9903000
|
direct allocation
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.2587231415.0000000009903000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
9903000
|
Size: |
10485760
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected GuLoader |
Data Obfuscation |
|
|
21CC1000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
0000000D.00000002.3718414338.0000000021CC1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21CC1000
|
Size: |
299008
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
Yara detected Snake Keylogger |
Stealing of Sensitive Information, Remote Access Functionality |
|
URLs found in memory or binary data |
Networking |
|
|
762000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1244564305.0000000000762000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
762000
|
Size: |
8192
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084524589.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
7AC0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2582813206.0000000007AC0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7AC0000
|
Size: |
65536
|
|
7B00000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3705353413.0000000007B00000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
7B00000
|
Size: |
4096
|
|
2E20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072849341.0000000002E20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E20000
|
Size: |
16384
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247112709.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
24B20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3722306944.0000000024B20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B20000
|
Size: |
49152
|
|
7BDB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2584017791.0000000007BDB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7BDB000
|
Size: |
20480
|
|
21D7B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021D7B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21D7B000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
24010000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3721835150.0000000024010000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
24010000
|
Size: |
65536
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243648287.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
65536
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085728040.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244559904.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
21D6B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021D6B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21D6B000
|
Size: |
4096
|
|
8640000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2584498157.0000000008640000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8640000
|
Size: |
49152
|
|
778000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1240992409.0000000000778000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
778000
|
Size: |
114688
|
|
21E4E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021E4E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21E4E000
|
Size: |
81920
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
873E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2584936262.000000000873E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
873E000
|
Size: |
8192
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244280877.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244163775.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085349727.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
570000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299859285.0000000000570000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
570000
|
Size: |
4096
|
|
23DA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3720966775.0000000023DA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23DA0000
|
Size: |
12288
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244498958.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
23DE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721276438.0000000023DE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23DE0000
|
Size: |
65536
|
|
7B70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2583854957.0000000007B70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B70000
|
Size: |
65536
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085329572.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
75B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1245792296.000000000075B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
75B000
|
Size: |
16384
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245814830.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244742158.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
24BB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3341483349.0000000024BB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BB0000
|
Size: |
36864
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3090949003.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
21D18000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021D18000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21D18000
|
Size: |
36864
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085249564.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
23E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3184082311.0000000023E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E40000
|
Size: |
32768
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085615937.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
21E6C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021E6C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21E6C000
|
Size: |
8192
|
|
2E6D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3701494494.0000000002E6D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E6D000
|
Size: |
12288
|
|
7910000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2582236221.0000000007910000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7910000
|
Size: |
8192
|
|
883E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2585022793.000000000883E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
883E000
|
Size: |
8192
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245634682.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
36864
|
|
21E3A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021E3A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21E3A000
|
Size: |
4096
|
|
24BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3342200293.0000000024BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BD0000
|
Size: |
45056
|
|
23E60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3192085906.0000000023E60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E60000
|
Size: |
65536
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243764394.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
40960
|
|
44A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299632881.000000000044A000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
44A000
|
Size: |
4096
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244523160.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3248707366.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
16384
|
|
23ED2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721562854.0000000023ED2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23ED2000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083900531.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
21B60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717776491.0000000021B60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21B60000
|
Size: |
8192
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083741354.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
20480
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3073272019.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
16384
|
|
21B92000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717980003.0000000021B92000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21B92000
|
Size: |
4096
|
|
24BC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3722447604.0000000024BC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BC0000
|
Size: |
32768
|
|
762000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1246387727.0000000000762000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
762000
|
Size: |
8192
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247767115.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3073099171.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
12288
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243147639.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
20480
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084914014.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
5DC9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2575506119.0000000005DC9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5DC9000
|
Size: |
69632
|
|
27BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300507358.00000000027BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
27BF000
|
Size: |
4096
|
|
23F55000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721691229.0000000023F55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23F55000
|
Size: |
8192
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247662734.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
2E30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072890446.0000000002E30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E30000
|
Size: |
57344
|
|
24BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3341831113.0000000024BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BD0000
|
Size: |
65536
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3250041724.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
65536
|
|
50AB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2575328388.00000000050AB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
50AB000
|
Size: |
20480
|
|
6314000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3070483712.0000000006314000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6314000
|
Size: |
4096
|
|
23E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3184168865.0000000023E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E40000
|
Size: |
16384
|
|
8B00000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2586204396.0000000008B00000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
8B00000
|
Size: |
4096
|
|
3130000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2570964603.0000000003130000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3130000
|
Size: |
4096
|
|
21B7D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3717879398.0000000021B7D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
21B7D000
|
Size: |
4096
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246696029.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085638348.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083250112.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
20480
|
|
31E3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2571309101.00000000031E3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
31E3000
|
Size: |
4096
|
|
7B00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2583342981.0000000007B00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B00000
|
Size: |
65536
|
|
21F57000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021F57000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21F57000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084712324.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246553374.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
88F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2585164008.00000000088F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
88F0000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084694115.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083470934.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
24576
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246458729.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
7AD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2582927975.0000000007AD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7AD0000
|
Size: |
61440
|
|
2199E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717307207.000000002199E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2199E000
|
Size: |
8192
|
|
24BC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3341363559.0000000024BC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BC0000
|
Size: |
16384
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244963649.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
65536
|
|
7230000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581023483.0000000007230000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
7230000
|
Size: |
4096
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245675568.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3250215774.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
36864
|
|
24001000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243081851.0000000024001000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24001000
|
Size: |
8192
|
|
7A8D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2582717880.0000000007A8D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7A8D000
|
Size: |
12288
|
|
8D90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2586865281.0000000008D90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8D90000
|
Size: |
65536
|
|
21B70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717801465.0000000021B70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21B70000
|
Size: |
8192
|
|
22E43000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022E43000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22E43000
|
Size: |
4096
|
|
60E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704570505.00000000060E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
60E0000
|
Size: |
16384
|
|
24BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3342471408.0000000024BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BD0000
|
Size: |
53248
|
|
3050000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2569796146.0000000003050000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3050000
|
Size: |
12288
|
|
8750000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2584986034.0000000008750000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8750000
|
Size: |
4096
|
|
327C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2572593855.000000000327C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
327C000
|
Size: |
45056
|
|
74F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1244018133.000000000074F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
74F000
|
Size: |
8192
|
|
2270000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300291538.0000000002270000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2270000
|
Size: |
8192
|
|
21F5E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021F5E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21F5E000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
23E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085507759.0000000023E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E40000
|
Size: |
28672
|
|
3080000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2570019764.0000000003080000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3080000
|
Size: |
4096
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243189222.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
12288
|
|
22F94000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022F94000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22F94000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084469447.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
20480
|
|
23E6A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721412508.0000000023E6A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E6A000
|
Size: |
24576
|
|
216B0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3716818960.00000000216B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
216B0000
|
Size: |
4096
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244222472.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
24BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3342113780.0000000024BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BD0000
|
Size: |
53248
|
|
21B90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717952777.0000000021B90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21B90000
|
Size: |
4096
|
|
7970000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2582413888.0000000007970000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7970000
|
Size: |
65536
|
|
760E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581287260.000000000760E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
760E000
|
Size: |
8192
|
|
22F88000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022F88000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22F88000
|
Size: |
4096
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247866894.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
21D6F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021D6F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21D6F000
|
Size: |
4096
|
|
24BA7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3722385015.0000000024BA7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BA7000
|
Size: |
36864
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247612680.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
24BB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3341618317.0000000024BB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BB0000
|
Size: |
28672
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245155352.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
21F64000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021F64000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21F64000
|
Size: |
188416
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247638319.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
240C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072315457.00000000240C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
240C1000
|
Size: |
131072
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246673587.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245276307.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
40960
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084639049.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3073175187.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
12288
|
|
61C0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704632556.00000000061C0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
61C0000
|
Size: |
4096
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3242995491.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
32768
|
|
62CC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3070503282.00000000062CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
62CC000
|
Size: |
4096
|
|
62D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704894727.00000000062D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
62D0000
|
Size: |
307200
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
4110000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3701573676.0000000004110000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
4110000
|
Size: |
372736
|
|
3250000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2572593855.0000000003250000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3250000
|
Size: |
28672
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083502938.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
4BC0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2574791953.0000000004BC0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
4BC0000
|
Size: |
4096
|
|
2E20000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3701293552.0000000002E20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E20000
|
Size: |
4096
|
|
89B1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2585285187.00000000089B1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
89B1000
|
Size: |
8192
|
|
44E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1239168074.000000000044E000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
44E000
|
Size: |
217088
|
|
4B70000
|
heap
|
page readonly
|
|
|
|
Name: |
00000002.00000002.2574092807.0000000004B70000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
4B70000
|
Size: |
4096
|
|
79CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2582572394.00000000079CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
79CE000
|
Size: |
8192
|
|
230AB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.00000000230AB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
230AB000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084015765.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
65536
|
|
2E71000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084992916.0000000002E71000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E71000
|
Size: |
61440
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085034504.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
23D9E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3720945519.0000000023D9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
23D9E000
|
Size: |
8192
|
|
26BF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300469973.00000000026BF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
26BF000
|
Size: |
4096
|
|
86F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2584869512.00000000086F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
86F0000
|
Size: |
65536
|
|
6230000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704836059.0000000006230000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
6230000
|
Size: |
4096
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246932222.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
65536
|
|
766000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299973852.0000000000766000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
766000
|
Size: |
45056
|
|
21FC7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021FC7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21FC7000
|
Size: |
4096
|
|
7711000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581437229.0000000007711000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7711000
|
Size: |
16384
|
|
8650000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2584597893.0000000008650000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
8650000
|
Size: |
12288
|
|
764E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581311529.000000000764E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
764E000
|
Size: |
8192
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244678661.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243055094.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
16384
|
|
24BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3342585501.0000000024BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BD0000
|
Size: |
65536
|
|
30C0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2570243514.00000000030C0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
30C0000
|
Size: |
4096
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3250156586.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
36864
|
|
3344000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2572593855.0000000003344000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3344000
|
Size: |
45056
|
|
21A00000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3028839669.0000000021A00000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
21A00000
|
Size: |
4096
|
|
22005000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000022005000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22005000
|
Size: |
135168
|
|
434000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299632881.0000000000434000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
434000
|
Size: |
16384
|
|
862E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2584444116.000000000862E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
862E000
|
Size: |
8192
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243347763.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
16384
|
|
789C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581850652.000000000789C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
789C000
|
Size: |
98304
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
24BF0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3722467999.0000000024BF0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
24BF0000
|
Size: |
36864
|
|
21D2D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021D2D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21D2D000
|
Size: |
8192
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085526620.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
65536
|
|
2E10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072708368.0000000002E10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E10000
|
Size: |
16384
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243596171.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
53248
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083687293.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
23FFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721771830.0000000023FFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
23FFE000
|
Size: |
8192
|
|
422000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299632881.0000000000422000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
422000
|
Size: |
4096
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246029542.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
21D0B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021D0B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21D0B000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
243BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721946131.00000000243BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
243BE000
|
Size: |
8192
|
|
24BB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3341444520.0000000024BB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BB0000
|
Size: |
12288
|
|
4CCF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1243503892.0000000004CCF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCF000
|
Size: |
57344
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245416695.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
4096
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245757127.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
30F0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2570467987.00000000030F0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
30F0000
|
Size: |
4096
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247820944.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
31E4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2571398287.00000000031E4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31E4000
|
Size: |
36864
|
|
23DAE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3720966775.0000000023DAE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23DAE000
|
Size: |
12288
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245840278.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
24BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3341920645.0000000024BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BD0000
|
Size: |
65536
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084950977.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
7809000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581477880.0000000007809000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7809000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083223904.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
22FDF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022FDF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22FDF000
|
Size: |
4096
|
|
4CA7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2575161931.0000000004CA7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CA7000
|
Size: |
8192
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083880426.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
8922000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2585285187.0000000008922000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8922000
|
Size: |
299008
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3722105821.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
65536
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246842871.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
40960
|
|
3066000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2569839842.0000000003066000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3066000
|
Size: |
12288
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245108820.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
23E60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3192029144.0000000023E60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E60000
|
Size: |
65536
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084195778.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084932729.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
320A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2571950749.000000000320A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
320A000
|
Size: |
4096
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245521350.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
53248
|
|
75B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1244018133.000000000075B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
75B000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084214347.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
21A90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717436304.0000000021A90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
21A90000
|
Size: |
4096
|
|
7900000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2582157028.0000000007900000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7900000
|
Size: |
57344
|
|
4C4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2574957809.0000000004C4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C4E000
|
Size: |
8192
|
|
7F920000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2651443330.000000007F920000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7F920000
|
Size: |
4096
|
|
23E80000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721562854.0000000023E80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23E80000
|
Size: |
245760
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3250271952.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
36864
|
|
224E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300276103.000000000224E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
224E000
|
Size: |
8192
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072622549.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
16384
|
|
21C7C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718258938.0000000021C7C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
21C7C000
|
Size: |
16384
|
|
8580000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2584385248.0000000008580000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8580000
|
Size: |
8192
|
|
4BA0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2574409678.0000000004BA0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
4BA0000
|
Size: |
65536
|
|
24B00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243804674.0000000024B00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B00000
|
Size: |
36864
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083448802.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
32B7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2572593855.00000000032B7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32B7000
|
Size: |
573440
|
|
60E7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072342739.00000000060E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
60E7000
|
Size: |
8192
|
|
21B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717903450.0000000021B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21B80000
|
Size: |
45056
|
|
2E10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072744263.0000000002E10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E10000
|
Size: |
16384
|
|
7B30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2583631080.0000000007B30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B30000
|
Size: |
65536
|
|
75B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1242853143.000000000075B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
75B000
|
Size: |
16384
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3073117985.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
12288
|
|
22D1F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022D1F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22D1F000
|
Size: |
4096
|
|
21D77000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021D77000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21D77000
|
Size: |
4096
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3242968570.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
16384
|
|
78CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581850652.00000000078CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
78CF000
|
Size: |
12288
|
|
6336000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704894727.0000000006336000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6336000
|
Size: |
4096
|
|
75B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1241362639.000000000075B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
75B000
|
Size: |
16384
|
|
7B90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2583959930.0000000007B90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B90000
|
Size: |
65536
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245934492.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
524F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2575506119.000000000524F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
524F000
|
Size: |
1003520
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245604099.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
32C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300635025.00000000032C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32C0000
|
Size: |
4096
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3248756409.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
8192
|
|
22F9F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022F9F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22F9F000
|
Size: |
4096
|
|
62B8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704894727.00000000062B8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
62B8000
|
Size: |
20480
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246605158.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
23E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3184195491.0000000023E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E40000
|
Size: |
12288
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083817039.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085133804.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
98000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299549057.0000000000098000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
98000
|
Size: |
32768
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084288984.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
21F14000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021F14000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21F14000
|
Size: |
4096
|
|
7AF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2583136950.0000000007AF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7AF0000
|
Size: |
65536
|
|
21FF7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021FF7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21FF7000
|
Size: |
8192
|
|
6090000
|
heap
|
page readonly
|
|
|
|
Name: |
0000000D.00000002.3704514493.0000000006090000.00000002.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page readonly
|
Base address: |
6090000
|
Size: |
4096
|
|
8A9B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2586090213.0000000008A9B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8A9B000
|
Size: |
20480
|
|
3190000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2571079430.0000000003190000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3190000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084306856.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
23E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084365425.0000000023E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E40000
|
Size: |
16384
|
|
24BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3342074503.0000000024BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BD0000
|
Size: |
20480
|
|
6219000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2579500230.0000000006219000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6219000
|
Size: |
184320
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084270810.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3250186693.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
36864
|
|
86D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2584749433.00000000086D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
86D0000
|
Size: |
65536
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244419553.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
4C9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2575005674.0000000004C9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C9E000
|
Size: |
8192
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085682087.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
24576
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3242949832.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
12288
|
|
24BB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3341587568.0000000024BB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BB0000
|
Size: |
28672
|
|
23EEF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721562854.0000000023EEF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23EEF000
|
Size: |
4096
|
|
24AE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245471083.0000000024AE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24AE0000
|
Size: |
12288
|
|
24BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3342046454.0000000024BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BD0000
|
Size: |
24576
|
|
78B6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581850652.00000000078B6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
78B6000
|
Size: |
12288
|
|
86C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2584670192.00000000086C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
86C0000
|
Size: |
12288
|
|
21880000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717112543.0000000021880000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21880000
|
Size: |
4096
|
|
21F1E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021F1E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21F1E000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
21DA3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021DA3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21DA3000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
632C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704894727.000000000632C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
632C000
|
Size: |
12288
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247142878.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
8740000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2584962048.0000000008740000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
8740000
|
Size: |
8192
|
|
2190F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717216271.000000002190F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2190F000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085708646.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
20480
|
|
23DC1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3720966775.0000000023DC1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23DC1000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083926672.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
20480
|
|
6220000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704807227.0000000006220000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
6220000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085404880.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3248953979.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
65536
|
|
22EEC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022EEC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22EEC000
|
Size: |
8192
|
|
5347000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2575506119.0000000005347000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5347000
|
Size: |
7274496
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
512E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2575370509.000000000512E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
512E000
|
Size: |
8192
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244036900.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083425260.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
7B10000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3705384492.0000000007B10000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
7B10000
|
Size: |
4096
|
|
502F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2575283177.000000000502F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
502F000
|
Size: |
4096
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3250298149.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
4096
|
|
89B9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2585285187.00000000089B9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
89B9000
|
Size: |
28672
|
|
77B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1241362639.000000000077B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77B000
|
Size: |
8192
|
|
60E5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704570505.00000000060E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
60E5000
|
Size: |
12288
|
|
23E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083992245.0000000023E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E40000
|
Size: |
36864
|
|
22E5A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022E5A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22E5A000
|
Size: |
8192
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085547167.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
24B00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3248032053.0000000024B00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B00000
|
Size: |
20480
|
|
3200000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2571835664.0000000003200000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3200000
|
Size: |
4096
|
|
24BC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3341677176.0000000024BC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BC0000
|
Size: |
45056
|
|
22CC1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022CC1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22CC1000
|
Size: |
32768
|
|
88FC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2585164008.00000000088FC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
88FC000
|
Size: |
4096
|
|
41E3000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3701573676.00000000041E3000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
41E3000
|
Size: |
10485760
|
|
61F1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2579500230.00000000061F1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
61F1000
|
Size: |
159744
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084233289.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
22F23000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022F23000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22F23000
|
Size: |
4096
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245581903.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244856669.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
23DCD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3720966775.0000000023DCD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23DCD000
|
Size: |
16384
|
|
21F94000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021F94000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21F94000
|
Size: |
98304
|
|
23DA6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3720966775.0000000023DA6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23DA6000
|
Size: |
4096
|
|
2E10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072727194.0000000002E10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E10000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085014725.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
8192
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245863148.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244989904.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
8B20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2586482934.0000000008B20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8B20000
|
Size: |
65536
|
|
75B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1244564305.000000000075B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
75B000
|
Size: |
16384
|
|
21FFC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021FFC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21FFC000
|
Size: |
4096
|
|
74F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1244564305.000000000074F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
74F000
|
Size: |
16384
|
|
21EAA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021EAA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21EAA000
|
Size: |
307200
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084252635.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3242519107.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
12288
|
|
5A38000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2575506119.0000000005A38000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5A38000
|
Size: |
86016
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
23E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084974990.0000000023E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E40000
|
Size: |
16384
|
|
23DD2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3720966775.0000000023DD2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23DD2000
|
Size: |
49152
|
|
88E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2585164008.00000000088E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
88E0000
|
Size: |
4096
|
|
21F2C000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021F2C000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21F2C000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
6080000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704484305.0000000006080000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6080000
|
Size: |
4096
|
|
21B74000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717853353.0000000021B74000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21B74000
|
Size: |
8192
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245205035.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
22DC9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022DC9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22DC9000
|
Size: |
12288
|
|
240C1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3192128167.00000000240C1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
240C1000
|
Size: |
196608
|
|
864D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2584498157.000000000864D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
864D000
|
Size: |
12288
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083404601.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084895506.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085749827.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
62C2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704894727.00000000062C2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
62C2000
|
Size: |
4096
|
|
21D73000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021D73000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21D73000
|
Size: |
4096
|
|
7660000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581332545.0000000007660000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7660000
|
Size: |
4096
|
|
21F51000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021F51000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21F51000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
6CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299942763.00000000006CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6CF000
|
Size: |
4096
|
|
8997000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2585285187.0000000008997000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8997000
|
Size: |
8192
|
|
E5C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2567260367.0000000000E5C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E5C000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085459451.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
20480
|
|
7B80000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3705457563.0000000007B80000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
7B80000
|
Size: |
4096
|
|
21F09000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021F09000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21F09000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084764886.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
65536
|
|
2E10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3073357962.0000000002E10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E10000
|
Size: |
12288
|
|
3220000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2572234666.0000000003220000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3220000
|
Size: |
24576
|
|
88E8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2585164008.00000000088E8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
88E8000
|
Size: |
4096
|
|
766000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1244018133.0000000000766000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
766000
|
Size: |
45056
|
|
23DC6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3720966775.0000000023DC6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23DC6000
|
Size: |
16384
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072689340.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
16384
|
|
24001000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243167454.0000000024001000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24001000
|
Size: |
4096
|
|
23E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084396463.0000000023E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E40000
|
Size: |
36864
|
|
24BE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3341899008.0000000024BE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BE0000
|
Size: |
16384
|
|
AD03000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2587231415.000000000AD03000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
AD03000
|
Size: |
10485760
|
|
3240000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2572399148.0000000003240000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3240000
|
Size: |
4096
|
|
2170E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3716863860.000000002170E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2170E000
|
Size: |
8192
|
|
22DE5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022DE5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22DE5000
|
Size: |
4096
|
|
3070000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2569935703.0000000003070000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3070000
|
Size: |
4096
|
|
7B40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2583688558.0000000007B40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B40000
|
Size: |
65536
|
|
217E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300238215.000000000217E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
217E000
|
Size: |
8192
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243864433.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
65536
|
|
22028000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000022028000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22028000
|
Size: |
303104
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084488969.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
7B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2583910930.0000000007B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B80000
|
Size: |
65536
|
|
24B00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247984297.0000000024B00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B00000
|
Size: |
20480
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072603599.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
12288
|
|
22FD4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022FD4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22FD4000
|
Size: |
4096
|
|
22FBB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022FBB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22FBB000
|
Size: |
4096
|
|
3060000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2569839842.0000000003060000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3060000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083633001.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
20480
|
|
22FB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022FB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22FB0000
|
Size: |
8192
|
|
8695000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2584625746.0000000008695000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8695000
|
Size: |
36864
|
|
93CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2586982318.00000000093CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
93CE000
|
Size: |
8192
|
|
244FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3722081238.00000000244FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
244FE000
|
Size: |
8192
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244363024.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
23DF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072258144.0000000023DF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23DF0000
|
Size: |
65536
|
|
24AE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243575576.0000000024AE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24AE0000
|
Size: |
65536
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1299583659.0000000000400000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
21C2E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718208310.0000000021C2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
21C2E000
|
Size: |
8192
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3073234408.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
12288
|
|
21A00000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3028876740.0000000021A00000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
21A00000
|
Size: |
4096
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246651643.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
24BB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3341414746.0000000024BB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BB0000
|
Size: |
65536
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085310348.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
91F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300132970.000000000091F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
91F000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084822212.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
62BF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704894727.00000000062BF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
62BF000
|
Size: |
8192
|
|
21BA7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3718134373.0000000021BA7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
21BA7000
|
Size: |
4096
|
|
23E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072234417.0000000023E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E00000
|
Size: |
40960
|
|
24AF0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3722226125.0000000024AF0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
24AF0000
|
Size: |
8192
|
|
22DB3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022DB3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22DB3000
|
Size: |
4096
|
|
2F70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2569169157.0000000002F70000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F70000
|
Size: |
4096
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243325638.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
16384
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3722333224.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
65536
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072670194.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
20480
|
|
2178D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3716953683.000000002178D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2178D000
|
Size: |
12288
|
|
23E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3184139550.0000000023E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E40000
|
Size: |
16384
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243736526.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
16384
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072647359.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
12288
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244083758.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245061541.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245083931.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
728000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299973852.0000000000728000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
728000
|
Size: |
176128
|
|
31ED000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2571472788.00000000031ED000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
31ED000
|
Size: |
12288
|
|
23DBE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3720966775.0000000023DBE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23DBE000
|
Size: |
4096
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246168355.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072977618.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
65536
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085191654.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
20480
|
|
2443E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3722000480.000000002443E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2443E000
|
Size: |
8192
|
|
2437E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721918933.000000002437E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2437E000
|
Size: |
8192
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245887067.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
772000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299973852.0000000000772000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
772000
|
Size: |
49152
|
|
22FA5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022FA5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22FA5000
|
Size: |
8192
|
|
23E70000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721541939.0000000023E70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23E70000
|
Size: |
4096
|
|
427000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299632881.0000000000427000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
427000
|
Size: |
8192
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084580413.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246435039.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
3289000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2572593855.0000000003289000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3289000
|
Size: |
184320
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247085692.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
401000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.1299598364.0000000000401000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
401000
|
Size: |
28672
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3073072062.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
16384
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247266494.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
7B10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2583513198.0000000007B10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B10000
|
Size: |
65536
|
|
4B2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2573779400.0000000004B2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4B2E000
|
Size: |
8192
|
|
7B20000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3705408932.0000000007B20000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
7B20000
|
Size: |
4096
|
|
21F4D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021F4D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21F4D000
|
Size: |
4096
|
|
22D21000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022D21000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22D21000
|
Size: |
4096
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247689868.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
21FFA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021FFA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21FFA000
|
Size: |
4096
|
|
2E10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072801529.0000000002E10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E10000
|
Size: |
16384
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247207568.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
5170000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2575386953.0000000005170000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5170000
|
Size: |
12288
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084856339.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
4B88000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2574231768.0000000004B88000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4B88000
|
Size: |
12288
|
|
8A4F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2585769681.0000000008A4F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8A4F000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2110000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300177128.0000000002110000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2110000
|
Size: |
8192
|
|
2433D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721892330.000000002433D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2433D000
|
Size: |
12288
|
|
A303000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2587231415.000000000A303000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
A303000
|
Size: |
10485760
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247739126.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
2135000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300194009.0000000002135000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2135000
|
Size: |
8192
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247844638.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
7980000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2582472504.0000000007980000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
7980000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084108821.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243691651.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
36864
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085386378.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3073193571.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
12288
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243404386.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
16384
|
|
6323000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704894727.0000000006323000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6323000
|
Size: |
32768
|
|
766000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1246387727.0000000000766000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
766000
|
Size: |
45056
|
|
61F0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704719017.00000000061F0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
61F0000
|
Size: |
4096
|
|
8D80000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2586718370.0000000008D80000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
8D80000
|
Size: |
65536
|
|
2E10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072763563.0000000002E10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E10000
|
Size: |
16384
|
|
23CC8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3720923934.0000000023CC8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23CC8000
|
Size: |
4096
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3073213951.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
12288
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247794105.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
940D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2587043605.000000000940D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
940D000
|
Size: |
12288
|
|
22F8D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022F8D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22F8D000
|
Size: |
4096
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247297696.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
772000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1244564305.0000000000772000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
772000
|
Size: |
28672
|
|
7F938000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2651485247.000000007F938000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7F938000
|
Size: |
4096
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3250104071.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
40960
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247058428.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244587847.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
89C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2585746521.00000000089C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
89C7000
|
Size: |
12288
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084506660.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
22F0B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022F0B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22F0B000
|
Size: |
4096
|
|
24BC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3341519226.0000000024BC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BC0000
|
Size: |
28672
|
|
51E9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2575426953.00000000051E9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
51E9000
|
Size: |
16384
|
|
86E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2584806480.00000000086E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
86E0000
|
Size: |
65536
|
|
23E50000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3721390198.0000000023E50000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
23E50000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085211999.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
21BA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718057616.0000000021BA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21BA0000
|
Size: |
4096
|
|
772000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1245792296.0000000000772000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
772000
|
Size: |
28672
|
|
23E3E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721338623.0000000023E3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
23E3E000
|
Size: |
8192
|
|
22EF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022EF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22EF0000
|
Size: |
8192
|
|
22F9A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022F9A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22F9A000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246362202.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246580967.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
8A61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2586047238.0000000008A61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8A61000
|
Size: |
12288
|
|
24B90000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3722362451.0000000024B90000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
24B90000
|
Size: |
65536
|
|
21D63000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021D63000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21D63000
|
Size: |
4096
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3248731447.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
20480
|
|
21B27000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717615106.0000000021B27000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
21B27000
|
Size: |
36864
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245229194.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085658332.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
20480
|
|
50EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2575352222.00000000050EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
50EE000
|
Size: |
8192
|
|
19A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299566628.000000000019A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
19A000
|
Size: |
24576
|
|
4BB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2574633258.0000000004BB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4BB0000
|
Size: |
65536
|
|
51F1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2575506119.00000000051F1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
51F1000
|
Size: |
380928
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
78D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581850652.00000000078D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
78D9000
|
Size: |
155648
|
|
7B60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2583799509.0000000007B60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B60000
|
Size: |
65536
|
|
21FBF000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021FBF000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21FBF000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084324391.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
23DA4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3720966775.0000000023DA4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23DA4000
|
Size: |
4096
|
|
766000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1242853143.0000000000766000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
766000
|
Size: |
45056
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084600716.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
28672
|
|
2E16000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072934570.0000000002E16000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E16000
|
Size: |
40960
|
|
21A7F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717369524.0000000021A7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
21A7F000
|
Size: |
4096
|
|
8AA7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2586117721.0000000008AA7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8AA7000
|
Size: |
24576
|
|
22D36000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022D36000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22D36000
|
Size: |
16384
|
|
22CE9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022CE9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22CE9000
|
Size: |
147456
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245491475.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
65536
|
|
86C4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2584670192.00000000086C4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
86C4000
|
Size: |
40960
|
|
23018000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000023018000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23018000
|
Size: |
16384
|
|
218CE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717145034.00000000218CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
218CE000
|
Size: |
8192
|
|
762000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1242853143.0000000000762000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
762000
|
Size: |
8192
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246137861.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083188248.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085271006.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246385276.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
8DA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2586952259.0000000008DA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8DA0000
|
Size: |
12288
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243666522.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
53248
|
|
31E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2571246110.00000000031E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31E0000
|
Size: |
12288
|
|
5FE3000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3701573676.0000000005FE3000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
5FE3000
|
Size: |
192512
|
|
B703000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2587231415.000000000B703000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
B703000
|
Size: |
192512
|
|
6250000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704894727.0000000006250000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6250000
|
Size: |
36864
|
|
77B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1244145321.000000000077B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77B000
|
Size: |
8192
|
|
21BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300256151.00000000021BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
21BE000
|
Size: |
8192
|
|
24BC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3341729286.0000000024BC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BC0000
|
Size: |
65536
|
|
2E10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3073335263.0000000002E10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E10000
|
Size: |
12288
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3073252776.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
12288
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247453631.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
30D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2570354680.00000000030D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
30D0000
|
Size: |
4096
|
|
24B00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246910757.0000000024B00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B00000
|
Size: |
12288
|
|
490000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299837860.0000000000490000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
490000
|
Size: |
4096
|
|
21F27000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021F27000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21F27000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083556149.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
20480
|
|
21E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21E40000
|
Size: |
4096
|
|
31F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2571651381.00000000031F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31F0000
|
Size: |
32768
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246743368.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246817954.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
75B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1246387727.000000000075B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
75B000
|
Size: |
16384
|
|
762000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1245792296.0000000000762000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
762000
|
Size: |
8192
|
|
22D4F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022D4F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22D4F000
|
Size: |
12288
|
|
21BA2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718082263.0000000021BA2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21BA2000
|
Size: |
4096
|
|
24510000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3722136049.0000000024510000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
24510000
|
Size: |
65536
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247533467.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
24C20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3342256969.0000000024C20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24C20000
|
Size: |
61440
|
|
7240000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581069356.0000000007240000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
7240000
|
Size: |
4096
|
|
7930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2582320093.0000000007930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7930000
|
Size: |
65536
|
|
20E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300155012.00000000020E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
20E0000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083579608.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246092602.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3250074556.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
36864
|
|
24AE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243844861.0000000024AE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24AE0000
|
Size: |
65536
|
|
28C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1242928835.00000000028C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28C8000
|
Size: |
380928
|
|
23E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3184220608.0000000023E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E40000
|
Size: |
16384
|
|
7920000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2582263395.0000000007920000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7920000
|
Size: |
65536
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245731487.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
580000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299873207.0000000000580000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
580000
|
Size: |
16384
|
|
24BB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3341544020.0000000024BB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BB0000
|
Size: |
65536
|
|
51E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2575426953.00000000051E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
51E0000
|
Size: |
28672
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245910603.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
74F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1245792296.000000000074F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
74F000
|
Size: |
16384
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244258111.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3242403252.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
36864
|
|
5CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299927339.00000000005CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5CE000
|
Size: |
8192
|
|
766000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1244564305.0000000000766000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
766000
|
Size: |
45056
|
|
21AEA000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717532209.0000000021AEA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
21AEA000
|
Size: |
24576
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3192003878.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
36864
|
|
8970000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2585285187.0000000008970000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8970000
|
Size: |
155648
|
|
23E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3184115569.0000000023E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E40000
|
Size: |
32768
|
|
24BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3341954369.0000000024BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BD0000
|
Size: |
40960
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244654585.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
21C30000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3718232509.0000000021C30000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
21C30000
|
Size: |
4096
|
|
2E10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072782751.0000000002E10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E10000
|
Size: |
16384
|
|
22EC1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022EC1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22EC1000
|
Size: |
4096
|
|
21CB0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718380604.0000000021CB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21CB0000
|
Size: |
4096
|
|
7A0E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2582602791.0000000007A0E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7A0E000
|
Size: |
8192
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246768100.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244013850.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244769095.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
629E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704894727.000000000629E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
629E000
|
Size: |
98304
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
772000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1244018133.0000000000772000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
772000
|
Size: |
28672
|
|
21F0E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021F0E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21F0E000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085074463.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
4096
|
|
24B90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3248934463.0000000024B90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B90000
|
Size: |
53248
|
|
408000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1239119868.0000000000408000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
408000
|
Size: |
8192
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083316847.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
24BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3342161421.0000000024BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BD0000
|
Size: |
24576
|
|
21B96000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3718007405.0000000021B96000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
21B96000
|
Size: |
8192
|
|
24BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3341705800.0000000024BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BD0000
|
Size: |
28672
|
|
22E12000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022E12000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22E12000
|
Size: |
16384
|
|
30A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2570175399.00000000030A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
30A0000
|
Size: |
4096
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246004824.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
55E3000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3701573676.00000000055E3000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
55E3000
|
Size: |
10485760
|
|
762000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299973852.0000000000762000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
762000
|
Size: |
8192
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243915238.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
49152
|
|
64E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3705295859.00000000064E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
64E0000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084877149.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247560986.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
230EC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.00000000230EC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
230EC000
|
Size: |
8192
|
|
21B40000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717694422.0000000021B40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21B40000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084620985.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3242928302.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
12288
|
|
24510000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243628849.0000000024510000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24510000
|
Size: |
65536
|
|
28C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1244645186.00000000028C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28C0000
|
Size: |
151552
|
|
22F39000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022F39000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22F39000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246991309.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
6240000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704864850.0000000006240000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
6240000
|
Size: |
4096
|
|
24C10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3342564766.0000000024C10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24C10000
|
Size: |
12288
|
|
7440000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581097948.0000000007440000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7440000
|
Size: |
36864
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3073376214.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
65536
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247425754.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245782873.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
762000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1244018133.0000000000762000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
762000
|
Size: |
8192
|
|
70E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299957997.000000000070E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
70E000
|
Size: |
8192
|
|
4CCF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300704712.0000000004CCF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CCF000
|
Size: |
81920
|
|
9410000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2587120035.0000000009410000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
9410000
|
Size: |
4096
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1239076985.0000000000400000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3242871137.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
12288
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243714280.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
12288
|
|
3210000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2572038524.0000000003210000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3210000
|
Size: |
4096
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246718821.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084436906.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
21F30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021F30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21F30000
|
Size: |
114688
|
|
2195D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717246299.000000002195D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2195D000
|
Size: |
12288
|
|
23E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072580578.0000000023E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E00000
|
Size: |
12288
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243302689.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
16384
|
|
5A4E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2575506119.0000000005A4E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5A4E000
|
Size: |
3645440
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084414523.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
65536
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084546252.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
21A00000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3028859592.0000000021A00000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
21A00000
|
Size: |
4096
|
|
8890000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2585112669.0000000008890000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8890000
|
Size: |
65536
|
|
28CC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1244161983.00000000028CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28CC000
|
Size: |
4096
|
|
2400D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721793173.000000002400D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2400D000
|
Size: |
12288
|
|
772000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1242853143.0000000000772000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
772000
|
Size: |
28672
|
|
21D5B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021D5B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21D5B000
|
Size: |
4096
|
|
60A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704543301.00000000060A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
60A0000
|
Size: |
8192
|
|
23DB2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3720966775.0000000023DB2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23DB2000
|
Size: |
28672
|
|
74F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1241362639.000000000074F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
74F000
|
Size: |
12288
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083605431.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
75B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299973852.000000000075B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
75B000
|
Size: |
20480
|
|
23E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084743228.0000000023E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E40000
|
Size: |
20480
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085794754.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
21D5F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021D5F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21D5F000
|
Size: |
4096
|
|
766000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1245792296.0000000000766000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
766000
|
Size: |
45056
|
|
432000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299632881.0000000000432000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
432000
|
Size: |
4096
|
|
2174F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3716895069.000000002174F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2174F000
|
Size: |
4096
|
|
22F33000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022F33000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22F33000
|
Size: |
4096
|
|
62D3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3070503282.00000000062D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
62D3000
|
Size: |
266240
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2184F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717081358.000000002184F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2184F000
|
Size: |
4096
|
|
21B9A000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3718034182.0000000021B9A000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
21B9A000
|
Size: |
8192
|
|
5175000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2575386953.0000000005175000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5175000
|
Size: |
16384
|
|
2E10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3073295711.0000000002E10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E10000
|
Size: |
12288
|
|
6398000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2579500230.0000000006398000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6398000
|
Size: |
8192
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084839256.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
21CA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718344875.0000000021CA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21CA0000
|
Size: |
65536
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243988420.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
401000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1239094477.0000000000401000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
401000
|
Size: |
28672
|
|
21FC9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021FC9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21FC9000
|
Size: |
12288
|
|
24510000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243884795.0000000024510000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24510000
|
Size: |
65536
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247914721.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
21BA5000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3718107994.0000000021BA5000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
21BA5000
|
Size: |
4096
|
|
3258000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2572593855.0000000003258000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3258000
|
Size: |
143360
|
|
6389000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2579500230.0000000006389000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6389000
|
Size: |
8192
|
|
21E7F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021E7F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21E7F000
|
Size: |
172032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
30B0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2570209677.00000000030B0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
30B0000
|
Size: |
4096
|
|
2130000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300194009.0000000002130000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2130000
|
Size: |
12288
|
|
24BA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3248637071.0000000024BA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BA0000
|
Size: |
4096
|
|
408000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1299617258.0000000000408000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
408000
|
Size: |
8192
|
|
8880000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2585047316.0000000008880000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8880000
|
Size: |
65536
|
|
23FBE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721751062.0000000023FBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
23FBE000
|
Size: |
8192
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245981060.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
74F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1246387727.000000000074F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
74F000
|
Size: |
8192
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083654201.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083530121.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244339326.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
21E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21E70000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083857364.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
9830000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2587231415.0000000009830000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
9830000
|
Size: |
372736
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084785817.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244878838.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3250323856.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
12288
|
|
772000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1246387727.0000000000772000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
772000
|
Size: |
28672
|
|
2E10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3073316671.0000000002E10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E10000
|
Size: |
12288
|
|
7819000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581477880.0000000007819000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7819000
|
Size: |
49152
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247585119.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
21D67000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021D67000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21D67000
|
Size: |
4096
|
|
24AF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243556188.0000000024AF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24AF0000
|
Size: |
65536
|
|
217CC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3716985951.00000000217CC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
217CC000
|
Size: |
16384
|
|
24B00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243535972.0000000024B00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B00000
|
Size: |
65536
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245252643.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
585000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299873207.0000000000585000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
585000
|
Size: |
20480
|
|
23DF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721310766.0000000023DF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23DF0000
|
Size: |
49152
|
|
31D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2571209129.00000000031D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31D0000
|
Size: |
12288
|
|
62D8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3033073718.00000000062D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
62D8000
|
Size: |
241664
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247402084.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
7AB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2582753238.0000000007AB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7AB0000
|
Size: |
65536
|
|
7450000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581097948.0000000007450000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7450000
|
Size: |
282624
|
|
62D3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3032999763.00000000062D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
62D3000
|
Size: |
12288
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247891769.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
78C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581850652.00000000078C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
78C0000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245038755.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246481856.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245132287.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
31C0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2571150147.00000000031C0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
31C0000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084804036.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
27C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300558895.00000000027C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
27C0000
|
Size: |
40960
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3248680038.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
65536
|
|
625A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2579500230.000000000625A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
625A000
|
Size: |
1200128
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
8B10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2586316395.0000000008B10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8B10000
|
Size: |
12288
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245014654.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
24B00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247960666.0000000024B00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B00000
|
Size: |
20480
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084088848.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084563435.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
23E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3184323452.0000000023E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E40000
|
Size: |
65536
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244793693.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
37D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300648958.00000000037D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
37D0000
|
Size: |
4096
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246628577.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
389C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300662074.000000000389C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
389C000
|
Size: |
16384
|
|
21C90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718314225.0000000021C90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21C90000
|
Size: |
65536
|
|
21FF2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021FF2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21FF2000
|
Size: |
12288
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085423113.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
62D8000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3032999763.00000000062D8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
62D8000
|
Size: |
241664
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3242463064.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
12288
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246529130.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
6380000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2579500230.0000000006380000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6380000
|
Size: |
8192
|
|
720000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299973852.0000000000720000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
720000
|
Size: |
24576
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3248789670.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
16384
|
|
88EC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2585164008.00000000088EC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
88EC000
|
Size: |
4096
|
|
44C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299632881.000000000044C000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
44C000
|
Size: |
4096
|
|
8A6B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2586070528.0000000008A6B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8A6B000
|
Size: |
12288
|
|
24C00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3342298585.0000000024C00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24C00000
|
Size: |
65536
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084047994.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247376386.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
24AE0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3722198155.0000000024AE0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
24AE0000
|
Size: |
65536
|
|
24BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3342319143.0000000024BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BD0000
|
Size: |
65536
|
|
21A3E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717340575.0000000021A3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
21A3E000
|
Size: |
8192
|
|
24B00000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3722249616.0000000024B00000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
24B00000
|
Size: |
65536
|
|
23EBF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721562854.0000000023EBF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23EBF000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085292465.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
21FC1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021FC1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21FC1000
|
Size: |
4096
|
|
8D70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2586540873.0000000008D70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8D70000
|
Size: |
4096
|
|
61E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704688396.00000000061E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
61E0000
|
Size: |
4096
|
|
21FB8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021FB8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21FB8000
|
Size: |
8192
|
|
24001000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243226420.0000000024001000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24001000
|
Size: |
8192
|
|
28C3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1246508687.00000000028C3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28C3000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084674399.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
21E72000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021E72000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21E72000
|
Size: |
4096
|
|
24BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3341984482.0000000024BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BD0000
|
Size: |
53248
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246792852.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
40A000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1239137966.000000000040A000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
40A000
|
Size: |
4096
|
|
23DAB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3720966775.0000000023DAB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23DAB000
|
Size: |
8192
|
|
9810000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2587141414.0000000009810000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
9810000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084656436.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
23E66000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721412508.0000000023E66000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E66000
|
Size: |
8192
|
|
3212000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2572074431.0000000003212000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3212000
|
Size: |
12288
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3073137008.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
12288
|
|
2447F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3722027946.000000002447F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2447F000
|
Size: |
4096
|
|
21FBC000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021FBC000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21FBC000
|
Size: |
8192
|
|
6210000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704779220.0000000006210000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
6210000
|
Size: |
4096
|
|
23E64000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721412508.0000000023E64000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E64000
|
Size: |
4096
|
|
8B14000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2586316395.0000000008B14000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8B14000
|
Size: |
8192
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247480505.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084346825.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
3227000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2572234666.0000000003227000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3227000
|
Size: |
32768
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243280522.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
16384
|
|
24001000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243367670.0000000024001000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24001000
|
Size: |
8192
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084156120.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
4CA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2575161931.0000000004CA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4CA0000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085367466.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
24BE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3341803141.0000000024BE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BE0000
|
Size: |
32768
|
|
24B90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3248659016.0000000024B90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B90000
|
Size: |
65536
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3242300186.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
16384
|
|
24BB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3722427991.0000000024BB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BB0000
|
Size: |
40960
|
|
6339000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704894727.0000000006339000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6339000
|
Size: |
90112
|
|
24B00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3248054639.0000000024B00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B00000
|
Size: |
20480
|
|
7AE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2583020694.0000000007AE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7AE0000
|
Size: |
65536
|
|
8570000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2584340601.0000000008570000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
8570000
|
Size: |
45056
|
|
399C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300686103.000000000399C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
399C000
|
Size: |
16384
|
|
2E71000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084134901.0000000002E71000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E71000
|
Size: |
57344
|
|
21DC5000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021DC5000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21DC5000
|
Size: |
438272
|
|
2E10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072934570.0000000002E10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E10000
|
Size: |
20480
|
|
6310000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3033138884.0000000006310000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6310000
|
Size: |
12288
|
|
21E7A000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021E7A000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21E7A000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247324902.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084069254.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
20480
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3722163920.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
65536
|
|
7680000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581356070.0000000007680000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7680000
|
Size: |
24576
|
|
22FD6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022FD6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22FD6000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246505703.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
243FF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721974291.00000000243FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
243FF000
|
Size: |
4096
|
|
24B10000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3722278937.0000000024B10000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
24B10000
|
Size: |
65536
|
|
60E7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3192161914.00000000060E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
60E7000
|
Size: |
4096
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3242850184.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
12288
|
|
40A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299632881.000000000040A000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
40A000
|
Size: |
94208
|
|
772000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1241362639.0000000000772000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
772000
|
Size: |
28672
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3250243653.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
36864
|
|
8630000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2584471470.0000000008630000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8630000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083836448.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
21BEE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718183478.0000000021BEE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
21BEE000
|
Size: |
8192
|
|
2452F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243596171.000000002452F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2452F000
|
Size: |
4096
|
|
7A4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2582684587.0000000007A4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7A4E000
|
Size: |
8192
|
|
21FCE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021FCE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21FCE000
|
Size: |
106496
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246961081.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
53248
|
|
31CF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300616009.00000000031CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
31CF000
|
Size: |
4096
|
|
24B00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247938077.0000000024B00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B00000
|
Size: |
20480
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246337806.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
2E00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3073156270.0000000002E00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
12288
|
|
3215000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2572114333.0000000003215000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
3215000
|
Size: |
45056
|
|
762000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1241362639.0000000000762000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
762000
|
Size: |
8192
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085230644.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
77B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1244018133.000000000077B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77B000
|
Size: |
8192
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085590606.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
21AA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717466979.0000000021AA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
21AA0000
|
Size: |
4096
|
|
24001000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243208408.0000000024001000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24001000
|
Size: |
8192
|
|
21D23000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021D23000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21D23000
|
Size: |
12288
|
|
24BD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3342522208.0000000024BD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BD0000
|
Size: |
57344
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247238921.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
9820000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2587164366.0000000009820000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
9820000
|
Size: |
16384
|
|
24B90000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3250017671.0000000024B90000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B90000
|
Size: |
28672
|
|
22001000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000022001000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22001000
|
Size: |
12288
|
|
24B80000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3248812830.0000000024B80000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B80000
|
Size: |
12288
|
|
74F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1242853143.000000000074F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
74F000
|
Size: |
16384
|
|
31B0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2571103271.00000000031B0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
31B0000
|
Size: |
4096
|
|
506D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2575304212.000000000506D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
506D000
|
Size: |
12288
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085101619.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
21C80000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3718287957.0000000021C80000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
21C80000
|
Size: |
65536
|
|
30E0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2570383566.00000000030E0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
30E0000
|
Size: |
4096
|
|
42D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1299632881.000000000042D000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
42D000
|
Size: |
4096
|
|
7B50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2583743621.0000000007B50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B50000
|
Size: |
65536
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244140349.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
62C4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704894727.00000000062C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
62C4000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247715311.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
7B20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2583570463.0000000007B20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7B20000
|
Size: |
65536
|
|
77B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1241805262.000000000077B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
77B000
|
Size: |
8192
|
|
240C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721865608.00000000240C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
240C0000
|
Size: |
4096
|
|
8565000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2584292315.0000000008565000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8565000
|
Size: |
45056
|
|
E97000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2568702659.0000000000E97000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E97000
|
Size: |
36864
|
|
21DA1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021DA1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21DA1000
|
Size: |
4096
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244943981.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
57344
|
|
21BAB000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3718158599.0000000021BAB000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
21BAB000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083280588.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
20480
|
|
61D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704660512.00000000061D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
61D0000
|
Size: |
4096
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3084176382.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
12288
|
|
7826000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581477880.0000000007826000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7826000
|
Size: |
421888
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083712728.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
20480
|
|
3100000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2570667965.0000000003100000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3100000
|
Size: |
4096
|
|
23E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721361803.0000000023E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E40000
|
Size: |
65536
|
|
21D35000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021D35000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21D35000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3192064698.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
61440
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247348812.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
64E7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3705295859.00000000064E7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
64E7000
|
Size: |
8192
|
|
24C10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3342277904.0000000024C10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24C10000
|
Size: |
65536
|
|
21B73000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3717826727.0000000021B73000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
21B73000
|
Size: |
4096
|
|
244BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3722053679.00000000244BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
244BE000
|
Size: |
8192
|
|
2E20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3072912740.0000000002E20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E20000
|
Size: |
65536
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244060062.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
62D4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3033073718.00000000062D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
62D4000
|
Size: |
8192
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246250089.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
23EC6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721562854.0000000023EC6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23EC6000
|
Size: |
32768
|
|
4BE3000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3701573676.0000000004BE3000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
4BE3000
|
Size: |
10485760
|
|
85ED000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2584415694.00000000085ED000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
85ED000
|
Size: |
12288
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3245180468.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3242821419.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
20480
|
|
88F4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2585164008.00000000088F4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
88F4000
|
Size: |
4096
|
|
3090000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2570092833.0000000003090000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3090000
|
Size: |
4096
|
|
4B6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2573950109.0000000004B6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4B6E000
|
Size: |
8192
|
|
7893000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581850652.0000000007893000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7893000
|
Size: |
16384
|
|
23E40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3083959204.0000000023E40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E40000
|
Size: |
20480
|
|
31F9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2571651381.00000000031F9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
31F9000
|
Size: |
16384
|
|
6200000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704747442.0000000006200000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
6200000
|
Size: |
4096
|
|
639E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2579500230.000000000639E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
639E000
|
Size: |
1220608
|
|
24B10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243473503.0000000024B10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B10000
|
Size: |
45056
|
|
22FC9000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022FC9000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22FC9000
|
Size: |
4096
|
|
24AF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243824870.0000000024AF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24AF0000
|
Size: |
65536
|
|
28CB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1245881737.00000000028CB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28CB000
|
Size: |
258048
|
|
625A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3704894727.000000000625A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
625A000
|
Size: |
266240
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
URLs found in memory or binary data |
Networking |
|
|
22F21000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022F21000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22F21000
|
Size: |
4096
|
|
7B30000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3705434074.0000000007B30000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
7B30000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721793173.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
49152
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085440255.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085768456.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
24001000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3243250418.0000000024001000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24001000
|
Size: |
8192
|
|
21D31000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021D31000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21D31000
|
Size: |
8192
|
|
2274000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1300291538.0000000002274000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2274000
|
Size: |
8192
|
|
7800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581477880.0000000007800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7800000
|
Size: |
4096
|
|
24000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3242329456.0000000024000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24000000
|
Size: |
40960
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085053302.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
766000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1241362639.0000000000766000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
766000
|
Size: |
45056
|
|
23F14000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3721691229.0000000023F14000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
23F14000
|
Size: |
262144
|
|
24500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3244444108.0000000024500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24500000
|
Size: |
12288
|
|
24B00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3248009107.0000000024B00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24B00000
|
Size: |
20480
|
|
24BA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3722385015.0000000024BA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24BA0000
|
Size: |
8192
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085479018.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3247504437.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
20480
|
|
4C0C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2574816293.0000000004C0C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4C0C000
|
Size: |
16384
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085568665.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
16384
|
|
23E60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3184298425.0000000023E60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
23E60000
|
Size: |
24576
|
|
21E74000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021E74000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21E74000
|
Size: |
4096
|
|
230AD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.00000000230AD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
230AD000
|
Size: |
4096
|
|
8AF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2586147626.0000000008AF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
8AF0000
|
Size: |
65536
|
|
2180E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3717020244.000000002180E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2180E000
|
Size: |
8192
|
|
28C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1241823315.00000000028C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
28C7000
|
Size: |
8192
|
|
21B8D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000D.00000002.3717928957.0000000021B8D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
21B8D000
|
Size: |
4096
|
|
7687000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2581356070.0000000007687000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7687000
|
Size: |
36864
|
|
21E49000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3718414338.0000000021E49000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21E49000
|
Size: |
12288
|
|
22F82000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.0000000022F82000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22F82000
|
Size: |
8192
|
|
44E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1299806598.000000000044E000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
44E000
|
Size: |
217088
|
|
24520000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3246410197.0000000024520000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
24520000
|
Size: |
12288
|
|
230E8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000002.3719866956.00000000230E8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
230E8000
|
Size: |
8192
|
|
2E70000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000D.00000003.3085161814.0000000002E70000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
13
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E70000
|
Size: |
40960
|
|