2E90000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1464956506.0000000002E90000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
2E90000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
B00000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
0000000A.00000002.3621725237.0000000000B00000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
B00000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
F30000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
0000000A.00000002.3623661223.0000000000F30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F30000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
4A00000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1465481640.0000000004A00000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4A00000
|
Size: |
5050368
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
5850000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
0000000B.00000002.3625779447.0000000005850000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5850000
|
Size: |
417792
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
2600000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1464653832.0000000002600000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
2600000
|
Size: |
290816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
FA0000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
0000000A.00000002.3623749046.0000000000FA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
FA0000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
4110000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000009.00000002.3623776214.0000000004110000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
4110000
|
Size: |
5050368
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635193708.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
34B9000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3623996294.00000000034B9000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
34B9000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639240602.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636405492.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
121000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1166011792.0000000000121000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
121000
|
Size: |
581632
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634626047.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3661000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3623996294.0000000003661000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3661000
|
Size: |
458752
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637005972.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
D13000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1166713819.0000000000D13000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D13000
|
Size: |
49152
|
|
2C00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1375753467.0000000002C00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C00000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
352E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3623996294.000000000352E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
352E000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2C20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3623620866.0000000002C20000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2C20000
|
Size: |
925696
|
|
1AF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1166083699.00000000001AF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1AF000
|
Size: |
147456
|
|
D54000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000D54000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D54000
|
Size: |
12288
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1633433334.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
21422DBE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1703141617.0000021422DBE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21422DBE000
|
Size: |
12288
|
|
37FC000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.00000000037FC000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
37FC000
|
Size: |
8192
|
|
3B28000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.0000000003B28000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3B28000
|
Size: |
8192
|
|
3032000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1464861423.0000000003032000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3032000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
CA1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1465353678.0000000000CA1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CA1000
|
Size: |
20480
|
|
21421302000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752937083.0000021421302000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21421302000
|
Size: |
28672
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638168853.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532805128.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
1DE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179587116.00000000001DE000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1DE000
|
Size: |
36864
|
|
4BC6000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.0000000004BC6000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4BC6000
|
Size: |
8192
|
|
214212DA000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752882069.00000214212DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
214212DA000
|
Size: |
61440
|
|
38F9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178046862.00000000038F9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38F9000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635157526.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
1AF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1179550850.00000000001AF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1AF000
|
Size: |
147456
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637325657.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
FF0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530359599.0000000000FF0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
FF0000
|
Size: |
4096
|
|
920000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1530119484.0000000000920000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
920000
|
Size: |
4096
|
|
21421050000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.1752718169.0000021421050000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
21421050000
|
Size: |
507904
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634933061.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
1420000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3622872407.0000000001420000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1420000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1633675117.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3804000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.0000000003804000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3804000
|
Size: |
4096
|
|
D89000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179911448.0000000000D89000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D89000
|
Size: |
12288
|
|
936000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3621800184.0000000000936000.00000004.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
936000
|
Size: |
8192
|
|
CF3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000CF3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF3000
|
Size: |
8192
|
|
58B7000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3625779447.00000000058B7000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
58B7000
|
Size: |
8192
|
|
120000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1179494957.0000000000120000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
120000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634474245.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
216A4000
|
system
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1751431759.00000000216A4000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
216A4000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637761628.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
311F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530708364.000000000311F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
311F000
|
Size: |
4096
|
|
A3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179657889.0000000000A3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A3E000
|
Size: |
8192
|
|
E46000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179987541.0000000000E46000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E46000
|
Size: |
81920
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638302456.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3753000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1177243361.0000000003753000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3753000
|
Size: |
507904
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636038886.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637955719.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3142000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.0000000003142000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3142000
|
Size: |
4096
|
|
FE0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530330391.0000000000FE0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FE0000
|
Size: |
4096
|
|
159B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623358160.000000000159B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
159B000
|
Size: |
16384
|
|
21421290000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752847968.0000021421290000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21421290000
|
Size: |
12288
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635771641.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638915112.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
FC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3622313456.0000000000FC0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FC0000
|
Size: |
4096
|
|
1AF1000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1530576343.0000000001AF1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1AF1000
|
Size: |
348160
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
EF0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3621993575.0000000000EF0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EF0000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637435653.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
21422DA6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1703180900.0000021422DA6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21422DA6000
|
Size: |
4096
|
|
4170000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.0000000004170000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4170000
|
Size: |
4096
|
|
1DE000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1166125281.00000000001DE000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
1DE000
|
Size: |
8192
|
|
3630000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1175755418.0000000003630000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3630000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
21422AB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1702109061.0000021422AB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21422AB0000
|
Size: |
4096
|
|
2F00000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3623789786.0000000002F00000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2F00000
|
Size: |
925696
|
|
EAD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179987541.0000000000EAD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EAD000
|
Size: |
4096
|
|
2A67000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1433762212.0000000002A67000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A67000
|
Size: |
8192
|
|
37D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178847968.00000000037D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
37D0000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
341C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.000000000341C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
341C000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637099079.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
C96000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1465481312.0000000000C96000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C96000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1649084526.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638710752.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
2E90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386799278.0000000002E90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2E90000
|
Size: |
172032
|
|
1030000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389560907.0000000001030000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1030000
|
Size: |
8192
|
|
2C10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3623575093.0000000002C10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C10000
|
Size: |
8192
|
|
3630000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1176847205.0000000003630000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3630000
|
Size: |
1187840
|
|
7D6B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1646898861.0000000007D6B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D6B000
|
Size: |
8192
|
|
4ADC000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.0000000004ADC000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4ADC000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384464296.0000000002813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2813000
|
Size: |
135168
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532618511.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
1220000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3623065437.0000000001220000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1220000
|
Size: |
36864
|
|
38F9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1175504009.00000000038F9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38F9000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1633724250.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
2C20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1389760180.0000000002C20000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2C20000
|
Size: |
925696
|
|
4660000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.3623776214.0000000004660000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
4660000
|
Size: |
10485760
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635557690.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532474604.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
21422DC4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1703141617.0000021422DC4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21422DC4000
|
Size: |
24576
|
|
4EE8000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1465481640.0000000004EE8000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4EE8000
|
Size: |
4096
|
|
D02000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1640822564.0000000000D02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D02000
|
Size: |
12288
|
|
3142000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530836076.0000000003142000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3142000
|
Size: |
4096
|
|
F00000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3622053947.0000000000F00000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F00000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637402450.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
37D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1176969324.00000000037D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
37D0000
|
Size: |
1196032
|
|
7D9A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1648507115.0000000007D9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D9A000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532878520.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634889026.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
B80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3622428679.0000000000B80000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B80000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1479533676.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
217088
|
|
2802000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1464764165.0000000002802000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2802000
|
Size: |
20480
|
|
D22000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1166713819.0000000000D22000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D22000
|
Size: |
565248
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638481896.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3342000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1464996844.0000000003342000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3342000
|
Size: |
40960
|
|
3600000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1465481640.0000000003600000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3600000
|
Size: |
10485760
|
|
1A50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1180111679.0000000001A50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1A50000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639180805.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
2780000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1464732571.0000000002780000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2780000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1649045793.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
1485000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623094571.0000000001485000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1485000
|
Size: |
12288
|
|
2A19000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1464811830.0000000002A19000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A19000
|
Size: |
4096
|
|
156A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623358160.000000000156A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
156A000
|
Size: |
8192
|
|
11BA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3623065437.00000000011BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11BA000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638597172.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532664236.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636903593.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
D41000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000D41000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D41000
|
Size: |
36864
|
|
2813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387132515.0000000002813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2813000
|
Size: |
233472
|
|
3753000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1175287884.0000000003753000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3753000
|
Size: |
507904
|
|
DCB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1166682343.0000000000DCB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DCB000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635406196.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634968269.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
C92000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1465291449.0000000000C92000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C92000
|
Size: |
36864
|
|
18EE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1180044154.00000000018EE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
18EE000
|
Size: |
8192
|
|
1994000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1180057620.0000000001994000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1994000
|
Size: |
8192
|
|
3390000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3623996294.0000000003390000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3390000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635038425.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
C9B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1465436250.0000000000C9B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9B000
|
Size: |
24576
|
|
939000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3621873297.0000000000939000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
939000
|
Size: |
61440
|
|
AB0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3622123098.0000000000AB0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AB0000
|
Size: |
4096
|
|
921000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000009.00000000.1389020084.0000000000921000.00000020.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
921000
|
Size: |
57344
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1633882052.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
921000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000009.00000002.3621651941.0000000000921000.00000020.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
921000
|
Size: |
57344
|
|
3753000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1175755418.0000000003753000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3753000
|
Size: |
507904
|
|
2813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386880079.0000000002813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2813000
|
Size: |
69632
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638625080.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
2E90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384314056.0000000002E90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2E90000
|
Size: |
172032
|
|
2813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384639903.0000000002813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2813000
|
Size: |
233472
|
|
B80000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3621855812.0000000000B80000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B80000
|
Size: |
4096
|
|
3134000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530723074.0000000003134000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3134000
|
Size: |
4096
|
|
D6A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1647043731.0000000000D6A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D6A000
|
Size: |
24576
|
|
457E000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.000000000457E000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
457E000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637715455.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639150732.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1649125226.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
1760000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1530559923.0000000001760000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1760000
|
Size: |
36864
|
|
2F00000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1530617131.0000000002F00000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2F00000
|
Size: |
925696
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639359244.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
FB0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1530282226.0000000000FB0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FB0000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639456929.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
37D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1177364529.00000000037D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
37D0000
|
Size: |
1196032
|
|
B90000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389436313.0000000000B90000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B90000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638944543.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
120000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1165994017.0000000000120000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
120000
|
Size: |
4096
|
|
38FD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1175504009.00000000038FD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38FD000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
175C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623645351.000000000175C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
175C000
|
Size: |
16384
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637544866.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
CAD000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000CAD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CAD000
|
Size: |
217088
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638512301.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
5950000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1465481640.0000000005950000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
5950000
|
Size: |
77824
|
|
FD0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1530311603.0000000000FD0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FD0000
|
Size: |
4096
|
|
AA0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1389180195.0000000000AA0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AA0000
|
Size: |
4096
|
|
3290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1476954761.0000000003290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3290000
|
Size: |
159744
|
|
D1D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1642878504.0000000000D1D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D1D000
|
Size: |
12288
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635122854.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
58DD000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3625779447.00000000058DD000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
58DD000
|
Size: |
16384
|
|
BE1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3622553621.0000000000BE1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BE1000
|
Size: |
12288
|
|
679000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179641376.0000000000679000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
679000
|
Size: |
28672
|
|
520E000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.000000000520E000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
520E000
|
Size: |
4096
|
|
1025000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3622558039.0000000001025000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1025000
|
Size: |
4096
|
|
5934000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3625779447.0000000005934000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
5934000
|
Size: |
319488
|
|
D14000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000D14000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D14000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637801673.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634392911.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
D65000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000D65000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D65000
|
Size: |
65536
|
|
7E60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3626998572.0000000007E60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7E60000
|
Size: |
4096
|
|
2A6A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1433666414.0000000002A6A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A6A000
|
Size: |
16384
|
|
1030000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3622834930.0000000001030000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1030000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637514963.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
38FD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1175910863.00000000038FD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38FD000
|
Size: |
458752
|
|
2813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1377525684.0000000002813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2813000
|
Size: |
69632
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634818238.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
1034000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3622834930.0000000001034000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1034000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634039159.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
20FE2000
|
system
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1751431759.0000000020FE2000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
20FE2000
|
Size: |
4096
|
|
2800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1464764165.0000000002800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2800000
|
Size: |
4096
|
|
D8B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1169312734.0000000000D8B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D8B000
|
Size: |
8192
|
|
7D8A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3626711632.0000000007D8A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D8A000
|
Size: |
36864
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634508215.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
2813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1386960186.0000000002813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2813000
|
Size: |
131072
|
|
2813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1377756393.0000000002813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2813000
|
Size: |
237568
|
|
1E7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1166155334.00000000001E7000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1E7000
|
Size: |
483328
|
|
CFE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1640822564.0000000000CFE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFE000
|
Size: |
4096
|
|
58C1000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3625779447.00000000058C1000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
58C1000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
156E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530506453.000000000156E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
156E000
|
Size: |
90112
|
|
D2E000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1179880843.0000000000D2E000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
D2E000
|
Size: |
20480
|
|
14EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1180029538.00000000014EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
14EF000
|
Size: |
4096
|
|
214212EC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752882069.00000214212EC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
214212EC000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
5060000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.3623776214.0000000005060000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
5060000
|
Size: |
77824
|
|
CEF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1640822564.0000000000CEF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CEF000
|
Size: |
4096
|
|
238C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1464616387.000000000238C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
238C000
|
Size: |
16384
|
|
3290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1474548383.0000000003290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3290000
|
Size: |
159744
|
|
150C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623290036.000000000150C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
150C000
|
Size: |
16384
|
|
3E4C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.0000000003E4C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3E4C000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
920000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1388987292.0000000000920000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
920000
|
Size: |
4096
|
|
2B4F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389732304.0000000002B4F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B4F000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638208803.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
C60000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622179551.0000000000C60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C60000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635250075.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
8000000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3627022787.0000000008000000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8000000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1471319141.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
21421302000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1703223531.0000021421302000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21421302000
|
Size: |
28672
|
|
E5A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1169756290.0000000000E5A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E5A000
|
Size: |
344064
|
|
21422D01000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1753085974.0000021422D01000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21422D01000
|
Size: |
4096
|
|
B70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1389381566.0000000000B70000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B70000
|
Size: |
4096
|
|
AB0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1389200844.0000000000AB0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AB0000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636582865.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
7DB6000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3626711632.0000000007DB6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7DB6000
|
Size: |
24576
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532836019.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
26A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1464715536.00000000026A0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
26A0000
|
Size: |
4096
|
|
2F2D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1377295466.0000000002F2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F2D000
|
Size: |
458752
|
|
507C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.000000000507C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
507C000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636518688.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532507391.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
21421170000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752812393.0000021421170000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21421170000
|
Size: |
4096
|
|
38FD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1176969324.00000000038FD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38FD000
|
Size: |
458752
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1471149760.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
217088
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635588058.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
396E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1175910863.000000000396E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
396E000
|
Size: |
24576
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638272420.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3130000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530723074.0000000003130000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3130000
|
Size: |
8192
|
|
D66000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1169235628.0000000000D66000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D66000
|
Size: |
118784
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637174211.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634755539.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639029908.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
92F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3621724189.000000000092F000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
92F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
21422C12000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752988636.0000021422C12000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21422C12000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636296949.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
939000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1389111226.0000000000939000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
939000
|
Size: |
61440
|
|
7E50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3626975606.0000000007E50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7E50000
|
Size: |
4096
|
|
7DAC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3626711632.0000000007DAC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7DAC000
|
Size: |
12288
|
|
2CFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1464858393.0000000002CFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2CFF000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638419156.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
C93000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000C93000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C93000
|
Size: |
77824
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
D07000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000D07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D07000
|
Size: |
12288
|
|
1480000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623094571.0000000001480000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1480000
|
Size: |
16384
|
|
BE1000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1389486599.0000000000BE1000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BE1000
|
Size: |
12288
|
|
B80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389407592.0000000000B80000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B80000
|
Size: |
4096
|
|
EFD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3622700066.0000000000EFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EFD000
|
Size: |
12288
|
|
4D58000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.0000000004D58000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4D58000
|
Size: |
4096
|
|
1440000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3622938006.0000000001440000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1440000
|
Size: |
16384
|
|
C97000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1465318558.0000000000C97000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C97000
|
Size: |
20480
|
|
21421260000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752831154.0000021421260000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
21421260000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636873808.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637618392.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
14CE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530482696.00000000014CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
14CE000
|
Size: |
8192
|
|
3000000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1464996844.0000000003000000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3000000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1649007454.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
12FC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3622628742.00000000012FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12FC000
|
Size: |
16384
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634788477.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
1411000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3622809511.0000000001411000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1411000
|
Size: |
12288
|
|
38FD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1177364529.00000000038FD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38FD000
|
Size: |
458752
|
|
36D2000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3623996294.00000000036D2000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
36D2000
|
Size: |
40960
|
|
494A000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.000000000494A000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
494A000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639088614.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637064215.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
D4B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1167298245.0000000000D4B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4B000
|
Size: |
229376
|
|
21422B00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752954922.0000021422B00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21422B00000
|
Size: |
4096
|
|
A5B000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3621511957.0000000000A5B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A5B000
|
Size: |
20480
|
|
47B8000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.00000000047B8000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
47B8000
|
Size: |
4096
|
|
F7A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530265789.0000000000F7A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F7A000
|
Size: |
24576
|
|
D2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1169235628.0000000000D2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D2F000
|
Size: |
172032
|
|
D14000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1640822564.0000000000D14000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D14000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532273411.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
11B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389631168.00000000011B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11B0000
|
Size: |
32768
|
|
2670000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1464699996.0000000002670000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2670000
|
Size: |
4096
|
|
156A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530506453.000000000156A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
156A000
|
Size: |
8192
|
|
4A34000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.0000000004A34000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4A34000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
39BC000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.00000000039BC000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
39BC000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
D2D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000D2D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D2D000
|
Size: |
4096
|
|
B50000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1389313705.0000000000B50000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B50000
|
Size: |
4096
|
|
3202000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.0000000003202000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3202000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638830954.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636844920.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639680122.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
396E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1176969324.000000000396E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
396E000
|
Size: |
24576
|
|
1589000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623358160.0000000001589000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1589000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
D89000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1169804594.0000000000D89000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D89000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634719156.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532329431.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
92F000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1530165457.000000000092F000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
92F000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
212BC000
|
system
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1751431759.00000000212BC000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
212BC000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637145005.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
425A000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.000000000425A000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
425A000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635712338.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
311F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623959377.000000000311F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
311F000
|
Size: |
4096
|
|
21422C00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752971276.0000021422C00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21422C00000
|
Size: |
4096
|
|
338E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3623961936.000000000338E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
338E000
|
Size: |
8192
|
|
4EEA000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.0000000004EEA000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4EEA000
|
Size: |
4096
|
|
21422C03000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752988636.0000021422C03000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21422C03000
|
Size: |
16384
|
|
3630000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1175287884.0000000003630000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3630000
|
Size: |
1187840
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638886944.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1479632280.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
A5B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179657889.0000000000A5B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A5B000
|
Size: |
20480
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634442219.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639488169.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636363906.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
F10000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3623616759.0000000000F10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F10000
|
Size: |
4096
|
|
2813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1381541350.0000000002813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2813000
|
Size: |
237568
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637362142.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
C9B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1465525999.0000000000C9B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9B000
|
Size: |
24576
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638023713.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
38FD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178046862.00000000038FD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38FD000
|
Size: |
458752
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638541384.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
40C8000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.00000000040C8000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
40C8000
|
Size: |
8192
|
|
FC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1530297142.0000000000FC0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FC0000
|
Size: |
4096
|
|
214210DC000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.1752718169.00000214210DC000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
214210DC000
|
Size: |
4096
|
|
B2E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179753045.0000000000B2E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B2E000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1633265584.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
F00000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1530235800.0000000000F00000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F00000
|
Size: |
4096
|
|
936000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389096537.0000000000936000.00000004.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
936000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635436792.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
330D000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3623934516.000000000330D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
330D000
|
Size: |
12288
|
|
BD4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1467082771.0000000000BD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BD4000
|
Size: |
4096
|
|
2E00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1377295466.0000000002E00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E00000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638802923.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3F36000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.0000000003F36000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3F36000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2650000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1464683475.0000000002650000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2650000
|
Size: |
4096
|
|
210FC000
|
system
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1751431759.00000000210FC000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
210FC000
|
Size: |
4096
|
|
1070000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389602904.0000000001070000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1070000
|
Size: |
20480
|
|
1411000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1530396389.0000000001411000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1411000
|
Size: |
12288
|
|
1050000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389589707.0000000001050000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1050000
|
Size: |
4096
|
|
854E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3627048282.000000000854E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
854E000
|
Size: |
8192
|
|
920000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3621525992.0000000000920000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
920000
|
Size: |
4096
|
|
FF0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3622499351.0000000000FF0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
FF0000
|
Size: |
4096
|
|
D18000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1642878504.0000000000D18000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D18000
|
Size: |
8192
|
|
11BE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389631168.00000000011BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11BE000
|
Size: |
94208
|
|
3401000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1465449290.0000000003401000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3401000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638680647.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
AE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179732710.0000000000AE0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
AE0000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639943668.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635528743.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635869592.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
92F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1389049639.000000000092F000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
92F000
|
Size: |
28672
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635499517.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
319E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1464996844.000000000319E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
319E000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638236788.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636715906.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
365D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3623996294.000000000365D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
365D000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634010342.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
11BE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3623065437.00000000011BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11BE000
|
Size: |
360448
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7D93000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1648507115.0000000007D93000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D93000
|
Size: |
4096
|
|
B1A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389222230.0000000000B1A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B1A000
|
Size: |
24576
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638972156.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
7D98000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1648507115.0000000007D98000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D98000
|
Size: |
4096
|
|
23CA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1464636031.00000000023CA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
23CA000
|
Size: |
24576
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635338011.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
2813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1377603895.0000000002813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2813000
|
Size: |
135168
|
|
2B01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1464842999.0000000002B01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B01000
|
Size: |
4096
|
|
38FD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178847968.00000000038FD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38FD000
|
Size: |
458752
|
|
1760000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3623684593.0000000001760000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1760000
|
Size: |
36864
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635678422.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636329457.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1648959996.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
4494000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.0000000004494000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4494000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
38F9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1175910863.00000000038F9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38F9000
|
Size: |
4096
|
|
936000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530186145.0000000000936000.00000004.00000001.01000000.00000007.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
936000
|
Size: |
8192
|
|
2D10000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.3623776214.0000000002D10000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
2D10000
|
Size: |
10485760
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637910978.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635949509.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
7D78000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1646898861.0000000007D78000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D78000
|
Size: |
4096
|
|
34BD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3623996294.00000000034BD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
34BD000
|
Size: |
458752
|
|
214210D9000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000C.00000002.1752718169.00000214210D9000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
214210D9000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636183253.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
43EC000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.00000000043EC000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
43EC000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
D36000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1167351450.0000000000D36000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D36000
|
Size: |
86016
|
|
1070000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3622987981.0000000001070000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1070000
|
Size: |
20480
|
|
D8C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1169890622.0000000000D8C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D8C000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636786344.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1633195894.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
CF3000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1640822564.0000000000CF3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF3000
|
Size: |
8192
|
|
C90000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1465119341.0000000000C90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C90000
|
Size: |
28672
|
|
1560000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623358160.0000000001560000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1560000
|
Size: |
32768
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639329998.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
1560000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530506453.0000000001560000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1560000
|
Size: |
32768
|
|
D76000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1166897292.0000000000D76000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D76000
|
Size: |
847872
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2A12000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1464811830.0000000002A12000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A12000
|
Size: |
24576
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638450836.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
325C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.000000000325C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
325C000
|
Size: |
8192
|
|
38F9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1177364529.00000000038F9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38F9000
|
Size: |
4096
|
|
1420000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530412267.0000000001420000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1420000
|
Size: |
4096
|
|
A4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179657889.0000000000A4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A4E000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634349792.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
58D1000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.3625779447.00000000058D1000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
58D1000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639425721.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
37D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1175504009.00000000037D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
37D0000
|
Size: |
1196032
|
|
936000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3621798433.0000000000936000.00000004.00000001.01000000.00000007.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
936000
|
Size: |
8192
|
|
F10000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3622112337.0000000000F10000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F10000
|
Size: |
4096
|
|
27CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1464748172.00000000027CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
27CE000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636615909.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
2813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1381305927.0000000002813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2813000
|
Size: |
69632
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636009095.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
1050000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3622939061.0000000001050000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1050000
|
Size: |
4096
|
|
3723BFC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752600216.0000003723BFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3723BFC000
|
Size: |
16384
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532116815.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
210A2000
|
system
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1751431759.00000000210A2000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
210A2000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637210785.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
D89000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1169235628.0000000000D89000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D89000
|
Size: |
16384
|
|
7D7F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3626711632.0000000007D7F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D7F000
|
Size: |
12288
|
|
2A6A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1433762212.0000000002A6A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A6A000
|
Size: |
16384
|
|
D8C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1169804594.0000000000D8C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D8C000
|
Size: |
4096
|
|
3130000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3623845716.0000000003130000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3130000
|
Size: |
90112
|
|
AA0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3622062843.0000000000AA0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
AA0000
|
Size: |
4096
|
|
3309000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1466835116.0000000003309000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3309000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637850611.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
1D4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1166083699.00000000001D4000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1D4000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638138155.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1633967011.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
1640000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1389698089.0000000001640000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1640000
|
Size: |
352256
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
D66000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179911448.0000000000D66000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D66000
|
Size: |
118784
|
|
1990000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1180057620.0000000001990000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1990000
|
Size: |
8192
|
|
396E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1176480029.000000000396E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
396E000
|
Size: |
24576
|
|
4626000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.0000000004626000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4626000
|
Size: |
8192
|
|
C9B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1465119341.0000000000C9B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9B000
|
Size: |
24576
|
|
2A17000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1375962245.0000000002A17000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A17000
|
Size: |
20480
|
|
B6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179767407.0000000000B6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B6E000
|
Size: |
8192
|
|
2E3F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1464902577.0000000002E3F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E3F000
|
Size: |
4096
|
|
CFE000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000CFE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CFE000
|
Size: |
4096
|
|
396E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178847968.000000000396E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
396E000
|
Size: |
24576
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638652990.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532777495.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
2813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384390724.0000000002813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2813000
|
Size: |
69632
|
|
1E7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1179603624.00000000001E7000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1E7000
|
Size: |
483328
|
|
2E90000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1433735498.0000000002E90000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2E90000
|
Size: |
172032
|
|
21422AB0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1702062837.0000021422AB0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21422AB0000
|
Size: |
4096
|
|
4F50000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1465481640.0000000004F50000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4F50000
|
Size: |
10485760
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639270903.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
DAC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1166580590.0000000000DAC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DAC000
|
Size: |
131072
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639583545.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
AD8000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3621653459.0000000000AD8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
AD8000
|
Size: |
32768
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636647054.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
C96000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1465160603.0000000000C96000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C96000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634858290.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532442104.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
7DA7000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3626711632.0000000007DA7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7DA7000
|
Size: |
12288
|
|
EFD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389513974.0000000000EFD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
EFD000
|
Size: |
12288
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635801483.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
11B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3623065437.00000000011B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11B0000
|
Size: |
32768
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634071421.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3753000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1176847205.0000000003753000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3753000
|
Size: |
507904
|
|
341C000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530836076.000000000341C000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
341C000
|
Size: |
53248
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639552558.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
312D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1464996844.000000000312D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
312D000
|
Size: |
458752
|
|
CC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179812850.0000000000CC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CC0000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636678301.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
2813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1381376362.0000000002813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2813000
|
Size: |
135168
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635919049.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532695501.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1467059579.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
65536
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532240560.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
7DAC000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1648507115.0000000007DAC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7DAC000
|
Size: |
4096
|
|
A90000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1389126811.0000000000A90000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A90000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532175285.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
D07000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1640822564.0000000000D07000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D07000
|
Size: |
12288
|
|
2A05000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1375943830.0000000002A05000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A05000
|
Size: |
49152
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637651652.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634316738.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
2A1A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1433666414.0000000002A1A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A1A000
|
Size: |
270336
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3DA4000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.0000000003DA4000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3DA4000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639300563.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
396E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178046862.000000000396E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
396E000
|
Size: |
24576
|
|
EF0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1530220833.0000000000EF0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
EF0000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532728368.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
2790000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1380981708.0000000002790000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2790000
|
Size: |
172032
|
|
CF8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179826478.0000000000CF8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF8000
|
Size: |
176128
|
|
3630000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178402734.0000000003630000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3630000
|
Size: |
1187840
|
|
F90000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3623712312.0000000000F90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F90000
|
Size: |
16384
|
|
7D7D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1646898861.0000000007D7D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D7D000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637574516.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
48A2000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.00000000048A2000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
48A2000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638101323.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
21422D00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1702687430.0000021422D00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21422D00000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638333048.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
2A17000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1376015135.0000000002A17000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A17000
|
Size: |
20480
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639000321.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3710000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.3623776214.0000000003710000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3710000
|
Size: |
10485760
|
|
214212D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752882069.00000214212D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
214212D0000
|
Size: |
32768
|
|
D2F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000D2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D2F000
|
Size: |
12288
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634592448.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
14CE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623220999.00000000014CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
14CE000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532367369.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
D2F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1167250463.0000000000D2F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D2F000
|
Size: |
110592
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634686608.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
12B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1389681244.00000000012B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
12B0000
|
Size: |
36864
|
|
396E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1177364529.000000000396E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
396E000
|
Size: |
24576
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639616426.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
4710000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.0000000004710000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4710000
|
Size: |
4096
|
|
D36000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1169804594.0000000000D36000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D36000
|
Size: |
315392
|
|
D22000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1166617088.0000000000D22000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D22000
|
Size: |
565248
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638858727.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
7D7B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3626711632.0000000007D7B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D7B000
|
Size: |
8192
|
|
4000000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1465481640.0000000004000000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4000000
|
Size: |
10485760
|
|
92F000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3621724388.000000000092F000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
92F000
|
Size: |
28672
|
|
2A3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1433762212.0000000002A3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A3D000
|
Size: |
126976
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
21422C15000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752988636.0000021422C15000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21422C15000
|
Size: |
16384
|
|
BD4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1471209646.0000000000BD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BD4000
|
Size: |
4096
|
|
D35000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1179880843.0000000000D35000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
D35000
|
Size: |
4096
|
|
32D1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1464996844.00000000032D1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
32D1000
|
Size: |
458752
|
|
3FDE000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.0000000003FDE000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3FDE000
|
Size: |
4096
|
|
31E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1466835116.00000000031E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31E0000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2C10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389746567.0000000002C10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C10000
|
Size: |
8192
|
|
12B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3623384137.00000000012B0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
12B0000
|
Size: |
36864
|
|
37253FF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752700084.00000037253FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
37253FF000
|
Size: |
4096
|
|
31E0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.3623890501.00000000031E0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
31E0000
|
Size: |
90112
|
|
11BA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389631168.00000000011BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11BA000
|
Size: |
8192
|
|
C5F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622123870.0000000000C5F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C5F000
|
Size: |
4096
|
|
1E2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1166125281.00000000001E2000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
1E2000
|
Size: |
8192
|
|
D23000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1166972098.0000000000D23000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D23000
|
Size: |
339968
|
|
1440000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1530428001.0000000001440000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1440000
|
Size: |
16384
|
|
3134000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623994419.0000000003134000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3134000
|
Size: |
4096
|
|
7D71000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1646898861.0000000007D71000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D71000
|
Size: |
4096
|
|
121000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.1179509778.0000000000121000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
121000
|
Size: |
581632
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1633773660.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639059814.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
A7C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179657889.0000000000A7C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
A7C000
|
Size: |
16384
|
|
45F8000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000009.00000002.3623776214.00000000045F8000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
45F8000
|
Size: |
4096
|
|
7D76000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3626711632.0000000007D76000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D76000
|
Size: |
8192
|
|
1AF0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3623708435.0000000001AF0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1AF0000
|
Size: |
352256
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639120214.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
2E40000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1464922286.0000000002E40000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
2E40000
|
Size: |
274432
|
|
3630000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1177243361.0000000003630000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3630000
|
Size: |
1187840
|
|
156E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623358160.000000000156E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
156E000
|
Size: |
94208
|
|
939000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3621877140.0000000000939000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
939000
|
Size: |
61440
|
|
D2A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179826478.0000000000D2A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D2A000
|
Size: |
16384
|
|
921000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000B.00000000.1530145102.0000000000921000.00000020.00000001.01000000.00000007.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
921000
|
Size: |
57344
|
|
2F9E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1377295466.0000000002F9E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F9E000
|
Size: |
24576
|
|
D34000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000D34000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D34000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532551225.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
2D3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1464881008.0000000002D3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D3E000
|
Size: |
8192
|
|
3753000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178402734.0000000003753000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3753000
|
Size: |
507904
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639519641.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636141453.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532302399.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635285582.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
B50000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3622250547.0000000000B50000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B50000
|
Size: |
4096
|
|
37D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1175910863.00000000037D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
37D0000
|
Size: |
1196032
|
|
19A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1180082767.00000000019A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
19A0000
|
Size: |
290816
|
|
7DA2000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3626711632.0000000007DA2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7DA2000
|
Size: |
12288
|
|
CEF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000CEF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CEF000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634654716.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
2A67000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1433666414.0000000002A67000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A67000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638569739.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
D2B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000D2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D2B000
|
Size: |
4096
|
|
C88000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000C88000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C88000
|
Size: |
36864
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532148255.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
B90000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3622497291.0000000000B90000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
B90000
|
Size: |
4096
|
|
214212FB000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1703223531.00000214212FB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
214212FB000
|
Size: |
4096
|
|
FD0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3622368061.0000000000FD0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FD0000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636754425.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
2813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1381451125.0000000002813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2813000
|
Size: |
200704
|
|
C90000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1465436250.0000000000C90000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C90000
|
Size: |
28672
|
|
37A2000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.00000000037A2000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
37A2000
|
Size: |
8192
|
|
D5F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000D5F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D5F000
|
Size: |
12288
|
|
1480000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530462519.0000000001480000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1480000
|
Size: |
20480
|
|
7D9F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1648507115.0000000007D9F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D9F000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635620884.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635978605.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1633358381.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
37D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178046862.00000000037D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
37D0000
|
Size: |
1196032
|
|
4C6E000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.0000000004C6E000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4C6E000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635649647.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
D4C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000D4C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D4C000
|
Size: |
12288
|
|
1020000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3622764714.0000000001020000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1020000
|
Size: |
16384
|
|
3290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532932649.0000000003290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3290000
|
Size: |
159744
|
|
85CF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3627075924.00000000085CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
85CF000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638740935.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1633313321.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3996000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.0000000003996000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3996000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
C9B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1465160603.0000000000C9B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9B000
|
Size: |
24576
|
|
2813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1387038468.0000000002813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2813000
|
Size: |
196608
|
|
3753000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1176177550.0000000003753000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3753000
|
Size: |
507904
|
|
B1A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3622178401.0000000000B1A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B1A000
|
Size: |
24576
|
|
3010000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530691667.0000000003010000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3010000
|
Size: |
8192
|
|
BD4000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1471240488.0000000000BD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BD4000
|
Size: |
4096
|
|
330D000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1466835116.000000000330D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
330D000
|
Size: |
458752
|
|
36E2000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3624631563.00000000036E2000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
36E2000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634564064.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3010000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623918034.0000000003010000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3010000
|
Size: |
12288
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636816944.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
214212FF000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1703223531.00000214212FF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
214212FF000
|
Size: |
4096
|
|
21422C21000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752988636.0000021422C21000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21422C21000
|
Size: |
4096
|
|
2813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1384546733.0000000002813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2813000
|
Size: |
200704
|
|
A90000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3621993719.0000000000A90000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
A90000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636448916.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639390621.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
38FD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1176480029.00000000038FD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38FD000
|
Size: |
458752
|
|
B60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1389354985.0000000000B60000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B60000
|
Size: |
4096
|
|
7D66000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1646898861.0000000007D66000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D66000
|
Size: |
8192
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1649164070.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
117F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389617801.000000000117F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
117F000
|
Size: |
4096
|
|
21422DCE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000003.1703120662.0000021422DCE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21422DCE000
|
Size: |
4096
|
|
3155000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1464861423.0000000003155000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3155000
|
Size: |
512000
|
|
1D4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1179550850.00000000001D4000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1D4000
|
Size: |
40960
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1640070000.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
BCE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3621975194.0000000000BCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BCE000
|
Size: |
8192
|
|
3130000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623994419.0000000003130000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3130000
|
Size: |
8192
|
|
1034000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389560907.0000000001034000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1034000
|
Size: |
4096
|
|
BF0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389500519.0000000000BF0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
BF0000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636485909.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
337E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1466835116.000000000337E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
337E000
|
Size: |
24576
|
|
38F9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178847968.00000000038F9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38F9000
|
Size: |
4096
|
|
2F29000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1377295466.0000000002F29000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2F29000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532411810.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
21422C0F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752988636.0000021422C0F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
21422C0F000
|
Size: |
8192
|
|
BDE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389464227.0000000000BDE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BDE000
|
Size: |
8192
|
|
B70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179781328.0000000000B70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B70000
|
Size: |
4096
|
|
7D83000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1646898861.0000000007D83000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D83000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635742566.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
B70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3622363803.0000000000B70000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B70000
|
Size: |
4096
|
|
2A00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1464794986.0000000002A00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A00000
|
Size: |
45056
|
|
D5A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000D5A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D5A000
|
Size: |
12288
|
|
32CD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1464996844.00000000032CD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
32CD000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635001924.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
C9B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1465208886.0000000000C9B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9B000
|
Size: |
24576
|
|
38F9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1176480029.00000000038F9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38F9000
|
Size: |
4096
|
|
DAB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179942845.0000000000DAB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DAB000
|
Size: |
630784
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1633921621.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
2A05000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1375999137.0000000002A05000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2A05000
|
Size: |
49152
|
|
F7A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3622176044.0000000000F7A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F7A000
|
Size: |
24576
|
|
921000
|
unkown
|
page execute read
|
|
|
|
Name: |
0000000B.00000002.3621649297.0000000000921000.00000020.00000001.01000000.00000007.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
921000
|
Size: |
57344
|
|
2D23000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1375753467.0000000002D23000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D23000
|
Size: |
507904
|
|
2813000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1377673354.0000000002813000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2813000
|
Size: |
196608
|
|
939000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1530203018.0000000000939000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
939000
|
Size: |
61440
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636951758.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
1460000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3623023973.0000000001460000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1460000
|
Size: |
4096
|
|
396E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1175504009.000000000396E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
396E000
|
Size: |
24576
|
|
BD0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622046795.0000000000BD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BD0000
|
Size: |
16384
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532203361.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
BF0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3622625266.0000000000BF0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
BF0000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639210317.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
3630000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1177609966.0000000003630000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3630000
|
Size: |
1187840
|
|
13E0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3622764250.00000000013E0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13E0000
|
Size: |
4096
|
|
3753000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1177609966.0000000003753000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3753000
|
Size: |
507904
|
|
1460000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530446744.0000000001460000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1460000
|
Size: |
4096
|
|
13D0000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3622701803.00000000013D0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
13D0000
|
Size: |
12288
|
|
FE0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3622427961.0000000000FE0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FE0000
|
Size: |
4096
|
|
B60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3622317247.0000000000B60000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
B60000
|
Size: |
4096
|
|
1640000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3623450945.0000000001640000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1640000
|
Size: |
352256
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
7D60000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3626711632.0000000007D60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D60000
|
Size: |
24576
|
|
3030000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3623817624.0000000003030000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3030000
|
Size: |
4096
|
|
1020000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000000.1389544496.0000000001020000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1020000
|
Size: |
16384
|
|
12FC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000000.1530378906.00000000012FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12FC000
|
Size: |
16384
|
|
3630000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1176177550.0000000003630000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3630000
|
Size: |
1187840
|
|
C9B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1465481312.0000000000C9B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C9B000
|
Size: |
24576
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637682171.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638772549.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
38F9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1176969324.00000000038F9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38F9000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1637482202.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
4302000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.0000000004302000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
4302000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3CBA000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3624057264.0000000003CBA000.00000004.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
3CBA000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635469279.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
37D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1176480029.00000000037D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
37D0000
|
Size: |
1196032
|
|
FB0000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000002.3622244028.0000000000FB0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FB0000
|
Size: |
4096
|
|
CA1000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1465092894.0000000000CA1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CA1000
|
Size: |
20480
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1532583821.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
F10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1470612179.0000000000F10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F10000
|
Size: |
159744
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1636550766.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
920000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000009.00000002.3621528781.0000000000920000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
920000
|
Size: |
4096
|
|
7DA5000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1648507115.0000000007DA5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7DA5000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1635376527.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
C80000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000C80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C80000
|
Size: |
24576
|
|
BB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179795781.0000000000BB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
BB0000
|
Size: |
24576
|
|
3129000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1464996844.0000000003129000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3129000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1634536353.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
4096
|
|
3031000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1638363614.0000000003031000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3031000
|
Size: |
8192
|
|
214212A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752865273.00000214212A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
214212A0000
|
Size: |
4096
|
|
3724BFE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752680438.0000003724BFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3724BFE000
|
Size: |
8192
|
|
CF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1179826478.0000000000CF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CF0000
|
Size: |
24576
|
|
101E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000000.1389528632.000000000101E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
101E000
|
Size: |
8192
|
|
F10000
|
unkown
|
page readonly
|
|
|
|
Name: |
0000000B.00000000.1530250477.0000000000F10000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F10000
|
Size: |
4096
|
|
6300000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3626591603.0000000006300000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6300000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7D55000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639821178.0000000007D55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7D55000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
DAB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1166972098.0000000000DAB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DAB000
|
Size: |
630784
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
D02000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.3622244312.0000000000D02000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D02000
|
Size: |
12288
|
|
37243FD000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000C.00000002.1752642132.00000037243FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
37243FD000
|
Size: |
12288
|
|