1FB0000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.419614314.0000000001FB0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
1FB0000
|
Size: |
6778880
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
1E0000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000004.00000002.626895631.00000000001E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1E0000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
290000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.419495871.0000000000290000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
290000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
400000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.419524838.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
290816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
190000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000004.00000002.626885310.0000000000190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
190000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
560000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000005.00000002.626989631.0000000000560000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
560000
|
Size: |
307200
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
210000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000008.00000002.481410737.0000000000210000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
210000
|
Size: |
393216
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3E60000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000003.00000002.627085177.0000000003E60000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3E60000
|
Size: |
6778880
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
80000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000004.00000002.626861797.0000000000080000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
80000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
6D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627060262.00000000006D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6D7000
|
Size: |
4096
|
|
C48000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.433978189.0000000000C48000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C48000
|
Size: |
8192
|
|
494000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.626956144.0000000000494000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
494000
|
Size: |
4096
|
|
2D84000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.359072755.0000000002D84000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D84000
|
Size: |
4096
|
|
579E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627774633.000000000579E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
579E000
|
Size: |
8192
|
|
8C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.419809000.00000000008C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8C0000
|
Size: |
4096
|
|
2D84000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355688173.0000000002D84000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D84000
|
Size: |
4096
|
|
CD1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.627106356.0000000000CD1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
CD1000
|
Size: |
4096
|
|
16B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000000.433796797.000000000016B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
16B000
|
Size: |
20480
|
|
83D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.419508364.000000000083D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
83D000
|
Size: |
409600
|
|
1070000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.434017018.0000000001070000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1070000
|
Size: |
348160
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
642000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626975590.0000000000642000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
642000
|
Size: |
8192
|
|
20000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000000.433791942.0000000000020000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
20000
|
Size: |
4096
|
|
1040000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.627199297.0000000001040000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1040000
|
Size: |
4096
|
|
6F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627060262.00000000006F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6F4000
|
Size: |
69632
|
|
FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.626862657.00000000000FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FB000
|
Size: |
20480
|
|
1041000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000005.00000000.434000601.0000000001041000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1041000
|
Size: |
57344
|
|
52D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.400899262.000000000052D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52D000
|
Size: |
409600
|
|
6D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626998866.00000000006D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6D3000
|
Size: |
45056
|
|
4E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482307418.0000000004E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E00000
|
Size: |
16384
|
|
1261000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.359591375.0000000001261000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1261000
|
Size: |
581632
|
|
593E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627590677.000000000593E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
593E000
|
Size: |
8192
|
|
60F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627857375.00000000060F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
60F0000
|
Size: |
16384
|
|
FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.402949608.00000000000FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FB000
|
Size: |
20480
|
|
20000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000000.402944854.0000000000020000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
20000
|
Size: |
4096
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.461868081.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
6D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.433850970.00000000006D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6D0000
|
Size: |
16384
|
|
950000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.627101904.0000000000950000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
950000
|
Size: |
12288
|
|
2B3D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354451283.0000000002B3D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2B3D000
|
Size: |
409600
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
5CFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627637045.0000000005CFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5CFF000
|
Size: |
4096
|
|
69E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626998866.000000000069E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
69E000
|
Size: |
208896
|
|
104F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.627216674.000000000104F000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
104F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1056000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627226507.0000000001056000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1056000
|
Size: |
8192
|
|
59A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627605431.00000000059A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59A0000
|
Size: |
4096
|
|
5830000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627791178.0000000005830000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5830000
|
Size: |
4096
|
|
118F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482043668.000000000118F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
118F000
|
Size: |
4096
|
|
5FCF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627656369.0000000005FCF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5FCF000
|
Size: |
4096
|
|
6A4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.401261747.00000000006A4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A4000
|
Size: |
4096
|
|
131E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359608917.000000000131E000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
131E000
|
Size: |
36864
|
|
62E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.464571300.00000000062E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
62E0000
|
Size: |
4096
|
|
892000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359558527.0000000000892000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
892000
|
Size: |
4096
|
|
307C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627266394.000000000307C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
307C000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2D70000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355275716.0000000002D70000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D70000
|
Size: |
4096
|
|
300000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.419501407.0000000000300000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
300000
|
Size: |
16384
|
|
391A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627266394.000000000391A000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
391A000
|
Size: |
4096
|
|
61ECE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.627953863.0000000061ECE000.00000002.00000001.01000000.00000008.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
61ECE000
|
Size: |
126976
|
|
D50000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.627106356.0000000000D50000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
D50000
|
Size: |
12288
|
|
6529000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.467962206.0000000006529000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6529000
|
Size: |
12288
|
|
66E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482019625.000000000066E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
66E000
|
Size: |
8192
|
|
480000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626948971.0000000000480000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
480000
|
Size: |
24576
|
|
346000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.419501407.0000000000346000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
346000
|
Size: |
131072
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1392000
|
system
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482046973.0000000001392000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
1392000
|
Size: |
8192
|
|
9D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.419809000.00000000009D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9D0000
|
Size: |
368640
|
|
180000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.480633596.0000000000180000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
180000
|
Size: |
12288
|
|
1A18000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627315561.0000000001A18000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
1A18000
|
Size: |
8192
|
|
61ECA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627943270.0000000061ECA000.00000004.00000001.01000000.00000008.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
61ECA000
|
Size: |
4096
|
|
2D81000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355376956.0000000002D81000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D81000
|
Size: |
4096
|
|
130C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627315561.000000000130C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
130C000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
219000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.626895232.0000000000219000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
219000
|
Size: |
61440
|
|
55FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627769004.00000000055FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
55FE000
|
Size: |
8192
|
|
6551000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.467864179.0000000006551000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6551000
|
Size: |
188416
|
|
2D90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.359072755.0000000002D90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D90000
|
Size: |
368640
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
2D87000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355275716.0000000002D87000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D87000
|
Size: |
4096
|
|
4556000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.627085177.0000000004556000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
4556000
|
Size: |
10485760
|
|
705000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626998866.0000000000705000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
705000
|
Size: |
299008
|
|
B80000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.403059453.0000000000B80000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B80000
|
Size: |
348160
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
2DF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355688173.0000000002DF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2DF0000
|
Size: |
20480
|
|
6D7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.433850970.00000000006D7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6D7000
|
Size: |
4096
|
|
2D84000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355275716.0000000002D84000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D84000
|
Size: |
4096
|
|
10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.402939905.0000000000010000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10000
|
Size: |
4096
|
|
CD4000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.627106356.0000000000CD4000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
CD4000
|
Size: |
4096
|
|
9C4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.419809000.00000000009C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C4000
|
Size: |
4096
|
|
20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.420378471.0000000000020000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
20000
|
Size: |
61440
|
|
9B7000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419535822.00000000009B7000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
9B7000
|
Size: |
4096
|
|
6103000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627857375.0000000006103000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6103000
|
Size: |
4096
|
|
2C80000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355376956.0000000002C80000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2C80000
|
Size: |
4096
|
|
B57000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.627106356.0000000000B57000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
B57000
|
Size: |
4096
|
|
2AB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626908570.00000000002AB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2AB000
|
Size: |
4096
|
|
6532000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.467962206.0000000006532000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6532000
|
Size: |
4096
|
|
8D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.419809000.00000000008D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D0000
|
Size: |
876544
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2D87000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.359072755.0000000002D87000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D87000
|
Size: |
4096
|
|
5A3C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627812941.0000000005A3C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A3C000
|
Size: |
16384
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.461585469.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
2A60000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355344717.0000000002A60000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A60000
|
Size: |
884736
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.627095141.00000000007D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7D0000
|
Size: |
20480
|
|
4F56000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.627085177.0000000004F56000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
4F56000
|
Size: |
3526656
|
|
2DF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354583889.0000000002DF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2DF0000
|
Size: |
20480
|
|
1322000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.352427435.0000000001322000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
1322000
|
Size: |
8192
|
|
4E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.626981084.00000000004E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E0000
|
Size: |
16384
|
|
5C4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.626941369.00000000005C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C4000
|
Size: |
4096
|
|
18B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626878323.000000000018B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
18B000
|
Size: |
20480
|
|
2B3D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354342574.0000000002B3D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2B3D000
|
Size: |
409600
|
|
2C40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359619343.0000000002C40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C40000
|
Size: |
4096
|
|
5CAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627824197.0000000005CAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5CAE000
|
Size: |
8192
|
|
667000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626998866.0000000000667000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
667000
|
Size: |
8192
|
|
2D90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354380243.0000000002D90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D90000
|
Size: |
368640
|
|
20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.421183911.0000000000020000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
20000
|
Size: |
61440
|
|
20000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.412914739.0000000000020000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
20000
|
Size: |
61440
|
|
E50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359564154.0000000000E50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E50000
|
Size: |
4096
|
|
200000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.402952731.0000000000200000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
200000
|
Size: |
4096
|
|
114C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627315561.000000000114C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
114C000
|
Size: |
8192
|
|
624000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626975590.0000000000624000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
624000
|
Size: |
4096
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.462046128.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
201000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000002.626875219.0000000000201000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
201000
|
Size: |
57344
|
|
6539000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627879547.0000000006539000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6539000
|
Size: |
8192
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.461978465.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
2D84000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354380243.0000000002D84000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D84000
|
Size: |
4096
|
|
1056000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000000.434009265.0000000001056000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1056000
|
Size: |
8192
|
|
230000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.403002116.0000000000230000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
230000
|
Size: |
913408
|
|
10F2000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627315561.00000000010F2000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
10F2000
|
Size: |
8192
|
|
20000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.626857101.0000000000020000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
20000
|
Size: |
4096
|
|
840000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354248752.0000000000840000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
840000
|
Size: |
339968
|
|
837000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419535822.0000000000837000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
837000
|
Size: |
4096
|
|
CC0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.627106356.0000000000CC0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
CC0000
|
Size: |
4096
|
|
20F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.627064019.00000000020F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20F0000
|
Size: |
4096
|
|
9B1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419535822.00000000009B1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
9B1000
|
Size: |
4096
|
|
6CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627053181.00000000006CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6CE000
|
Size: |
4096
|
|
6550000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.467962206.0000000006550000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6550000
|
Size: |
4096
|
|
6B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.401261747.00000000006B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6B0000
|
Size: |
368640
|
|
3BF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627691581.0000000003BF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3BF0000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2C80000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.359072755.0000000002C80000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2C80000
|
Size: |
4096
|
|
30E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.400959563.000000000030E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30E000
|
Size: |
8192
|
|
2D84000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355376956.0000000002D84000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D84000
|
Size: |
4096
|
|
2E62000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627266394.0000000002E62000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2E62000
|
Size: |
8192
|
|
5C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.403024733.00000000005C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C0000
|
Size: |
4096
|
|
67C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.464367984.00000000067C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
67C0000
|
Size: |
4096
|
|
2B3D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.356094084.0000000002B3D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2B3D000
|
Size: |
311296
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
820000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419535822.0000000000820000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
820000
|
Size: |
4096
|
|
1314000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.359600734.0000000001314000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1314000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
307C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000000.434029214.000000000307C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
307C000
|
Size: |
24576
|
|
2D81000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.359072755.0000000002D81000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D81000
|
Size: |
4096
|
|
2DF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355376956.0000000002DF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2DF0000
|
Size: |
20480
|
|
30A6000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419614314.00000000030A6000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
30A6000
|
Size: |
3526656
|
|
1D3C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627315561.0000000001D3C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
1D3C000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.421513142.0000000000020000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
20000
|
Size: |
61440
|
|
600000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.403035933.0000000000600000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
600000
|
Size: |
8192
|
|
6E7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359424808.00000000006E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6E7000
|
Size: |
4096
|
|
690000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.401261747.0000000000690000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
690000
|
Size: |
4096
|
|
700000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.403040619.0000000000700000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
700000
|
Size: |
20480
|
|
6539000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.468336788.0000000006539000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6539000
|
Size: |
8192
|
|
2DA2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627266394.0000000002DA2000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2DA2000
|
Size: |
4096
|
|
15B0000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419614314.00000000015B0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
15B0000
|
Size: |
10485760
|
|
2EF000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.481410737.00000000002EF000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
2EF000
|
Size: |
139264
|
|
10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.626843901.0000000000010000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10000
|
Size: |
4096
|
|
6420000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627874289.0000000006420000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6420000
|
Size: |
4096
|
|
2D84000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354583889.0000000002D84000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D84000
|
Size: |
4096
|
|
DE0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627177979.0000000000DE0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
DE0000
|
Size: |
4096
|
|
6524000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.467962206.0000000006524000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6524000
|
Size: |
4096
|
|
1327000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.359612115.0000000001327000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1327000
|
Size: |
385024
|
|
700000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482022957.0000000000700000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
700000
|
Size: |
4096
|
|
20000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.626855796.0000000000020000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
20000
|
Size: |
4096
|
|
5D4000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.626989631.00000000005D4000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5D4000
|
Size: |
12288
|
|
17D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.480596367.000000000017D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
17D000
|
Size: |
12288
|
|
A60000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.627106356.0000000000A60000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
A60000
|
Size: |
876544
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
8F7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.403046296.00000000008F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F7000
|
Size: |
4096
|
|
A50000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.627106356.0000000000A50000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
A50000
|
Size: |
4096
|
|
4B2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.626956144.00000000004B2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B2000
|
Size: |
12288
|
|
219000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.402970657.0000000000219000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
219000
|
Size: |
61440
|
|
D40000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.627106356.0000000000D40000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
D40000
|
Size: |
20480
|
|
9A0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419535822.00000000009A0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
9A0000
|
Size: |
4096
|
|
20000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.401870868.0000000000020000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
20000
|
Size: |
61440
|
|
6541000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.468336788.0000000006541000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6541000
|
Size: |
16384
|
|
3464000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627266394.0000000003464000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3464000
|
Size: |
4096
|
|
C44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.433978189.0000000000C44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C44000
|
Size: |
4096
|
|
A20000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419535822.0000000000A20000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
A20000
|
Size: |
20480
|
|
652F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.467962206.000000000652F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
652F000
|
Size: |
4096
|
|
5B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.401261747.00000000005B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5B0000
|
Size: |
876544
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
CE0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.627106356.0000000000CE0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
CE0000
|
Size: |
368640
|
|
880000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.403043327.0000000000880000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
880000
|
Size: |
12288
|
|
72B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.352577995.000000000072B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
72B000
|
Size: |
94208
|
|
23E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.626905583.000000000023E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
23E000
|
Size: |
8192
|
|
4DE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.469643927.0000000004DE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DE0000
|
Size: |
4096
|
|
880000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.626991551.0000000000880000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
880000
|
Size: |
12288
|
|
2D90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355275716.0000000002D90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D90000
|
Size: |
368640
|
|
36D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000000.433805422.000000000036D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
36D000
|
Size: |
12288
|
|
2C80000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354380243.0000000002C80000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2C80000
|
Size: |
4096
|
|
BAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627111100.0000000000BAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BAE000
|
Size: |
8192
|
|
324000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.419501407.0000000000324000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
324000
|
Size: |
122880
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
730000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419535822.0000000000730000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
730000
|
Size: |
4096
|
|
587D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627576022.000000000587D000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
587D000
|
Size: |
12288
|
|
61EC7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.627937640.0000000061EC7000.00000002.00000001.01000000.00000008.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
61EC7000
|
Size: |
12288
|
|
2D81000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355275716.0000000002D81000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D81000
|
Size: |
4096
|
|
2B7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626908570.00000000002B7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B7000
|
Size: |
36864
|
|
B80000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.627042938.0000000000B80000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B80000
|
Size: |
348160
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
684000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626998866.0000000000684000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
684000
|
Size: |
24576
|
|
2B3D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355344717.0000000002B3D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2B3D000
|
Size: |
409600
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.461986129.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
BE0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.627106356.0000000000BE0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
BE0000
|
Size: |
876544
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
6534000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.467962206.0000000006534000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6534000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4DE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.469665484.0000000004DE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4DE0000
|
Size: |
4096
|
|
485000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.481864203.0000000000485000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
485000
|
Size: |
69632
|
|
7CD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.352521311.00000000007CD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CD000
|
Size: |
4096
|
|
6539000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.467962206.0000000006539000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6539000
|
Size: |
8192
|
|
BEC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627120175.0000000000BEC000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
BEC000
|
Size: |
16384
|
|
778000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.353052964.0000000000778000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
778000
|
Size: |
131072
|
|
6130000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.461326358.0000000006130000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
557056
|
|
380000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.481858525.0000000000380000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
380000
|
Size: |
16384
|
|
830000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419535822.0000000000830000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
830000
|
Size: |
12288
|
|
8A0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419535822.00000000008A0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
8A0000
|
Size: |
20480
|
|
A30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.419809000.0000000000A30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A30000
|
Size: |
20480
|
|
591C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627802074.000000000591C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
591C000
|
Size: |
16384
|
|
2D70000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.359072755.0000000002D70000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D70000
|
Size: |
4096
|
|
5DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359397613.00000000005DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5DE000
|
Size: |
8192
|
|
190000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359389986.0000000000190000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
190000
|
Size: |
20480
|
|
1041000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000005.00000002.627208317.0000000001041000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1041000
|
Size: |
57344
|
|
5B8000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.626989631.00000000005B8000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5B8000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
48D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000000.403021644.000000000048D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
48D000
|
Size: |
12288
|
|
20000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.402705987.0000000000020000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
20000
|
Size: |
61440
|
|
2D70000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354583889.0000000002D70000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D70000
|
Size: |
4096
|
|
940000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.626998389.0000000000940000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
940000
|
Size: |
126976
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
5B0F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627621148.0000000005B0F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5B0F000
|
Size: |
4096
|
|
9B4000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419535822.00000000009B4000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
9B4000
|
Size: |
4096
|
|
FB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359573121.0000000000FB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FB4000
|
Size: |
4096
|
|
777000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.353042098.0000000000777000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
777000
|
Size: |
135168
|
|
1261000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.352407673.0000000001261000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
1261000
|
Size: |
581632
|
|
4E13000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482307418.0000000004E13000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E13000
|
Size: |
4096
|
|
20F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.403067552.00000000020F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20F4000
|
Size: |
4096
|
|
1360000
|
system
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482046973.0000000001360000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
1360000
|
Size: |
8192
|
|
2C90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354380243.0000000002C90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2C90000
|
Size: |
876544
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2D81000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355688173.0000000002D81000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D81000
|
Size: |
4096
|
|
4E19000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482307418.0000000004E19000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4E19000
|
Size: |
4096
|
|
62A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.464377845.00000000062A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
62A0000
|
Size: |
4096
|
|
12D2000
|
system
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482046973.00000000012D2000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
12D2000
|
Size: |
4096
|
|
3460000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.627085177.0000000003460000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3460000
|
Size: |
10485760
|
|
6528000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.464597189.0000000006528000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6528000
|
Size: |
40960
|
|
5D10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627830280.0000000005D10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5D10000
|
Size: |
4096
|
|
10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.480488052.0000000000010000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10000
|
Size: |
4096
|
|
52A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.400899262.000000000052A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52A000
|
Size: |
4096
|
|
190000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.626880621.0000000000190000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
190000
|
Size: |
4096
|
|
2C90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355376956.0000000002C90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2C90000
|
Size: |
876544
|
|
370000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.626921297.0000000000370000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
370000
|
Size: |
913408
|
|
2C90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354583889.0000000002C90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2C90000
|
Size: |
876544
|
|
13EC000
|
system
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482046973.00000000013EC000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
13EC000
|
Size: |
8192
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.461960686.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
5400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627713084.0000000005400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5400000
|
Size: |
4096
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.462020286.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
2D87000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354583889.0000000002D87000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D87000
|
Size: |
4096
|
|
804000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482027022.0000000000804000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
804000
|
Size: |
4096
|
|
914000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.626998389.0000000000914000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
914000
|
Size: |
159744
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
20000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000003.402458558.0000000000020000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
20000
|
Size: |
61440
|
|
2D87000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355376956.0000000002D87000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D87000
|
Size: |
4096
|
|
C80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359561132.0000000000C80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C80000
|
Size: |
4096
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.461718730.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
B54000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.627106356.0000000000B54000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
B54000
|
Size: |
8192
|
|
680000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.626975140.0000000000680000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
680000
|
Size: |
20480
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.462004183.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
7D0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.433949036.00000000007D0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7D0000
|
Size: |
20480
|
|
9C1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.419809000.00000000009C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C1000
|
Size: |
4096
|
|
FB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359573121.0000000000FB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FB0000
|
Size: |
4096
|
|
D30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627162283.0000000000D30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D30000
|
Size: |
8192
|
|
6A7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.401261747.00000000006A7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A7000
|
Size: |
4096
|
|
5C2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627819304.0000000005C2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5C2E000
|
Size: |
8192
|
|
2D90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355688173.0000000002D90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D90000
|
Size: |
368640
|
|
2D70000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354380243.0000000002D70000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D70000
|
Size: |
4096
|
|
1032000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627315561.0000000001032000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
1032000
|
Size: |
4096
|
|
3AAC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627266394.0000000003AAC000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3AAC000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
20C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.481394419.000000000020C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
20C000
|
Size: |
16384
|
|
545F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627713084.000000000545F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
545F000
|
Size: |
16384
|
|
686000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359419370.0000000000686000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
686000
|
Size: |
12288
|
|
5EA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359397613.00000000005EA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5EA000
|
Size: |
24576
|
|
100F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627191860.000000000100F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
100F000
|
Size: |
4096
|
|
5443000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627713084.0000000005443000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5443000
|
Size: |
36864
|
|
5476000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627713084.0000000005476000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5476000
|
Size: |
24576
|
|
2B3A000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.356094084.0000000002B3A000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2B3A000
|
Size: |
4096
|
|
60D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359397613.000000000060D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60D000
|
Size: |
12288
|
|
C48000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627127515.0000000000C48000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C48000
|
Size: |
8192
|
|
72B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.352542823.000000000072B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
72B000
|
Size: |
1130496
|
|
696000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.419548458.0000000000696000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
696000
|
Size: |
40960
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.461714866.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
600000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.626968353.0000000000600000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
600000
|
Size: |
8192
|
|
4D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626955608.00000000004D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4D3000
|
Size: |
12288
|
|
61E00000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.627896110.0000000061E00000.00000002.00000001.01000000.00000008.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
61E00000
|
Size: |
4096
|
|
36D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.626912734.000000000036D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
36D000
|
Size: |
12288
|
|
2EBC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627266394.0000000002EBC000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2EBC000
|
Size: |
8192
|
|
DA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627170268.0000000000DA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA0000
|
Size: |
20480
|
|
2A60000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.356094084.0000000002A60000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A60000
|
Size: |
884736
|
|
760000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.419508364.0000000000760000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
760000
|
Size: |
884736
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
10C0000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627315561.00000000010C0000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
10C0000
|
Size: |
8192
|
|
5520000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627750442.0000000005520000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5520000
|
Size: |
12288
|
|
5CB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.626941369.00000000005CB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5CB000
|
Size: |
61440
|
|
680000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.403038137.0000000000680000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
680000
|
Size: |
16384
|
|
494000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.433836831.0000000000494000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
494000
|
Size: |
4096
|
|
370000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.433808885.0000000000370000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
370000
|
Size: |
913408
|
|
BC0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.627106356.0000000000BC0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
BC0000
|
Size: |
20480
|
|
1070000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.627242066.0000000001070000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1070000
|
Size: |
348160
|
|
541D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627713084.000000000541D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
541D000
|
Size: |
151552
|
|
2D81000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354380243.0000000002D81000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D81000
|
Size: |
4096
|
|
5A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.401261747.00000000005A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A0000
|
Size: |
4096
|
|
3A0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.626936363.00000000003A0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
3A0000
|
Size: |
90112
|
|
467000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.481864203.0000000000467000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
467000
|
Size: |
8192
|
|
4C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626955608.00000000004C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C0000
|
Size: |
20480
|
|
2C90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355275716.0000000002C90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2C90000
|
Size: |
876544
|
|
10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359348010.0000000000010000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10000
|
Size: |
4096
|
|
30F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.400952425.000000000030F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30F000
|
Size: |
45056
|
|
8F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.626998389.00000000008F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F0000
|
Size: |
16384
|
|
1886000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627315561.0000000001886000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
1886000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1C6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.480861407.00000000001C6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C6000
|
Size: |
4096
|
|
606F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627851273.000000000606F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
606F000
|
Size: |
4096
|
|
704000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359424808.0000000000704000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
704000
|
Size: |
155648
|
|
19B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.419483049.000000000019B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
19B000
|
Size: |
20480
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.461968919.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
58BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627796317.00000000058BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
58BF000
|
Size: |
4096
|
|
131E000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.352427435.000000000131E000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
131E000
|
Size: |
8192
|
|
660000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626998866.0000000000660000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
660000
|
Size: |
16384
|
|
DFD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627177979.0000000000DFD000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
DFD000
|
Size: |
8192
|
|
680000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359419370.0000000000680000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
680000
|
Size: |
12288
|
|
A30000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419535822.0000000000A30000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
A30000
|
Size: |
12288
|
|
1D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.433801379.00000000001D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D0000
|
Size: |
8192
|
|
778000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354269381.0000000000778000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
778000
|
Size: |
4096
|
|
2D90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355376956.0000000002D90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D90000
|
Size: |
368640
|
|
729000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.352512205.0000000000729000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
729000
|
Size: |
544768
|
|
2D87000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354380243.0000000002D87000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D87000
|
Size: |
4096
|
|
834000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419535822.0000000000834000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
834000
|
Size: |
8192
|
|
740000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419535822.0000000000740000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
740000
|
Size: |
876544
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2B3A000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354342574.0000000002B3A000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2B3A000
|
Size: |
4096
|
|
610000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359414050.0000000000610000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
610000
|
Size: |
290816
|
|
490000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.433836831.0000000000490000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
490000
|
Size: |
4096
|
|
8C0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419535822.00000000008C0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
8C0000
|
Size: |
876544
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
6541000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.467962206.0000000006541000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6541000
|
Size: |
20480
|
|
1C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.480861407.00000000001C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C0000
|
Size: |
8192
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.461994452.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
2E30000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627266394.0000000002E30000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2E30000
|
Size: |
8192
|
|
2B3D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355466959.0000000002B3D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2B3D000
|
Size: |
409600
|
|
7AD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359548361.00000000007AD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AD000
|
Size: |
602112
|
|
201000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000003.00000000.402955086.0000000000201000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
201000
|
Size: |
57344
|
|
1059000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.434012762.0000000001059000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1059000
|
Size: |
61440
|
|
2D87000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355688173.0000000002D87000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D87000
|
Size: |
4096
|
|
1A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.419485752.00000000001A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
1A0000
|
Size: |
274432
|
|
9B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.419809000.00000000009B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9B0000
|
Size: |
4096
|
|
1260000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.359588741.0000000001260000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1260000
|
Size: |
4096
|
|
61EC6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627932585.0000000061EC6000.00000004.00000001.01000000.00000008.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
61EC6000
|
Size: |
4096
|
|
309000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.400952425.0000000000309000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
309000
|
Size: |
4096
|
|
9C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.419809000.00000000009C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9C7000
|
Size: |
4096
|
|
C4B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627127515.0000000000C4B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C4B000
|
Size: |
61440
|
|
5E4F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627651509.0000000005E4F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5E4F000
|
Size: |
4096
|
|
230000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.626901738.0000000000230000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
230000
|
Size: |
913408
|
|
272000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.481410737.0000000000272000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
272000
|
Size: |
4096
|
|
210000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.419491474.0000000000210000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
210000
|
Size: |
90112
|
|
1260000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.352404575.0000000001260000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1260000
|
Size: |
4096
|
|
8B6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627088614.00000000008B6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8B6000
|
Size: |
40960
|
|
2B3A000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355344717.0000000002B3A000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2B3A000
|
Size: |
4096
|
|
4B2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.433836831.00000000004B2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4B2000
|
Size: |
12288
|
|
6545000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.468329134.0000000006545000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6545000
|
Size: |
4096
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.462037548.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
628F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627868657.000000000628F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
628F000
|
Size: |
4096
|
|
8B0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419535822.00000000008B0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
8B0000
|
Size: |
4096
|
|
216000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000000.402961983.0000000000216000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
216000
|
Size: |
8192
|
|
1D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.626889662.00000000001D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D0000
|
Size: |
12288
|
|
26A6000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419614314.00000000026A6000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
26A6000
|
Size: |
10485760
|
|
1D6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.626889662.00000000001D6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1D6000
|
Size: |
12288
|
|
840000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419535822.0000000000840000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
840000
|
Size: |
368640
|
|
61EB2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000004.00000002.627925855.0000000061EB2000.00000002.00000001.01000000.00000008.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
61EB2000
|
Size: |
81920
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
6541000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.464597189.0000000006541000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6541000
|
Size: |
16384
|
|
2B3A000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355466959.0000000002B3A000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2B3A000
|
Size: |
4096
|
|
10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.419474353.0000000000010000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10000
|
Size: |
4096
|
|
5C8000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.626989631.00000000005C8000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5C8000
|
Size: |
4096
|
|
16F4000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627315561.00000000016F4000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
16F4000
|
Size: |
4096
|
|
5C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.626941369.00000000005C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C0000
|
Size: |
4096
|
|
580E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627785428.000000000580E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
580E000
|
Size: |
8192
|
|
5FAD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627845589.0000000005FAD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5FAD000
|
Size: |
12288
|
|
44ED000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.627085177.00000000044ED000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
44ED000
|
Size: |
4096
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.462011878.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
950000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.433967038.0000000000950000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
950000
|
Size: |
12288
|
|
2DA2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000000.434029214.0000000002DA2000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2DA2000
|
Size: |
4096
|
|
BD0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.627106356.0000000000BD0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
BD0000
|
Size: |
4096
|
|
2D70000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355688173.0000000002D70000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D70000
|
Size: |
4096
|
|
216000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000003.00000002.626889229.0000000000216000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
216000
|
Size: |
8192
|
|
914000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.403046296.0000000000914000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
914000
|
Size: |
57344
|
|
8F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.403046296.00000000008F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F0000
|
Size: |
16384
|
|
807000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482027022.0000000000807000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
807000
|
Size: |
20480
|
|
2DF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355275716.0000000002DF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2DF0000
|
Size: |
20480
|
|
FD2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359573121.0000000000FD2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FD2000
|
Size: |
16384
|
|
20F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.626883011.000000000020F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
20F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
36A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.419501407.000000000036A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
36A000
|
Size: |
12288
|
|
6A1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.401261747.00000000006A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6A1000
|
Size: |
4096
|
|
5580000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627763392.0000000005580000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5580000
|
Size: |
4096
|
|
460000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.481864203.0000000000460000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
460000
|
Size: |
16384
|
|
5C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.626941369.00000000005C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C8000
|
Size: |
8192
|
|
2B3A000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355091022.0000000002B3A000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2B3A000
|
Size: |
4096
|
|
20F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000000.402959344.000000000020F000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
20F000
|
Size: |
28672
|
|
74F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626998866.000000000074F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
74F000
|
Size: |
69632
|
|
61E01000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000004.00000002.627900884.0000000061E01000.00000020.00000001.01000000.00000008.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
61E01000
|
Size: |
712704
|
|
5C4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.403024733.00000000005C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C4000
|
Size: |
4096
|
|
2DF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354380243.0000000002DF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2DF0000
|
Size: |
20480
|
|
CD7000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.627106356.0000000000CD7000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
CD7000
|
Size: |
4096
|
|
777000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359539393.0000000000777000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
777000
|
Size: |
126976
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
2A60000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354342574.0000000002A60000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A60000
|
Size: |
884736
|
|
16B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.626872646.000000000016B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
16B000
|
Size: |
20480
|
|
2C90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355688173.0000000002C90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2C90000
|
Size: |
876544
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.461589274.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
2C80000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355275716.0000000002C80000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2C80000
|
Size: |
4096
|
|
1314000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.352419601.0000000001314000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1314000
|
Size: |
40960
|
|
963000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.626998389.0000000000963000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
963000
|
Size: |
16384
|
|
1059000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000002.627235882.0000000001059000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1059000
|
Size: |
61440
|
|
5F1F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627840305.0000000005F1F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5F1F000
|
Size: |
4096
|
|
B60000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.627106356.0000000000B60000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
B60000
|
Size: |
368640
|
|
2A60000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.627085177.0000000002A60000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
2A60000
|
Size: |
10485760
|
|
83A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.419508364.000000000083A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
83A000
|
Size: |
4096
|
|
B40000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.627106356.0000000000B40000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
B40000
|
Size: |
4096
|
|
731000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.359533800.0000000000731000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
731000
|
Size: |
4096
|
|
732000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.353042098.0000000000732000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
732000
|
Size: |
278528
|
|
7BC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627081721.00000000007BC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7BC000
|
Size: |
16384
|
|
200000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.626869932.0000000000200000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
200000
|
Size: |
4096
|
|
6541000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627879547.0000000006541000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6541000
|
Size: |
16384
|
|
6550000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.468329134.0000000006550000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6550000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6520000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627879547.0000000006520000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6520000
|
Size: |
20480
|
|
6539000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.464597189.0000000006539000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6539000
|
Size: |
8192
|
|
450000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.400899262.0000000000450000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
450000
|
Size: |
884736
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
700000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000003.00000002.626985176.0000000000700000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
700000
|
Size: |
20480
|
|
10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626854549.0000000000010000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10000
|
Size: |
4096
|
|
96B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.626998389.000000000096B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
96B000
|
Size: |
20480
|
|
6E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359424808.00000000006E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6E0000
|
Size: |
16384
|
|
52D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482010215.000000000052D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
52D000
|
Size: |
8192
|
|
1327000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.352433102.0000000001327000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1327000
|
Size: |
385024
|
|
2A60000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355091022.0000000002A60000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A60000
|
Size: |
884736
|
|
263D000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419614314.000000000263D000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
263D000
|
Size: |
4096
|
|
CCF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627154636.0000000000CCF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CCF000
|
Size: |
4096
|
|
708000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627060262.0000000000708000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
708000
|
Size: |
77824
|
|
6E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626998866.00000000006E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6E0000
|
Size: |
36864
|
|
570000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.419532236.0000000000570000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
570000
|
Size: |
8192
|
|
499000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.481864203.0000000000499000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
499000
|
Size: |
28672
|
|
2B3A000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354451283.0000000002B3A000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2B3A000
|
Size: |
4096
|
|
2A60000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355466959.0000000002A60000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A60000
|
Size: |
884736
|
|
2A60000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354451283.0000000002A60000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2A60000
|
Size: |
884736
|
|
12EF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.352419601.00000000012EF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
12EF000
|
Size: |
147456
|
|
2B3D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355091022.0000000002B3D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2B3D000
|
Size: |
409600
|
|
C40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627127515.0000000000C40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C40000
|
Size: |
4096
|
|
5BD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626969970.00000000005BD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5BD000
|
Size: |
12288
|
|
5C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.403024733.00000000005C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5C8000
|
Size: |
8192
|
|
2DF0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.359072755.0000000002DF0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2DF0000
|
Size: |
20480
|
|
20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.434384503.0000000000020000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
20000
|
Size: |
61440
|
|
15AC000
|
system
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482046973.00000000015AC000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
15AC000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.433786731.0000000000010000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10000
|
Size: |
4096
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.461592499.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
20F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.403067552.00000000020F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20F0000
|
Size: |
4096
|
|
35F6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627266394.00000000035F6000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
35F6000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7AE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.352505941.00000000007AE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7AE000
|
Size: |
131072
|
|
71B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.352525990.000000000071B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
71B000
|
Size: |
45056
|
|
8B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627088614.00000000008B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8B0000
|
Size: |
12288
|
|
2D70000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355376956.0000000002D70000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D70000
|
Size: |
4096
|
|
68C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626998866.000000000068C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
68C000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
620000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626975590.0000000000620000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
620000
|
Size: |
4096
|
|
CC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.419479574.00000000000CC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CC000
|
Size: |
16384
|
|
510000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482010215.0000000000510000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
510000
|
Size: |
4096
|
|
12EF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.359600734.00000000012EF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
12EF000
|
Size: |
147456
|
|
2112000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.403067552.0000000002112000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2112000
|
Size: |
12288
|
|
1BAA000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627315561.0000000001BAA000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
1BAA000
|
Size: |
4096
|
|
307000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.419501407.0000000000307000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
307000
|
Size: |
4096
|
|
2D81000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354583889.0000000002D81000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D81000
|
Size: |
4096
|
|
72A000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.359533800.000000000072A000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
72A000
|
Size: |
16384
|
|
759000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359539393.0000000000759000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
759000
|
Size: |
118784
|
|
59ED000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627807488.00000000059ED000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59ED000
|
Size: |
12288
|
|
5DEE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627834877.0000000005DEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5DEE000
|
Size: |
8192
|
|
61EAF000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627921507.0000000061EAF000.00000004.00000001.01000000.00000008.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
61EAF000
|
Size: |
12288
|
|
5CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359397613.00000000005CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5CE000
|
Size: |
8192
|
|
5469000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627713084.0000000005469000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5469000
|
Size: |
24576
|
|
F0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.626866928.00000000000F0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
F0000
|
Size: |
12288
|
|
490000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.626956144.0000000000490000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
490000
|
Size: |
4096
|
|
61ECD000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000004.00000002.627948410.0000000061ECD000.00000008.00000001.01000000.00000008.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
61ECD000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2112000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.627064019.0000000002112000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2112000
|
Size: |
12288
|
|
5AD000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.626989631.00000000005AD000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5AD000
|
Size: |
8192
|
|
710000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000003.401261747.0000000000710000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
710000
|
Size: |
20480
|
|
20F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.627064019.00000000020F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20F4000
|
Size: |
4096
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.461721984.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
BB0000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419614314.0000000000BB0000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
BB0000
|
Size: |
10485760
|
|
6130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000003.462029812.0000000006130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6130000
|
Size: |
4096
|
|
372000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.419501407.0000000000372000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
372000
|
Size: |
12288
|
|
3788000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627266394.0000000003788000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3788000
|
Size: |
8192
|
|
1994000
|
system
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482046973.0000000001994000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
1994000
|
Size: |
4096
|
|
10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.626850307.0000000000010000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10000
|
Size: |
4096
|
|
9C0000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.419535822.00000000009C0000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
9C0000
|
Size: |
368640
|
|
72A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.352525990.000000000072A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
72A000
|
Size: |
540672
|
|
4E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.433847392.00000000004E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4E0000
|
Size: |
16384
|
|
980000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482039880.0000000000980000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
980000
|
Size: |
20480
|
|
62B000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000005.00000002.626989631.000000000062B000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
62B000
|
Size: |
86016
|
|
48D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.626934954.000000000048D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
48D000
|
Size: |
12288
|
|
C4B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.433978189.0000000000C4B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C4B000
|
Size: |
61440
|
|
104F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.434005130.000000000104F000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
104F000
|
Size: |
28672
|
|
5CB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000000.403024733.00000000005CB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5CB000
|
Size: |
61440
|
|
2C90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.359072755.0000000002C90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2C90000
|
Size: |
876544
|
|
9A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.359381645.000000000009A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9A000
|
Size: |
24576
|
|
800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.482027022.0000000000800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
800000
|
Size: |
4096
|
|
2C80000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.355688173.0000000002C80000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2C80000
|
Size: |
4096
|
|
2C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.626920718.00000000002C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C0000
|
Size: |
90112
|
|
8F7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.626998389.00000000008F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8F7000
|
Size: |
4096
|
|
C40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.433978189.0000000000C40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C40000
|
Size: |
4096
|
|
6D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627060262.00000000006D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6D0000
|
Size: |
16384
|
|
C44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000002.627127515.0000000000C44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C44000
|
Size: |
4096
|
|
B50000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.627106356.0000000000B50000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
B50000
|
Size: |
12288
|
|
1040000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000005.00000000.433997501.0000000001040000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1040000
|
Size: |
4096
|
|
68C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000003.419552551.000000000068C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
68C000
|
Size: |
40960
|
|
6F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000005.00000000.433850970.00000000006F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
5
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6F4000
|
Size: |
57344
|
|
5570000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.627755995.0000000005570000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5570000
|
Size: |
4096
|
|
2C80000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354583889.0000000002C80000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2C80000
|
Size: |
4096
|
|
2D90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.354583889.0000000002D90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2D90000
|
Size: |
368640
|
|
340000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.481600621.0000000000340000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
340000
|
Size: |
4096
|
|