7f15b7fff000
|
|
page read and write
|
|
|
|
Name: |
6219.1.00007f15b77ff000.00007f15b7fff000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f15b7fff000
|
Size: |
8388608
|
|
563d16d09000
|
|
page execute read
|
|
|
|
Name: |
6219.1.0000563d16b58000.0000563d16d09000.r-x.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page execute read
|
Base address: |
563d16d09000
|
Size: |
1773568
|
|
7f15b8021000
|
|
page read and write
|
|
|
|
Name: |
6219.1.00007f15b8000000.00007f15b8021000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f15b8021000
|
Size: |
135168
|
|
7ffcde96b000
|
|
page read and write
|
|
|
|
Name: |
6219.1.00007ffcde94a000.00007ffcde96b000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7ffcde96b000
|
Size: |
135168
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
7f15be030000
|
|
page read and write
|
|
|
|
Name: |
6219.1.00007f15be02e000.00007f15be030000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f15be030000
|
Size: |
8192
|
|
7f14b8023000
|
|
page execute read
|
|
|
|
Name: |
6219.1.00007f14b8017000.00007f14b8023000.r-x.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page execute read
|
Base address: |
7f14b8023000
|
Size: |
49152
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Malicious sample detected (through community Yara rule) |
System Summary |
|
Yara signature match |
System Summary |
|
|
563d16f5a000
|
|
page read and write
|
|
|
|
Name: |
6219.1.0000563d16f50000.0000563d16f5a000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
563d16f5a000
|
Size: |
40960
|
|
7f15beb4f000
|
|
page read and write
|
|
|
|
Name: |
6219.1.00007f15beb4d000.00007f15beb4f000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f15beb4f000
|
Size: |
8192
|
|
7f14b8030000
|
|
page read and write
|
|
|
|
Name: |
6219.1.00007f14b802a000.00007f14b8030000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f14b8030000
|
Size: |
24576
|
|
563d18f78000
|
|
page read and write
|
|
|
|
Name: |
6219.1.0000563d18f62000.0000563d18f78000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
563d18f78000
|
Size: |
90112
|
|
7ffcde9f8000
|
|
page execute read
|
|
|
|
Name: |
6219.1.00007ffcde9f7000.00007ffcde9f8000.r-x.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page execute read
|
Base address: |
7ffcde9f8000
|
Size: |
4096
|
|
7f15be96e000
|
|
page read and write
|
|
|
|
Name: |
6219.1.00007f15be96b000.00007f15be96e000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f15be96e000
|
Size: |
12288
|
|
7f15bd796000
|
|
page read and write
|
|
|
|
Name: |
6219.1.00007f15bd715000.00007f15bd796000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f15bd796000
|
Size: |
528384
|
|
7f15be78c000
|
|
page read and write
|
|
|
|
Name: |
6219.1.00007f15be78a000.00007f15be78c000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f15be78c000
|
Size: |
8192
|
|
7f15bec78000
|
|
page read and write
|
|
|
|
Name: |
6219.1.00007f15bec77000.00007f15bec78000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f15bec78000
|
Size: |
4096
|
|
7f15bec9c000
|
|
page read and write
|
|
|
|
Name: |
6219.1.00007f15bec9a000.00007f15bec9c000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f15bec9c000
|
Size: |
8192
|
|
563d16f63000
|
|
page read and write
|
|
|
|
Name: |
6219.1.0000563d16f5a000.0000563d16f63000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
563d16f63000
|
Size: |
36864
|
|
7f15bece1000
|
|
page read and write
|
|
|
|
Name: |
6219.1.00007f15bece0000.00007f15bece1000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f15bece1000
|
Size: |
4096
|
|
7f15be5fd000
|
|
page read and write
|
|
|
|
Name: |
6219.1.00007f15be5f9000.00007f15be5fd000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f15be5fd000
|
Size: |
16384
|
|
7f15be620000
|
|
page read and write
|
|
|
|
Name: |
6219.1.00007f15be61c000.00007f15be620000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f15be620000
|
Size: |
16384
|
|
563d18f61000
|
|
page execute and read and write
|
|
|
|
Name: |
6219.1.0000563d16f63000.0000563d18f61000.rwx.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page execute and read and write
|
Base address: |
563d18f61000
|
Size: |
33546240
|
|
563d192a4000
|
|
page read and write
|
|
|
|
Name: |
6219.1.0000563d190b6000.0000563d192a4000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
563d192a4000
|
Size: |
2023424
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory) |
Malware Analysis System Evasion |
Security Software Discovery
|
|
7f15bdf9e000
|
|
page read and write
|
|
|
|
Name: |
6219.1.00007f15bd797000.00007f15bdf9e000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f15bdf9e000
|
Size: |
8417280
|
|
7f15be392000
|
|
page read and write
|
|
|
|
Name: |
6219.1.00007f15be390000.00007f15be392000.rw-.sdmp
|
TargetID: |
12
|
Dumpstage: |
process exit
|
Protect: |
page read and write
|
Base address: |
7f15be392000
|
Size: |
8192
|
|