Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: ""
- [*] MalScore: 0.8
- [*] File Name: "atpbtqwlcs.tmp"
- [*] File Size: 922112
- [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- [*] SHA256: "e8730b0bf8f94cbb8babbfefb32cef8e8d19ec823f28c33a7d48c78589710762"
- [*] MD5: "f8b110dc2063d3b29502aa7042d26122"
- [*] SHA1: "1a0fd3db79eadc1ce714f6267d476ddbec0f5e79"
- [*] SHA512: "f3125d3f575aff68105ebb3eadbce30547d34e12237d8ebbc555c6fe12bcc0a5ea85a38e26f2900d70af70ec07efde3b8cd65dc0fdada637496531245ea5052f"
- [*] CRC32: "4A8D3BB9"
- [*] SSDEEP: "24576:dkHgKPNrPA37hzHIA6/oR36vln6sYEubnhRgZtnTZDExa/:d6frPA37hzHIA6/3UvjhRgZ9Te"
- [*] Process Execution: [
- "atpbtqwlcs.tmp"
- ]
- [*] Signatures Detected: [
- {
- "Description": "Creates RWX memory",
- "Details": []
- },
- {
- "Description": "Reads data out of its own binary image",
- "Details": [
- {
- "self_read": "process: atpbtqwlcs.tmp, pid: 1464, offset: 0x00000030, length: 0x00000004"
- }
- ]
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: []
- [*] Mutexes: [
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1"
- ]
- [*] Modified Files: []
- [*] Deleted Files: []
- [*] Modified Registry Keys: []
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DeleteCriticalSection",
- "address": "0x4d117c"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x4d1180"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x4d1184"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x4d1188"
- },
- {
- "name": "VirtualFree",
- "address": "0x4d118c"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x4d1190"
- },
- {
- "name": "LocalFree",
- "address": "0x4d1194"
- },
- {
- "name": "LocalAlloc",
- "address": "0x4d1198"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x4d119c"
- },
- {
- "name": "TlsSetValue",
- "address": "0x4d11a0"
- },
- {
- "name": "TlsGetValue",
- "address": "0x4d11a4"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x4d11a8"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x4d11ac"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x4d11b0"
- },
- {
- "name": "GetLastError",
- "address": "0x4d11b4"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x4d11b8"
- },
- {
- "name": "WriteFile",
- "address": "0x4d11bc"
- },
- {
- "name": "SetFilePointer",
- "address": "0x4d11c0"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x4d11c4"
- },
- {
- "name": "RtlUnwind",
- "address": "0x4d11c8"
- },
- {
- "name": "ReadFile",
- "address": "0x4d11cc"
- },
- {
- "name": "RaiseException",
- "address": "0x4d11d0"
- },
- {
- "name": "GetStdHandle",
- "address": "0x4d11d4"
- },
- {
- "name": "GetFileSize",
- "address": "0x4d11d8"
- },
- {
- "name": "GetSystemTime",
- "address": "0x4d11dc"
- },
- {
- "name": "GetFileType",
- "address": "0x4d11e0"
- },
- {
- "name": "ExitProcess",
- "address": "0x4d11e4"
- },
- {
- "name": "CreateFileA",
- "address": "0x4d11e8"
- },
- {
- "name": "CloseHandle",
- "address": "0x4d11ec"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "MessageBoxA",
- "address": "0x4d11f4"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "SafeArrayPutElement",
- "address": "0x4d11fc"
- },
- {
- "name": "SafeArrayCreate",
- "address": "0x4d1200"
- },
- {
- "name": "VariantChangeTypeEx",
- "address": "0x4d1204"
- },
- {
- "name": "VariantCopyInd",
- "address": "0x4d1208"
- },
- {
- "name": "VariantClear",
- "address": "0x4d120c"
- },
- {
- "name": "SysStringLen",
- "address": "0x4d1210"
- },
- {
- "name": "SysAllocStringLen",
- "address": "0x4d1214"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "RegSetValueExA",
- "address": "0x4d121c"
- },
- {
- "name": "RegQueryValueExA",
- "address": "0x4d1220"
- },
- {
- "name": "RegQueryInfoKeyA",
- "address": "0x4d1224"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x4d1228"
- },
- {
- "name": "RegEnumValueA",
- "address": "0x4d122c"
- },
- {
- "name": "RegEnumKeyExA",
- "address": "0x4d1230"
- },
- {
- "name": "RegDeleteValueA",
- "address": "0x4d1234"
- },
- {
- "name": "RegDeleteKeyA",
- "address": "0x4d1238"
- },
- {
- "name": "RegCreateKeyExA",
- "address": "0x4d123c"
- },
- {
- "name": "RegCloseKey",
- "address": "0x4d1240"
- },
- {
- "name": "OpenThreadToken",
- "address": "0x4d1244"
- },
- {
- "name": "OpenProcessToken",
- "address": "0x4d1248"
- },
- {
- "name": "LookupPrivilegeValueA",
- "address": "0x4d124c"
- },
- {
- "name": "GetUserNameA",
- "address": "0x4d1250"
- },
- {
- "name": "GetTokenInformation",
- "address": "0x4d1254"
- },
- {
- "name": "FreeSid",
- "address": "0x4d1258"
- },
- {
- "name": "EqualSid",
- "address": "0x4d125c"
- },
- {
- "name": "AllocateAndInitializeSid",
- "address": "0x4d1260"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "lstrcmpA",
- "address": "0x4d1268"
- },
- {
- "name": "WriteProfileStringA",
- "address": "0x4d126c"
- },
- {
- "name": "WritePrivateProfileStringA",
- "address": "0x4d1270"
- },
- {
- "name": "WriteFile",
- "address": "0x4d1274"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x4d1278"
- },
- {
- "name": "VirtualFree",
- "address": "0x4d127c"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x4d1280"
- },
- {
- "name": "UnmapViewOfFile",
- "address": "0x4d1284"
- },
- {
- "name": "TransactNamedPipe",
- "address": "0x4d1288"
- },
- {
- "name": "TerminateThread",
- "address": "0x4d128c"
- },
- {
- "name": "TerminateProcess",
- "address": "0x4d1290"
- },
- {
- "name": "Sleep",
- "address": "0x4d1294"
- },
- {
- "name": "SizeofResource",
- "address": "0x4d1298"
- },
- {
- "name": "SetNamedPipeHandleState",
- "address": "0x4d129c"
- },
- {
- "name": "SetLastError",
- "address": "0x4d12a0"
- },
- {
- "name": "SetFileTime",
- "address": "0x4d12a4"
- },
- {
- "name": "SetFilePointer",
- "address": "0x4d12a8"
- },
- {
- "name": "SetFileAttributesA",
- "address": "0x4d12ac"
- },
- {
- "name": "SetErrorMode",
- "address": "0x4d12b0"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x4d12b4"
- },
- {
- "name": "SetCurrentDirectoryA",
- "address": "0x4d12b8"
- },
- {
- "name": "RemoveDirectoryA",
- "address": "0x4d12bc"
- },
- {
- "name": "ReleaseMutex",
- "address": "0x4d12c0"
- },
- {
- "name": "ReadFile",
- "address": "0x4d12c4"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x4d12c8"
- },
- {
- "name": "OpenProcess",
- "address": "0x4d12cc"
- },
- {
- "name": "OpenMutexA",
- "address": "0x4d12d0"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x4d12d4"
- },
- {
- "name": "MulDiv",
- "address": "0x4d12d8"
- },
- {
- "name": "MoveFileExA",
- "address": "0x4d12dc"
- },
- {
- "name": "MoveFileA",
- "address": "0x4d12e0"
- },
- {
- "name": "MapViewOfFile",
- "address": "0x4d12e4"
- },
- {
- "name": "LockResource",
- "address": "0x4d12e8"
- },
- {
- "name": "LocalFree",
- "address": "0x4d12ec"
- },
- {
- "name": "LocalFileTimeToFileTime",
- "address": "0x4d12f0"
- },
- {
- "name": "LoadResource",
- "address": "0x4d12f4"
- },
- {
- "name": "LoadLibraryExA",
- "address": "0x4d12f8"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x4d12fc"
- },
- {
- "name": "IsDBCSLeadByte",
- "address": "0x4d1300"
- },
- {
- "name": "IsBadWritePtr",
- "address": "0x4d1304"
- },
- {
- "name": "GlobalUnlock",
- "address": "0x4d1308"
- },
- {
- "name": "GlobalReAlloc",
- "address": "0x4d130c"
- },
- {
- "name": "GlobalHandle",
- "address": "0x4d1310"
- },
- {
- "name": "GlobalLock",
- "address": "0x4d1314"
- },
- {
- "name": "GlobalFree",
- "address": "0x4d1318"
- },
- {
- "name": "GlobalDeleteAtom",
- "address": "0x4d131c"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x4d1320"
- },
- {
- "name": "GlobalAddAtomA",
- "address": "0x4d1324"
- },
- {
- "name": "GetWindowsDirectoryA",
- "address": "0x4d1328"
- },
- {
- "name": "GetVersionExA",
- "address": "0x4d132c"
- },
- {
- "name": "GetVersion",
- "address": "0x4d1330"
- },
- {
- "name": "GetUserDefaultLangID",
- "address": "0x4d1334"
- },
- {
- "name": "GetTickCount",
- "address": "0x4d1338"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x4d133c"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x4d1340"
- },
- {
- "name": "GetSystemDirectoryA",
- "address": "0x4d1344"
- },
- {
- "name": "GetSystemDefaultLCID",
- "address": "0x4d1348"
- },
- {
- "name": "GetShortPathNameA",
- "address": "0x4d134c"
- },
- {
- "name": "GetProfileStringA",
- "address": "0x4d1350"
- },
- {
- "name": "GetProcAddress",
- "address": "0x4d1354"
- },
- {
- "name": "GetPrivateProfileStringA",
- "address": "0x4d1358"
- },
- {
- "name": "GetOverlappedResult",
- "address": "0x4d135c"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x4d1360"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x4d1364"
- },
- {
- "name": "GetLogicalDrives",
- "address": "0x4d1368"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x4d136c"
- },
- {
- "name": "GetLocalTime",
- "address": "0x4d1370"
- },
- {
- "name": "GetLastError",
- "address": "0x4d1374"
- },
- {
- "name": "GetFullPathNameA",
- "address": "0x4d1378"
- },
- {
- "name": "GetFileSize",
- "address": "0x4d137c"
- },
- {
- "name": "GetFileAttributesA",
- "address": "0x4d1380"
- },
- {
- "name": "GetExitCodeProcess",
- "address": "0x4d1384"
- },
- {
- "name": "GetEnvironmentVariableA",
- "address": "0x4d1388"
- },
- {
- "name": "GetDriveTypeA",
- "address": "0x4d138c"
- },
- {
- "name": "GetDiskFreeSpaceA",
- "address": "0x4d1390"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x4d1394"
- },
- {
- "name": "GetCurrentThread",
- "address": "0x4d1398"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x4d139c"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x4d13a0"
- },
- {
- "name": "GetCurrentDirectoryA",
- "address": "0x4d13a4"
- },
- {
- "name": "GetComputerNameA",
- "address": "0x4d13a8"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x4d13ac"
- },
- {
- "name": "GetACP",
- "address": "0x4d13b0"
- },
- {
- "name": "FreeResource",
- "address": "0x4d13b4"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x4d13b8"
- },
- {
- "name": "FreeLibrary",
- "address": "0x4d13bc"
- },
- {
- "name": "FormatMessageA",
- "address": "0x4d13c0"
- },
- {
- "name": "FlushFileBuffers",
- "address": "0x4d13c4"
- },
- {
- "name": "FindResourceA",
- "address": "0x4d13c8"
- },
- {
- "name": "FindNextFileA",
- "address": "0x4d13cc"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x4d13d0"
- },
- {
- "name": "FindClose",
- "address": "0x4d13d4"
- },
- {
- "name": "FileTimeToSystemTime",
- "address": "0x4d13d8"
- },
- {
- "name": "FileTimeToLocalFileTime",
- "address": "0x4d13dc"
- },
- {
- "name": "DeviceIoControl",
- "address": "0x4d13e0"
- },
- {
- "name": "DeleteFileA",
- "address": "0x4d13e4"
- },
- {
- "name": "CreateThread",
- "address": "0x4d13e8"
- },
- {
- "name": "CreateProcessA",
- "address": "0x4d13ec"
- },
- {
- "name": "CreateNamedPipeA",
- "address": "0x4d13f0"
- },
- {
- "name": "CreateMutexA",
- "address": "0x4d13f4"
- },
- {
- "name": "CreateFileMappingA",
- "address": "0x4d13f8"
- },
- {
- "name": "CreateFileA",
- "address": "0x4d13fc"
- },
- {
- "name": "CreateEventA",
- "address": "0x4d1400"
- },
- {
- "name": "CreateDirectoryA",
- "address": "0x4d1404"
- },
- {
- "name": "CopyFileA",
- "address": "0x4d1408"
- },
- {
- "name": "CompareStringA",
- "address": "0x4d140c"
- },
- {
- "name": "CompareFileTime",
- "address": "0x4d1410"
- },
- {
- "name": "CloseHandle",
- "address": "0x4d1414"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "WNetOpenEnumA",
- "address": "0x4d141c"
- },
- {
- "name": "WNetGetUniversalNameA",
- "address": "0x4d1420"
- },
- {
- "name": "WNetGetConnectionA",
- "address": "0x4d1424"
- },
- {
- "name": "WNetEnumResourceA",
- "address": "0x4d1428"
- },
- {
- "name": "WNetCloseEnum",
- "address": "0x4d142c"
- }
- ],
- "dll": "mpr.dll"
- },
- {
- "imports": [
- {
- "name": "VerQueryValueA",
- "address": "0x4d1434"
- },
- {
- "name": "GetFileVersionInfoSizeA",
- "address": "0x4d1438"
- },
- {
- "name": "GetFileVersionInfoA",
- "address": "0x4d143c"
- }
- ],
- "dll": "version.dll"
- },
- {
- "imports": [
- {
- "name": "UnrealizeObject",
- "address": "0x4d1444"
- },
- {
- "name": "TextOutA",
- "address": "0x4d1448"
- },
- {
- "name": "StretchDIBits",
- "address": "0x4d144c"
- },
- {
- "name": "StretchBlt",
- "address": "0x4d1450"
- },
- {
- "name": "StartPage",
- "address": "0x4d1454"
- },
- {
- "name": "StartDocA",
- "address": "0x4d1458"
- },
- {
- "name": "SetWindowOrgEx",
- "address": "0x4d145c"
- },
- {
- "name": "SetViewportOrgEx",
- "address": "0x4d1460"
- },
- {
- "name": "SetTextColor",
- "address": "0x4d1464"
- },
- {
- "name": "SetTextAlign",
- "address": "0x4d1468"
- },
- {
- "name": "SetStretchBltMode",
- "address": "0x4d146c"
- },
- {
- "name": "SetROP2",
- "address": "0x4d1470"
- },
- {
- "name": "SetPixel",
- "address": "0x4d1474"
- },
- {
- "name": "SetBkMode",
- "address": "0x4d1478"
- },
- {
- "name": "SetBkColor",
- "address": "0x4d147c"
- },
- {
- "name": "SetAbortProc",
- "address": "0x4d1480"
- },
- {
- "name": "SelectPalette",
- "address": "0x4d1484"
- },
- {
- "name": "SelectObject",
- "address": "0x4d1488"
- },
- {
- "name": "SelectClipRgn",
- "address": "0x4d148c"
- },
- {
- "name": "SaveDC",
- "address": "0x4d1490"
- },
- {
- "name": "RoundRect",
- "address": "0x4d1494"
- },
- {
- "name": "RestoreDC",
- "address": "0x4d1498"
- },
- {
- "name": "RemoveFontResourceA",
- "address": "0x4d149c"
- },
- {
- "name": "Rectangle",
- "address": "0x4d14a0"
- },
- {
- "name": "RectVisible",
- "address": "0x4d14a4"
- },
- {
- "name": "RealizePalette",
- "address": "0x4d14a8"
- },
- {
- "name": "Polyline",
- "address": "0x4d14ac"
- },
- {
- "name": "Pie",
- "address": "0x4d14b0"
- },
- {
- "name": "PatBlt",
- "address": "0x4d14b4"
- },
- {
- "name": "MoveToEx",
- "address": "0x4d14b8"
- },
- {
- "name": "LineTo",
- "address": "0x4d14bc"
- },
- {
- "name": "LineDDA",
- "address": "0x4d14c0"
- },
- {
- "name": "IntersectClipRect",
- "address": "0x4d14c4"
- },
- {
- "name": "GetWindowOrgEx",
- "address": "0x4d14c8"
- },
- {
- "name": "GetTextMetricsA",
- "address": "0x4d14cc"
- },
- {
- "name": "GetTextExtentPointA",
- "address": "0x4d14d0"
- },
- {
- "name": "GetTextExtentPoint32A",
- "address": "0x4d14d4"
- },
- {
- "name": "GetSystemPaletteEntries",
- "address": "0x4d14d8"
- },
- {
- "name": "GetStockObject",
- "address": "0x4d14dc"
- },
- {
- "name": "GetPixel",
- "address": "0x4d14e0"
- },
- {
- "name": "GetPaletteEntries",
- "address": "0x4d14e4"
- },
- {
- "name": "GetObjectA",
- "address": "0x4d14e8"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x4d14ec"
- },
- {
- "name": "GetDIBits",
- "address": "0x4d14f0"
- },
- {
- "name": "GetCurrentPositionEx",
- "address": "0x4d14f4"
- },
- {
- "name": "GetClipBox",
- "address": "0x4d14f8"
- },
- {
- "name": "GetBitmapBits",
- "address": "0x4d14fc"
- },
- {
- "name": "ExtTextOutA",
- "address": "0x4d1500"
- },
- {
- "name": "ExtFloodFill",
- "address": "0x4d1504"
- },
- {
- "name": "ExcludeClipRect",
- "address": "0x4d1508"
- },
- {
- "name": "EnumFontsA",
- "address": "0x4d150c"
- },
- {
- "name": "EndPage",
- "address": "0x4d1510"
- },
- {
- "name": "EndDoc",
- "address": "0x4d1514"
- },
- {
- "name": "Ellipse",
- "address": "0x4d1518"
- },
- {
- "name": "DeleteObject",
- "address": "0x4d151c"
- },
- {
- "name": "DeleteDC",
- "address": "0x4d1520"
- },
- {
- "name": "CreateSolidBrush",
- "address": "0x4d1524"
- },
- {
- "name": "CreateRectRgn",
- "address": "0x4d1528"
- },
- {
- "name": "CreatePenIndirect",
- "address": "0x4d152c"
- },
- {
- "name": "CreatePalette",
- "address": "0x4d1530"
- },
- {
- "name": "CreateICA",
- "address": "0x4d1534"
- },
- {
- "name": "CreateFontIndirectA",
- "address": "0x4d1538"
- },
- {
- "name": "CreateDIBitmap",
- "address": "0x4d153c"
- },
- {
- "name": "CreateDCA",
- "address": "0x4d1540"
- },
- {
- "name": "CreateCompatibleDC",
- "address": "0x4d1544"
- },
- {
- "name": "CreateCompatibleBitmap",
- "address": "0x4d1548"
- },
- {
- "name": "CreateBrushIndirect",
- "address": "0x4d154c"
- },
- {
- "name": "CreateBitmap",
- "address": "0x4d1550"
- },
- {
- "name": "Chord",
- "address": "0x4d1554"
- },
- {
- "name": "BitBlt",
- "address": "0x4d1558"
- },
- {
- "name": "Arc",
- "address": "0x4d155c"
- },
- {
- "name": "AddFontResourceA",
- "address": "0x4d1560"
- }
- ],
- "dll": "gdi32.dll"
- },
- {
- "imports": [
- {
- "name": "WindowFromPoint",
- "address": "0x4d1568"
- },
- {
- "name": "WinHelpA",
- "address": "0x4d156c"
- },
- {
- "name": "WaitMessage",
- "address": "0x4d1570"
- },
- {
- "name": "WaitForInputIdle",
- "address": "0x4d1574"
- },
- {
- "name": "UpdateWindow",
- "address": "0x4d1578"
- },
- {
- "name": "UnregisterClassA",
- "address": "0x4d157c"
- },
- {
- "name": "UnhookWindowsHookEx",
- "address": "0x4d1580"
- },
- {
- "name": "TranslateMessage",
- "address": "0x4d1584"
- },
- {
- "name": "TranslateMDISysAccel",
- "address": "0x4d1588"
- },
- {
- "name": "TrackPopupMenu",
- "address": "0x4d158c"
- },
- {
- "name": "SystemParametersInfoA",
- "address": "0x4d1590"
- },
- {
- "name": "ShowWindow",
- "address": "0x4d1594"
- },
- {
- "name": "ShowOwnedPopups",
- "address": "0x4d1598"
- },
- {
- "name": "ShowCursor",
- "address": "0x4d159c"
- },
- {
- "name": "SetWindowRgn",
- "address": "0x4d15a0"
- },
- {
- "name": "SetWindowsHookExA",
- "address": "0x4d15a4"
- },
- {
- "name": "SetWindowTextA",
- "address": "0x4d15a8"
- },
- {
- "name": "SetWindowPos",
- "address": "0x4d15ac"
- },
- {
- "name": "SetWindowPlacement",
- "address": "0x4d15b0"
- },
- {
- "name": "SetWindowLongW",
- "address": "0x4d15b4"
- },
- {
- "name": "SetWindowLongA",
- "address": "0x4d15b8"
- },
- {
- "name": "SetTimer",
- "address": "0x4d15bc"
- },
- {
- "name": "SetScrollRange",
- "address": "0x4d15c0"
- },
- {
- "name": "SetScrollPos",
- "address": "0x4d15c4"
- },
- {
- "name": "SetScrollInfo",
- "address": "0x4d15c8"
- },
- {
- "name": "SetRectEmpty",
- "address": "0x4d15cc"
- },
- {
- "name": "SetRect",
- "address": "0x4d15d0"
- },
- {
- "name": "SetPropA",
- "address": "0x4d15d4"
- },
- {
- "name": "SetParent",
- "address": "0x4d15d8"
- },
- {
- "name": "SetMenu",
- "address": "0x4d15dc"
- },
- {
- "name": "SetForegroundWindow",
- "address": "0x4d15e0"
- },
- {
- "name": "SetFocus",
- "address": "0x4d15e4"
- },
- {
- "name": "SetCursor",
- "address": "0x4d15e8"
- },
- {
- "name": "SetCapture",
- "address": "0x4d15ec"
- },
- {
- "name": "SetActiveWindow",
- "address": "0x4d15f0"
- },
- {
- "name": "SendNotifyMessageA",
- "address": "0x4d15f4"
- },
- {
- "name": "SendMessageTimeoutA",
- "address": "0x4d15f8"
- },
- {
- "name": "SendMessageW",
- "address": "0x4d15fc"
- },
- {
- "name": "SendMessageA",
- "address": "0x4d1600"
- },
- {
- "name": "ScrollWindowEx",
- "address": "0x4d1604"
- },
- {
- "name": "ScrollWindow",
- "address": "0x4d1608"
- },
- {
- "name": "ScreenToClient",
- "address": "0x4d160c"
- },
- {
- "name": "ReplyMessage",
- "address": "0x4d1610"
- },
- {
- "name": "RemovePropA",
- "address": "0x4d1614"
- },
- {
- "name": "RemoveMenu",
- "address": "0x4d1618"
- },
- {
- "name": "ReleaseDC",
- "address": "0x4d161c"
- },
- {
- "name": "ReleaseCapture",
- "address": "0x4d1620"
- },
- {
- "name": "RegisterWindowMessageA",
- "address": "0x4d1624"
- },
- {
- "name": "RegisterClassA",
- "address": "0x4d1628"
- },
- {
- "name": "PtInRect",
- "address": "0x4d162c"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x4d1630"
- },
- {
- "name": "PostMessageA",
- "address": "0x4d1634"
- },
- {
- "name": "PeekMessageA",
- "address": "0x4d1638"
- },
- {
- "name": "OffsetRect",
- "address": "0x4d163c"
- },
- {
- "name": "OemToCharBuffA",
- "address": "0x4d1640"
- },
- {
- "name": "OemToCharA",
- "address": "0x4d1644"
- },
- {
- "name": "MsgWaitForMultipleObjects",
- "address": "0x4d1648"
- },
- {
- "name": "MoveWindow",
- "address": "0x4d164c"
- },
- {
- "name": "MessageBoxA",
- "address": "0x4d1650"
- },
- {
- "name": "MessageBeep",
- "address": "0x4d1654"
- },
- {
- "name": "MapWindowPoints",
- "address": "0x4d1658"
- },
- {
- "name": "MapVirtualKeyA",
- "address": "0x4d165c"
- },
- {
- "name": "LoadStringA",
- "address": "0x4d1660"
- },
- {
- "name": "LoadIconA",
- "address": "0x4d1664"
- },
- {
- "name": "LoadCursorA",
- "address": "0x4d1668"
- },
- {
- "name": "LoadBitmapA",
- "address": "0x4d166c"
- },
- {
- "name": "KillTimer",
- "address": "0x4d1670"
- },
- {
- "name": "IsZoomed",
- "address": "0x4d1674"
- },
- {
- "name": "IsWindowVisible",
- "address": "0x4d1678"
- },
- {
- "name": "IsWindowEnabled",
- "address": "0x4d167c"
- },
- {
- "name": "IsWindow",
- "address": "0x4d1680"
- },
- {
- "name": "IsRectEmpty",
- "address": "0x4d1684"
- },
- {
- "name": "IsIconic",
- "address": "0x4d1688"
- },
- {
- "name": "IsDialogMessageA",
- "address": "0x4d168c"
- },
- {
- "name": "IsChild",
- "address": "0x4d1690"
- },
- {
- "name": "InvalidateRect",
- "address": "0x4d1694"
- },
- {
- "name": "IntersectRect",
- "address": "0x4d1698"
- },
- {
- "name": "InsertMenuItemA",
- "address": "0x4d169c"
- },
- {
- "name": "InsertMenuA",
- "address": "0x4d16a0"
- },
- {
- "name": "InflateRect",
- "address": "0x4d16a4"
- },
- {
- "name": "GetWindowThreadProcessId",
- "address": "0x4d16a8"
- },
- {
- "name": "GetWindowTextA",
- "address": "0x4d16ac"
- },
- {
- "name": "GetWindowRgn",
- "address": "0x4d16b0"
- },
- {
- "name": "GetWindowRect",
- "address": "0x4d16b4"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x4d16b8"
- },
- {
- "name": "GetWindowLongA",
- "address": "0x4d16bc"
- },
- {
- "name": "GetWindowDC",
- "address": "0x4d16c0"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x4d16c4"
- },
- {
- "name": "GetSystemMenu",
- "address": "0x4d16c8"
- },
- {
- "name": "GetSysColorBrush",
- "address": "0x4d16cc"
- },
- {
- "name": "GetSysColor",
- "address": "0x4d16d0"
- },
- {
- "name": "GetSubMenu",
- "address": "0x4d16d4"
- },
- {
- "name": "GetScrollPos",
- "address": "0x4d16d8"
- },
- {
- "name": "GetPropA",
- "address": "0x4d16dc"
- },
- {
- "name": "GetParent",
- "address": "0x4d16e0"
- },
- {
- "name": "GetWindow",
- "address": "0x4d16e4"
- },
- {
- "name": "GetMessagePos",
- "address": "0x4d16e8"
- },
- {
- "name": "GetMessageA",
- "address": "0x4d16ec"
- },
- {
- "name": "GetMenuStringA",
- "address": "0x4d16f0"
- },
- {
- "name": "GetMenuState",
- "address": "0x4d16f4"
- },
- {
- "name": "GetMenuItemCount",
- "address": "0x4d16f8"
- },
- {
- "name": "GetMenu",
- "address": "0x4d16fc"
- },
- {
- "name": "GetLastActivePopup",
- "address": "0x4d1700"
- },
- {
- "name": "GetKeyState",
- "address": "0x4d1704"
- },
- {
- "name": "GetKeyNameTextA",
- "address": "0x4d1708"
- },
- {
- "name": "GetIconInfo",
- "address": "0x4d170c"
- },
- {
- "name": "GetForegroundWindow",
- "address": "0x4d1710"
- },
- {
- "name": "GetFocus",
- "address": "0x4d1714"
- },
- {
- "name": "GetDlgItem",
- "address": "0x4d1718"
- },
- {
- "name": "GetDlgCtrlID",
- "address": "0x4d171c"
- },
- {
- "name": "GetDesktopWindow",
- "address": "0x4d1720"
- },
- {
- "name": "GetDCEx",
- "address": "0x4d1724"
- },
- {
- "name": "GetDC",
- "address": "0x4d1728"
- },
- {
- "name": "GetCursorPos",
- "address": "0x4d172c"
- },
- {
- "name": "GetCursor",
- "address": "0x4d1730"
- },
- {
- "name": "GetClientRect",
- "address": "0x4d1734"
- },
- {
- "name": "GetClassNameA",
- "address": "0x4d1738"
- },
- {
- "name": "GetClassInfoW",
- "address": "0x4d173c"
- },
- {
- "name": "GetClassInfoA",
- "address": "0x4d1740"
- },
- {
- "name": "GetCapture",
- "address": "0x4d1744"
- },
- {
- "name": "GetActiveWindow",
- "address": "0x4d1748"
- },
- {
- "name": "FrameRect",
- "address": "0x4d174c"
- },
- {
- "name": "FindWindowA",
- "address": "0x4d1750"
- },
- {
- "name": "FillRect",
- "address": "0x4d1754"
- },
- {
- "name": "ExitWindowsEx",
- "address": "0x4d1758"
- },
- {
- "name": "EqualRect",
- "address": "0x4d175c"
- },
- {
- "name": "EnumWindows",
- "address": "0x4d1760"
- },
- {
- "name": "EnumThreadWindows",
- "address": "0x4d1764"
- },
- {
- "name": "EndPaint",
- "address": "0x4d1768"
- },
- {
- "name": "EnableWindow",
- "address": "0x4d176c"
- },
- {
- "name": "EnableMenuItem",
- "address": "0x4d1770"
- },
- {
- "name": "DrawTextW",
- "address": "0x4d1774"
- },
- {
- "name": "DrawTextA",
- "address": "0x4d1778"
- },
- {
- "name": "DrawMenuBar",
- "address": "0x4d177c"
- },
- {
- "name": "DrawIconEx",
- "address": "0x4d1780"
- },
- {
- "name": "DrawIcon",
- "address": "0x4d1784"
- },
- {
- "name": "DrawFrameControl",
- "address": "0x4d1788"
- },
- {
- "name": "DrawFocusRect",
- "address": "0x4d178c"
- },
- {
- "name": "DrawEdge",
- "address": "0x4d1790"
- },
- {
- "name": "DispatchMessageA",
- "address": "0x4d1794"
- },
- {
- "name": "DestroyWindow",
- "address": "0x4d1798"
- },
- {
- "name": "DestroyMenu",
- "address": "0x4d179c"
- },
- {
- "name": "DestroyIcon",
- "address": "0x4d17a0"
- },
- {
- "name": "DestroyCursor",
- "address": "0x4d17a4"
- },
- {
- "name": "DeleteMenu",
- "address": "0x4d17a8"
- },
- {
- "name": "DefWindowProcA",
- "address": "0x4d17ac"
- },
- {
- "name": "DefMDIChildProcA",
- "address": "0x4d17b0"
- },
- {
- "name": "DefFrameProcA",
- "address": "0x4d17b4"
- },
- {
- "name": "CreateWindowExA",
- "address": "0x4d17b8"
- },
- {
- "name": "CreatePopupMenu",
- "address": "0x4d17bc"
- },
- {
- "name": "CreateMenu",
- "address": "0x4d17c0"
- },
- {
- "name": "CreateIcon",
- "address": "0x4d17c4"
- },
- {
- "name": "CreateAcceleratorTableA",
- "address": "0x4d17c8"
- },
- {
- "name": "CopyIcon",
- "address": "0x4d17cc"
- },
- {
- "name": "ClientToScreen",
- "address": "0x4d17d0"
- },
- {
- "name": "CheckMenuItem",
- "address": "0x4d17d4"
- },
- {
- "name": "CallWindowProcW",
- "address": "0x4d17d8"
- },
- {
- "name": "CallWindowProcA",
- "address": "0x4d17dc"
- },
- {
- "name": "CallNextHookEx",
- "address": "0x4d17e0"
- },
- {
- "name": "BringWindowToTop",
- "address": "0x4d17e4"
- },
- {
- "name": "BeginPaint",
- "address": "0x4d17e8"
- },
- {
- "name": "AppendMenuA",
- "address": "0x4d17ec"
- },
- {
- "name": "CharPrevA",
- "address": "0x4d17f0"
- },
- {
- "name": "CharNextA",
- "address": "0x4d17f4"
- },
- {
- "name": "CharLowerBuffA",
- "address": "0x4d17f8"
- },
- {
- "name": "CharLowerA",
- "address": "0x4d17fc"
- },
- {
- "name": "CharUpperBuffA",
- "address": "0x4d1800"
- },
- {
- "name": "CharToOemBuffA",
- "address": "0x4d1804"
- },
- {
- "name": "AdjustWindowRectEx",
- "address": "0x4d1808"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "ImageList_GetImageInfo",
- "address": "0x4d1810"
- },
- {
- "name": "ImageList_SetIconSize",
- "address": "0x4d1814"
- },
- {
- "name": "ImageList_GetIconSize",
- "address": "0x4d1818"
- },
- {
- "name": "ImageList_GetDragImage",
- "address": "0x4d181c"
- },
- {
- "name": "ImageList_DragShowNolock",
- "address": "0x4d1820"
- },
- {
- "name": "ImageList_SetDragCursorImage",
- "address": "0x4d1824"
- },
- {
- "name": "ImageList_DragMove",
- "address": "0x4d1828"
- },
- {
- "name": "ImageList_DragLeave",
- "address": "0x4d182c"
- },
- {
- "name": "ImageList_DragEnter",
- "address": "0x4d1830"
- },
- {
- "name": "ImageList_EndDrag",
- "address": "0x4d1834"
- },
- {
- "name": "ImageList_BeginDrag",
- "address": "0x4d1838"
- },
- {
- "name": "ImageList_LoadImage",
- "address": "0x4d183c"
- },
- {
- "name": "ImageList_GetIcon",
- "address": "0x4d1840"
- },
- {
- "name": "ImageList_Remove",
- "address": "0x4d1844"
- },
- {
- "name": "ImageList_DrawEx",
- "address": "0x4d1848"
- },
- {
- "name": "ImageList_AddMasked",
- "address": "0x4d184c"
- },
- {
- "name": "ImageList_Replace",
- "address": "0x4d1850"
- },
- {
- "name": "ImageList_Draw",
- "address": "0x4d1854"
- },
- {
- "name": "ImageList_SetOverlayImage",
- "address": "0x4d1858"
- },
- {
- "name": "ImageList_GetBkColor",
- "address": "0x4d185c"
- },
- {
- "name": "ImageList_SetBkColor",
- "address": "0x4d1860"
- },
- {
- "name": "ImageList_ReplaceIcon",
- "address": "0x4d1864"
- },
- {
- "name": "ImageList_Add",
- "address": "0x4d1868"
- },
- {
- "name": "ImageList_GetImageCount",
- "address": "0x4d186c"
- },
- {
- "name": "ImageList_Destroy",
- "address": "0x4d1870"
- },
- {
- "name": "ImageList_Create",
- "address": "0x4d1874"
- },
- {
- "name": "InitCommonControls",
- "address": "0x4d1878"
- }
- ],
- "dll": "comctl32.dll"
- },
- {
- "imports": [
- {
- "name": "OpenPrinterA",
- "address": "0x4d1880"
- },
- {
- "name": "EnumPrintersA",
- "address": "0x4d1884"
- },
- {
- "name": "DocumentPropertiesA",
- "address": "0x4d1888"
- },
- {
- "name": "ClosePrinter",
- "address": "0x4d188c"
- }
- ],
- "dll": "winspool.drv"
- },
- {
- "imports": [
- {
- "name": "GetSaveFileNameA",
- "address": "0x4d1894"
- },
- {
- "name": "GetOpenFileNameA",
- "address": "0x4d1898"
- }
- ],
- "dll": "comdlg32.dll"
- },
- {
- "imports": [
- {
- "name": "CoTaskMemFree",
- "address": "0x4d18a0"
- },
- {
- "name": "CLSIDFromProgID",
- "address": "0x4d18a4"
- },
- {
- "name": "CoCreateInstance",
- "address": "0x4d18a8"
- },
- {
- "name": "CoFreeUnusedLibraries",
- "address": "0x4d18ac"
- },
- {
- "name": "CoUninitialize",
- "address": "0x4d18b0"
- },
- {
- "name": "CoInitialize",
- "address": "0x4d18b4"
- },
- {
- "name": "IsEqualGUID",
- "address": "0x4d18b8"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "GetActiveObject",
- "address": "0x4d18c0"
- },
- {
- "name": "RegisterTypeLib",
- "address": "0x4d18c4"
- },
- {
- "name": "LoadTypeLib",
- "address": "0x4d18c8"
- },
- {
- "name": "SysFreeString",
- "address": "0x4d18cc"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "ShellExecuteExA",
- "address": "0x4d18d4"
- },
- {
- "name": "ShellExecuteA",
- "address": "0x4d18d8"
- },
- {
- "name": "SHGetFileInfoA",
- "address": "0x4d18dc"
- },
- {
- "name": "ExtractIconA",
- "address": "0x4d18e0"
- }
- ],
- "dll": "shell32.dll"
- },
- {
- "imports": [
- {
- "name": "SHChangeNotify",
- "address": "0x4d18e8"
- },
- {
- "name": "SHBrowseForFolder",
- "address": "0x4d18ec"
- },
- {
- "name": "SHGetPathFromIDList",
- "address": "0x4d18f0"
- },
- {
- "name": "SHGetMalloc",
- "address": "0x4d18f4"
- }
- ],
- "dll": "shell32.dll"
- },
- {
- "imports": [
- {
- "name": "CoDisconnectObject",
- "address": "0x4d18fc"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "AdjustTokenPrivileges",
- "address": "0x4d1904"
- }
- ],
- "dll": "advapi32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x000e1cac",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x004cbf10",
- "timestamp": "1992-06-19 22:22:17",
- "osversion": "1.0",
- "sections": [
- {
- "name": "CODE",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x000cb200",
- "entropy": "6.55",
- "raw_address": "0x00000400",
- "virtual_size": "0x000cb180",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": "DATA",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x000cd000",
- "size_of_data": "0x00001400",
- "entropy": "4.28",
- "raw_address": "0x000cb600",
- "virtual_size": "0x0000138c",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": "BSS",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x000cf000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x000cca00",
- "virtual_size": "0x000015a4",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".idata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x000d1000",
- "size_of_data": "0x00002a00",
- "entropy": "5.02",
- "raw_address": "0x000cca00",
- "virtual_size": "0x0000293a",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x000d4000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x000cf400",
- "virtual_size": "0x00000008",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x000d5000",
- "size_of_data": "0x00000200",
- "entropy": "0.21",
- "raw_address": "0x000cf400",
- "virtual_size": "0x00000018",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x000d6000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x000cf600",
- "virtual_size": "0x0000bd9c",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x000e2000",
- "size_of_data": "0x00011c00",
- "entropy": "4.96",
- "raw_address": "0x000cf600",
- "virtual_size": "0x00011c00",
- "characteristics_raw": "0x50000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x000d1000",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000293a"
- },
- {
- "virtual_address": "0x000e2000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00011c00"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x000d5000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "a2449d4160b59e7f523a1790ed0ed3a0",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 18,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "kernel32.dll.SetDllDirectoryW",
- "kernel32.dll.SetSearchPathMode",
- "kernel32.dll.SetProcessDEPPolicy",
- "uxtheme.dll.OpenThemeData",
- "uxtheme.dll.CloseThemeData",
- "uxtheme.dll.DrawThemeBackground",
- "uxtheme.dll.DrawThemeText",
- "uxtheme.dll.GetThemeBackgroundContentRect",
- "uxtheme.dll.GetThemePartSize",
- "uxtheme.dll.GetThemeTextExtent",
- "uxtheme.dll.GetThemeTextMetrics",
- "uxtheme.dll.GetThemeBackgroundRegion",
- "uxtheme.dll.HitTestThemeBackground",
- "uxtheme.dll.DrawThemeEdge",
- "uxtheme.dll.DrawThemeIcon",
- "uxtheme.dll.IsThemePartDefined",
- "uxtheme.dll.IsThemeBackgroundPartiallyTransparent",
- "uxtheme.dll.GetThemeColor",
- "uxtheme.dll.GetThemeMetric",
- "uxtheme.dll.GetThemeString",
- "uxtheme.dll.GetThemeBool",
- "uxtheme.dll.GetThemeInt",
- "uxtheme.dll.GetThemeEnumValue",
- "uxtheme.dll.GetThemePosition",
- "uxtheme.dll.GetThemeFont",
- "uxtheme.dll.GetThemeRect",
- "uxtheme.dll.GetThemeMargins",
- "uxtheme.dll.GetThemeIntList",
- "uxtheme.dll.GetThemePropertyOrigin",
- "uxtheme.dll.SetWindowTheme",
- "uxtheme.dll.GetThemeFilename",
- "uxtheme.dll.GetThemeSysColor",
- "uxtheme.dll.GetThemeSysColorBrush",
- "uxtheme.dll.GetThemeSysBool",
- "uxtheme.dll.GetThemeSysSize",
- "uxtheme.dll.GetThemeSysFont",
- "uxtheme.dll.GetThemeSysString",
- "uxtheme.dll.GetThemeSysInt",
- "uxtheme.dll.IsThemeActive",
- "uxtheme.dll.IsAppThemed",
- "uxtheme.dll.GetWindowTheme",
- "uxtheme.dll.EnableThemeDialogTexture",
- "uxtheme.dll.IsThemeDialogTextureEnabled",
- "uxtheme.dll.GetThemeAppProperties",
- "uxtheme.dll.SetThemeAppProperties",
- "uxtheme.dll.GetCurrentThemeName",
- "uxtheme.dll.GetThemeDocumentationProperty",
- "uxtheme.dll.DrawThemeParentBackground",
- "uxtheme.dll.EnableTheming",
- "user32.dll.NotifyWinEvent",
- "kernel32.dll.Wow64DisableWow64FsRedirection",
- "kernel32.dll.Wow64RevertWow64FsRedirection",
- "cryptbase.dll.SystemFunction036",
- "uxtheme.dll.ThemeInitApiHook",
- "user32.dll.IsProcessDPIAware",
- "shell32.dll.SHCreateItemFromParsingName",
- "shell32.dll.SHPathPrepareForWriteA",
- "kernel32.dll.VerSetConditionMask",
- "kernel32.dll.VerifyVersionInfoW",
- "kernel32.dll.GetNativeSystemInfo",
- "kernel32.dll.IsWow64Process",
- "kernel32.dll.GetSystemWow64DirectoryA",
- "advapi32.dll.RegDeleteKeyExA",
- "user32.dll.AnimateWindow",
- "dwmapi.dll.DwmIsCompositionEnabled",
- "gdi32.dll.GetLayout",
- "gdi32.dll.GdiRealizationInfo",
- "gdi32.dll.FontIsLinked",
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegQueryInfoKeyW",
- "gdi32.dll.GetTextFaceAliasW",
- "advapi32.dll.RegEnumValueW",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.RegQueryValueExW",
- "gdi32.dll.GetFontAssocStatus",
- "advapi32.dll.RegQueryValueExA",
- "advapi32.dll.RegEnumKeyExW",
- "gdi32.dll.GdiIsMetaPrintDC",
- "ole32.dll.CoInitializeEx",
- "ole32.dll.CoUninitialize",
- "ole32.dll.CoRegisterInitializeSpy",
- "ole32.dll.CoRevokeInitializeSpy",
- "kernel32.dll.SortGetHandle",
- "kernel32.dll.SortCloseHandle",
- "comctl32.dll._TrackMouseEvent",
- "msimg32.dll.TransparentBlt",
- "user32.dll.DisableProcessWindowsGhosting",
- "advapi32.dll.CheckTokenMembership",
- "user32.dll.MonitorFromWindow",
- "user32.dll.GetMonitorInfoA",
- "comctl32.dll.RegisterClassNameW",
- "uxtheme.dll.BufferedPaintInit",
- "uxtheme.dll.BufferedPaintRenderAnimation",
- "uxtheme.dll.GetThemeTransitionDuration",
- "uxtheme.dll.BeginBufferedAnimation",
- "uxtheme.dll.EndBufferedAnimation",
- "uxtheme.dll.BufferedPaintStopAllAnimations",
- "uxtheme.dll.BufferedPaintUnInit",
- "user32.dll.ShutdownBlockReasonDestroy",
- "oleaut32.dll.#500"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DeleteCriticalSection",
- "address": "0x4d117c"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x4d1180"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x4d1184"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x4d1188"
- },
- {
- "name": "VirtualFree",
- "address": "0x4d118c"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x4d1190"
- },
- {
- "name": "LocalFree",
- "address": "0x4d1194"
- },
- {
- "name": "LocalAlloc",
- "address": "0x4d1198"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x4d119c"
- },
- {
- "name": "TlsSetValue",
- "address": "0x4d11a0"
- },
- {
- "name": "TlsGetValue",
- "address": "0x4d11a4"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x4d11a8"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x4d11ac"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x4d11b0"
- },
- {
- "name": "GetLastError",
- "address": "0x4d11b4"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x4d11b8"
- },
- {
- "name": "WriteFile",
- "address": "0x4d11bc"
- },
- {
- "name": "SetFilePointer",
- "address": "0x4d11c0"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x4d11c4"
- },
- {
- "name": "RtlUnwind",
- "address": "0x4d11c8"
- },
- {
- "name": "ReadFile",
- "address": "0x4d11cc"
- },
- {
- "name": "RaiseException",
- "address": "0x4d11d0"
- },
- {
- "name": "GetStdHandle",
- "address": "0x4d11d4"
- },
- {
- "name": "GetFileSize",
- "address": "0x4d11d8"
- },
- {
- "name": "GetSystemTime",
- "address": "0x4d11dc"
- },
- {
- "name": "GetFileType",
- "address": "0x4d11e0"
- },
- {
- "name": "ExitProcess",
- "address": "0x4d11e4"
- },
- {
- "name": "CreateFileA",
- "address": "0x4d11e8"
- },
- {
- "name": "CloseHandle",
- "address": "0x4d11ec"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "MessageBoxA",
- "address": "0x4d11f4"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "SafeArrayPutElement",
- "address": "0x4d11fc"
- },
- {
- "name": "SafeArrayCreate",
- "address": "0x4d1200"
- },
- {
- "name": "VariantChangeTypeEx",
- "address": "0x4d1204"
- },
- {
- "name": "VariantCopyInd",
- "address": "0x4d1208"
- },
- {
- "name": "VariantClear",
- "address": "0x4d120c"
- },
- {
- "name": "SysStringLen",
- "address": "0x4d1210"
- },
- {
- "name": "SysAllocStringLen",
- "address": "0x4d1214"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "RegSetValueExA",
- "address": "0x4d121c"
- },
- {
- "name": "RegQueryValueExA",
- "address": "0x4d1220"
- },
- {
- "name": "RegQueryInfoKeyA",
- "address": "0x4d1224"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x4d1228"
- },
- {
- "name": "RegEnumValueA",
- "address": "0x4d122c"
- },
- {
- "name": "RegEnumKeyExA",
- "address": "0x4d1230"
- },
- {
- "name": "RegDeleteValueA",
- "address": "0x4d1234"
- },
- {
- "name": "RegDeleteKeyA",
- "address": "0x4d1238"
- },
- {
- "name": "RegCreateKeyExA",
- "address": "0x4d123c"
- },
- {
- "name": "RegCloseKey",
- "address": "0x4d1240"
- },
- {
- "name": "OpenThreadToken",
- "address": "0x4d1244"
- },
- {
- "name": "OpenProcessToken",
- "address": "0x4d1248"
- },
- {
- "name": "LookupPrivilegeValueA",
- "address": "0x4d124c"
- },
- {
- "name": "GetUserNameA",
- "address": "0x4d1250"
- },
- {
- "name": "GetTokenInformation",
- "address": "0x4d1254"
- },
- {
- "name": "FreeSid",
- "address": "0x4d1258"
- },
- {
- "name": "EqualSid",
- "address": "0x4d125c"
- },
- {
- "name": "AllocateAndInitializeSid",
- "address": "0x4d1260"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "lstrcmpA",
- "address": "0x4d1268"
- },
- {
- "name": "WriteProfileStringA",
- "address": "0x4d126c"
- },
- {
- "name": "WritePrivateProfileStringA",
- "address": "0x4d1270"
- },
- {
- "name": "WriteFile",
- "address": "0x4d1274"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x4d1278"
- },
- {
- "name": "VirtualFree",
- "address": "0x4d127c"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x4d1280"
- },
- {
- "name": "UnmapViewOfFile",
- "address": "0x4d1284"
- },
- {
- "name": "TransactNamedPipe",
- "address": "0x4d1288"
- },
- {
- "name": "TerminateThread",
- "address": "0x4d128c"
- },
- {
- "name": "TerminateProcess",
- "address": "0x4d1290"
- },
- {
- "name": "Sleep",
- "address": "0x4d1294"
- },
- {
- "name": "SizeofResource",
- "address": "0x4d1298"
- },
- {
- "name": "SetNamedPipeHandleState",
- "address": "0x4d129c"
- },
- {
- "name": "SetLastError",
- "address": "0x4d12a0"
- },
- {
- "name": "SetFileTime",
- "address": "0x4d12a4"
- },
- {
- "name": "SetFilePointer",
- "address": "0x4d12a8"
- },
- {
- "name": "SetFileAttributesA",
- "address": "0x4d12ac"
- },
- {
- "name": "SetErrorMode",
- "address": "0x4d12b0"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x4d12b4"
- },
- {
- "name": "SetCurrentDirectoryA",
- "address": "0x4d12b8"
- },
- {
- "name": "RemoveDirectoryA",
- "address": "0x4d12bc"
- },
- {
- "name": "ReleaseMutex",
- "address": "0x4d12c0"
- },
- {
- "name": "ReadFile",
- "address": "0x4d12c4"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x4d12c8"
- },
- {
- "name": "OpenProcess",
- "address": "0x4d12cc"
- },
- {
- "name": "OpenMutexA",
- "address": "0x4d12d0"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x4d12d4"
- },
- {
- "name": "MulDiv",
- "address": "0x4d12d8"
- },
- {
- "name": "MoveFileExA",
- "address": "0x4d12dc"
- },
- {
- "name": "MoveFileA",
- "address": "0x4d12e0"
- },
- {
- "name": "MapViewOfFile",
- "address": "0x4d12e4"
- },
- {
- "name": "LockResource",
- "address": "0x4d12e8"
- },
- {
- "name": "LocalFree",
- "address": "0x4d12ec"
- },
- {
- "name": "LocalFileTimeToFileTime",
- "address": "0x4d12f0"
- },
- {
- "name": "LoadResource",
- "address": "0x4d12f4"
- },
- {
- "name": "LoadLibraryExA",
- "address": "0x4d12f8"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x4d12fc"
- },
- {
- "name": "IsDBCSLeadByte",
- "address": "0x4d1300"
- },
- {
- "name": "IsBadWritePtr",
- "address": "0x4d1304"
- },
- {
- "name": "GlobalUnlock",
- "address": "0x4d1308"
- },
- {
- "name": "GlobalReAlloc",
- "address": "0x4d130c"
- },
- {
- "name": "GlobalHandle",
- "address": "0x4d1310"
- },
- {
- "name": "GlobalLock",
- "address": "0x4d1314"
- },
- {
- "name": "GlobalFree",
- "address": "0x4d1318"
- },
- {
- "name": "GlobalDeleteAtom",
- "address": "0x4d131c"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x4d1320"
- },
- {
- "name": "GlobalAddAtomA",
- "address": "0x4d1324"
- },
- {
- "name": "GetWindowsDirectoryA",
- "address": "0x4d1328"
- },
- {
- "name": "GetVersionExA",
- "address": "0x4d132c"
- },
- {
- "name": "GetVersion",
- "address": "0x4d1330"
- },
- {
- "name": "GetUserDefaultLangID",
- "address": "0x4d1334"
- },
- {
- "name": "GetTickCount",
- "address": "0x4d1338"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x4d133c"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x4d1340"
- },
- {
- "name": "GetSystemDirectoryA",
- "address": "0x4d1344"
- },
- {
- "name": "GetSystemDefaultLCID",
- "address": "0x4d1348"
- },
- {
- "name": "GetShortPathNameA",
- "address": "0x4d134c"
- },
- {
- "name": "GetProfileStringA",
- "address": "0x4d1350"
- },
- {
- "name": "GetProcAddress",
- "address": "0x4d1354"
- },
- {
- "name": "GetPrivateProfileStringA",
- "address": "0x4d1358"
- },
- {
- "name": "GetOverlappedResult",
- "address": "0x4d135c"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x4d1360"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x4d1364"
- },
- {
- "name": "GetLogicalDrives",
- "address": "0x4d1368"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x4d136c"
- },
- {
- "name": "GetLocalTime",
- "address": "0x4d1370"
- },
- {
- "name": "GetLastError",
- "address": "0x4d1374"
- },
- {
- "name": "GetFullPathNameA",
- "address": "0x4d1378"
- },
- {
- "name": "GetFileSize",
- "address": "0x4d137c"
- },
- {
- "name": "GetFileAttributesA",
- "address": "0x4d1380"
- },
- {
- "name": "GetExitCodeProcess",
- "address": "0x4d1384"
- },
- {
- "name": "GetEnvironmentVariableA",
- "address": "0x4d1388"
- },
- {
- "name": "GetDriveTypeA",
- "address": "0x4d138c"
- },
- {
- "name": "GetDiskFreeSpaceA",
- "address": "0x4d1390"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x4d1394"
- },
- {
- "name": "GetCurrentThread",
- "address": "0x4d1398"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x4d139c"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x4d13a0"
- },
- {
- "name": "GetCurrentDirectoryA",
- "address": "0x4d13a4"
- },
- {
- "name": "GetComputerNameA",
- "address": "0x4d13a8"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x4d13ac"
- },
- {
- "name": "GetACP",
- "address": "0x4d13b0"
- },
- {
- "name": "FreeResource",
- "address": "0x4d13b4"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x4d13b8"
- },
- {
- "name": "FreeLibrary",
- "address": "0x4d13bc"
- },
- {
- "name": "FormatMessageA",
- "address": "0x4d13c0"
- },
- {
- "name": "FlushFileBuffers",
- "address": "0x4d13c4"
- },
- {
- "name": "FindResourceA",
- "address": "0x4d13c8"
- },
- {
- "name": "FindNextFileA",
- "address": "0x4d13cc"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x4d13d0"
- },
- {
- "name": "FindClose",
- "address": "0x4d13d4"
- },
- {
- "name": "FileTimeToSystemTime",
- "address": "0x4d13d8"
- },
- {
- "name": "FileTimeToLocalFileTime",
- "address": "0x4d13dc"
- },
- {
- "name": "DeviceIoControl",
- "address": "0x4d13e0"
- },
- {
- "name": "DeleteFileA",
- "address": "0x4d13e4"
- },
- {
- "name": "CreateThread",
- "address": "0x4d13e8"
- },
- {
- "name": "CreateProcessA",
- "address": "0x4d13ec"
- },
- {
- "name": "CreateNamedPipeA",
- "address": "0x4d13f0"
- },
- {
- "name": "CreateMutexA",
- "address": "0x4d13f4"
- },
- {
- "name": "CreateFileMappingA",
- "address": "0x4d13f8"
- },
- {
- "name": "CreateFileA",
- "address": "0x4d13fc"
- },
- {
- "name": "CreateEventA",
- "address": "0x4d1400"
- },
- {
- "name": "CreateDirectoryA",
- "address": "0x4d1404"
- },
- {
- "name": "CopyFileA",
- "address": "0x4d1408"
- },
- {
- "name": "CompareStringA",
- "address": "0x4d140c"
- },
- {
- "name": "CompareFileTime",
- "address": "0x4d1410"
- },
- {
- "name": "CloseHandle",
- "address": "0x4d1414"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "WNetOpenEnumA",
- "address": "0x4d141c"
- },
- {
- "name": "WNetGetUniversalNameA",
- "address": "0x4d1420"
- },
- {
- "name": "WNetGetConnectionA",
- "address": "0x4d1424"
- },
- {
- "name": "WNetEnumResourceA",
- "address": "0x4d1428"
- },
- {
- "name": "WNetCloseEnum",
- "address": "0x4d142c"
- }
- ],
- "dll": "mpr.dll"
- },
- {
- "imports": [
- {
- "name": "VerQueryValueA",
- "address": "0x4d1434"
- },
- {
- "name": "GetFileVersionInfoSizeA",
- "address": "0x4d1438"
- },
- {
- "name": "GetFileVersionInfoA",
- "address": "0x4d143c"
- }
- ],
- "dll": "version.dll"
- },
- {
- "imports": [
- {
- "name": "UnrealizeObject",
- "address": "0x4d1444"
- },
- {
- "name": "TextOutA",
- "address": "0x4d1448"
- },
- {
- "name": "StretchDIBits",
- "address": "0x4d144c"
- },
- {
- "name": "StretchBlt",
- "address": "0x4d1450"
- },
- {
- "name": "StartPage",
- "address": "0x4d1454"
- },
- {
- "name": "StartDocA",
- "address": "0x4d1458"
- },
- {
- "name": "SetWindowOrgEx",
- "address": "0x4d145c"
- },
- {
- "name": "SetViewportOrgEx",
- "address": "0x4d1460"
- },
- {
- "name": "SetTextColor",
- "address": "0x4d1464"
- },
- {
- "name": "SetTextAlign",
- "address": "0x4d1468"
- },
- {
- "name": "SetStretchBltMode",
- "address": "0x4d146c"
- },
- {
- "name": "SetROP2",
- "address": "0x4d1470"
- },
- {
- "name": "SetPixel",
- "address": "0x4d1474"
- },
- {
- "name": "SetBkMode",
- "address": "0x4d1478"
- },
- {
- "name": "SetBkColor",
- "address": "0x4d147c"
- },
- {
- "name": "SetAbortProc",
- "address": "0x4d1480"
- },
- {
- "name": "SelectPalette",
- "address": "0x4d1484"
- },
- {
- "name": "SelectObject",
- "address": "0x4d1488"
- },
- {
- "name": "SelectClipRgn",
- "address": "0x4d148c"
- },
- {
- "name": "SaveDC",
- "address": "0x4d1490"
- },
- {
- "name": "RoundRect",
- "address": "0x4d1494"
- },
- {
- "name": "RestoreDC",
- "address": "0x4d1498"
- },
- {
- "name": "RemoveFontResourceA",
- "address": "0x4d149c"
- },
- {
- "name": "Rectangle",
- "address": "0x4d14a0"
- },
- {
- "name": "RectVisible",
- "address": "0x4d14a4"
- },
- {
- "name": "RealizePalette",
- "address": "0x4d14a8"
- },
- {
- "name": "Polyline",
- "address": "0x4d14ac"
- },
- {
- "name": "Pie",
- "address": "0x4d14b0"
- },
- {
- "name": "PatBlt",
- "address": "0x4d14b4"
- },
- {
- "name": "MoveToEx",
- "address": "0x4d14b8"
- },
- {
- "name": "LineTo",
- "address": "0x4d14bc"
- },
- {
- "name": "LineDDA",
- "address": "0x4d14c0"
- },
- {
- "name": "IntersectClipRect",
- "address": "0x4d14c4"
- },
- {
- "name": "GetWindowOrgEx",
- "address": "0x4d14c8"
- },
- {
- "name": "GetTextMetricsA",
- "address": "0x4d14cc"
- },
- {
- "name": "GetTextExtentPointA",
- "address": "0x4d14d0"
- },
- {
- "name": "GetTextExtentPoint32A",
- "address": "0x4d14d4"
- },
- {
- "name": "GetSystemPaletteEntries",
- "address": "0x4d14d8"
- },
- {
- "name": "GetStockObject",
- "address": "0x4d14dc"
- },
- {
- "name": "GetPixel",
- "address": "0x4d14e0"
- },
- {
- "name": "GetPaletteEntries",
- "address": "0x4d14e4"
- },
- {
- "name": "GetObjectA",
- "address": "0x4d14e8"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x4d14ec"
- },
- {
- "name": "GetDIBits",
- "address": "0x4d14f0"
- },
- {
- "name": "GetCurrentPositionEx",
- "address": "0x4d14f4"
- },
- {
- "name": "GetClipBox",
- "address": "0x4d14f8"
- },
- {
- "name": "GetBitmapBits",
- "address": "0x4d14fc"
- },
- {
- "name": "ExtTextOutA",
- "address": "0x4d1500"
- },
- {
- "name": "ExtFloodFill",
- "address": "0x4d1504"
- },
- {
- "name": "ExcludeClipRect",
- "address": "0x4d1508"
- },
- {
- "name": "EnumFontsA",
- "address": "0x4d150c"
- },
- {
- "name": "EndPage",
- "address": "0x4d1510"
- },
- {
- "name": "EndDoc",
- "address": "0x4d1514"
- },
- {
- "name": "Ellipse",
- "address": "0x4d1518"
- },
- {
- "name": "DeleteObject",
- "address": "0x4d151c"
- },
- {
- "name": "DeleteDC",
- "address": "0x4d1520"
- },
- {
- "name": "CreateSolidBrush",
- "address": "0x4d1524"
- },
- {
- "name": "CreateRectRgn",
- "address": "0x4d1528"
- },
- {
- "name": "CreatePenIndirect",
- "address": "0x4d152c"
- },
- {
- "name": "CreatePalette",
- "address": "0x4d1530"
- },
- {
- "name": "CreateICA",
- "address": "0x4d1534"
- },
- {
- "name": "CreateFontIndirectA",
- "address": "0x4d1538"
- },
- {
- "name": "CreateDIBitmap",
- "address": "0x4d153c"
- },
- {
- "name": "CreateDCA",
- "address": "0x4d1540"
- },
- {
- "name": "CreateCompatibleDC",
- "address": "0x4d1544"
- },
- {
- "name": "CreateCompatibleBitmap",
- "address": "0x4d1548"
- },
- {
- "name": "CreateBrushIndirect",
- "address": "0x4d154c"
- },
- {
- "name": "CreateBitmap",
- "address": "0x4d1550"
- },
- {
- "name": "Chord",
- "address": "0x4d1554"
- },
- {
- "name": "BitBlt",
- "address": "0x4d1558"
- },
- {
- "name": "Arc",
- "address": "0x4d155c"
- },
- {
- "name": "AddFontResourceA",
- "address": "0x4d1560"
- }
- ],
- "dll": "gdi32.dll"
- },
- {
- "imports": [
- {
- "name": "WindowFromPoint",
- "address": "0x4d1568"
- },
- {
- "name": "WinHelpA",
- "address": "0x4d156c"
- },
- {
- "name": "WaitMessage",
- "address": "0x4d1570"
- },
- {
- "name": "WaitForInputIdle",
- "address": "0x4d1574"
- },
- {
- "name": "UpdateWindow",
- "address": "0x4d1578"
- },
- {
- "name": "UnregisterClassA",
- "address": "0x4d157c"
- },
- {
- "name": "UnhookWindowsHookEx",
- "address": "0x4d1580"
- },
- {
- "name": "TranslateMessage",
- "address": "0x4d1584"
- },
- {
- "name": "TranslateMDISysAccel",
- "address": "0x4d1588"
- },
- {
- "name": "TrackPopupMenu",
- "address": "0x4d158c"
- },
- {
- "name": "SystemParametersInfoA",
- "address": "0x4d1590"
- },
- {
- "name": "ShowWindow",
- "address": "0x4d1594"
- },
- {
- "name": "ShowOwnedPopups",
- "address": "0x4d1598"
- },
- {
- "name": "ShowCursor",
- "address": "0x4d159c"
- },
- {
- "name": "SetWindowRgn",
- "address": "0x4d15a0"
- },
- {
- "name": "SetWindowsHookExA",
- "address": "0x4d15a4"
- },
- {
- "name": "SetWindowTextA",
- "address": "0x4d15a8"
- },
- {
- "name": "SetWindowPos",
- "address": "0x4d15ac"
- },
- {
- "name": "SetWindowPlacement",
- "address": "0x4d15b0"
- },
- {
- "name": "SetWindowLongW",
- "address": "0x4d15b4"
- },
- {
- "name": "SetWindowLongA",
- "address": "0x4d15b8"
- },
- {
- "name": "SetTimer",
- "address": "0x4d15bc"
- },
- {
- "name": "SetScrollRange",
- "address": "0x4d15c0"
- },
- {
- "name": "SetScrollPos",
- "address": "0x4d15c4"
- },
- {
- "name": "SetScrollInfo",
- "address": "0x4d15c8"
- },
- {
- "name": "SetRectEmpty",
- "address": "0x4d15cc"
- },
- {
- "name": "SetRect",
- "address": "0x4d15d0"
- },
- {
- "name": "SetPropA",
- "address": "0x4d15d4"
- },
- {
- "name": "SetParent",
- "address": "0x4d15d8"
- },
- {
- "name": "SetMenu",
- "address": "0x4d15dc"
- },
- {
- "name": "SetForegroundWindow",
- "address": "0x4d15e0"
- },
- {
- "name": "SetFocus",
- "address": "0x4d15e4"
- },
- {
- "name": "SetCursor",
- "address": "0x4d15e8"
- },
- {
- "name": "SetCapture",
- "address": "0x4d15ec"
- },
- {
- "name": "SetActiveWindow",
- "address": "0x4d15f0"
- },
- {
- "name": "SendNotifyMessageA",
- "address": "0x4d15f4"
- },
- {
- "name": "SendMessageTimeoutA",
- "address": "0x4d15f8"
- },
- {
- "name": "SendMessageW",
- "address": "0x4d15fc"
- },
- {
- "name": "SendMessageA",
- "address": "0x4d1600"
- },
- {
- "name": "ScrollWindowEx",
- "address": "0x4d1604"
- },
- {
- "name": "ScrollWindow",
- "address": "0x4d1608"
- },
- {
- "name": "ScreenToClient",
- "address": "0x4d160c"
- },
- {
- "name": "ReplyMessage",
- "address": "0x4d1610"
- },
- {
- "name": "RemovePropA",
- "address": "0x4d1614"
- },
- {
- "name": "RemoveMenu",
- "address": "0x4d1618"
- },
- {
- "name": "ReleaseDC",
- "address": "0x4d161c"
- },
- {
- "name": "ReleaseCapture",
- "address": "0x4d1620"
- },
- {
- "name": "RegisterWindowMessageA",
- "address": "0x4d1624"
- },
- {
- "name": "RegisterClassA",
- "address": "0x4d1628"
- },
- {
- "name": "PtInRect",
- "address": "0x4d162c"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x4d1630"
- },
- {
- "name": "PostMessageA",
- "address": "0x4d1634"
- },
- {
- "name": "PeekMessageA",
- "address": "0x4d1638"
- },
- {
- "name": "OffsetRect",
- "address": "0x4d163c"
- },
- {
- "name": "OemToCharBuffA",
- "address": "0x4d1640"
- },
- {
- "name": "OemToCharA",
- "address": "0x4d1644"
- },
- {
- "name": "MsgWaitForMultipleObjects",
- "address": "0x4d1648"
- },
- {
- "name": "MoveWindow",
- "address": "0x4d164c"
- },
- {
- "name": "MessageBoxA",
- "address": "0x4d1650"
- },
- {
- "name": "MessageBeep",
- "address": "0x4d1654"
- },
- {
- "name": "MapWindowPoints",
- "address": "0x4d1658"
- },
- {
- "name": "MapVirtualKeyA",
- "address": "0x4d165c"
- },
- {
- "name": "LoadStringA",
- "address": "0x4d1660"
- },
- {
- "name": "LoadIconA",
- "address": "0x4d1664"
- },
- {
- "name": "LoadCursorA",
- "address": "0x4d1668"
- },
- {
- "name": "LoadBitmapA",
- "address": "0x4d166c"
- },
- {
- "name": "KillTimer",
- "address": "0x4d1670"
- },
- {
- "name": "IsZoomed",
- "address": "0x4d1674"
- },
- {
- "name": "IsWindowVisible",
- "address": "0x4d1678"
- },
- {
- "name": "IsWindowEnabled",
- "address": "0x4d167c"
- },
- {
- "name": "IsWindow",
- "address": "0x4d1680"
- },
- {
- "name": "IsRectEmpty",
- "address": "0x4d1684"
- },
- {
- "name": "IsIconic",
- "address": "0x4d1688"
- },
- {
- "name": "IsDialogMessageA",
- "address": "0x4d168c"
- },
- {
- "name": "IsChild",
- "address": "0x4d1690"
- },
- {
- "name": "InvalidateRect",
- "address": "0x4d1694"
- },
- {
- "name": "IntersectRect",
- "address": "0x4d1698"
- },
- {
- "name": "InsertMenuItemA",
- "address": "0x4d169c"
- },
- {
- "name": "InsertMenuA",
- "address": "0x4d16a0"
- },
- {
- "name": "InflateRect",
- "address": "0x4d16a4"
- },
- {
- "name": "GetWindowThreadProcessId",
- "address": "0x4d16a8"
- },
- {
- "name": "GetWindowTextA",
- "address": "0x4d16ac"
- },
- {
- "name": "GetWindowRgn",
- "address": "0x4d16b0"
- },
- {
- "name": "GetWindowRect",
- "address": "0x4d16b4"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x4d16b8"
- },
- {
- "name": "GetWindowLongA",
- "address": "0x4d16bc"
- },
- {
- "name": "GetWindowDC",
- "address": "0x4d16c0"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x4d16c4"
- },
- {
- "name": "GetSystemMenu",
- "address": "0x4d16c8"
- },
- {
- "name": "GetSysColorBrush",
- "address": "0x4d16cc"
- },
- {
- "name": "GetSysColor",
- "address": "0x4d16d0"
- },
- {
- "name": "GetSubMenu",
- "address": "0x4d16d4"
- },
- {
- "name": "GetScrollPos",
- "address": "0x4d16d8"
- },
- {
- "name": "GetPropA",
- "address": "0x4d16dc"
- },
- {
- "name": "GetParent",
- "address": "0x4d16e0"
- },
- {
- "name": "GetWindow",
- "address": "0x4d16e4"
- },
- {
- "name": "GetMessagePos",
- "address": "0x4d16e8"
- },
- {
- "name": "GetMessageA",
- "address": "0x4d16ec"
- },
- {
- "name": "GetMenuStringA",
- "address": "0x4d16f0"
- },
- {
- "name": "GetMenuState",
- "address": "0x4d16f4"
- },
- {
- "name": "GetMenuItemCount",
- "address": "0x4d16f8"
- },
- {
- "name": "GetMenu",
- "address": "0x4d16fc"
- },
- {
- "name": "GetLastActivePopup",
- "address": "0x4d1700"
- },
- {
- "name": "GetKeyState",
- "address": "0x4d1704"
- },
- {
- "name": "GetKeyNameTextA",
- "address": "0x4d1708"
- },
- {
- "name": "GetIconInfo",
- "address": "0x4d170c"
- },
- {
- "name": "GetForegroundWindow",
- "address": "0x4d1710"
- },
- {
- "name": "GetFocus",
- "address": "0x4d1714"
- },
- {
- "name": "GetDlgItem",
- "address": "0x4d1718"
- },
- {
- "name": "GetDlgCtrlID",
- "address": "0x4d171c"
- },
- {
- "name": "GetDesktopWindow",
- "address": "0x4d1720"
- },
- {
- "name": "GetDCEx",
- "address": "0x4d1724"
- },
- {
- "name": "GetDC",
- "address": "0x4d1728"
- },
- {
- "name": "GetCursorPos",
- "address": "0x4d172c"
- },
- {
- "name": "GetCursor",
- "address": "0x4d1730"
- },
- {
- "name": "GetClientRect",
- "address": "0x4d1734"
- },
- {
- "name": "GetClassNameA",
- "address": "0x4d1738"
- },
- {
- "name": "GetClassInfoW",
- "address": "0x4d173c"
- },
- {
- "name": "GetClassInfoA",
- "address": "0x4d1740"
- },
- {
- "name": "GetCapture",
- "address": "0x4d1744"
- },
- {
- "name": "GetActiveWindow",
- "address": "0x4d1748"
- },
- {
- "name": "FrameRect",
- "address": "0x4d174c"
- },
- {
- "name": "FindWindowA",
- "address": "0x4d1750"
- },
- {
- "name": "FillRect",
- "address": "0x4d1754"
- },
- {
- "name": "ExitWindowsEx",
- "address": "0x4d1758"
- },
- {
- "name": "EqualRect",
- "address": "0x4d175c"
- },
- {
- "name": "EnumWindows",
- "address": "0x4d1760"
- },
- {
- "name": "EnumThreadWindows",
- "address": "0x4d1764"
- },
- {
- "name": "EndPaint",
- "address": "0x4d1768"
- },
- {
- "name": "EnableWindow",
- "address": "0x4d176c"
- },
- {
- "name": "EnableMenuItem",
- "address": "0x4d1770"
- },
- {
- "name": "DrawTextW",
- "address": "0x4d1774"
- },
- {
- "name": "DrawTextA",
- "address": "0x4d1778"
- },
- {
- "name": "DrawMenuBar",
- "address": "0x4d177c"
- },
- {
- "name": "DrawIconEx",
- "address": "0x4d1780"
- },
- {
- "name": "DrawIcon",
- "address": "0x4d1784"
- },
- {
- "name": "DrawFrameControl",
- "address": "0x4d1788"
- },
- {
- "name": "DrawFocusRect",
- "address": "0x4d178c"
- },
- {
- "name": "DrawEdge",
- "address": "0x4d1790"
- },
- {
- "name": "DispatchMessageA",
- "address": "0x4d1794"
- },
- {
- "name": "DestroyWindow",
- "address": "0x4d1798"
- },
- {
- "name": "DestroyMenu",
- "address": "0x4d179c"
- },
- {
- "name": "DestroyIcon",
- "address": "0x4d17a0"
- },
- {
- "name": "DestroyCursor",
- "address": "0x4d17a4"
- },
- {
- "name": "DeleteMenu",
- "address": "0x4d17a8"
- },
- {
- "name": "DefWindowProcA",
- "address": "0x4d17ac"
- },
- {
- "name": "DefMDIChildProcA",
- "address": "0x4d17b0"
- },
- {
- "name": "DefFrameProcA",
- "address": "0x4d17b4"
- },
- {
- "name": "CreateWindowExA",
- "address": "0x4d17b8"
- },
- {
- "name": "CreatePopupMenu",
- "address": "0x4d17bc"
- },
- {
- "name": "CreateMenu",
- "address": "0x4d17c0"
- },
- {
- "name": "CreateIcon",
- "address": "0x4d17c4"
- },
- {
- "name": "CreateAcceleratorTableA",
- "address": "0x4d17c8"
- },
- {
- "name": "CopyIcon",
- "address": "0x4d17cc"
- },
- {
- "name": "ClientToScreen",
- "address": "0x4d17d0"
- },
- {
- "name": "CheckMenuItem",
- "address": "0x4d17d4"
- },
- {
- "name": "CallWindowProcW",
- "address": "0x4d17d8"
- },
- {
- "name": "CallWindowProcA",
- "address": "0x4d17dc"
- },
- {
- "name": "CallNextHookEx",
- "address": "0x4d17e0"
- },
- {
- "name": "BringWindowToTop",
- "address": "0x4d17e4"
- },
- {
- "name": "BeginPaint",
- "address": "0x4d17e8"
- },
- {
- "name": "AppendMenuA",
- "address": "0x4d17ec"
- },
- {
- "name": "CharPrevA",
- "address": "0x4d17f0"
- },
- {
- "name": "CharNextA",
- "address": "0x4d17f4"
- },
- {
- "name": "CharLowerBuffA",
- "address": "0x4d17f8"
- },
- {
- "name": "CharLowerA",
- "address": "0x4d17fc"
- },
- {
- "name": "CharUpperBuffA",
- "address": "0x4d1800"
- },
- {
- "name": "CharToOemBuffA",
- "address": "0x4d1804"
- },
- {
- "name": "AdjustWindowRectEx",
- "address": "0x4d1808"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "ImageList_GetImageInfo",
- "address": "0x4d1810"
- },
- {
- "name": "ImageList_SetIconSize",
- "address": "0x4d1814"
- },
- {
- "name": "ImageList_GetIconSize",
- "address": "0x4d1818"
- },
- {
- "name": "ImageList_GetDragImage",
- "address": "0x4d181c"
- },
- {
- "name": "ImageList_DragShowNolock",
- "address": "0x4d1820"
- },
- {
- "name": "ImageList_SetDragCursorImage",
- "address": "0x4d1824"
- },
- {
- "name": "ImageList_DragMove",
- "address": "0x4d1828"
- },
- {
- "name": "ImageList_DragLeave",
- "address": "0x4d182c"
- },
- {
- "name": "ImageList_DragEnter",
- "address": "0x4d1830"
- },
- {
- "name": "ImageList_EndDrag",
- "address": "0x4d1834"
- },
- {
- "name": "ImageList_BeginDrag",
- "address": "0x4d1838"
- },
- {
- "name": "ImageList_LoadImage",
- "address": "0x4d183c"
- },
- {
- "name": "ImageList_GetIcon",
- "address": "0x4d1840"
- },
- {
- "name": "ImageList_Remove",
- "address": "0x4d1844"
- },
- {
- "name": "ImageList_DrawEx",
- "address": "0x4d1848"
- },
- {
- "name": "ImageList_AddMasked",
- "address": "0x4d184c"
- },
- {
- "name": "ImageList_Replace",
- "address": "0x4d1850"
- },
- {
- "name": "ImageList_Draw",
- "address": "0x4d1854"
- },
- {
- "name": "ImageList_SetOverlayImage",
- "address": "0x4d1858"
- },
- {
- "name": "ImageList_GetBkColor",
- "address": "0x4d185c"
- },
- {
- "name": "ImageList_SetBkColor",
- "address": "0x4d1860"
- },
- {
- "name": "ImageList_ReplaceIcon",
- "address": "0x4d1864"
- },
- {
- "name": "ImageList_Add",
- "address": "0x4d1868"
- },
- {
- "name": "ImageList_GetImageCount",
- "address": "0x4d186c"
- },
- {
- "name": "ImageList_Destroy",
- "address": "0x4d1870"
- },
- {
- "name": "ImageList_Create",
- "address": "0x4d1874"
- },
- {
- "name": "InitCommonControls",
- "address": "0x4d1878"
- }
- ],
- "dll": "comctl32.dll"
- },
- {
- "imports": [
- {
- "name": "OpenPrinterA",
- "address": "0x4d1880"
- },
- {
- "name": "EnumPrintersA",
- "address": "0x4d1884"
- },
- {
- "name": "DocumentPropertiesA",
- "address": "0x4d1888"
- },
- {
- "name": "ClosePrinter",
- "address": "0x4d188c"
- }
- ],
- "dll": "winspool.drv"
- },
- {
- "imports": [
- {
- "name": "GetSaveFileNameA",
- "address": "0x4d1894"
- },
- {
- "name": "GetOpenFileNameA",
- "address": "0x4d1898"
- }
- ],
- "dll": "comdlg32.dll"
- },
- {
- "imports": [
- {
- "name": "CoTaskMemFree",
- "address": "0x4d18a0"
- },
- {
- "name": "CLSIDFromProgID",
- "address": "0x4d18a4"
- },
- {
- "name": "CoCreateInstance",
- "address": "0x4d18a8"
- },
- {
- "name": "CoFreeUnusedLibraries",
- "address": "0x4d18ac"
- },
- {
- "name": "CoUninitialize",
- "address": "0x4d18b0"
- },
- {
- "name": "CoInitialize",
- "address": "0x4d18b4"
- },
- {
- "name": "IsEqualGUID",
- "address": "0x4d18b8"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "GetActiveObject",
- "address": "0x4d18c0"
- },
- {
- "name": "RegisterTypeLib",
- "address": "0x4d18c4"
- },
- {
- "name": "LoadTypeLib",
- "address": "0x4d18c8"
- },
- {
- "name": "SysFreeString",
- "address": "0x4d18cc"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "ShellExecuteExA",
- "address": "0x4d18d4"
- },
- {
- "name": "ShellExecuteA",
- "address": "0x4d18d8"
- },
- {
- "name": "SHGetFileInfoA",
- "address": "0x4d18dc"
- },
- {
- "name": "ExtractIconA",
- "address": "0x4d18e0"
- }
- ],
- "dll": "shell32.dll"
- },
- {
- "imports": [
- {
- "name": "SHChangeNotify",
- "address": "0x4d18e8"
- },
- {
- "name": "SHBrowseForFolder",
- "address": "0x4d18ec"
- },
- {
- "name": "SHGetPathFromIDList",
- "address": "0x4d18f0"
- },
- {
- "name": "SHGetMalloc",
- "address": "0x4d18f4"
- }
- ],
- "dll": "shell32.dll"
- },
- {
- "imports": [
- {
- "name": "CoDisconnectObject",
- "address": "0x4d18fc"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "AdjustTokenPrivileges",
- "address": "0x4d1904"
- }
- ],
- "dll": "advapi32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x000e1cac",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x004cbf10",
- "timestamp": "1992-06-19 22:22:17",
- "osversion": "1.0",
- "sections": [
- {
- "name": "CODE",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x000cb200",
- "entropy": "6.55",
- "raw_address": "0x00000400",
- "virtual_size": "0x000cb180",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": "DATA",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x000cd000",
- "size_of_data": "0x00001400",
- "entropy": "4.28",
- "raw_address": "0x000cb600",
- "virtual_size": "0x0000138c",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": "BSS",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x000cf000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x000cca00",
- "virtual_size": "0x000015a4",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".idata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x000d1000",
- "size_of_data": "0x00002a00",
- "entropy": "5.02",
- "raw_address": "0x000cca00",
- "virtual_size": "0x0000293a",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x000d4000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x000cf400",
- "virtual_size": "0x00000008",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x000d5000",
- "size_of_data": "0x00000200",
- "entropy": "0.21",
- "raw_address": "0x000cf400",
- "virtual_size": "0x00000018",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x000d6000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x000cf600",
- "virtual_size": "0x0000bd9c",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x000e2000",
- "size_of_data": "0x00011c00",
- "entropy": "4.96",
- "raw_address": "0x000cf600",
- "virtual_size": "0x00011c00",
- "characteristics_raw": "0x50000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x000d1000",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000293a"
- },
- {
- "virtual_address": "0x000e2000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00011c00"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x000d5000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "a2449d4160b59e7f523a1790ed0ed3a0",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 18,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement