Advertisement
guelfoweb

Zerolocker / PEframe analysis --json

Aug 28th, 2014
9,364
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.34 KB | None | 0 0
  1. ./peframe.py --json zerolocker.exe
  2. {
  3. "Short Info": {
  4. "Compile Time": "2014-08-05 06:27:06",
  5. "Directories": [
  6. "Import",
  7. "Resource",
  8. "Debug",
  9. "Relocation"
  10. ],
  11. "Hash SHA-1": "5ed36132872be3d5d94627b89f15a7369f68fba1",
  12. "DLL": false,
  13. "File Size": "407552",
  14. "Detected": [
  15. "Packer"
  16. ],
  17. "Hash MD5": "bd0a3c308a6d3372817a474b7c653097",
  18. "Import Hash": "f34d5f2d4577ed6d9ceec516c1f5a744",
  19. "Sections": 3,
  20. "File Name": "zerolocker.exe"
  21. }
  22. } {
  23. "Digital Signature": {
  24. "Block Size": 0,
  25. "Virtual Address": 0,
  26. "Hash MD5": false,
  27. "Hash SHA-1": false
  28. }
  29. } {
  30. "Packer": [
  31. "Microsoft Visual C# / Basic .NET",
  32. "Microsoft Visual Studio .NET",
  33. ".NET executable",
  34. "Microsoft Visual C# v7.0 / Basic .NET"
  35. ]
  36. } {
  37. "Anti Debug": []
  38. } {
  39. "Anti VM": []
  40. } {
  41. "Suspicious API": []
  42. } {
  43. "Suspicious Sections": [
  44. {
  45. "Section": ".text\u0000\u0000\u0000",
  46. "Hash MD5": "60665dcc259f239b2df4113b981ffbd2",
  47. "Hash SHA-1": "e72fd0bd670709d0bb05b4ba43c4dc68f8555f34"
  48. },
  49. {
  50. "Section": ".reloc\u0000\u0000",
  51. "Hash MD5": "e2f2c68a0fa342279057585223afef4a",
  52. "Hash SHA-1": "a84cc1fc20e0c227cd75f1e2b3d749f08b693ac9"
  53. }
  54. ]
  55. } {
  56. "Url": [
  57. "System.Net"
  58. ],
  59. "File Name": [
  60. [
  61. "Executable",
  62. [
  63. "Task Manager.exe"
  64. ]
  65. ],
  66. [
  67. "Library",
  68. [
  69. "mscoree.dll"
  70. ]
  71. ],
  72. [
  73. "Database",
  74. [
  75. "C:\\Users\\George\\Desktop\\Projects\\ZeroLocker\\Testing Stuff\\Testing Stuff\\obj\\Debug\\Task Manager.pdb"
  76. ]
  77. ]
  78. ]
  79. } {
  80. "Meta Data": [
  81. "Translation: 0x0000 0x04b0",
  82. "LegalCopyright: Copyright \\xa9 2014",
  83. "Assembly Version: 3.23.12.12",
  84. "InternalName: Task Manager.exe",
  85. "FileVersion: 3.23.12.12",
  86. "ProductName: Task Manager",
  87. "ProductVersion: 3.23.12.12",
  88. "FileDescription: Task Manager",
  89. "OriginalFilename: Task Manager.exe"
  90. ]
  91. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement