3790000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1404778921.0000000003790000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3790000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
4EC0000
|
unkown
|
page execute and read and write
|
 |
|
|
Name: |
00000007.00000002.3677471460.0000000004EC0000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
4EC0000
|
Size: |
5890048
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3050000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000008.00000002.3676000841.0000000003050000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3050000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3000000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000008.00000002.3675864670.0000000003000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3000000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
400000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1404313483.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
286720
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
7F20000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000007.00000002.3681688673.0000000007F20000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
7F20000
|
Size: |
290816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
5C50000
|
unclassified section
|
page execute and read and write
|
 |
|
|
Name: |
00000001.00000002.1405459163.0000000005C50000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
5C50000
|
Size: |
5890048
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
A00000
|
system
|
page execute and read and write
|
 |
|
|
Name: |
00000008.00000002.3675258966.0000000000A00000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
A00000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected FormBook |
AV Detection, E-Banking Fraud, Stealing of Sensitive Information, Remote Access Functionality |
|
|
3593000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1406538532.0000000003593000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3593000
|
Size: |
4096
|
|
3200000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1404561085.0000000003200000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3200000
|
Size: |
4096
|
|
3A22000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.0000000003A22000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3A22000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573323885.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576363892.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
1B00C190000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1696866636.000001B00C190000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B00C190000
|
Size: |
4096
|
|
7C9D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3679790336.0000000007C9D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C9D000
|
Size: |
45056
|
|
5250000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1405459163.0000000005250000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
5250000
|
Size: |
10485760
|
|
1184000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3675785737.0000000001184000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1184000
|
Size: |
4096
|
|
1B00DEAD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1641171073.000001B00DEAD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B00DEAD000
|
Size: |
8192
|
|
120E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1251111331.000000000120E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
120E000
|
Size: |
4096
|
|
D61000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.1250776978.0000000000D61000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
D61000
|
Size: |
581632
|
|
6E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1300789960.00000000006E0000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6E0000
|
Size: |
4096
|
|
321D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.000000000321D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
321D000
|
Size: |
8192
|
|
B20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3675678239.0000000000B20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B20000
|
Size: |
4096
|
|
7C83000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1585854152.0000000007C83000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C83000
|
Size: |
4096
|
|
3AAE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1231143626.0000000003AAE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3AAE000
|
Size: |
24576
|
|
11C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1220251300.00000000011C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11C0000
|
Size: |
98304
|
|
120D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1223222360.000000000120D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
120D000
|
Size: |
8192
|
|
11EF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222917250.00000000011EF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11EF000
|
Size: |
118784
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470683653.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
7F40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3680089859.0000000007F40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7F40000
|
Size: |
4096
|
|
11BF000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1251071349.00000000011BF000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
11BF000
|
Size: |
16384
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575941525.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
136A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1301145865.000000000136A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
136A000
|
Size: |
8192
|
|
11EF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222039292.00000000011EF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11EF000
|
Size: |
118784
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1297333656.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573697475.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
B40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3675722057.0000000000B40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B40000
|
Size: |
16384
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575248069.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574054664.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
120D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222039292.000000000120D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
120D000
|
Size: |
12288
|
|
6E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3674945239.00000000006E0000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6E0000
|
Size: |
4096
|
|
2E40000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3676997514.0000000002E40000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2E40000
|
Size: |
4096
|
|
197E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1251234477.000000000197E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
197E000
|
Size: |
8192
|
|
6E1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000007.00000000.1300830188.00000000006E1000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
6E1000
|
Size: |
57344
|
|
7C93000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3679790336.0000000007C93000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C93000
|
Size: |
8192
|
|
3600000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1268719730.0000000003600000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3600000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2FC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3677283972.0000000002FC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FC0000
|
Size: |
12288
|
|
2EAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1301439384.0000000002EAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2EAE000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573966808.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
F30000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1300941620.0000000000F30000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F30000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573836715.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1288249420.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
626D000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1405459163.000000000626D000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
626D000
|
Size: |
3293184
|
|
3770000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1230522676.0000000003770000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3770000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574290257.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3720000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1228972224.0000000003720000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3720000
|
Size: |
1187840
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576068561.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574081802.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
307A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1404457173.000000000307A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
307A000
|
Size: |
24576
|
|
31C8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1404936671.00000000031C8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31C8000
|
Size: |
20480
|
|
1140000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1250975809.0000000001140000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1140000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572547736.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
69D2000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.00000000069D2000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
69D2000
|
Size: |
4096
|
|
31DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1404539896.00000000031DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
31DE000
|
Size: |
8192
|
|
7C77000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1585854152.0000000007C77000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C77000
|
Size: |
4096
|
|
1A30000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1301326656.0000000001A30000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A30000
|
Size: |
352256
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
399E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1271844661.000000000399E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
399E000
|
Size: |
24576
|
|
1237000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1219672912.0000000001237000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1237000
|
Size: |
131072
|
|
58D2000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.00000000058D2000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
58D2000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575625536.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
7FE5000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3681688673.0000000007FE5000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
7FE5000
|
Size: |
16384
|
|
31C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1404896681.00000000031C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31C7000
|
Size: |
24576
|
|
3E4F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1405374085.0000000003E4F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
3E4F000
|
Size: |
4096
|
|
1164000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1250989290.0000000001164000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1164000
|
Size: |
8192
|
|
38DD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3677649396.00000000038DD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
38DD000
|
Size: |
4096
|
|
6E1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000007.00000002.3675133937.00000000006E1000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
6E1000
|
Size: |
57344
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470780815.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575803479.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
31C3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1405016236.00000000031C3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31C3000
|
Size: |
20480
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576204065.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2FC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1301570239.0000000002FC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2FC0000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1469851560.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
6EF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3675227158.00000000006EF000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6EF000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1B00DD0D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1697502514.000001B00DD0D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B00DD0D000
|
Size: |
4096
|
|
7C70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3679790336.0000000007C70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C70000
|
Size: |
8192
|
|
47FE000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.00000000047FE000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
47FE000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
32B0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3677525874.00000000032B0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
32B0000
|
Size: |
94208
|
|
1B00DECE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1641061506.000001B00DECE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B00DECE000
|
Size: |
4096
|
|
4E46000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.0000000004E46000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4E46000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1B00D9F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639800821.000001B00D9F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B00D9F0000
|
Size: |
4096
|
|
1B00BFD3000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1696344462.000001B00BFD3000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
1B00BFD3000
|
Size: |
8192
|
|
39E9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229797992.00000000039E9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39E9000
|
Size: |
4096
|
|
7C8B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3679790336.0000000007C8B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C8B000
|
Size: |
4096
|
|
1B00BF30000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1696344462.000001B00BF30000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
1B00BF30000
|
Size: |
606208
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575873025.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3801000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1404839993.0000000003801000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3801000
|
Size: |
8192
|
|
373D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3677649396.000000000373D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
373D000
|
Size: |
458752
|
|
1236000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1251111331.0000000001236000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1236000
|
Size: |
581632
|
|
38E1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3677649396.00000000038E1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
38E1000
|
Size: |
458752
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1586329292.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573721825.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
31CD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1405044005.00000000031CD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31CD000
|
Size: |
20480
|
|
329B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1584637097.000000000329B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
329B000
|
Size: |
24576
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1577291329.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575780177.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
328D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.000000000328D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
328D000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574772697.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3CD1000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1404871036.0000000003CD1000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3CD1000
|
Size: |
458752
|
|
31CD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1404816400.00000000031CD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31CD000
|
Size: |
20480
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575711876.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
98B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3674958637.000000000098B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
98B000
|
Size: |
20480
|
|
7FF0000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3681854929.0000000007FF0000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF0000
|
Size: |
4096
|
|
1180000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1251017363.0000000001180000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1180000
|
Size: |
24576
|
|
33DD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1404599304.00000000033DD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
33DD000
|
Size: |
512000
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575404201.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470131591.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1273130660.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
196608
|
|
1B00DEC4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1641107794.000001B00DEC4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B00DEC4000
|
Size: |
24576
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575965265.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
3910000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1233535333.0000000003910000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3910000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1586258728.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
39E9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229336350.00000000039E9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39E9000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1419126340.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
229376
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576585340.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574928779.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2E50000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3677065494.0000000002E50000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2E50000
|
Size: |
12288
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573450322.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
E1E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1250904013.0000000000E1E000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
E1E000
|
Size: |
36864
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1469944223.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
6F9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1300902963.00000000006F9000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6F9000
|
Size: |
61440
|
|
1236000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1223222360.0000000001236000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1236000
|
Size: |
581632
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576460555.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
13E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1471315586.00000000013E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
13E0000
|
Size: |
24576
|
|
3AAE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1233535333.0000000003AAE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3AAE000
|
Size: |
4096
|
|
3150000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1417005814.0000000003150000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3150000
|
Size: |
167936
|
|
3489000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1351856103.0000000003489000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3489000
|
Size: |
16384
|
|
3893000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1231439011.0000000003893000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3893000
|
Size: |
507904
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
3287000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.0000000003287000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3287000
|
Size: |
8192
|
|
39ED000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229797992.00000000039ED000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39ED000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1469883888.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
E1E000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1219229051.0000000000E1E000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
E1E000
|
Size: |
8192
|
|
11BC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1251017363.00000000011BC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11BC000
|
Size: |
12288
|
|
C80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1250456979.0000000000C80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C80000
|
Size: |
4096
|
|
B0F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3675543461.0000000000B0F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
B0F000
|
Size: |
4096
|
|
3893000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1231009776.0000000003893000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3893000
|
Size: |
507904
|
|
FF0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3675718748.0000000000FF0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FF0000
|
Size: |
4096
|
|
3501000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1404669749.0000000003501000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3501000
|
Size: |
4096
|
|
3790000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1351795275.0000000003790000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3790000
|
Size: |
180224
|
|
FAA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3675591300.0000000000FAA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FAA000
|
Size: |
24576
|
|
61F8000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.00000000061F8000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
61F8000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573348697.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
36759FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1696201177.00000036759FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
36759FE000
|
Size: |
8192
|
|
12FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3675860815.00000000012FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12FC000
|
Size: |
16384
|
|
B44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1406805032.0000000000B44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B44000
|
Size: |
4096
|
|
36749FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1696008974.00000036749FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
36749FE000
|
Size: |
8192
|
|
36761FF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1696240877.00000036761FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
36761FF000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572976796.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
1310000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1301076124.0000000001310000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1310000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470602687.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470162438.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573132343.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575849348.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2E64000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1301392584.0000000002E64000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E64000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1586383972.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
31B7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.00000000031B7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31B7000
|
Size: |
16384
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573030952.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1571633354.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
4CB4000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.0000000004CB4000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4CB4000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574168224.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575030936.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
1B00DE01000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1697696049.000001B00DE01000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B00DE01000
|
Size: |
4096
|
|
3417000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1269200761.0000000003417000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3417000
|
Size: |
20480
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1293668502.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1293585424.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
1460000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1301210065.0000000001460000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1460000
|
Size: |
16384
|
|
548E000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.000000000548E000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
548E000
|
Size: |
8192
|
|
1236000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1219967091.0000000001236000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1236000
|
Size: |
581632
|
|
341A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1351722684.000000000341A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
341A000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
322C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.000000000322C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
322C000
|
Size: |
4096
|
|
325E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.000000000325E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
325E000
|
Size: |
12288
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575659945.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576133158.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
3740000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1404740697.0000000003740000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3740000
|
Size: |
274432
|
|
32BA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1404599304.00000000032BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32BA000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
39E9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1230254850.00000000039E9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39E9000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574721667.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
5812000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.0000000005812000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
5812000
|
Size: |
4096
|
|
7C8F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1585854152.0000000007C8F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C8F000
|
Size: |
8192
|
|
3720000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229633331.0000000003720000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3720000
|
Size: |
1187840
|
|
1B00DD21000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1697502514.000001B00DD21000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B00DD21000
|
Size: |
4096
|
|
3720000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1230065659.0000000003720000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3720000
|
Size: |
1187840
|
|
3A3D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1233535333.0000000003A3D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A3D000
|
Size: |
458752
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1288163187.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
E27000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1219290938.0000000000E27000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E27000
|
Size: |
405504
|
|
136E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3676254184.000000000136E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
136E000
|
Size: |
94208
|
|
3190000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1404520299.0000000003190000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3190000
|
Size: |
4096
|
|
7C68000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1584547010.0000000007C68000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C68000
|
Size: |
4096
|
|
3AC0000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3677471460.0000000003AC0000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
3AC0000
|
Size: |
10485760
|
|
343B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1351856103.000000000343B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
343B000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7C6B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3679790336.0000000007C6B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C6B000
|
Size: |
8192
|
|
16A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1301303496.00000000016A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
16A0000
|
Size: |
36864
|
|
BFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1250161163.0000000000BFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BFC000
|
Size: |
16384
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574239515.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574337645.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3412000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1404626407.0000000003412000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3412000
|
Size: |
24576
|
|
3AAE000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1230710015.0000000003AAE000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3AAE000
|
Size: |
24576
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1469914132.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
4024000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.0000000004024000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4024000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574029736.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576227067.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572067601.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
38C0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229797992.00000000038C0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38C0000
|
Size: |
1196032
|
|
7C89000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1585854152.0000000007C89000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C89000
|
Size: |
4096
|
|
31C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1405124700.00000000031C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31C7000
|
Size: |
24576
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572683640.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573475247.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
120F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222819569.000000000120F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
120F000
|
Size: |
131072
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575081969.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
7C73000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3679790336.0000000007C73000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C73000
|
Size: |
28672
|
|
136A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3676254184.000000000136A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
136A000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576533783.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
7C66000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3679790336.0000000007C66000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C66000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574510203.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470356319.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
D60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1218833721.0000000000D60000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
D60000
|
Size: |
4096
|
|
52FC000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.00000000052FC000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
52FC000
|
Size: |
4096
|
|
4850000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1405459163.0000000004850000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
4850000
|
Size: |
10485760
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576704552.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
1300000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1301057538.0000000001300000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1300000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576437514.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576271793.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
11C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222039292.00000000011C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11C0000
|
Size: |
172032
|
|
1480000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1301230366.0000000001480000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1480000
|
Size: |
20480
|
|
1206000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1219905444.0000000001206000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1206000
|
Size: |
778240
|
|
3405000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1269289997.0000000003405000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3405000
|
Size: |
49152
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574362678.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
5475000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3677471460.0000000005475000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
5475000
|
Size: |
4096
|
|
5ED4000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.0000000005ED4000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
5ED4000
|
Size: |
4096
|
|
1B00C070000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1696685116.000001B00C070000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B00C070000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1410560809.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
229376
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575736110.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1571716926.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573298665.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
3929000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1271844661.0000000003929000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3929000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576681357.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2DE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1404387078.0000000002DE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DE0000
|
Size: |
4096
|
|
1B00DD13000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1697502514.000001B00DD13000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B00DD13000
|
Size: |
20480
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575687015.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576750216.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
844F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3680142096.000000000844F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
844F000
|
Size: |
4096
|
|
31C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1405071275.00000000031C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31C7000
|
Size: |
24576
|
|
3610000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3677649396.0000000003610000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3610000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
31BE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1404965529.00000000031BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31BE000
|
Size: |
32768
|
|
BBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1250161163.0000000000BBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BBE000
|
Size: |
8192
|
|
3770000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1231009776.0000000003770000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3770000
|
Size: |
1187840
|
|
11EF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1251111331.00000000011EF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11EF000
|
Size: |
118784
|
|
169F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1301278931.000000000169F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
169F000
|
Size: |
4096
|
|
F40000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3675527211.0000000000F40000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F40000
|
Size: |
4096
|
|
B44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1410600157.0000000000B44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B44000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574262984.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576659571.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575602831.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1272915871.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
69632
|
|
3150000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1471110562.0000000003150000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3150000
|
Size: |
167936
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575112195.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
4FD8000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.0000000004FD8000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4FD8000
|
Size: |
8192
|
|
2E64000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3677148510.0000000002E64000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E64000
|
Size: |
4096
|
|
31C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1404965529.00000000031C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31C7000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1273249713.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
245760
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574996018.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
840E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3680114239.000000000840E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
840E000
|
Size: |
8192
|
|
37AE000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3677649396.00000000037AE000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
37AE000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
ACE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3675463629.0000000000ACE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
ACE000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575213168.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1419191655.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3597000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1406538532.0000000003597000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3597000
|
Size: |
458752
|
|
7F82000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3681688673.0000000007F82000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
7F82000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575362011.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576810598.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
E14000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1250863893.0000000000E14000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E14000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573999778.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572871258.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
36751FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1696058060.00000036751FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
36751FE000
|
Size: |
8192
|
|
A80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3675387170.0000000000A80000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
A80000
|
Size: |
4096
|
|
7F8E000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3681688673.0000000007F8E000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
7F8E000
|
Size: |
8192
|
|
44C0000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3677471460.00000000044C0000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
44C0000
|
Size: |
10485760
|
|
3A7C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.0000000003A7C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3A7C000
|
Size: |
8192
|
|
1B00C220000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1696932388.000001B00C220000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B00C220000
|
Size: |
36864
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470241396.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
11C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1223222360.00000000011C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11C7000
|
Size: |
65536
|
|
3962000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.0000000003962000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3962000
|
Size: |
4096
|
|
7D40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3680041469.0000000007D40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D40000
|
Size: |
4096
|
|
30A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676105235.00000000030A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
30A0000
|
Size: |
94208
|
|
6B64000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.0000000006B64000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
6B64000
|
Size: |
8192
|
|
1320000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1301094959.0000000001320000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1320000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1419520551.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
9C8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3675158238.00000000009C8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9C8000
|
Size: |
32768
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572939039.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
36741FC000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1694226998.00000036741FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
36741FC000
|
Size: |
16384
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573791221.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1293885023.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
245760
|
|
1020000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1250957275.0000000001020000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1020000
|
Size: |
20480
|
|
1B00C23B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1696932388.000001B00C23B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B00C23B000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572803355.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572185325.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576249348.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
7C61000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1584547010.0000000007C61000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C61000
|
Size: |
4096
|
|
3739000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3677649396.0000000003739000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3739000
|
Size: |
4096
|
|
38C0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229336350.00000000038C0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38C0000
|
Size: |
1196032
|
|
3236000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.0000000003236000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3236000
|
Size: |
12288
|
|
11B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1219719590.00000000011B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11B3000
|
Size: |
540672
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576611400.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
7C7E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1585854152.0000000007C7E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C7E000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470634121.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572482295.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1288346366.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
7C56000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1584547010.0000000007C56000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C56000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470404555.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1586412605.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
6F9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3675327479.00000000006F9000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6F9000
|
Size: |
61440
|
|
11CE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1220299924.00000000011CE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11CE000
|
Size: |
221184
|
|
D60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1250708331.0000000000D60000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
D60000
|
Size: |
4096
|
|
6F6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1300885716.00000000006F6000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6F6000
|
Size: |
8192
|
|
3080000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1404478124.0000000003080000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3080000
|
Size: |
4096
|
|
1360000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1301145865.0000000001360000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1360000
|
Size: |
32768
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1297517831.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
120D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222161991.000000000120D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
120D000
|
Size: |
12288
|
|
392D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1271844661.000000000392D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
392D000
|
Size: |
458752
|
|
2FD0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1301594115.0000000002FD0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2FD0000
|
Size: |
925696
|
|
1340000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3676189315.0000000001340000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1340000
|
Size: |
4096
|
|
BDB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1250161163.0000000000BDB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BDB000
|
Size: |
20480
|
|
CB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1250586404.0000000000CB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
CB0000
|
Size: |
8192
|
|
36D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1251263561.00000000036D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
36D0000
|
Size: |
290816
|
|
644D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3679739130.000000000644D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
644D000
|
Size: |
12288
|
|
F40000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1300959768.0000000000F40000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F40000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1410698198.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3243000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.0000000003243000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3243000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
SQL strings found in memory and binary data |
System Summary |
|
|
11B4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1219967091.00000000011B4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11B4000
|
Size: |
335872
|
|
1300000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3675950119.0000000001300000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1300000
|
Size: |
4096
|
|
4BA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1249963339.00000000004BA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4BA000
|
Size: |
24576
|
|
31BE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.00000000031BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31BE000
|
Size: |
94208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
31C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1404838079.00000000031C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31C7000
|
Size: |
24576
|
|
F20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3675391825.0000000000F20000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F20000
|
Size: |
4096
|
|
3790000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1293488064.0000000003790000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3790000
|
Size: |
180224
|
|
11A4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1219813134.00000000011A4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11A4000
|
Size: |
49152
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1586298510.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3893000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1230522676.0000000003893000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3893000
|
Size: |
507904
|
|
3263000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.0000000003263000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3263000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574884821.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1297421335.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
1384000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000003.1471315586.0000000001384000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1384000
|
Size: |
114688
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3910000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1230710015.0000000003910000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3910000
|
Size: |
1196032
|
|
1320000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3676074588.0000000001320000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1320000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470291524.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3800000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1271844661.0000000003800000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3800000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572510404.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470747591.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
BF82000
|
system
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1689216523.000000000BF82000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
BF82000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574457021.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575895616.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575542969.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3292000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.0000000003292000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3292000
|
Size: |
12288
|
|
4348000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.0000000004348000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4348000
|
Size: |
8192
|
|
1B00C210000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1696932388.000001B00C210000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B00C210000
|
Size: |
36864
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470716341.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572142853.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
1188000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1251017363.0000000001188000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1188000
|
Size: |
180224
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470003972.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574855651.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576294538.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574960901.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3CCD000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1404871036.0000000003CCD000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3CCD000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572240923.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
FF0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1301013622.0000000000FF0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FF0000
|
Size: |
4096
|
|
1D7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1251246804.0000000001D7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1D7E000
|
Size: |
8192
|
|
3B29000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1404871036.0000000003B29000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3B29000
|
Size: |
4096
|
|
11C6000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1251071349.00000000011C6000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
11C6000
|
Size: |
4096
|
|
7C42000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1577199348.0000000007C42000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C42000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3C3C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.0000000003C3C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
3C3C000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1297660712.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
245760
|
|
1B00C242000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1696932388.000001B00C242000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B00C242000
|
Size: |
32768
|
|
66AE000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.00000000066AE000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
66AE000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575287512.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
7C7C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1585854152.0000000007C7C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C7C000
|
Size: |
4096
|
|
31DC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.00000000031DC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31DC000
|
Size: |
204800
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575136000.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576017048.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
1B00D9F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1639847620.000001B00D9F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B00D9F0000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573179914.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576510602.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575825973.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575990914.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
6840000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.0000000006840000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
6840000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
804C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3681874373.000000000804C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
804C000
|
Size: |
16384
|
|
1B00D9F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1640418068.000001B00D9F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B00D9F0000
|
Size: |
4096
|
|
7F72000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3681688673.0000000007F72000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
7F72000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3266000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.0000000003266000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3266000
|
Size: |
4096
|
|
1331000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3676140414.0000000001331000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1331000
|
Size: |
12288
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574413154.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572092500.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
30C0000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3677471460.00000000030C0000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
30C0000
|
Size: |
10485760
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574575178.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
814C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3681896831.000000000814C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
814C000
|
Size: |
16384
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573272812.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470324357.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
1460000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3676576588.0000000001460000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1460000
|
Size: |
16384
|
|
1340000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1301126042.0000000001340000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1340000
|
Size: |
4096
|
|
6066000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.0000000006066000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
6066000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1404598987.0000000003400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3400000
|
Size: |
45056
|
|
1B00C22C000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1696932388.000001B00C22C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B00C22C000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572826178.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
12FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1301031695.00000000012FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
12FC000
|
Size: |
16384
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576317587.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2E60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1301392584.0000000002E60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E60000
|
Size: |
8192
|
|
6E88000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.0000000006E88000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
6E88000
|
Size: |
8192
|
|
3202000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1404561085.0000000003202000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3202000
|
Size: |
20480
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572916344.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
4B22000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.0000000004B22000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4B22000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470436152.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3214000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.0000000003214000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3214000
|
Size: |
4096
|
|
3B2D000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1404871036.0000000003B2D000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3B2D000
|
Size: |
458752
|
|
54DD000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3677471460.00000000054DD000.00000040.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
54DD000
|
Size: |
3293184
|
|
3E50000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1405459163.0000000003E50000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
3E50000
|
Size: |
10485760
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470200246.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
1B00DC00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1697388222.000001B00DC00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B00DC00000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572736675.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
322F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.000000000322F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
322F000
|
Size: |
16384
|
|
159E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3676758369.000000000159E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
159E000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572627441.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573500452.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
31A0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1287548693.00000000031A0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
31A0000
|
Size: |
180224
|
|
373F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1404713458.000000000373F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
373F000
|
Size: |
4096
|
|
325C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.000000000325C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
325C000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576727074.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576387848.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573247302.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576486686.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
346A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1406538532.000000000346A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
346A000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7D50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3680066367.0000000007D50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7D50000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574388267.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3723000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1268719730.0000000003723000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3723000
|
Size: |
507904
|
|
11DB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222917250.00000000011DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11DB000
|
Size: |
61440
|
|
3A39000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1230710015.0000000003A39000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A39000
|
Size: |
4096
|
|
3D42000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1404871036.0000000003D42000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3D42000
|
Size: |
40960
|
|
1236000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222819569.0000000001236000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1236000
|
Size: |
581632
|
|
BEC2000
|
system
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1689216523.000000000BEC2000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
BEC2000
|
Size: |
4096
|
|
7C8E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3679790336.0000000007C8E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C8E000
|
Size: |
8192
|
|
3419000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1404626407.0000000003419000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3419000
|
Size: |
4096
|
|
12CA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1223175264.00000000012CA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12CA000
|
Size: |
335872
|
|
3259000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.0000000003259000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3259000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573650395.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1288453986.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
245760
|
|
41B6000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.00000000041B6000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
41B6000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576157421.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
6190000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3679639621.0000000006190000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6190000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
FE0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3675663277.0000000000FE0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FE0000
|
Size: |
4096
|
|
1236000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1223352658.0000000001236000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1236000
|
Size: |
581632
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572713642.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
7C50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3679790336.0000000007C50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C50000
|
Size: |
24576
|
|
733E000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.000000000733E000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
733E000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572781248.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
31BC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1405071275.00000000031BC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31BC000
|
Size: |
24576
|
|
1B00DEBE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000003.1641107794.000001B00DEBE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B00DEBE000
|
Size: |
8192
|
|
2E40000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1301374411.0000000002E40000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2E40000
|
Size: |
4096
|
|
1399000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3676254184.0000000001399000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1399000
|
Size: |
28672
|
|
303C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1404438660.000000000303C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
303C000
|
Size: |
16384
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573572893.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
3843000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1230065659.0000000003843000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3843000
|
Size: |
507904
|
|
3A5E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229336350.0000000003A5E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A5E000
|
Size: |
24576
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572209064.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470569096.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573813138.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
C19C000
|
system
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1689216523.000000000C19C000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
C19C000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1B00DBA0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1697347811.000001B00DBA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B00DBA0000
|
Size: |
12288
|
|
3A39000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1231143626.0000000003A39000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A39000
|
Size: |
4096
|
|
3150000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1414250615.0000000003150000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3150000
|
Size: |
167936
|
|
3405000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1269164511.0000000003405000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3405000
|
Size: |
49152
|
|
6205000
|
unclassified section
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1405459163.0000000006205000.00000040.10000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page execute and read and write
|
Base address: |
6205000
|
Size: |
4096
|
|
1B00BFD0000
|
system
|
page execute and read and write
|
|
|
|
Name: |
0000000A.00000002.1696344462.000001B00BFD0000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
1B00BFD0000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1577427691.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
7C6E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1584547010.0000000007C6E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C6E000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
16A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3676860531.00000000016A0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
16A0000
|
Size: |
36864
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470043045.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
648E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3679764897.000000000648E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
648E000
|
Size: |
8192
|
|
3222000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.0000000003222000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3222000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572659177.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573373942.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
520000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1250138924.0000000000520000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
520000
|
Size: |
4096
|
|
516A000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.000000000516A000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
516A000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576558931.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1586356807.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573202410.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572848654.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
30B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1404503711.00000000030B0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
30B0000
|
Size: |
4096
|
|
1485000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3676634726.0000000001485000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1485000
|
Size: |
12288
|
|
320F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.000000000320F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
320F000
|
Size: |
16384
|
|
71AC000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.00000000071AC000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
71AC000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573082230.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
131B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1251219889.000000000131B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
131B000
|
Size: |
4096
|
|
3843000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1228972224.0000000003843000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3843000
|
Size: |
507904
|
|
1B00DD0F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1697502514.000001B00DD0F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B00DD0F000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572758927.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
1B00C23F000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1696932388.000001B00C23F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B00C23F000
|
Size: |
4096
|
|
1480000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3676634726.0000000001480000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1480000
|
Size: |
16384
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573941006.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3417000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1269324422.0000000003417000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3417000
|
Size: |
20480
|
|
3843000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229633331.0000000003843000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3843000
|
Size: |
507904
|
|
651C000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.000000000651C000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
651C000
|
Size: |
8192
|
|
11EF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1223222360.00000000011EF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11EF000
|
Size: |
118784
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573916573.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470467408.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
1B00C21A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1696932388.000001B00C21A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B00C21A000
|
Size: |
20480
|
|
DEF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1250863893.0000000000DEF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
DEF000
|
Size: |
147456
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576636889.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573225064.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
1360000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3676254184.0000000001360000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1360000
|
Size: |
32768
|
|
E27000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1250920262.0000000000E27000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E27000
|
Size: |
405504
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575174102.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3A39000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1233535333.0000000003A39000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A39000
|
Size: |
4096
|
|
6EF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1300862792.00000000006EF000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
6EF000
|
Size: |
28672
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574659220.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
324D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.000000000324D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
324D000
|
Size: |
12288
|
|
39ED000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1230254850.00000000039ED000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39ED000
|
Size: |
458752
|
|
701A000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.000000000701A000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
701A000
|
Size: |
4096
|
|
3A3D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1231143626.0000000003A3D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A3D000
|
Size: |
458752
|
|
BCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1250161163.0000000000BCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BCE000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1469973907.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
7F91000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3681688673.0000000007F91000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
7F91000
|
Size: |
4096
|
|
FAA000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1300978803.0000000000FAA000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
FAA000
|
Size: |
24576
|
|
E14000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1218920212.0000000000E14000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
E14000
|
Size: |
40960
|
|
1160000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1250989290.0000000001160000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1160000
|
Size: |
8192
|
|
6CF6000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.0000000006CF6000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
6CF6000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576094075.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
FE0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1300995188.0000000000FE0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
FE0000
|
Size: |
4096
|
|
2E60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3677148510.0000000002E60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2E60000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572121060.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
592C000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.000000000592C000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
592C000
|
Size: |
8192
|
|
3A00000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1404871036.0000000003A00000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3A00000
|
Size: |
1208320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1331000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1301111214.0000000001331000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1331000
|
Size: |
12288
|
|
1310000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3676018034.0000000001310000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1310000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572596510.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573157177.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
5AEC000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.0000000005AEC000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
5AEC000
|
Size: |
53248
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3608000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1406538532.0000000003608000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3608000
|
Size: |
24576
|
|
169F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3676816320.000000000169F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
169F000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1406778232.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
65536
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1273040092.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
135168
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572037288.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
1B00DD00000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1697469445.000001B00DD00000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B00DD00000
|
Size: |
4096
|
|
2FD0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3677318011.0000000002FD0000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
2FD0000
|
Size: |
925696
|
|
3910000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1231143626.0000000003910000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3910000
|
Size: |
1196032
|
|
3790000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1297246548.0000000003790000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3790000
|
Size: |
180224
|
|
3270000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.0000000003270000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3270000
|
Size: |
61440
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573548940.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3213000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000003.1293758718.0000000003213000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3213000
|
Size: |
200704
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576340609.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
F30000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3675442328.0000000000F30000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F30000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1571600220.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
7C5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1584547010.0000000007C5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C5C000
|
Size: |
4096
|
|
120E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222211443.000000000120E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
120E000
|
Size: |
8192
|
|
1A31000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000002.3676909128.0000000001A31000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A31000
|
Size: |
348160
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470844668.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576413711.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
7C73000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1584547010.0000000007C73000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C73000
|
Size: |
4096
|
|
C7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1250407567.0000000000C7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C7E000
|
Size: |
8192
|
|
4990000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.0000000004990000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
4990000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572893463.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
39ED000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229336350.00000000039ED000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39ED000
|
Size: |
458752
|
|
F20000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000007.00000000.1300925084.0000000000F20000.00000002.00000001.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F20000
|
Size: |
4096
|
|
11B3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1219813134.00000000011B3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11B3000
|
Size: |
540672
|
|
1256000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1219783663.0000000001256000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1256000
|
Size: |
4096
|
|
3A5E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1230254850.0000000003A5E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A5E000
|
Size: |
24576
|
|
31B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.00000000031B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31B0000
|
Size: |
24576
|
|
31BC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1404838079.00000000031BC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31BC000
|
Size: |
24576
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574313756.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573890617.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
11EF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222161991.00000000011EF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11EF000
|
Size: |
118784
|
|
B10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3675607355.0000000000B10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B10000
|
Size: |
4096
|
|
D61000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1218863967.0000000000D61000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
D61000
|
Size: |
581632
|
|
1389000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3676254184.0000000001389000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1389000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
3A3D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1230710015.0000000003A3D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A3D000
|
Size: |
458752
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1571492723.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
DEF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1218920212.0000000000DEF000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
DEF000
|
Size: |
147456
|
|
120E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1223352658.000000000120E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
120E000
|
Size: |
4096
|
|
1B00DD03000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1697502514.000001B00DD03000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1B00DD03000
|
Size: |
16384
|
|
159E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1301251885.000000000159E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
159E000
|
Size: |
8192
|
|
E22000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1219229051.0000000000E22000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
E22000
|
Size: |
8192
|
|
44DA000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.00000000044DA000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
44DA000
|
Size: |
4096
|
|
3770000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1231439011.0000000003770000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3770000
|
Size: |
1187840
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1572164005.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
6F6000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3675283868.00000000006F6000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6F6000
|
Size: |
8192
|
|
3297000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.0000000003297000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3297000
|
Size: |
28672
|
|
638A000
|
system
|
page read and write
|
|
|
|
Name: |
00000007.00000002.3680411287.000000000638A000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
638A000
|
Size: |
4096
|
|
7F68000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000007.00000002.3681688673.0000000007F68000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
7F68000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573056689.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573107049.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
120D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1222917250.000000000120D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
120D000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573004030.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1470080464.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2FAF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1301465310.0000000002FAF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2FAF000
|
Size: |
4096
|
|
136E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000007.00000000.1301145865.000000000136E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
7
|
Dumpstage: |
process new
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
136E000
|
Size: |
90112
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574605563.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
31A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676198889.00000000031A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31A0000
|
Size: |
16384
|
|
1B00C160000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1696723122.000001B00C160000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1B00C160000
|
Size: |
8192
|
|
3000000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1410097823.0000000003000000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3000000
|
Size: |
172032
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576181338.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573425371.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
7C89000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3679790336.0000000007C89000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7C89000
|
Size: |
4096
|
|
31C7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1405151523.00000000031C7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
31C7000
|
Size: |
24576
|
|
C3E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1250380664.0000000000C3E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
C3E000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575918418.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
3A5E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1229797992.0000000003A5E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A5E000
|
Size: |
24576
|
|
3952000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.3677649396.0000000003952000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3952000
|
Size: |
40960
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1469813088.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573768820.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
3B9E000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.1404871036.0000000003B9E000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
3B9E000
|
Size: |
1220608
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574193137.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574809889.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
B44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1410629628.0000000000B44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
B44000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573744848.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
12C5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1251204698.00000000012C5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12C5000
|
Size: |
20480
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575468900.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573524687.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
466C000
|
unclassified section
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3678084173.000000000466C000.00000004.10000000.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
unclassified section
|
Protect: |
page read and write
|
Base address: |
466C000
|
Size: |
8192
|
|
32A4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3676253646.00000000032A4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
32A4000
|
Size: |
16384
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574215783.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1574690007.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
38C0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1230254850.00000000038C0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38C0000
|
Size: |
1196032
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1571565380.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
BFDC000
|
system
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1689216523.000000000BFDC000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
BFDC000
|
Size: |
4096
|
|
C584000
|
system
|
page read and write
|
|
|
|
Name: |
0000000A.00000002.1689216523.000000000C584000.00000004.80000000.00040000.00000000.sdmp
|
TargetID: |
10
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page read and write
|
Base address: |
C584000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1576042998.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1575568513.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
4096
|
|
2D00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.3675809197.0000000002D00000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D00000
|
Size: |
4096
|
|
2D01000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000003.1573399717.0000000002D01000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D01000
|
Size: |
8192
|
|
363E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.1404690748.000000000363E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
363E000
|
Size: |
8192
|
|