7FF957A69000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4096667524.00007FF957A69000.00000004.00000001.01000000.0000001E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF957A69000
|
Size: |
4096
|
|
7FF93CB60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3256032571.00007FF93CB60000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93CB60000
|
Size: |
4096
|
|
7FF6AC861000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3252636873.00007FF6AC861000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF6AC861000
|
Size: |
2248704
|
|
7FF93C02D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3254258923.00007FF93C02D000.00000004.00000001.01000000.00000016.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93C02D000
|
Size: |
4096
|
|
192784A7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3167190423.00000192784A7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
192784A7000
|
Size: |
4096
|
|
7FF93CF19000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3256335958.00007FF93CF19000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93CF19000
|
Size: |
2461696
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF957AC4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176944487.00007FF957AC4000.00000002.00000001.01000000.00000011.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957AC4000
|
Size: |
12288
|
|
7FF957ABD000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176869456.00007FF957ABD000.00000002.00000001.01000000.00000011.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957ABD000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1F401DF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3252102053.000001F401DF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401DF0000
|
Size: |
8192
|
|
7FF94405B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176374441.00007FF94405B000.00000002.00000001.01000000.00000012.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF94405B000
|
Size: |
16384
|
|
7FF93CB60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3172965469.00007FF93CB60000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93CB60000
|
Size: |
4096
|
|
7FF93CB00000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3255606487.00007FF93CB00000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB00000
|
Size: |
16384
|
|
1DDB4C92000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3142375286.000001DDB4C92000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C92000
|
Size: |
16384
|
|
7FF93C218000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3254538389.00007FF93C218000.00000020.00000001.01000000.00000013.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93C218000
|
Size: |
2121728
|
|
7FF956DC3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3259336464.00007FF956DC3000.00000004.00000001.01000000.00000018.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF956DC3000
|
Size: |
4096
|
|
7FF950BD1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3259120957.00007FF950BD1000.00000020.00000001.01000000.00000019.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF950BD1000
|
Size: |
36864
|
|
8332394000
|
stack
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3251830494.0000008332394000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
8332394000
|
Size: |
49152
|
|
7FF93CB04000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3172545946.00007FF93CB04000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB04000
|
Size: |
24576
|
|
7FF93D189000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3173862835.00007FF93D189000.00000008.00000001.01000000.0000000C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D189000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
7FF6ACD4E000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3253246448.00007FF6ACD4E000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6ACD4E000
|
Size: |
8192
|
|
7FF943FE1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3176219137.00007FF943FE1000.00000020.00000001.01000000.00000012.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF943FE1000
|
Size: |
348160
|
|
7FF9586B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3260098219.00007FF9586B0000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9586B0000
|
Size: |
4096
|
|
2CAF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3005185426.0000000002CAF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2CAF000
|
Size: |
4096
|
|
1DDB19D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4081482497.000001DDB19D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB19D0000
|
Size: |
12288
|
|
7FF93F144000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176179587.00007FF93F144000.00000002.00000001.01000000.0000001A.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93F144000
|
Size: |
8192
|
|
1927A010000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3169300199.000001927A010000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1927A010000
|
Size: |
12288
|
|
7FF93C02F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3171157121.00007FF93C02F000.00000002.00000001.01000000.00000016.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C02F000
|
Size: |
36864
|
|
1DDB53A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3129105713.000001DDB53A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB53A6000
|
Size: |
65536
|
|
7FF93C515000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3254925828.00007FF93C515000.00000004.00000001.01000000.00000013.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93C515000
|
Size: |
4096
|
|
19278485000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3168410395.0000019278485000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19278485000
|
Size: |
4096
|
|
7FF93D18E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3256785070.00007FF93D18E000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D18E000
|
Size: |
20480
|
|
7FF95DD5A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4098898146.00007FF95DD5A000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95DD5A000
|
Size: |
8192
|
|
7FF9586B1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3260125452.00007FF9586B1000.00000020.00000001.01000000.00000006.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF9586B1000
|
Size: |
32768
|
|
4C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3004747632.00000000004C0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
4C0000
|
Size: |
4096
|
|
7FF93CB04000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3255632703.00007FF93CB04000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB04000
|
Size: |
24576
|
|
7FF93D6B8000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3174944445.00007FF93D6B8000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6B8000
|
Size: |
4096
|
|
7FF956DB1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3176562839.00007FF956DB1000.00000020.00000001.01000000.00000018.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF956DB1000
|
Size: |
61440
|
|
7FF943FE1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3258909813.00007FF943FE1000.00000020.00000001.01000000.00000012.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF943FE1000
|
Size: |
348160
|
|
7FF93D189000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4091728053.00007FF93D189000.00000008.00000001.01000000.0000000C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D189000
|
Size: |
20480
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
7FF93D69F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3174779185.00007FF93D69F000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D69F000
|
Size: |
12288
|
|
1927A1D3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3169395286.000001927A1D3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1927A1D3000
|
Size: |
12288
|
|
7FF95DD57000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3177427548.00007FF95DD57000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95DD57000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93BF30000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3170989480.00007FF93BF30000.00000002.00000001.01000000.00000016.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BF30000
|
Size: |
4096
|
|
7FF93D198000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4091763308.00007FF93D198000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D198000
|
Size: |
8192
|
|
7FF93DBA2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3175446521.00007FF93DBA2000.00000008.00000001.01000000.0000000A.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93DBA2000
|
Size: |
204800
|
|
7FF93D6BA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3257584324.00007FF93D6BA000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6BA000
|
Size: |
4096
|
|
7FF957AC3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4097487540.00007FF957AC3000.00000004.00000001.01000000.00000011.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF957AC3000
|
Size: |
4096
|
|
7FF93CB18000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3255863680.00007FF93CB18000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB18000
|
Size: |
8192
|
|
7FF6ACD5D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3253512226.00007FF6ACD5D000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF6ACD5D000
|
Size: |
12288
|
|
3231000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.3007456185.0000000003231000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3231000
|
Size: |
90112
|
|
1DDB4CB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125514317.000001DDB4CB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB5000
|
Size: |
4096
|
|
7FF93C550000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3254995549.00007FF93C550000.00000002.00000001.01000000.00000010.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C550000
|
Size: |
4096
|
|
7FF93DC11000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3258299014.00007FF93DC11000.00000020.00000001.01000000.00000007.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93DC11000
|
Size: |
905216
|
|
7FF957E00000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3259703439.00007FF957E00000.00000002.00000001.01000000.0000000E.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957E00000
|
Size: |
4096
|
|
7FF94405B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3259054975.00007FF94405B000.00000002.00000001.01000000.00000012.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF94405B000
|
Size: |
16384
|
|
7FF93BD70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3170209949.00007FF93BD70000.00000002.00000001.01000000.0000001C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BD70000
|
Size: |
4096
|
|
7FF93CB25000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4090653541.00007FF93CB25000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB25000
|
Size: |
24576
|
|
7FF6AC860000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3252609671.00007FF6AC860000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6AC860000
|
Size: |
4096
|
|
1DDB19F1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3122082159.000001DDB19F1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB19F1000
|
Size: |
212992
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF93CB10000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4090369926.00007FF93CB10000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB10000
|
Size: |
8192
|
|
7FF93D698000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4092545583.00007FF93D698000.00000008.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D698000
|
Size: |
28672
|
|
1F403AE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3252459654.000001F403AE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F403AE0000
|
Size: |
8192
|
|
7FF93DD58000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3175694962.00007FF93DD58000.00000008.00000001.01000000.00000007.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93DD58000
|
Size: |
4096
|
|
7FF93D6A7000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3257480594.00007FF93D6A7000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6A7000
|
Size: |
4096
|
|
1927A1D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3169395286.000001927A1D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1927A1D0000
|
Size: |
8192
|
|
7FF93CB18000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3172793215.00007FF93CB18000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB18000
|
Size: |
8192
|
|
1F403920000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3252380794.000001F403920000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F403920000
|
Size: |
4096
|
|
7FF93CB14000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4090434058.00007FF93CB14000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB14000
|
Size: |
4096
|
|
7FF95DD5A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3177448162.00007FF95DD5A000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95DD5A000
|
Size: |
8192
|
|
7FF956DB0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096398284.00007FF956DB0000.00000002.00000001.01000000.00000018.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF956DB0000
|
Size: |
4096
|
|
7FF93D46B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3257131259.00007FF93D46B000.00000002.00000001.01000000.0000000B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93D46B000
|
Size: |
2273280
|
|
1DDB4CA3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127210061.000001DDB4CA3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CA3000
|
Size: |
4096
|
|
1DDB4CB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127210061.000001DDB4CB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB4000
|
Size: |
8192
|
|
7FF93D17E000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3173735665.00007FF93D17E000.00000008.00000001.01000000.0000000C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D17E000
|
Size: |
4096
|
|
7FF957E0E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3177116575.00007FF957E0E000.00000002.00000001.01000000.0000000E.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957E0E000
|
Size: |
8192
|
|
345F000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3008059611.000000000345F000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
345F000
|
Size: |
4096
|
|
7FF93BFF2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4088325018.00007FF93BFF2000.00000002.00000001.01000000.00000016.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BFF2000
|
Size: |
241664
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93CB00000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3172519109.00007FF93CB00000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB00000
|
Size: |
16384
|
|
7FF6ACD4B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4086356053.00007FF6ACD4B000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF6ACD4B000
|
Size: |
12288
|
|
7FF93C5D2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3171968253.00007FF93C5D2000.00000004.00000001.01000000.00000010.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93C5D2000
|
Size: |
4096
|
|
7FF93C041000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4088490100.00007FF93C041000.00000020.00000001.01000000.00000014.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93C041000
|
Size: |
561152
|
|
1F401FDC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3252315517.000001F401FDC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FDC000
|
Size: |
77824
|
|
7FF93BDA0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4087708924.00007FF93BDA0000.00000002.00000001.01000000.0000001B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BDA0000
|
Size: |
4096
|
|
7FF93C5AC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3255077391.00007FF93C5AC000.00000002.00000001.01000000.00000010.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C5AC000
|
Size: |
143360
|
|
192784A3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3167376076.00000192784A3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
192784A3000
|
Size: |
4096
|
|
7FF93C519000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3254959729.00007FF93C519000.00000002.00000001.01000000.00000013.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C519000
|
Size: |
192512
|
|
7FF944043000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176282328.00007FF944043000.00000002.00000001.01000000.00000012.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF944043000
|
Size: |
94208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF6ACA86000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4085937700.00007FF6ACA86000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6ACA86000
|
Size: |
2834432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1DDB4C92000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3123975137.000001DDB4C92000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C92000
|
Size: |
61440
|
|
7FF93BA86000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4086915398.00007FF93BA86000.00000002.00000001.01000000.0000001F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BA86000
|
Size: |
2744320
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
2B4E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3005024760.0000000002B4E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B4E000
|
Size: |
8192
|
|
7FF93D184000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3256656260.00007FF93D184000.00000008.00000001.01000000.0000000C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D184000
|
Size: |
4096
|
|
7FF93DD9F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3258646867.00007FF93DD9F000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DD9F000
|
Size: |
114688
|
|
2BCE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3005077431.0000000002BCE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2BCE000
|
Size: |
8192
|
|
7FF93D6BC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4094854209.00007FF93D6BC000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6BC000
|
Size: |
4096
|
|
2BE0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3005098507.0000000002BE0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2BE0000
|
Size: |
12288
|
|
1DDB4C8C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3126451794.000001DDB4C8C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C8C000
|
Size: |
8192
|
|
7FF93D17F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3173753579.00007FF93D17F000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D17F000
|
Size: |
20480
|
|
3248000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.3007635388.0000000003248000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3248000
|
Size: |
53248
|
|
7FF93C5D2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4089607696.00007FF93C5D2000.00000004.00000001.01000000.00000010.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93C5D2000
|
Size: |
4096
|
|
7FF6ACD57000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3170071597.00007FF6ACD57000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6ACD57000
|
Size: |
24576
|
|
3210000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3007883531.0000000003210000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3210000
|
Size: |
12288
|
|
7FF93C5D2000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3255134076.00007FF93C5D2000.00000004.00000001.01000000.00000010.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93C5D2000
|
Size: |
4096
|
|
7FF93C0DB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4088691515.00007FF93C0DB000.00000004.00000001.01000000.00000014.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93C0DB000
|
Size: |
4096
|
|
7FF95DD50000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4098672841.00007FF95DD50000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95DD50000
|
Size: |
4096
|
|
7FF6ACD4E000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3169965337.00007FF6ACD4E000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6ACD4E000
|
Size: |
8192
|
|
7FF93C5AC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3171911099.00007FF93C5AC000.00000002.00000001.01000000.00000010.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C5AC000
|
Size: |
143360
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93BD8B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3170310906.00007FF93BD8B000.00000002.00000001.01000000.0000001C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BD8B000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF6AC860000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000000.3165210562.00007FF6AC860000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
22
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6AC860000
|
Size: |
4096
|
|
1927A015000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3169300199.000001927A015000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1927A015000
|
Size: |
4096
|
|
7FF95D9C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4098458129.00007FF95D9C0000.00000002.00000001.01000000.0000000D.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95D9C0000
|
Size: |
4096
|
|
3255000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.3007434433.0000000003255000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3255000
|
Size: |
16384
|
|
7FF6ACD3A000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3169893598.00007FF6ACD3A000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6ACD3A000
|
Size: |
69632
|
|
7FF950BDD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3259183819.00007FF950BDD000.00000004.00000001.01000000.00000019.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF950BDD000
|
Size: |
4096
|
|
7FF957ABD000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4097420375.00007FF957ABD000.00000002.00000001.01000000.00000011.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957ABD000
|
Size: |
24576
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF956DC5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3259365890.00007FF956DC5000.00000002.00000001.01000000.00000018.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF956DC5000
|
Size: |
8192
|
|
7FF93D696000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3174738786.00007FF93D696000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D696000
|
Size: |
8192
|
|
7FF957A70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3259395321.00007FF957A70000.00000002.00000001.01000000.00000015.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957A70000
|
Size: |
4096
|
|
7FF957A71000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3176694950.00007FF957A71000.00000020.00000001.01000000.00000015.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF957A71000
|
Size: |
147456
|
|
7FF93DC10000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3258268748.00007FF93DC10000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DC10000
|
Size: |
4096
|
|
1DDB4EC0000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4083476237.000001DDB4EC0000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DDB4EC0000
|
Size: |
176128
|
|
1F401F99000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3252205643.000001F401F99000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401F99000
|
Size: |
167936
|
|
192784AF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3167351505.00000192784AF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
192784AF000
|
Size: |
4096
|
|
2D1E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3004324266.0000000002D1E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D1E000
|
Size: |
49152
|
|
7FF957AC3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3176920218.00007FF957AC3000.00000004.00000001.01000000.00000011.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF957AC3000
|
Size: |
4096
|
|
1DDB1A3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3122449090.000001DDB1A3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB1A3D000
|
Size: |
4096
|
|
7FF93C5D4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3171996231.00007FF93C5D4000.00000002.00000001.01000000.00000010.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C5D4000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1F401FD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3251160164.000001F401FD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FD4000
|
Size: |
12288
|
|
1DDB5311000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3129046334.000001DDB5311000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB5311000
|
Size: |
327680
|
|
1F401FC9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3251201564.000001F401FC9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FC9000
|
Size: |
36864
|
|
1DDB4650000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4082332519.000001DDB4650000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4650000
|
Size: |
4096
|
|
1DDB4C9A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125635278.000001DDB4C9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9A000
|
Size: |
8192
|
|
1DDB7951000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4085504093.000001DDB7951000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB7951000
|
Size: |
65536
|
|
7FF93BE6B000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4087918360.00007FF93BE6B000.00000008.00000001.01000000.0000001B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93BE6B000
|
Size: |
4096
|
|
7FF93C041000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3171228231.00007FF93C041000.00000020.00000001.01000000.00000014.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93C041000
|
Size: |
561152
|
|
341E000
|
unkown
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3008036951.000000000341E000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
341E000
|
Size: |
8192
|
|
7FF93DBDE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3258227158.00007FF93DBDE000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DBDE000
|
Size: |
147456
|
|
3248000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3007965807.0000000003248000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3248000
|
Size: |
53248
|
|
1DDB3553000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4082017302.000001DDB3553000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB3553000
|
Size: |
20480
|
|
1DDB53FA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4084058069.000001DDB53FA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB53FA000
|
Size: |
225280
|
|
7FF93D6A4000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3257423388.00007FF93D6A4000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6A4000
|
Size: |
8192
|
|
1DDB4CA3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3123831877.000001DDB4CA3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CA3000
|
Size: |
4096
|
|
7FF6ACD50000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3253334206.00007FF6ACD50000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF6ACD50000
|
Size: |
8192
|
|
1927849E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3169221098.000001927849E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1927849E000
|
Size: |
20480
|
|
84FA2FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3168788166.00000084FA2FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
84FA2FD000
|
Size: |
12288
|
|
7FF950BDD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4096348018.00007FF950BDD000.00000004.00000001.01000000.00000019.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF950BDD000
|
Size: |
4096
|
|
7FF94405A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3176352801.00007FF94405A000.00000004.00000001.01000000.00000012.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF94405A000
|
Size: |
4096
|
|
7FF93DD9F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3175928902.00007FF93DD9F000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DD9F000
|
Size: |
114688
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF95D9CF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3177344391.00007FF95D9CF000.00000002.00000001.01000000.0000000D.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95D9CF000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF957A95000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3259470056.00007FF957A95000.00000002.00000001.01000000.00000015.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957A95000
|
Size: |
40960
|
|
1DDB4C9C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127410139.000001DDB4C9C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9C000
|
Size: |
32768
|
|
7FF93C039000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4088404002.00007FF93C039000.00000002.00000001.01000000.00000016.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C039000
|
Size: |
4096
|
|
1DDB5535000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4084439337.000001DDB5535000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB5535000
|
Size: |
172032
|
|
7FF93DD59000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3258515517.00007FF93DD59000.00000004.00000001.01000000.00000007.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93DD59000
|
Size: |
4096
|
|
1F401FC9000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3252249259.000001F401FC9000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FC9000
|
Size: |
36864
|
|
1DDB54CF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4084439337.000001DDB54CF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB54CF000
|
Size: |
413696
|
|
7FF93D6A0000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4092617531.00007FF93D6A0000.00000008.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D6A0000
|
Size: |
4096
|
|
1927844D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3168656346.000001927844D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1927844D000
|
Size: |
65536
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF957A61000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4096598140.00007FF957A61000.00000020.00000001.01000000.0000001E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF957A61000
|
Size: |
16384
|
|
2CF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3005208277.0000000002CF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CF0000
|
Size: |
8192
|
|
7FF93C0F1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4088826054.00007FF93C0F1000.00000020.00000001.01000000.00000013.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93C0F1000
|
Size: |
1204224
|
|
7FF93BD33000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4087321980.00007FF93BD33000.00000008.00000001.01000000.0000001F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93BD33000
|
Size: |
28672
|
|
7FF93BE80000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3170727789.00007FF93BE80000.00000002.00000001.01000000.00000017.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BE80000
|
Size: |
4096
|
|
1DDB4C81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3126433508.000001DDB4C81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C81000
|
Size: |
53248
|
|
19279E50000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3169274066.0000019279E50000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19279E50000
|
Size: |
4096
|
|
1DDB52E5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3129192300.000001DDB52E5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB52E5000
|
Size: |
180224
|
|
516F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3008129555.000000000516F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
516F000
|
Size: |
4096
|
|
7FF93D6A8000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4093227488.00007FF93D6A8000.00000008.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D6A8000
|
Size: |
45056
|
|
7FF950BD1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3176422329.00007FF950BD1000.00000020.00000001.01000000.00000019.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF950BD1000
|
Size: |
36864
|
|
7FF6ACD52000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4086468939.00007FF6ACD52000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6ACD52000
|
Size: |
12288
|
|
7FF93C93E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4090045675.00007FF93C93E000.00000002.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C93E000
|
Size: |
1843200
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2A7E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3004943722.0000000002A7E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2A7E000
|
Size: |
8192
|
|
7FF956DB1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4096423997.00007FF956DB1000.00000020.00000001.01000000.00000018.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF956DB1000
|
Size: |
61440
|
|
7FF93BDA0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3170391097.00007FF93BDA0000.00000002.00000001.01000000.0000001B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BDA0000
|
Size: |
4096
|
|
19278478000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3168611006.0000019278478000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19278478000
|
Size: |
49152
|
|
7FF93C02D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3171134019.00007FF93C02D000.00000004.00000001.01000000.00000016.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93C02D000
|
Size: |
4096
|
|
1DDB19D4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4081482497.000001DDB19D4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB19D4000
|
Size: |
331776
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1DDB4CB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127142438.000001DDB4CB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB4000
|
Size: |
8192
|
|
7FF9586B1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3177199587.00007FF9586B1000.00000020.00000001.01000000.00000006.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF9586B1000
|
Size: |
32768
|
|
1DDB4C88000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125530964.000001DDB4C88000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C88000
|
Size: |
40960
|
|
7FF93BE6C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3253921686.00007FF93BE6C000.00000004.00000001.01000000.0000001B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93BE6C000
|
Size: |
8192
|
|
1DDB4CB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3123831877.000001DDB4CB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB4000
|
Size: |
8192
|
|
7FF93D6B6000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3174927023.00007FF93D6B6000.00000008.00000001.01000000.0000000B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D6B6000
|
Size: |
8192
|
|
83328FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3251933384.00000083328FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83328FE000
|
Size: |
8192
|
|
1DDB4C92000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127445423.000001DDB4C92000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C92000
|
Size: |
40960
|
|
BEB9FFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4081202047.000000BEB9FFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BEB9FFE000
|
Size: |
8192
|
|
7FF93D19A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3256840246.00007FF93D19A000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93D19A000
|
Size: |
229376
|
|
7FF95D9C1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4098489383.00007FF95D9C1000.00000020.00000001.01000000.0000000D.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF95D9C1000
|
Size: |
57344
|
|
7FF93C5CF000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3171943043.00007FF93C5CF000.00000008.00000001.01000000.00000010.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93C5CF000
|
Size: |
12288
|
|
7FF93DBA1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3258132393.00007FF93DBA1000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93DBA1000
|
Size: |
4096
|
|
1DDB52CC000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3129359369.000001DDB52CC000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB52CC000
|
Size: |
20480
|
|
1DDB4CB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125716489.000001DDB4CB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB5000
|
Size: |
4096
|
|
7FF93CB14000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3172695481.00007FF93CB14000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB14000
|
Size: |
4096
|
|
7FF93D1E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3256880309.00007FF93D1E0000.00000002.00000001.01000000.0000000B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93D1E0000
|
Size: |
4096
|
|
7FF93DBA2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3258161364.00007FF93DBA2000.00000008.00000001.01000000.0000000A.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93DBA2000
|
Size: |
204800
|
|
7FF93CB2D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3255991808.00007FF93CB2D000.00000002.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93CB2D000
|
Size: |
208896
|
|
1DDB4C9A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3123873968.000001DDB4C9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9A000
|
Size: |
8192
|
|
1DDB5361000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3128992468.000001DDB5361000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB5361000
|
Size: |
131072
|
|
2D38000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3004196396.0000000002D38000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D38000
|
Size: |
20480
|
|
7FF93DBA1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4095315638.00007FF93DBA1000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93DBA1000
|
Size: |
4096
|
|
1DDB3590000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4082150081.000001DDB3590000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB3590000
|
Size: |
16384
|
|
19278478000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3169127644.0000019278478000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19278478000
|
Size: |
49152
|
|
1F401F97000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3251332708.000001F401F97000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401F97000
|
Size: |
176128
|
|
7FF93CB00000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4090250485.00007FF93CB00000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB00000
|
Size: |
16384
|
|
7FF93D6B3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3174908789.00007FF93D6B3000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6B3000
|
Size: |
12288
|
|
7FF95DD50000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3177387424.00007FF95DD50000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95DD50000
|
Size: |
4096
|
|
1DDB52C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3129331050.000001DDB52C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB52C0000
|
Size: |
69632
|
|
7FF950BDA000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096319904.00007FF950BDA000.00000002.00000001.01000000.00000019.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF950BDA000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3120000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3007800875.0000000003120000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3120000
|
Size: |
4096
|
|
1F401FD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3252275662.000001F401FD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FD4000
|
Size: |
12288
|
|
7FF6ACD3A000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4086305214.00007FF6ACD3A000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6ACD3A000
|
Size: |
69632
|
|
7FF6ACD4B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3253217856.00007FF6ACD4B000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF6ACD4B000
|
Size: |
12288
|
|
7FF93B8A0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4086673910.00007FF93B8A0000.00000002.00000001.01000000.0000001F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93B8A0000
|
Size: |
4096
|
|
2D3C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3005442219.0000000002D3C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D3C000
|
Size: |
4096
|
|
7FF93BFF2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3171096150.00007FF93BFF2000.00000002.00000001.01000000.00000016.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BFF2000
|
Size: |
241664
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1DDB4C93000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3142270709.000001DDB4C93000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C93000
|
Size: |
57344
|
|
1DDB4CB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127410139.000001DDB4CB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB4000
|
Size: |
8192
|
|
7FF9610C1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3177488120.00007FF9610C1000.00000020.00000001.01000000.00000008.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF9610C1000
|
Size: |
12288
|
|
2D32000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3004691881.0000000002D32000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D32000
|
Size: |
24576
|
|
3238000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3007965807.0000000003238000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3238000
|
Size: |
61440
|
|
7FF6ACD4B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3169925143.00007FF6ACD4B000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF6ACD4B000
|
Size: |
12288
|
|
7FF950BDA000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176445737.00007FF950BDA000.00000002.00000001.01000000.00000019.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF950BDA000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93BD3A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4087353703.00007FF93BD3A000.00000004.00000001.01000000.0000001F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93BD3A000
|
Size: |
8192
|
|
7FF93BDA1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3170418437.00007FF93BDA1000.00000020.00000001.01000000.0000001B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93BDA1000
|
Size: |
548864
|
|
7FF93DCEE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3258393377.00007FF93DCEE000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DCEE000
|
Size: |
393216
|
|
7FF93D46B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3174571972.00007FF93D46B000.00000002.00000001.01000000.0000000B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93D46B000
|
Size: |
2273280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93D6BE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3175009795.00007FF93D6BE000.00000002.00000001.01000000.0000000B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93D6BE000
|
Size: |
475136
|
|
1DDB532A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4083835158.000001DDB532A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB532A000
|
Size: |
12288
|
|
7FF93C5E1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4089710050.00007FF93C5E1000.00000020.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93C5E1000
|
Size: |
3526656
|
|
7FF957E00000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4097699116.00007FF957E00000.00000002.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957E00000
|
Size: |
4096
|
|
1DDB4CA3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127142438.000001DDB4CA3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CA3000
|
Size: |
4096
|
|
7FF93BDA1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4087739986.00007FF93BDA1000.00000020.00000001.01000000.0000001B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93BDA1000
|
Size: |
548864
|
|
7FF93DD4E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3175674928.00007FF93DD4E000.00000004.00000001.01000000.00000007.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93DD4E000
|
Size: |
40960
|
|
1F401FCF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3250242398.000001F401FCF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FCF000
|
Size: |
12288
|
|
7FF93D188000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3173836712.00007FF93D188000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D188000
|
Size: |
4096
|
|
1DDB4C81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3123892444.000001DDB4C81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C81000
|
Size: |
24576
|
|
1DDB4C92000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127278989.000001DDB4C92000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C92000
|
Size: |
4096
|
|
1DDB4CB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125575496.000001DDB4CB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB5000
|
Size: |
4096
|
|
7FF95D9C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3177300569.00007FF95D9C0000.00000002.00000001.01000000.0000000D.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95D9C0000
|
Size: |
4096
|
|
7FF957A71000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3259423967.00007FF957A71000.00000020.00000001.01000000.00000015.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF957A71000
|
Size: |
147456
|
|
3248000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.3007568388.0000000003248000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3248000
|
Size: |
53248
|
|
7FF93BD70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3253592067.00007FF93BD70000.00000002.00000001.01000000.0000001C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BD70000
|
Size: |
4096
|
|
84F9F84000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3168761644.00000084F9F84000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
84F9F84000
|
Size: |
49152
|
|
3214000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3007883531.0000000003214000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3214000
|
Size: |
86016
|
|
7FF9586BE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4098424694.00007FF9586BE000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9586BE000
|
Size: |
8192
|
|
7FF93BE6B000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3170565106.00007FF93BE6B000.00000008.00000001.01000000.0000001B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93BE6B000
|
Size: |
4096
|
|
7FF93DBD4000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3258201137.00007FF93DBD4000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93DBD4000
|
Size: |
4096
|
|
1DDB4C9B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125716489.000001DDB4C9B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9B000
|
Size: |
4096
|
|
1DDB4CA3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125457436.000001DDB4CA3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CA3000
|
Size: |
36864
|
|
7FF93CB15000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4090465232.00007FF93CB15000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB15000
|
Size: |
4096
|
|
7FF6AC860000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4085600553.00007FF6AC860000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6AC860000
|
Size: |
4096
|
|
1DDB4C9A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3142375286.000001DDB4C9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9A000
|
Size: |
4096
|
|
1DDB4CB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3123993650.000001DDB4CB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB5000
|
Size: |
4096
|
|
7FF6AC861000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4085634750.00007FF6AC861000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF6AC861000
|
Size: |
2248704
|
|
7FF93C511000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3171745010.00007FF93C511000.00000008.00000001.01000000.00000013.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93C511000
|
Size: |
16384
|
|
1DDB55A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4084831570.000001DDB55A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB55A6000
|
Size: |
4096
|
|
19278260000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3168933820.0000019278260000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19278260000
|
Size: |
4096
|
|
7FF9610C7000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3177526578.00007FF9610C7000.00000004.00000001.01000000.00000008.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF9610C7000
|
Size: |
4096
|
|
7FF93BD71000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3253618172.00007FF93BD71000.00000020.00000001.01000000.0000001C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93BD71000
|
Size: |
106496
|
|
7FF6ACD50000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3169992503.00007FF6ACD50000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF6ACD50000
|
Size: |
8192
|
|
7FF93BD25000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4087260834.00007FF93BD25000.00000008.00000001.01000000.0000001F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93BD25000
|
Size: |
45056
|
|
2ABF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3004972758.0000000002ABF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2ABF000
|
Size: |
4096
|
|
7FF6ACD3A000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000000.3118593549.00007FF6ACD3A000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6ACD3A000
|
Size: |
147456
|
|
7FF93BE68000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3170535337.00007FF93BE68000.00000004.00000001.01000000.0000001B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93BE68000
|
Size: |
12288
|
|
7FF9610C8000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3260660269.00007FF9610C8000.00000002.00000001.01000000.00000008.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9610C8000
|
Size: |
8192
|
|
7FF93D17E000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3256606872.00007FF93D17E000.00000008.00000001.01000000.0000000C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D17E000
|
Size: |
4096
|
|
7FF93C41E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3171650373.00007FF93C41E000.00000002.00000001.01000000.00000013.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C41E000
|
Size: |
995328
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1DDB4C81000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125530964.000001DDB4C81000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C81000
|
Size: |
24576
|
|
7FF93D6A6000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3257451304.00007FF93D6A6000.00000008.00000001.01000000.0000000B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D6A6000
|
Size: |
4096
|
|
7FF957AC4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4097618190.00007FF957AC4000.00000002.00000001.01000000.00000011.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957AC4000
|
Size: |
12288
|
|
7FF944036000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176282328.00007FF944036000.00000002.00000001.01000000.00000012.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF944036000
|
Size: |
45056
|
|
7FF93BE80000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4088014699.00007FF93BE80000.00000002.00000001.01000000.00000017.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BE80000
|
Size: |
4096
|
|
7FF957E01000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4097785949.00007FF957E01000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF957E01000
|
Size: |
36864
|
|
7FF6ACA86000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000000.3118368978.00007FF6ACA86000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6ACA86000
|
Size: |
2834432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF93F121000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4095998085.00007FF93F121000.00000020.00000001.01000000.0000001A.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93F121000
|
Size: |
8192
|
|
7FF93D187000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3256708580.00007FF93D187000.00000008.00000001.01000000.0000000C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D187000
|
Size: |
4096
|
|
7FF93CB1A000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3172816987.00007FF93CB1A000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB1A000
|
Size: |
8192
|
|
7FF956DC5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176648227.00007FF956DC5000.00000002.00000001.01000000.00000018.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF956DC5000
|
Size: |
8192
|
|
7FF93D198000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3256785070.00007FF93D198000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D198000
|
Size: |
8192
|
|
7FF93D17F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4091535707.00007FF93D17F000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D17F000
|
Size: |
20480
|
|
7FF957AB1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4097288961.00007FF957AB1000.00000020.00000001.01000000.00000011.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF957AB1000
|
Size: |
49152
|
|
7FF6ACD60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4086595294.00007FF6ACD60000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6ACD60000
|
Size: |
372736
|
|
7FF93CB61000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3256057829.00007FF93CB61000.00000020.00000001.01000000.0000000C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93CB61000
|
Size: |
3895296
|
|
7FF957A95000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096783705.00007FF957A95000.00000002.00000001.01000000.00000015.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957A95000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93DD58000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3258487319.00007FF93DD58000.00000008.00000001.01000000.00000007.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93DD58000
|
Size: |
4096
|
|
7FF93BDA0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3253736167.00007FF93BDA0000.00000002.00000001.01000000.0000001B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BDA0000
|
Size: |
4096
|
|
7FF93DBA2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4095339371.00007FF93DBA2000.00000008.00000001.01000000.0000000A.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93DBA2000
|
Size: |
204800
|
|
1DDB4C9B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3142297706.000001DDB4C9B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9B000
|
Size: |
32768
|
|
7FF957A65000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096644792.00007FF957A65000.00000002.00000001.01000000.0000001E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957A65000
|
Size: |
16384
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93C040000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3254340209.00007FF93C040000.00000002.00000001.01000000.00000014.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C040000
|
Size: |
4096
|
|
19278484000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3166809720.0000019278484000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19278484000
|
Size: |
4096
|
|
7FF9610C8000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4099261970.00007FF9610C8000.00000002.00000001.01000000.00000008.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9610C8000
|
Size: |
8192
|
|
7FF6AC861000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000000.3118179946.00007FF6AC861000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF6AC861000
|
Size: |
2248704
|
|
7FF93C039000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3254281097.00007FF93C039000.00000002.00000001.01000000.00000016.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C039000
|
Size: |
4096
|
|
7FF6ACD60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000000.3118625867.00007FF6ACD60000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6ACD60000
|
Size: |
372736
|
|
7FF93CF19000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3173443311.00007FF93CF19000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93CF19000
|
Size: |
2461696
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93C93E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3255467408.00007FF93C93E000.00000002.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C93E000
|
Size: |
1843200
|
|
7FF93CB16000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3172745770.00007FF93CB16000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB16000
|
Size: |
4096
|
|
7FF93D185000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4091613963.00007FF93D185000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D185000
|
Size: |
8192
|
|
7FF93CF19000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4091209691.00007FF93CF19000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93CF19000
|
Size: |
2461696
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF6AC861000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000000.3165229450.00007FF6AC861000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
22
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF6AC861000
|
Size: |
2248704
|
|
7FF944043000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096160060.00007FF944043000.00000002.00000001.01000000.00000012.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF944043000
|
Size: |
94208
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1F403BDF000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000018.00000002.3252523482.000001F403BDF000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
1F403BDF000
|
Size: |
4096
|
|
1DDB54CB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4084439337.000001DDB54CB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB54CB000
|
Size: |
12288
|
|
7FF94405A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3259026828.00007FF94405A000.00000004.00000001.01000000.00000012.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF94405A000
|
Size: |
4096
|
|
3231000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3007925813.0000000003231000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3231000
|
Size: |
24576
|
|
1DDB4969000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4082675025.000001DDB4969000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4969000
|
Size: |
24576
|
|
7FF95DD51000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3260434666.00007FF95DD51000.00000020.00000001.01000000.00000009.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF95DD51000
|
Size: |
20480
|
|
1DDB4C88000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3123892444.000001DDB4C88000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C88000
|
Size: |
32768
|
|
1DDB4C8C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125753209.000001DDB4C8C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C8C000
|
Size: |
20480
|
|
19278498000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3169221098.0000019278498000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19278498000
|
Size: |
16384
|
|
309C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3007778965.000000000309C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
309C000
|
Size: |
16384
|
|
7FF93CB61000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4090796556.00007FF93CB61000.00000020.00000001.01000000.0000000C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93CB61000
|
Size: |
3895296
|
|
7FF957E01000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3177069568.00007FF957E01000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF957E01000
|
Size: |
36864
|
|
7FF9610C4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4099027666.00007FF9610C4000.00000002.00000001.01000000.00000008.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9610C4000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93CB1C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4090621728.00007FF93CB1C000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB1C000
|
Size: |
36864
|
|
1F401FF7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3250539269.000001F401FF7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FF7000
|
Size: |
8192
|
|
7FF93F123000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096019479.00007FF93F123000.00000002.00000001.01000000.0000001A.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93F123000
|
Size: |
131072
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93BEFA000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3254059897.00007FF93BEFA000.00000002.00000001.01000000.00000017.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BEFA000
|
Size: |
163840
|
|
7FF93DD70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3258575445.00007FF93DD70000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DD70000
|
Size: |
4096
|
|
192784A3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3167888458.00000192784A3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
192784A3000
|
Size: |
4096
|
|
7FF9586B1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4098249698.00007FF9586B1000.00000020.00000001.01000000.00000006.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF9586B1000
|
Size: |
32768
|
|
192784A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3167888458.00000192784A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
192784A6000
|
Size: |
8192
|
|
7FF93D184000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3173775061.00007FF93D184000.00000008.00000001.01000000.0000000C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D184000
|
Size: |
4096
|
|
2AF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3004997957.0000000002AF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2AF0000
|
Size: |
20480
|
|
7FF93D17E000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4091500493.00007FF93D17E000.00000008.00000001.01000000.0000000C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D17E000
|
Size: |
4096
|
|
7FF93D6B8000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4094825563.00007FF93D6B8000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6B8000
|
Size: |
12288
|
|
2D3C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3004435245.0000000002D3C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D3C000
|
Size: |
4096
|
|
522E000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3008207583.000000000522E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
522E000
|
Size: |
8192
|
|
7FF956DC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096458026.00007FF956DC0000.00000002.00000001.01000000.00000018.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF956DC0000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93DD71000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4095692306.00007FF93DD71000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93DD71000
|
Size: |
188416
|
|
7FF956DC5000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096537889.00007FF956DC5000.00000002.00000001.01000000.00000018.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF956DC5000
|
Size: |
8192
|
|
2D29000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3004636977.0000000002D29000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D29000
|
Size: |
4096
|
|
7FF93CB2D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3172924055.00007FF93CB2D000.00000002.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93CB2D000
|
Size: |
208896
|
|
7FF6ACD55000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3170046340.00007FF6ACD55000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF6ACD55000
|
Size: |
8192
|
|
52AE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3008253393.00000000052AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52AE000
|
Size: |
8192
|
|
7FF6AC860000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3169451981.00007FF6AC860000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6AC860000
|
Size: |
4096
|
|
7FF93C218000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4088826054.00007FF93C218000.00000020.00000001.01000000.00000013.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93C218000
|
Size: |
2121728
|
|
7FF6ACA86000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3169651614.00007FF6ACA86000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6ACA86000
|
Size: |
2834432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1DDB4CB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3142176112.000001DDB4CB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB4000
|
Size: |
8192
|
|
1F401FF8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3250674599.000001F401FF8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FF8000
|
Size: |
4096
|
|
7FF93DD71000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3258601849.00007FF93DD71000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93DD71000
|
Size: |
188416
|
|
2D42000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3005463534.0000000002D42000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D42000
|
Size: |
8192
|
|
7FF93C93E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3172356309.00007FF93C93E000.00000002.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C93E000
|
Size: |
1843200
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2D18000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3004457262.0000000002D18000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D18000
|
Size: |
20480
|
|
7FF956DC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3259309603.00007FF956DC0000.00000002.00000001.01000000.00000018.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF956DC0000
|
Size: |
12288
|
|
7FF95D9C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3260255851.00007FF95D9C0000.00000002.00000001.01000000.0000000D.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95D9C0000
|
Size: |
4096
|
|
7FF93CB0A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3255661293.00007FF93CB0A000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB0A000
|
Size: |
12288
|
|
1DDB5659000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4084831570.000001DDB5659000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB5659000
|
Size: |
32768
|
|
27FE000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3004887594.00000000027FE000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
27FE000
|
Size: |
8192
|
|
1F403955000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3252407379.000001F403955000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F403955000
|
Size: |
4096
|
|
2D2B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3004324266.0000000002D2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D2B000
|
Size: |
53248
|
|
7FF957AA0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3259500064.00007FF957AA0000.00000002.00000001.01000000.00000015.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957AA0000
|
Size: |
16384
|
|
7FF94405A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4096209114.00007FF94405A000.00000004.00000001.01000000.00000012.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF94405A000
|
Size: |
4096
|
|
7FF950BDE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176498588.00007FF950BDE000.00000002.00000001.01000000.00000019.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF950BDE000
|
Size: |
8192
|
|
7FF950BDE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096372809.00007FF950BDE000.00000002.00000001.01000000.00000019.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF950BDE000
|
Size: |
8192
|
|
7FF93C519000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3171797523.00007FF93C519000.00000002.00000001.01000000.00000013.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C519000
|
Size: |
192512
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF95DD5A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3260501515.00007FF95DD5A000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95DD5A000
|
Size: |
8192
|
|
2CF4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3005208277.0000000002CF4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2CF4000
|
Size: |
81920
|
|
7FF93CB60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4090762736.00007FF93CB60000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93CB60000
|
Size: |
4096
|
|
7FF93BE70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3170629164.00007FF93BE70000.00000002.00000001.01000000.0000001B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BE70000
|
Size: |
40960
|
|
1DDB4CB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125438729.000001DDB4CB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB5000
|
Size: |
4096
|
|
7FF957E0E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4098058264.00007FF957E0E000.00000002.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957E0E000
|
Size: |
8192
|
|
1DDB4C9A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127337990.000001DDB4C9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9A000
|
Size: |
20480
|
|
7FF93CB0A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4090317953.00007FF93CB0A000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB0A000
|
Size: |
12288
|
|
1DDB5560000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4084439337.000001DDB5560000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB5560000
|
Size: |
282624
|
|
7FF93BF23000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3170962965.00007FF93BF23000.00000002.00000001.01000000.00000017.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BF23000
|
Size: |
40960
|
|
7FF93BD96000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3170336552.00007FF93BD96000.00000004.00000001.01000000.0000001C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93BD96000
|
Size: |
4096
|
|
7FF93D741000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4094979872.00007FF93D741000.00000020.00000001.01000000.0000000A.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93D741000
|
Size: |
3272704
|
|
7FF9586BE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3177272357.00007FF9586BE000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9586BE000
|
Size: |
8192
|
|
7FF6ACD60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000000.3249388555.00007FF6ACD60000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
24
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6ACD60000
|
Size: |
372736
|
|
7FF9586BE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3260223064.00007FF9586BE000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9586BE000
|
Size: |
8192
|
|
7FF93D69F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3257371072.00007FF93D69F000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D69F000
|
Size: |
12288
|
|
7FF93C519000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4089396385.00007FF93C519000.00000002.00000001.01000000.00000013.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C519000
|
Size: |
192512
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1DDB4C9A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3142347907.000001DDB4C9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9A000
|
Size: |
4096
|
|
1DDB4C9A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127571385.000001DDB4C9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9A000
|
Size: |
4096
|
|
7FF6ACD52000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3170016582.00007FF6ACD52000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6ACD52000
|
Size: |
12288
|
|
7FF93DBDE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3175501801.00007FF93DBDE000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DBDE000
|
Size: |
147456
|
|
19278486000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3168102258.0000019278486000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19278486000
|
Size: |
90112
|
|
322A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.3007568388.000000000322A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
322A000
|
Size: |
24576
|
|
7FF956DB0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176525155.00007FF956DB0000.00000002.00000001.01000000.00000018.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF956DB0000
|
Size: |
4096
|
|
7FF93D172000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3173713772.00007FF93D172000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D172000
|
Size: |
49152
|
|
7FF93BD4A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4087495148.00007FF93BD4A000.00000002.00000001.01000000.0000001F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BD4A000
|
Size: |
110592
|
|
1DDB4CB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3126366663.000001DDB4CB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB4000
|
Size: |
8192
|
|
84FA4FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3168837791.00000084FA4FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
84FA4FE000
|
Size: |
8192
|
|
7FF93D6BE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4094892078.00007FF93D6BE000.00000002.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93D6BE000
|
Size: |
475136
|
|
1927845E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3168656346.000001927845E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1927845E000
|
Size: |
81920
|
|
7FF93CB61000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3172998173.00007FF93CB61000.00000020.00000001.01000000.0000000C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93CB61000
|
Size: |
3895296
|
|
7FF93DD59000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4095621471.00007FF93DD59000.00000004.00000001.01000000.00000007.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93DD59000
|
Size: |
4096
|
|
2D0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3004324266.0000000002D0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D0A000
|
Size: |
77824
|
|
7FF93DDBD000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3175975653.00007FF93DDBD000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DDBD000
|
Size: |
24576
|
|
1F401FF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3251261929.000001F401FF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FF0000
|
Size: |
28672
|
|
7FF93C040000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3171202819.00007FF93C040000.00000002.00000001.01000000.00000014.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C040000
|
Size: |
4096
|
|
7FF93F121000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3258774807.00007FF93F121000.00000020.00000001.01000000.0000001A.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93F121000
|
Size: |
8192
|
|
7FF93C41E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3254809753.00007FF93C41E000.00000002.00000001.01000000.00000013.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C41E000
|
Size: |
995328
|
|
7FF93D6A6000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3174850774.00007FF93D6A6000.00000008.00000001.01000000.0000000B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D6A6000
|
Size: |
4096
|
|
7FF957AC4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3259664734.00007FF957AC4000.00000002.00000001.01000000.00000011.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957AC4000
|
Size: |
12288
|
|
7FF93BE70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4087980551.00007FF93BE70000.00000002.00000001.01000000.0000001B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BE70000
|
Size: |
40960
|
|
7FF93F121000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3176074809.00007FF93F121000.00000020.00000001.01000000.0000001A.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93F121000
|
Size: |
8192
|
|
7FF93CB14000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3255764668.00007FF93CB14000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB14000
|
Size: |
4096
|
|
7FF6ACD5D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3170132916.00007FF6ACD5D000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF6ACD5D000
|
Size: |
12288
|
|
7FF93C02F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4088404002.00007FF93C02F000.00000002.00000001.01000000.00000016.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C02F000
|
Size: |
36864
|
|
7FF93C0DC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3171335645.00007FF93C0DC000.00000002.00000001.01000000.00000014.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C0DC000
|
Size: |
24576
|
|
7FF93CB0D000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4090349381.00007FF93CB0D000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB0D000
|
Size: |
12288
|
|
7FF95D9CF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3260333562.00007FF95D9CF000.00000002.00000001.01000000.0000000D.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95D9CF000
|
Size: |
28672
|
|
34BE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3008081663.00000000034BE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
34BE000
|
Size: |
8192
|
|
7FF93BD8B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3253648850.00007FF93BD8B000.00000002.00000001.01000000.0000001C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BD8B000
|
Size: |
45056
|
|
7FF93CB10000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3172639497.00007FF93CB10000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB10000
|
Size: |
8192
|
|
7FF93DC10000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4095430644.00007FF93DC10000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DC10000
|
Size: |
4096
|
|
7FF93BD24000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4087225506.00007FF93BD24000.00000004.00000001.01000000.0000001F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93BD24000
|
Size: |
4096
|
|
7FF93D740000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3257729559.00007FF93D740000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93D740000
|
Size: |
4096
|
|
7FF93BD3F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4087414922.00007FF93BD3F000.00000004.00000001.01000000.0000001F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93BD3F000
|
Size: |
8192
|
|
7FF93DD5B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4095642423.00007FF93DD5B000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DD5B000
|
Size: |
61440
|
|
7FF93DCEE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3175629660.00007FF93DCEE000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DCEE000
|
Size: |
393216
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found strings which match to known social media urls |
Networking |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1DDB4C9C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125575496.000001DDB4C9C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9C000
|
Size: |
12288
|
|
7FF93BD71000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4087559809.00007FF93BD71000.00000020.00000001.01000000.0000001C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93BD71000
|
Size: |
106496
|
|
7FF93C0CA000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3171285759.00007FF93C0CA000.00000002.00000001.01000000.00000014.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C0CA000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93F120000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176052966.00007FF93F120000.00000002.00000001.01000000.0000001A.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93F120000
|
Size: |
4096
|
|
2D33000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3005364310.0000000002D33000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D33000
|
Size: |
20480
|
|
1DDB4670000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4082400095.000001DDB4670000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4670000
|
Size: |
266240
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF93BF23000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4088163312.00007FF93BF23000.00000002.00000001.01000000.00000017.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BF23000
|
Size: |
40960
|
|
1DDB5395000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3129105713.000001DDB5395000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB5395000
|
Size: |
65536
|
|
7FF943FE0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176200761.00007FF943FE0000.00000002.00000001.01000000.00000012.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF943FE0000
|
Size: |
4096
|
|
7FF93BE81000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4088044404.00007FF93BE81000.00000020.00000001.01000000.00000017.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93BE81000
|
Size: |
495616
|
|
2C6E000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3005160840.0000000002C6E000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C6E000
|
Size: |
8192
|
|
7FF9586BD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3260188613.00007FF9586BD000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF9586BD000
|
Size: |
4096
|
|
1DDB5666000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4084831570.000001DDB5666000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB5666000
|
Size: |
102400
|
|
7FF957E0A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4097904725.00007FF957E0A000.00000002.00000001.01000000.0000000E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957E0A000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF9610C7000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3260625569.00007FF9610C7000.00000004.00000001.01000000.00000008.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF9610C7000
|
Size: |
4096
|
|
7FF6ACD52000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3253432007.00007FF6ACD52000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6ACD52000
|
Size: |
12288
|
|
1DDB4C9A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4083225011.000001DDB4C9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9A000
|
Size: |
4096
|
|
19278434000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3168985612.0000019278434000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19278434000
|
Size: |
77824
|
|
1927A0FF000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000016.00000002.3169347151.000001927A0FF000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
1927A0FF000
|
Size: |
4096
|
|
2D3C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3004324266.0000000002D3C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D3C000
|
Size: |
4096
|
|
1DDB4C9A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3126401199.000001DDB4C9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9A000
|
Size: |
4096
|
|
2DF0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3007734368.0000000002DF0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2DF0000
|
Size: |
4096
|
|
1DDB4C80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4083225011.000001DDB4C80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C80000
|
Size: |
77824
|
|
7FF95D9D7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3260371649.00007FF95D9D7000.00000002.00000001.01000000.0000000D.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95D9D7000
|
Size: |
12288
|
|
7FF93C5D4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3255161698.00007FF93C5D4000.00000002.00000001.01000000.00000010.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C5D4000
|
Size: |
32768
|
|
7FF93BD96000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3253679066.00007FF93BD96000.00000004.00000001.01000000.0000001C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93BD96000
|
Size: |
4096
|
|
3190000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3007835872.0000000003190000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3190000
|
Size: |
12288
|
|
7FF93C040000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4088454900.00007FF93C040000.00000002.00000001.01000000.00000014.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C040000
|
Size: |
4096
|
|
19278448000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3169043289.0000019278448000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19278448000
|
Size: |
20480
|
|
1DDB495C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4082675025.000001DDB495C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB495C000
|
Size: |
49152
|
|
7FF950BD1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4096293514.00007FF950BD1000.00000020.00000001.01000000.00000019.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF950BD1000
|
Size: |
36864
|
|
1F401FFB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3250674599.000001F401FFB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FFB000
|
Size: |
8192
|
|
7FF93C511000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4089336493.00007FF93C511000.00000008.00000001.01000000.00000013.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93C511000
|
Size: |
16384
|
|
7FF93D6A6000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4092827262.00007FF93D6A6000.00000008.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D6A6000
|
Size: |
4096
|
|
7FF93D6B6000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4094798825.00007FF93D6B6000.00000008.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D6B6000
|
Size: |
8192
|
|
7FF957AB0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176824552.00007FF957AB0000.00000002.00000001.01000000.00000011.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957AB0000
|
Size: |
4096
|
|
7FF9610C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4098937868.00007FF9610C0000.00000002.00000001.01000000.00000008.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9610C0000
|
Size: |
4096
|
|
7FF957E0A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3177092336.00007FF957E0A000.00000002.00000001.01000000.0000000E.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957E0A000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1DDB4C70000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4083225011.000001DDB4C70000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C70000
|
Size: |
4096
|
|
1DDB4C9A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3123993650.000001DDB4C9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9A000
|
Size: |
73728
|
|
7FF95D9D7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3177366542.00007FF95D9D7000.00000002.00000001.01000000.0000000D.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95D9D7000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF9586B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3177142708.00007FF9586B0000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9586B0000
|
Size: |
4096
|
|
7FF956DB0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3259244348.00007FF956DB0000.00000002.00000001.01000000.00000018.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF956DB0000
|
Size: |
4096
|
|
BEB9DFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4081079316.000000BEB9DFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BEB9DFE000
|
Size: |
8192
|
|
1F404AA0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3252557052.000001F404AA0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F404AA0000
|
Size: |
4096
|
|
3248000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.3007456185.0000000003248000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3248000
|
Size: |
53248
|
|
7FF9586B9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3260154674.00007FF9586B9000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9586B9000
|
Size: |
12288
|
|
7FF93CB16000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4090497114.00007FF93CB16000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB16000
|
Size: |
4096
|
|
7FF6ACD50000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4086420514.00007FF6ACD50000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF6ACD50000
|
Size: |
8192
|
|
7FF93C5CF000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3255110357.00007FF93C5CF000.00000008.00000001.01000000.00000010.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93C5CF000
|
Size: |
12288
|
|
7FF957AC3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3259624871.00007FF957AC3000.00000004.00000001.01000000.00000011.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF957AC3000
|
Size: |
4096
|
|
7FF956DB1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3259274368.00007FF956DB1000.00000020.00000001.01000000.00000018.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF956DB1000
|
Size: |
61440
|
|
1DDB4CB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3142246713.000001DDB4CB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB4000
|
Size: |
8192
|
|
1DDB4CB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3142297706.000001DDB4CB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB4000
|
Size: |
8192
|
|
1DDB4CA3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3142094889.000001DDB4CA3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CA3000
|
Size: |
4096
|
|
7FF9610C7000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4099220846.00007FF9610C7000.00000004.00000001.01000000.00000008.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF9610C7000
|
Size: |
4096
|
|
7FF93BEFA000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3170869722.00007FF93BEFA000.00000002.00000001.01000000.00000017.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BEFA000
|
Size: |
163840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF957A6A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096692176.00007FF957A6A000.00000002.00000001.01000000.0000001E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957A6A000
|
Size: |
16384
|
|
7FF93C02D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4088373592.00007FF93C02D000.00000004.00000001.01000000.00000016.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93C02D000
|
Size: |
4096
|
|
7FF950BDD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3176470016.00007FF950BDD000.00000004.00000001.01000000.00000019.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF950BDD000
|
Size: |
4096
|
|
1DDB4C8C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127462705.000001DDB4C8C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C8C000
|
Size: |
24576
|
|
7FF93DD4E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3258452956.00007FF93DD4E000.00000004.00000001.01000000.00000007.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93DD4E000
|
Size: |
40960
|
|
7FF93F144000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3258841249.00007FF93F144000.00000002.00000001.01000000.0000001A.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93F144000
|
Size: |
8192
|
|
1DDB55E3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4084831570.000001DDB55E3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB55E3000
|
Size: |
73728
|
|
2D2B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3005342149.0000000002D2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D2B000
|
Size: |
28672
|
|
1DDB4CB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125365396.000001DDB4CB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB5000
|
Size: |
4096
|
|
1DDB5494000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4084439337.000001DDB5494000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB5494000
|
Size: |
212992
|
|
7FF93DDBD000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4095950129.00007FF93DDBD000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DDBD000
|
Size: |
24576
|
|
1DDB52BE000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4083613409.000001DDB52BE000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB52BE000
|
Size: |
438272
|
|
1DDB4CAF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125457436.000001DDB4CAF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CAF000
|
Size: |
16384
|
|
7FF93C0DB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3171312966.00007FF93C0DB000.00000004.00000001.01000000.00000014.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93C0DB000
|
Size: |
4096
|
|
7FF93BDA1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3253760946.00007FF93BDA1000.00000020.00000001.01000000.0000001B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93BDA1000
|
Size: |
548864
|
|
7FF93CB17000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4090528152.00007FF93CB17000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB17000
|
Size: |
4096
|
|
7FF93C5E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3172024840.00007FF93C5E0000.00000002.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C5E0000
|
Size: |
4096
|
|
1DDB4C94000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127547612.000001DDB4C94000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C94000
|
Size: |
28672
|
|
1F401FFB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3250539269.000001F401FFB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FFB000
|
Size: |
8192
|
|
7FF93CB2D000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4090711676.00007FF93CB2D000.00000002.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93CB2D000
|
Size: |
208896
|
|
7FF957E00000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176996860.00007FF957E00000.00000002.00000001.01000000.0000000E.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957E00000
|
Size: |
4096
|
|
7FF956DC3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3176610687.00007FF956DC3000.00000004.00000001.01000000.00000018.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF956DC3000
|
Size: |
4096
|
|
1DDB4C9A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3142142985.000001DDB4C9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9A000
|
Size: |
4096
|
|
7FF6ACA86000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000000.3165382566.00007FF6ACA86000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
22
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6ACA86000
|
Size: |
2834432
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1F401F80000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3252129635.000001F401F80000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401F80000
|
Size: |
12288
|
|
1DDB5441000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4084058069.000001DDB5441000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB5441000
|
Size: |
335872
|
|
1DDB4C92000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3126451794.000001DDB4C92000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C92000
|
Size: |
12288
|
|
7FF9610C8000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3177545081.00007FF9610C8000.00000002.00000001.01000000.00000008.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9610C8000
|
Size: |
8192
|
|
7FF9610C1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3260566712.00007FF9610C1000.00000020.00000001.01000000.00000008.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF9610C1000
|
Size: |
12288
|
|
7FF93BE70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3253946877.00007FF93BE70000.00000002.00000001.01000000.0000001B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BE70000
|
Size: |
40960
|
|
5F0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3004832135.00000000005F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
5F0000
|
Size: |
4096
|
|
7FF95DD51000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4098705546.00007FF95DD51000.00000020.00000001.01000000.00000009.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF95DD51000
|
Size: |
20480
|
|
7FF95D9C1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3177319939.00007FF95D9C1000.00000020.00000001.01000000.0000000D.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF95D9C1000
|
Size: |
57344
|
|
7FF6ACD4E000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4086388761.00007FF6ACD4E000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6ACD4E000
|
Size: |
8192
|
|
7FF95D9D7000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4098605466.00007FF95D9D7000.00000002.00000001.01000000.0000000D.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95D9D7000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
52C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3004773466.000000000052C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52C000
|
Size: |
16384
|
|
192784A6000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3167376076.00000192784A6000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
192784A6000
|
Size: |
8192
|
|
2A3F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3004922549.0000000002A3F000.00000004.00000001.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
2A3F000
|
Size: |
4096
|
|
7FF93D6A2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4092695077.00007FF93D6A2000.00000008.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D6A2000
|
Size: |
8192
|
|
1DDB5382000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3128992468.000001DDB5382000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB5382000
|
Size: |
69632
|
|
7FF93BF23000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3254095663.00007FF93BF23000.00000002.00000001.01000000.00000017.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BF23000
|
Size: |
40960
|
|
1DDB4674000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3123481347.000001DDB4674000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4674000
|
Size: |
536576
|
|
7FF93D696000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3257312801.00007FF93D696000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D696000
|
Size: |
8192
|
|
7FF93C551000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3255021412.00007FF93C551000.00000020.00000001.01000000.00000010.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93C551000
|
Size: |
372736
|
|
1F401FF7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3250473439.000001F401FF7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FF7000
|
Size: |
4096
|
|
2BE4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3005098507.0000000002BE4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2BE4000
|
Size: |
24576
|
|
19278447000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3168710019.0000019278447000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19278447000
|
Size: |
24576
|
|
7FF957AB1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3176847099.00007FF957AB1000.00000020.00000001.01000000.00000011.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF957AB1000
|
Size: |
49152
|
|
51AE000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3008154498.00000000051AE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
51AE000
|
Size: |
8192
|
|
7FF93D187000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4091649178.00007FF93D187000.00000008.00000001.01000000.0000000C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D187000
|
Size: |
4096
|
|
7FF93C0F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3254513142.00007FF93C0F0000.00000002.00000001.01000000.00000013.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C0F0000
|
Size: |
4096
|
|
7FF93BF30000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4088190320.00007FF93BF30000.00000002.00000001.01000000.00000016.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BF30000
|
Size: |
4096
|
|
7FF9610C4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3177508058.00007FF9610C4000.00000002.00000001.01000000.00000008.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9610C4000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93CB04000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4090284566.00007FF93CB04000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB04000
|
Size: |
24576
|
|
7FF93DC10000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3175528177.00007FF93DC10000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DC10000
|
Size: |
4096
|
|
19278497000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3168356706.0000019278497000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19278497000
|
Size: |
20480
|
|
7FF6ACD3A000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000000.3249354473.00007FF6ACD3A000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
24
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6ACD3A000
|
Size: |
147456
|
|
7FF93CB0A000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3172570604.00007FF93CB0A000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB0A000
|
Size: |
12288
|
|
7FF93CB17000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3172768849.00007FF93CB17000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB17000
|
Size: |
4096
|
|
7FF93BE27000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3170489266.00007FF93BE27000.00000002.00000001.01000000.0000001B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BE27000
|
Size: |
266240
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93C515000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3171769100.00007FF93C515000.00000004.00000001.01000000.00000013.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93C515000
|
Size: |
4096
|
|
7FF93BF31000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3254145907.00007FF93BF31000.00000020.00000001.01000000.00000016.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93BF31000
|
Size: |
790528
|
|
BEB9BFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4080872873.000000BEB9BFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BEB9BFE000
|
Size: |
8192
|
|
7FF93CB18000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4090560890.00007FF93CB18000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB18000
|
Size: |
8192
|
|
7FF93D69F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4092581789.00007FF93D69F000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D69F000
|
Size: |
4096
|
|
7FF6ACD3A000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3253153261.00007FF6ACD3A000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6ACD3A000
|
Size: |
69632
|
|
1DDB7930000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4085504093.000001DDB7930000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB7930000
|
Size: |
73728
|
|
1F401FD7000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3251017922.000001F401FD7000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FD7000
|
Size: |
98304
|
|
7FF93BF31000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4088219640.00007FF93BF31000.00000020.00000001.01000000.00000016.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93BF31000
|
Size: |
790528
|
|
7FF93D1E1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3173975771.00007FF93D1E1000.00000020.00000001.01000000.0000000B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93D1E1000
|
Size: |
2662400
|
|
7FF957A70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096718593.00007FF957A70000.00000002.00000001.01000000.00000015.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957A70000
|
Size: |
4096
|
|
7FF957AB1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3259563857.00007FF957AB1000.00000020.00000001.01000000.00000011.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF957AB1000
|
Size: |
49152
|
|
19278320000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3168959983.0000019278320000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19278320000
|
Size: |
8192
|
|
7FF93CB1C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3172842744.00007FF93CB1C000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB1C000
|
Size: |
36864
|
|
83327FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3251904393.00000083327FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83327FD000
|
Size: |
12288
|
|
7FF93C02F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3254281097.00007FF93C02F000.00000002.00000001.01000000.00000016.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C02F000
|
Size: |
36864
|
|
7FF93CB0D000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3255686524.00007FF93CB0D000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB0D000
|
Size: |
12288
|
|
7FF93C550000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4089443826.00007FF93C550000.00000002.00000001.01000000.00000010.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C550000
|
Size: |
4096
|
|
7FF93C041000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3254369174.00007FF93C041000.00000020.00000001.01000000.00000014.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93C041000
|
Size: |
561152
|
|
1DDB532F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4083835158.000001DDB532F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB532F000
|
Size: |
409600
|
|
7FF93C039000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3171157121.00007FF93C039000.00000002.00000001.01000000.00000016.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C039000
|
Size: |
4096
|
|
1DDB4EA2000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4083476237.000001DDB4EA2000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DDB4EA2000
|
Size: |
118784
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF957AA0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176773001.00007FF957AA0000.00000002.00000001.01000000.00000015.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957AA0000
|
Size: |
16384
|
|
1F401FC2000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3251201564.000001F401FC2000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FC2000
|
Size: |
4096
|
|
7FF93BE6C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4087948206.00007FF93BE6C000.00000004.00000001.01000000.0000001B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93BE6C000
|
Size: |
12288
|
|
1DDB4770000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4082675025.000001DDB4770000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4770000
|
Size: |
69632
|
|
7FF93D18E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3173885084.00007FF93D18E000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D18E000
|
Size: |
20480
|
|
322E000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3007925813.000000000322E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
322E000
|
Size: |
8192
|
|
7FF9610C4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3260598256.00007FF9610C4000.00000002.00000001.01000000.00000008.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9610C4000
|
Size: |
12288
|
|
7FF93CB25000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3255939851.00007FF93CB25000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB25000
|
Size: |
24576
|
|
2D2B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3004636977.0000000002D2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D2B000
|
Size: |
53248
|
|
7FF93D184000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4091575725.00007FF93D184000.00000008.00000001.01000000.0000000C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D184000
|
Size: |
4096
|
|
1F401F84000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3252129635.000001F401F84000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401F84000
|
Size: |
77824
|
|
7FF93D741000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3175079124.00007FF93D741000.00000020.00000001.01000000.0000000A.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93D741000
|
Size: |
3272704
|
|
83329FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3251961224.00000083329FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83329FE000
|
Size: |
8192
|
|
2D1E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3005288528.0000000002D1E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D1E000
|
Size: |
45056
|
|
7FF6ACD55000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3253458042.00007FF6ACD55000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF6ACD55000
|
Size: |
8192
|
|
7FF93CB12000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3172669276.00007FF93CB12000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB12000
|
Size: |
8192
|
|
7FF9610C1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4098967785.00007FF9610C1000.00000020.00000001.01000000.00000008.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF9610C1000
|
Size: |
12288
|
|
7FF93D6BC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3257635777.00007FF93D6BC000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6BC000
|
Size: |
4096
|
|
7FF944036000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3258958800.00007FF944036000.00000002.00000001.01000000.00000012.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF944036000
|
Size: |
45056
|
|
7FF93D185000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3173796154.00007FF93D185000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D185000
|
Size: |
8192
|
|
7FF93C0DC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3254484933.00007FF93C0DC000.00000002.00000001.01000000.00000014.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C0DC000
|
Size: |
24576
|
|
56C000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3004807839.000000000056C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
56C000
|
Size: |
16384
|
|
7FF93CB2B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4090686634.00007FF93CB2B000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB2B000
|
Size: |
4096
|
|
2D0E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3005260061.0000000002D0E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D0E000
|
Size: |
40960
|
|
192784AA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3167888458.00000192784AA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
192784AA000
|
Size: |
4096
|
|
7FF93CB15000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3172721414.00007FF93CB15000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB15000
|
Size: |
4096
|
|
7FF93C5E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3255188502.00007FF93C5E0000.00000002.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C5E0000
|
Size: |
4096
|
|
7FF6AC861000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000000.3248959521.00007FF6AC861000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
24
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF6AC861000
|
Size: |
2248704
|
|
7FF93D741000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3257755862.00007FF93D741000.00000020.00000001.01000000.0000000A.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93D741000
|
Size: |
3272704
|
|
192784AA000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3167376076.00000192784AA000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
192784AA000
|
Size: |
4096
|
|
7FF93D6A1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4092661259.00007FF93D6A1000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6A1000
|
Size: |
4096
|
|
7FF6ACD3A000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000000.3165759004.00007FF6ACD3A000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
22
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6ACD3A000
|
Size: |
147456
|
|
2C2F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3005138605.0000000002C2F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2C2F000
|
Size: |
4096
|
|
1927849C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3167039976.000001927849C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1927849C000
|
Size: |
8192
|
|
7FF93D698000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3257339293.00007FF93D698000.00000008.00000001.01000000.0000000B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D698000
|
Size: |
28672
|
|
7FF93DBD4000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4095370554.00007FF93DBD4000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93DBD4000
|
Size: |
36864
|
|
7FF6AC860000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000000.3248931047.00007FF6AC860000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
24
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6AC860000
|
Size: |
4096
|
|
7FF93D185000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3256684630.00007FF93D185000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D185000
|
Size: |
8192
|
|
1DDB5662000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4084831570.000001DDB5662000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB5662000
|
Size: |
12288
|
|
7FF93BD30000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4087291603.00007FF93BD30000.00000004.00000001.01000000.0000001F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93BD30000
|
Size: |
12288
|
|
7FF6ACD55000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4086497208.00007FF6ACD55000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF6ACD55000
|
Size: |
8192
|
|
7FF93DDBD000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3258715480.00007FF93DDBD000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DDBD000
|
Size: |
24576
|
|
1DDB1A25000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3122054216.000001DDB1A25000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB1A25000
|
Size: |
4096
|
|
7FF93BE80000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3253971302.00007FF93BE80000.00000002.00000001.01000000.00000017.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BE80000
|
Size: |
4096
|
|
7FF93C515000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4089362267.00007FF93C515000.00000004.00000001.01000000.00000013.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93C515000
|
Size: |
4096
|
|
7FF93DC11000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4095452321.00007FF93DC11000.00000020.00000001.01000000.00000007.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93DC11000
|
Size: |
905216
|
|
1F401FDB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3251261929.000001F401FDB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FDB000
|
Size: |
81920
|
|
192784AF000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3167121070.00000192784AF000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
192784AF000
|
Size: |
4096
|
|
7FF93C5E1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3172051158.00007FF93C5E1000.00000020.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93C5E1000
|
Size: |
3526656
|
|
7FF93F123000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3258803704.00007FF93F123000.00000002.00000001.01000000.0000001A.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93F123000
|
Size: |
131072
|
|
7FF93C0F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3171367500.00007FF93C0F0000.00000002.00000001.01000000.00000013.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C0F0000
|
Size: |
4096
|
|
7FF957A95000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176748418.00007FF957A95000.00000002.00000001.01000000.00000015.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957A95000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
3258000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3008009736.0000000003258000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3258000
|
Size: |
4096
|
|
7FF6ACD60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3170159018.00007FF6ACD60000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6ACD60000
|
Size: |
372736
|
|
7FF93DD59000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3175717685.00007FF93DD59000.00000004.00000001.01000000.00000007.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93DD59000
|
Size: |
4096
|
|
7FF93C5AC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4089548597.00007FF93C5AC000.00000002.00000001.01000000.00000010.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C5AC000
|
Size: |
143360
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93D19A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4091832948.00007FF93D19A000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93D19A000
|
Size: |
229376
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93BD3C000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4087384884.00007FF93BD3C000.00000008.00000001.01000000.0000001F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93BD3C000
|
Size: |
12288
|
|
7FF93CB15000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3255788771.00007FF93CB15000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB15000
|
Size: |
4096
|
|
BEB9CFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4080977522.000000BEB9CFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BEB9CFF000
|
Size: |
4096
|
|
7FF93CB2B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3255967561.00007FF93CB2B000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB2B000
|
Size: |
4096
|
|
52EF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3008277776.00000000052EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
52EF000
|
Size: |
4096
|
|
7FF93BE6B000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3253894429.00007FF93BE6B000.00000008.00000001.01000000.0000001B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93BE6B000
|
Size: |
4096
|
|
7FF93D17F000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3256632242.00007FF93D17F000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D17F000
|
Size: |
20480
|
|
2D3D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3004174862.0000000002D3D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D3D000
|
Size: |
28672
|
|
1DDB4C9C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125365396.000001DDB4C9C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9C000
|
Size: |
65536
|
|
7FF93CB1A000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4090590956.00007FF93CB1A000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB1A000
|
Size: |
8192
|
|
7FF95DD51000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3177404503.00007FF95DD51000.00000020.00000001.01000000.00000009.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF95DD51000
|
Size: |
20480
|
|
1F403950000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3252407379.000001F403950000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F403950000
|
Size: |
12288
|
|
7FF93F120000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4095974861.00007FF93F120000.00000002.00000001.01000000.0000001A.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93F120000
|
Size: |
4096
|
|
7FF957E0A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3259766669.00007FF957E0A000.00000002.00000001.01000000.0000000E.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957E0A000
|
Size: |
12288
|
|
1DDB46C0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4082400095.000001DDB46C0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB46C0000
|
Size: |
716800
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
1DDB52D1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3129232124.000001DDB52D1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB52D1000
|
Size: |
81920
|
|
1DDB19A0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4081350108.000001DDB19A0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB19A0000
|
Size: |
12288
|
|
7FF93C551000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3171861270.00007FF93C551000.00000020.00000001.01000000.00000010.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93C551000
|
Size: |
372736
|
|
7FF93CB17000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3255839981.00007FF93CB17000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB17000
|
Size: |
4096
|
|
3237000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.3007635388.0000000003237000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3237000
|
Size: |
65536
|
|
7FF93BD47000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4087466501.00007FF93BD47000.00000004.00000001.01000000.0000001F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93BD47000
|
Size: |
8192
|
|
1DDB4C92000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127337990.000001DDB4C92000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C92000
|
Size: |
24576
|
|
2D1E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3004457262.0000000002D1E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D1E000
|
Size: |
49152
|
|
1DDB4C82000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125680434.000001DDB4C82000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C82000
|
Size: |
20480
|
|
7FF944036000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096160060.00007FF944036000.00000002.00000001.01000000.00000012.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF944036000
|
Size: |
45056
|
|
7FF93BD71000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3170236438.00007FF93BD71000.00000020.00000001.01000000.0000001C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93BD71000
|
Size: |
106496
|
|
7FF93BE6C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3170599264.00007FF93BE6C000.00000004.00000001.01000000.0000001B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93BE6C000
|
Size: |
8192
|
|
1927849E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3168356706.000001927849E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1927849E000
|
Size: |
20480
|
|
7FF93C0CA000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3254432975.00007FF93C0CA000.00000002.00000001.01000000.00000014.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C0CA000
|
Size: |
69632
|
|
7FF93D188000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3256732617.00007FF93D188000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D188000
|
Size: |
4096
|
|
7FF93D740000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4094952851.00007FF93D740000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93D740000
|
Size: |
4096
|
|
1DDB4C9B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127500950.000001DDB4C9B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9B000
|
Size: |
4096
|
|
7FF6ACA86000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000000.3249143963.00007FF6ACA86000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
24
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6ACA86000
|
Size: |
2834432
|
|
7FF93BF30000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3254122497.00007FF93BF30000.00000002.00000001.01000000.00000016.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BF30000
|
Size: |
4096
|
|
1DDB6F50000
|
trusted library allocation
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4085470133.000001DDB6F50000.00000004.00000800.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
trusted library allocation
|
Protect: |
page read and write
|
Base address: |
1DDB6F50000
|
Size: |
4096
|
|
7FF93D1E1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3256905479.00007FF93D1E1000.00000020.00000001.01000000.0000000B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93D1E1000
|
Size: |
2662400
|
|
7FF93D1E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3173957253.00007FF93D1E0000.00000002.00000001.01000000.0000000B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93D1E0000
|
Size: |
4096
|
|
7FF957AB0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4097125726.00007FF957AB0000.00000002.00000001.01000000.00000011.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957AB0000
|
Size: |
4096
|
|
7FF93BE27000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4087820584.00007FF93BE27000.00000002.00000001.01000000.0000001B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BE27000
|
Size: |
266240
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93BEFA000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4088123746.00007FF93BEFA000.00000002.00000001.01000000.00000017.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BEFA000
|
Size: |
163840
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF95DD50000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3260403703.00007FF95DD50000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95DD50000
|
Size: |
4096
|
|
526F000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3008232644.000000000526F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
526F000
|
Size: |
4096
|
|
7FF93BF31000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3171014682.00007FF93BF31000.00000020.00000001.01000000.00000016.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93BF31000
|
Size: |
790528
|
|
7FF93C5E1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3255213543.00007FF93C5E1000.00000020.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93C5E1000
|
Size: |
3526656
|
|
7FF93D6BC000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3174988669.00007FF93D6BC000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6BC000
|
Size: |
4096
|
|
7FF93DDBB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3175955380.00007FF93DDBB000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93DDBB000
|
Size: |
8192
|
|
1DDB4C8F000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127571385.000001DDB4C8F000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C8F000
|
Size: |
12288
|
|
7FF93F123000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176094001.00007FF93F123000.00000002.00000001.01000000.0000001A.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93F123000
|
Size: |
131072
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93C0F0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4088789837.00007FF93C0F0000.00000002.00000001.01000000.00000013.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C0F0000
|
Size: |
4096
|
|
2D19000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3005288528.0000000002D19000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D19000
|
Size: |
16384
|
|
1DDB1A27000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4081482497.000001DDB1A27000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB1A27000
|
Size: |
688128
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
84FA3FE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3168813839.00000084FA3FE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
84FA3FE000
|
Size: |
8192
|
|
1DDB18E0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4081274248.000001DDB18E0000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB18E0000
|
Size: |
4096
|
|
7FF93BD97000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3170366348.00007FF93BD97000.00000002.00000001.01000000.0000001C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BD97000
|
Size: |
16384
|
|
7FF93DA60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3175318715.00007FF93DA60000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DA60000
|
Size: |
1314816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1F401FD4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3250782819.000001F401FD4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FD4000
|
Size: |
110592
|
|
7FF93BFF2000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3254222565.00007FF93BFF2000.00000002.00000001.01000000.00000016.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BFF2000
|
Size: |
241664
|
|
3259000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.3007409368.0000000003259000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3259000
|
Size: |
28672
|
|
7FF93D6A7000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3174870576.00007FF93D6A7000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6A7000
|
Size: |
4096
|
|
7FF93DD58000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4095600640.00007FF93DD58000.00000008.00000001.01000000.00000007.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93DD58000
|
Size: |
4096
|
|
1DDB4C88000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125680434.000001DDB4C88000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C88000
|
Size: |
36864
|
|
7FF93DD70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4095668008.00007FF93DD70000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DD70000
|
Size: |
4096
|
|
1DDB4CA3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3126366663.000001DDB4CA3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CA3000
|
Size: |
4096
|
|
1DDB4CB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4083404766.000001DDB4CB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB4000
|
Size: |
8192
|
|
7FF95DD57000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3260469135.00007FF95DD57000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95DD57000
|
Size: |
8192
|
|
7FF957E01000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3259734951.00007FF957E01000.00000020.00000001.01000000.0000000E.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF957E01000
|
Size: |
36864
|
|
1DDB4CB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127500950.000001DDB4CB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB4000
|
Size: |
8192
|
|
19278472000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3168611006.0000019278472000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19278472000
|
Size: |
4096
|
|
7FF6ACD60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000000.3165784210.00007FF6ACD60000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
22
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6ACD60000
|
Size: |
372736
|
|
7FF93DD9F000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4095832762.00007FF93DD9F000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DD9F000
|
Size: |
114688
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
322A000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.3007456185.000000000322A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
322A000
|
Size: |
24576
|
|
7FF93D740000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3175059031.00007FF93D740000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93D740000
|
Size: |
4096
|
|
7FF93D6B3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3257531765.00007FF93D6B3000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6B3000
|
Size: |
12288
|
|
7FF93D6A7000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4092883352.00007FF93D6A7000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6A7000
|
Size: |
4096
|
|
7FF93D172000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3256526969.00007FF93D172000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D172000
|
Size: |
49152
|
|
BEB9AFE000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4080786605.000000BEB9AFE000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BEB9AFE000
|
Size: |
8192
|
|
7FF93BD8B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4087602282.00007FF93BD8B000.00000002.00000001.01000000.0000001C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BD8B000
|
Size: |
45056
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93BE81000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3253994079.00007FF93BE81000.00000020.00000001.01000000.00000017.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93BE81000
|
Size: |
495616
|
|
7FF93DD5B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3175778403.00007FF93DD5B000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DD5B000
|
Size: |
61440
|
|
7FF93D172000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4091468892.00007FF93D172000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D172000
|
Size: |
49152
|
|
1DDB3550000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4082017302.000001DDB3550000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB3550000
|
Size: |
8192
|
|
BEB96E5000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4080678270.000000BEB96E5000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BEB96E5000
|
Size: |
110592
|
|
1927848D000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3169151453.000001927848D000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1927848D000
|
Size: |
40960
|
|
7FF9610C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3177468763.00007FF9610C0000.00000002.00000001.01000000.00000008.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9610C0000
|
Size: |
4096
|
|
7FF957A70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176673013.00007FF957A70000.00000002.00000001.01000000.00000015.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957A70000
|
Size: |
4096
|
|
1DDB34D0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4081951414.000001DDB34D0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB34D0000
|
Size: |
8192
|
|
1DDB1A4C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3122449090.000001DDB1A4C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB1A4C000
|
Size: |
8192
|
|
2D2B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3004457262.0000000002D2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D2B000
|
Size: |
53248
|
|
1DDB5280000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4083613409.000001DDB5280000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB5280000
|
Size: |
249856
|
|
1DDB4C9A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3142222936.000001DDB4C9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9A000
|
Size: |
4096
|
|
1DDB5605000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4084831570.000001DDB5605000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB5605000
|
Size: |
278528
|
|
305C000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3007758428.000000000305C000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
305C000
|
Size: |
16384
|
|
7FF93D19A000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3173924410.00007FF93D19A000.00000002.00000001.01000000.0000000C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93D19A000
|
Size: |
229376
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF956DC0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176587539.00007FF956DC0000.00000002.00000001.01000000.00000018.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF956DC0000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93DD70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3175811761.00007FF93DD70000.00000002.00000001.01000000.00000005.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DD70000
|
Size: |
4096
|
|
7FF93DD4E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4095576691.00007FF93DD4E000.00000004.00000001.01000000.00000007.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93DD4E000
|
Size: |
40960
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Public key (encryption) found |
Cryptography |
|
|
7FF93C218000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3171390987.00007FF93C218000.00000020.00000001.01000000.00000013.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93C218000
|
Size: |
2121728
|
|
7FF93C0F1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3254538389.00007FF93C0F1000.00000020.00000001.01000000.00000013.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93C0F1000
|
Size: |
1204224
|
|
7FF93DA60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3258013423.00007FF93DA60000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DA60000
|
Size: |
1314816
|
|
7FF93D6A8000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3174889305.00007FF93D6A8000.00000008.00000001.01000000.0000000B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D6A8000
|
Size: |
45056
|
|
7FF93C0DB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3254461680.00007FF93C0DB000.00000004.00000001.01000000.00000014.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93C0DB000
|
Size: |
4096
|
|
7FF9586B9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4098279468.00007FF9586B9000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9586B9000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1DDB5394000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4084058069.000001DDB5394000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB5394000
|
Size: |
413696
|
|
7FF93C41E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4089209402.00007FF93C41E000.00000002.00000001.01000000.00000013.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C41E000
|
Size: |
995328
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1F401D30000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3252069442.000001F401D30000.00000004.00000020.00040000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401D30000
|
Size: |
4096
|
|
7FF93D187000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3173815178.00007FF93D187000.00000008.00000001.01000000.0000000C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D187000
|
Size: |
4096
|
|
7FF93DA60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4095222872.00007FF93DA60000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DA60000
|
Size: |
1314816
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1DDB4C91000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125635278.000001DDB4C91000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C91000
|
Size: |
4096
|
|
3170000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3007817738.0000000003170000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3170000
|
Size: |
4096
|
|
1927848B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3168539946.000001927848B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1927848B000
|
Size: |
49152
|
|
3194000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3007835872.0000000003194000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3194000
|
Size: |
24576
|
|
7FF93BD96000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4087636420.00007FF93BD96000.00000004.00000001.01000000.0000001C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93BD96000
|
Size: |
4096
|
|
7FF93BE68000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3253867837.00007FF93BE68000.00000004.00000001.01000000.0000001B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93BE68000
|
Size: |
12288
|
|
7FF93D6BA000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3174944445.00007FF93D6BA000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6BA000
|
Size: |
4096
|
|
7FF93DBD4000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3175481218.00007FF93DBD4000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93DBD4000
|
Size: |
4096
|
|
7FF93CB0D000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3172595454.00007FF93CB0D000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB0D000
|
Size: |
12288
|
|
1DDB4791000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4082675025.000001DDB4791000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4791000
|
Size: |
991232
|
|
7FF93D6A4000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4092785076.00007FF93D6A4000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6A4000
|
Size: |
8192
|
|
7FF93DD71000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3175833901.00007FF93DD71000.00000020.00000001.01000000.00000005.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93DD71000
|
Size: |
188416
|
|
1F401FF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3250782819.000001F401FF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FF0000
|
Size: |
28672
|
|
7FF93C551000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4089476238.00007FF93C551000.00000020.00000001.01000000.00000010.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93C551000
|
Size: |
372736
|
|
7FF93D6A8000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3257505143.00007FF93D6A8000.00000008.00000001.01000000.0000000B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D6A8000
|
Size: |
45056
|
|
7FF950BD0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3176396006.00007FF950BD0000.00000002.00000001.01000000.00000019.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF950BD0000
|
Size: |
4096
|
|
1DDB4C8C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127374637.000001DDB4C8C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C8C000
|
Size: |
24576
|
|
7FF93CB1A000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3255890132.00007FF93CB1A000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB1A000
|
Size: |
8192
|
|
1DDB496C000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3129308817.000001DDB496C000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB496C000
|
Size: |
12288
|
|
1DDB378C000
|
direct allocation
|
page execute and read and write
|
|
|
|
Name: |
00000013.00000002.4082265139.000001DDB378C000.00000040.00001000.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
direct allocation
|
Protect: |
page execute and read and write
|
Base address: |
1DDB378C000
|
Size: |
16384
|
|
7FF93D696000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4092509720.00007FF93D696000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D696000
|
Size: |
8192
|
|
2660000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3004855858.0000000002660000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2660000
|
Size: |
4096
|
|
7FF93C5D4000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4089639795.00007FF93C5D4000.00000002.00000001.01000000.00000010.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C5D4000
|
Size: |
32768
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF6AC860000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000000.3118154644.00007FF6AC860000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
19
|
Dumpstage: |
process new
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6AC860000
|
Size: |
4096
|
|
7FF93BE68000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4087889387.00007FF93BE68000.00000004.00000001.01000000.0000001B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93BE68000
|
Size: |
12288
|
|
1F401FF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3252315517.000001F401FF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FF0000
|
Size: |
28672
|
|
7FF93DC11000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3175545804.00007FF93DC11000.00000020.00000001.01000000.00000007.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93DC11000
|
Size: |
905216
|
|
2D0E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3004608068.0000000002D0E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D0E000
|
Size: |
40960
|
|
7FF93C0DC000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4088739529.00007FF93C0DC000.00000002.00000001.01000000.00000014.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C0DC000
|
Size: |
24576
|
|
7FF93F144000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096051593.00007FF93F144000.00000002.00000001.01000000.0000001A.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93F144000
|
Size: |
8192
|
|
7FF6ACD57000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3253486988.00007FF6ACD57000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6ACD57000
|
Size: |
24576
|
|
7FF943FE1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4096111770.00007FF943FE1000.00000020.00000001.01000000.00000012.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF943FE1000
|
Size: |
348160
|
|
7FF93D6A2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3174804965.00007FF93D6A2000.00000008.00000001.01000000.0000000B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D6A2000
|
Size: |
8192
|
|
7FF957ABD000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3259597058.00007FF957ABD000.00000002.00000001.01000000.00000011.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957ABD000
|
Size: |
24576
|
|
7FF95D9CF000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4098576060.00007FF95D9CF000.00000002.00000001.01000000.0000000D.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95D9CF000
|
Size: |
28672
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF956DC3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4096493235.00007FF956DC3000.00000004.00000001.01000000.00000018.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF956DC3000
|
Size: |
4096
|
|
7FF6ACA86000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3252862534.00007FF6ACA86000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6ACA86000
|
Size: |
2834432
|
|
1927845E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3169068793.000001927845E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1927845E000
|
Size: |
81920
|
|
7FF93D1E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4091885724.00007FF93D1E0000.00000002.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93D1E0000
|
Size: |
4096
|
|
7FF93D198000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3173885084.00007FF93D198000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D198000
|
Size: |
8192
|
|
2D1E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3004221402.0000000002D1E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D1E000
|
Size: |
49152
|
|
7FF950BD0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3259089435.00007FF950BD0000.00000002.00000001.01000000.00000019.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF950BD0000
|
Size: |
4096
|
|
7FF9586B9000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3177224774.00007FF9586B9000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9586B9000
|
Size: |
12288
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93C511000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3254901105.00007FF93C511000.00000008.00000001.01000000.00000013.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93C511000
|
Size: |
16384
|
|
1DDB4CB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3123955333.000001DDB4CB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB5000
|
Size: |
4096
|
|
7FF957AA0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096967313.00007FF957AA0000.00000002.00000001.01000000.00000015.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957AA0000
|
Size: |
16384
|
|
7FF9586BD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3177251908.00007FF9586BD000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF9586BD000
|
Size: |
4096
|
|
7FF957E0E000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3259865644.00007FF957E0E000.00000002.00000001.01000000.0000000E.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957E0E000
|
Size: |
8192
|
|
7FF93BD70000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4087540060.00007FF93BD70000.00000002.00000001.01000000.0000001C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BD70000
|
Size: |
4096
|
|
7FF9610C0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3260538234.00007FF9610C0000.00000002.00000001.01000000.00000008.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9610C0000
|
Size: |
4096
|
|
7FF93CB12000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3255739809.00007FF93CB12000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB12000
|
Size: |
8192
|
|
1DDB4C9A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3123801148.000001DDB4C9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9A000
|
Size: |
8192
|
|
7FF93DBA1000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3175426119.00007FF93DBA1000.00000004.00000001.01000000.0000000A.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93DBA1000
|
Size: |
4096
|
|
7FF93D6B8000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3257584324.00007FF93D6B8000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6B8000
|
Size: |
4096
|
|
7FF95D9C1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000018.00000002.3260297021.00007FF95D9C1000.00000020.00000001.01000000.0000000D.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF95D9C1000
|
Size: |
57344
|
|
7FF93C0CA000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4088582697.00007FF93C0CA000.00000002.00000001.01000000.00000014.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C0CA000
|
Size: |
69632
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1927848B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3168410395.000001927848B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1927848B000
|
Size: |
49152
|
|
7FF93C5CF000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4089587574.00007FF93C5CF000.00000008.00000001.01000000.00000010.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93C5CF000
|
Size: |
12288
|
|
7FF950BDE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3259212921.00007FF950BDE000.00000002.00000001.01000000.00000019.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF950BDE000
|
Size: |
8192
|
|
83326FD000
|
stack
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3251873080.00000083326FD000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
83326FD000
|
Size: |
12288
|
|
7FF93BE27000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3253821274.00007FF93BE27000.00000002.00000001.01000000.0000001B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BE27000
|
Size: |
266240
|
|
7FF950BDA000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3259150084.00007FF950BDA000.00000002.00000001.01000000.00000019.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF950BDA000
|
Size: |
12288
|
|
2D0A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3004221402.0000000002D0A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D0A000
|
Size: |
77824
|
|
7FF93DD5B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3258542732.00007FF93DD5B000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DD5B000
|
Size: |
61440
|
|
1DDB4CB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127317855.000001DDB4CB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB4000
|
Size: |
8192
|
|
7FF9586B0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4098165876.00007FF9586B0000.00000002.00000001.01000000.00000006.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF9586B0000
|
Size: |
4096
|
|
7FF9586BD000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4098313026.00007FF9586BD000.00000004.00000001.01000000.00000006.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF9586BD000
|
Size: |
4096
|
|
7FF957A71000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4096745087.00007FF957A71000.00000020.00000001.01000000.00000015.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF957A71000
|
Size: |
147456
|
|
7FF6ACD57000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4086524921.00007FF6ACD57000.00000008.00000001.01000000.00000004.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF6ACD57000
|
Size: |
24576
|
|
7FF93DDBB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3258684054.00007FF93DDBB000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93DDBB000
|
Size: |
8192
|
|
1F401FF0000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3251017922.000001F401FF0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FF0000
|
Size: |
28672
|
|
1927A130000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3169370556.000001927A130000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1927A130000
|
Size: |
4096
|
|
7FF93CB10000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3255714609.00007FF93CB10000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB10000
|
Size: |
8192
|
|
7FF93D18E000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4091763308.00007FF93D18E000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D18E000
|
Size: |
20480
|
|
7FF944043000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3258958800.00007FF944043000.00000002.00000001.01000000.00000012.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF944043000
|
Size: |
94208
|
|
1DDB3595000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4082150081.000001DDB3595000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB3595000
|
Size: |
16384
|
|
7FF93DDBB000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4095921226.00007FF93DDBB000.00000004.00000001.01000000.00000005.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93DDBB000
|
Size: |
8192
|
|
2D2B000
|
heap
|
page read and write
|
|
|
|
Name: |
00000009.00000003.3004221402.0000000002D2B000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
2D2B000
|
Size: |
53248
|
|
7FF93D6B6000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3257558136.00007FF93D6B6000.00000008.00000001.01000000.0000000B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D6B6000
|
Size: |
8192
|
|
7FF93D6A4000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3174827490.00007FF93D6A4000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6A4000
|
Size: |
8192
|
|
7FF94405B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096233038.00007FF94405B000.00000002.00000001.01000000.00000012.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF94405B000
|
Size: |
16384
|
|
1DDB4CA3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3142176112.000001DDB4CA3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CA3000
|
Size: |
4096
|
|
1DDB4893000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4082675025.000001DDB4893000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4893000
|
Size: |
815104
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF93DCEE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4095535046.00007FF93DCEE000.00000002.00000001.01000000.00000007.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DCEE000
|
Size: |
393216
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Found strings which match to known social media urls |
Networking |
|
URLs found in memory or binary data |
Networking |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1F403AE3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3252459654.000001F403AE3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F403AE3000
|
Size: |
12288
|
|
7FF93D6B3000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4094638321.00007FF93D6B3000.00000004.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D6B3000
|
Size: |
12288
|
|
7FF93CB12000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4090401087.00007FF93CB12000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB12000
|
Size: |
8192
|
|
7FF93C5E0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4089680180.00007FF93C5E0000.00000002.00000001.01000000.0000000F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C5E0000
|
Size: |
4096
|
|
7FF93BD97000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4087666332.00007FF93BD97000.00000002.00000001.01000000.0000001C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BD97000
|
Size: |
16384
|
|
19278430000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3168985612.0000019278430000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19278430000
|
Size: |
12288
|
|
7FF943FE0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096083116.00007FF943FE0000.00000002.00000001.01000000.00000012.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF943FE0000
|
Size: |
4096
|
|
1DDB4CB4000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3142094889.000001DDB4CB4000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB4000
|
Size: |
8192
|
|
7FF943FE0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3258879549.00007FF943FE0000.00000002.00000001.01000000.00000012.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF943FE0000
|
Size: |
4096
|
|
51EF000
|
stack
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3008180061.00000000051EF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
51EF000
|
Size: |
4096
|
|
7FF93F120000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3258745875.00007FF93F120000.00000002.00000001.01000000.0000001A.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93F120000
|
Size: |
4096
|
|
7FF93CB16000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3255813204.00007FF93CB16000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB16000
|
Size: |
4096
|
|
1DDB4C8E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3126417616.000001DDB4C8E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C8E000
|
Size: |
28672
|
|
7FF957AB0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3259530536.00007FF957AB0000.00000002.00000001.01000000.00000011.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957AB0000
|
Size: |
4096
|
|
7FF93C0F1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3171390987.00007FF93C0F1000.00000020.00000001.01000000.00000013.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93C0F1000
|
Size: |
1204224
|
|
7FF93CB2B000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3172894475.00007FF93CB2B000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB2B000
|
Size: |
4096
|
|
19278473000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3168462451.0000019278473000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
19278473000
|
Size: |
69632
|
|
7FF6ACD5D000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4086562557.00007FF6ACD5D000.00000004.00000001.01000000.00000004.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF6ACD5D000
|
Size: |
12288
|
|
7FF93BD97000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3253708404.00007FF93BD97000.00000002.00000001.01000000.0000001C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93BD97000
|
Size: |
16384
|
|
7FF93CB25000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3172866153.00007FF93CB25000.00000008.00000001.01000000.0000000F.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93CB25000
|
Size: |
24576
|
|
1DDB4CB5000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125457436.000001DDB4CB5000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB5000
|
Size: |
4096
|
|
34F0000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000002.3008104665.00000000034F0000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
34F0000
|
Size: |
20480
|
|
7FF93D6BE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3257661560.00007FF93D6BE000.00000002.00000001.01000000.0000000B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93D6BE000
|
Size: |
475136
|
|
1DDB4C9A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127278989.000001DDB4C9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9A000
|
Size: |
4096
|
|
2B8F000
|
stack
|
page read and write
|
|
|
|
Name: |
00000009.00000002.3005054494.0000000002B8F000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
9
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
2B8F000
|
Size: |
4096
|
|
7FF93D188000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4091682691.00007FF93D188000.00000004.00000001.01000000.0000000C.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93D188000
|
Size: |
4096
|
|
7FF93B8A1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4086708461.00007FF93B8A1000.00000020.00000001.01000000.0000001F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93B8A1000
|
Size: |
1986560
|
|
3231000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.3007568388.0000000003231000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3231000
|
Size: |
90112
|
|
1DDB55A8000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4084831570.000001DDB55A8000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB55A8000
|
Size: |
221184
|
|
7FF6ACD60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000018.00000002.3253536420.00007FF6ACD60000.00000002.00000001.01000000.00000004.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF6ACD60000
|
Size: |
372736
|
|
192784A3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3167190423.00000192784A3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
192784A3000
|
Size: |
4096
|
|
1DDB4CB1000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3125575496.000001DDB4CB1000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4CB1000
|
Size: |
8192
|
|
1DDB4C9A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3126451794.000001DDB4C9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9A000
|
Size: |
4096
|
|
7FF93D46B000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4092224554.00007FF93D46B000.00000002.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93D46B000
|
Size: |
2273280
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
7FF93D6A2000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3257397499.00007FF93D6A2000.00000008.00000001.01000000.0000000B.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D6A2000
|
Size: |
8192
|
|
1927849E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000003.3168102258.000001927849E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1927849E000
|
Size: |
20480
|
|
7FF93C550000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000016.00000002.3171837501.00007FF93C550000.00000002.00000001.01000000.00000010.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93C550000
|
Size: |
4096
|
|
7FF93DBDE000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4095395370.00007FF93DBDE000.00000002.00000001.01000000.0000000A.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF93DBDE000
|
Size: |
147456
|
|
7FF6AC861000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3169475161.00007FF6AC861000.00000020.00000001.01000000.00000004.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF6AC861000
|
Size: |
2248704
|
|
7FF93D189000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000018.00000002.3256756559.00007FF93D189000.00000008.00000001.01000000.0000000C.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D189000
|
Size: |
20480
|
|
1927844E000
|
heap
|
page read and write
|
|
|
|
Name: |
00000016.00000002.3169068793.000001927844E000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1927844E000
|
Size: |
61440
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
URLs found in memory or binary data |
Networking |
|
|
7FF950BD0000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096261871.00007FF950BD0000.00000002.00000001.01000000.00000019.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF950BD0000
|
Size: |
4096
|
|
7FF93D1E1000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000013.00000002.4091922336.00007FF93D1E1000.00000020.00000001.01000000.0000000B.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93D1E1000
|
Size: |
2662400
|
|
3258000
|
heap
|
page read and write
|
|
|
|
Name: |
0000000B.00000003.3007550222.0000000003258000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
11
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
3258000
|
Size: |
4096
|
|
1F401FFB000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3250473439.000001F401FFB000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FFB000
|
Size: |
4096
|
|
7FF95DD57000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4098807577.00007FF95DD57000.00000002.00000001.01000000.00000009.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF95DD57000
|
Size: |
8192
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
1DDB4C9A000
|
heap
|
page read and write
|
|
|
|
Name: |
00000013.00000003.3127181049.000001DDB4C9A000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1DDB4C9A000
|
Size: |
4096
|
|
7FF93BE81000
|
unkown
|
page execute read
|
|
|
|
Name: |
00000016.00000002.3170754706.00007FF93BE81000.00000020.00000001.01000000.00000017.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page execute read
|
Base address: |
7FF93BE81000
|
Size: |
495616
|
|
BEB9EFF000
|
stack
|
page read and write
|
|
|
|
Name: |
00000013.00000002.4081128259.000000BEB9EFF000.00000004.00000010.00020000.00000000.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
stack
|
Protect: |
page read and write
|
Base address: |
BEB9EFF000
|
Size: |
4096
|
|
7FF93BD41000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000013.00000002.4087436532.00007FF93BD41000.00000008.00000001.01000000.0000001F.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93BD41000
|
Size: |
24576
|
|
7FF93D698000
|
unkown
|
page write copy
|
|
|
|
Name: |
00000016.00000002.3174758979.00007FF93D698000.00000008.00000001.01000000.0000000B.sdmp
|
TargetID: |
22
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page write copy
|
Base address: |
7FF93D698000
|
Size: |
28672
|
|
7FF93CB1C000
|
unkown
|
page read and write
|
|
|
|
Name: |
00000018.00000002.3255914965.00007FF93CB1C000.00000004.00000001.01000000.0000000F.sdmp
|
TargetID: |
24
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page read and write
|
Base address: |
7FF93CB1C000
|
Size: |
36864
|
|
7FF957A60000
|
unkown
|
page readonly
|
|
|
|
Name: |
00000013.00000002.4096566107.00007FF957A60000.00000002.00000001.01000000.0000001E.sdmp
|
TargetID: |
19
|
Dumpstage: |
process exit
|
Regiontype: |
unkown
|
Protect: |
page readonly
|
Base address: |
7FF957A60000
|
Size: |
4096
|
|
1F401FC3000
|
heap
|
page read and write
|
|
|
|
Name: |
00000018.00000003.3250782819.000001F401FC3000.00000004.00000020.00020000.00000000.sdmp
|
TargetID: |
24
|
Dumpstage: |
free memory
|
Regiontype: |
heap
|
Protect: |
page read and write
|
Base address: |
1F401FC3000
|
Size: |
61440
|
|