2C11000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000003.00000002.1225998463.0000000002C11000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C11000
|
Size: |
425984
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
|
CEB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1333736565.0000000000CEB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CEB000
|
Size: |
16384
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1317757300.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
77824
|
|
B30000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1313912568.0000000000B30000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B30000
|
Size: |
4096
|
|
F40C2FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1314822382.000000F40C2FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F40C2FE000
|
Size: |
8192
|
|
CF6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1200460626.0000000000CF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF6000
|
Size: |
122880
|
|
2DE2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DE2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DE2000
|
Size: |
4096
|
|
24FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197763222.00000000024FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
24FE000
|
Size: |
8192
|
|
FF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225173601.0000000000FF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FF0000
|
Size: |
4096
|
|
D1C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1200448029.0000000000D1C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1C000
|
Size: |
8192
|
|
F8A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224640117.0000000000F8A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F8A000
|
Size: |
4096
|
|
39CD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1209915745.00000000039CD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39CD000
|
Size: |
458752
|
|
CC1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1200300892.0000000000CC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC1000
|
Size: |
176128
|
|
2584C9BE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1315104537.000002584C9BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2584C9BE000
|
Size: |
4096
|
|
BE4000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1314017582.0000000000BE4000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BE4000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
4D0C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1228492079.0000000004D0C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4D0C000
|
Size: |
16384
|
|
2DFD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DFD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DFD000
|
Size: |
4096
|
|
8F5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1230784951.0000000008F5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8F5E000
|
Size: |
8192
|
|
D1C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1201350396.0000000000D1C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1C000
|
Size: |
4096
|
|
FFF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225243900.0000000000FFF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FFF000
|
Size: |
131072
|
|
D4D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1317894300.0000000000D4D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4D000
|
Size: |
65536
|
|
2D59000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D59000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D59000
|
Size: |
4096
|
|
2D85000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D85000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D85000
|
Size: |
36864
|
|
F10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224575145.0000000000F10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F10000
|
Size: |
57344
|
|
1094000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1196947213.0000000001094000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1094000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
110000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1329814573.0000000000110000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
110000
|
Size: |
4096
|
|
CF6000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1333835491.0000000000CF6000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
CF6000
|
Size: |
4096
|
|
9C7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1223728826.00000000009C7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9C7000
|
Size: |
36864
|
|
FE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225133584.0000000000FE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FE0000
|
Size: |
8192
|
|
109E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1196991008.000000000109E000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
109E000
|
Size: |
36864
|
|
5410000
|
trusted library section
|
page readonly
|
|
|
|
Name: |
00000003.00000002.1229584504.0000000005410000.00000002.08000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page readonly
|
Base address: |
5410000
|
Size: |
65536
|
|
371E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1325508574.000000000371E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
371E000
|
Size: |
24576
|
|
2584C6F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1314921445.000002584C6F0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2584C6F0000
|
Size: |
4096
|
|
2DCD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DCD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DCD000
|
Size: |
4096
|
|
5123000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229185839.0000000005123000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5123000
|
Size: |
12288
|
|
CF7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1315341812.0000000000CF7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF7000
|
Size: |
90112
|
|
5420000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229635845.0000000005420000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5420000
|
Size: |
8192
|
|
F8F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224865246.0000000000F8F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F8F000
|
Size: |
4096
|
|
D25000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1317098952.0000000000D25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D25000
|
Size: |
122880
|
|
7FD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1330968928.00000000007FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7FD000
|
Size: |
12288
|
|
26D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197791423.00000000026D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
26D0000
|
Size: |
8192
|
|
2D76000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D76000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D76000
|
Size: |
12288
|
|
F20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224640117.0000000000F20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F20000
|
Size: |
28672
|
|
199C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1189505172.000000000199C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
199C000
|
Size: |
77824
|
|
5444000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229688060.0000000005444000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5444000
|
Size: |
20480
|
|
371E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1323887887.000000000371E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
371E000
|
Size: |
24576
|
|
371E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1326174546.000000000371E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
371E000
|
Size: |
24576
|
|
3580000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1324454454.0000000003580000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3580000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
E2E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1201236057.0000000000E2E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E2E000
|
Size: |
4096
|
|
D5B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1196973654.0000000000D5B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D5B000
|
Size: |
4096
|
|
364B000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1211337755.000000000364B000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
364B000
|
Size: |
114688
|
|
CF7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1318102641.0000000000CF7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF7000
|
Size: |
65536
|
|
B30000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.1332479467.0000000000B30000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B30000
|
Size: |
4096
|
|
E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1223906799.0000000000E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
E00000
|
Size: |
8192
|
|
D60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1223826127.0000000000D60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D60000
|
Size: |
16384
|
|
D65000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1223826127.0000000000D65000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D65000
|
Size: |
16384
|
|
33E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1325335062.00000000033E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33E0000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2584C7F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1314963915.000002584C7F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2584C7F0000
|
Size: |
4096
|
|
2BD1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225430592.0000000002BD1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BD1000
|
Size: |
16384
|
|
2584E240000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1315146800.000002584E240000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2584E240000
|
Size: |
4096
|
|
39C9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1208955351.00000000039C9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39C9000
|
Size: |
4096
|
|
1094000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1185916150.0000000001094000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1094000
|
Size: |
40960
|
|
2D61000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D61000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D61000
|
Size: |
4096
|
|
19BE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197705211.00000000019BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19BE000
|
Size: |
499712
|
|
F4B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224640117.0000000000F4B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F4B000
|
Size: |
12288
|
|
199C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197388850.000000000199C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
199C000
|
Size: |
16384
|
|
8E5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1230750079.0000000008E5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8E5E000
|
Size: |
8192
|
|
F58000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224640117.0000000000F58000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F58000
|
Size: |
184320
|
|
1580000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1211283133.0000000001580000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1580000
|
Size: |
8192
|
|
E32000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224128599.0000000000E32000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
E32000
|
Size: |
4096
|
|
50E0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1229127595.00000000050E0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
50E0000
|
Size: |
65536
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1318102641.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
12288
|
|
D1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1200960877.0000000000D1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1A000
|
Size: |
77824
|
|
FCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225059987.0000000000FCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FCE000
|
Size: |
4096
|
|
CB3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1197084180.0000000000CB3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB3000
|
Size: |
368640
|
|
1977000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197388850.0000000001977000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1977000
|
Size: |
122880
|
|
3580000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1325508574.0000000003580000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3580000
|
Size: |
1196032
|
|
9CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1210330833.00000000009CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9CE000
|
Size: |
8192
|
|
555D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229784515.000000000555D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
555D000
|
Size: |
12288
|
|
F9C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224895027.0000000000F9C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F9C000
|
Size: |
12288
|
|
D8A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1314751962.0000000000D8A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D8A000
|
Size: |
4096
|
|
1A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1330761629.00000000001A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A0000
|
Size: |
20480
|
|
F28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224640117.0000000000F28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F28000
|
Size: |
139264
|
|
36AD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1323887887.00000000036AD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36AD000
|
Size: |
458752
|
|
B30000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000002.1210446198.0000000000B30000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B30000
|
Size: |
4096
|
|
38A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1208955351.00000000038A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38A0000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
373D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1327555110.000000000373D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
373D000
|
Size: |
458752
|
|
37AE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1328649613.00000000037AE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
37AE000
|
Size: |
24576
|
|
BEE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1210651450.0000000000BEE000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
BEE000
|
Size: |
36864
|
|
195F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1186864386.000000000195F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
195F000
|
Size: |
200704
|
|
82C000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.2428304585.000000000082C000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
82C000
|
Size: |
4096
|
|
FBF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224895027.0000000000FBF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FBF000
|
Size: |
4096
|
|
D4C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1318272546.0000000000D4C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4C000
|
Size: |
4096
|
|
2D80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D80000
|
Size: |
4096
|
|
2D97000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D97000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D97000
|
Size: |
4096
|
|
199C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1189459285.000000000199C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
199C000
|
Size: |
77824
|
|
373D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1326736664.000000000373D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
373D000
|
Size: |
458752
|
|
183D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197143734.000000000183D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
183D000
|
Size: |
12288
|
|
3610000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1328649613.0000000003610000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3610000
|
Size: |
1196032
|
|
3593000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1326507868.0000000003593000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3593000
|
Size: |
507904
|
|
39C9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1209397202.00000000039C9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39C9000
|
Size: |
4096
|
|
3503000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1324761365.0000000003503000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3503000
|
Size: |
507904
|
|
CF6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1200300892.0000000000CF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF6000
|
Size: |
122880
|
|
3580000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1326174546.0000000003580000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3580000
|
Size: |
1196032
|
|
D3B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1197084180.0000000000D3B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3B000
|
Size: |
491520
|
|
3580000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1324950064.0000000003580000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3580000
|
Size: |
1196032
|
|
D0D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1315268373.0000000000D0D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D0D000
|
Size: |
221184
|
|
19E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1329912326.000000000019E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
19E000
|
Size: |
8192
|
|
3580000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1323887887.0000000003580000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3580000
|
Size: |
1196032
|
|
2DD3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DD3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DD3000
|
Size: |
57344
|
|
400000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1223578891.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
4096
|
|
BE4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000000.1196336799.0000000000BE4000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BE4000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
39C9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1209915745.00000000039C9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39C9000
|
Size: |
4096
|
|
D1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1200999019.0000000000D1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1A000
|
Size: |
77824
|
|
792E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1230598874.000000000792E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
792E000
|
Size: |
8192
|
|
8CDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1230660080.0000000008CDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8CDE000
|
Size: |
8192
|
|
2584C820000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1314978929.000002584C820000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2584C820000
|
Size: |
212992
|
|
FC4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224895027.0000000000FC4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FC4000
|
Size: |
8192
|
|
3470000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1326507868.0000000003470000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3470000
|
Size: |
1187840
|
|
199F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1189569178.000000000199F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
199F000
|
Size: |
65536
|
|
D25000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1333872603.0000000000D25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D25000
|
Size: |
122880
|
|
3670000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1208123549.0000000003670000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3670000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
5430000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229666679.0000000005430000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5430000
|
Size: |
4096
|
|
371E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1324950064.000000000371E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
371E000
|
Size: |
24576
|
|
A9000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1329785440.00000000000A9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A9000
|
Size: |
28672
|
|
199C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1188768175.000000000199C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
199C000
|
Size: |
16384
|
|
2D91000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D91000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D91000
|
Size: |
4096
|
|
D1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1200460626.0000000000D1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1A000
|
Size: |
8192
|
|
3700000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1209245346.0000000003700000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3700000
|
Size: |
1187840
|
|
2DCB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DCB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DCB000
|
Size: |
4096
|
|
D1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1211020363.0000000000D1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1A000
|
Size: |
12288
|
|
10A7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1185990091.00000000010A7000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
10A7000
|
Size: |
442368
|
|
17FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197060523.00000000017FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
17FC000
|
Size: |
16384
|
|
1AB2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1190379938.0000000001AB2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1AB2000
|
Size: |
4096
|
|
C30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1223747207.0000000000C30000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C30000
|
Size: |
4096
|
|
CC7000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1210956696.0000000000CC7000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
CC7000
|
Size: |
4096
|
|
393D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1208249429.000000000393D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
393D000
|
Size: |
458752
|
|
2D5D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D5D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D5D000
|
Size: |
4096
|
|
33E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1325882810.00000000033E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33E0000
|
Size: |
1187840
|
|
2CB7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002CB7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CB7000
|
Size: |
12288
|
|
402000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1223578891.0000000000402000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
402000
|
Size: |
176128
|
|
2BDD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225430592.0000000002BDD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BDD000
|
Size: |
16384
|
|
2C7A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002C7A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C7A000
|
Size: |
245760
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
CCE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1197434390.0000000000CCE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CCE000
|
Size: |
131072
|
|
1B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1330807139.00000000001B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B0000
|
Size: |
4096
|
|
1524000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1211246493.0000000001524000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1524000
|
Size: |
8192
|
|
CF6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1200999019.0000000000CF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF6000
|
Size: |
122880
|
|
2D7A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D7A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D7A000
|
Size: |
12288
|
|
1977000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1188881505.0000000001977000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1977000
|
Size: |
122880
|
|
BEE000
|
unkown
|
page write copy
|
|
|
|
Name: |
0000000B.00000000.1314106486.0000000000BEE000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
BEE000
|
Size: |
8192
|
|
3810000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1207841609.0000000003810000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3810000
|
Size: |
1196032
|
|
D4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1223777820.0000000000D4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D4E000
|
Size: |
8192
|
|
D3D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1314811933.0000000000D3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3D000
|
Size: |
679936
|
|
5354000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229425525.0000000005354000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5354000
|
Size: |
20480
|
|
6D10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1230065927.0000000006D10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6D10000
|
Size: |
24576
|
|
50C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1228982035.00000000050C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
50C0000
|
Size: |
4096
|
|
199E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1190533254.000000000199E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
199E000
|
Size: |
4096
|
|
2690000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197778166.0000000002690000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2690000
|
Size: |
4096
|
|
CF6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1211020363.0000000000CF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF6000
|
Size: |
122880
|
|
F40BEFF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1314716561.000000F40BEFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F40BEFF000
|
Size: |
4096
|
|
C88000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1210880812.0000000000C88000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C88000
|
Size: |
176128
|
|
3C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1210251812.00000000003C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3C0000
|
Size: |
20480
|
|
5690000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1230037188.0000000005690000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5690000
|
Size: |
16384
|
|
CDD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1200460626.0000000000CDD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CDD000
|
Size: |
61440
|
|
3939000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1207430961.0000000003939000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3939000
|
Size: |
4096
|
|
14E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1211228565.00000000014E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
14E0000
|
Size: |
4096
|
|
2E03000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002E03000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E03000
|
Size: |
4096
|
|
3823000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1209245346.0000000003823000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3823000
|
Size: |
507904
|
|
4200000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1196010430.0000000004200000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4200000
|
Size: |
729088
|
|
E57000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1224278753.0000000000E57000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E57000
|
Size: |
4096
|
|
194F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1186837166.000000000194F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
194F000
|
Size: |
135168
|
|
2DEC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DEC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DEC000
|
Size: |
4096
|
|
49C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.2428008908.000000000049C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
49C000
|
Size: |
16384
|
|
CE2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1314692476.0000000000CE2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE2000
|
Size: |
561152
|
|
DB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1201236057.0000000000DB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DB4000
|
Size: |
372736
|
|
3503000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1323713633.0000000003503000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3503000
|
Size: |
507904
|
|
1977000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1189505172.0000000001977000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1977000
|
Size: |
122880
|
|
531A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229325977.000000000531A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
531A000
|
Size: |
16384
|
|
2DEA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DEA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DEA000
|
Size: |
4096
|
|
2D3B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D3B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D3B000
|
Size: |
102400
|
|
FAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1196861675.0000000000FAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FAE000
|
Size: |
8192
|
|
2DEE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DEE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DEE000
|
Size: |
4096
|
|
5596000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229956984.0000000005596000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5596000
|
Size: |
81920
|
|
FF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225189903.0000000000FF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FF4000
|
Size: |
12288
|
|
3593000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1327271627.0000000003593000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3593000
|
Size: |
507904
|
|
33E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1324271210.00000000033E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33E0000
|
Size: |
1187840
|
|
2D9B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D9B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D9B000
|
Size: |
24576
|
|
2E01000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002E01000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E01000
|
Size: |
4096
|
|
2DD1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DD1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DD1000
|
Size: |
4096
|
|
3350000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1334057135.0000000003350000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3350000
|
Size: |
434176
|
|
1977000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1189459285.0000000001977000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1977000
|
Size: |
122880
|
|
194A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1190458004.000000000194A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
194A000
|
Size: |
65536
|
|
711E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1230441179.000000000711E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
711E000
|
Size: |
24576
|
|
D3C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1196889977.0000000000D3C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3C000
|
Size: |
131072
|
|
2CED000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002CED000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CED000
|
Size: |
126976
|
|
3470000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1328144070.0000000003470000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3470000
|
Size: |
1187840
|
|
D1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1200417351.0000000000D1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1A000
|
Size: |
16384
|
|
FE1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.1196893718.0000000000FE1000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FE1000
|
Size: |
581632
|
|
199C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1188881505.000000000199C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
199C000
|
Size: |
16384
|
|
42E000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1223578891.000000000042E000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
42E000
|
Size: |
376832
|
|
195A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1189505172.000000000195A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
195A000
|
Size: |
65536
|
|
19DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1186445980.00000000019DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19DE000
|
Size: |
4096
|
|
2CBB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002CBB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CBB000
|
Size: |
155648
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found strings which match to known social media urls |
Networking |
|
|
17CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197060523.00000000017CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
17CE000
|
Size: |
8192
|
|
E36000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1224151165.0000000000E36000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E36000
|
Size: |
8192
|
|
2DE4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DE4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DE4000
|
Size: |
4096
|
|
2D63000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D63000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D63000
|
Size: |
4096
|
|
1900000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197215602.0000000001900000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1900000
|
Size: |
24576
|
|
D25000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1317757300.0000000000D25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D25000
|
Size: |
122880
|
|
3823000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1209698783.0000000003823000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3823000
|
Size: |
507904
|
|
9DB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1210330833.00000000009DB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9DB000
|
Size: |
20480
|
|
D50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1223800198.0000000000D50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D50000
|
Size: |
8192
|
|
3939000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1207841609.0000000003939000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3939000
|
Size: |
4096
|
|
2D7E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D7E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D7E000
|
Size: |
4096
|
|
2DC3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DC3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DC3000
|
Size: |
12288
|
|
CF6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1201294389.0000000000CF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF6000
|
Size: |
122880
|
|
CB0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1333736565.0000000000CB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB0000
|
Size: |
24576
|
|
2584C9B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1315104537.000002584C9B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2584C9B0000
|
Size: |
16384
|
|
E14000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1223975441.0000000000E14000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
E14000
|
Size: |
4096
|
|
39AE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1208249429.00000000039AE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39AE000
|
Size: |
24576
|
|
3610000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1327555110.0000000003610000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3610000
|
Size: |
1196032
|
|
F40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1196795275.0000000000F40000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F40000
|
Size: |
4096
|
|
36AD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1326174546.00000000036AD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36AD000
|
Size: |
458752
|
|
3793000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1207691762.0000000003793000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3793000
|
Size: |
507904
|
|
E3A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1224195382.0000000000E3A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E3A000
|
Size: |
4096
|
|
2D93000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D93000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D93000
|
Size: |
4096
|
|
35E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1211337755.00000000035E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
35E0000
|
Size: |
434176
|
|
36A9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1324950064.00000000036A9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36A9000
|
Size: |
4096
|
|
2D82000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D82000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D82000
|
Size: |
8192
|
|
4170000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1198892732.0000000004170000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
4170000
|
Size: |
552960
|
|
DC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1223888641.0000000000DC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DC0000
|
Size: |
4096
|
|
F92000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224895027.0000000000F92000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F92000
|
Size: |
28672
|
|
BBF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000002.1210557427.0000000000BBF000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BBF000
|
Size: |
147456
|
|
DAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1223869543.0000000000DAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
DAE000
|
Size: |
8192
|
|
2D65000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D65000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D65000
|
Size: |
57344
|
|
147F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1211180120.000000000147F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
147F000
|
Size: |
4096
|
|
2584C855000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1314978929.000002584C855000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2584C855000
|
Size: |
188416
|
|
3000000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1334017771.0000000003000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3000000
|
Size: |
8192
|
|
1942000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1186812232.0000000001942000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1942000
|
Size: |
90112
|
|
2BB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225430592.0000000002BB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BB0000
|
Size: |
12288
|
|
1990000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1186499675.0000000001990000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1990000
|
Size: |
679936
|
|
2E05000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002E05000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E05000
|
Size: |
4096
|
|
2DB6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DB6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DB6000
|
Size: |
4096
|
|
FE0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1185849804.0000000000FE0000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FE0000
|
Size: |
4096
|
|
FAB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224895027.0000000000FAB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FAB000
|
Size: |
8192
|
|
3C15000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1228432060.0000000003C15000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C15000
|
Size: |
16384
|
|
36AD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1325508574.00000000036AD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36AD000
|
Size: |
458752
|
|
BBF000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.1333494921.0000000000BBF000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BBF000
|
Size: |
147456
|
|
FF8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225189903.0000000000FF8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FF8000
|
Size: |
4096
|
|
3670000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1207691762.0000000003670000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3670000
|
Size: |
1187840
|
|
1936000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1186554288.0000000001936000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1936000
|
Size: |
368640
|
|
DE4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1318065458.0000000000DE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DE4000
|
Size: |
372736
|
|
3E20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197805210.0000000003E20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3E20000
|
Size: |
8192
|
|
CF6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1200417351.0000000000CF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF6000
|
Size: |
122880
|
|
42B3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1196010430.00000000042B3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42B3000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
782D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1230569716.000000000782D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
782D000
|
Size: |
12288
|
|
F40BCFF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1314694874.000000F40BCFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F40BCFF000
|
Size: |
4096
|
|
312F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1211301646.000000000312F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
312F000
|
Size: |
4096
|
|
36A9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1324454454.00000000036A9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36A9000
|
Size: |
4096
|
|
E52000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224249144.0000000000E52000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
E52000
|
Size: |
4096
|
|
1949000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1197314081.0000000001949000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1949000
|
Size: |
4096
|
|
EF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224491665.0000000000EF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
EF0000
|
Size: |
65536
|
|
7110000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1230441179.0000000007110000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7110000
|
Size: |
53248
|
|
B10000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1332403163.0000000000B10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B10000
|
Size: |
4096
|
|
106F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1196947213.000000000106F000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
106F000
|
Size: |
147456
|
|
1908000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197215602.0000000001908000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1908000
|
Size: |
188416
|
|
18AF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1333994373.00000000018AF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
18AF000
|
Size: |
4096
|
|
3810000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1208249429.0000000003810000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3810000
|
Size: |
1196032
|
|
FE6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225150616.0000000000FE6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FE6000
|
Size: |
4096
|
|
195E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1188937113.000000000195E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
195E000
|
Size: |
61440
|
|
371E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1324454454.000000000371E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
371E000
|
Size: |
24576
|
|
3939000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1208249429.0000000003939000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3939000
|
Size: |
4096
|
|
CC8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1201294389.0000000000CC8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC8000
|
Size: |
65536
|
|
3739000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1326736664.0000000003739000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3739000
|
Size: |
4096
|
|
38A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1209397202.00000000038A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38A0000
|
Size: |
1196032
|
|
42C1000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1196010430.00000000042C1000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
42C1000
|
Size: |
438272
|
|
6D32000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1230065927.0000000006D32000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6D32000
|
Size: |
1572864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
50D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229043192.00000000050D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
50D0000
|
Size: |
65536
|
|
7DB000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1330968928.00000000007DB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7DB000
|
Size: |
20480
|
|
BEE000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1333641878.0000000000BEE000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
BEE000
|
Size: |
36864
|
|
BF7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000002.1210831659.0000000000BF7000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BF7000
|
Size: |
442368
|
|
13F7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225375768.00000000013F7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13F7000
|
Size: |
32768
|
|
36AD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1324454454.00000000036AD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36AD000
|
Size: |
458752
|
|
3793000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1208123549.0000000003793000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3793000
|
Size: |
507904
|
|
2DC7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DC7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DC7000
|
Size: |
4096
|
|
CF0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1317098952.0000000000CF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF0000
|
Size: |
28672
|
|
E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224334214.0000000000E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
E70000
|
Size: |
4096
|
|
7EF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1330968928.00000000007EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7EF000
|
Size: |
4096
|
|
2E4C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002E4C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E4C000
|
Size: |
4096
|
|
E13000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1223949119.0000000000E13000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E13000
|
Size: |
4096
|
|
2D5F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D5F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D5F000
|
Size: |
4096
|
|
E0F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1200935610.0000000000E0F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E0F000
|
Size: |
131072
|
|
F40BBFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1314670298.000000F40BBFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F40BBFE000
|
Size: |
8192
|
|
B0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1210423418.0000000000B0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B0E000
|
Size: |
8192
|
|
2D95000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D95000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D95000
|
Size: |
4096
|
|
D07000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1317796343.0000000000D07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D07000
|
Size: |
65536
|
|
5560000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1229810945.0000000005560000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5560000
|
Size: |
40960
|
|
2DB2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DB2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DB2000
|
Size: |
4096
|
|
2E47000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002E47000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E47000
|
Size: |
16384
|
|
F1F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224575145.0000000000F1F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F1F000
|
Size: |
4096
|
|
9FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1210330833.00000000009FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9FC000
|
Size: |
16384
|
|
3503000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1324271210.0000000003503000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3503000
|
Size: |
507904
|
|
121F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225325251.000000000121F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
121F000
|
Size: |
4096
|
|
CB8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1333736565.0000000000CB8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB8000
|
Size: |
180224
|
|
14BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1211207811.00000000014BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
14BE000
|
Size: |
8192
|
|
35A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1210226567.000000000035A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
35A000
|
Size: |
24576
|
|
ED0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224436939.0000000000ED0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
ED0000
|
Size: |
8192
|
|
13EC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225351972.00000000013EC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
13EC000
|
Size: |
16384
|
|
D25000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1318102641.0000000000D25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D25000
|
Size: |
122880
|
|
199C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1190458004.000000000199C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
199C000
|
Size: |
12288
|
|
5570000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229840543.0000000005570000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5570000
|
Size: |
12288
|
|
2DB4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DB4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DB4000
|
Size: |
4096
|
|
3593000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1328144070.0000000003593000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3593000
|
Size: |
507904
|
|
1500000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1206931493.0000000001500000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
1500000
|
Size: |
4096
|
|
BBF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000000.1196336799.0000000000BBF000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BBF000
|
Size: |
147456
|
|
D3B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1211085229.0000000000D3B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D3B000
|
Size: |
495616
|
|
18E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197165413.00000000018E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
18E0000
|
Size: |
4096
|
|
37AE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1327555110.00000000037AE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
37AE000
|
Size: |
24576
|
|
2D99000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D99000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D99000
|
Size: |
4096
|
|
199C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1188937113.000000000199C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
199C000
|
Size: |
8192
|
|
5440000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229688060.0000000005440000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5440000
|
Size: |
12288
|
|
1A93000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1189433946.0000000001A93000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A93000
|
Size: |
131072
|
|
3670000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1207301623.0000000003670000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3670000
|
Size: |
1187840
|
|
EBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224383025.0000000000EBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EBE000
|
Size: |
8192
|
|
BE4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000002.1210557427.0000000000BE4000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BE4000
|
Size: |
40960
|
|
CFE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1317098952.0000000000CFE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFE000
|
Size: |
151552
|
|
532A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229325977.000000000532A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
532A000
|
Size: |
4096
|
|
8D1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1230687732.0000000008D1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8D1E000
|
Size: |
8192
|
|
7BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1330968928.00000000007BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7BE000
|
Size: |
8192
|
|
E1D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1224008859.0000000000E1D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E1D000
|
Size: |
4096
|
|
E5B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1224308478.0000000000E5B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E5B000
|
Size: |
4096
|
|
14AD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1333971840.00000000014AD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
14AD000
|
Size: |
12288
|
|
5080000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1228629370.0000000005080000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5080000
|
Size: |
65536
|
|
1520000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1211246493.0000000001520000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1520000
|
Size: |
8192
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1317796343.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
77824
|
|
CB2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1196919861.0000000000CB2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB2000
|
Size: |
565248
|
|
193E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197215602.000000000193E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
193E000
|
Size: |
12288
|
|
2BB4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225430592.0000000002BB4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BB4000
|
Size: |
16384
|
|
D6A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1333918754.0000000000D6A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D6A000
|
Size: |
499712
|
|
F40BAFA000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1314588818.000000F40BAFA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F40BAFA000
|
Size: |
24576
|
|
37AE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1326736664.00000000037AE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
37AE000
|
Size: |
24576
|
|
D6B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1314659300.0000000000D6B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D6B000
|
Size: |
131072
|
|
BF2000
|
unkown
|
page write copy
|
|
|
|
Name: |
0000000B.00000000.1314106486.0000000000BF2000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
BF2000
|
Size: |
8192
|
|
36A9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1323887887.00000000036A9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36A9000
|
Size: |
4096
|
|
13F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225375768.00000000013F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13F0000
|
Size: |
20480
|
|
17DB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197060523.00000000017DB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
17DB000
|
Size: |
20480
|
|
5450000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229758912.0000000005450000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5450000
|
Size: |
8192
|
|
1941000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1197314081.0000000001941000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1941000
|
Size: |
20480
|
|
E30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224098354.0000000000E30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
E30000
|
Size: |
4096
|
|
36AD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1324950064.00000000036AD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36AD000
|
Size: |
458752
|
|
CBA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1210880812.0000000000CBA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CBA000
|
Size: |
24576
|
|
111E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225299226.000000000111E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
111E000
|
Size: |
8192
|
|
D1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1200300892.0000000000D1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1A000
|
Size: |
16384
|
|
3793000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1207301623.0000000003793000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3793000
|
Size: |
507904
|
|
D1D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1201048942.0000000000D1D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1D000
|
Size: |
65536
|
|
5322000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229325977.0000000005322000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5322000
|
Size: |
12288
|
|
B31000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000001.00000000.1196285249.0000000000B31000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
B31000
|
Size: |
581632
|
|
5300000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1229305516.0000000005300000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5300000
|
Size: |
4096
|
|
2CE6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002CE6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CE6000
|
Size: |
24576
|
|
F40C5FB000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1314897513.000000F40C5FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F40C5FB000
|
Size: |
20480
|
|
EC0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1224408780.0000000000EC0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
EC0000
|
Size: |
65536
|
|
EDA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1196635382.0000000000EDA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EDA000
|
Size: |
24576
|
|
5090000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1228705042.0000000005090000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5090000
|
Size: |
65536
|
|
CC0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1210956696.0000000000CC0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
CC0000
|
Size: |
16384
|
|
BF2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000001.00000000.1196384484.0000000000BF2000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
BF2000
|
Size: |
8192
|
|
2BCE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225430592.0000000002BCE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BCE000
|
Size: |
4096
|
|
D25000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1317796343.0000000000D25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D25000
|
Size: |
122880
|
|
2E07000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002E07000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E07000
|
Size: |
229376
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Installs a raw input device (often for capturing keystrokes) |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
1977000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1188937113.0000000001977000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1977000
|
Size: |
122880
|
|
5100000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229159720.0000000005100000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5100000
|
Size: |
65536
|
|
2DFF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DFF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DFF000
|
Size: |
4096
|
|
3503000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1325882810.0000000003503000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3503000
|
Size: |
507904
|
|
3004000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1334017771.0000000003004000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3004000
|
Size: |
8192
|
|
38A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1209915745.00000000038A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38A0000
|
Size: |
1196032
|
|
BF7000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1314174972.0000000000BF7000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BF7000
|
Size: |
442368
|
|
1977000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1188768175.0000000001977000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1977000
|
Size: |
122880
|
|
CC1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1197411115.0000000000CC1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC1000
|
Size: |
86016
|
|
FE1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1185862721.0000000000FE1000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
FE1000
|
Size: |
581632
|
|
F50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1196815379.0000000000F50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F50000
|
Size: |
4096
|
|
1A38000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1190379938.0000000001A38000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A38000
|
Size: |
372736
|
|
199E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1188921083.000000000199E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
199E000
|
Size: |
8192
|
|
2D55000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D55000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D55000
|
Size: |
12288
|
|
E10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1223930926.0000000000E10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
E10000
|
Size: |
4096
|
|
2BD6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225430592.0000000002BD6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BD6000
|
Size: |
16384
|
|
3739000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1328649613.0000000003739000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3739000
|
Size: |
4096
|
|
F40C3FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1314841393.000000F40C3FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F40C3FE000
|
Size: |
8192
|
|
3E24000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197805210.0000000003E24000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3E24000
|
Size: |
8192
|
|
F65000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1196829412.0000000000F65000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F65000
|
Size: |
8192
|
|
F40C4FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1314874600.000000F40C4FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F40C4FE000
|
Size: |
8192
|
|
BEE000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000001.00000000.1196384484.0000000000BEE000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
BEE000
|
Size: |
8192
|
|
2D8F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D8F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D8F000
|
Size: |
4096
|
|
F00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224532169.0000000000F00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F00000
|
Size: |
65536
|
|
39AE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1207841609.00000000039AE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39AE000
|
Size: |
24576
|
|
106F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1185916150.000000000106F000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
106F000
|
Size: |
147456
|
|
36A9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1326174546.00000000036A9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36A9000
|
Size: |
4096
|
|
FE0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1196878740.0000000000FE0000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FE0000
|
Size: |
4096
|
|
CEF000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1333835491.0000000000CEF000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
CEF000
|
Size: |
20480
|
|
15D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1329848884.000000000015D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
15D000
|
Size: |
12288
|
|
B30000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000000.1196269483.0000000000B30000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B30000
|
Size: |
4096
|
|
CD8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1200999019.0000000000CD8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CD8000
|
Size: |
65536
|
|
2DC9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DC9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DC9000
|
Size: |
4096
|
|
BF7000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.1333681174.0000000000BF7000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BF7000
|
Size: |
442368
|
|
3503000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1325335062.0000000003503000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3503000
|
Size: |
507904
|
|
2B0F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225408821.0000000002B0F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B0F000
|
Size: |
4096
|
|
1935000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1186389529.0000000001935000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1935000
|
Size: |
565248
|
|
BE4000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.1333494921.0000000000BE4000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BE4000
|
Size: |
40960
|
|
33E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1323713633.00000000033E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33E0000
|
Size: |
1187840
|
|
3470000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1327271627.0000000003470000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3470000
|
Size: |
1187840
|
|
1942000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1188768175.0000000001942000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1942000
|
Size: |
176128
|
|
9BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1210330833.00000000009BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9BE000
|
Size: |
8192
|
|
10A2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1185962222.00000000010A2000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
10A2000
|
Size: |
8192
|
|
55C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229997275.00000000055C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
55C7000
|
Size: |
53248
|
|
39AE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1207430961.00000000039AE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39AE000
|
Size: |
24576
|
|
3739000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1327555110.0000000003739000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3739000
|
Size: |
4096
|
|
2C00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225927058.0000000002C00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C00000
|
Size: |
4096
|
|
BBF000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1314017582.0000000000BBF000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BBF000
|
Size: |
147456
|
|
E2D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1224064619.0000000000E2D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
E2D000
|
Size: |
4096
|
|
2DA2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DA2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DA2000
|
Size: |
61440
|
|
393D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1207841609.000000000393D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
393D000
|
Size: |
458752
|
|
393D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1207430961.000000000393D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
393D000
|
Size: |
458752
|
|
3E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1210298100.00000000003E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3E0000
|
Size: |
4096
|
|
5310000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229325977.0000000005310000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5310000
|
Size: |
24576
|
|
2DF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DF0000
|
Size: |
49152
|
|
1977000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1190458004.0000000001977000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1977000
|
Size: |
122880
|
|
A60000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1332346835.0000000000A60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A60000
|
Size: |
8192
|
|
D5C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1318272546.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D5C000
|
Size: |
4096
|
|
B31000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000B.00000002.1332575311.0000000000B31000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
B31000
|
Size: |
581632
|
|
5050000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1228542505.0000000005050000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5050000
|
Size: |
65536
|
|
3810000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1207430961.0000000003810000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3810000
|
Size: |
1196032
|
|
D0D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1197023437.0000000000D0D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D0D000
|
Size: |
679936
|
|
2BF5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225728720.0000000002BF5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BF5000
|
Size: |
45056
|
|
8CA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1223694476.00000000008CA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8CA000
|
Size: |
24576
|
|
19BF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1186350606.00000000019BF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19BF000
|
Size: |
131072
|
|
5120000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229185839.0000000005120000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5120000
|
Size: |
4096
|
|
3D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1210272968.00000000003D0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3D0000
|
Size: |
4096
|
|
10A7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1197005031.00000000010A7000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
10A7000
|
Size: |
442368
|
|
2BE2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225430592.0000000002BE2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BE2000
|
Size: |
49152
|
|
E40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224219269.0000000000E40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E40000
|
Size: |
12288
|
|
FFA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225189903.0000000000FFA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FFA000
|
Size: |
8192
|
|
F60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1196829412.0000000000F60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F60000
|
Size: |
16384
|
|
20FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197749574.00000000020FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
20FE000
|
Size: |
8192
|
|
C80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1210880812.0000000000C80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C80000
|
Size: |
24576
|
|
3C11000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1228432060.0000000003C11000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C11000
|
Size: |
12288
|
|
796E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1230619929.000000000796E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
796E000
|
Size: |
8192
|
|
2BF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225728720.0000000002BF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BF0000
|
Size: |
16384
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1317098952.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
8192
|
|
CF6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1200960877.0000000000CF6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF6000
|
Size: |
122880
|
|
D6A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1314895500.0000000000D6A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D6A000
|
Size: |
495616
|
|
E3F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1317696499.0000000000E3F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E3F000
|
Size: |
131072
|
|
D5C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1318102641.0000000000D5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D5C000
|
Size: |
4096
|
|
F40C1FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1314763792.000000F40C1FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F40C1FE000
|
Size: |
8192
|
|
2DB9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DB9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DB9000
|
Size: |
36864
|
|
F40BFFF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1314737491.000000F40BFFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F40BFFF000
|
Size: |
4096
|
|
5575000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229840543.0000000005575000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5575000
|
Size: |
40960
|
|
B31000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000001.00000002.1210471572.0000000000B31000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
B31000
|
Size: |
581632
|
|
3A3E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1209397202.0000000003A3E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A3E000
|
Size: |
24576
|
|
2CE2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002CE2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CE2000
|
Size: |
12288
|
|
E20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1224040046.0000000000E20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
E20000
|
Size: |
45056
|
|
8E1F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1230717568.0000000008E1F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8E1F000
|
Size: |
4096
|
|
17BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1197060523.00000000017BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
17BF000
|
Size: |
4096
|
|
3610000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1326736664.0000000003610000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3610000
|
Size: |
1196032
|
|
2BBB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225430592.0000000002BBB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BBB000
|
Size: |
69632
|
|
2584C7D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1314941852.000002584C7D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2584C7D0000
|
Size: |
8192
|
|
109E000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1185962222.000000000109E000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
109E000
|
Size: |
8192
|
|
CDE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1197463878.0000000000CDE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CDE000
|
Size: |
200704
|
|
7CE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1330968928.00000000007CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7CE000
|
Size: |
8192
|
|
19BE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1186554288.00000000019BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19BE000
|
Size: |
491520
|
|
36A9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1325508574.00000000036A9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36A9000
|
Size: |
4096
|
|
2D74000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D74000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D74000
|
Size: |
4096
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1333872603.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
12288
|
|
2584C886000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1314978929.000002584C886000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2584C886000
|
Size: |
360448
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
3823000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1208796427.0000000003823000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3823000
|
Size: |
507904
|
|
52FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229222448.00000000052FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52FB000
|
Size: |
20480
|
|
2DE6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DE6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DE6000
|
Size: |
12288
|
|
B31000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000B.00000000.1313938971.0000000000B31000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
B31000
|
Size: |
581632
|
|
2D5B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D5B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D5B000
|
Size: |
4096
|
|
33E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1324761365.00000000033E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33E0000
|
Size: |
1187840
|
|
39CD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1209397202.00000000039CD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39CD000
|
Size: |
458752
|
|
EE0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000003.00000002.1224462591.0000000000EE0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
EE0000
|
Size: |
4096
|
|
39CD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1208955351.00000000039CD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39CD000
|
Size: |
458752
|
|
535A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229425525.000000000535A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
535A000
|
Size: |
40960
|
|
CF0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1315176868.0000000000CF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF0000
|
Size: |
90112
|
|
5590000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229924084.0000000005590000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5590000
|
Size: |
20480
|
|
2D0E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002D0E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2D0E000
|
Size: |
180224
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
33BB000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1334057135.00000000033BB000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33BB000
|
Size: |
114688
|
|
3A3E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1208955351.0000000003A3E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A3E000
|
Size: |
24576
|
|
2584C9B5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1315104537.000002584C9B5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2584C9B5000
|
Size: |
32768
|
|
D4A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1315268373.0000000000D4A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4A000
|
Size: |
8192
|
|
3A3E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1209915745.0000000003A3E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A3E000
|
Size: |
24576
|
|
D1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1201294389.0000000000D1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1A000
|
Size: |
12288
|
|
3700000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1208796427.0000000003700000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3700000
|
Size: |
1187840
|
|
2DCF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225998463.0000000002DCF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DCF000
|
Size: |
4096
|
|
BF7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000001.00000000.1196417034.0000000000BF7000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
1
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BF7000
|
Size: |
442368
|
|
FD5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1225073504.0000000000FD5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FD5000
|
Size: |
8192
|
|
3700000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1209698783.0000000003700000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3700000
|
Size: |
1187840
|
|
373D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1328649613.000000000373D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
373D000
|
Size: |
458752
|
|
5580000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1229889994.0000000005580000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5580000
|
Size: |
4096
|
|
CE3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.1314895500.0000000000CE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CE3000
|
Size: |
368640
|
|