2150000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441129024.0000000002150000.00000004.00000800.00040000.00000009.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2150000
|
Size: |
8192
|
|
770000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2440795477.0000000000770000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
770000
|
Size: |
4096
|
|
337F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441722517.000000000337F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
337F000
|
Size: |
4096
|
|
2B50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441632729.0000000002B50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B50000
|
Size: |
32768
|
|
97000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2440095617.0000000000097000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
97000
|
Size: |
36864
|
|
7ED000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000003.1194397721.00000000007ED000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7ED000
|
Size: |
122880
|
|
44D000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2440259445.000000000044D000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
44D000
|
Size: |
4096
|
|
401000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2440259445.0000000000401000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
401000
|
Size: |
286720
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to development resources |
System Summary |
|
URLs found in memory or binary data |
Networking |
|
|
4A9F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441747471.0000000004A9F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
4A9F000
|
Size: |
4096
|
|
7BA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2440874901.00000000007BA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7BA000
|
Size: |
8192
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000002.2440217088.0000000000400000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
220E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441170706.000000000220E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
220E000
|
Size: |
8192
|
|
4B20000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441766513.0000000004B20000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
4B20000
|
Size: |
4096
|
|
460000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2440532251.0000000000460000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
460000
|
Size: |
4096
|
|
44F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2440498654.000000000044F000.00000004.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
44F000
|
Size: |
8192
|
|
635000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2440712576.0000000000635000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
635000
|
Size: |
12288
|
|
2B40000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441574351.0000000002B40000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B40000
|
Size: |
8192
|
|
22C0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441490757.00000000022C0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
22C0000
|
Size: |
4096
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
44F000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000000.00000000.1193198292.000000000044F000.00000008.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
44F000
|
Size: |
8192
|
|
7B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2440874901.00000000007B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7B0000
|
Size: |
32768
|
|
226E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441298600.000000000226E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
226E000
|
Size: |
8192
|
|
449000
|
unkown
|
page execute and read and write
|
|
|
|
Name: |
00000000.00000002.2440259445.0000000000449000.00000040.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and read and write
|
Base address: |
449000
|
Size: |
8192
|
|
22B0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441406652.00000000022B0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22B0000
|
Size: |
12288
|
|
44E000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000000.00000002.2440450479.000000000044E000.00000080.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
44E000
|
Size: |
4096
|
|
540000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2440581650.0000000000540000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
540000
|
Size: |
4096
|
|
2218000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441212044.0000000002218000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2218000
|
Size: |
28672
|
|
22B9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441406652.00000000022B9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22B9000
|
Size: |
16384
|
|
499E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441735098.000000000499E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
499E000
|
Size: |
8192
|
|
2B1E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441543924.0000000002B1E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B1E000
|
Size: |
8192
|
|
19B000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2440175058.000000000019B000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
19B000
|
Size: |
20480
|
|
2C50000
|
trusted library section
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441657629.0000000002C50000.00000004.08000000.00040000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library section
|
Protect: |
page read and write
|
Base address: |
2C50000
|
Size: |
16384
|
|
22B5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441406652.00000000022B5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
22B5000
|
Size: |
12288
|
|
2AD0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441515404.0000000002AD0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AD0000
|
Size: |
4096
|
|
790000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2440837120.0000000000790000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
790000
|
Size: |
4096
|
|
7CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2440874901.00000000007CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7CF000
|
Size: |
282624
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
630000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2440712576.0000000000630000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
630000
|
Size: |
16384
|
|
2B44000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441574351.0000000002B44000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2B44000
|
Size: |
16384
|
|
2290000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441376082.0000000002290000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
2290000
|
Size: |
4096
|
|
7BE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2440874901.00000000007BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
7BE000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
AV process strings found (often used to terminate AV products) |
Lowering of HIPS / PFW / Operating System Security Settings |
Security Software Discovery
|
|
2210000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441212044.0000000002210000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2210000
|
Size: |
24576
|
|
444000
|
unkown
|
page execute and write copy
|
|
|
|
Name: |
00000000.00000000.1193164113.0000000000444000.00000080.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute and write copy
|
Base address: |
444000
|
Size: |
45056
|
|
620000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2440669880.0000000000620000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
620000
|
Size: |
4096
|
|
400000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000000.00000000.1193148026.0000000000400000.00000002.00000001.01000000.00000003.sdmp
|
TargetID: |
0
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
400000
|
Size: |
4096
|
|
2270000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441335234.0000000002270000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2270000
|
Size: |
8192
|
|
5F0000
|
trusted library allocation
|
page execute read
|
|
|
|
Name: |
00000000.00000002.2440622748.00000000005F0000.00000020.00000800.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page execute read
|
Base address: |
5F0000
|
Size: |
40960
|
|
327E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441700699.000000000327E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
327E000
|
Size: |
8192
|
|
323F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2441680721.000000000323F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
323F000
|
Size: |
4096
|
|
815000
|
heap
|
page read and write
|
|
|
|
Name: |
00000000.00000002.2440874901.0000000000815000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
0
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
815000
|
Size: |
12288
|
|