|
Size: |
12288
|
|
2B7E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002B7E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B7E000
|
Size: |
4096
|
|
ED4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1225564726.0000000000ED4000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ED4000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
3BFA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003BFA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3BFA000
|
Size: |
8192
|
|
1654000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226269710.0000000001654000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1654000
|
Size: |
188416
|
|
3890000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238630319.0000000003890000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3890000
|
Size: |
8192
|
|
3C64000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003C64000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C64000
|
Size: |
4096
|
|
2702000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702176407.0000000002702000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2702000
|
Size: |
4096
|
|
1682000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226198872.0000000001682000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1682000
|
Size: |
819200
|
|
E21000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.1238069534.0000000000E21000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
E21000
|
Size: |
581632
|
|
408E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235234155.000000000408E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
408E000
|
Size: |
24576
|
|
4E50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705424925.0000000004E50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E50000
|
Size: |
4096
|
|
63E0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3706455031.00000000063E0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
63E0000
|
Size: |
8192
|
|
3F40000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236873842.0000000003F40000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F40000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4E16000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705102915.0000000004E16000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E16000
|
Size: |
8192
|
|
2705000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3702193493.0000000002705000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2705000
|
Size: |
4096
|
|
27D0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3702350710.00000000027D0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
27D0000
|
Size: |
4096
|
|
3DA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1237139316.0000000003DA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3DA0000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3C00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003C00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C00000
|
Size: |
8192
|
|
2AB9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002AB9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AB9000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4ED0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3705534860.0000000004ED0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
4ED0000
|
Size: |
4096
|
|
1E1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238561569.0000000001E1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1E1E000
|
Size: |
8192
|
|
2B2E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002B2E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B2E000
|
Size: |
45056
|
|
D80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701755333.0000000000D80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D80000
|
Size: |
8192
|
|
29A6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.00000000029A6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29A6000
|
Size: |
4096
|
|
16D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226103038.00000000016D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16D3000
|
Size: |
4096
|
|
2C9D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002C9D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C9D000
|
Size: |
299008
|
|
12EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238217087.00000000012EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12EE000
|
Size: |
8192
|
|
1644000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226130192.0000000001644000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1644000
|
Size: |
45056
|
|
2C6C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002C6C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C6C000
|
Size: |
4096
|
|
16B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226580744.00000000016B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16B3000
|
Size: |
741376
|
|
6460000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706638651.0000000006460000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6460000
|
Size: |
12288
|
|
29DC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.00000000029DC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29DC000
|
Size: |
4096
|
|
3999000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003999000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3999000
|
Size: |
4096
|
|
2C79000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002C79000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C79000
|
Size: |
139264
|
|
2AEA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002AEA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AEA000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6520000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3706991411.0000000006520000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6520000
|
Size: |
40960
|
|
270B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3702227915.000000000270B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
270B000
|
Size: |
4096
|
|
F30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702032758.0000000000F30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F30000
|
Size: |
16384
|
|
40DE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236440827.00000000040DE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40DE000
|
Size: |
24576
|
|
178E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229449422.000000000178E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
178E000
|
Size: |
135168
|
|
3D0E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003D0E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3D0E000
|
Size: |
4096
|
|
2AB3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002AB3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AB3000
|
Size: |
4096
|
|
6880000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3707041928.0000000006880000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6880000
|
Size: |
8192
|
|
176E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229610006.000000000176E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
176E000
|
Size: |
4096
|
|
3C57000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003C57000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C57000
|
Size: |
8192
|
|
297F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.000000000297F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
297F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
EE2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1225607954.0000000000EE2000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
EE2000
|
Size: |
8192
|
|
2BA5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002BA5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BA5000
|
Size: |
118784
|
|
27AC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702285257.00000000027AC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
27AC000
|
Size: |
16384
|
|
167C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226580744.000000000167C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
167C000
|
Size: |
106496
|
|
EAF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1238115570.0000000000EAF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EAF000
|
Size: |
147456
|
|
F20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701924923.0000000000F20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F20000
|
Size: |
8192
|
|
B9E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701655620.0000000000B9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B9E000
|
Size: |
69632
|
|
16B4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226034310.00000000016B4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16B4000
|
Size: |
131072
|
|
166D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1228900928.000000000166D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
166D000
|
Size: |
151552
|
|
63F0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3706502535.00000000063F0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
63F0000
|
Size: |
65536
|
|
EE7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1238182650.0000000000EE7000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EE7000
|
Size: |
262144
|
|
2920000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702461881.0000000002920000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2920000
|
Size: |
4096
|
|
53E0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3705752849.00000000053E0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
53E0000
|
Size: |
65536
|
|
2BA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002BA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BA0000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
1660000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1238433611.0000000001660000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1660000
|
Size: |
16384
|
|
4E1B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705102915.0000000004E1B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E1B000
|
Size: |
8192
|
|
2997000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002997000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2997000
|
Size: |
12288
|
|
5F3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705865399.0000000005F3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5F3E000
|
Size: |
8192
|
|
3959000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003959000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3959000
|
Size: |
172032
|
|
1450000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238346436.0000000001450000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1450000
|
Size: |
8192
|
|
2720000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702245916.0000000002720000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2720000
|
Size: |
4096
|
|
D7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701711112.0000000000D7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D7E000
|
Size: |
8192
|
|
E21000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1225512794.0000000000E21000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
E21000
|
Size: |
581632
|
|
2910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702436525.0000000002910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2910000
|
Size: |
65536
|
|
4FA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705676743.0000000004FA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4FA0000
|
Size: |
4096
|
|
EE7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1225635169.0000000000EE7000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EE7000
|
Size: |
262144
|
|
4E2A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705102915.0000000004E2A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E2A000
|
Size: |
4096
|
|
3C1E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003C1E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C1E000
|
Size: |
8192
|
|
64F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706899306.00000000064F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
64F0000
|
Size: |
8192
|
|
26ED000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3702073720.00000000026ED000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
26ED000
|
Size: |
4096
|
|
446000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3700812554.0000000000446000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
446000
|
Size: |
4096
|
|
2C6E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002C6E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C6E000
|
Size: |
4096
|
|
3A42000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003A42000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3A42000
|
Size: |
12288
|
|
3AD2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003AD2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3AD2000
|
Size: |
12288
|
|
2A35000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002A35000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A35000
|
Size: |
4096
|
|
3B99000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003B99000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B99000
|
Size: |
16384
|
|
B50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237956619.0000000000B50000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B50000
|
Size: |
4096
|
|
5F83000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705893406.0000000005F83000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F83000
|
Size: |
176128
|
|
5FBD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705893406.0000000005FBD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5FBD000
|
Size: |
49152
|
|
2BD8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002BD8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BD8000
|
Size: |
192512
|
|
3BB1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003BB1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3BB1000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2C43000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002C43000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C43000
|
Size: |
102400
|
|
4019000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235985534.0000000004019000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4019000
|
Size: |
4096
|
|
39AE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.00000000039AE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
39AE000
|
Size: |
16384
|
|
4EE6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705552105.0000000004EE6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4EE6000
|
Size: |
8192
|
|
3D60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003D60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3D60000
|
Size: |
12288
|
|
4938000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705050130.0000000004938000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4938000
|
Size: |
4096
|
|
40DE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236873842.00000000040DE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40DE000
|
Size: |
24576
|
|
3DA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236266295.0000000003DA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3DA0000
|
Size: |
1187840
|
|
4069000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236873842.0000000004069000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4069000
|
Size: |
4096
|
|
2B82000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002B82000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B82000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
16B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238468255.00000000016B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16B3000
|
Size: |
741376
|
|
3B3A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003B3A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B3A000
|
Size: |
4096
|
|
E20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1225492633.0000000000E20000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E20000
|
Size: |
4096
|
|
3997000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003997000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3997000
|
Size: |
4096
|
|
29A2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.00000000029A2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29A2000
|
Size: |
4096
|
|
3C28000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003C28000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C28000
|
Size: |
12288
|
|
4E3D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705102915.0000000004E3D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E3D000
|
Size: |
16384
|
|
1628000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238364786.0000000001628000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1628000
|
Size: |
180224
|
|
4EF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705621870.0000000004EF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4EF0000
|
Size: |
49152
|
|
3E73000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235109577.0000000003E73000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E73000
|
Size: |
507904
|
|
5E3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705844141.0000000005E3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5E3E000
|
Size: |
8192
|
|
408E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235985534.000000000408E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
408E000
|
Size: |
24576
|
|
298C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.000000000298C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
298C000
|
Size: |
36864
|
|
3F40000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1237661746.0000000003F40000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F40000
|
Size: |
1196032
|
|
3C41000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003C41000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C41000
|
Size: |
8192
|
|
165B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238364786.000000000165B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
165B000
|
Size: |
20480
|
|
2C36000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002C36000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C36000
|
Size: |
4096
|
|
3C0C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003C0C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C0C000
|
Size: |
8192
|
|
39C8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.00000000039C8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
39C8000
|
Size: |
12288
|
|
3BAB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003BAB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3BAB000
|
Size: |
8192
|
|
3EC3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236266295.0000000003EC3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3EC3000
|
Size: |
507904
|
|
DCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701795057.0000000000DCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DCE000
|
Size: |
8192
|
|
130B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238217087.000000000130B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
130B000
|
Size: |
20480
|
|
2AEF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002AEF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AEF000
|
Size: |
172032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
16B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229024920.00000000016B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16B3000
|
Size: |
741376
|
|
4EC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705503882.0000000004EC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4EC0000
|
Size: |
53248
|
|
6480000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3706720529.0000000006480000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6480000
|
Size: |
65536
|
|
40DE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1237661746.00000000040DE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40DE000
|
Size: |
24576
|
|
A55000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701140550.0000000000A55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A55000
|
Size: |
12288
|
|
3B68000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003B68000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B68000
|
Size: |
12288
|
|
AB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701305566.0000000000AB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AB0000
|
Size: |
28672
|
|
61FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706272753.00000000061FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61FE000
|
Size: |
8192
|
|
406D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1237661746.000000000406D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
406D000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
2AB1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002AB1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AB1000
|
Size: |
4096
|
|
2AE2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002AE2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AE2000
|
Size: |
4096
|
|
26E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702052370.00000000026E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26E0000
|
Size: |
45056
|
|
400000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3700812554.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
4096
|
|
3A2C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003A2C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3A2C000
|
Size: |
4096
|
|
1652000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226063938.0000000001652000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1652000
|
Size: |
401408
|
|
17AE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229743841.00000000017AE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17AE000
|
Size: |
4096
|
|
BE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238039485.0000000000BE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BE0000
|
Size: |
4096
|
|
29E8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.00000000029E8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29E8000
|
Size: |
4096
|
|
60BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706220032.00000000060BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60BE000
|
Size: |
8192
|
|
29D8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.00000000029D8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29D8000
|
Size: |
4096
|
|
4EEA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705552105.0000000004EEA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4EEA000
|
Size: |
24576
|
|
DE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701837661.0000000000DE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DE0000
|
Size: |
16384
|
|
4E10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705102915.0000000004E10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E10000
|
Size: |
20480
|
|
F10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701899735.0000000000F10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F10000
|
Size: |
8192
|
|
401D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235234155.000000000401D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
401D000
|
Size: |
458752
|
|
176F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229328927.000000000176F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
176F000
|
Size: |
262144
|
|
3931000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003931000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3931000
|
Size: |
36864
|
|
6400000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3706575390.0000000006400000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6400000
|
Size: |
65536
|
|
4019000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235234155.0000000004019000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4019000
|
Size: |
4096
|
|
2BCC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002BCC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BCC000
|
Size: |
12288
|
|
63BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706324575.00000000063BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63BE000
|
Size: |
8192
|
|
3EF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235234155.0000000003EF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3EF0000
|
Size: |
1196032
|
|
28DF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702369530.00000000028DF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
28DF000
|
Size: |
4096
|
|
4E53000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705424925.0000000004E53000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E53000
|
Size: |
8192
|
|
1667000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226671492.0000000001667000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1667000
|
Size: |
86016
|
|
2ABE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002ABE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2ABE000
|
Size: |
81920
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
F2D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3702008100.0000000000F2D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
F2D000
|
Size: |
4096
|
|
176E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1228900928.000000000176E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
176E000
|
Size: |
4096
|
|
521E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705712441.000000000521E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
521E000
|
Size: |
8192
|
|
3B64000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003B64000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B64000
|
Size: |
12288
|
|
1667000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1238433611.0000000001667000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1667000
|
Size: |
4096
|
|
29F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.00000000029F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29F0000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2A15000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002A15000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A15000
|
Size: |
4096
|
|
1620000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238364786.0000000001620000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1620000
|
Size: |
24576
|
|
63C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706357434.00000000063C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63C0000
|
Size: |
65536
|
|
3A5E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003A5E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3A5E000
|
Size: |
4096
|
|
3D50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235109577.0000000003D50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D50000
|
Size: |
1187840
|
|
6E9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701053178.00000000006E9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6E9000
|
Size: |
28672
|
|
3C33000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003C33000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C33000
|
Size: |
8192
|
|
3C4C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003C4C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C4C000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1668000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229610006.0000000001668000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1668000
|
Size: |
258048
|
|
6496000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706751904.0000000006496000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6496000
|
Size: |
4096
|
|
64D2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706802927.00000000064D2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
64D2000
|
Size: |
8192
|
|
B68000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701305566.0000000000B68000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B68000
|
Size: |
4096
|
|
E2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701872629.0000000000E2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E2E000
|
Size: |
8192
|
|
2B40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002B40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B40000
|
Size: |
167936
|
|
2C31000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002C31000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C31000
|
Size: |
16384
|
|
A50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701140550.0000000000A50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A50000
|
Size: |
16384
|
|
3D50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235863422.0000000003D50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D50000
|
Size: |
1187840
|
|
408E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235607866.000000000408E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
408E000
|
Size: |
24576
|
|
2C70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002C70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C70000
|
Size: |
4096
|
|
60FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706243090.00000000060FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60FE000
|
Size: |
8192
|
|
2900000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702411152.0000000002900000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2900000
|
Size: |
65536
|
|
406D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236440827.000000000406D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
406D000
|
Size: |
458752
|
|
2AAB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002AAB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AAB000
|
Size: |
8192
|
|
12FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238217087.00000000012FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12FE000
|
Size: |
8192
|
|
62BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706299646.00000000062BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
62BE000
|
Size: |
8192
|
|
4E36000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705102915.0000000004E36000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E36000
|
Size: |
16384
|
|
3EC3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236719230.0000000003EC3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3EC3000
|
Size: |
507904
|
|
EDE000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1225607954.0000000000EDE000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
EDE000
|
Size: |
8192
|
|
29E4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.00000000029E4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29E4000
|
Size: |
4096
|
|
2700000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702159597.0000000002700000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2700000
|
Size: |
4096
|
|
4E42000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705102915.0000000004E42000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E42000
|
Size: |
49152
|
|
BDD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238009190.0000000000BDD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BDD000
|
Size: |
12288
|
|
2AE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002AE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AE0000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
AEA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237876043.0000000000AEA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AEA000
|
Size: |
24576
|
|
29EC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.00000000029EC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29EC000
|
Size: |
4096
|
|
5F40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705893406.0000000005F40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F40000
|
Size: |
159744
|
|
16B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1226269710.00000000016B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16B3000
|
Size: |
618496
|
|
3D23000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003D23000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3D23000
|
Size: |
16384
|
|
176E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238468255.000000000176E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
176E000
|
Size: |
8192
|
|
3E73000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235488215.0000000003E73000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E73000
|
Size: |
507904
|
|
6510000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706967834.0000000006510000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6510000
|
Size: |
32768
|
|
406D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236873842.000000000406D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
406D000
|
Size: |
458752
|
|
4E2E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705102915.0000000004E2E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E2E000
|
Size: |
4096
|
|
ED4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1238115570.0000000000ED4000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ED4000
|
Size: |
40960
|
|
4069000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1237661746.0000000004069000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4069000
|
Size: |
4096
|
|
E20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1238056070.0000000000E20000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E20000
|
Size: |
4096
|
|
17AE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229610006.00000000017AE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17AE000
|
Size: |
4096
|
|
3D64000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003D64000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3D64000
|
Size: |
12288
|
|
64D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706802927.00000000064D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
64D0000
|
Size: |
4096
|
|
4ACE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705078788.0000000004ACE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4ACE000
|
Size: |
8192
|
|
B9D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1237984256.0000000000B9D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B9D000
|
Size: |
12288
|
|
27B0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3702304143.00000000027B0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
27B0000
|
Size: |
65536
|
|
2A19000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002A19000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A19000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2C3E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002C3E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C3E000
|
Size: |
12288
|
|
2707000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3702210113.0000000002707000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2707000
|
Size: |
4096
|
|
3DA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236719230.0000000003DA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3DA0000
|
Size: |
1187840
|
|
3A8A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003A8A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3A8A000
|
Size: |
20480
|
|
5FAF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705893406.0000000005FAF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5FAF000
|
Size: |
8192
|
|
4E31000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705102915.0000000004E31000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E31000
|
Size: |
16384
|
|
7E7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701099320.00000000007E7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7E7000
|
Size: |
36864
|
|
28E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702390941.00000000028E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28E0000
|
Size: |
4096
|
|
26F2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702107316.00000000026F2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
26F2000
|
Size: |
4096
|
|
A60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701220917.0000000000A60000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A60000
|
Size: |
4096
|
|
5FCF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705893406.0000000005FCF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5FCF000
|
Size: |
167936
|
|
132C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238217087.000000000132C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
132C000
|
Size: |
16384
|
|
2C09000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002C09000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C09000
|
Size: |
98304
|
|
176E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229361645.000000000176E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
176E000
|
Size: |
4096
|
|
3EF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235607866.0000000003EF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3EF0000
|
Size: |
1196032
|
|
64F7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706899306.00000000064F7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
64F7000
|
Size: |
36864
|
|
EAF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1225564726.0000000000EAF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EAF000
|
Size: |
147456
|
|
1661000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1228900928.0000000001661000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1661000
|
Size: |
28672
|
|
53F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705781759.00000000053F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53F0000
|
Size: |
65536
|
|
531E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705733739.000000000531E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
531E000
|
Size: |
8192
|
|
2A37000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002A37000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A37000
|
Size: |
434176
|
|
4069000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236440827.0000000004069000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4069000
|
Size: |
4096
|
|
2C2C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002C2C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C2C000
|
Size: |
12288
|
|
4EE4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705552105.0000000004EE4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4EE4000
|
Size: |
4096
|
|
29AA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.00000000029AA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29AA000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
F23000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3701953920.0000000000F23000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
F23000
|
Size: |
4096
|
|
1440000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238328111.0000000001440000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1440000
|
Size: |
4096
|
|
3C90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003C90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C90000
|
Size: |
20480
|
|
3E73000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235863422.0000000003E73000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3E73000
|
Size: |
507904
|
|
AAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701264961.0000000000AAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AAE000
|
Size: |
8192
|
|
3F40000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1236440827.0000000003F40000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F40000
|
Size: |
1196032
|
|
401D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235607866.000000000401D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
401D000
|
Size: |
458752
|
|
AB8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701305566.0000000000AB8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AB8000
|
Size: |
135168
|
|
F24000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701982365.0000000000F24000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F24000
|
Size: |
8192
|
|
26FA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3702142805.00000000026FA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
26FA000
|
Size: |
8192
|
|
4E60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705471389.0000000004E60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E60000
|
Size: |
49152
|
|
4EFD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705621870.0000000004EFD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4EFD000
|
Size: |
12288
|
|
3EF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235985534.0000000003EF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3EF0000
|
Size: |
1196032
|
|
4E1E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705102915.0000000004E1E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E1E000
|
Size: |
45056
|
|
2C3C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002C3C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C3C000
|
Size: |
4096
|
|
6500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706942729.0000000006500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6500000
|
Size: |
40960
|
|
6464000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706638651.0000000006464000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6464000
|
Size: |
28672
|
|
2BC6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002BC6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BC6000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
5400000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3705811940.0000000005400000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5400000
|
Size: |
65536
|
|
6470000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706683875.0000000006470000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6470000
|
Size: |
65536
|
|
2C66000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002C66000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C66000
|
Size: |
12288
|
|
221E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238580119.000000000221E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
221E000
|
Size: |
8192
|
|
27C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702326329.00000000027C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
27C0000
|
Size: |
65536
|
|
3C05000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003C05000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C05000
|
Size: |
8192
|
|
5F69000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3705893406.0000000005F69000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F69000
|
Size: |
8192
|
|
401D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235985534.000000000401D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
401D000
|
Size: |
458752
|
|
ADA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3701305566.0000000000ADA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ADA000
|
Size: |
16384
|
|
2B9C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002B9C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B9C000
|
Size: |
4096
|
|
64D5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706802927.00000000064D5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
64D5000
|
Size: |
45056
|
|
3ABC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003ABC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3ABC000
|
Size: |
4096
|
|
176E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229024920.000000000176E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
176E000
|
Size: |
4096
|
|
2BD2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002BD2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BD2000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
64E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706873235.00000000064E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
64E0000
|
Size: |
40960
|
|
29E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.00000000029E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29E0000
|
Size: |
4096
|
|
2AAF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002AAF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AAF000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3D50000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1235488215.0000000003D50000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3D50000
|
Size: |
1187840
|
|
3C12000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3704002615.0000000003C12000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C12000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
607D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3706196929.000000000607D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
607D000
|
Size: |
12288
|
|
26F6000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3702123401.00000000026F6000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
26F6000
|
Size: |
8192
|
|
6550000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3707019206.0000000006550000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6550000
|
Size: |
4096
|
|
63D0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3706405864.00000000063D0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
63D0000
|
Size: |
65536
|
|
2ADC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3702479918.0000000002ADC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2ADC000
|
Size: |
8192
|
|
3894000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1238630319.0000000003894000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3894000
|
Size: |
8192
|
|