25BD21AF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285976348.0000025BD21AF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21AF000
|
Size: |
4096
|
|
25BD2290000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1286963753.0000025BD2290000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD2290000
|
Size: |
8192
|
|
25BD21F5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285464229.0000025BD21F5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21F5000
|
Size: |
8192
|
|
25BD21A3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1286743174.0000025BD21A3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21A3000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
25BD2180000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1279965521.0000025BD2180000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
25BD2180000
|
Size: |
4096
|
|
25BD21DA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285667297.0000025BD21DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21DA000
|
Size: |
45056
|
|
25BD21CC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1286529827.0000025BD21CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21CC000
|
Size: |
57344
|
|
25BD22B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1286984065.0000025BD22B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD22B0000
|
Size: |
4096
|
|
25BD220F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285569789.0000025BD220F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD220F000
|
Size: |
4096
|
|
25BD21F5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285569789.0000025BD21F5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21F5000
|
Size: |
8192
|
|
25BD21B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285860104.0000025BD21B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21B0000
|
Size: |
8192
|
|
25BD21CB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285860104.0000025BD21CB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21CB000
|
Size: |
61440
|
|
25BD21DF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1286909284.0000025BD21DF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21DF000
|
Size: |
20480
|
|
25BD2190000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1286743174.0000025BD2190000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD2190000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
25BD21A9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1286589463.0000025BD21A9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21A9000
|
Size: |
16384
|
|
25BD21AA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1286835266.0000025BD21AA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21AA000
|
Size: |
12288
|
|
25BD220F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285464229.0000025BD220F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD220F000
|
Size: |
4096
|
|
25BD21AF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285926902.0000025BD21AF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21AF000
|
Size: |
4096
|
|
25BD21DB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1286909284.0000025BD21DB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21DB000
|
Size: |
12288
|
|
25BD21A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285926902.0000025BD21A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21A6000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
25BD21DE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285836483.0000025BD21DE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21DE000
|
Size: |
28672
|
|
25BD21CB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285780725.0000025BD21CB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21CB000
|
Size: |
61440
|
|
25BD21AF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1286863732.0000025BD21AF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21AF000
|
Size: |
4096
|
|
25BD21AE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285903615.0000025BD21AE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21AE000
|
Size: |
8192
|
|
25BD2404000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1287005204.0000025BD2404000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD2404000
|
Size: |
4096
|
|
25BD20A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1286717985.0000025BD20A0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD20A0000
|
Size: |
4096
|
|
25BD21A1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1286743174.0000025BD21A1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21A1000
|
Size: |
4096
|
|
25BD2180000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1280009296.0000025BD2180000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
25BD2180000
|
Size: |
4096
|
|
25BD220F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285691006.0000025BD220F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD220F000
|
Size: |
4096
|
|
25BD21E5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285569789.0000025BD21E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21E5000
|
Size: |
4096
|
|
25BD21DA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285529683.0000025BD21DA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21DA000
|
Size: |
49152
|
|
7A1D2FC000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1286643124.0000007A1D2FC000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7A1D2FC000
|
Size: |
16384
|
|
25BD2197000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1286743174.0000025BD2197000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD2197000
|
Size: |
36864
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
25BD2400000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1287005204.0000025BD2400000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD2400000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7A1D4FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1286694241.0000007A1D4FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7A1D4FE000
|
Size: |
8192
|
|
25BD21AD000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285976348.0000025BD21AD000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21AD000
|
Size: |
4096
|
|
25BD21CC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1286863732.0000025BD21CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21CC000
|
Size: |
57344
|
|
25BD21B2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1285780725.0000025BD21B2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
25BD21B2000
|
Size: |
4096
|
|
25BD2180000
|
remote allocation
|
page read and write
|
|
|
|
Name: |
00000003.00000003.1280054152.0000025BD2180000.00000004.00000400.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
free memory
|
Regiontype: |
remote allocation
|
Protect: |
page read and write
|
Base address: |
25BD2180000
|
Size: |
4096
|
|
7A1D3FF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000003.00000002.1286666370.0000007A1D3FF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
3
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
7A1D3FF000
|
Size: |
4096
|
|