22D1000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000002.00000002.3626097293.00000000022D1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22D1000
|
Size: |
692224
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
URLs found in memory or binary data |
Networking |
|
|
24A1000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000002.00000002.3626097293.00000000024A1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24A1000
|
Size: |
368640
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
|
23F0000
|
direct allocation
|
page read and write
|
 |
|
|
Name: |
0000000A.00000002.1298138781.00000000023F0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
23F0000
|
Size: |
135168
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
402000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
0000000B.00000002.3623457854.0000000000402000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
402000
|
Size: |
139264
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
18E0000
|
direct allocation
|
page read and write
|
 |
|
|
Name: |
00000001.00000002.1184876100.00000000018E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
18E0000
|
Size: |
135168
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
2AB1000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
0000000B.00000002.3626990844.0000000002AB1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AB1000
|
Size: |
716800
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
URLs found in memory or binary data |
Networking |
|
|
2C85000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
0000000B.00000002.3626990844.0000000002C85000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C85000
|
Size: |
376832
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
|
380000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000A.00000000.1276473240.0000000000380000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
10
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
380000
|
Size: |
4096
|
|
2900000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626333933.0000000002900000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2900000
|
Size: |
4096
|
|
2536000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002536000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2536000
|
Size: |
131072
|
|
5977000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629844064.0000000005977000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5977000
|
Size: |
184320
|
|
29D6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626369694.00000000029D6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29D6000
|
Size: |
16384
|
|
243C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.000000000243C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
243C000
|
Size: |
106496
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4902000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628596806.0000000004902000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4902000
|
Size: |
28672
|
|
2C69000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002C69000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C69000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
24C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1170231874.00000000024C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
24C0000
|
Size: |
4096
|
|
5C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3624187203.00000000005C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C0000
|
Size: |
28672
|
|
108F000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1184699373.000000000108F000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
108F000
|
Size: |
16384
|
|
19B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184934502.00000000019B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19B0000
|
Size: |
8192
|
|
A50000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623800179.0000000000A50000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A50000
|
Size: |
4096
|
|
1950000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184899247.0000000001950000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1950000
|
Size: |
8192
|
|
10C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184754095.00000000010C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10C8000
|
Size: |
8192
|
|
E40000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1158084403.0000000000E40000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E40000
|
Size: |
4096
|
|
40B3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1289025543.00000000040B3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40B3000
|
Size: |
507904
|
|
434000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000A.00000000.1276620017.0000000000434000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
10
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
434000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
5A6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3630199713.0000000005A6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A6E000
|
Size: |
8192
|
|
1907000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1170065845.0000000001907000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1907000
|
Size: |
184320
|
|
48F6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628596806.00000000048F6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
48F6000
|
Size: |
8192
|
|
11A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1173233793.00000000011A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11A6000
|
Size: |
139264
|
|
4D5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629547531.0000000004D5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D5E000
|
Size: |
8192
|
|
23DE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.00000000023DE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23DE000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1936000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1170065845.0000000001936000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1936000
|
Size: |
4096
|
|
32F9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628143098.00000000032F9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32F9000
|
Size: |
184320
|
|
C08000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624742202.0000000000C08000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C08000
|
Size: |
90112
|
|
3990000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1183665269.0000000003990000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3990000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
5DF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3630772013.0000000005DF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5DF0000
|
Size: |
49152
|
|
184A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1169968071.000000000184A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
184A000
|
Size: |
8192
|
|
1770000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1169099448.0000000001770000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1770000
|
Size: |
24576
|
|
FC0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626068540.0000000000FC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FC0000
|
Size: |
16384
|
|
F44000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3625506327.0000000000F44000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F44000
|
Size: |
8192
|
|
4259000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1287155755.0000000004259000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4259000
|
Size: |
4096
|
|
2D0A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002D0A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D0A000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
380000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000A.00000002.1295814609.0000000000380000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
380000
|
Size: |
4096
|
|
4F66000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629617783.0000000004F66000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4F66000
|
Size: |
4096
|
|
1BF4D430000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1278148610.000001BF4D430000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1BF4D430000
|
Size: |
4096
|
|
1630000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1297607184.0000000001630000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1630000
|
Size: |
24576
|
|
18A7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1158691084.00000000018A7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18A7000
|
Size: |
4096
|
|
29E2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626369694.00000000029E2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29E2000
|
Size: |
49152
|
|
35D1AFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277162283.00000035D1AFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35D1AFF000
|
Size: |
4096
|
|
2524000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002524000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2524000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
1BF4BA5E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277679159.000001BF4BA5E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1BF4BA5E000
|
Size: |
28672
|
|
4130000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1291124269.0000000004130000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4130000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
35D21FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277541758.00000035D21FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35D21FB000
|
Size: |
20480
|
|
F43000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3625485331.0000000000F43000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
F43000
|
Size: |
4096
|
|
7F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3625370991.00000000007F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7F0000
|
Size: |
4096
|
|
42CE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1291124269.00000000042CE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42CE000
|
Size: |
24576
|
|
28F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626279460.00000000028F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
28F0000
|
Size: |
65536
|
|
4259000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1289749803.0000000004259000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4259000
|
Size: |
4096
|
|
35D17FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277071661.00000035D17FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35D17FE000
|
Size: |
8192
|
|
4130000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1290247149.0000000004130000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4130000
|
Size: |
1196032
|
|
42CE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1289214695.00000000042CE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42CE000
|
Size: |
24576
|
|
2532000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002532000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2532000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
3B45000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3628784701.0000000003B45000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B45000
|
Size: |
8192
|
|
5DB3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3630495852.0000000005DB3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5DB3000
|
Size: |
8192
|
|
15F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1297579176.00000000015F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
15F0000
|
Size: |
20480
|
|
4130000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1287155755.0000000004130000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4130000
|
Size: |
1196032
|
|
17BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1169372057.00000000017BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
17BE000
|
Size: |
8192
|
|
5F4E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629842048.0000000005F4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5F4E000
|
Size: |
8192
|
|
7ED000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3625329376.00000000007ED000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7ED000
|
Size: |
4096
|
|
1186000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1172797627.0000000001186000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1186000
|
Size: |
4096
|
|
2424000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1170196365.0000000002424000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2424000
|
Size: |
8192
|
|
62CE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3630313496.00000000062CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
62CE000
|
Size: |
8192
|
|
1857000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1158805281.0000000001857000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1857000
|
Size: |
716800
|
|
DFF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3625280796.0000000000DFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DFF000
|
Size: |
4096
|
|
4130000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1289749803.0000000004130000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4130000
|
Size: |
1196032
|
|
208E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3625859485.000000000208E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
208E000
|
Size: |
8192
|
|
48FE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628596806.00000000048FE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
48FE000
|
Size: |
12288
|
|
16B7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1281508487.00000000016B7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16B7000
|
Size: |
458752
|
|
1B7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3623534828.00000000001B7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1B7000
|
Size: |
36864
|
|
3AB3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1182092792.0000000003AB3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3AB3000
|
Size: |
507904
|
|
2B97000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002B97000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B97000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
40B3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1287000859.00000000040B3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40B3000
|
Size: |
507904
|
|
447000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000A.00000002.1296866637.0000000000447000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
447000
|
Size: |
192512
|
|
10D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1172455556.00000000010D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10D6000
|
Size: |
712704
|
|
1BF4BBBE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1278035432.000001BF4BBBE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1BF4BBBE000
|
Size: |
4096
|
|
42CE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1289749803.00000000042CE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42CE000
|
Size: |
24576
|
|
E41000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1158098503.0000000000E41000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
E41000
|
Size: |
581632
|
|
528E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629278135.000000000528E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
528E000
|
Size: |
8192
|
|
2D40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002D40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D40000
|
Size: |
12288
|
|
4936000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628944181.0000000004936000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4936000
|
Size: |
40960
|
|
5BEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3630309554.0000000005BEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5BEE000
|
Size: |
8192
|
|
42CE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1290247149.00000000042CE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42CE000
|
Size: |
24576
|
|
3990000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1181641737.0000000003990000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3990000
|
Size: |
1187840
|
|
1186000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1174140728.0000000001186000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1186000
|
Size: |
4096
|
|
3C5D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1181393066.0000000003C5D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C5D000
|
Size: |
458752
|
|
64A0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3630635189.00000000064A0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
64A0000
|
Size: |
24576
|
|
ECF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1158152997.0000000000ECF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ECF000
|
Size: |
147456
|
|
4F60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629617783.0000000004F60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4F60000
|
Size: |
8192
|
|
4D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3623920255.00000000004D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D0000
|
Size: |
16384
|
|
5CAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3630414593.0000000005CAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5CAE000
|
Size: |
8192
|
|
2D18000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002D18000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D18000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
11C6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1174111082.00000000011C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11C6000
|
Size: |
8192
|
|
29F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626725436.00000000029F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29F0000
|
Size: |
65536
|
|
595B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629844064.000000000595B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
595B000
|
Size: |
4096
|
|
2B69000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002B69000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B69000
|
Size: |
8192
|
|
2D4C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002D4C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D4C000
|
Size: |
12288
|
|
5DD0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3630697395.0000000005DD0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5DD0000
|
Size: |
4096
|
|
3AB1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3628784701.0000000003AB1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3AB1000
|
Size: |
32768
|
|
29CA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626369694.00000000029CA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29CA000
|
Size: |
4096
|
|
1671000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1297778818.0000000001671000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1671000
|
Size: |
16384
|
|
2A33000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626841834.0000000002A33000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A33000
|
Size: |
8192
|
|
7E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3625283540.00000000007E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7E0000
|
Size: |
49152
|
|
10B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1172455556.00000000010B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10B3000
|
Size: |
57344
|
|
2D00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002D00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D00000
|
Size: |
4096
|
|
5F58000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629872362.0000000005F58000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F58000
|
Size: |
4096
|
|
3AB3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1181641737.0000000003AB3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3AB3000
|
Size: |
507904
|
|
1834000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1158862490.0000000001834000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1834000
|
Size: |
143360
|
|
53AF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629544202.00000000053AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
53AF000
|
Size: |
4096
|
|
17A6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1281474902.00000000017A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17A6000
|
Size: |
4096
|
|
22CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626061799.00000000022CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
22CF000
|
Size: |
4096
|
|
5298000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629359823.0000000005298000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5298000
|
Size: |
8192
|
|
4A6A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629346163.0000000004A6A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A6A000
|
Size: |
12288
|
|
2426000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002426000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2426000
|
Size: |
8192
|
|
3B30000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1183111799.0000000003B30000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B30000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
4259000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1289214695.0000000004259000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4259000
|
Size: |
4096
|
|
381000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000A.00000002.1296357941.0000000000381000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
381000
|
Size: |
581632
|
|
1662000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1277245467.0000000001662000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1662000
|
Size: |
352256
|
|
13DB000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1297244174.00000000013DB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13DB000
|
Size: |
20480
|
|
B9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3623466128.00000000000B9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B9000
|
Size: |
28672
|
|
3355000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628143098.0000000003355000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3355000
|
Size: |
8192
|
|
2CFA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002CFA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CFA000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
807000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3625584034.0000000000807000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
807000
|
Size: |
4096
|
|
5EA0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3630891943.0000000005EA0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5EA0000
|
Size: |
24576
|
|
1040000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184575312.0000000001040000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1040000
|
Size: |
4096
|
|
1058000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184591968.0000000001058000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1058000
|
Size: |
61440
|
|
2B61000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002B61000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B61000
|
Size: |
8192
|
|
3C59000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1183960602.0000000003C59000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C59000
|
Size: |
4096
|
|
1842000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1169894659.0000000001842000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1842000
|
Size: |
16384
|
|
49C3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629211019.00000000049C3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
49C3000
|
Size: |
8192
|
|
3CCE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1183960602.0000000003CCE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3CCE000
|
Size: |
24576
|
|
2388000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002388000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2388000
|
Size: |
12288
|
|
241A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.000000000241A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
241A000
|
Size: |
4096
|
|
15CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1168989622.00000000015CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15CE000
|
Size: |
8192
|
|
176D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1169080851.000000000176D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
176D000
|
Size: |
12288
|
|
27AE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626113226.00000000027AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
27AE000
|
Size: |
8192
|
|
3AD9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3628784701.0000000003AD9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3AD9000
|
Size: |
192512
|
|
4934000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628944181.0000000004934000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4934000
|
Size: |
4096
|
|
EB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184518442.0000000000EB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EB0000
|
Size: |
4096
|
|
3990000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1182941285.0000000003990000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3990000
|
Size: |
1187840
|
|
2BB9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002BB9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BB9000
|
Size: |
8192
|
|
20C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3625971484.00000000020C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20C0000
|
Size: |
4096
|
|
624E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3630249531.000000000624E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
624E000
|
Size: |
8192
|
|
69D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3630678427.00000000069D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
69D0000
|
Size: |
8192
|
|
1887000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1159252782.0000000001887000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1887000
|
Size: |
520192
|
|
2561000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002561000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2561000
|
Size: |
4096
|
|
F77000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3625883598.0000000000F77000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
F77000
|
Size: |
4096
|
|
2BBD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002BBD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BBD000
|
Size: |
12288
|
|
15CE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1297537790.00000000015CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15CE000
|
Size: |
8192
|
|
2A9D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626935739.0000000002A9D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A9D000
|
Size: |
12288
|
|
E20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3625326487.0000000000E20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
E20000
|
Size: |
8192
|
|
10D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1168910309.00000000010D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10D7000
|
Size: |
131072
|
|
1786000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1280632906.0000000001786000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1786000
|
Size: |
135168
|
|
1672000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1278020116.0000000001672000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1672000
|
Size: |
200704
|
|
1BF4B9C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277679159.000001BF4B9C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1BF4B9C0000
|
Size: |
28672
|
|
2500000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1170253721.0000000002500000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2500000
|
Size: |
8192
|
|
102E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184557280.000000000102E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
102E000
|
Size: |
8192
|
|
3C59000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1183111799.0000000003C59000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C59000
|
Size: |
4096
|
|
1833000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1158720743.0000000001833000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1833000
|
Size: |
348160
|
|
2457000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002457000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2457000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
35D16FA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277037715.00000035D16FA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35D16FA000
|
Size: |
24576
|
|
35D1BFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277189709.00000035D1BFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35D1BFF000
|
Size: |
4096
|
|
4259000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1290247149.0000000004259000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4259000
|
Size: |
4096
|
|
496F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629100005.000000000496F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
496F000
|
Size: |
4096
|
|
10F6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1168974685.00000000010F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10F6000
|
Size: |
4096
|
|
5030000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629188578.0000000005030000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5030000
|
Size: |
4096
|
|
1186000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1172280643.0000000001186000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1186000
|
Size: |
4096
|
|
1887000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1169968071.0000000001887000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1887000
|
Size: |
520192
|
|
608D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3630112929.000000000608D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
608D000
|
Size: |
12288
|
|
2B7C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002B7C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B7C000
|
Size: |
4096
|
|
5C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3624187203.00000000005C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C8000
|
Size: |
135168
|
|
548A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629642261.000000000548A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
548A000
|
Size: |
16384
|
|
3F90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1290592073.0000000003F90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F90000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
DBF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184386044.0000000000DBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DBF000
|
Size: |
4096
|
|
2BC1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002BC1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BC1000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
29DD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626369694.00000000029DD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29DD000
|
Size: |
16384
|
|
60CE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3630146410.00000000060CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60CE000
|
Size: |
8192
|
|
59B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629844064.00000000059B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59B3000
|
Size: |
53248
|
|
5C6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3630382622.0000000005C6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5C6E000
|
Size: |
8192
|
|
FA0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3625965575.0000000000FA0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
FA0000
|
Size: |
65536
|
|
5DAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3630469642.0000000005DAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5DAE000
|
Size: |
8192
|
|
F6A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3625756365.0000000000F6A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
F6A000
|
Size: |
8192
|
|
42CE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1287155755.00000000042CE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42CE000
|
Size: |
24576
|
|
2C12000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002C12000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C12000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
80B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3625620529.000000000080B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
80B000
|
Size: |
4096
|
|
6480000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3630597848.0000000006480000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6480000
|
Size: |
4096
|
|
5E80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3630862461.0000000005E80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5E80000
|
Size: |
4096
|
|
43E000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000001.00000000.1168435976.000000000043E000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
43E000
|
Size: |
8192
|
|
16B7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1278020116.00000000016B7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16B7000
|
Size: |
458752
|
|
2398000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002398000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2398000
|
Size: |
8192
|
|
5DE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3630722922.0000000005DE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5DE0000
|
Size: |
65536
|
|
E40000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1168833083.0000000000E40000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E40000
|
Size: |
4096
|
|
4259000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1288656929.0000000004259000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4259000
|
Size: |
4096
|
|
1888000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1158629977.0000000001888000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1888000
|
Size: |
131072
|
|
2380000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002380000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2380000
|
Size: |
8192
|
|
28AE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626184637.00000000028AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
28AE000
|
Size: |
8192
|
|
10D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1172280643.00000000010D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10D6000
|
Size: |
712704
|
|
2D52000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002D52000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D52000
|
Size: |
188416
|
|
49C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629211019.00000000049C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
49C0000
|
Size: |
4096
|
|
29B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626369694.00000000029B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29B0000
|
Size: |
20480
|
|
3B42000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3628784701.0000000003B42000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B42000
|
Size: |
8192
|
|
59A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629844064.00000000059A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59A6000
|
Size: |
4096
|
|
1580000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1297508757.0000000001580000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1580000
|
Size: |
4096
|
|
2B64000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002B64000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B64000
|
Size: |
16384
|
|
5280000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629278135.0000000005280000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5280000
|
Size: |
53248
|
|
1BF4BBB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1278035432.000001BF4BBB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1BF4BBB5000
|
Size: |
32768
|
|
2465000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002465000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2465000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
43E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184309081.000000000043E000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
43E000
|
Size: |
36864
|
|
63CE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3630349696.00000000063CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63CE000
|
Size: |
8192
|
|
3F90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1290078255.0000000003F90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F90000
|
Size: |
1187840
|
|
35D1FFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277340644.00000035D1FFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35D1FFE000
|
Size: |
8192
|
|
2BFE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002BFE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BFE000
|
Size: |
4096
|
|
21CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626014266.00000000021CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
21CE000
|
Size: |
8192
|
|
40B3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1290592073.00000000040B3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40B3000
|
Size: |
507904
|
|
5DBA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3630495852.0000000005DBA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5DBA000
|
Size: |
16384
|
|
490A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628596806.000000000490A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
490A000
|
Size: |
4096
|
|
F02000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1158192161.0000000000F02000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
F02000
|
Size: |
8192
|
|
242E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.000000000242E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
242E000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
AC5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624186481.0000000000AC5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AC5000
|
Size: |
16384
|
|
3AB3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1181264434.0000000003AB3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3AB3000
|
Size: |
507904
|
|
4130000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1288656929.0000000004130000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4130000
|
Size: |
1196032
|
|
241E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.000000000241E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
241E000
|
Size: |
4096
|
|
4F70000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3629759973.0000000004F70000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
4F70000
|
Size: |
65536
|
|
1073000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1169006841.0000000001073000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1073000
|
Size: |
45056
|
|
10A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1169128859.00000000010A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10A6000
|
Size: |
786432
|
|
381000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000001.00000002.1184200464.0000000000381000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
381000
|
Size: |
581632
|
|
A9E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623923777.0000000000A9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A9E000
|
Size: |
8192
|
|
425D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1289749803.000000000425D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
425D000
|
Size: |
458752
|
|
BDE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624472949.0000000000BDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BDE000
|
Size: |
8192
|
|
41D1000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1168159334.00000000041D1000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
41D1000
|
Size: |
192512
|
|
1654000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1277485135.0000000001654000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1654000
|
Size: |
45056
|
|
1843000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1161470832.0000000001843000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1843000
|
Size: |
204800
|
|
1687000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1277619939.0000000001687000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1687000
|
Size: |
655360
|
|
2BFA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002BFA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BFA000
|
Size: |
4096
|
|
336B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628143098.000000000336B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
336B000
|
Size: |
4096
|
|
EAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184494760.0000000000EAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EAE000
|
Size: |
8192
|
|
DCF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184386044.0000000000DCF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DCF000
|
Size: |
4096
|
|
23D2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.00000000023D2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23D2000
|
Size: |
4096
|
|
1887000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1158862490.0000000001887000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1887000
|
Size: |
520192
|
|
2BF6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002BF6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BF6000
|
Size: |
4096
|
|
3CCE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1181393066.0000000003CCE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3CCE000
|
Size: |
24576
|
|
F07000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1158223729.0000000000F07000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F07000
|
Size: |
192512
|
|
1887000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1161901261.0000000001887000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1887000
|
Size: |
520192
|
|
44AD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628407920.00000000044AD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
44AD000
|
Size: |
12288
|
|
40F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000002.1184258520.000000000040F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
40F000
|
Size: |
147456
|
|
592F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629818812.000000000592F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
592F000
|
Size: |
4096
|
|
2C06000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002C06000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C06000
|
Size: |
4096
|
|
4F6B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629617783.0000000004F6B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4F6B000
|
Size: |
12288
|
|
1672000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1280140992.0000000001672000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1672000
|
Size: |
204800
|
|
16B7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1277704426.00000000016B7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16B7000
|
Size: |
458752
|
|
1887000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1162548718.0000000001887000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1887000
|
Size: |
520192
|
|
1650000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1169060332.0000000001650000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1650000
|
Size: |
4096
|
|
1638000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1297607184.0000000001638000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1638000
|
Size: |
180224
|
|
2B7E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002B7E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B7E000
|
Size: |
77824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2514000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002514000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2514000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
4110000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1168159334.0000000004110000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4110000
|
Size: |
729088
|
|
183D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1169421649.000000000183D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
183D000
|
Size: |
20480
|
|
6360000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3630921635.0000000006360000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6360000
|
Size: |
8192
|
|
EFE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1168939768.0000000000EFE000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
EFE000
|
Size: |
36864
|
|
6EA000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623603815.00000000006EA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6EA000
|
Size: |
24576
|
|
2C0A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002C0A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C0A000
|
Size: |
4096
|
|
4960000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629100005.0000000004960000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4960000
|
Size: |
57344
|
|
4A60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629346163.0000000004A60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A60000
|
Size: |
4096
|
|
4A64000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629346163.0000000004A64000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A64000
|
Size: |
12288
|
|
42CE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1288656929.00000000042CE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42CE000
|
Size: |
24576
|
|
3C5D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1183111799.0000000003C5D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C5D000
|
Size: |
458752
|
|
35D1EFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277301040.00000035D1EFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35D1EFF000
|
Size: |
4096
|
|
256C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.000000000256C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
256C000
|
Size: |
188416
|
|
425D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1291124269.000000000425D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
425D000
|
Size: |
458752
|
|
3CCE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1182686824.0000000003CCE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3CCE000
|
Size: |
24576
|
|
239B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.000000000239B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
239B000
|
Size: |
77824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
40F000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000A.00000002.1296767740.000000000040F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
40F000
|
Size: |
147456
|
|
40B3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1287455483.00000000040B3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40B3000
|
Size: |
507904
|
|
3C59000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1181827999.0000000003C59000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C59000
|
Size: |
4096
|
|
2C64000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002C64000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C64000
|
Size: |
4096
|
|
1BF4B9A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277650555.000001BF4B9A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1BF4B9A0000
|
Size: |
4096
|
|
63F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3630493909.00000000063F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63F0000
|
Size: |
53248
|
|
2BB5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002BB5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BB5000
|
Size: |
8192
|
|
23B3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.00000000023B3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23B3000
|
Size: |
77824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
23DA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.00000000023DA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23DA000
|
Size: |
12288
|
|
7BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3624965538.00000000007BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7BE000
|
Size: |
8192
|
|
1FFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1170136008.0000000001FFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1FFE000
|
Size: |
8192
|
|
5290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629359823.0000000005290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5290000
|
Size: |
8192
|
|
3C59000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1182275644.0000000003C59000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C59000
|
Size: |
4096
|
|
442000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000001.00000000.1168435976.0000000000442000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
442000
|
Size: |
8192
|
|
3B38000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3628784701.0000000003B38000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B38000
|
Size: |
8192
|
|
C38000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624742202.0000000000C38000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C38000
|
Size: |
815104
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2AA0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3626966377.0000000002AA0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2AA0000
|
Size: |
4096
|
|
1186000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184754095.0000000001186000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1186000
|
Size: |
4096
|
|
9E0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3625723903.00000000009E0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
9E0000
|
Size: |
65536
|
|
F4D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3625551096.0000000000F4D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
F4D000
|
Size: |
4096
|
|
5483000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629642261.0000000005483000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5483000
|
Size: |
8192
|
|
C1F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624742202.0000000000C1F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C1F000
|
Size: |
45056
|
|
434000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000A.00000002.1296767740.0000000000434000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
434000
|
Size: |
40960
|
|
1096000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1184699373.0000000001096000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1096000
|
Size: |
4096
|
|
1728000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1297953600.0000000001728000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1728000
|
Size: |
245760
|
|
1186000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1172455556.0000000001186000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1186000
|
Size: |
4096
|
|
AA0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624033014.0000000000AA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AA0000
|
Size: |
8192
|
|
2C49000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002C49000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C49000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1910000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1181000255.0000000001910000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
1910000
|
Size: |
4096
|
|
3AB3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1183665269.0000000003AB3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3AB3000
|
Size: |
507904
|
|
3AB3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1182533641.0000000003AB3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3AB3000
|
Size: |
507904
|
|
4922000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628596806.0000000004922000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4922000
|
Size: |
49152
|
|
20B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3625922022.00000000020B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
20B0000
|
Size: |
65536
|
|
1833000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1158659424.0000000001833000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1833000
|
Size: |
348160
|
|
F3E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3625416920.0000000000F3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F3E000
|
Size: |
8192
|
|
434000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000002.1184258520.0000000000434000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
434000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
2420000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1170196365.0000000002420000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2420000
|
Size: |
8192
|
|
7D3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3625138087.00000000007D3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7D3000
|
Size: |
4096
|
|
F62000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3625693673.0000000000F62000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F62000
|
Size: |
4096
|
|
5F75000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629872362.0000000005F75000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F75000
|
Size: |
4096
|
|
400000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3623457854.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
4096
|
|
13BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1297244174.00000000013BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13BE000
|
Size: |
8192
|
|
4C50000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3629517800.0000000004C50000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
4C50000
|
Size: |
4096
|
|
10D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1170101644.00000000010D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10D6000
|
Size: |
589824
|
|
5C2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3630346043.0000000005C2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5C2E000
|
Size: |
8192
|
|
7DD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3625238198.00000000007DD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7DD000
|
Size: |
4096
|
|
49E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3623639149.000000000049E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
49E000
|
Size: |
8192
|
|
548F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629642261.000000000548F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
548F000
|
Size: |
4096
|
|
4259000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1291124269.0000000004259000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4259000
|
Size: |
4096
|
|
204E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3625809216.000000000204E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
204E000
|
Size: |
8192
|
|
610E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3630179368.000000000610E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
610E000
|
Size: |
8192
|
|
16B7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1297871262.00000000016B7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16B7000
|
Size: |
458752
|
|
335F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628143098.000000000335F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
335F000
|
Size: |
8192
|
|
4BAE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629096389.0000000004BAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4BAE000
|
Size: |
8192
|
|
5AEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3630274710.0000000005AEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5AEE000
|
Size: |
8192
|
|
2420000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1298181089.0000000002420000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2420000
|
Size: |
8192
|
|
1083000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1170101644.0000000001083000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1083000
|
Size: |
143360
|
|
3C5D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1183960602.0000000003C5D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C5D000
|
Size: |
458752
|
|
381000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000001.00000000.1168353498.0000000000381000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
381000
|
Size: |
581632
|
|
5490000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3629793411.0000000005490000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5490000
|
Size: |
65536
|
|
2416000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002416000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2416000
|
Size: |
4096
|
|
32D1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628143098.00000000032D1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32D1000
|
Size: |
32768
|
|
255A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.000000000255A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
255A000
|
Size: |
12288
|
|
4F68000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629617783.0000000004F68000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4F68000
|
Size: |
8192
|
|
2D1C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002D1C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D1C000
|
Size: |
131072
|
|
381000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000A.00000000.1276494298.0000000000381000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
10
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
381000
|
Size: |
581632
|
|
7D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3625092777.00000000007D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D0000
|
Size: |
8192
|
|
AC0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624186481.0000000000AC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AC0000
|
Size: |
16384
|
|
7C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3625043502.00000000007C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7C0000
|
Size: |
8192
|
|
5930000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629844064.0000000005930000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
167936
|
|
1082000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1169006841.0000000001082000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1082000
|
Size: |
348160
|
|
237B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.000000000237B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
237B000
|
Size: |
16384
|
|
16D7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1277321552.00000000016D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16D7000
|
Size: |
4096
|
|
5E50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3630821000.0000000005E50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5E50000
|
Size: |
24576
|
|
2422000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002422000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2422000
|
Size: |
4096
|
|
F07000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1168956262.0000000000F07000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F07000
|
Size: |
192512
|
|
F40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3625451289.0000000000F40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F40000
|
Size: |
8192
|
|
1843000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1159252782.0000000001843000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1843000
|
Size: |
200704
|
|
1976000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1162512106.0000000001976000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1976000
|
Size: |
8192
|
|
7E7000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623653603.00000000007E7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7E7000
|
Size: |
36864
|
|
2090000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3625896877.0000000002090000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2090000
|
Size: |
4096
|
|
F7B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3625918294.0000000000F7B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
F7B000
|
Size: |
4096
|
|
3AB3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1182941285.0000000003AB3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3AB3000
|
Size: |
507904
|
|
63E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3630413398.00000000063E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
63E0000
|
Size: |
65536
|
|
2A30000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626841834.0000000002A30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A30000
|
Size: |
4096
|
|
184F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184857711.000000000184F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
184F000
|
Size: |
4096
|
|
2C0E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002C0E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C0E000
|
Size: |
12288
|
|
2B6C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002B6C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B6C000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1090000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1170547496.0000000001090000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1090000
|
Size: |
196608
|
|
3CCE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1183111799.0000000003CCE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3CCE000
|
Size: |
24576
|
|
16B7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1280230655.00000000016B7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16B7000
|
Size: |
458752
|
|
49B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629168188.00000000049B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
49B0000
|
Size: |
65536
|
|
48F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628596806.00000000048F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
48F0000
|
Size: |
20480
|
|
5AAF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3630233475.0000000005AAF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5AAF000
|
Size: |
4096
|
|
C2B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624742202.0000000000C2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C2B000
|
Size: |
12288
|
|
1664000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1277704426.0000000001664000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1664000
|
Size: |
143360
|
|
1678000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1297778818.0000000001678000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1678000
|
Size: |
4096
|
|
2BAC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002BAC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BAC000
|
Size: |
8192
|
|
529B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629359823.000000000529B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
529B000
|
Size: |
20480
|
|
2481000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002481000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2481000
|
Size: |
4096
|
|
35D1DFD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277264018.00000035D1DFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35D1DFD000
|
Size: |
12288
|
|
2566000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002566000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2566000
|
Size: |
12288
|
|
491D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628596806.000000000491D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
491D000
|
Size: |
16384
|
|
E41000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.1168847058.0000000000E41000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
E41000
|
Size: |
581632
|
|
5296000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629359823.0000000005296000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5296000
|
Size: |
4096
|
|
17C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1169402698.00000000017C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
17C0000
|
Size: |
4096
|
|
3F90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1289025543.0000000003F90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F90000
|
Size: |
1187840
|
|
3B30000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1182275644.0000000003B30000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B30000
|
Size: |
1196032
|
|
2383000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002383000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2383000
|
Size: |
16384
|
|
2C02000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002C02000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C02000
|
Size: |
4096
|
|
4A50000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3629295475.0000000004A50000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
4A50000
|
Size: |
65536
|
|
10D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1172387706.00000000010D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10D6000
|
Size: |
712704
|
|
2412000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002412000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2412000
|
Size: |
4096
|
|
10D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1174140728.00000000010D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10D6000
|
Size: |
712704
|
|
1808000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1169421649.0000000001808000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1808000
|
Size: |
184320
|
|
3C59000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1181393066.0000000003C59000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C59000
|
Size: |
4096
|
|
29CE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626369694.00000000029CE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29CE000
|
Size: |
4096
|
|
434000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000000.1168400751.0000000000434000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
434000
|
Size: |
40960
|
|
1BF4B9F5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277679159.000001BF4B9F5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1BF4B9F5000
|
Size: |
176128
|
|
3B4E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3628784701.0000000003B4E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B4E000
|
Size: |
4096
|
|
3C59000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1182686824.0000000003C59000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C59000
|
Size: |
4096
|
|
7FA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3625469546.00000000007FA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FA000
|
Size: |
8192
|
|
1BF4BA68000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277679159.000001BF4BA68000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1BF4BA68000
|
Size: |
102400
|
|
620E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3630215849.000000000620E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
620E000
|
Size: |
8192
|
|
43E000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1296835621.000000000043E000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
43E000
|
Size: |
36864
|
|
43E000
|
unkown
|
page write copy
|
|
|
|
Name: |
0000000A.00000000.1276707045.000000000043E000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
10
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
43E000
|
Size: |
8192
|
|
251A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.000000000251A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
251A000
|
Size: |
4096
|
|
2C77000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002C77000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C77000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
40F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000000.1168400751.000000000040F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
40F000
|
Size: |
147456
|
|
10D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1174697625.00000000010D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10D6000
|
Size: |
712704
|
|
40B3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1289567023.00000000040B3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40B3000
|
Size: |
507904
|
|
6AD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3624876954.00000000006AD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6AD000
|
Size: |
73728
|
|
1679000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1281508487.0000000001679000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1679000
|
Size: |
208896
|
|
47F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628436882.00000000047F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
47F0000
|
Size: |
36864
|
|
3F90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1289567023.0000000003F90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F90000
|
Size: |
1187840
|
|
546E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629572135.000000000546E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
546E000
|
Size: |
8192
|
|
184A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1162548718.000000000184A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
184A000
|
Size: |
208896
|
|
DFA000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1297107882.0000000000DFA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DFA000
|
Size: |
24576
|
|
1887000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1161470832.0000000001887000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1887000
|
Size: |
520192
|
|
BE0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624680057.0000000000BE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BE0000
|
Size: |
4096
|
|
48FB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628596806.00000000048FB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
48FB000
|
Size: |
8192
|
|
29D1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626369694.00000000029D1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29D1000
|
Size: |
16384
|
|
4130000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1289214695.0000000004130000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4130000
|
Size: |
1196032
|
|
43AD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628381862.00000000043AD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
43AD000
|
Size: |
12288
|
|
F75000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3625832208.0000000000F75000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
F75000
|
Size: |
4096
|
|
3990000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1182092792.0000000003990000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3990000
|
Size: |
1187840
|
|
1082000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1168937860.0000000001082000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1082000
|
Size: |
348160
|
|
10CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1174697625.00000000010CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10CA000
|
Size: |
4096
|
|
9F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3625769555.00000000009F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9F0000
|
Size: |
16384
|
|
3CCE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1182275644.0000000003CCE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3CCE000
|
Size: |
24576
|
|
4940000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629053480.0000000004940000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4940000
|
Size: |
65536
|
|
16B7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1280563923.00000000016B7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16B7000
|
Size: |
458752
|
|
447000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000A.00000000.1276768341.0000000000447000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
10
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
447000
|
Size: |
192512
|
|
1663000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1277485135.0000000001663000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1663000
|
Size: |
348160
|
|
3B30000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1183960602.0000000003B30000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B30000
|
Size: |
1196032
|
|
4F80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629126877.0000000004F80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4F80000
|
Size: |
65536
|
|
3C5D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1181827999.0000000003C5D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C5D000
|
Size: |
458752
|
|
3B30000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1182686824.0000000003B30000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B30000
|
Size: |
1196032
|
|
250F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.000000000250F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
250F000
|
Size: |
4096
|
|
EFE000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1158192161.0000000000EFE000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
EFE000
|
Size: |
8192
|
|
1050000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184591968.0000000001050000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1050000
|
Size: |
24576
|
|
EF4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1168888424.0000000000EF4000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EF4000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
4930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628944181.0000000004930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4930000
|
Size: |
4096
|
|
2A10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626782794.0000000002A10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2A10000
|
Size: |
65536
|
|
1937000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1161850841.0000000001937000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1937000
|
Size: |
266240
|
|
1800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1169421649.0000000001800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1800000
|
Size: |
24576
|
|
FB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626018168.0000000000FB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
FB0000
|
Size: |
65536
|
|
425D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1288656929.000000000425D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
425D000
|
Size: |
458752
|
|
4911000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628596806.0000000004911000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4911000
|
Size: |
16384
|
|
1460000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1297442748.0000000001460000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1460000
|
Size: |
4096
|
|
F72000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3625795523.0000000000F72000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F72000
|
Size: |
4096
|
|
2D13000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002D13000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D13000
|
Size: |
4096
|
|
7FA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184363128.00000000007FA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7FA000
|
Size: |
24576
|
|
4A0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629259216.0000000004A0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4A0E000
|
Size: |
8192
|
|
1887000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1161552199.0000000001887000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1887000
|
Size: |
520192
|
|
F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3625582188.0000000000F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F50000
|
Size: |
28672
|
|
16B8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1277167120.00000000016B8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16B8000
|
Size: |
131072
|
|
1BF4B970000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277571488.000001BF4B970000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1BF4B970000
|
Size: |
4096
|
|
ECF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1168888424.0000000000ECF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
ECF000
|
Size: |
147456
|
|
10D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184754095.00000000010D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10D6000
|
Size: |
712704
|
|
4D5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3623920255.00000000004D5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D5000
|
Size: |
12288
|
|
805000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3625548971.0000000000805000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
805000
|
Size: |
4096
|
|
1BF4BA23000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277679159.000001BF4BA23000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1BF4BA23000
|
Size: |
229376
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
7F6000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3625435143.00000000007F6000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7F6000
|
Size: |
8192
|
|
4916000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628596806.0000000004916000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4916000
|
Size: |
16384
|
|
23D6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.00000000023D6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23D6000
|
Size: |
4096
|
|
35D20FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277498407.00000035D20FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35D20FE000
|
Size: |
8192
|
|
1068000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184591968.0000000001068000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1068000
|
Size: |
110592
|
|
5DB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3630495852.0000000005DB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5DB0000
|
Size: |
8192
|
|
5EA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3624187203.00000000005EA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5EA000
|
Size: |
16384
|
|
425D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1287155755.000000000425D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
425D000
|
Size: |
458752
|
|
425D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1290247149.000000000425D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
425D000
|
Size: |
458752
|
|
380000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000000.1168338110.0000000000380000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
380000
|
Size: |
4096
|
|
35D18FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277129287.00000035D18FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35D18FE000
|
Size: |
8192
|
|
3B30000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1181393066.0000000003B30000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B30000
|
Size: |
1196032
|
|
442000
|
unkown
|
page write copy
|
|
|
|
Name: |
0000000A.00000000.1276707045.0000000000442000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
10
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
442000
|
Size: |
8192
|
|
1BF4BA5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277679159.000001BF4BA5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1BF4BA5C000
|
Size: |
4096
|
|
333B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628143098.000000000333B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
333B000
|
Size: |
4096
|
|
29BB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626369694.00000000029BB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29BB000
|
Size: |
8192
|
|
29B6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626369694.00000000029B6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29B6000
|
Size: |
8192
|
|
40F000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000A.00000000.1276620017.000000000040F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
10
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
40F000
|
Size: |
147456
|
|
3990000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1181264434.0000000003990000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3990000
|
Size: |
1187840
|
|
23C9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.00000000023C9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23C9000
|
Size: |
8192
|
|
3B50000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1298210516.0000000003B50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3B50000
|
Size: |
8192
|
|
447000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000002.1184330028.0000000000447000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
447000
|
Size: |
192512
|
|
3C5D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1182275644.0000000003C5D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C5D000
|
Size: |
458752
|
|
4A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3623801090.00000000004A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4A0000
|
Size: |
8192
|
|
13CE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1297244174.00000000013CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13CE000
|
Size: |
8192
|
|
1090000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1172280643.0000000001090000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1090000
|
Size: |
200704
|
|
628E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3630288615.000000000628E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
628E000
|
Size: |
8192
|
|
6400000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3630552862.0000000006400000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6400000
|
Size: |
24576
|
|
F5D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3625621896.0000000000F5D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
F5D000
|
Size: |
4096
|
|
FEA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1168976341.0000000000FEA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FEA000
|
Size: |
24576
|
|
F60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3625661856.0000000000F60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F60000
|
Size: |
4096
|
|
DDB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184386044.0000000000DDB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DDB000
|
Size: |
20480
|
|
2485000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.0000000002485000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2485000
|
Size: |
110592
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2C2D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002C2D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C2D000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7F2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3625396794.00000000007F2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7F2000
|
Size: |
4096
|
|
1187000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1172760958.0000000001187000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1187000
|
Size: |
266240
|
|
5480000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629642261.0000000005480000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5480000
|
Size: |
8192
|
|
E60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184472463.0000000000E60000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E60000
|
Size: |
4096
|
|
1097000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1174140728.0000000001097000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1097000
|
Size: |
212992
|
|
840000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3625691039.0000000000840000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
840000
|
Size: |
16384
|
|
830000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3625659440.0000000000830000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
830000
|
Size: |
4096
|
|
4800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628436882.0000000004800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4800000
|
Size: |
253952
|
|
4A6E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629346163.0000000004A6E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4A6E000
|
Size: |
8192
|
|
108A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184591968.000000000108A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
108A000
|
Size: |
20480
|
|
355F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184952330.000000000355F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
355F000
|
Size: |
4096
|
|
1BF4BA66000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277679159.000001BF4BA66000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1BF4BA66000
|
Size: |
4096
|
|
40B3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1290078255.00000000040B3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40B3000
|
Size: |
507904
|
|
1766000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1297953600.0000000001766000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1766000
|
Size: |
4096
|
|
4F5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629579642.0000000004F5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4F5E000
|
Size: |
8192
|
|
7D4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3625189299.00000000007D4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D4000
|
Size: |
8192
|
|
2C1F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002C1F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C1F000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
490E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628596806.000000000490E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
490E000
|
Size: |
4096
|
|
41C3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1168159334.00000000041C3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
41C3000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
1767000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1280521773.0000000001767000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1767000
|
Size: |
262144
|
|
16B7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1280140992.00000000016B7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16B7000
|
Size: |
458752
|
|
3362000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3628143098.0000000003362000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3362000
|
Size: |
8192
|
|
2C3B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002C3B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C3B000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
10D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1170547496.00000000010D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10D6000
|
Size: |
679936
|
|
1954000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184899247.0000000001954000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1954000
|
Size: |
8192
|
|
2CF5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002CF5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CF5000
|
Size: |
4096
|
|
40E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1170268970.00000000040E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
40E0000
|
Size: |
135168
|
|
13EF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1297244174.00000000013EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13EF000
|
Size: |
4096
|
|
1E2F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1298039100.0000000001E2F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1E2F000
|
Size: |
4096
|
|
63D0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3630384015.00000000063D0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
63D0000
|
Size: |
4096
|
|
15BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1168989622.00000000015BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15BE000
|
Size: |
8192
|
|
5F8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3624187203.00000000005F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F8000
|
Size: |
475136
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
3CCE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1181827999.0000000003CCE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3CCE000
|
Size: |
24576
|
|
F66000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3625721350.0000000000F66000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
F66000
|
Size: |
8192
|
|
5DBF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3630495852.0000000005DBF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5DBF000
|
Size: |
4096
|
|
1956000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1161966672.0000000001956000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1956000
|
Size: |
139264
|
|
5F81000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629872362.0000000005F81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F81000
|
Size: |
172032
|
|
3C5D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1182686824.0000000003C5D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C5D000
|
Size: |
458752
|
|
2D47000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626990844.0000000002D47000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D47000
|
Size: |
4096
|
|
5F50000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629872362.0000000005F50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F50000
|
Size: |
4096
|
|
10D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1172797627.00000000010D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10D6000
|
Size: |
712704
|
|
380000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000002.1184176212.0000000000380000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
380000
|
Size: |
4096
|
|
802000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3625503085.0000000000802000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
802000
|
Size: |
4096
|
|
3F90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1287455483.0000000003F90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F90000
|
Size: |
1187840
|
|
1824000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1158720743.0000000001824000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1824000
|
Size: |
49152
|
|
15DB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1168989622.00000000015DB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15DB000
|
Size: |
20480
|
|
222E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1298076060.000000000222E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
222E000
|
Size: |
8192
|
|
252D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.000000000252D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
252D000
|
Size: |
4096
|
|
595D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3629844064.000000000595D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
595D000
|
Size: |
4096
|
|
1BF4BBB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1278035432.000001BF4BBB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1BF4BBB0000
|
Size: |
16384
|
|
E30000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3625371340.0000000000E30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E30000
|
Size: |
16384
|
|
28ED000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626229297.00000000028ED000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
28ED000
|
Size: |
12288
|
|
29BE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3626369694.00000000029BE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
29BE000
|
Size: |
45056
|
|
DFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184386044.0000000000DFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DFC000
|
Size: |
16384
|
|
15FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1168989622.00000000015FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15FC000
|
Size: |
16384
|
|
F10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1184535844.0000000000F10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F10000
|
Size: |
20480
|
|
450000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3623590985.0000000000450000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
450000
|
Size: |
4096
|
|
166C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1297607184.000000000166C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
166C000
|
Size: |
20480
|
|
447000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000000.1168463576.0000000000447000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
447000
|
Size: |
192512
|
|
23FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1170154574.00000000023FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
23FE000
|
Size: |
8192
|
|
1BF4B980000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277622682.000001BF4B980000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1BF4B980000
|
Size: |
8192
|
|
1186000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1174697625.0000000001186000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1186000
|
Size: |
4096
|
|
157E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1297479730.000000000157E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
157E000
|
Size: |
8192
|
|
3B30000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1181827999.0000000003B30000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B30000
|
Size: |
1196032
|
|
1186000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1172387706.0000000001186000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1186000
|
Size: |
4096
|
|
238C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.000000000238C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
238C000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5DC0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.3630649901.0000000005DC0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5DC0000
|
Size: |
65536
|
|
3F90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1287000859.0000000003F90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3F90000
|
Size: |
1187840
|
|
3B54000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1298210516.0000000003B54000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3B54000
|
Size: |
8192
|
|
13FC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1297244174.00000000013FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13FC000
|
Size: |
16384
|
|
52A0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3629489400.00000000052A0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
52A0000
|
Size: |
4096
|
|
5F70000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3629872362.0000000005F70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F70000
|
Size: |
12288
|
|
23D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1298107413.00000000023D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23D0000
|
Size: |
4096
|
|
3990000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1182533641.0000000003990000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3990000
|
Size: |
1187840
|
|
242A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.3626097293.000000000242A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
242A000
|
Size: |
12288
|
|
5470000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3629603174.0000000005470000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5470000
|
Size: |
65536
|
|
EF4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1158152997.0000000000EF4000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EF4000
|
Size: |
40960
|
|
425D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1289214695.000000000425D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
425D000
|
Size: |
458752
|
|
5270000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3629229352.0000000005270000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5270000
|
Size: |
65536
|
|
C00000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624742202.0000000000C00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C00000
|
Size: |
24576
|
|
1BF4B9C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.1277679159.000001BF4B9C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1BF4B9C8000
|
Size: |
180224
|
|
3B1E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3628784701.0000000003B1E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3B1E000
|
Size: |
4096
|
|