3374000
|
heap
|
page read and write
|
 |
|
|
Name: |
00000001.00000002.2126100985.0000000003374000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3374000
|
Size: |
299008
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Telegram RAT |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected VIP Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7940000
|
trusted library section
|
page read and write
|
 |
|
|
Name: |
00000001.00000002.2131036571.0000000007940000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
7940000
|
Size: |
299008
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Telegram RAT |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected VIP Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7D00000
|
trusted library section
|
page read and write
|
 |
|
|
Name: |
00000001.00000002.2131821345.0000000007D00000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
7D00000
|
Size: |
294912
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Telegram RAT |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected VIP Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
326D000
|
heap
|
page read and write
|
 |
|
|
Name: |
00000001.00000003.874966902.000000000326D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
326D000
|
Size: |
307200
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Telegram RAT |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected VIP Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
53A1000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000001.00000002.2127341239.00000000053A1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53A1000
|
Size: |
315392
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
URLs found in memory or binary data |
Networking |
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.967295509.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
36864
|
|
56AA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.00000000056AA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56AA000
|
Size: |
4096
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024335683.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
91A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1959336033.00000000091A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91A0000
|
Size: |
16384
|
|
7DE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.890873142.0000000007DE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DE0000
|
Size: |
36864
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024200402.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
7DE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891912107.0000000007DE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DE0000
|
Size: |
20480
|
|
230000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.874291658.0000000000230000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
230000
|
Size: |
4096
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024856365.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
7A01000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2131454333.0000000007A01000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
7A01000
|
Size: |
20480
|
|
5617000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005617000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5617000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
327C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.887539577.000000000327C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
327C000
|
Size: |
4096
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892635950.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019952951.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
EC9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874631244.0000000000EC9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EC9000
|
Size: |
118784
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1017797290.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
20480
|
|
66FD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000066FD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
66FD000
|
Size: |
8192
|
|
7D60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.875400850.0000000007D60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D60000
|
Size: |
65536
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1022263189.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
45056
|
|
90E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018521263.00000000090E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90E0000
|
Size: |
65536
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.893186302.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
20480
|
|
5447000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005447000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5447000
|
Size: |
4096
|
|
7B18000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131521951.0000000007B18000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B18000
|
Size: |
20480
|
|
67B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000067B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
67B0000
|
Size: |
4096
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891588815.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.890616444.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
9190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1959768082.0000000009190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9190000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.889960341.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
20480
|
|
544B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.000000000544B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
544B000
|
Size: |
4096
|
|
2F7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2124468339.0000000002F7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2F7E000
|
Size: |
8192
|
|
4DA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126344030.0000000004DA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4DA0000
|
Size: |
4096
|
|
9601000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2133157813.0000000009601000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9601000
|
Size: |
8192
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.875691709.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
12288
|
|
3A7E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873148270.0000000003A7E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A7E000
|
Size: |
24576
|
|
79E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131394212.00000000079E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79E0000
|
Size: |
65536
|
|
2BC6000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2124091435.0000000002BC6000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2BC6000
|
Size: |
40960
|
|
90F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018797371.00000000090F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90F0000
|
Size: |
65536
|
|
7DD0000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.894232527.0000000007DD0000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
4096
|
|
326A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2125605305.000000000326A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
326A000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1026100260.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021530237.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
3A0D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873148270.0000000003A0D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A0D000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.889730191.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
2FF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2124757752.0000000002FF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FF0000
|
Size: |
4096
|
|
54AA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.00000000054AA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
54AA000
|
Size: |
4096
|
|
91D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1025868996.00000000091D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91D0000
|
Size: |
65536
|
|
33F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.875114425.00000000033F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33F4000
|
Size: |
8192
|
|
79A6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131122578.00000000079A6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79A6000
|
Size: |
8192
|
|
54FD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.00000000054FD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
54FD000
|
Size: |
8192
|
|
32B5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126004311.00000000032B5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32B5000
|
Size: |
327680
|
|
32BC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.874680325.00000000032BC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32BC000
|
Size: |
139264
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132514668.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
65536
|
|
3A0D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.871212257.0000000003A0D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A0D000
|
Size: |
458752
|
|
3A0D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873973111.0000000003A0D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A0D000
|
Size: |
458752
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019927089.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891873336.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891292769.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
56E2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.00000000056E2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56E2000
|
Size: |
4096
|
|
2BF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.860763832.00000000002BF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2BF000
|
Size: |
147456
|
|
32CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.874824269.00000000032CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32CA000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.890758147.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
545F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.000000000545F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
545F000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
554F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.000000000554F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
554F000
|
Size: |
167936
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5001000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126781574.0000000005001000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5001000
|
Size: |
16384
|
|
3A7E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873565650.0000000003A7E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A7E000
|
Size: |
24576
|
|
38E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.872520541.00000000038E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38E0000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.875775196.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
16384
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018955533.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
90F0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2132632070.00000000090F0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
90F0000
|
Size: |
8192
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020965730.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
8E5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132377295.0000000008E5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8E5E000
|
Size: |
8192
|
|
38E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873973111.00000000038E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38E0000
|
Size: |
1196032
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021476023.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
4DE3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2126519886.0000000004DE3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
4DE3000
|
Size: |
4096
|
|
CF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874573294.0000000000CF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF0000
|
Size: |
24576
|
|
3274000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.883193639.0000000003274000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3274000
|
Size: |
4096
|
|
9250000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1028453840.0000000009250000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9250000
|
Size: |
65536
|
|
7DE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.890830926.0000000007DE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DE0000
|
Size: |
20480
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024236715.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.889931379.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
231000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.874307554.0000000000231000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
231000
|
Size: |
581632
|
|
544F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.000000000544F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
544F000
|
Size: |
4096
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877373710.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
16384
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020317895.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
53248
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024391603.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020828065.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1026004069.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
8192
|
|
7DD0000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.894274378.0000000007DD0000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
4096
|
|
9190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132799582.0000000009190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9190000
|
Size: |
40960
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1017658026.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
40960
|
|
7B30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.950890913.0000000007B30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B30000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024758023.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
8296000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132053654.0000000008296000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8296000
|
Size: |
8192
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892849643.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
521B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2127114268.000000000521B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
521B000
|
Size: |
4096
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892569605.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
20480
|
|
9225000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132999640.0000000009225000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9225000
|
Size: |
45056
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1026458933.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
65536
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019382968.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
9240000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2133104048.0000000009240000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
9240000
|
Size: |
53248
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1017880116.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
12288
|
|
558C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.000000000558C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
558C000
|
Size: |
8192
|
|
E74000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.861405424.0000000000E74000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E74000
|
Size: |
53248
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892360236.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
322B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2125051450.000000000322B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
322B000
|
Size: |
4096
|
|
3A7E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.872520541.0000000003A7E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A7E000
|
Size: |
24576
|
|
520A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2126956711.000000000520A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
520A000
|
Size: |
8192
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021504482.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020403669.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
36864
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891175738.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
7B34000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131632241.0000000007B34000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B34000
|
Size: |
16384
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1017859255.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
12288
|
|
EF7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.861284551.0000000000EF7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EF7000
|
Size: |
131072
|
|
9187000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132746952.0000000009187000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9187000
|
Size: |
36864
|
|
3A7E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.872097503.0000000003A7E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A7E000
|
Size: |
24576
|
|
8294000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132053654.0000000008294000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8294000
|
Size: |
4096
|
|
56ED000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.00000000056ED000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56ED000
|
Size: |
303104
|
|
6793000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.0000000006793000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6793000
|
Size: |
16384
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018240178.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
16384
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.890715512.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877539857.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
12288
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1017931034.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
16384
|
|
565D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.000000000565D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
565D000
|
Size: |
229376
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018884938.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
53248
|
|
426000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2123681636.0000000000426000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
426000
|
Size: |
4096
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1017906282.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
12288
|
|
3740000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.871968789.0000000003740000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3740000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020456962.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1023943840.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
91E6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132939882.00000000091E6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91E6000
|
Size: |
4096
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877397000.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891531949.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
20480
|
|
829D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.967378606.000000000829D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
829D000
|
Size: |
12288
|
|
3740000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873032833.0000000003740000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3740000
|
Size: |
1187840
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019037982.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
4E01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126712282.0000000004E01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E01000
|
Size: |
16384
|
|
667B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.000000000667B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
667B000
|
Size: |
4096
|
|
9260000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1962538015.0000000009260000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9260000
|
Size: |
65536
|
|
6713000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.0000000006713000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6713000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
56B3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.00000000056B3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56B3000
|
Size: |
8192
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892427399.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
55A3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.00000000055A3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
55A3000
|
Size: |
307200
|
|
3A7E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.871212257.0000000003A7E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A7E000
|
Size: |
24576
|
|
6459000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.0000000006459000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6459000
|
Size: |
172032
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019677744.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
65536
|
|
FF3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.865554852.0000000000FF3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FF3000
|
Size: |
69632
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018703816.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
16384
|
|
E83000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.861167411.0000000000E83000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E83000
|
Size: |
253952
|
|
6824000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.0000000006824000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6824000
|
Size: |
12288
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019071700.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
63A9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000063A9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63A9000
|
Size: |
4096
|
|
5240000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127191999.0000000005240000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5240000
|
Size: |
4096
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892140843.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
90DF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018544241.00000000090DF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90DF000
|
Size: |
4096
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024059452.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020907247.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019735957.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
5212000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127014194.0000000005212000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5212000
|
Size: |
4096
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1022228298.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
9260000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1028431994.0000000009260000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9260000
|
Size: |
61440
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1962090343.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
53248
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891980837.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
2E00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2124167577.0000000002E00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
4096
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891661562.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892594910.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021399177.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891238911.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
56DA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.00000000056DA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56DA000
|
Size: |
12288
|
|
7B2B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.919913799.0000000007B2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B2B000
|
Size: |
24576
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877573574.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891810676.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
EEF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.861931024.0000000000EEF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EEF000
|
Size: |
659456
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1023839228.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
793E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131002906.000000000793E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
793E000
|
Size: |
8192
|
|
78E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2130973945.00000000078E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
78E0000
|
Size: |
65536
|
|
7B38000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.920086694.0000000007B38000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B38000
|
Size: |
16384
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.889704280.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
20480
|
|
EC9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.864540091.0000000000EC9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EC9000
|
Size: |
118784
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1027908745.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
36864
|
|
5501000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005501000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5501000
|
Size: |
57344
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877416776.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
12288
|
|
3A0D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.871679703.0000000003A0D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A0D000
|
Size: |
458752
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891318271.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
3863000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873032833.0000000003863000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3863000
|
Size: |
507904
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
4DFD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2126675956.0000000004DFD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
4DFD000
|
Size: |
4096
|
|
5625000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005625000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5625000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
9260000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1962639765.0000000009260000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9260000
|
Size: |
53248
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1023502940.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
FE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.865214527.0000000000FE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FE4000
|
Size: |
131072
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.889772102.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
38E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.871679703.00000000038E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38E0000
|
Size: |
1196032
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892720910.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891712074.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
28672
|
|
65A5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000065A5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
65A5000
|
Size: |
20480
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891153004.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
5487000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005487000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5487000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4DE4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126545346.0000000004DE4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DE4000
|
Size: |
8192
|
|
65D7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000065D7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
65D7000
|
Size: |
4096
|
|
757E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2130877059.000000000757E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
757E000
|
Size: |
8192
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892063834.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.890265195.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
20480
|
|
5415000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005415000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5415000
|
Size: |
4096
|
|
2E4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.874362016.00000000002E4000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2E4000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018603616.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
65536
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1022380964.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
65536
|
|
9190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1960876706.0000000009190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9190000
|
Size: |
28672
|
|
7DE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131921428.0000000007DE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DE0000
|
Size: |
61440
|
|
747C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2130849060.000000000747C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
747C000
|
Size: |
16384
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020347708.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
20480
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892529158.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
40960
|
|
56A7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.00000000056A7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56A7000
|
Size: |
8192
|
|
7B74000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1961315459.0000000007B74000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B74000
|
Size: |
8192
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892321365.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
9460000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1962428471.0000000009460000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9460000
|
Size: |
61440
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018038815.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
20480
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891954450.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1025895097.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
65536
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.889674268.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
20480
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024534308.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
EF6000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.874793133.0000000000EF6000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
EF6000
|
Size: |
4096
|
|
56A1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.00000000056A1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56A1000
|
Size: |
8192
|
|
5518000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005518000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5518000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024302698.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
9260000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1962156765.0000000009260000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9260000
|
Size: |
24576
|
|
2F7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.874413580.00000000002F7000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2F7000
|
Size: |
319488
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018130159.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.890790770.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
20480
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.890190596.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
5407000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005407000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5407000
|
Size: |
12288
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019846603.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
553B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.000000000553B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
553B000
|
Size: |
8192
|
|
7DD1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892226550.0000000007DD1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD1000
|
Size: |
61440
|
|
231000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.860702481.0000000000231000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
231000
|
Size: |
581632
|
|
82AD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132134393.00000000082AD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82AD000
|
Size: |
12288
|
|
8290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.958981022.0000000008290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8290000
|
Size: |
12288
|
|
436000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2123681636.0000000000436000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
436000
|
Size: |
4096
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018653556.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
36864
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1961985128.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
65536
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891120788.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
7B54000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1961612260.0000000007B54000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B54000
|
Size: |
16384
|
|
80CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131949628.00000000080CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
80CF000
|
Size: |
4096
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1023749012.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
3A09000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.872097503.0000000003A09000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A09000
|
Size: |
4096
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892021242.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
65ED000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000065ED000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
65ED000
|
Size: |
12288
|
|
91B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132854256.00000000091B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91B0000
|
Size: |
45056
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024274418.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
7D80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.875893359.0000000007D80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D80000
|
Size: |
16384
|
|
34FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126273438.00000000034FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
34FE000
|
Size: |
8192
|
|
79BE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131122578.00000000079BE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79BE000
|
Size: |
4096
|
|
64E3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000064E3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
64E3000
|
Size: |
12288
|
|
7B2A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.904520642.0000000007B2A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B2A000
|
Size: |
36864
|
|
5F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874461012.00000000005F0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F0000
|
Size: |
4096
|
|
7D80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877733148.0000000007D80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D80000
|
Size: |
12288
|
|
53EF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.00000000053EF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53EF000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
32B4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1969222885.00000000032B4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32B4000
|
Size: |
331776
|
|
9222000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132999640.0000000009222000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9222000
|
Size: |
8192
|
|
7B5F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1961516262.0000000007B5F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B5F000
|
Size: |
45056
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891029236.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1027785103.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
40960
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024096975.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019815377.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877489057.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021642987.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
8290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.958924588.0000000008290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8290000
|
Size: |
16384
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.889799597.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892039737.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
9250000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2133132525.0000000009250000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9250000
|
Size: |
4096
|
|
BBF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874480050.0000000000BBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BBF000
|
Size: |
4096
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020992493.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
6707000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.0000000006707000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6707000
|
Size: |
8192
|
|
7B1E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131549322.0000000007B1E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B1E000
|
Size: |
4096
|
|
7D50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131862695.0000000007D50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D50000
|
Size: |
65536
|
|
73C5D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2133290926.0000000073C5D000.00000004.00000001.01000000.00000009.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
73C5D000
|
Size: |
8192
|
|
3740000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873399601.0000000003740000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3740000
|
Size: |
1187840
|
|
32D1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.874729103.00000000032D1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32D1000
|
Size: |
53248
|
|
5512000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005512000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5512000
|
Size: |
4096
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.875736349.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
12288
|
|
3740000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.871061291.0000000003740000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3740000
|
Size: |
1187840
|
|
F16000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.861365640.0000000000F16000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F16000
|
Size: |
4096
|
|
2BF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.874362016.00000000002BF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2BF000
|
Size: |
147456
|
|
E85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.861589030.0000000000E85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E85000
|
Size: |
245760
|
|
FA3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874923730.0000000000FA3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FA3000
|
Size: |
16384
|
|
2B89000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2124005880.0000000002B89000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B89000
|
Size: |
28672
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024559839.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021451168.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
5202000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126887030.0000000005202000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5202000
|
Size: |
4096
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021672276.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
5230000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127152294.0000000005230000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5230000
|
Size: |
4096
|
|
91C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132880305.00000000091C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
4096
|
|
F91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874892308.0000000000F91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F91000
|
Size: |
69632
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.959086719.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
24576
|
|
3863000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873835799.0000000003863000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3863000
|
Size: |
507904
|
|
8F5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132404036.0000000008F5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8F5E000
|
Size: |
8192
|
|
3863000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873399601.0000000003863000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3863000
|
Size: |
507904
|
|
9110000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018455847.0000000009110000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9110000
|
Size: |
45056
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877620289.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
16384
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891203057.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
6653000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.0000000006653000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6653000
|
Size: |
4096
|
|
7D80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877683881.0000000007D80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D80000
|
Size: |
12288
|
|
8290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.959110943.0000000008290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8290000
|
Size: |
65536
|
|
7B31000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131549322.0000000007B31000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B31000
|
Size: |
8192
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.875813343.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
12288
|
|
79CD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131122578.00000000079CD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79CD000
|
Size: |
69632
|
|
73C40000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000002.2133200295.0000000073C40000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
73C40000
|
Size: |
4096
|
|
5101000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126818366.0000000005101000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5101000
|
Size: |
4096
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020882847.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024504377.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
9260000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1962704256.0000000009260000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9260000
|
Size: |
57344
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018189126.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
16384
|
|
63D3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000063D3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63D3000
|
Size: |
12288
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.875847268.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
20480
|
|
E92000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.862079731.0000000000E92000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E92000
|
Size: |
86016
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021238079.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
4F01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126747396.0000000004F01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4F01000
|
Size: |
4096
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018729679.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
40960
|
|
53FB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.00000000053FB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53FB000
|
Size: |
40960
|
|
3A09000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.871212257.0000000003A09000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A09000
|
Size: |
4096
|
|
7D80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877709540.0000000007D80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D80000
|
Size: |
12288
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1025968566.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
20480
|
|
EC9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.865407354.0000000000EC9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EC9000
|
Size: |
118784
|
|
3272000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2125605305.0000000003272000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3272000
|
Size: |
45056
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1028497111.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
53248
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1023376885.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019133954.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
8290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.967319401.0000000008290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8290000
|
Size: |
65536
|
|
6668000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.0000000006668000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6668000
|
Size: |
16384
|
|
8A9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132214554.0000000008A9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8A9E000
|
Size: |
8192
|
|
9190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1961019983.0000000009190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9190000
|
Size: |
28672
|
|
3863000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.871061291.0000000003863000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3863000
|
Size: |
507904
|
|
5651000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005651000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5651000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892683442.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
90A0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2132486056.00000000090A0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
90A0000
|
Size: |
65536
|
|
79C1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131122578.00000000079C1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79C1000
|
Size: |
16384
|
|
37FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126307380.00000000037FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
37FF000
|
Size: |
4096
|
|
543F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.000000000543F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
543F000
|
Size: |
4096
|
|
3333000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126100985.0000000003333000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3333000
|
Size: |
262144
|
|
328F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2125910774.000000000328F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
328F000
|
Size: |
151552
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018284959.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
12288
|
|
5206000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2126920605.0000000005206000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5206000
|
Size: |
8192
|
|
909E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132458836.000000000909E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
909E000
|
Size: |
8192
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877467835.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
12288
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020045529.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
40960
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891768429.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021183243.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1027709115.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
65536
|
|
323C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2125224742.000000000323C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
323C000
|
Size: |
4096
|
|
5590000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005590000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5590000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
79C6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131122578.00000000079C6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79C6000
|
Size: |
16384
|
|
90C0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2132545614.00000000090C0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
90C0000
|
Size: |
65536
|
|
32CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.874760291.00000000032CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32CF000
|
Size: |
8192
|
|
2E50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2124318391.0000000002E50000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E50000
|
Size: |
4096
|
|
EF6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.865071589.0000000000EF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EF6000
|
Size: |
630784
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1023551615.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
9110000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2132686491.0000000009110000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
9110000
|
Size: |
65536
|
|
E50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874631244.0000000000E50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E50000
|
Size: |
20480
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1023064261.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
53248
|
|
9100000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018476745.0000000009100000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9100000
|
Size: |
65536
|
|
90D0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2132576347.00000000090D0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
90D0000
|
Size: |
65536
|
|
7DE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891438520.0000000007DE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DE0000
|
Size: |
36864
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891844469.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
5453000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005453000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5453000
|
Size: |
4096
|
|
6408000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.0000000006408000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6408000
|
Size: |
16384
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.875539582.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
229376
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892121854.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877451579.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
12288
|
|
9260000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1961754453.0000000009260000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9260000
|
Size: |
32768
|
|
79F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131422922.00000000079F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79F0000
|
Size: |
65536
|
|
E57000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874631244.0000000000E57000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E57000
|
Size: |
188416
|
|
3863000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.871968789.0000000003863000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3863000
|
Size: |
507904
|
|
9180000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132746952.0000000009180000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9180000
|
Size: |
8192
|
|
3863000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.871503358.0000000003863000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3863000
|
Size: |
507904
|
|
641D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.000000000641D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
641D000
|
Size: |
8192
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1017619671.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
20480
|
|
4DE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126484481.0000000004DE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DE0000
|
Size: |
12288
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018625926.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
53248
|
|
7B38000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1030471863.0000000007B38000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B38000
|
Size: |
36864
|
|
E83000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.861405424.0000000000E83000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E83000
|
Size: |
475136
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019355002.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
9214000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132970625.0000000009214000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9214000
|
Size: |
36864
|
|
5620000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005620000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5620000
|
Size: |
4096
|
|
3287000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2125768223.0000000003287000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3287000
|
Size: |
28672
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892701976.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
545B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.000000000545B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
545B000
|
Size: |
4096
|
|
54AC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.00000000054AC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
54AC000
|
Size: |
290816
|
|
7D86000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877188234.0000000007D86000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D86000
|
Size: |
40960
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1017831529.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
16384
|
|
7D80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.876765665.0000000007D80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D80000
|
Size: |
16384
|
|
327E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2125768223.000000000327E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
327E000
|
Size: |
32768
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.893233805.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
829A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132053654.000000000829A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
829A000
|
Size: |
24576
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1028622066.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
20480
|
|
8BDD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132268806.0000000008BDD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8BDD000
|
Size: |
12288
|
|
CD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874556310.0000000000CD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD0000
|
Size: |
4096
|
|
8290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.958954629.0000000008290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8290000
|
Size: |
16384
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.967355622.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
65536
|
|
7B4A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.974065675.0000000007B4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B4A000
|
Size: |
16384
|
|
322D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2125224742.000000000322D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
322D000
|
Size: |
28672
|
|
90F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018498986.00000000090F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90F0000
|
Size: |
65536
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019183482.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019300190.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021291513.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
7B20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131549322.0000000007B20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B20000
|
Size: |
65536
|
|
7D90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877157973.0000000007D90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D90000
|
Size: |
65536
|
|
4DC0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126409899.0000000004DC0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
4DC0000
|
Size: |
4096
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021317076.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
554A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.000000000554A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
554A000
|
Size: |
8192
|
|
655D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.000000000655D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
655D000
|
Size: |
12288
|
|
3740000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873835799.0000000003740000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3740000
|
Size: |
1187840
|
|
820E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132001087.000000000820E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
820E000
|
Size: |
8192
|
|
3220000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.874010228.0000000003220000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3220000
|
Size: |
36864
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019327062.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
2FE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2124678861.0000000002FE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FE0000
|
Size: |
4096
|
|
EF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.864674058.0000000000EF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EF0000
|
Size: |
655360
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
90E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020259928.00000000090E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90E0000
|
Size: |
12288
|
|
2F7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.860840320.00000000002F7000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2F7000
|
Size: |
319488
|
|
4DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126447031.0000000004DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DD0000
|
Size: |
8192
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1023629942.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
8B9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132240213.0000000008B9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8B9E000
|
Size: |
8192
|
|
63A1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000063A1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63A1000
|
Size: |
20480
|
|
90C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018863686.00000000090C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90C0000
|
Size: |
65536
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891557893.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
8CDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132297823.0000000008CDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8CDE000
|
Size: |
8192
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892099452.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
79AB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131122578.00000000079AB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79AB000
|
Size: |
8192
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.875870855.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
16384
|
|
32B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1959973931.00000000032B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32B3000
|
Size: |
335872
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132134393.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
49152
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019872763.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
5629000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005629000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5629000
|
Size: |
122880
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1027941210.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
36864
|
|
560D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.000000000560D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
560D000
|
Size: |
4096
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891684617.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
2E20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2124240812.0000000002E20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E20000
|
Size: |
12288
|
|
9220000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132999640.0000000009220000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9220000
|
Size: |
4096
|
|
3002000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2124819435.0000000003002000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3002000
|
Size: |
20480
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.875369206.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
40960
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1027879985.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
36864
|
|
7B3C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.945785917.0000000007B3C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B3C000
|
Size: |
32768
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021615485.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
4DED000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2126579773.0000000004DED000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
4DED000
|
Size: |
4096
|
|
EEF000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.874793133.0000000000EEF000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
EEF000
|
Size: |
16384
|
|
2F2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.860807992.00000000002F2000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
2F2000
|
Size: |
8192
|
|
67DC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000067DC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
67DC000
|
Size: |
20480
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021423498.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
38E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.871212257.00000000038E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38E0000
|
Size: |
1196032
|
|
3274000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.883117517.0000000003274000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3274000
|
Size: |
36864
|
|
5579000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005579000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5579000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024822577.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019501677.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.893095015.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
2FD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2124602300.0000000002FD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FD0000
|
Size: |
4096
|
|
EA7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.861931024.0000000000EA7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EA7000
|
Size: |
258048
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020283007.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
65536
|
|
78C0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2130908710.00000000078C0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
78C0000
|
Size: |
65536
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018084504.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
12288
|
|
9100000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132658826.0000000009100000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9100000
|
Size: |
65536
|
|
5543000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005543000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5543000
|
Size: |
4096
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.875474904.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
135168
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1028002939.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
4096
|
|
3A09000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873565650.0000000003A09000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A09000
|
Size: |
4096
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1027756819.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
36864
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892825878.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
9270000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1962500859.0000000009270000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9270000
|
Size: |
65536
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892914439.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
5541000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005541000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5541000
|
Size: |
4096
|
|
E98000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.864540091.0000000000E98000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E98000
|
Size: |
151552
|
|
7B72000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131768306.0000000007B72000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B72000
|
Size: |
8192
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024009427.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
5457000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005457000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5457000
|
Size: |
4096
|
|
8290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.898595882.0000000008290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8290000
|
Size: |
16384
|
|
8290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.959009353.0000000008290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8290000
|
Size: |
16384
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.890050814.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
1BE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874994518.0000000001BE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1BE0000
|
Size: |
4096
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.893072977.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892872027.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018544241.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
53248
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892968390.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
65536
|
|
79B2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131122578.00000000079B2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79B2000
|
Size: |
28672
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024134652.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
56E4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.00000000056E4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56E4000
|
Size: |
4096
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1028586060.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
12288
|
|
9190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1960266426.0000000009190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9190000
|
Size: |
36864
|
|
5250000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2127227524.0000000005250000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5250000
|
Size: |
4096
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891466756.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
65536
|
|
324A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.874132213.000000000324A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
324A000
|
Size: |
24576
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1028783467.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
36864
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1017982574.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
16384
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021070919.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
38E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873148270.00000000038E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38E0000
|
Size: |
1196032
|
|
589000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874445445.0000000000589000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
589000
|
Size: |
28672
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1023795696.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
7B4C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1961612260.0000000007B4C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B4C000
|
Size: |
28672
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.893017464.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
66EB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000066EB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
66EB000
|
Size: |
8192
|
|
7DE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892170650.0000000007DE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DE0000
|
Size: |
16384
|
|
7B5D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1874813572.0000000007B5D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B5D000
|
Size: |
36864
|
|
9100000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018772888.0000000009100000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9100000
|
Size: |
36864
|
|
32A2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.908597650.00000000032A2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32A2000
|
Size: |
61440
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877597435.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021211193.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
3277000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.883193639.0000000003277000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3277000
|
Size: |
24576
|
|
32C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.874779896.00000000032C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32C7000
|
Size: |
32768
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024693469.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
3A09000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.872520541.0000000003A09000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A09000
|
Size: |
4096
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1023134590.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891635316.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
529E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127266167.000000000529E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
529E000
|
Size: |
8192
|
|
1BF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.875030230.0000000001BF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1BF0000
|
Size: |
8192
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1023415881.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021100482.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
2F30000
|
heap
|
page readonly
|
|
|
|
Name: |
00000001.00000002.2124396008.0000000002F30000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
2F30000
|
Size: |
4096
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018403990.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
16384
|
|
7CFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131793963.0000000007CFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7CFE000
|
Size: |
8192
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877287965.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
65536
|
|
7DD0000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.894254327.0000000007DD0000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
4096
|
|
7DE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892946383.0000000007DE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DE0000
|
Size: |
28672
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891001947.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
3000000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2124819435.0000000003000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3000000
|
Size: |
4096
|
|
7B34000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1874690407.0000000007B34000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B34000
|
Size: |
16384
|
|
4DF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126615007.0000000004DF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DF0000
|
Size: |
8192
|
|
8290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.958852575.0000000008290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8290000
|
Size: |
32768
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019562965.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
6547000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.0000000006547000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6547000
|
Size: |
4096
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019240502.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018677878.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
12288
|
|
7B23000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.904520642.0000000007B23000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B23000
|
Size: |
4096
|
|
3A09000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873148270.0000000003A09000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A09000
|
Size: |
4096
|
|
2E4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.860763832.00000000002E4000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2E4000
|
Size: |
40960
|
|
6579000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.0000000006579000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6579000
|
Size: |
4096
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1027972488.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
36864
|
|
3310000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.875059190.0000000003310000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3310000
|
Size: |
208896
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Yara signature match |
System Summary |
|
|
230000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.860679782.0000000000230000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
230000
|
Size: |
4096
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021559051.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020188801.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
4096
|
|
5411000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005411000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5411000
|
Size: |
4096
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.890894297.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
65536
|
|
33F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.875114425.00000000033F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33F0000
|
Size: |
8192
|
|
79BA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131122578.00000000079BA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79BA000
|
Size: |
4096
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892615725.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
9190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1959521765.0000000009190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9190000
|
Size: |
65536
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.890667633.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019653431.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
57344
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1017768154.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
12288
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018930985.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
32CD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.874802870.00000000032CD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32CD000
|
Size: |
8192
|
|
BDB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874480050.0000000000BDB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BDB000
|
Size: |
20480
|
|
66DA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000066DA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
66DA000
|
Size: |
16384
|
|
90E0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2132604592.00000000090E0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
90E0000
|
Size: |
65536
|
|
73C56000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000002.2133256550.0000000073C56000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
73C56000
|
Size: |
28672
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024596529.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
79A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131122578.00000000079A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79A0000
|
Size: |
20480
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891498860.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
7B39000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131658935.0000000007B39000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B39000
|
Size: |
32768
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019897310.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891266027.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
5210000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126991076.0000000005210000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5210000
|
Size: |
4096
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.889640514.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020370826.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
20480
|
|
91A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1960425146.00000000091A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91A0000
|
Size: |
28672
|
|
9240000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1028475295.0000000009240000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9240000
|
Size: |
65536
|
|
79A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.875070631.00000000079A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79A0000
|
Size: |
16384
|
|
63F3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000063F3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F3000
|
Size: |
4096
|
|
4DF3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126640403.0000000004DF3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DF3000
|
Size: |
28672
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019708683.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
5443000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005443000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5443000
|
Size: |
4096
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.890975290.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
20480
|
|
7DE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891397323.0000000007DE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DE0000
|
Size: |
16384
|
|
5419000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005419000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5419000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020803396.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
EEF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.865407354.0000000000EEF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EEF000
|
Size: |
16384
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019528787.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
BFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874480050.0000000000BFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BFC000
|
Size: |
16384
|
|
5200000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126854916.0000000005200000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5200000
|
Size: |
4096
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018107537.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
12288
|
|
7D80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.876547122.0000000007D80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D80000
|
Size: |
16384
|
|
9260000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1962303732.0000000009260000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9260000
|
Size: |
24576
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891370404.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
D3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874590545.0000000000D3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D3E000
|
Size: |
8192
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.889870795.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
24576
|
|
7DCD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131894644.0000000007DCD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7DCD000
|
Size: |
12288
|
|
3A0D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873565650.0000000003A0D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A0D000
|
Size: |
458752
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021701631.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892781577.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.889905195.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
90E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018820514.00000000090E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90E0000
|
Size: |
65536
|
|
3200000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2124969978.0000000003200000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3200000
|
Size: |
69632
|
|
E83000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.861319981.0000000000E83000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E83000
|
Size: |
475136
|
|
7B29000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.950890913.0000000007B29000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B29000
|
Size: |
4096
|
|
EF6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.865407354.0000000000EF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EF6000
|
Size: |
630784
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
FA7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.865579548.0000000000FA7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FA7000
|
Size: |
249856
|
|
6423000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.0000000006423000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6423000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7D00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.875157821.0000000007D00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D00000
|
Size: |
45056
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1022143505.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
8290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.958892555.0000000008290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8290000
|
Size: |
32768
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892390410.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
4096
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.893211505.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
3212000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2125051450.0000000003212000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3212000
|
Size: |
98304
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024445736.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024472106.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018062427.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
12288
|
|
7D80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877188234.0000000007D80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D80000
|
Size: |
20480
|
|
824D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132027278.000000000824D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
824D000
|
Size: |
12288
|
|
91A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132827527.00000000091A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91A0000
|
Size: |
32768
|
|
7B00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131483796.0000000007B00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B00000
|
Size: |
94208
|
|
1A4F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874970525.0000000001A4F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1A4F000
|
Size: |
4096
|
|
9450000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1962758467.0000000009450000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9450000
|
Size: |
12288
|
|
3740000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.871503358.0000000003740000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3740000
|
Size: |
1187840
|
|
EA3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.865071589.0000000000EA3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EA3000
|
Size: |
131072
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.890549445.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
7B57000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1030503141.0000000007B57000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B57000
|
Size: |
20480
|
|
56DF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.00000000056DF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56DF000
|
Size: |
8192
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024362690.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1028646662.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
16384
|
|
EEF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.865071589.0000000000EEF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EEF000
|
Size: |
16384
|
|
551D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.000000000551D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
551D000
|
Size: |
81920
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1017957800.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
32768
|
|
3A0D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.872520541.0000000003A0D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A0D000
|
Size: |
458752
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021344971.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891094131.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018216755.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
16384
|
|
2EE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874398582.00000000002EE000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2EE000
|
Size: |
36864
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892082597.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
2FCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2124544717.0000000002FCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FCE000
|
Size: |
8192
|
|
66A5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000066A5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
66A5000
|
Size: |
12288
|
|
7D90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.876887640.0000000007D90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D90000
|
Size: |
16384
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018263699.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
16384
|
|
EF7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874835292.0000000000EF7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EF7000
|
Size: |
626688
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
91E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1025842121.00000000091E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91E0000
|
Size: |
4096
|
|
73C5F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000002.2133352276.0000000073C5F000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
73C5F000
|
Size: |
12288
|
|
3863000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.872368982.0000000003863000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3863000
|
Size: |
507904
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019587972.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
38E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.872097503.00000000038E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38E0000
|
Size: |
1196032
|
|
3740000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.872368982.0000000003740000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3740000
|
Size: |
1187840
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1026054803.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
16384
|
|
564A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.000000000564A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
564A000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019438485.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
6702000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.0000000006702000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6702000
|
Size: |
8192
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891610250.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.889835288.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019760981.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892894328.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
20480
|
|
63D7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000063D7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63D7000
|
Size: |
12288
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877513934.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
12288
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018155585.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.890132255.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
9230000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2133077584.0000000009230000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9230000
|
Size: |
45056
|
|
7B42000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131684554.0000000007B42000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B42000
|
Size: |
16384
|
|
642D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.000000000642D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
642D000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
|
3A7E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873973111.0000000003A7E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A7E000
|
Size: |
24576
|
|
9450000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1962461818.0000000009450000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9450000
|
Size: |
65536
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1028039523.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020932007.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018013467.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
12288
|
|
895F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132188039.000000000895F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
895F000
|
Size: |
4096
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.893255697.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.893152721.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
24576
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892991669.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024416690.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018980018.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.889604792.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
7D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877754707.0000000007D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D70000
|
Size: |
65536
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021018332.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892467017.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
E92000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.865407354.0000000000E92000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E92000
|
Size: |
69632
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.890944512.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019268713.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018842053.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
65536
|
|
9100000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1022354818.0000000009100000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9100000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020856279.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
7DD1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891065258.0000000007DD1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD1000
|
Size: |
57344
|
|
3A0D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.872097503.0000000003A0D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A0D000
|
Size: |
458752
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019097972.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
3A09000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.871679703.0000000003A09000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A09000
|
Size: |
4096
|
|
66A9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000066A9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
66A9000
|
Size: |
12288
|
|
91D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1027675780.00000000091D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91D0000
|
Size: |
32768
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892278319.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
8192
|
|
4DB0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2126376799.0000000004DB0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
4DB0000
|
Size: |
4096
|
|
9260000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1961936399.0000000009260000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9260000
|
Size: |
16384
|
|
9190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1960590667.0000000009190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9190000
|
Size: |
65536
|
|
38E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873565650.00000000038E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38E0000
|
Size: |
1196032
|
|
7D80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.875930499.0000000007D80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D80000
|
Size: |
16384
|
|
BCF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874480050.0000000000BCF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BCF000
|
Size: |
4096
|
|
6428000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.0000000006428000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6428000
|
Size: |
8192
|
|
E8C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874631244.0000000000E8C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E8C000
|
Size: |
28672
|
|
9260000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1962787836.0000000009260000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9260000
|
Size: |
65536
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024627847.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
5510000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005510000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5510000
|
Size: |
4096
|
|
7B59000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131742851.0000000007B59000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B59000
|
Size: |
28672
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020772622.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019159595.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1027844699.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
36864
|
|
7D80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.875911692.0000000007D80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D80000
|
Size: |
16384
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019213055.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021153182.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
323E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2125224742.000000000323E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
323E000
|
Size: |
16384
|
|
8290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.967378606.0000000008290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8290000
|
Size: |
49152
|
|
D7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874607434.0000000000D7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D7E000
|
Size: |
8192
|
|
79AE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131122578.00000000079AE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79AE000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024659602.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1961792851.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
65536
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891739744.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
3243000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2125433137.0000000003243000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3243000
|
Size: |
65536
|
|
3252000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.874132213.0000000003252000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3252000
|
Size: |
4096
|
|
3A09000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.873973111.0000000003A09000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A09000
|
Size: |
4096
|
|
7DA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877029813.0000000007DA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DA0000
|
Size: |
57344
|
|
5602000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005602000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5602000
|
Size: |
4096
|
|
66C5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000066C5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
66C5000
|
Size: |
4096
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021373753.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
E92000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.864540091.0000000000E92000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E92000
|
Size: |
16384
|
|
5657000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005657000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5657000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
5215000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2127046429.0000000005215000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5215000
|
Size: |
4096
|
|
5607000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.0000000005607000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5607000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
9260000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1962193433.0000000009260000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9260000
|
Size: |
20480
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1023268460.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1017687875.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
36864
|
|
7990000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131084381.0000000007990000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7990000
|
Size: |
65536
|
|
9260000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1962242233.0000000009260000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9260000
|
Size: |
53248
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024165631.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024725590.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
91D0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2132908091.00000000091D0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
91D0000
|
Size: |
65536
|
|
5217000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2127081108.0000000005217000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5217000
|
Size: |
4096
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892002290.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.893283559.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1020018299.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892664034.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
7D80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.877648179.0000000007D80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D80000
|
Size: |
12288
|
|
7D80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.876707823.0000000007D80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D80000
|
Size: |
16384
|
|
8F9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132431192.0000000008F9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8F9E000
|
Size: |
8192
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892803299.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
82A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1017717053.00000000082A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
82A0000
|
Size: |
12288
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019467856.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1025932555.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
16384
|
|
3254000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2125524665.0000000003254000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3254000
|
Size: |
86016
|
|
9170000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132715755.0000000009170000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9170000
|
Size: |
65536
|
|
90C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1018581168.00000000090C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90C0000
|
Size: |
65536
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.893042676.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.889992937.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
8D1D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132324004.0000000008D1D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8D1D000
|
Size: |
12288
|
|
78D0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2130948623.00000000078D0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
78D0000
|
Size: |
4096
|
|
EC9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.865071589.0000000000EC9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EC9000
|
Size: |
118784
|
|
73A8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2130808076.00000000073A8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
73A8000
|
Size: |
4096
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019005026.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
2EE000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.860807992.00000000002EE000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
2EE000
|
Size: |
8192
|
|
677E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.000000000677E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
677E000
|
Size: |
4096
|
|
9260000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1962357008.0000000009260000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
9260000
|
Size: |
45056
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019986952.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
7B48000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131710154.0000000007B48000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B48000
|
Size: |
65536
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1024790335.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
91A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1961424991.00000000091A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91A0000
|
Size: |
65536
|
|
680E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.000000000680E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
680E000
|
Size: |
4096
|
|
400000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.2123681636.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
147456
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara signature match |
System Summary |
|
|
73C41000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000001.00000002.2133226159.0000000073C41000.00000020.00000001.01000000.00000009.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
73C41000
|
Size: |
86016
|
|
66F6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.00000000066F6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
66F6000
|
Size: |
8192
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891344208.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019615736.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
8290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.959147946.0000000008290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8290000
|
Size: |
4096
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021045182.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
6496000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2129691011.0000000006496000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6496000
|
Size: |
8192
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891791370.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
16384
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019788080.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
EEF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.864540091.0000000000EEF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EEF000
|
Size: |
659456
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.892758568.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
12288
|
|
8E1D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2132349018.0000000008E1D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8E1D000
|
Size: |
12288
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.890222294.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
20480
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1961397363.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
28672
|
|
3013000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.967434065.0000000003013000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3013000
|
Size: |
229376
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021125868.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
56B8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.00000000056B8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56B8000
|
Size: |
98304
|
|
EC1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.861516004.0000000000EC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EC1000
|
Size: |
847872
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
91C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1962044659.00000000091C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91C0000
|
Size: |
40960
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.891930513.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
65536
|
|
EF6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.861589030.0000000000EF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EF6000
|
Size: |
630784
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021263893.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
91D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1026431249.00000000091D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91D0000
|
Size: |
53248
|
|
539E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127303040.000000000539E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
539E000
|
Size: |
8192
|
|
3A7E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.871679703.0000000003A7E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A7E000
|
Size: |
24576
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.893119210.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
20480
|
|
90B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1019410915.00000000090B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90B0000
|
Size: |
12288
|
|
164D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.874947517.000000000164D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
164D000
|
Size: |
12288
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1023228111.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
24576
|
|
91A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1961166028.00000000091A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
91A0000
|
Size: |
45056
|
|
7DD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.890114073.0000000007DD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7DD0000
|
Size: |
20480
|
|
90D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1021586174.00000000090D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
90D0000
|
Size: |
12288
|
|
56E9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2127341239.00000000056E9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
56E9000
|
Size: |
12288
|
|
810E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.2131975628.000000000810E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
810E000
|
Size: |
8192
|
|