29DF000
|
heap
|
page read and write
|
 |
|
|
Name: |
00000001.00000002.3627265809.00000000029DF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
29DF000
|
Size: |
598016
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected AgentTesla |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected PureLog Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3DC1000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000001.00000002.3629495623.0000000003DC1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3DC1000
|
Size: |
684032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected AgentTesla |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected PureLog Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
54D0000
|
trusted library section
|
page read and write
|
 |
|
|
Name: |
00000001.00000002.3630635978.00000000054D0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
54D0000
|
Size: |
327680
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected AgentTesla |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected PureLog Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
52D0000
|
trusted library section
|
page read and write
|
 |
|
|
Name: |
00000001.00000002.3630306285.00000000052D0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
52D0000
|
Size: |
323584
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara detected AgentTesla |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected PureLog Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
Yara signature match |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
2E14000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000001.00000002.3627872448.0000000002E14000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E14000
|
Size: |
327680
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected AgentTesla |
Stealing of Sensitive Information, Remote Access Functionality |
|
Yara detected Credential Stealer |
Stealing of Sensitive Information |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
URLs found in memory or binary data |
Networking |
|
|
12EB000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.1308840519.00000000012EB000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
12EB000
|
Size: |
4096
|
|
15C7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1390503748.00000000015C7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
15C7000
|
Size: |
4096
|
|
F5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178272031.0000000000F5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F5C000
|
Size: |
450560
|
|
5212000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3629919297.0000000005212000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5212000
|
Size: |
36864
|
|
E90000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3625944629.0000000000E90000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
E90000
|
Size: |
4096
|
|
15F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390541913.00000000015F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
15F0000
|
Size: |
12288
|
|
38D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1185399242.00000000038D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38D0000
|
Size: |
1187840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
156E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390251397.000000000156E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
156E000
|
Size: |
8192
|
|
FCF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626913351.0000000000FCF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FCF000
|
Size: |
327680
|
|
D4B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3625675297.0000000000D4B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D4B000
|
Size: |
20480
|
|
39F9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1185117209.00000000039F9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39F9000
|
Size: |
4096
|
|
F0B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3626841628.0000000000F0B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
F0B000
|
Size: |
4096
|
|
F48000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178272031.0000000000F48000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F48000
|
Size: |
57344
|
|
6810000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631787900.0000000006810000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6810000
|
Size: |
65536
|
|
F02000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626736320.0000000000F02000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
F02000
|
Size: |
4096
|
|
99A000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3625510975.000000000099A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
99A000
|
Size: |
24576
|
|
725D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632654102.000000000725D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
725D000
|
Size: |
12288
|
|
2C70000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3627652836.0000000002C70000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2C70000
|
Size: |
4096
|
|
1195000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308603341.0000000001195000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1195000
|
Size: |
12288
|
|
7117000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632558102.0000000007117000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7117000
|
Size: |
32768
|
|
F23000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178385259.0000000000F23000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F23000
|
Size: |
118784
|
|
1350000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390193266.0000000001350000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1350000
|
Size: |
16384
|
|
33C0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1184602450.00000000033C0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33C0000
|
Size: |
1187840
|
|
6BE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632275982.0000000006BE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6BE0000
|
Size: |
65536
|
|
1AAE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1195029692.0000000001AAE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
1AAE000
|
Size: |
8192
|
|
E7C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308054811.0000000000E7C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E7C000
|
Size: |
16384
|
|
591E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631230163.000000000591E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
591E000
|
Size: |
8192
|
|
2D3C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309107955.0000000002D3C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2D3C000
|
Size: |
16384
|
|
5920000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631254258.0000000005920000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5920000
|
Size: |
12288
|
|
4091000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390739173.0000000004091000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4091000
|
Size: |
12288
|
|
56FE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390834203.00000000056FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
56FE000
|
Size: |
8192
|
|
2D60000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.1309143228.0000000002D60000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2D60000
|
Size: |
4096
|
|
5AB0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3631370858.0000000005AB0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5AB0000
|
Size: |
65536
|
|
F7F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626913351.0000000000F7F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F7F000
|
Size: |
16384
|
|
70CC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632437501.00000000070CC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
70CC000
|
Size: |
16384
|
|
BCF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194306716.0000000000BCF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BCF000
|
Size: |
4096
|
|
168C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390582521.000000000168C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
168C000
|
Size: |
16384
|
|
3E6F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3629495623.0000000003E6F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E6F000
|
Size: |
4096
|
|
2DC1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627872448.0000000002DC1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DC1000
|
Size: |
225280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
53C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3630534692.00000000053C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53C0000
|
Size: |
49152
|
|
BEA000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000008.00000000.1305321677.0000000000BEA000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BEA000
|
Size: |
4096
|
|
1A4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1192685281.00000000001A4000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A4000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary is likely a compiled AutoIt script file |
System Summary |
|
|
3B99000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1186031238.0000000003B99000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B99000
|
Size: |
4096
|
|
F1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.1192621564.00000000000F1000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
F1000
|
Size: |
581632
|
|
EB8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194731056.0000000000EB8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EB8000
|
Size: |
176128
|
|
1AE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1192746101.00000000001AE000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
1AE000
|
Size: |
36864
|
|
1640000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1390569615.0000000001640000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
1640000
|
Size: |
4096
|
|
4EBD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3629884300.0000000004EBD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4EBD000
|
Size: |
12288
|
|
6CEC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632343740.0000000006CEC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6CEC000
|
Size: |
122880
|
|
F7C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1173507210.0000000000F7C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F7C000
|
Size: |
4096
|
|
11E0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1389801228.00000000011E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11E0000
|
Size: |
4096
|
|
130E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308861298.000000000130E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
130E000
|
Size: |
8192
|
|
3A70000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1186031238.0000000003A70000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A70000
|
Size: |
1196032
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
F5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178169147.0000000000F5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F5C000
|
Size: |
450560
|
|
12F8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308861298.00000000012F8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12F8000
|
Size: |
86016
|
|
62FB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631469871.00000000062FB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
62FB000
|
Size: |
20480
|
|
67E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631627814.00000000067E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
67E0000
|
Size: |
24576
|
|
567E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390804613.000000000567E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
567E000
|
Size: |
8192
|
|
1230000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1389819458.0000000001230000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1230000
|
Size: |
8192
|
|
F5D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1173372447.0000000000F5D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F5D000
|
Size: |
131072
|
|
53BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3630492485.00000000053BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
53BE000
|
Size: |
8192
|
|
6826000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631826954.0000000006826000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6826000
|
Size: |
40960
|
|
F5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1191177321.0000000000F5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F5C000
|
Size: |
450560
|
|
2BC8000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627598080.0000000002BC8000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BC8000
|
Size: |
8192
|
|
116A000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1389720667.000000000116A000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
116A000
|
Size: |
24576
|
|
535C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3630429535.000000000535C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
535C000
|
Size: |
16384
|
|
1AE000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1172790605.00000000001AE000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
1AE000
|
Size: |
8192
|
|
3584000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1195104410.0000000003584000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3584000
|
Size: |
8192
|
|
CF8000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3625563849.0000000000CF8000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CF8000
|
Size: |
32768
|
|
D60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194657021.0000000000D60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D60000
|
Size: |
4096
|
|
6804000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631730402.0000000006804000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6804000
|
Size: |
36864
|
|
EE2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1173555771.0000000000EE2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EE2000
|
Size: |
503808
|
|
BDB000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194306716.0000000000BDB000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BDB000
|
Size: |
20480
|
|
F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1172687166.00000000000F0000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F0000
|
Size: |
4096
|
|
70E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632491415.00000000070E0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70E0000
|
Size: |
8192
|
|
1218000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1389819458.0000000001218000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1218000
|
Size: |
94208
|
|
7260000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632679125.0000000007260000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7260000
|
Size: |
5242880
|
|
66BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631573652.00000000066BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
66BE000
|
Size: |
8192
|
|
F4F000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1194863426.0000000000F4F000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
F4F000
|
Size: |
16384
|
|
15A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390365446.00000000015A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
15A0000
|
Size: |
8192
|
|
2B10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627467209.0000000002B10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B10000
|
Size: |
12288
|
|
15E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390529422.00000000015E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
15E0000
|
Size: |
4096
|
|
129F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308652170.000000000129F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
129F000
|
Size: |
4096
|
|
55CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309418214.00000000055CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
55CE000
|
Size: |
8192
|
|
3EC7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3629495623.0000000003EC7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3EC7000
|
Size: |
8192
|
|
15CB000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1390516795.00000000015CB000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
15CB000
|
Size: |
4096
|
|
EF6000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3626666104.0000000000EF6000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
EF6000
|
Size: |
8192
|
|
3080000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390708222.0000000003080000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3080000
|
Size: |
4096
|
|
EF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178341017.0000000000EF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EF0000
|
Size: |
114688
|
|
2E10000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627872448.0000000002E10000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E10000
|
Size: |
4096
|
|
EE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626427728.0000000000EE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
EE0000
|
Size: |
8192
|
|
EE6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194731056.0000000000EE6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EE6000
|
Size: |
40960
|
|
2C80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627707471.0000000002C80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2C80000
|
Size: |
4096
|
|
5200000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3629919297.0000000005200000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5200000
|
Size: |
32768
|
|
12B3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.1308687456.00000000012B3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
12B3000
|
Size: |
4096
|
|
6BD0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3632233586.0000000006BD0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6BD0000
|
Size: |
65536
|
|
12E7000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.1308822272.00000000012E7000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
12E7000
|
Size: |
4096
|
|
2DFA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627872448.0000000002DFA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2DFA000
|
Size: |
24576
|
|
2CB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627771917.0000000002CB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CB0000
|
Size: |
16384
|
|
571C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3630793113.000000000571C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
571C000
|
Size: |
16384
|
|
E7C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3625884863.0000000000E7C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
E7C000
|
Size: |
16384
|
|
62BC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631444181.00000000062BC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
62BC000
|
Size: |
16384
|
|
8160000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3634929946.0000000008160000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8160000
|
Size: |
4096
|
|
1248000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1389819458.0000000001248000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1248000
|
Size: |
262144
|
|
2AD0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627358772.0000000002AD0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AD0000
|
Size: |
4096
|
|
12A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308671427.00000000012A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
12A0000
|
Size: |
4096
|
|
5360000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.1309270443.0000000005360000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5360000
|
Size: |
8192
|
|
F23000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178169147.0000000000F23000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F23000
|
Size: |
118784
|
|
67F0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3631687908.00000000067F0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
67F0000
|
Size: |
65536
|
|
7FD20000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3635255124.000000007FD20000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
7FD20000
|
Size: |
4096
|
|
522E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390759081.000000000522E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
522E000
|
Size: |
8192
|
|
691E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631983535.000000000691E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
691E000
|
Size: |
8192
|
|
39F3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1185399242.00000000039F3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39F3000
|
Size: |
507904
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
DA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194678249.0000000000DA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
DA0000
|
Size: |
24576
|
|
F85000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626913351.0000000000F85000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F85000
|
Size: |
176128
|
|
3B9D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1185555952.0000000003B9D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B9D000
|
Size: |
458752
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
|
6C3C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632314987.0000000006C3C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6C3C000
|
Size: |
16384
|
|
61BC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631415596.00000000061BC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
61BC000
|
Size: |
16384
|
|
3B99000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1185555952.0000000003B99000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B99000
|
Size: |
4096
|
|
1B7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1192784929.00000000001B7000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1B7000
|
Size: |
385024
|
|
1100000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308207736.0000000001100000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1100000
|
Size: |
4096
|
|
BE2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000008.00000000.1305301535.0000000000BE2000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BE2000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
F57000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1191177321.0000000000F57000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F57000
|
Size: |
12288
|
|
38D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1184347511.00000000038D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38D0000
|
Size: |
1196032
|
|
15A4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390393699.00000000015A4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
15A4000
|
Size: |
24576
|
|
56BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390819430.00000000056BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
56BE000
|
Size: |
8192
|
|
BFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194306716.0000000000BFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BFC000
|
Size: |
16384
|
|
3091000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390721297.0000000003091000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3091000
|
Size: |
53248
|
|
573C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3630833563.000000000573C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
573C000
|
Size: |
4096
|
|
57EF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3630908451.00000000057EF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57EF000
|
Size: |
196608
|
|
BBF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194306716.0000000000BBF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BBF000
|
Size: |
4096
|
|
38D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1186369174.00000000038D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38D0000
|
Size: |
1187840
|
|
EF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1174139345.0000000000EF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EF0000
|
Size: |
184320
|
|
F5D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626913351.0000000000F5D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F5D000
|
Size: |
135168
|
|
E30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3625832070.0000000000E30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E30000
|
Size: |
8192
|
|
EF2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626615393.0000000000EF2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
EF2000
|
Size: |
4096
|
|
522D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3629919297.000000000522D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
522D000
|
Size: |
16384
|
|
F23000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194798938.0000000000F23000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F23000
|
Size: |
118784
|
|
6840000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3631928901.0000000006840000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6840000
|
Size: |
4096
|
|
C00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194581954.0000000000C00000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
C00000
|
Size: |
4096
|
|
3A6E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1184729361.0000000003A6E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A6E000
|
Size: |
24576
|
|
5226000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3629919297.0000000005226000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5226000
|
Size: |
16384
|
|
111C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627211204.000000000111C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
111C000
|
Size: |
16384
|
|
10FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308176829.00000000010FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
10FE000
|
Size: |
8192
|
|
D00000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3625623972.0000000000D00000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D00000
|
Size: |
4096
|
|
6820000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631826954.0000000006820000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6820000
|
Size: |
20480
|
|
1B2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1172790605.00000000001B2000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
1B2000
|
Size: |
8192
|
|
560E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309436849.000000000560E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
560E000
|
Size: |
8192
|
|
D1D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194609356.0000000000D1D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D1D000
|
Size: |
12288
|
|
6B1C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632124886.0000000006B1C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6B1C000
|
Size: |
16384
|
|
38D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1185117209.00000000038D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38D0000
|
Size: |
1196032
|
|
EAB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3625987097.0000000000EAB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EAB000
|
Size: |
12288
|
|
2E67000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627872448.0000000002E67000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E67000
|
Size: |
729088
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
12B4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308703703.00000000012B4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
12B4000
|
Size: |
4096
|
|
426000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3625204702.0000000000426000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
426000
|
Size: |
4096
|
|
5610000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1390790321.0000000005610000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5610000
|
Size: |
8192
|
|
12E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308804757.00000000012E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
12E0000
|
Size: |
4096
|
|
599000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1193548340.0000000000599000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
599000
|
Size: |
28672
|
|
2B5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627494934.0000000002B5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B5E000
|
Size: |
8192
|
|
5570000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390772348.0000000005570000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5570000
|
Size: |
49152
|
|
5720000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3630833563.0000000005720000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5720000
|
Size: |
4096
|
|
2BB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627571693.0000000002BB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2BB0000
|
Size: |
4096
|
|
2BA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627542615.0000000002BA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2BA0000
|
Size: |
65536
|
|
2B9C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627520248.0000000002B9C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B9C000
|
Size: |
16384
|
|
EFD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178385259.0000000000EFD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EFD000
|
Size: |
61440
|
|
67BE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631601363.00000000067BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
67BE000
|
Size: |
8192
|
|
101F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194985270.000000000101F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
101F000
|
Size: |
4096
|
|
3580000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1195104410.0000000003580000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3580000
|
Size: |
8192
|
|
2D40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309126303.0000000002D40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D40000
|
Size: |
4096
|
|
520B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3629919297.000000000520B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
520B000
|
Size: |
8192
|
|
657D000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631522748.000000000657D000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
657D000
|
Size: |
12288
|
|
2E03000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627872448.0000000002E03000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E03000
|
Size: |
8192
|
|
52C0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3630277266.00000000052C0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
52C0000
|
Size: |
20480
|
|
1BA0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1195048008.0000000001BA0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
1BA0000
|
Size: |
274432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Sample file is different than original file name gathered from version info |
System Summary |
|
Yara signature match |
System Summary |
|
|
585E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390859397.000000000585E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
585E000
|
Size: |
8192
|
|
7110000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632558102.0000000007110000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7110000
|
Size: |
24576
|
|
57D9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3630908451.00000000057D9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
57D9000
|
Size: |
4096
|
|
3A6E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1184347511.0000000003A6E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A6E000
|
Size: |
24576
|
|
5232000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3629919297.0000000005232000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5232000
|
Size: |
49152
|
|
15C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390487636.00000000015C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
15C0000
|
Size: |
4096
|
|
1690000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1390598808.0000000001690000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1690000
|
Size: |
8192
|
|
2CB7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627771917.0000000002CB7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CB7000
|
Size: |
8192
|
|
5380000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309319698.0000000005380000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5380000
|
Size: |
49152
|
|
ED4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626329035.0000000000ED4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
ED4000
|
Size: |
8192
|
|
34E3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1184991194.00000000034E3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
34E3000
|
Size: |
507904
|
|
3B9D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1187292625.0000000003B9D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B9D000
|
Size: |
458752
|
|
F46000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1191052468.0000000000F46000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F46000
|
Size: |
36864
|
|
306F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390675843.000000000306F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
306F000
|
Size: |
4096
|
|
2D70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309162699.0000000002D70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D70000
|
Size: |
4096
|
|
F45000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178367928.0000000000F45000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F45000
|
Size: |
12288
|
|
1313000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308861298.0000000001313000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1313000
|
Size: |
24576
|
|
34E3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1184207570.00000000034E3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
34E3000
|
Size: |
507904
|
|
1180000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308583245.0000000001180000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1180000
|
Size: |
12288
|
|
6920000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3632009451.0000000006920000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
6920000
|
Size: |
65536
|
|
BE0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000008.00000000.1305281709.0000000000BE0000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
8
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
BE0000
|
Size: |
4096
|
|
ED3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3626279042.0000000000ED3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
ED3000
|
Size: |
4096
|
|
F5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194906827.0000000000F5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F5C000
|
Size: |
450560
|
|
39F3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1186369174.00000000039F3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39F3000
|
Size: |
507904
|
|
FE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308151270.0000000000FE0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FE0000
|
Size: |
4096
|
|
17F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1192685281.000000000017F000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
17F000
|
Size: |
147456
|
|
2CA0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627734559.0000000002CA0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2CA0000
|
Size: |
65536
|
|
F79000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308121752.0000000000F79000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
F79000
|
Size: |
28672
|
|
2C60000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627623669.0000000002C60000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C60000
|
Size: |
65536
|
|
D5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194633725.0000000000D5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
D5E000
|
Size: |
8192
|
|
63FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631495708.00000000063FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63FD000
|
Size: |
12288
|
|
152E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390233664.000000000152E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
152E000
|
Size: |
8192
|
|
2AF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627420427.0000000002AF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AF0000
|
Size: |
65536
|
|
3E87000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3629495623.0000000003E87000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E87000
|
Size: |
180224
|
|
3B99000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1187292625.0000000003B99000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B99000
|
Size: |
4096
|
|
5AA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631335975.0000000005AA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5AA0000
|
Size: |
4096
|
|
32AA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627872448.00000000032AA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
32AA000
|
Size: |
958464
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
EB0000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626138923.0000000000EB0000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
EB0000
|
Size: |
4096
|
|
17CF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390661433.00000000017CF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
17CF000
|
Size: |
4096
|
|
38D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1185847781.00000000038D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38D0000
|
Size: |
1187840
|
|
581F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309496498.000000000581F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
581F000
|
Size: |
4096
|
|
1550000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309089660.0000000001550000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1550000
|
Size: |
12288
|
|
39FD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1185117209.00000000039FD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39FD000
|
Size: |
458752
|
|
6BC0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632209735.0000000006BC0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6BC0000
|
Size: |
4096
|
|
F10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626866678.0000000000F10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F10000
|
Size: |
8192
|
|
5929000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631254258.0000000005929000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5929000
|
Size: |
8192
|
|
EC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626180978.0000000000EC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
EC0000
|
Size: |
8192
|
|
135A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308861298.000000000135A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
135A000
|
Size: |
53248
|
|
EE2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1173431922.0000000000EE2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EE2000
|
Size: |
503808
|
|
F30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1173681959.0000000000F30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F30000
|
Size: |
630784
|
|
1327000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308861298.0000000001327000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1327000
|
Size: |
204800
|
|
FB2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626913351.0000000000FB2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FB2000
|
Size: |
114688
|
|
EDD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3626380723.0000000000EDD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
EDD000
|
Size: |
4096
|
|
131A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308861298.000000000131A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
131A000
|
Size: |
12288
|
|
1210000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1389819458.0000000001210000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1210000
|
Size: |
28672
|
|
EB0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194731056.0000000000EB0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EB0000
|
Size: |
24576
|
|
12C4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308768753.00000000012C4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
12C4000
|
Size: |
24576
|
|
521E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3629919297.000000000521E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
521E000
|
Size: |
4096
|
|
667E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631548142.000000000667E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
667E000
|
Size: |
8192
|
|
F44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178385259.0000000000F44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F44000
|
Size: |
4096
|
|
F1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1172704594.00000000000F1000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
F1000
|
Size: |
581632
|
|
6B9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632183630.0000000006B9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6B9E000
|
Size: |
8192
|
|
F5A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626913351.0000000000F5A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F5A000
|
Size: |
4096
|
|
5520000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3630755724.0000000005520000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5520000
|
Size: |
4096
|
|
53CD000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3630534692.00000000053CD000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
53CD000
|
Size: |
12288
|
|
F5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1174263212.0000000000F5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F5C000
|
Size: |
450560
|
|
E60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194709665.0000000000E60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E60000
|
Size: |
4096
|
|
F28000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626913351.0000000000F28000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F28000
|
Size: |
159744
|
|
6CE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632343740.0000000006CE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
6CE0000
|
Size: |
40960
|
|
D55000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3625726289.0000000000D55000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D55000
|
Size: |
12288
|
|
F23000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1191052468.0000000000F23000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F23000
|
Size: |
118784
|
|
3A6E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1185117209.0000000003A6E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A6E000
|
Size: |
24576
|
|
548E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309364676.000000000548E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
548E000
|
Size: |
8192
|
|
121C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627238981.000000000121C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
121C000
|
Size: |
16384
|
|
F44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1191052468.0000000000F44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F44000
|
Size: |
4096
|
|
F44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194798938.0000000000F44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F44000
|
Size: |
4096
|
|
FCB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194953175.0000000000FCB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FCB000
|
Size: |
32768
|
|
520E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3629919297.000000000520E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
520E000
|
Size: |
12288
|
|
558E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309399766.000000000558E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
558E000
|
Size: |
8192
|
|
595F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390873431.000000000595F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
595F000
|
Size: |
4096
|
|
1500000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309053491.0000000001500000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1500000
|
Size: |
4096
|
|
2F1B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627872448.0000000002F1B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2F1B000
|
Size: |
3084288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
ED3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1173555771.0000000000ED3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
ED3000
|
Size: |
45056
|
|
39F9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1184729361.00000000039F9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39F9000
|
Size: |
4096
|
|
38D0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1184729361.00000000038D0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
38D0000
|
Size: |
1196032
|
|
12BD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.1308721828.00000000012BD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
12BD000
|
Size: |
4096
|
|
15AD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1390436379.00000000015AD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
15AD000
|
Size: |
8192
|
|
F05000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3626768388.0000000000F05000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
F05000
|
Size: |
4096
|
|
F14000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626866678.0000000000F14000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F14000
|
Size: |
4096
|
|
D50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3625726289.0000000000D50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D50000
|
Size: |
16384
|
|
33C0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1184991194.00000000033C0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33C0000
|
Size: |
1187840
|
|
715B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632625093.000000000715B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
715B000
|
Size: |
20480
|
|
1A4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1172755881.00000000001A4000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1A4000
|
Size: |
40960
|
|
123B000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1389819458.000000000123B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
123B000
|
Size: |
12288
|
|
5750000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1390847054.0000000005750000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5750000
|
Size: |
4096
|
|
F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1192597363.00000000000F0000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
F0000
|
Size: |
4096
|
|
F50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626913351.0000000000F50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F50000
|
Size: |
20480
|
|
F56000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.1194863426.0000000000F56000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
F56000
|
Size: |
4096
|
|
5610000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.1309455181.0000000005610000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
5610000
|
Size: |
4096
|
|
52A0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3630228204.00000000052A0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
52A0000
|
Size: |
65536
|
|
EED000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3626529366.0000000000EED000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
EED000
|
Size: |
4096
|
|
39F3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1185847781.00000000039F3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39F3000
|
Size: |
507904
|
|
6A1C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632094764.0000000006A1C000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
6A1C000
|
Size: |
16384
|
|
1580000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390269347.0000000001580000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1580000
|
Size: |
4096
|
|
2E7F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309181235.0000000002E7F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2E7F000
|
Size: |
4096
|
|
6930000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632053114.0000000006930000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6930000
|
Size: |
65536
|
|
159D000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1390320914.000000000159D000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
159D000
|
Size: |
4096
|
|
134E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390153823.000000000134E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
134E000
|
Size: |
8192
|
|
445000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3625204702.0000000000445000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
445000
|
Size: |
8192
|
|
1594000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390303790.0000000001594000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1594000
|
Size: |
4096
|
|
2E81000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309202155.0000000002E81000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2E81000
|
Size: |
53248
|
|
3A70000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1185555952.0000000003A70000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A70000
|
Size: |
1196032
|
|
68DE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631955807.00000000068DE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
68DE000
|
Size: |
8192
|
|
EF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1173941830.0000000000EF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EF0000
|
Size: |
262144
|
|
1355000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390193266.0000000001355000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1355000
|
Size: |
12288
|
|
5420000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.1309341165.0000000005420000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5420000
|
Size: |
8192
|
|
39FD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1184729361.00000000039FD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39FD000
|
Size: |
458752
|
|
571F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309474198.000000000571F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
571F000
|
Size: |
4096
|
|
F44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1178169147.0000000000F44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F44000
|
Size: |
73728
|
|
5A30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631307659.0000000005A30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5A30000
|
Size: |
4096
|
|
5762000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3630908451.0000000005762000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5762000
|
Size: |
45056
|
|
EF0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626586147.0000000000EF0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
EF0000
|
Size: |
4096
|
|
11D0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1389762403.00000000011D0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
11D0000
|
Size: |
4096
|
|
114E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308561903.000000000114E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
114E000
|
Size: |
8192
|
|
1190000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308603341.0000000001190000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1190000
|
Size: |
16384
|
|
39FD000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1184347511.00000000039FD000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39FD000
|
Size: |
458752
|
|
2AE0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3627381626.0000000002AE0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
2AE0000
|
Size: |
65536
|
|
6800000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631730402.0000000006800000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6800000
|
Size: |
12288
|
|
6830000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631887876.0000000006830000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6830000
|
Size: |
65536
|
|
3C0E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1185555952.0000000003C0E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C0E000
|
Size: |
24576
|
|
34E3000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1184602450.00000000034E3000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
34E3000
|
Size: |
507904
|
|
3B9D000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1186031238.0000000003B9D000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3B9D000
|
Size: |
458752
|
|
1C10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1195084548.0000000001C10000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1C10000
|
Size: |
8192
|
|
12F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308861298.00000000012F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
12F0000
|
Size: |
28672
|
|
576E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3630908451.000000000576E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
576E000
|
Size: |
417792
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
F5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1174183896.0000000000F5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F5C000
|
Size: |
450560
|
|
3C0E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1186031238.0000000003C0E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C0E000
|
Size: |
24576
|
|
F07000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3626803414.0000000000F07000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
F07000
|
Size: |
4096
|
|
FD3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1190719744.0000000000FD3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
FD3000
|
Size: |
315392
|
|
16AE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1195009381.00000000016AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
16AE000
|
Size: |
8192
|
|
12CD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000008.00000002.1308787056.00000000012CD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
12CD000
|
Size: |
8192
|
|
3A70000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1187292625.0000000003A70000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3A70000
|
Size: |
1196032
|
|
501E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309253353.000000000501E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
501E000
|
Size: |
8192
|
|
1593000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
0000000B.00000002.1390286439.0000000001593000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1593000
|
Size: |
4096
|
|
1235000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1389819458.0000000001235000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1235000
|
Size: |
20480
|
|
F20000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626913351.0000000000F20000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F20000
|
Size: |
28672
|
|
70D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632466846.00000000070D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
70D0000
|
Size: |
4096
|
|
6B5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632156050.0000000006B5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
6B5E000
|
Size: |
8192
|
|
EE3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626476098.0000000000EE3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
EE3000
|
Size: |
28672
|
|
F5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1174067677.0000000000F5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F5C000
|
Size: |
450560
|
|
5370000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309293046.0000000005370000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5370000
|
Size: |
65536
|
|
F46000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1191673959.0000000000F46000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F46000
|
Size: |
36864
|
|
3E81000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309224577.0000000003E81000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3E81000
|
Size: |
12288
|
|
163E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390556035.000000000163E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
163E000
|
Size: |
8192
|
|
EE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1191591053.0000000000EE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EE3000
|
Size: |
53248
|
|
106C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1389659499.000000000106C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
106C000
|
Size: |
16384
|
|
EFA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3626698093.0000000000EFA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
EFA000
|
Size: |
8192
|
|
EA7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3625987097.0000000000EA7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EA7000
|
Size: |
12288
|
|
39F9000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1184347511.00000000039F9000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
39F9000
|
Size: |
4096
|
|
16C0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390624293.00000000016C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16C0000
|
Size: |
12288
|
|
EF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1191052468.0000000000EF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EF0000
|
Size: |
196608
|
|
1B7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1172819132.00000000001B7000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
1B7000
|
Size: |
385024
|
|
54CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3630610574.00000000054CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
54CE000
|
Size: |
8192
|
|
F46000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194842816.0000000000F46000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F46000
|
Size: |
36864
|
|
ED0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3626230286.0000000000ED0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
ED0000
|
Size: |
12288
|
|
33C0000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1184207570.00000000033C0000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
33C0000
|
Size: |
1187840
|
|
2DBE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627841873.0000000002DBE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2DBE000
|
Size: |
8192
|
|
7100000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3632524429.0000000007100000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
7100000
|
Size: |
12288
|
|
5221000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3629919297.0000000005221000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5221000
|
Size: |
16384
|
|
154E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309071460.000000000154E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
154E000
|
Size: |
8192
|
|
16A0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390611826.00000000016A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
16A0000
|
Size: |
4096
|
|
F0E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1174183896.0000000000F0E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F0E000
|
Size: |
180224
|
|
527E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3630191287.000000000527E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
527E000
|
Size: |
8192
|
|
F5C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1173941830.0000000000F5C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F5C000
|
Size: |
450560
|
|
EA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3625987097.0000000000EA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EA0000
|
Size: |
16384
|
|
5A5F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390885535.0000000005A5F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5A5F000
|
Size: |
4096
|
|
8170000
|
heap
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3634929946.0000000008170000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
8170000
|
Size: |
16384
|
|
3217000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3627872448.0000000003217000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3217000
|
Size: |
552960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
3070000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.1390688622.0000000003070000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3070000
|
Size: |
65536
|
|
67E7000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000001.00000002.3631627814.00000000067E7000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
67E7000
|
Size: |
32768
|
|
12C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1308745198.00000000012C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
12C0000
|
Size: |
8192
|
|
14EF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000008.00000002.1309032994.00000000014EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
8
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
14EF000
|
Size: |
4096
|
|
17F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1172755881.000000000017F000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
17F000
|
Size: |
147456
|
|
400000
|
system
|
page execute and read and write
|
|
|
|
Name: |
00000001.00000002.3625204702.0000000000400000.00000040.80000000.00040000.00000000.sdmp
|
TargetID: |
1
|
Dumpstage: |
process exit
|
Regiontype: |
system
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
147456
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara signature match |
System Summary |
|
|
3C0E000
|
direct allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1187292625.0000000003C0E000.00000004.00001000.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
direct allocation
|
Protect: |
page read and write
|
Base address: |
3C0E000
|
Size: |
24576
|
|