Overview
overview
5Static
static
4TeraBox_sl....1.exe
windows7-x64
4TeraBox_sl....1.exe
windows10-2004-x64
4$PLUGINSDI...UI.dll
windows7-x64
3$PLUGINSDI...UI.dll
windows10-2004-x64
3$PLUGINSDI...em.dll
windows7-x64
3$PLUGINSDI...em.dll
windows10-2004-x64
3$PLUGINSDI...sW.dll
windows7-x64
3$PLUGINSDI...sW.dll
windows10-2004-x64
3$TEMP/kernel.dll
windows7-x64
1$TEMP/kernel.dll
windows10-2004-x64
1AppUtil.dll
windows7-x64
1AppUtil.dll
windows10-2004-x64
1AutoUpdate...il.dll
windows7-x64
1AutoUpdate...il.dll
windows10-2004-x64
3AutoUpdate...te.exe
windows7-x64
1AutoUpdate...te.exe
windows10-2004-x64
1BugReport.exe
windows7-x64
3BugReport.exe
windows10-2004-x64
5Bull140U.dll
windows7-x64
1Bull140U.dll
windows10-2004-x64
1ChromeNati...st.exe
windows7-x64
1ChromeNati...st.exe
windows10-2004-x64
1HelpUtility.exe
windows7-x64
1HelpUtility.exe
windows10-2004-x64
1TeraBox.exe
windows7-x64
5TeraBox.exe
windows10-2004-x64
5TeraBoxHost.exe
windows7-x64
1TeraBoxHost.exe
windows10-2004-x64
1TeraBoxRender.exe
windows7-x64
1TeraBoxRender.exe
windows10-2004-x64
1TeraBoxWebService.exe
windows7-x64
1TeraBoxWebService.exe
windows10-2004-x64
1Analysis
-
max time kernel
15s -
max time network
173s -
platform
windows7_x64 -
resource
win7-20240221-en -
resource tags
arch:x64arch:x86image:win7-20240221-enlocale:en-usos:windows7-x64system -
submitted
30-06-2024 11:54
Behavioral task
behavioral1
Sample
TeraBox_sl_b_1.31.0.1.exe
Resource
win7-20240419-en
Behavioral task
behavioral2
Sample
TeraBox_sl_b_1.31.0.1.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral3
Sample
$PLUGINSDIR/NsisInstallUI.dll
Resource
win7-20240508-en
Behavioral task
behavioral4
Sample
$PLUGINSDIR/NsisInstallUI.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral5
Sample
$PLUGINSDIR/System.dll
Resource
win7-20240611-en
Behavioral task
behavioral6
Sample
$PLUGINSDIR/System.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral7
Sample
$PLUGINSDIR/nsProcessW.dll
Resource
win7-20240508-en
Behavioral task
behavioral8
Sample
$PLUGINSDIR/nsProcessW.dll
Resource
win10v2004-20240226-en
Behavioral task
behavioral9
Sample
$TEMP/kernel.dll
Resource
win7-20240611-en
Behavioral task
behavioral10
Sample
$TEMP/kernel.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral11
Sample
AppUtil.dll
Resource
win7-20231129-en
Behavioral task
behavioral12
Sample
AppUtil.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral13
Sample
AutoUpdate/AutoUpdateUtil.dll
Resource
win7-20240220-en
Behavioral task
behavioral14
Sample
AutoUpdate/AutoUpdateUtil.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral15
Sample
AutoUpdate/Autoupdate.exe
Resource
win7-20240221-en
Behavioral task
behavioral16
Sample
AutoUpdate/Autoupdate.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral17
Sample
BugReport.exe
Resource
win7-20240508-en
Behavioral task
behavioral18
Sample
BugReport.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral19
Sample
Bull140U.dll
Resource
win7-20240508-en
Behavioral task
behavioral20
Sample
Bull140U.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral21
Sample
ChromeNativeMessagingHost.exe
Resource
win7-20240419-en
Behavioral task
behavioral22
Sample
ChromeNativeMessagingHost.exe
Resource
win10v2004-20240226-en
Behavioral task
behavioral23
Sample
HelpUtility.exe
Resource
win7-20240611-en
Behavioral task
behavioral24
Sample
HelpUtility.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral25
Sample
TeraBox.exe
Resource
win7-20240221-en
Behavioral task
behavioral26
Sample
TeraBox.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral27
Sample
TeraBoxHost.exe
Resource
win7-20240220-en
Behavioral task
behavioral28
Sample
TeraBoxHost.exe
Resource
win10v2004-20240508-en
Behavioral task
behavioral29
Sample
TeraBoxRender.exe
Resource
win7-20231129-en
Behavioral task
behavioral30
Sample
TeraBoxRender.exe
Resource
win10v2004-20240611-en
Behavioral task
behavioral31
Sample
TeraBoxWebService.exe
Resource
win7-20240419-en
Behavioral task
behavioral32
Sample
TeraBoxWebService.exe
Resource
win10v2004-20240611-en
General
-
Target
TeraBox.exe
-
Size
6.3MB
-
MD5
7ab6073a5c400a5071bfa4ef2d936425
-
SHA1
f794ea18eced4330979972da2a4bfa33c03afa2f
-
SHA256
7774449e13c24d2b0b69114d9ba044e80dc8378fa3dfb5d17a142d5cb4cde8af
-
SHA512
4371b6b49df43dab4abf90a71819276f30dca823c93335edd5513a67a646c97ef575b2ede650ceb2f0f168af13431254530e9bffc3db0f5b0eada1492c3cab73
-
SSDEEP
98304:52XswubXaFliXVEaqz56LtbSeK78yYkVvkg7m8Etg1C9Y41WCpq:8XswuuKE7E4IDkVvkgK9fVWCo
Malware Config
Signatures
-
Checks computer location settings 2 TTPs 1 IoCs
Looks up country code configured in the registry, likely geofence.
Processes:
TeraBox.exedescription ioc process Key value queried \REGISTRY\USER\S-1-5-21-1298544033-3225604241-2703760938-1000\Control Panel\International\Geo\Nation TeraBox.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Suspicious behavior: EnumeratesProcesses 7 IoCs
Processes:
TeraBox.exeTeraBoxRender.exeTeraBoxRender.exeTeraBoxRender.exeTeraBoxRender.exeTeraBoxRender.exepid process 1692 TeraBox.exe 1692 TeraBox.exe 2128 TeraBoxRender.exe 2964 TeraBoxRender.exe 1688 TeraBoxRender.exe 2896 TeraBoxRender.exe 2732 TeraBoxRender.exe -
Suspicious use of FindShellTrayWindow 1 IoCs
Processes:
TeraBox.exepid process 1692 TeraBox.exe -
Suspicious use of SendNotifyMessage 1 IoCs
Processes:
TeraBox.exepid process 1692 TeraBox.exe -
Suspicious use of WriteProcessMemory 24 IoCs
Processes:
TeraBox.exedescription pid process target process PID 1692 wrote to memory of 2128 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 2128 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 2128 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 2128 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 2964 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 2964 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 2964 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 2964 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 2896 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 2896 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 2896 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 2896 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 1688 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 1688 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 1688 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 1688 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 1644 1692 TeraBox.exe TeraBoxWebService.exe PID 1692 wrote to memory of 1644 1692 TeraBox.exe TeraBoxWebService.exe PID 1692 wrote to memory of 1644 1692 TeraBox.exe TeraBoxWebService.exe PID 1692 wrote to memory of 1644 1692 TeraBox.exe TeraBoxWebService.exe PID 1692 wrote to memory of 2732 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 2732 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 2732 1692 TeraBox.exe TeraBoxRender.exe PID 1692 wrote to memory of 2732 1692 TeraBox.exe TeraBoxRender.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\TeraBox.exe"C:\Users\Admin\AppData\Local\Temp\TeraBox.exe"1⤵
- Checks computer location settings
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of FindShellTrayWindow
- Suspicious use of SendNotifyMessage
- Suspicious use of WriteProcessMemory
-
C:\Users\Admin\AppData\Local\Temp\TeraBoxRender.exe"C:\Users\Admin\AppData\Local\Temp\TeraBoxRender.exe" --type=gpu-process --field-trial-handle=2012,14223002036459560281,10445704673352245585,131072 --enable-features=CastMediaRouteProvider --no-sandbox --locales-dir-path="C:\Users\Admin\AppData\Local\Temp\browserres\locales" --log-file="C:\Users\Admin\AppData\Local\Temp\debug.log" --log-severity=disable --resources-dir-path="C:\Users\Admin\AppData\Local\Temp\browserres" --user-agent="Mozilla/5.0; (Windows NT 6.1; WOW64); AppleWebKit/537.36; (KHTML, like Gecko); Chrome/86.0.4240.198; Safari/537.36; terabox;1.31.0.1;PC;PC-Windows;6.1.7601;WindowsTeraBox" --lang=en-US --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --log-file="C:\Users\Admin\AppData\Local\Temp\debug.log" --mojo-platform-channel-handle=2080 /prefetch:22⤵
- Suspicious behavior: EnumeratesProcesses
-
C:\Users\Admin\AppData\Local\Temp\TeraBoxRender.exe"C:\Users\Admin\AppData\Local\Temp\TeraBoxRender.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=2012,14223002036459560281,10445704673352245585,131072 --enable-features=CastMediaRouteProvider --lang=en-US --service-sandbox-type=network --no-sandbox --locales-dir-path="C:\Users\Admin\AppData\Local\Temp\browserres\locales" --log-file="C:\Users\Admin\AppData\Local\Temp\debug.log" --log-severity=disable --resources-dir-path="C:\Users\Admin\AppData\Local\Temp\browserres" --user-agent="Mozilla/5.0; (Windows NT 6.1; WOW64); AppleWebKit/537.36; (KHTML, like Gecko); Chrome/86.0.4240.198; Safari/537.36; terabox;1.31.0.1;PC;PC-Windows;6.1.7601;WindowsTeraBox" --lang=en-US --log-file="C:\Users\Admin\AppData\Local\Temp\debug.log" --mojo-platform-channel-handle=2860 /prefetch:82⤵
- Suspicious behavior: EnumeratesProcesses
-
C:\Users\Admin\AppData\Local\Temp\TeraBoxRender.exe"C:\Users\Admin\AppData\Local\Temp\TeraBoxRender.exe" --type=renderer --no-sandbox --log-file="C:\Users\Admin\AppData\Local\Temp\debug.log" --field-trial-handle=2012,14223002036459560281,10445704673352245585,131072 --enable-features=CastMediaRouteProvider --lang=en-US --locales-dir-path="C:\Users\Admin\AppData\Local\Temp\browserres\locales" --log-file="C:\Users\Admin\AppData\Local\Temp\debug.log" --log-severity=disable --resources-dir-path="C:\Users\Admin\AppData\Local\Temp\browserres" --user-agent="Mozilla/5.0; (Windows NT 6.1; WOW64); AppleWebKit/537.36; (KHTML, like Gecko); Chrome/86.0.4240.198; Safari/537.36; terabox;1.31.0.1;PC;PC-Windows;6.1.7601;WindowsTeraBox" --disable-extensions --ppapi-flash-path="C:\Users\Admin\AppData\Local\Temp\pepflashplayer.dll" --ppapi-flash-version=20.0.0.306 --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3164 /prefetch:12⤵
- Suspicious behavior: EnumeratesProcesses
-
C:\Users\Admin\AppData\Local\Temp\TeraBoxRender.exe"C:\Users\Admin\AppData\Local\Temp\TeraBoxRender.exe" --type=renderer --no-sandbox --log-file="C:\Users\Admin\AppData\Local\Temp\debug.log" --field-trial-handle=2012,14223002036459560281,10445704673352245585,131072 --enable-features=CastMediaRouteProvider --lang=en-US --locales-dir-path="C:\Users\Admin\AppData\Local\Temp\browserres\locales" --log-file="C:\Users\Admin\AppData\Local\Temp\debug.log" --log-severity=disable --resources-dir-path="C:\Users\Admin\AppData\Local\Temp\browserres" --user-agent="Mozilla/5.0; (Windows NT 6.1; WOW64); AppleWebKit/537.36; (KHTML, like Gecko); Chrome/86.0.4240.198; Safari/537.36; terabox;1.31.0.1;PC;PC-Windows;6.1.7601;WindowsTeraBox" --disable-extensions --ppapi-flash-path="C:\Users\Admin\AppData\Local\Temp\pepflashplayer.dll" --ppapi-flash-version=20.0.0.306 --device-scale-factor=1 --num-raster-threads=4 --enable-main-frame-before-activation --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3172 /prefetch:12⤵
- Suspicious behavior: EnumeratesProcesses
-
C:\Users\Admin\AppData\Local\Temp\TeraBoxWebService.exe"C:\Users\Admin\AppData\Local\Temp\TeraBoxWebService.exe"2⤵
-
C:\Users\Admin\AppData\Local\Temp\TeraBoxRender.exe"C:\Users\Admin\AppData\Local\Temp\TeraBoxRender.exe" --type=gpu-process --field-trial-handle=2012,14223002036459560281,10445704673352245585,131072 --enable-features=CastMediaRouteProvider --no-sandbox --locales-dir-path="C:\Users\Admin\AppData\Local\Temp\browserres\locales" --log-file="C:\Users\Admin\AppData\Local\Temp\debug.log" --log-severity=disable --resources-dir-path="C:\Users\Admin\AppData\Local\Temp\browserres" --user-agent="Mozilla/5.0; (Windows NT 6.1; WOW64); AppleWebKit/537.36; (KHTML, like Gecko); Chrome/86.0.4240.198; Safari/537.36; terabox;1.31.0.1;PC;PC-Windows;6.1.7601;WindowsTeraBox" --lang=en-US --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --use-gl=swiftshader-webgl --log-file="C:\Users\Admin\AppData\Local\Temp\debug.log" --mojo-platform-channel-handle=2080 /prefetch:22⤵
- Suspicious behavior: EnumeratesProcesses
-
C:\Users\Admin\AppData\Local\Temp\TeraBoxHost.exe-PluginId 1502 -PluginPath "C:\Users\Admin\AppData\Local\Temp\kernel.dll" -ChannelName terabox.1692.0.429191399\763967515 -QuitEventName TERABOX_KERNEL_SDK_997C8EFA-C5ED-47A0-A6A8-D139CD6017F4 -TeraBoxId "" -IP "10.127.1.16" -PcGuid "TBIMXV2-O_B5A095B08A55487D93B3433E82F6CC37-C_0-D_4d51303031302033202020202020202020202020-M_5267BFD3BAD1-V_499EC2B4" -Version "1.31.0.1" -DiskApiHttps 0 -StatisticHttps 0 -ReportCrash 12⤵
-
C:\Users\Admin\AppData\Local\Temp\TeraBoxHost.exe"C:\Users\Admin\AppData\Local\Temp\TeraBoxHost.exe" -PluginId 1502 -PluginPath "C:\Users\Admin\AppData\Local\Temp\kernel.dll" -ChannelName terabox.1692.0.429191399\763967515 -QuitEventName TERABOX_KERNEL_SDK_997C8EFA-C5ED-47A0-A6A8-D139CD6017F4 -TeraBoxId "" -IP "10.127.1.16" -PcGuid "TBIMXV2-O_B5A095B08A55487D93B3433E82F6CC37-C_0-D_4d51303031302033202020202020202020202020-M_5267BFD3BAD1-V_499EC2B4" -Version "1.31.0.1" -DiskApiHttps 0 -StatisticHttps 0 -ReportCrash 12⤵
-
C:\Users\Admin\AppData\Local\Temp\TeraBoxHost.exe"C:\Users\Admin\AppData\Local\Temp\TeraBoxHost.exe" -PluginId 1501 -PluginPath "C:\Users\Admin\AppData\Local\Temp\module\VastPlayer\VastPlayer.dll" -ChannelName terabox.1692.1.486237401\2073958214 -QuitEventName TERABOX_VIDEO_PLAY_SDK_997C8EFA-C5ED-47A0-A6A8-D139CD6017F4 -TeraBoxId "" -IP "10.127.1.16" -PcGuid "TBIMXV2-O_B5A095B08A55487D93B3433E82F6CC37-C_0-D_4d51303031302033202020202020202020202020-M_5267BFD3BAD1-V_499EC2B4" -Version "1.31.0.1" -DiskApiHttps 0 -StatisticHttps 0 -ReportCrash 12⤵
-
C:\Users\Admin\AppData\Local\Temp\AutoUpdate\AutoUpdate.exe"C:\Users\Admin\AppData\Local\Temp\AutoUpdate\AutoUpdate.exe" -client_info "C:\Users\Admin\AppData\Local\Temp\TeraBox_status" -update_cfg_url "aHR0cHM6Ly90ZXJhYm94LmNvbS9hdXRvdXBkYXRl" -srvwnd 201b2 -unlogin2⤵
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6525274CBC2077D43D7D17A33C868C4FFilesize
959B
MD5d5e98140c51869fc462c8975620faa78
SHA107e032e020b72c3f192f0628a2593a19a70f069e
SHA2565c58468d55f58e497e743982d2b50010b6d165374acf83a7d4a32db768c4408e
SHA5129bd164cc4b9ef07386762d3775c6d9528b82d4a9dc508c3040104b8d41cfec52eb0b7e6f8dc47c5021ce2fe3ca542c4ae2b54fd02d76b0eabd9724484621a105
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015Filesize
70KB
MD549aebf8cbd62d92ac215b2923fb1b9f5
SHA11723be06719828dda65ad804298d0431f6aff976
SHA256b33efcb95235b98b48508e019afa4b7655e80cf071defabd8b2123fc8b29307f
SHA512bf86116b015fb56709516d686e168e7c9c68365136231cc51d0b6542ae95323a71d2c7acec84aad7dcecc2e410843f6d82a0a6d51b9acfc721a9c84fdd877b5b
-
C:\Users\Admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6525274CBC2077D43D7D17A33C868C4FFilesize
192B
MD5b296ab0374518a3d5840e3d6aaad86a0
SHA1389ad3b85946f84326c8172f79bf225de9bfc16a
SHA25636e5b9a555eb84de0a0b6d49577e7e78a8d03fc9382becbf8dd1f89b1c72cc54
SHA512cb74414f5d1a6d6999b5153e3355b452d2f252303eb3a4e147dbd103aeaa001b5deeceb20af629983be3a9c35c24e7d69f41b1a845df1f1fff5d532572dc5145
-
C:\Users\Admin\AppData\Local\Temp\AutoUpdate\Download\AutoUpdate.xmlFilesize
24KB
MD5c286cd40cd06c343b0a0daba4a8787ba
SHA1971b13c25faff896033f77e0866fe21f7b26cbd5
SHA2560af3d4862222a6b68993220e693c2501de14d6e922c3ecce1a60754462822c60
SHA512e4ab1154ac2ece073d33277cf8d8394cec51100014589c6d997341d3553d19734b69cfc0ce9f3c87c55e34e833b7647c70a60e1972894762dba71914e38ac10b
-
C:\Users\Admin\AppData\Local\Temp\Cab8E2E.tmpFilesize
65KB
MD5ac05d27423a85adc1622c714f2cb6184
SHA1b0fe2b1abddb97837ea0195be70ab2ff14d43198
SHA256c6456e12e5e53287a547af4103e0397cb9697e466cf75844312dc296d43d144d
SHA5126d0ef9050e41fbae680e0e59dd0f90b6ac7fea5579ef5708b69d5da33a0ece7e8b16574b58b17b64a34cc34a4ffc22b4a62c1ece61f36c4a11a0665e0536b90d
-
C:\Users\Admin\AppData\Local\Temp\Tar8F4E.tmpFilesize
181KB
MD54ea6026cf93ec6338144661bf1202cd1
SHA1a1dec9044f750ad887935a01430bf49322fbdcb7
SHA2568efbc21559ef8b1bcf526800d8070baad42474ce7198e26fa771dbb41a76b1d8
SHA5126c7e0980e39aacf4c3689802353f464a08cd17753bd210ee997e5f2a455deb4f287a9ef74d84579dbde49bc96213cd2b8b247723919c412ea980aa6e6bfe218b
-
C:\Users\Admin\AppData\Local\Temp\TeraBox_statusFilesize
111B
MD5e6498ae9f7bea80db9462454a33c7cfd
SHA113d7ec387b1a82b0df9838bc2e3c1da12d6a5017
SHA256e8643c10d17c384ea41ce20944c6a4eac50757a16cd78e909881ef39f416c7d0
SHA51201ce26d86ee4d0c3d20644f6bfb76ed0bb3cdaee683ff79a638b3760c4dffc9c55878d4d3b6614b05d91004de92da091a5c2d344123265c8ac0bfcc89cfec8c1
-
memory/1692-10-0x0000000077190000-0x0000000077339000-memory.dmpFilesize
1.7MB
-
memory/1692-22-0x0000000077190000-0x0000000077339000-memory.dmpFilesize
1.7MB
-
memory/1692-815-0x0000000077190000-0x0000000077339000-memory.dmpFilesize
1.7MB
-
memory/1692-979-0x0000000077190000-0x0000000077339000-memory.dmpFilesize
1.7MB
-
memory/1692-1054-0x000000000B260000-0x000000000BA60000-memory.dmpFilesize
8.0MB
-
memory/1692-1053-0x000000000B260000-0x000000000BA60000-memory.dmpFilesize
8.0MB
-
memory/1692-1290-0x0000000077190000-0x0000000077339000-memory.dmpFilesize
1.7MB
-
memory/2824-1788-0x0000000000530000-0x0000000000531000-memory.dmpFilesize
4KB
-
memory/2824-1771-0x0000000000400000-0x0000000000401000-memory.dmpFilesize
4KB
-
memory/2824-1791-0x0000000000540000-0x0000000000541000-memory.dmpFilesize
4KB
-
memory/2824-1786-0x0000000000530000-0x0000000000531000-memory.dmpFilesize
4KB
-
memory/2824-1783-0x0000000000520000-0x0000000000521000-memory.dmpFilesize
4KB
-
memory/2824-1781-0x0000000000520000-0x0000000000521000-memory.dmpFilesize
4KB
-
memory/2824-1778-0x0000000000510000-0x0000000000511000-memory.dmpFilesize
4KB
-
memory/2824-1776-0x0000000000510000-0x0000000000511000-memory.dmpFilesize
4KB
-
memory/2824-1773-0x0000000000400000-0x0000000000401000-memory.dmpFilesize
4KB
-
memory/2824-1789-0x0000000000540000-0x0000000000541000-memory.dmpFilesize
4KB
-
memory/2824-1768-0x0000000000370000-0x0000000000371000-memory.dmpFilesize
4KB
-
memory/2824-1766-0x0000000000370000-0x0000000000371000-memory.dmpFilesize
4KB
-
memory/2824-1764-0x0000000000370000-0x0000000000371000-memory.dmpFilesize
4KB
-
memory/2824-1763-0x0000000000230000-0x0000000000231000-memory.dmpFilesize
4KB
-
memory/2824-1761-0x0000000000230000-0x0000000000231000-memory.dmpFilesize
4KB
-
memory/2824-1759-0x0000000000230000-0x0000000000231000-memory.dmpFilesize
4KB
-
memory/2824-1793-0x0000000000540000-0x0000000000541000-memory.dmpFilesize
4KB
-
memory/2824-1794-0x0000000067D00000-0x000000006912C000-memory.dmpFilesize
20.2MB