7f2e583b9000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00007f2e583b8000.00007f2e583b9000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f2e583b9000
|
Size: |
4096
|
|
7f2e583c1000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00007f2e583bf000.00007f2e583c1000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f2e583c1000
|
Size: |
8192
|
|
7f2e50021000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00007f2e50000000.00007f2e50021000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f2e50021000
|
Size: |
135168
|
|
7f2dd040e000
|
|
page execute read
|
|
|
|
Name: |
6251.1.00007f2dd0400000.00007f2dd040e000.r-x.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page execute read
|
Base address: |
7f2dd040e000
|
Size: |
57344
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara signature match |
System Summary |
|
|
7ffeac141000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00007ffeac120000.00007ffeac141000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7ffeac141000
|
Size: |
135168
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
7f2e5799d000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00007f2e5799b000.00007f2e5799d000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f2e5799d000
|
Size: |
8192
|
|
7f2e58406000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00007f2e58405000.00007f2e58406000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f2e58406000
|
Size: |
4096
|
|
7f2e57d3e000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00007f2e57d3a000.00007f2e57d3e000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f2e57d3e000
|
Size: |
16384
|
|
7f2e50000000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00007f2e4f800000.00007f2e50000000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f2e50000000
|
Size: |
8388608
|
|
5559b00eb000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00005559b00c1000.00005559b00eb000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
5559b00eb000
|
Size: |
172032
|
|
7ffeac185000
|
|
page execute read
|
|
|
|
Name: |
6251.1.00007ffeac184000.00007ffeac185000.r-x.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page execute read
|
Base address: |
7ffeac185000
|
Size: |
4096
|
|
5559afe63000
|
|
page execute read
|
|
|
|
Name: |
6251.1.00005559afc40000.00005559afe63000.r-x.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page execute read
|
Base address: |
5559afe63000
|
Size: |
2240512
|
|
5559b2b73000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00005559b2aec000.00005559b2b73000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
5559b2b73000
|
Size: |
552960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
5559b20f3000
|
|
page execute and read and write
|
|
|
|
Name: |
6251.1.00005559b00f5000.00005559b20f3000.rwx.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page execute and read and write
|
Base address: |
5559b20f3000
|
Size: |
33546240
|
|
7f2e580af000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00007f2e580ac000.00007f2e580af000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f2e580af000
|
Size: |
12288
|
|
7f2dd0130000
|
|
page execute and read and write
|
|
|
|
Name: |
6251.1.00007f2dd012f000.00007f2dd0130000.rwx.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page execute and read and write
|
Base address: |
7f2dd0130000
|
Size: |
4096
|
|
7f2e57d61000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00007f2e57d5d000.00007f2e57d61000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f2e57d61000
|
Size: |
16384
|
|
7f2e57d7e000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00007f2e57d7c000.00007f2e57d7e000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f2e57d7e000
|
Size: |
8192
|
|
7f2e576df000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00007f2e56ed8000.00007f2e576df000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f2e576df000
|
Size: |
8417280
|
|
7f2dd0454000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00007f2dd044e000.00007f2dd0454000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f2dd0454000
|
Size: |
24576
|
|
5559b210a000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00005559b20f4000.00005559b210a000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
5559b210a000
|
Size: |
90112
|
|
7f2e58290000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00007f2e5828e000.00007f2e58290000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f2e58290000
|
Size: |
8192
|
|
7f2e56ed7000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00007f2e56e56000.00007f2e56ed7000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f2e56ed7000
|
Size: |
528384
|
|
7f2e576ed000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00007f2e576eb000.00007f2e576ed000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f2e576ed000
|
Size: |
8192
|
|
5559b00f5000
|
|
page read and write
|
|
|
|
Name: |
6251.1.00005559b00eb000.00005559b00f5000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
5559b00f5000
|
Size: |
40960
|
|