3021000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000004.00000002.3340632815.0000000003021000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3021000
|
Size: |
315392
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
URLs found in memory or binary data |
Networking |
|
|
46D9000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000000.00000002.885422652.00000000046D9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
46D9000
|
Size: |
831488
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Telegram RAT |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected VIP Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
402000
|
remote allocation
|
page execute and read and write
|
 |
|
|
Name: |
00000004.00000002.3338165117.0000000000402000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
402000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected Telegram RAT |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected VIP Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
592E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886935107.000000000592E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
592E000
|
Size: |
8192
|
|
6D50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345965732.0000000006D50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6D50000
|
Size: |
8192
|
|
7950000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887691823.0000000007950000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
7950000
|
Size: |
557056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
5400000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886202288.0000000005400000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5400000
|
Size: |
65536
|
|
2ED0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340554449.0000000002ED0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ED0000
|
Size: |
4096
|
|
5760000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344595645.0000000005760000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5760000
|
Size: |
49152
|
|
30D3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000030D3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30D3000
|
Size: |
4096
|
|
2ECE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884336327.0000000002ECE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2ECE000
|
Size: |
8192
|
|
1223000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883761019.0000000001223000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1223000
|
Size: |
28672
|
|
677E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344983543.000000000677E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
677E000
|
Size: |
8192
|
|
4323000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004323000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4323000
|
Size: |
8192
|
|
79F0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.887892154.00000000079F0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
79F0000
|
Size: |
45056
|
|
59F0000
|
trusted library section
|
page readonly
|
|
|
|
Name: |
00000000.00000002.887147714.00000000059F0000.00000002.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page readonly
|
Base address: |
59F0000
|
Size: |
61440
|
|
5A00000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3344706606.0000000005A00000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5A00000
|
Size: |
65536
|
|
4289000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004289000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4289000
|
Size: |
16384
|
|
7384000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887594240.0000000007384000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7384000
|
Size: |
4096
|
|
54A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886386168.00000000054A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
54A0000
|
Size: |
4096
|
|
43FE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.00000000043FE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
43FE000
|
Size: |
4096
|
|
5AB0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.887272863.0000000005AB0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5AB0000
|
Size: |
65536
|
|
6196000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887328567.0000000006196000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6196000
|
Size: |
8192
|
|
7370000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887594240.0000000007370000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7370000
|
Size: |
77824
|
|
687E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345017333.000000000687E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
687E000
|
Size: |
8192
|
|
32A9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000032A9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32A9000
|
Size: |
122880
|
|
4021000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004021000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4021000
|
Size: |
36864
|
|
61BA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887455487.00000000061BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
61BA000
|
Size: |
188416
|
|
2F1A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884355765.0000000002F1A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F1A000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
7572000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887659688.0000000007572000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7572000
|
Size: |
32768
|
|
10E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883627447.00000000010E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10E0000
|
Size: |
8192
|
|
B92000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.872064435.0000000000B92000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B92000
|
Size: |
753664
|
|
1620000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340321137.0000000001620000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1620000
|
Size: |
20480
|
|
6ABE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345150664.0000000006ABE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6ABE000
|
Size: |
8192
|
|
2E90000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3340500690.0000000002E90000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2E90000
|
Size: |
4096
|
|
548D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344109057.000000000548D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
548D000
|
Size: |
16384
|
|
4049000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004049000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4049000
|
Size: |
172032
|
|
4132000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004132000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4132000
|
Size: |
12288
|
|
4302000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004302000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4302000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
336F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.000000000336F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
336F000
|
Size: |
8192
|
|
155E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340092500.000000000155E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
155E000
|
Size: |
8192
|
|
143A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3339904751.000000000143A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
143A000
|
Size: |
8192
|
|
308A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.000000000308A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
308A000
|
Size: |
4096
|
|
31D9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000031D9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31D9000
|
Size: |
4096
|
|
31DF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000031DF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31DF000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5500000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886598762.0000000005500000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5500000
|
Size: |
4096
|
|
1447000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3340003104.0000000001447000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1447000
|
Size: |
4096
|
|
55E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344568552.00000000055E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
55E0000
|
Size: |
4096
|
|
3348000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.0000000003348000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3348000
|
Size: |
98304
|
|
59D0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887110926.00000000059D0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
59D0000
|
Size: |
69632
|
|
3287000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.0000000003287000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3287000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
B5AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.888638956.000000000B5AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B5AE000
|
Size: |
8192
|
|
422A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.000000000422A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
422A000
|
Size: |
4096
|
|
10F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883641946.00000000010F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10F0000
|
Size: |
16384
|
|
3233000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.0000000003233000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3233000
|
Size: |
241664
|
|
3343000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.0000000003343000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3343000
|
Size: |
8192
|
|
40B8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.00000000040B8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
40B8000
|
Size: |
4096
|
|
59B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887036560.00000000059B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
59B0000
|
Size: |
65536
|
|
B7EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.888717750.000000000B7EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B7EE000
|
Size: |
8192
|
|
12D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883791192.00000000012D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12D4000
|
Size: |
8192
|
|
31A8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000031A8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31A8000
|
Size: |
4096
|
|
1414000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3339714512.0000000001414000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1414000
|
Size: |
8192
|
|
2E80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340442000.0000000002E80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E80000
|
Size: |
65536
|
|
333A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.000000000333A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
333A000
|
Size: |
4096
|
|
2E74000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340380174.0000000002E74000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E74000
|
Size: |
49152
|
|
5420000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886270846.0000000005420000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5420000
|
Size: |
16384
|
|
1214000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883716536.0000000001214000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1214000
|
Size: |
4096
|
|
5520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344456300.0000000005520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5520000
|
Size: |
53248
|
|
6D35000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345766854.0000000006D35000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6D35000
|
Size: |
45056
|
|
1400000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3339634470.0000000001400000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1400000
|
Size: |
8192
|
|
31B3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000031B3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31B3000
|
Size: |
77824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3106000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.0000000003106000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3106000
|
Size: |
73728
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
6C40000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3345407099.0000000006C40000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6C40000
|
Size: |
8192
|
|
B92E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.888760891.000000000B92E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B92E000
|
Size: |
8192
|
|
4258000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004258000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4258000
|
Size: |
12288
|
|
7B3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887941735.0000000007B3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7B3E000
|
Size: |
8192
|
|
6BFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345195900.0000000006BFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6BFE000
|
Size: |
8192
|
|
1560000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884199398.0000000001560000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1560000
|
Size: |
4096
|
|
6CD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345560937.0000000006CD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6CD0000
|
Size: |
65536
|
|
6654000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344808409.0000000006654000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6654000
|
Size: |
4096
|
|
53F2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.885988256.00000000053F2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53F2000
|
Size: |
49152
|
|
12D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883791192.00000000012D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12D0000
|
Size: |
12288
|
|
1450000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340058525.0000000001450000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1450000
|
Size: |
16384
|
|
4354000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004354000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4354000
|
Size: |
4096
|
|
32DD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000032DD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32DD000
|
Size: |
188416
|
|
6682000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344857259.0000000006682000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6682000
|
Size: |
249856
|
|
546E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344109057.000000000546E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
546E000
|
Size: |
45056
|
|
400000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3338165117.0000000000400000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
4096
|
|
30CF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000030CF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30CF000
|
Size: |
4096
|
|
122D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.883777383.000000000122D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
122D000
|
Size: |
4096
|
|
42A1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.00000000042A1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
42A1000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
42EB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.00000000042EB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
42EB000
|
Size: |
8192
|
|
409F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.000000000409F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
409F000
|
Size: |
4096
|
|
53CB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.885988256.00000000053CB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53CB000
|
Size: |
69632
|
|
1532000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884078781.0000000001532000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1532000
|
Size: |
4096
|
|
3096000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.0000000003096000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3096000
|
Size: |
4096
|
|
618C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887328567.000000000618C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
618C000
|
Size: |
12288
|
|
5486000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344109057.0000000005486000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5486000
|
Size: |
16384
|
|
142D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3339805085.000000000142D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
142D000
|
Size: |
4096
|
|
429C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.000000000429C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
429C000
|
Size: |
4096
|
|
4451000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004451000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4451000
|
Size: |
8192
|
|
6C20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345312027.0000000006C20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6C20000
|
Size: |
65536
|
|
1136000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3338879017.0000000001136000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1136000
|
Size: |
188416
|
|
121D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.883733209.000000000121D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
121D000
|
Size: |
4096
|
|
593E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886953265.000000000593E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
593E000
|
Size: |
4096
|
|
111E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3338879017.000000000111E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
111E000
|
Size: |
40960
|
|
59C5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887068419.00000000059C5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59C5000
|
Size: |
40960
|
|
5A80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887181616.0000000005A80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A80000
|
Size: |
4096
|
|
553A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344496952.000000000553A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
553A000
|
Size: |
24576
|
|
6D32000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345766854.0000000006D32000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6D32000
|
Size: |
8192
|
|
617C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887328567.000000000617C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
617C000
|
Size: |
8192
|
|
4087000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004087000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4087000
|
Size: |
4096
|
|
142E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884023862.000000000142E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
142E000
|
Size: |
8192
|
|
1040000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883559864.0000000001040000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1040000
|
Size: |
4096
|
|
417A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.000000000417A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
417A000
|
Size: |
20480
|
|
1213000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.883703804.0000000001213000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1213000
|
Size: |
4096
|
|
506C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.885925314.000000000506C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
506C000
|
Size: |
16384
|
|
5930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886953265.0000000005930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5930000
|
Size: |
53248
|
|
3331000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.0000000003331000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3331000
|
Size: |
8192
|
|
1436000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3339878001.0000000001436000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1436000
|
Size: |
8192
|
|
433C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.000000000433C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
433C000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2DD8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340354216.0000000002DD8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DD8000
|
Size: |
4096
|
|
DD7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883540008.0000000000DD7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DD7000
|
Size: |
36864
|
|
3ED9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.885422652.0000000003ED9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3ED9000
|
Size: |
4096
|
|
123E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883791192.000000000123E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
123E000
|
Size: |
102400
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
4426000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004426000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4426000
|
Size: |
4096
|
|
54F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886568759.00000000054F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
54F0000
|
Size: |
65536
|
|
6D80000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3346094255.0000000006D80000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6D80000
|
Size: |
45056
|
|
42F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.00000000042F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
42F0000
|
Size: |
8192
|
|
3092000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.0000000003092000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3092000
|
Size: |
4096
|
|
1108000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3338879017.0000000001108000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1108000
|
Size: |
86016
|
|
1570000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340122683.0000000001570000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1570000
|
Size: |
4096
|
|
6D70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3346060290.0000000006D70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6D70000
|
Size: |
32768
|
|
62A7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887577663.00000000062A7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
62A7000
|
Size: |
4096
|
|
54C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886467384.00000000054C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
54C0000
|
Size: |
4096
|
|
1220000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883746228.0000000001220000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1220000
|
Size: |
8192
|
|
5481000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344109057.0000000005481000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5481000
|
Size: |
16384
|
|
10D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883611395.00000000010D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10D0000
|
Size: |
12288
|
|
1442000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3339955698.0000000001442000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1442000
|
Size: |
4096
|
|
1129000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3338879017.0000000001129000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1129000
|
Size: |
12288
|
|
31E4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000031E4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31E4000
|
Size: |
172032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1610000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884289283.0000000001610000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1610000
|
Size: |
4096
|
|
4331000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004331000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4331000
|
Size: |
8192
|
|
6A7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345128911.0000000006A7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6A7E000
|
Size: |
8192
|
|
1620000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884303059.0000000001620000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1620000
|
Size: |
32768
|
|
1230000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883791192.0000000001230000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1230000
|
Size: |
36864
|
|
6AFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345173294.0000000006AFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6AFE000
|
Size: |
8192
|
|
4380000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004380000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4380000
|
Size: |
20480
|
|
1600000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3340221515.0000000001600000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1600000
|
Size: |
65536
|
|
6CE0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3345606749.0000000006CE0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6CE0000
|
Size: |
65536
|
|
59BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344682525.00000000059BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59BE000
|
Size: |
8192
|
|
653E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344763282.000000000653E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
653E000
|
Size: |
8192
|
|
B6EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.888692157.000000000B6EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B6EE000
|
Size: |
8192
|
|
40A1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.00000000040A1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
40A1000
|
Size: |
4096
|
|
1600000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.884269931.0000000001600000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1600000
|
Size: |
4096
|
|
1540000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884139864.0000000001540000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1540000
|
Size: |
4096
|
|
3372000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.0000000003372000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3372000
|
Size: |
4096
|
|
B90000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.872050626.0000000000B90000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B90000
|
Size: |
4096
|
|
2EA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340520220.0000000002EA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2EA0000
|
Size: |
49152
|
|
10A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3338687226.00000000010A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10A0000
|
Size: |
8192
|
|
5770000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886699893.0000000005770000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5770000
|
Size: |
65536
|
|
54DA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886516179.00000000054DA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
54DA000
|
Size: |
24576
|
|
68BD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345041170.00000000068BD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
68BD000
|
Size: |
12288
|
|
7A3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887921677.0000000007A3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7A3E000
|
Size: |
8192
|
|
6C30000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3345358643.0000000006C30000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6C30000
|
Size: |
65536
|
|
4347000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004347000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4347000
|
Size: |
8192
|
|
53DE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.885988256.00000000053DE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53DE000
|
Size: |
8192
|
|
109E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883591667.000000000109E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
109E000
|
Size: |
8192
|
|
6C60000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3345477239.0000000006C60000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6C60000
|
Size: |
65536
|
|
3297000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.0000000003297000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3297000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
42F6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.00000000042F6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
42F6000
|
Size: |
4096
|
|
5460000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344109057.0000000005460000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5460000
|
Size: |
20480
|
|
6D60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3346025191.0000000006D60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6D60000
|
Size: |
40960
|
|
31D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000031D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31D0000
|
Size: |
12288
|
|
53B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.885952065.00000000053B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53B0000
|
Size: |
65536
|
|
1410000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3339661922.0000000001410000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1410000
|
Size: |
8192
|
|
3227000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.0000000003227000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3227000
|
Size: |
24576
|
|
4089000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004089000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4089000
|
Size: |
4096
|
|
6D30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345766854.0000000006D30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6D30000
|
Size: |
4096
|
|
120E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883658907.000000000120E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
120E000
|
Size: |
8192
|
|
5780000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886740847.0000000005780000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5780000
|
Size: |
8192
|
|
1133000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3338879017.0000000001133000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1133000
|
Size: |
8192
|
|
1050000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883576154.0000000001050000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1050000
|
Size: |
8192
|
|
2ED1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884355765.0000000002ED1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2ED1000
|
Size: |
286720
|
|
53C4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.885988256.00000000053C4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53C4000
|
Size: |
16384
|
|
30CB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000030CB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30CB000
|
Size: |
4096
|
|
337D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.000000000337D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
337D000
|
Size: |
135168
|
|
68FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345066250.00000000068FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
68FF000
|
Size: |
4096
|
|
11C4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3338879017.00000000011C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11C4000
|
Size: |
241664
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4274000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004274000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4274000
|
Size: |
4096
|
|
7240000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3346165703.0000000007240000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7240000
|
Size: |
8192
|
|
6C50000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3345429614.0000000006C50000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6C50000
|
Size: |
65536
|
|
30C7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000030C7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30C7000
|
Size: |
4096
|
|
41AC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.00000000041AC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
41AC000
|
Size: |
4096
|
|
6CF6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345659604.0000000006CF6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6CF6000
|
Size: |
4096
|
|
5534000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344496952.0000000005534000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5534000
|
Size: |
4096
|
|
336A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.000000000336A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
336A000
|
Size: |
12288
|
|
576B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886676326.000000000576B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
576B000
|
Size: |
20480
|
|
1430000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3339831802.0000000001430000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1430000
|
Size: |
4096
|
|
10FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3338824686.00000000010FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10FE000
|
Size: |
8192
|
|
1536000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.884097933.0000000001536000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1536000
|
Size: |
8192
|
|
2ED3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340554449.0000000002ED3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2ED3000
|
Size: |
8192
|
|
32CA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000032CA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32CA000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
411C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.000000000411C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
411C000
|
Size: |
4096
|
|
CDA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883264276.0000000000CDA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CDA000
|
Size: |
24576
|
|
5425000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886270846.0000000005425000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5425000
|
Size: |
45056
|
|
6170000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887328567.0000000006170000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6170000
|
Size: |
40960
|
|
15AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884215215.00000000015AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15AE000
|
Size: |
8192
|
|
511E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344087834.000000000511E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
511E000
|
Size: |
8192
|
|
5536000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344496952.0000000005536000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5536000
|
Size: |
8192
|
|
3338000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.0000000003338000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3338000
|
Size: |
4096
|
|
7D50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887985101.0000000007D50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D50000
|
Size: |
4096
|
|
53E6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.885988256.00000000053E6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53E6000
|
Size: |
16384
|
|
1547000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.884168384.0000000001547000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1547000
|
Size: |
4096
|
|
1440000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3339931921.0000000001440000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1440000
|
Size: |
4096
|
|
430E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.000000000430E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
430E000
|
Size: |
8192
|
|
13CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3339610047.00000000013CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13CE000
|
Size: |
8192
|
|
DE7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3338521669.0000000000DE7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DE7000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
2F10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340592464.0000000002F10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F10000
|
Size: |
4096
|
|
30BF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000030BF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30BF000
|
Size: |
4096
|
|
59AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887017817.00000000059AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
59AE000
|
Size: |
8192
|
|
2F25000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884355765.0000000002F25000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F25000
|
Size: |
4096
|
|
15FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340178925.00000000015FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15FC000
|
Size: |
16384
|
|
152E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884042422.000000000152E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
152E000
|
Size: |
8192
|
|
53ED000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.885988256.00000000053ED000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53ED000
|
Size: |
16384
|
|
54D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886516179.00000000054D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
54D0000
|
Size: |
36864
|
|
144B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3340029407.000000000144B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
144B000
|
Size: |
4096
|
|
6280000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887548067.0000000006280000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6280000
|
Size: |
57344
|
|
33A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000033A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
33A0000
|
Size: |
299008
|
|
6D57000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345965732.0000000006D57000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6D57000
|
Size: |
36864
|
|
59C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887068419.00000000059C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
59C0000
|
Size: |
12288
|
|
328D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.000000000328D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
328D000
|
Size: |
4096
|
|
54C2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886467384.00000000054C2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
54C2000
|
Size: |
57344
|
|
32D7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000032D7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32D7000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
414E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.000000000414E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
414E000
|
Size: |
4096
|
|
4454000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004454000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4454000
|
Size: |
12288
|
|
1258000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883791192.0000000001258000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1258000
|
Size: |
49152
|
|
1273000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883791192.0000000001273000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1273000
|
Size: |
372736
|
|
15BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340147583.00000000015BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15BE000
|
Size: |
8192
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340380174.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
4096
|
|
330D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.000000000330D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
330D000
|
Size: |
98304
|
|
3ED1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.885422652.0000000003ED1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3ED1000
|
Size: |
28672
|
|
5AA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887237631.0000000005AA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5AA0000
|
Size: |
65536
|
|
5503000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886598762.0000000005503000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5503000
|
Size: |
8192
|
|
1445000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3339979305.0000000001445000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1445000
|
Size: |
4096
|
|
30C3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000030C3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30C3000
|
Size: |
4096
|
|
116A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3338879017.000000000116A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
116A000
|
Size: |
364544
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
1210000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883676195.0000000001210000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1210000
|
Size: |
8192
|
|
32A5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000032A5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32A5000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
693E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345085124.000000000693E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
693E000
|
Size: |
8192
|
|
6A3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345106187.0000000006A3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6A3E000
|
Size: |
8192
|
|
31D5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000031D5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31D5000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
41C2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.00000000041C2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
41C2000
|
Size: |
12288
|
|
1432000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3339854820.0000000001432000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1432000
|
Size: |
4096
|
|
6194000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887328567.0000000006194000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6194000
|
Size: |
4096
|
|
307C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.000000000307C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
307C000
|
Size: |
36864
|
|
306F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.000000000306F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
306F000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4ED8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.885892861.0000000004ED8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4ED8000
|
Size: |
4096
|
|
616E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887311900.000000000616E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
616E000
|
Size: |
8192
|
|
40BA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.00000000040BA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
40BA000
|
Size: |
4096
|
|
5950000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887001742.0000000005950000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5950000
|
Size: |
4096
|
|
30D7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000030D7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30D7000
|
Size: |
4096
|
|
153A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.884122343.000000000153A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
153A000
|
Size: |
4096
|
|
5466000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344109057.0000000005466000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5466000
|
Size: |
4096
|
|
5410000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886235112.0000000005410000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5410000
|
Size: |
65536
|
|
54DD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344428194.00000000054DD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
54DD000
|
Size: |
12288
|
|
30DB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000030DB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30DB000
|
Size: |
4096
|
|
6180000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887328567.0000000006180000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6180000
|
Size: |
4096
|
|
10B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3338741680.00000000010B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
10B0000
|
Size: |
16384
|
|
5490000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.886372047.0000000005490000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5490000
|
Size: |
4096
|
|
446000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3338165117.0000000000446000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
446000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
3374000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.0000000003374000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3374000
|
Size: |
4096
|
|
6270000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887532457.0000000006270000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6270000
|
Size: |
4096
|
|
1542000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884153931.0000000001542000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1542000
|
Size: |
4096
|
|
31AE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000031AE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31AE000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
154B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.884184085.000000000154B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
154B000
|
Size: |
4096
|
|
3379000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.0000000003379000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3379000
|
Size: |
12288
|
|
1100000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3338879017.0000000001100000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1100000
|
Size: |
28672
|
|
312A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.000000000312A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
312A000
|
Size: |
438272
|
|
1270000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883791192.0000000001270000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1270000
|
Size: |
4096
|
|
547E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344109057.000000000547E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
547E000
|
Size: |
4096
|
|
6C00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345218355.0000000006C00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6C00000
|
Size: |
65536
|
|
4413000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004413000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4413000
|
Size: |
16384
|
|
15F0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.884249868.00000000015F0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
15F0000
|
Size: |
65536
|
|
5A90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887202998.0000000005A90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5A90000
|
Size: |
65536
|
|
32A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000032A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32A0000
|
Size: |
4096
|
|
CEA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3338469406.0000000000CEA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CEA000
|
Size: |
24576
|
|
4308000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004308000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4308000
|
Size: |
4096
|
|
30DF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000030DF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30DF000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5492000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344109057.0000000005492000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5492000
|
Size: |
49152
|
|
6DB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3346140158.0000000006DB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6DB0000
|
Size: |
4096
|
|
2F27000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884355765.0000000002F27000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F27000
|
Size: |
712704
|
|
6CC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345525204.0000000006CC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6CC0000
|
Size: |
45056
|
|
6C10000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3345263592.0000000006C10000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6C10000
|
Size: |
65536
|
|
547A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344109057.000000000547A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
547A000
|
Size: |
4096
|
|
53C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.885988256.00000000053C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53C0000
|
Size: |
12288
|
|
53E1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.885988256.00000000053E1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53E1000
|
Size: |
16384
|
|
3087000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.0000000003087000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3087000
|
Size: |
8192
|
|
109E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3338645321.000000000109E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
109E000
|
Size: |
8192
|
|
1420000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3339766117.0000000001420000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1420000
|
Size: |
45056
|
|
546B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344109057.000000000546B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
546B000
|
Size: |
8192
|
|
6D24000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345712562.0000000006D24000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6D24000
|
Size: |
36864
|
|
1610000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340265313.0000000001610000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1610000
|
Size: |
65536
|
|
1413000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3339690988.0000000001413000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1413000
|
Size: |
4096
|
|
6640000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344808409.0000000006640000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6640000
|
Size: |
4096
|
|
1530000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884062522.0000000001530000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1530000
|
Size: |
4096
|
|
54B0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.886402231.00000000054B0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
54B0000
|
Size: |
65536
|
|
42FD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.00000000042FD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
42FD000
|
Size: |
4096
|
|
B6AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.888669583.000000000B6AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B6AE000
|
Size: |
8192
|
|
15EB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884233338.00000000015EB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15EB000
|
Size: |
20480
|
|
79E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.887875971.00000000079E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
79E0000
|
Size: |
4096
|
|
301F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340612620.000000000301F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
301F000
|
Size: |
4096
|
|
2FD6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884355765.0000000002FD6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2FD6000
|
Size: |
4173824
|
|
31A4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000031A4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31A4000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
309A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.000000000309A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
309A000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
B82E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.888737799.000000000B82E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B82E000
|
Size: |
8192
|
|
320F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.000000000320F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
320F000
|
Size: |
81920
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
5430000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886312293.0000000005430000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5430000
|
Size: |
65536
|
|
663E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344786647.000000000663E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
663E000
|
Size: |
8192
|
|
4255000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004255000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4255000
|
Size: |
8192
|
|
12F6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883791192.00000000012F6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12F6000
|
Size: |
233472
|
|
32D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.00000000032D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32D0000
|
Size: |
16384
|
|
576D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3344595645.000000000576D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
576D000
|
Size: |
12288
|
|
5460000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.886342401.0000000005460000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5460000
|
Size: |
65536
|
|
141D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3339742779.000000000141D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
141D000
|
Size: |
4096
|
|
4318000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3343087060.0000000004318000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4318000
|
Size: |
12288
|
|
1265000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883791192.0000000001265000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1265000
|
Size: |
32768
|
|
319F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.000000000319F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
319F000
|
Size: |
12288
|
|
162A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.884303059.000000000162A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
162A000
|
Size: |
20480
|
|
1050000
|
heap
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3338573342.0000000001050000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1050000
|
Size: |
4096
|
|
5710000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.886637210.0000000005710000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5710000
|
Size: |
65536
|
|
3282000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3340632815.0000000003282000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3282000
|
Size: |
4096
|
|
5770000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000004.00000002.3344661613.0000000005770000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5770000
|
Size: |
4096
|
|
123A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.883791192.000000000123A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
123A000
|
Size: |
8192
|
|
6D40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000004.00000002.3345896893.0000000006D40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
4
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6D40000
|
Size: |
40960
|
|