402000
|
remote allocation
|
page execute and read and write
|
 |
|
|
Name: |
00000002.00000002.2438516374.0000000000402000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
402000
|
Size: |
192512
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Yara detected RedLine Stealer |
Stealing of Sensitive Information, Remote Access Functionality |
|
URLs found in memory or binary data |
Networking |
|
|
2C61000
|
trusted library allocation
|
page read and write
|
 |
|
|
Name: |
00000002.00000002.2441151142.0000000002C61000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2C61000
|
Size: |
1785856
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found malware configuration |
AV Detection |
|
URLs found in memory or binary data |
Networking |
|
|
1260000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440519810.0000000001260000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1260000
|
Size: |
65536
|
|
60CE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442931998.00000000060CE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
60CE000
|
Size: |
8192
|
|
55E1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442003741.00000000055E1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
55E1000
|
Size: |
32768
|
|
2B30000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441009846.0000000002B30000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B30000
|
Size: |
16384
|
|
4DFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441569372.0000000004DFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4DFE000
|
Size: |
8192
|
|
56C4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442612919.00000000056C4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
56C4000
|
Size: |
4096
|
|
1230000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440442903.0000000001230000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1230000
|
Size: |
4096
|
|
10F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440180980.00000000010F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10F0000
|
Size: |
4096
|
|
5340000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441715039.0000000005340000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5340000
|
Size: |
4096
|
|
10C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2439861698.00000000010C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10C0000
|
Size: |
8192
|
|
2AE0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440698812.0000000002AE0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AE0000
|
Size: |
12288
|
|
56B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442612919.00000000056B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
56B0000
|
Size: |
4096
|
|
7FF6A2121000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000002.1194056247.00007FF6A2121000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF6A2121000
|
Size: |
368640
|
|
5810000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442901921.0000000005810000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5810000
|
Size: |
4096
|
|
F1E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2439389543.0000000000F1E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F1E000
|
Size: |
8192
|
|
2359B8A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1193350594.000002359B8A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2359B8A0000
|
Size: |
40960
|
|
2359D320000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1193956628.000002359D320000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2359D320000
|
Size: |
4096
|
|
7FF6A2120000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1188764413.00007FF6A2120000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6A2120000
|
Size: |
4096
|
|
7FF6A217B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1194140344.00007FF6A217B000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6A217B000
|
Size: |
45056
|
|
6110000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442948101.0000000006110000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
6110000
|
Size: |
36864
|
|
55B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442003741.00000000055B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
55B0000
|
Size: |
36864
|
|
5680000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442514235.0000000005680000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5680000
|
Size: |
65536
|
|
1250000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440497515.0000000001250000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1250000
|
Size: |
12288
|
|
56F2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442699870.00000000056F2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
56F2000
|
Size: |
106496
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
536B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441794830.000000000536B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
536B000
|
Size: |
20480
|
|
2AE4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440698812.0000000002AE4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AE4000
|
Size: |
4096
|
|
2B28000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440962067.0000000002B28000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B28000
|
Size: |
8192
|
|
437000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2438516374.0000000000437000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
437000
|
Size: |
57344
|
|
2AEE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440698812.0000000002AEE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AEE000
|
Size: |
12288
|
|
EA8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2439389543.0000000000EA8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
EA8000
|
Size: |
352256
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
55D2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442003741.00000000055D2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
55D2000
|
Size: |
36864
|
|
2C5F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441130086.0000000002C5F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C5F000
|
Size: |
4096
|
|
7FF6A2186000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1188845432.00007FF6A2186000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6A2186000
|
Size: |
4096
|
|
55DE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442003741.00000000055DE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
55DE000
|
Size: |
8192
|
|
547E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441897654.000000000547E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
547E000
|
Size: |
8192
|
|
3C61000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441494983.0000000003C61000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C61000
|
Size: |
36864
|
|
10D0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2439903391.00000000010D0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10D0000
|
Size: |
8192
|
|
1217000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2440395871.0000000001217000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1217000
|
Size: |
4096
|
|
5150000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441593846.0000000005150000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5150000
|
Size: |
61440
|
|
D70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2439310561.0000000000D70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D70000
|
Size: |
16384
|
|
2B0D000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440698812.0000000002B0D000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B0D000
|
Size: |
16384
|
|
560B000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442257615.000000000560B000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
560B000
|
Size: |
8192
|
|
5610000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442350346.0000000005610000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5610000
|
Size: |
65536
|
|
56A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442580602.00000000056A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
56A0000
|
Size: |
8192
|
|
10D4000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2439983291.00000000010D4000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10D4000
|
Size: |
8192
|
|
2B12000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440698812.0000000002B12000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B12000
|
Size: |
49152
|
|
560E000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442257615.000000000560E000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
560E000
|
Size: |
8192
|
|
5600000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442257615.0000000005600000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5600000
|
Size: |
4096
|
|
7FF6A2189000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1194197258.00007FF6A2189000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6A2189000
|
Size: |
16384
|
|
10ED000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2440146704.00000000010ED000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
10ED000
|
Size: |
4096
|
|
10E3000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440066468.00000000010E3000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10E3000
|
Size: |
32768
|
|
FFB00000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2442999933.00000000FFB00000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
FFB00000
|
Size: |
4096
|
|
5690000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442555216.0000000005690000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5690000
|
Size: |
65536
|
|
400000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2438516374.0000000000400000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
400000
|
Size: |
4096
|
|
5330000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441690761.0000000005330000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5330000
|
Size: |
4096
|
|
2B35000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441009846.0000000002B35000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B35000
|
Size: |
45056
|
|
5640000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2442449648.0000000005640000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5640000
|
Size: |
65536
|
|
446000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2438516374.0000000000446000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
446000
|
Size: |
36864
|
|
D75000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2439310561.0000000000D75000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D75000
|
Size: |
16384
|
|
2AFE000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440698812.0000000002AFE000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AFE000
|
Size: |
4096
|
|
D60000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2439256956.0000000000D60000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D60000
|
Size: |
8192
|
|
5263000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441623135.0000000005263000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5263000
|
Size: |
8192
|
|
2B40000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441075197.0000000002B40000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B40000
|
Size: |
65536
|
|
5342000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441715039.0000000005342000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5342000
|
Size: |
12288
|
|
543E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441870006.000000000543E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
543E000
|
Size: |
8192
|
|
1210000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440317658.0000000001210000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1210000
|
Size: |
4096
|
|
63C1BFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1193215120.00000063C1BFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63C1BFF000
|
Size: |
4096
|
|
1212000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440346119.0000000001212000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1212000
|
Size: |
4096
|
|
2B50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441104625.0000000002B50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B50000
|
Size: |
20480
|
|
5260000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441623135.0000000005260000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5260000
|
Size: |
4096
|
|
10E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440066468.00000000010E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10E0000
|
Size: |
8192
|
|
5FCF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442917248.0000000005FCF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
5FCF000
|
Size: |
4096
|
|
7FF6A2189000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1188860502.00007FF6A2189000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6A2189000
|
Size: |
16384
|
|
5620000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442388759.0000000005620000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5620000
|
Size: |
65536
|
|
5490000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441952222.0000000005490000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5490000
|
Size: |
65536
|
|
5360000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441794830.0000000005360000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5360000
|
Size: |
12288
|
|
1215000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2440372825.0000000001215000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1215000
|
Size: |
4096
|
|
2B01000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440698812.0000000002B01000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B01000
|
Size: |
16384
|
|
432000
|
remote allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2438516374.0000000000432000.00000040.00000400.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
remote allocation
|
Protect: |
page execute and read and write
|
Base address: |
432000
|
Size: |
16384
|
|
3C6F000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441494983.0000000003C6F000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C6F000
|
Size: |
12288
|
|
7FF6A2121000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000000.00000000.1188785160.00007FF6A2121000.00000020.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF6A2121000
|
Size: |
368640
|
|
9A9000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2439003980.00000000009A9000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
9A9000
|
Size: |
28672
|
|
55EA000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442003741.00000000055EA000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
55EA000
|
Size: |
12288
|
|
2AA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440625937.0000000002AA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AA0000
|
Size: |
4096
|
|
CF7000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2439076921.0000000000CF7000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
CF7000
|
Size: |
36864
|
|
55BB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442003741.00000000055BB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
55BB000
|
Size: |
20480
|
|
2359B850000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1193272063.000002359B850000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2359B850000
|
Size: |
8192
|
|
2359B8AB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1193350594.000002359B8AB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2359B8AB000
|
Size: |
77824
|
|
7FF6A218E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1188877110.00007FF6A218E000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6A218E000
|
Size: |
8192
|
|
2AE6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440698812.0000000002AE6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AE6000
|
Size: |
4096
|
|
7FF6A217B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1188824883.00007FF6A217B000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6A217B000
|
Size: |
45056
|
|
5605000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442257615.0000000005605000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5605000
|
Size: |
4096
|
|
E70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2439389543.0000000000E70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E70000
|
Size: |
24576
|
|
10DD000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2440030088.00000000010DD000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
10DD000
|
Size: |
4096
|
|
57C0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2442780803.00000000057C0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
57C0000
|
Size: |
65536
|
|
F05000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2439389543.0000000000F05000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F05000
|
Size: |
77824
|
|
2AC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440648280.0000000002AC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AC0000
|
Size: |
65536
|
|
57B0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442755171.00000000057B0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
57B0000
|
Size: |
65536
|
|
5350000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2441765944.0000000005350000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5350000
|
Size: |
65536
|
|
5365000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441794830.0000000005365000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5365000
|
Size: |
8192
|
|
1100000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440297328.0000000001100000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1100000
|
Size: |
12288
|
|
7FF6A2120000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1194023513.00007FF6A2120000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6A2120000
|
Size: |
4096
|
|
63C1CFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1193234172.00000063C1CFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63C1CFE000
|
Size: |
8192
|
|
5800000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2442877073.0000000005800000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
5800000
|
Size: |
65536
|
|
2359B840000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1193254104.000002359B840000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2359B840000
|
Size: |
4096
|
|
10F6000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2440239627.00000000010F6000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
10F6000
|
Size: |
12288
|
|
5480000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441924591.0000000005480000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5480000
|
Size: |
36864
|
|
57F0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442853816.00000000057F0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
57F0000
|
Size: |
65536
|
|
F30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2439389543.0000000000F30000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F30000
|
Size: |
217088
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
57D0000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2442804841.00000000057D0000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
57D0000
|
Size: |
65536
|
|
2A5E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440577922.0000000002A5E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A5E000
|
Size: |
8192
|
|
10D3000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2439943186.00000000010D3000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
10D3000
|
Size: |
4096
|
|
570D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442699870.000000000570D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
570D000
|
Size: |
49152
|
|
7FF6A218E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.1194222250.00007FF6A218E000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6A218E000
|
Size: |
8192
|
|
E9A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2439389543.0000000000E9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E9A000
|
Size: |
16384
|
|
2AEB000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440698812.0000000002AEB000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AEB000
|
Size: |
8192
|
|
2AF2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440698812.0000000002AF2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2AF2000
|
Size: |
36864
|
|
57E0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442829659.00000000057E0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
57E0000
|
Size: |
65536
|
|
63C1AFC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1193191895.00000063C1AFC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
63C1AFC000
|
Size: |
16384
|
|
1240000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2440465030.0000000001240000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
1240000
|
Size: |
65536
|
|
55F1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442227215.00000000055F1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
55F1000
|
Size: |
61440
|
|
10F2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440213297.00000000010F2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
10F2000
|
Size: |
4096
|
|
1270000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440547140.0000000001270000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1270000
|
Size: |
12288
|
|
55C6000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442003741.00000000055C6000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
55C6000
|
Size: |
45056
|
|
7FF6A2186000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1194177986.00007FF6A2186000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF6A2186000
|
Size: |
8192
|
|
55C1000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442003741.00000000055C1000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
55C1000
|
Size: |
16384
|
|
2B06000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440698812.0000000002B06000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B06000
|
Size: |
16384
|
|
2AD0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2440677818.0000000002AD0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
2AD0000
|
Size: |
4096
|
|
5670000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442483940.0000000005670000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5670000
|
Size: |
65536
|
|
7FF6A2190000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000002.1194385477.00007FF6A2190000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6A2190000
|
Size: |
622592
|
|
2A9E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440603862.0000000002A9E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A9E000
|
Size: |
8192
|
|
E78000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2439389543.0000000000E78000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
E78000
|
Size: |
135168
|
|
D10000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2439156957.0000000000D10000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
D10000
|
Size: |
4096
|
|
3C81000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2441494983.0000000003C81000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
3C81000
|
Size: |
4096
|
|
2359D21C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1193670269.000002359D21C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2359D21C000
|
Size: |
1056768
|
|
121B000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2440419118.000000000121B000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
121B000
|
Size: |
4096
|
|
7FF6A2190000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1188891632.00007FF6A2190000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6A2190000
|
Size: |
622592
|
|
54A0000
|
heap
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2441979217.00000000054A0000.00000040.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page execute and read and write
|
Base address: |
54A0000
|
Size: |
4096
|
|
2359D3F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.1193993951.000002359D3F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2359D3F0000
|
Size: |
12288
|
|
5630000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2442422713.0000000005630000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
5630000
|
Size: |
65536
|
|
2B20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2440962067.0000000002B20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2B20000
|
Size: |
28672
|
|
10FA000
|
trusted library allocation
|
page execute and read and write
|
|
|
|
Name: |
00000002.00000002.2440267148.00000000010FA000.00000040.00000800.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute and read and write
|
Base address: |
10FA000
|
Size: |
16384
|
|
F6C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000002.00000002.2439389543.0000000000F6C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
2
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
F6C000
|
Size: |
12288
|
|