7FF572518000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.536691514.00007FF572518000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF572518000
|
Size:
|
12288
|
|
B60000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494410044.0000000000B60000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
B60000
|
Size:
|
4096
|
|
2E7C000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.582280308.0000000002E7C000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E7C000
|
Size:
|
4096
|
|
2ED0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.591135724.0000000002ED0000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2ED0000
|
Size:
|
32768
|
|
2F97000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.555247228.0000000002F97000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F97000
|
Size:
|
16384
|
|
2F7B000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597249512.0000000002F7B000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F7B000
|
Size:
|
16384
|
|
2F97000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.497944631.0000000002F97000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F97000
|
Size:
|
16384
|
|
24367D90000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000017.00000002.494442657.0000024367D90000.00000002.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
24367D90000
|
Size:
|
4096
|
|
221EC613000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492268830.00000221EC613000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
221EC613000
|
Size:
|
65536
|
|
7FF5723FD000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523934850.00007FF5723FD000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF5723FD000
|
Size:
|
8192
|
|
2DC4000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544120880.0000000002DC4000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2DC4000
|
Size:
|
8192
|
|
6DEAD000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.583528665.000000006DEAD000.00000002.00020000.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DEAD000
|
Size:
|
28672
|
|
2436D324000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.265662797.000002436D324000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D324000
|
Size:
|
4096
|
|
2ED0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493148818.0000000002ED0000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2ED0000
|
Size:
|
32768
|
|
2F7B000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.549421981.0000000002F7B000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F7B000
|
Size:
|
16384
|
|
7FF572066000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523903152.00007FF572066000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF572066000
|
Size:
|
4096
|
|
7FF57248D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523981870.00007FF57248D000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF57248D000
|
Size:
|
28672
|
|
2436D3D0000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.266104339.000002436D3D0000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D3D0000
|
Size:
|
4096
|
|
7FF572410000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523945893.00007FF572410000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF572410000
|
Size:
|
20480
|
|
24368E00000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000017.00000002.530298318.0000024368E00000.00000002.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
24368E00000
|
Size:
|
65536
|
|
1140000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000002.00000002.540545344.0000000001140000.00000004.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
1140000
|
Size:
|
4096
|
|
2EC4000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.588171630.0000000002EC4000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EC4000
|
Size:
|
40960
|
|
3340000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.613558655.0000000003340000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
3340000
|
Size:
|
315392
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
24367DA0000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494446065.0000024367DA0000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367DA0000
|
Size:
|
4096
|
|
7FF571D30000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523886387.00007FF571D30000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF571D30000
|
Size:
|
4096
|
|
2EC4000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493143571.0000000002EC4000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EC4000
|
Size:
|
40960
|
|
D2A000
|
heap default
|
page read and write
|
|
|
|
Name:
|
00000003.00000002.569754010.0000000000D2A000.00000004.00000020.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
D2A000
|
Size:
|
122880
|
|
3370000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493224435.0000000003370000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
3370000
|
Size:
|
32768
|
|
24367EAD000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494570146.0000024367EAD000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367EAD000
|
Size:
|
57344
|
|
B00000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494402964.0000000000B00000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
B00000
|
Size:
|
4096
|
|
B80000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493005631.0000000000B80000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
B80000
|
Size:
|
16384
|
|
2E8D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.583750919.0000000002E8D000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E8D000
|
Size:
|
28672
|
|
24367E00000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494454918.0000024367E00000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367E00000
|
Size:
|
73728
|
|
2E9D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.586033515.0000000002E9D000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E9D000
|
Size:
|
8192
|
|
2F97000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000000.265884583.0000000002F97000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process new
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F97000
|
Size:
|
16384
|
|
24367F13000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494597288.0000024367F13000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367F13000
|
Size:
|
12288
|
|
6DEAC000
|
unkown image
|
page read and write
|
|
|
|
Name:
|
00000014.00000002.619529506.000000006DEAC000.00000004.00020000.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page read and write
|
Base address:
|
6DEAC000
|
Size:
|
4096
|
|
7F0000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000000F.00000002.494278602.00000000007F0000.00000004.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7F0000
|
Size:
|
4096
|
|
24368718000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.292918238.0000024368718000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24368718000
|
Size:
|
4096
|
|
243685D1000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.500393490.00000243685D1000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
243685D1000
|
Size:
|
4096
|
|
221EC628000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492281999.00000221EC628000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
221EC628000
|
Size:
|
81920
|
|
A20000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494295066.0000000000A20000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
A20000
|
Size:
|
806912
|
|
2F81000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493206990.0000000002F81000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F81000
|
Size:
|
8192
|
|
10E9000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000000.00000002.498881590.00000000010E9000.00000004.00000001.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
10E9000
|
Size:
|
4096
|
|
BF0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493015366.0000000000BF0000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
BF0000
|
Size:
|
4096
|
|
2EC0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493140411.0000000002EC0000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EC0000
|
Size:
|
12288
|
|
24368E10000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000017.00000002.536391165.0000024368E10000.00000002.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
24368E10000
|
Size:
|
65536
|
|
2F1D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.606061856.0000000002F1D000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F1D000
|
Size:
|
8192
|
|
2EB6000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.586799501.0000000002EB6000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EB6000
|
Size:
|
4096
|
|
243685F0000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.501899087.00000243685F0000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
243685F0000
|
Size:
|
8192
|
|
7FF571DA4000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523893560.00007FF571DA4000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF571DA4000
|
Size:
|
8192
|
|
97B000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000000C.00000002.497345266.000000000097B000.00000004.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
97B000
|
Size:
|
20480
|
|
24368615000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.508227436.0000024368615000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24368615000
|
Size:
|
4096
|
|
6DDB0000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000000.00000002.567135782.000000006DDB0000.00000002.00020000.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DDB0000
|
Size:
|
4096
|
|
7C9407F000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494327030.0000007C9407F000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7C9407F000
|
Size:
|
4096
|
|
2EC4000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544163251.0000000002EC4000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EC4000
|
Size:
|
40960
|
|
24367EA0000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494561441.0000024367EA0000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367EA0000
|
Size:
|
49152
|
|
12FC000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000000.00000002.500389692.00000000012FC000.00000004.00000001.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
12FC000
|
Size:
|
16384
|
|
C87E0FB000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492139598.000000C87E0FB000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
C87E0FB000
|
Size:
|
20480
|
|
50C000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000014.00000002.494901880.000000000050C000.00000004.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
50C000
|
Size:
|
16384
|
|
2F05000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494541179.0000000002F05000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F05000
|
Size:
|
12288
|
|
7FF57255F000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000000.280728742.00007FF57255F000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process new
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF57255F000
|
Size:
|
20480
|
|
10D0000
|
heap private
|
page read and write
|
|
|
|
Name:
|
0000000C.00000002.574873109.00000000010D0000.00000004.00000040.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap private
|
Protect:
|
page read and write
|
Base address:
|
10D0000
|
Size:
|
20480
|
|
3560000
|
heap private
|
page read and write
|
|
|
|
Name:
|
00000002.00000002.570154607.0000000003560000.00000004.00000040.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap private
|
Protect:
|
page read and write
|
Base address:
|
3560000
|
Size:
|
20480
|
|
A10000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.531869062.0000000000A10000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
A10000
|
Size:
|
806912
|
|
B40000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.560870706.0000000000B40000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
B40000
|
Size:
|
4096
|
|
7C93979000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494280815.0000007C93979000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7C93979000
|
Size:
|
28672
|
|
3570000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.571963094.0000000003570000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
3570000
|
Size:
|
32768
|
|
2F1D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.604916307.0000000002F1D000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F1D000
|
Size:
|
8192
|
|
7C93DFF000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494310229.0000007C93DFF000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7C93DFF000
|
Size:
|
4096
|
|
2EB9000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.585624947.0000000002EB9000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EB9000
|
Size:
|
8192
|
|
31B0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.500091312.00000000031B0000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
31B0000
|
Size:
|
315392
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
24368E30000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000017.00000002.547241249.0000024368E30000.00000002.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
24368E30000
|
Size:
|
65536
|
|
2F2D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493194494.0000000002F2D000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F2D000
|
Size:
|
73728
|
|
7FF57240D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523940542.00007FF57240D000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF57240D000
|
Size:
|
8192
|
|
2F81000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.551066198.0000000002F81000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F81000
|
Size:
|
8192
|
|
2EC0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.589408794.0000000002EC0000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EC0000
|
Size:
|
12288
|
|
2F1D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493188860.0000000002F1D000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F1D000
|
Size:
|
8192
|
|
C10000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.507288966.0000000000C10000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
C10000
|
Size:
|
4096
|
|
2F05000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.602841854.0000000002F05000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F05000
|
Size:
|
12288
|
|
24368C30000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.521120603.0000024368C30000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24368C30000
|
Size:
|
4096
|
|
C87E1FB000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492145394.000000C87E1FB000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
C87E1FB000
|
Size:
|
20480
|
|
221EC66C000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492313194.00000221EC66C000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
221EC66C000
|
Size:
|
24576
|
|
2F7B000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494582393.0000000002F7B000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F7B000
|
Size:
|
16384
|
|
79C000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000003.00000002.494902610.000000000079C000.00000004.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
79C000
|
Size:
|
16384
|
|
24368E20000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000017.00000002.542887767.0000024368E20000.00000002.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
24368E20000
|
Size:
|
65536
|
|
2E8D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493127616.0000000002E8D000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E8D000
|
Size:
|
28672
|
|
2E8D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.581054158.0000000002E8D000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E8D000
|
Size:
|
28672
|
|
B60000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000018.00000002.493002759.0000000000B60000.00000004.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
B60000
|
Size:
|
4096
|
|
340A000
|
heap default
|
page read and write
|
|
|
|
Name:
|
00000002.00000002.562546047.000000000340A000.00000004.00000020.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
340A000
|
Size:
|
118784
|
|
2436D30E000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.265648865.000002436D30E000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D30E000
|
Size:
|
73728
|
|
7C93C7B000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494296809.0000007C93C7B000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7C93C7B000
|
Size:
|
20480
|
|
2E9D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544140046.0000000002E9D000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E9D000
|
Size:
|
8192
|
|
2F8C000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.554251166.0000000002F8C000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F8C000
|
Size:
|
4096
|
|
2E9D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493131978.0000000002E9D000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E9D000
|
Size:
|
8192
|
|
2DC4000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493121929.0000000002DC4000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2DC4000
|
Size:
|
8192
|
|
FC0000
|
heap default
|
page read and write
|
|
|
|
Name:
|
00000018.00000002.493044415.0000000000FC0000.00000004.00000020.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
FC0000
|
Size:
|
20480
|
|
2F97000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000000.226388585.0000000002F97000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process new
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F97000
|
Size:
|
16384
|
|
2DC4000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.581056909.0000000002DC4000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2DC4000
|
Size:
|
8192
|
|
9E0000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000000C.00000002.500089867.00000000009E0000.00000004.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
9E0000
|
Size:
|
4096
|
|
2F24000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.605590261.0000000002F24000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F24000
|
Size:
|
4096
|
|
2436D4B1000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.300180276.000002436D4B1000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D4B1000
|
Size:
|
8192
|
|
BE0000
|
heap default
|
page read and write
|
|
|
|
Name:
|
00000003.00000002.563719338.0000000000BE0000.00000004.00000020.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
BE0000
|
Size:
|
20480
|
|
10E5000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000000.00000002.497039866.00000000010E5000.00000004.00000001.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
10E5000
|
Size:
|
8192
|
|
2F0D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493185209.0000000002F0D000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F0D000
|
Size:
|
8192
|
|
2EE5000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.598249163.0000000002EE5000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EE5000
|
Size:
|
4096
|
|
221EC658000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492302736.00000221EC658000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
221EC658000
|
Size:
|
73728
|
|
6DDB0000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000002.00000001.226712151.000000006DDB0000.00000002.00020000.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
image loaded
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DDB0000
|
Size:
|
4096
|
|
2EC0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.589005747.0000000002EC0000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EC0000
|
Size:
|
12288
|
|
2E7C000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.582746421.0000000002E7C000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E7C000
|
Size:
|
4096
|
|
2ED0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494496388.0000000002ED0000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2ED0000
|
Size:
|
32768
|
|
2D35000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.580091077.0000000002D35000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2D35000
|
Size:
|
4096
|
|
2F09000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597215731.0000000002F09000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F09000
|
Size:
|
8192
|
|
7C6000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000014.00000002.508866083.00000000007C6000.00000004.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7C6000
|
Size:
|
4096
|
|
24368702000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.511275678.0000024368702000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24368702000
|
Size:
|
32768
|
|
2EF9000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494529671.0000000002EF9000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF9000
|
Size:
|
8192
|
|
6DDB0000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000018.00000001.268333476.000000006DDB0000.00000002.00020000.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
image loaded
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DDB0000
|
Size:
|
4096
|
|
6DDB0000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597319397.000000006DDB0000.00000002.00020000.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DDB0000
|
Size:
|
4096
|
|
E20000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.576767114.0000000000E20000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
E20000
|
Size:
|
32768
|
|
2436D340000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.265803176.000002436D340000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D340000
|
Size:
|
4096
|
|
1070000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.495223875.0000000001070000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
1070000
|
Size:
|
806912
|
|
24368602000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.506687622.0000024368602000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24368602000
|
Size:
|
4096
|
|
6DE95000
|
unkown image
|
page read and write
|
|
|
|
Name:
|
00000002.00000002.620714092.000000006DE95000.00000004.00020000.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page read and write
|
Base address:
|
6DE95000
|
Size:
|
12288
|
|
2F2D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.545036572.0000000002F2D000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F2D000
|
Size:
|
73728
|
|
2EE5000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.595801888.0000000002EE5000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EE5000
|
Size:
|
4096
|
|
2F2D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.606066212.0000000002F2D000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F2D000
|
Size:
|
73728
|
|
2F85000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.609916949.0000000002F85000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F85000
|
Size:
|
24576
|
|
D8A000
|
heap default
|
page read and write
|
|
|
|
Name:
|
0000000C.00000002.518475512.0000000000D8A000.00000004.00000020.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
D8A000
|
Size:
|
122880
|
|
243685F3000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.503678135.00000243685F3000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
243685F3000
|
Size:
|
4096
|
|
24368C10000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.519499436.0000024368C10000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24368C10000
|
Size:
|
4096
|
|
D30000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494439554.0000000000D30000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
D30000
|
Size:
|
32768
|
|
2F09000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494550927.0000000002F09000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F09000
|
Size:
|
8192
|
|
1AA0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000000.00000002.549620718.0000000001AA0000.00000002.00000001.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
1AA0000
|
Size:
|
315392
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
31B0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.612316842.00000000031B0000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
31B0000
|
Size:
|
32768
|
|
2436D300000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.270182592.000002436D300000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D300000
|
Size:
|
4096
|
|
7FF57255F000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.555043489.00007FF57255F000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF57255F000
|
Size:
|
20480
|
|
2D2B000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494447905.0000000002D2B000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2D2B000
|
Size:
|
8192
|
|
2F97000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597271949.0000000002F97000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F97000
|
Size:
|
16384
|
|
2F8C000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.496436255.0000000002F8C000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F8C000
|
Size:
|
4096
|
|
2EFC000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544234031.0000000002EFC000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EFC000
|
Size:
|
32768
|
|
6DEAD000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.551664488.000000006DEAD000.00000002.00020000.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DEAD000
|
Size:
|
28672
|
|
2EC4000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494487860.0000000002EC4000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EC4000
|
Size:
|
40960
|
|
2F8C000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.612182724.0000000002F8C000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F8C000
|
Size:
|
4096
|
|
7C93A7A000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494287524.0000007C93A7A000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7C93A7A000
|
Size:
|
24576
|
|
221EC700000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492324246.00000221EC700000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
221EC700000
|
Size:
|
4096
|
|
6DE95000
|
unkown image
|
page read and write
|
|
|
|
Name:
|
00000014.00000002.618443966.000000006DE95000.00000004.00020000.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page read and write
|
Base address:
|
6DE95000
|
Size:
|
28672
|
|
6DDB0000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.521959783.000000006DDB0000.00000002.00020000.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DDB0000
|
Size:
|
4096
|
|
6DEAD000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.620043150.000000006DEAD000.00000002.00020000.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DEAD000
|
Size:
|
28672
|
|
2EDA000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.594833637.0000000002EDA000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EDA000
|
Size:
|
36864
|
|
2F85000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493209833.0000000002F85000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F85000
|
Size:
|
24576
|
|
2F05000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.604077747.0000000002F05000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F05000
|
Size:
|
12288
|
|
9BB000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000000F.00000002.494285831.00000000009BB000.00000004.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
9BB000
|
Size:
|
4096
|
|
2EF1000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493164169.0000000002EF1000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF1000
|
Size:
|
12288
|
|
24367E79000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494533330.0000024367E79000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367E79000
|
Size:
|
4096
|
|
2DC4000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494457406.0000000002DC4000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2DC4000
|
Size:
|
8192
|
|
3540000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.569145695.0000000003540000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
3540000
|
Size:
|
4096
|
|
7FF572276000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523919348.00007FF572276000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF572276000
|
Size:
|
4096
|
|
850000
|
heap private
|
page read and write
|
|
|
|
Name:
|
00000014.00000002.511877930.0000000000850000.00000004.00000040.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap private
|
Protect:
|
page read and write
|
Base address:
|
850000
|
Size:
|
20480
|
|
B80000
|
heap default
|
page read and write
|
|
|
|
Name:
|
0000000F.00000002.494413894.0000000000B80000.00000004.00000020.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
B80000
|
Size:
|
32768
|
|
3400000
|
heap default
|
page read and write
|
|
|
|
Name:
|
00000002.00000002.560068671.0000000003400000.00000004.00000020.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
3400000
|
Size:
|
32768
|
|
2D35000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.577894735.0000000002D35000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2D35000
|
Size:
|
4096
|
|
6DDB0000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000003.00000001.227063269.000000006DDB0000.00000002.00020000.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
image loaded
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DDB0000
|
Size:
|
4096
|
|
2F24000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544269338.0000000002F24000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F24000
|
Size:
|
4096
|
|
24367C40000
|
heap private
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494334250.0000024367C40000.00000004.00000040.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap private
|
Protect:
|
page read and write
|
Base address:
|
24367C40000
|
Size:
|
4096
|
|
24367E71000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494522844.0000024367E71000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367E71000
|
Size:
|
4096
|
|
7FF572417000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523953704.00007FF572417000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF572417000
|
Size:
|
4096
|
|
D20000
|
heap default
|
page read and write
|
|
|
|
Name:
|
00000003.00000002.567338853.0000000000D20000.00000004.00000020.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
D20000
|
Size:
|
32768
|
|
2E9D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.585626252.0000000002E9D000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E9D000
|
Size:
|
8192
|
|
2F24000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.606697487.0000000002F24000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F24000
|
Size:
|
4096
|
|
2436D300000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.265636557.000002436D300000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D300000
|
Size:
|
28672
|
|
2EFC000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493173093.0000000002EFC000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EFC000
|
Size:
|
32768
|
|
221EC624000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492277187.00000221EC624000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
221EC624000
|
Size:
|
12288
|
|
24367E8C000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494541843.0000024367E8C000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367E8C000
|
Size:
|
20480
|
|
24368390000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000017.00000002.497946299.0000024368390000.00000002.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
24368390000
|
Size:
|
16384
|
|
100B000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000002.00000002.495208182.000000000100B000.00000004.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
100B000
|
Size:
|
20480
|
|
2F97000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000000.236216192.0000000002F97000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process new
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F97000
|
Size:
|
16384
|
|
E1A000
|
heap default
|
page read and write
|
|
|
|
Name:
|
00000018.00000002.493030980.0000000000E1A000.00000004.00000020.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
E1A000
|
Size:
|
122880
|
|
5F0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.505483916.00000000005F0000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
5F0000
|
Size:
|
4096
|
|
2E8D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.583325425.0000000002E8D000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E8D000
|
Size:
|
28672
|
|
6DE3A000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.608296058.000000006DE3A000.00000002.00020000.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DE3A000
|
Size:
|
372736
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
D77000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000018.00000002.493018348.0000000000D77000.00000004.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
D77000
|
Size:
|
8192
|
|
2F97000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000000.226715635.0000000002F97000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process new
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F97000
|
Size:
|
16384
|
|
2EDA000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544191273.0000000002EDA000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EDA000
|
Size:
|
36864
|
|
24368C00000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.517824615.0000024368C00000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24368C00000
|
Size:
|
4096
|
|
2EE5000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494510261.0000000002EE5000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EE5000
|
Size:
|
4096
|
|
8C7000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000003.00000002.501898033.00000000008C7000.00000004.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
8C7000
|
Size:
|
4096
|
|
2EDA000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.593264925.0000000002EDA000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EDA000
|
Size:
|
36864
|
|
24368718000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.288362687.0000024368718000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24368718000
|
Size:
|
4096
|
|
221EC702000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492327290.00000221EC702000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
221EC702000
|
Size:
|
49152
|
|
2EEB000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.596674379.0000000002EEB000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EEB000
|
Size:
|
8192
|
|
2EE5000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.596198739.0000000002EE5000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EE5000
|
Size:
|
4096
|
|
221EC440000
|
heap private
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492158866.00000221EC440000.00000004.00000040.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap private
|
Protect:
|
page read and write
|
Base address:
|
221EC440000
|
Size:
|
4096
|
|
CB0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.510369133.0000000000CB0000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
CB0000
|
Size:
|
4096
|
|
221ED000000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.492351700.00000221ED000000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
221ED000000
|
Size:
|
3371008
|
|
2F97000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493216590.0000000002F97000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F97000
|
Size:
|
16384
|
|
E80000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.529324505.0000000000E80000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
E80000
|
Size:
|
806912
|
|
2EC4000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.590890790.0000000002EC4000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EC4000
|
Size:
|
40960
|
|
7C93CFE000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494302155.0000007C93CFE000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7C93CFE000
|
Size:
|
8192
|
|
1710000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000000.00000002.547242910.0000000001710000.00000002.00000001.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
1710000
|
Size:
|
32768
|
|
6DDB1000
|
unkown image
|
page execute read
|
|
|
|
Name:
|
00000000.00000002.568139486.000000006DDB1000.00000020.00020000.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page execute read
|
Base address:
|
6DDB1000
|
Size:
|
561152
|
|
6DDB1000
|
unkown image
|
page execute read
|
|
|
|
Name:
|
00000003.00000002.619761789.000000006DDB1000.00000020.00020000.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page execute read
|
Base address:
|
6DDB1000
|
Size:
|
8192
|
|
2F1D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544263169.0000000002F1D000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F1D000
|
Size:
|
8192
|
|
221EC600000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492257776.00000221EC600000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
221EC600000
|
Size:
|
4096
|
|
7FF56B13F000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000017.00000000.263066461.00007FF56B13F000.00000002.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process new
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF56B13F000
|
Size:
|
20480
|
|
74C000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000000F.00000002.494265774.000000000074C000.00000004.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
74C000
|
Size:
|
16384
|
|
221EC5A0000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492254170.00000221EC5A0000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
221EC5A0000
|
Size:
|
4096
|
|
D7B000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000018.00000002.493022017.0000000000D7B000.00000004.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
D7B000
|
Size:
|
4096
|
|
2EF9000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544227850.0000000002EF9000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF9000
|
Size:
|
8192
|
|
A5B000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000000C.00000002.501594884.0000000000A5B000.00000004.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
A5B000
|
Size:
|
8192
|
|
7FF572467000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523972003.00007FF572467000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF572467000
|
Size:
|
8192
|
|
24367E13000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494465205.0000024367E13000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367E13000
|
Size:
|
86016
|
|
7C93B7F000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494293145.0000007C93B7F000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7C93B7F000
|
Size:
|
4096
|
|
5B0000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000014.00000002.500088260.00000000005B0000.00000004.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
5B0000
|
Size:
|
4096
|
|
24368E40000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000017.00000002.551270802.0000024368E40000.00000002.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
24368E40000
|
Size:
|
65536
|
|
6DDB0000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.619443639.000000006DDB0000.00000002.00020000.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DDB0000
|
Size:
|
4096
|
|
AE0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.576548433.0000000000AE0000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
AE0000
|
Size:
|
32768
|
|
7FF57252B000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.544395150.00007FF57252B000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF57252B000
|
Size:
|
4096
|
|
2E8D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544131687.0000000002E8D000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E8D000
|
Size:
|
28672
|
|
2EB6000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544146115.0000000002EB6000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EB6000
|
Size:
|
4096
|
|
2436D4AE000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.295561903.000002436D4AE000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D4AE000
|
Size:
|
8192
|
|
2EF1000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544213052.0000000002EF1000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF1000
|
Size:
|
12288
|
|
6DEAC000
|
unkown image
|
page read and write
|
|
|
|
Name:
|
00000000.00000002.609706769.000000006DEAC000.00000004.00020000.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page read and write
|
Base address:
|
6DEAC000
|
Size:
|
4096
|
|
CA0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.508864489.0000000000CA0000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
CA0000
|
Size:
|
4096
|
|
6DEAC000
|
unkown image
|
page read and write
|
|
|
|
Name:
|
00000018.00000002.550625167.000000006DEAC000.00000004.00020000.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page read and write
|
Base address:
|
6DEAC000
|
Size:
|
4096
|
|
1510000
|
heap default
|
page read and write
|
|
|
|
Name:
|
00000000.00000002.534281279.0000000001510000.00000004.00000020.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
1510000
|
Size:
|
36864
|
|
D20000
|
heap private
|
page read and write
|
|
|
|
Name:
|
0000000F.00000002.494433513.0000000000D20000.00000004.00000040.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap private
|
Protect:
|
page read and write
|
Base address:
|
D20000
|
Size:
|
20480
|
|
2ED0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544181924.0000000002ED0000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2ED0000
|
Size:
|
32768
|
|
7C93FFE000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494322620.0000007C93FFE000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7C93FFE000
|
Size:
|
8192
|
|
5D0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.501596920.00000000005D0000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
5D0000
|
Size:
|
16384
|
|
2EB9000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.587803340.0000000002EB9000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EB9000
|
Size:
|
8192
|
|
2F85000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597261217.0000000002F85000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F85000
|
Size:
|
24576
|
|
2D35000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493119217.0000000002D35000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2D35000
|
Size:
|
4096
|
|
78B000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000000F.00000002.494273469.000000000078B000.00000004.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
78B000
|
Size:
|
20480
|
|
2EDA000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493154028.0000000002EDA000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EDA000
|
Size:
|
36864
|
|
7FF572495000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.525212522.00007FF572495000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF572495000
|
Size:
|
8192
|
|
A5F000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000000C.00000002.503370716.0000000000A5F000.00000004.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
A5F000
|
Size:
|
4096
|
|
2436D321000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.265659346.000002436D321000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D321000
|
Size:
|
4096
|
|
2EEB000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493161414.0000000002EEB000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EEB000
|
Size:
|
8192
|
|
2436D4AC000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.294320709.000002436D4AC000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D4AC000
|
Size:
|
4096
|
|
2EEB000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544206985.0000000002EEB000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EEB000
|
Size:
|
8192
|
|
31F0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.556853574.00000000031F0000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
31F0000
|
Size:
|
4096
|
|
7FF5722A9000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523923327.00007FF5722A9000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF5722A9000
|
Size:
|
4096
|
|
7FF57255D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.554044777.00007FF57255D000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF57255D000
|
Size:
|
4096
|
|
FCC000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000002.00000002.494900644.0000000000FCC000.00000004.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
FCC000
|
Size:
|
16384
|
|
B50000
|
heap private
|
page read and write
|
|
|
|
Name:
|
00000003.00000002.561875384.0000000000B50000.00000004.00000040.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap private
|
Protect:
|
page read and write
|
Base address:
|
B50000
|
Size:
|
20480
|
|
221EC602000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492260740.00000221EC602000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
221EC602000
|
Size:
|
65536
|
|
2EFC000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.602838628.0000000002EFC000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EFC000
|
Size:
|
32768
|
|
7C93EFA000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494313951.0000007C93EFA000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7C93EFA000
|
Size:
|
24576
|
|
B10000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000003.00000002.558259337.0000000000B10000.00000004.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
B10000
|
Size:
|
4096
|
|
2EF1000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.600293403.0000000002EF1000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF1000
|
Size:
|
12288
|
|
7C9427E000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494330574.0000007C9427E000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7C9427E000
|
Size:
|
8192
|
|
2F09000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.603634221.0000000002F09000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F09000
|
Size:
|
8192
|
|
6DEAC000
|
unkown image
|
page read and write
|
|
|
|
Name:
|
0000000F.00000002.582478013.000000006DEAC000.00000004.00020000.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page read and write
|
Base address:
|
6DEAC000
|
Size:
|
4096
|
|
8C3000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000003.00000002.500091968.00000000008C3000.00000004.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
8C3000
|
Size:
|
8192
|
|
D00000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.566332252.0000000000D00000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
D00000
|
Size:
|
4096
|
|
2F0D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544255956.0000000002F0D000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F0D000
|
Size:
|
8192
|
|
7DB000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000003.00000002.497344554.00000000007DB000.00000004.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7DB000
|
Size:
|
20480
|
|
2E8D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494464876.0000000002E8D000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E8D000
|
Size:
|
28672
|
|
7FF5724A3000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.529992859.00007FF5724A3000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF5724A3000
|
Size:
|
12288
|
|
5E0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.503974941.00000000005E0000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
5E0000
|
Size:
|
4096
|
|
2EF9000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.600491865.0000000002EF9000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF9000
|
Size:
|
8192
|
|
24367E7B000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494537807.0000024367E7B000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367E7B000
|
Size:
|
4096
|
|
C87E2FF000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492151624.000000C87E2FF000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
C87E2FF000
|
Size:
|
4096
|
|
1490000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000000.00000002.533430835.0000000001490000.00000002.00000001.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
1490000
|
Size:
|
16384
|
|
6DDB3000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.620321006.000000006DDB3000.00000002.00020000.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DDB3000
|
Size:
|
4096
|
|
7FF5721EA000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523914361.00007FF5721EA000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF5721EA000
|
Size:
|
4096
|
|
7C93D7F000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494306151.0000007C93D7F000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7C93D7F000
|
Size:
|
4096
|
|
2F81000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.610406630.0000000002F81000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F81000
|
Size:
|
8192
|
|
221EC63D000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492291597.00000221EC63D000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
221EC63D000
|
Size:
|
106496
|
|
7FF5724AA000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.532171191.00007FF5724AA000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF5724AA000
|
Size:
|
16384
|
|
2D2B000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.576755804.0000000002D2B000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2D2B000
|
Size:
|
8192
|
|
24368713000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.515027563.0000024368713000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24368713000
|
Size:
|
20480
|
|
6DDB1000
|
unkown image
|
page execute read
|
|
|
|
Name:
|
00000018.00000002.523505436.000000006DDB1000.00000020.00020000.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page execute read
|
Base address:
|
6DDB1000
|
Size:
|
561152
|
|
2EF9000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493169855.0000000002EF9000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF9000
|
Size:
|
8192
|
|
2EF1000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.598049990.0000000002EF1000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF1000
|
Size:
|
12288
|
|
24367F02000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494587631.0000024367F02000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367F02000
|
Size:
|
45056
|
|
24368758000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.292923706.0000024368758000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24368758000
|
Size:
|
8192
|
|
221EC580000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.492244734.00000221EC580000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
221EC580000
|
Size:
|
16384
|
|
93C000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000000C.00000002.494902309.000000000093C000.00000004.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
93C000
|
Size:
|
16384
|
|
2436D460000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.265616103.000002436D460000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D460000
|
Size:
|
8192
|
|
2EB9000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544151436.0000000002EB9000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EB9000
|
Size:
|
8192
|
|
C87E3FE000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492155230.000000C87E3FE000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
C87E3FE000
|
Size:
|
8192
|
|
1180000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544102496.0000000001180000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
1180000
|
Size:
|
4096
|
|
6DE3A000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.561475064.000000006DE3A000.00000002.00020000.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DE3A000
|
Size:
|
372736
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2F09000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.604812821.0000000002F09000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F09000
|
Size:
|
8192
|
|
4800000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000003.00000002.619412894.0000000004800000.00000004.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
4800000
|
Size:
|
4096
|
|
B8A000
|
heap default
|
page read and write
|
|
|
|
Name:
|
0000000F.00000002.494419875.0000000000B8A000.00000004.00000020.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
B8A000
|
Size:
|
122880
|
|
2E7C000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.580088137.0000000002E7C000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E7C000
|
Size:
|
4096
|
|
B50000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494406818.0000000000B50000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
B50000
|
Size:
|
4096
|
|
7FF57254B000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.551065147.00007FF57254B000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF57254B000
|
Size:
|
8192
|
|
2EDA000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494502744.0000000002EDA000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EDA000
|
Size:
|
36864
|
|
9B7000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000000F.00000002.494282718.00000000009B7000.00000004.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
9B7000
|
Size:
|
8192
|
|
2DC4000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.578896831.0000000002DC4000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2DC4000
|
Size:
|
8192
|
|
7FF57253D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.548416145.00007FF57253D000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF57253D000
|
Size:
|
16384
|
|
478E000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000003.00000002.619397203.000000000478E000.00000004.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
478E000
|
Size:
|
8192
|
|
2F0D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.604285302.0000000002F0D000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F0D000
|
Size:
|
8192
|
|
1350000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000000.00000002.502765765.0000000001350000.00000004.00000001.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
1350000
|
Size:
|
4096
|
|
7FF57254E000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.552337260.00007FF57254E000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF57254E000
|
Size:
|
16384
|
|
2F8C000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493214054.0000000002F8C000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F8C000
|
Size:
|
4096
|
|
7FF57232E000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523930851.00007FF57232E000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF57232E000
|
Size:
|
4096
|
|
24368600000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.505180116.0000024368600000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24368600000
|
Size:
|
4096
|
|
24367EFD000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494581456.0000024367EFD000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367EFD000
|
Size:
|
16384
|
|
7C2000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000014.00000002.506990276.00000000007C2000.00000004.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7C2000
|
Size:
|
8192
|
|
6DEAD000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000000.00000002.610220654.000000006DEAD000.00000002.00020000.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DEAD000
|
Size:
|
28672
|
|
6DDB0000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.590655909.000000006DDB0000.00000002.00020000.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DDB0000
|
Size:
|
4096
|
|
2EC4000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.590255072.0000000002EC4000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EC4000
|
Size:
|
40960
|
|
2F97000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.611379496.0000000002F97000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F97000
|
Size:
|
16384
|
|
24367E93000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494552402.0000024367E93000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367E93000
|
Size:
|
49152
|
|
7FF5722D7000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523926977.00007FF5722D7000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF5722D7000
|
Size:
|
4096
|
|
1170000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544095783.0000000001170000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
1170000
|
Size:
|
16384
|
|
FD0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493048447.0000000000FD0000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
FD0000
|
Size:
|
806912
|
|
24367E41000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494493589.0000024367E41000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367E41000
|
Size:
|
81920
|
|
2F97000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.612788122.0000000002F97000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F97000
|
Size:
|
16384
|
|
7FF572544000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.550022691.00007FF572544000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF572544000
|
Size:
|
4096
|
|
6DE3A000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000000.00000002.596199111.000000006DE3A000.00000002.00020000.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DE3A000
|
Size:
|
372736
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2F85000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.552142770.0000000002F85000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F85000
|
Size:
|
24576
|
|
FED000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000000.00000002.494896820.0000000000FED000.00000004.00000001.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
FED000
|
Size:
|
12288
|
|
2E7C000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494461561.0000000002E7C000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E7C000
|
Size:
|
4096
|
|
2D35000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544115528.0000000002D35000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2D35000
|
Size:
|
4096
|
|
2EB6000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.584623326.0000000002EB6000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EB6000
|
Size:
|
4096
|
|
AF0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494397779.0000000000AF0000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
AF0000
|
Size:
|
16384
|
|
32D3000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000002.00000002.559063871.00000000032D3000.00000004.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
32D3000
|
Size:
|
4096
|
|
2E9D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.583323827.0000000002E9D000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E9D000
|
Size:
|
8192
|
|
2E7C000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493124936.0000000002E7C000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E7C000
|
Size:
|
4096
|
|
1360000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000000.00000002.504273626.0000000001360000.00000002.00000001.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
1360000
|
Size:
|
4096
|
|
3900000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.574472644.0000000003900000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
3900000
|
Size:
|
315392
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
3070000
|
heap private
|
page read and write
|
|
|
|
Name:
|
00000000.00000002.565931578.0000000003070000.00000004.00000040.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap private
|
Protect:
|
page read and write
|
Base address:
|
3070000
|
Size:
|
8192
|
|
221EC67F000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492319531.00000221EC67F000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
221EC67F000
|
Size:
|
4096
|
|
2EF5000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.599393135.0000000002EF5000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF5000
|
Size:
|
8192
|
|
2F05000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544242948.0000000002F05000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F05000
|
Size:
|
12288
|
|
B30000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.559263975.0000000000B30000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
B30000
|
Size:
|
16384
|
|
24368E50000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000017.00000002.555446333.0000024368E50000.00000002.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
24368E50000
|
Size:
|
2138112
|
|
2F09000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544250032.0000000002F09000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F09000
|
Size:
|
8192
|
|
7FF572526000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.541986378.00007FF572526000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF572526000
|
Size:
|
16384
|
|
2F24000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493191828.0000000002F24000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F24000
|
Size:
|
4096
|
|
2436D4B2000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.302424604.000002436D4B2000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D4B2000
|
Size:
|
4096
|
|
2436D308000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.265643959.000002436D308000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D308000
|
Size:
|
16384
|
|
221EC4B0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.492165834.00000221EC4B0000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
221EC4B0000
|
Size:
|
806912
|
|
2EB9000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.588170171.0000000002EB9000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EB9000
|
Size:
|
8192
|
|
221EC713000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492334313.00000221EC713000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
221EC713000
|
Size:
|
16384
|
|
2F2D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.607225647.0000000002F2D000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F2D000
|
Size:
|
73728
|
|
24368759000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.292927852.0000024368759000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24368759000
|
Size:
|
4096
|
|
1150000
|
heap default
|
page read and write
|
|
|
|
Name:
|
00000002.00000002.541987705.0000000001150000.00000004.00000020.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
1150000
|
Size:
|
20480
|
|
7FF572499000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.527083102.00007FF572499000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF572499000
|
Size:
|
20480
|
|
2EC0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494483510.0000000002EC0000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EC0000
|
Size:
|
12288
|
|
6DDB1000
|
unkown image
|
page execute read
|
|
|
|
Name:
|
00000002.00000002.591627412.000000006DDB1000.00000020.00020000.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page execute read
|
Base address:
|
6DDB1000
|
Size:
|
561152
|
|
2F0D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494556426.0000000002F0D000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F0D000
|
Size:
|
8192
|
|
2D35000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.580436833.0000000002D35000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2D35000
|
Size:
|
4096
|
|
2ED0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.593527227.0000000002ED0000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2ED0000
|
Size:
|
32768
|
|
2F1D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597227125.0000000002F1D000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F1D000
|
Size:
|
8192
|
|
2E9D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494470407.0000000002E9D000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E9D000
|
Size:
|
8192
|
|
2D2B000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544109491.0000000002D2B000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2D2B000
|
Size:
|
8192
|
|
2F8C000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597267339.0000000002F8C000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F8C000
|
Size:
|
4096
|
|
2EEB000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.599220398.0000000002EEB000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EEB000
|
Size:
|
8192
|
|
2F85000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.611078329.0000000002F85000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F85000
|
Size:
|
24576
|
|
ABC000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000018.00000002.492994257.0000000000ABC000.00000004.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
ABC000
|
Size:
|
16384
|
|
3570000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.496937623.0000000003570000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
3570000
|
Size:
|
315392
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
6DDB0000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000000.00000001.272718847.000000006DDB0000.00000002.00020000.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
image loaded
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DDB0000
|
Size:
|
4096
|
|
91A000
|
heap default
|
page read and write
|
|
|
|
Name:
|
00000014.00000002.521473850.000000000091A000.00000004.00000020.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
91A000
|
Size:
|
118784
|
|
2D35000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494452451.0000000002D35000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2D35000
|
Size:
|
4096
|
|
6DDB0000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000014.00000001.264924585.000000006DDB0000.00000002.00020000.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
image loaded
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DDB0000
|
Size:
|
4096
|
|
2F05000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493177949.0000000002F05000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F05000
|
Size:
|
12288
|
|
2436D660000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.266840755.000002436D660000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D660000
|
Size:
|
4096
|
|
2EF9000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.602170483.0000000002EF9000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF9000
|
Size:
|
8192
|
|
2F05000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597206055.0000000002F05000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F05000
|
Size:
|
12288
|
|
2F0D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597221423.0000000002F0D000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F0D000
|
Size:
|
8192
|
|
2EF5000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597190350.0000000002EF5000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF5000
|
Size:
|
8192
|
|
24367E56000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494506563.0000024367E56000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367E56000
|
Size:
|
4096
|
|
6DDB1000
|
unkown image
|
page execute read
|
|
|
|
Name:
|
0000000F.00000002.526779862.000000006DDB1000.00000020.00020000.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page execute read
|
Base address:
|
6DDB1000
|
Size:
|
561152
|
|
2D2B000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493115643.0000000002D2B000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2D2B000
|
Size:
|
8192
|
|
7FF57246C000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523976217.00007FF57246C000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF57246C000
|
Size:
|
20480
|
|
2EF9000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597195137.0000000002EF9000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF9000
|
Size:
|
8192
|
|
A10000
|
heap default
|
page read and write
|
|
|
|
Name:
|
0000000F.00000002.494290125.0000000000A10000.00000004.00000020.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
A10000
|
Size:
|
20480
|
|
B90000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493009393.0000000000B90000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
B90000
|
Size:
|
4096
|
|
2EFC000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494535004.0000000002EFC000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EFC000
|
Size:
|
32768
|
|
3540000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.613557283.0000000003540000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
3540000
|
Size:
|
315392
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
6DE3A000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.538841611.000000006DE3A000.00000002.00020000.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DE3A000
|
Size:
|
372736
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
910000
|
heap default
|
page read and write
|
|
|
|
Name:
|
00000014.00000002.517502962.0000000000910000.00000004.00000020.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
910000
|
Size:
|
32768
|
|
24367CB0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000017.00000002.494342069.0000024367CB0000.00000002.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
24367CB0000
|
Size:
|
806912
|
|
7C93877000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494274071.0000007C93877000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7C93877000
|
Size:
|
36864
|
|
24367E29000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494477462.0000024367E29000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367E29000
|
Size:
|
94208
|
|
2F09000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493182037.0000000002F09000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F09000
|
Size:
|
8192
|
|
24367D80000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000017.00000002.494436946.0000024367D80000.00000002.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
24367D80000
|
Size:
|
16384
|
|
47CF000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000003.00000002.619405994.00000000047CF000.00000004.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
47CF000
|
Size:
|
4096
|
|
2D2B000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.578903085.0000000002D2B000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2D2B000
|
Size:
|
8192
|
|
54B000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000014.00000002.497343263.000000000054B000.00000004.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
54B000
|
Size:
|
20480
|
|
D80000
|
heap default
|
page read and write
|
|
|
|
Name:
|
0000000C.00000002.514556792.0000000000D80000.00000004.00000020.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
D80000
|
Size:
|
32768
|
|
2F7B000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493203204.0000000002F7B000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F7B000
|
Size:
|
16384
|
|
221EC4A0000
|
heap default
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492162134.00000221EC4A0000.00000004.00000020.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
221EC4A0000
|
Size:
|
8192
|
|
221ECE02000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492348158.00000221ECE02000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
221ECE02000
|
Size:
|
4096
|
|
2EEB000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494514008.0000000002EEB000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EEB000
|
Size:
|
8192
|
|
2EFC000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.601598709.0000000002EFC000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EFC000
|
Size:
|
32768
|
|
2EEB000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597179039.0000000002EEB000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EEB000
|
Size:
|
8192
|
|
2F24000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494565888.0000000002F24000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F24000
|
Size:
|
4096
|
|
221EC800000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.492340103.00000221EC800000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
221EC800000
|
Size:
|
4096
|
|
2EF5000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544219890.0000000002EF5000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF5000
|
Size:
|
8192
|
|
CC0000
|
heap default
|
page read and write
|
|
|
|
Name:
|
0000000C.00000002.511877027.0000000000CC0000.00000004.00000020.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
CC0000
|
Size:
|
20480
|
|
2436D660000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.266835553.000002436D660000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D660000
|
Size:
|
4096
|
|
7FF57252E000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.545433693.00007FF57252E000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF57252E000
|
Size:
|
45056
|
|
221EC590000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.492250296.00000221EC590000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
221EC590000
|
Size:
|
4096
|
|
2F81000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494587166.0000000002F81000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F81000
|
Size:
|
8192
|
|
151B000
|
heap default
|
page read and write
|
|
|
|
Name:
|
00000000.00000002.537964034.000000000151B000.00000004.00000020.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
151B000
|
Size:
|
122880
|
|
2EB6000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.587199767.0000000002EB6000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EB6000
|
Size:
|
4096
|
|
7FF572457000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523968242.00007FF572457000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF572457000
|
Size:
|
4096
|
|
2EB6000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494474273.0000000002EB6000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EB6000
|
Size:
|
4096
|
|
2F1D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494561202.0000000002F1D000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F1D000
|
Size:
|
8192
|
|
32CF000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000002.00000002.557857263.00000000032CF000.00000004.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
32CF000
|
Size:
|
8192
|
|
2EC0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544157017.0000000002EC0000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EC0000
|
Size:
|
12288
|
|
2DC4000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.581481405.0000000002DC4000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2DC4000
|
Size:
|
8192
|
|
24368000000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000017.00000002.496439736.0000024368000000.00000002.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
24368000000
|
Size:
|
4096
|
|
2F81000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597256343.0000000002F81000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F81000
|
Size:
|
8192
|
|
24367E58000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494509861.0000024367E58000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367E58000
|
Size:
|
73728
|
|
2F24000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597232278.0000000002F24000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F24000
|
Size:
|
4096
|
|
2D2B000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.579264859.0000000002D2B000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2D2B000
|
Size:
|
8192
|
|
7C93F7F000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494319100.0000007C93F7F000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7C93F7F000
|
Size:
|
4096
|
|
2436D450000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.265696513.000002436D450000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D450000
|
Size:
|
4096
|
|
2EF1000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494518753.0000000002EF1000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF1000
|
Size:
|
12288
|
|
2EDA000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.595704341.0000000002EDA000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EDA000
|
Size:
|
36864
|
|
6DE3A000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.610940867.000000006DE3A000.00000002.00020000.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DE3A000
|
Size:
|
372736
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
Binary contains paths to debug symbols |
Compliance, System Summary |
|
|
2F2D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597236857.0000000002F2D000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F2D000
|
Size:
|
73728
|
|
24367CA0000
|
heap default
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494337708.0000024367CA0000.00000004.00000020.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
24367CA0000
|
Size:
|
12288
|
|
13B0000
|
heap default
|
page read and write
|
|
|
|
Name:
|
00000000.00000002.505789228.00000000013B0000.00000004.00000020.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
13B0000
|
Size:
|
20480
|
|
6DE95000
|
unkown image
|
page read and write
|
|
|
|
Name:
|
00000000.00000002.608518190.000000006DE95000.00000004.00020000.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page read and write
|
Base address:
|
6DE95000
|
Size:
|
28672
|
|
AFB000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000018.00000002.492998809.0000000000AFB000.00000004.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
AFB000
|
Size:
|
20480
|
|
2F2D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494569685.0000000002F2D000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F2D000
|
Size:
|
73728
|
|
C00000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.504879912.0000000000C00000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
C00000
|
Size:
|
16384
|
|
2ED0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.593096912.0000000002ED0000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2ED0000
|
Size:
|
32768
|
|
2436D344000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.265807599.000002436D344000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D344000
|
Size:
|
4096
|
|
7FF5724C5000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.534581661.00007FF5724C5000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF5724C5000
|
Size:
|
12288
|
|
3360000
|
heap private
|
page read and write
|
|
|
|
Name:
|
00000018.00000002.493220675.0000000003360000.00000004.00000040.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap private
|
Protect:
|
page read and write
|
Base address:
|
3360000
|
Size:
|
20480
|
|
7FF57244C000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523964158.00007FF57244C000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF57244C000
|
Size:
|
4096
|
|
2EC0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.586797346.0000000002EC0000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EC0000
|
Size:
|
12288
|
|
2EB9000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493137533.0000000002EB9000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EB9000
|
Size:
|
8192
|
|
6DDB1000
|
unkown image
|
page execute read
|
|
|
|
Name:
|
00000014.00000002.597326528.000000006DDB1000.00000020.00020000.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page execute read
|
Base address:
|
6DDB1000
|
Size:
|
561152
|
|
13C0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000000.00000002.508529042.00000000013C0000.00000002.00000001.sdmp
|
TargetID:
|
0
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
13C0000
|
Size:
|
806912
|
|
2436D660000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.266844848.000002436D660000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D660000
|
Size:
|
4096
|
|
2F7B000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.608398652.0000000002F7B000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F7B000
|
Size:
|
16384
|
|
24368D10000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.522679819.0000024368D10000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24368D10000
|
Size:
|
4096
|
|
2EF1000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597184795.0000000002EF1000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF1000
|
Size:
|
12288
|
|
2436D330000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000003.265703807.000002436D330000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
free memory
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
2436D330000
|
Size:
|
8192
|
|
2EB9000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494477745.0000000002EB9000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EB9000
|
Size:
|
8192
|
|
2EF5000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494524949.0000000002EF5000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF5000
|
Size:
|
8192
|
|
6DDB0000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.525210035.000000006DDB0000.00000002.00020000.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DDB0000
|
Size:
|
4096
|
|
2EFC000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597199604.0000000002EFC000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EFC000
|
Size:
|
32768
|
|
BF0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.565327758.0000000000BF0000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
BF0000
|
Size:
|
4096
|
|
7FF572442000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523958702.00007FF572442000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF572442000
|
Size:
|
8192
|
|
C87DFFA000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492132865.000000C87DFFA000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
C87DFFA000
|
Size:
|
24576
|
|
BE0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493012311.0000000000BE0000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
BE0000
|
Size:
|
4096
|
|
7FF57251F000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.538902177.00007FF57251F000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF57251F000
|
Size:
|
20480
|
|
2E7C000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544126663.0000000002E7C000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2E7C000
|
Size:
|
4096
|
|
7FF572091000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.523908965.00007FF572091000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
7FF572091000
|
Size:
|
4096
|
|
6DDB0000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
0000000F.00000001.245827082.000000006DDB0000.00000002.00020000.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
image loaded
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DDB0000
|
Size:
|
4096
|
|
8C0000
|
heap default
|
page read and write
|
|
|
|
Name:
|
00000014.00000002.514557433.00000000008C0000.00000004.00000020.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
8C0000
|
Size:
|
20480
|
|
2EF5000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493167000.0000000002EF5000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF5000
|
Size:
|
8192
|
|
2EF5000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.601565008.0000000002EF5000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EF5000
|
Size:
|
8192
|
|
2EE5000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493158951.0000000002EE5000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EE5000
|
Size:
|
4096
|
|
24368DF0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000017.00000002.524305473.0000024368DF0000.00000002.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
24368DF0000
|
Size:
|
65536
|
|
2F85000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000002.494591713.0000000002F85000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F85000
|
Size:
|
24576
|
|
6DE95000
|
unkown image
|
page read and write
|
|
|
|
Name:
|
0000000F.00000002.580235339.000000006DE95000.00000004.00020000.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page read and write
|
Base address:
|
6DE95000
|
Size:
|
28672
|
|
A40000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.503372407.0000000000A40000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
A40000
|
Size:
|
806912
|
|
6DE95000
|
unkown image
|
page read and write
|
|
|
|
Name:
|
00000018.00000002.548414228.000000006DE95000.00000004.00020000.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown image
|
Protect:
|
page read and write
|
Base address:
|
6DE95000
|
Size:
|
28672
|
|
6DDB0000
|
unkown image
|
page readonly
|
|
|
|
Name:
|
0000000C.00000001.238003615.000000006DDB0000.00000002.00020000.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
image loaded
|
Regiontype:
|
unkown image
|
Protect:
|
page readonly
|
Base address:
|
6DDB0000
|
Size:
|
4096
|
|
840000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.510370559.0000000000840000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
840000
|
Size:
|
4096
|
|
2F97000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000000.255153396.0000000002F97000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process new
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F97000
|
Size:
|
16384
|
|
2F97000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000F.00000000.244752166.0000000002F97000.00000002.00000001.sdmp
|
TargetID:
|
15
|
Dumpstage:
|
process new
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F97000
|
Size:
|
16384
|
|
E10000
|
heap default
|
page read and write
|
|
|
|
Name:
|
00000018.00000002.493025514.0000000000E10000.00000004.00000020.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
heap default
|
Protect:
|
page read and write
|
Base address:
|
E10000
|
Size:
|
32768
|
|
24367DB0000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494450733.0000024367DB0000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367DB0000
|
Size:
|
4096
|
|
31B0000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000014.00000002.597280299.00000000031B0000.00000002.00000001.sdmp
|
TargetID:
|
20
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
31B0000
|
Size:
|
315392
|
Signature Hits |
Behavior Group |
Mitre Attack |
|
May try to detect the Windows Explorer process (often used for injection) |
HIPS / PFW / Operating System Protection Evasion |
|
|
2F7B000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.609603491.0000000002F7B000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F7B000
|
Size:
|
16384
|
|
2F81000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.609268113.0000000002F81000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F81000
|
Size:
|
8192
|
|
221ECB90000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000001F.00000002.492343902.00000221ECB90000.00000002.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
221ECB90000
|
Size:
|
16384
|
|
2F8C000
|
unkown
|
page readonly
|
|
|
|
Name:
|
0000000C.00000002.610941968.0000000002F8C000.00000002.00000001.sdmp
|
TargetID:
|
12
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F8C000
|
Size:
|
4096
|
|
2F0D000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000003.00000002.605426553.0000000002F0D000.00000002.00000001.sdmp
|
TargetID:
|
3
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2F0D000
|
Size:
|
8192
|
|
24368700000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.509766686.0000024368700000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24368700000
|
Size:
|
4096
|
|
C87DB8B000
|
unkown
|
page read and write
|
|
|
|
Name:
|
0000001F.00000002.492126321.000000C87DB8B000.00000004.00000001.sdmp
|
TargetID:
|
31
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
C87DB8B000
|
Size:
|
20480
|
|
7C9367B000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494268228.0000007C9367B000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
7C9367B000
|
Size:
|
20480
|
|
2EE5000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000002.00000002.544200913.0000000002EE5000.00000002.00000001.sdmp
|
TargetID:
|
2
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EE5000
|
Size:
|
4096
|
|
2EB6000
|
unkown
|
page readonly
|
|
|
|
Name:
|
00000018.00000002.493135071.0000000002EB6000.00000002.00000001.sdmp
|
TargetID:
|
24
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page readonly
|
Base address:
|
2EB6000
|
Size:
|
4096
|
|
24367E76000
|
unkown
|
page read and write
|
|
|
|
Name:
|
00000017.00000002.494528230.0000024367E76000.00000004.00000001.sdmp
|
TargetID:
|
23
|
Dumpstage:
|
process exit
|
Regiontype:
|
unkown
|
Protect:
|
page read and write
|
Base address:
|
24367E76000
|
Size:
|
8192
|
|