paladin316

Loki_e27462c1f63121d12b1159950e279000_exe_2019-07-05_08_30.t

Jul 7th, 2019
2,237
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 80.81 KB | None | 0 0
  1.  
  2. * MalFamily: ""
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Loki_e27462c1f63121d12b1159950e279000.exe"
  7. * File Size: 737280
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "c68a852844dfc2341879a7bc8a55f373130e61e4316ef17cbf9cd9e355f537ee"
  10. * MD5: "e27462c1f63121d12b1159950e279000"
  11. * SHA1: "af95b412feb38ac6f2a8c8c9bceadd2f48f66555"
  12. * SHA512: "c386cc79a482764d4af79271e42e167d05a7f64cc51a7e54d580cc2cd9362387ff84eb0783bb4826899a839de86b95d8f20fe58e84e883bb5f539ce2f80cf43d"
  13. * CRC32: "BFAE0736"
  14. * SSDEEP: "12288:Arvv7/pm5+g9+NqfHPfUDJA+QSCWXTr4QQNWIYFVMwOA9Fp:6vT2+w+NEHUVFTrYWIYbLp"
  15.  
  16. * Process Execution:
  17. "Loki_e27462c1f63121d12b1159950e279000.exe",
  18. "services.exe",
  19. "sc.exe",
  20. "svchost.exe"
  21.  
  22.  
  23. * Signatures Detected:
  24.  
  25. "Description": "Creates RWX memory",
  26. "Details":
  27.  
  28.  
  29. "Description": "A process attempted to delay the analysis task.",
  30. "Details":
  31.  
  32. "Process": "Loki_e27462c1f63121d12b1159950e279000.exe tried to sleep 1440 seconds, actually delayed analysis time by 0 seconds"
  33.  
  34.  
  35.  
  36.  
  37. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  38. "Details":
  39.  
  40. "post_no_referer": "HTTP traffic contains a POST request with no referer header"
  41.  
  42.  
  43. "http_version_old": "HTTP traffic uses version 1.0"
  44.  
  45.  
  46. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  47.  
  48.  
  49. "suspicious_request": "http://54.39.161.153/wp/web/html/upload/log/test/Panel/five/fre.php"
  50.  
  51.  
  52.  
  53.  
  54. "Description": "Performs some HTTP requests",
  55. "Details":
  56.  
  57. "url": "http://54.39.161.153/wp/web/html/upload/log/test/Panel/five/fre.php"
  58.  
  59.  
  60.  
  61.  
  62. "Description": "The binary likely contains encrypted or compressed data.",
  63. "Details":
  64.  
  65. "section": "name: .rsrc, entropy: 7.32, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x00039c00, virtual_size: 0x00039b0c"
  66.  
  67.  
  68.  
  69.  
  70. "Description": "Deletes its original binary from disk",
  71. "Details":
  72.  
  73.  
  74. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  75. "Details":
  76.  
  77. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 16342991 times"
  78.  
  79.  
  80.  
  81.  
  82. "Description": "Steals private information from local Internet browsers",
  83. "Details":
  84.  
  85. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
  86.  
  87.  
  88.  
  89.  
  90. "Description": "Spoofs its process name and/or associated pathname to appear as a legitimate process",
  91. "Details":
  92.  
  93. "modified_name": "loki_e27462c1f63121d12b1159950e279000.exe",
  94. "modified_path": "C:\\Users\\user\\AppData\\Local\\Temp\\loki_e27462c1f63121d12b1159950e279000.exe",
  95. "original_name": "Loki_e27462c1f63121d12b1159950e279000.exe",
  96. "original_path": "C:\\Users\\user\\AppData\\Local\\Temp\\Loki_e27462c1f63121d12b1159950e279000.exe"
  97.  
  98.  
  99.  
  100.  
  101. "Description": "Creates a hidden or system file",
  102. "Details":
  103.  
  104. "file": "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.exe"
  105.  
  106.  
  107. "file": "C:\\Users\\user\\AppData\\Roaming\\474604"
  108.  
  109.  
  110.  
  111.  
  112. "Description": "File has been identified by 12 Antiviruses on VirusTotal as malicious",
  113. "Details":
  114.  
  115. "FireEye": "Generic.mg.e27462c1f63121d1"
  116.  
  117.  
  118. "Invincea": "heuristic"
  119.  
  120.  
  121. "Symantec": "ML.Attribute.HighConfidence"
  122.  
  123.  
  124. "APEX": "Malicious"
  125.  
  126.  
  127. "Kaspersky": "UDS:DangerousObject.Multi.Generic"
  128.  
  129.  
  130. "Rising": "Spyware.Stealer!8.3090/N3#88% (RDM+:cmRtazq7i2HZkiq14JlvaNVJHw7r)"
  131.  
  132.  
  133. "Ikarus": "Trojan-Ransom.GandCrab"
  134.  
  135.  
  136. "Endgame": "malicious (moderate confidence)"
  137.  
  138.  
  139. "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
  140.  
  141.  
  142. "Cylance": "Unsafe"
  143.  
  144.  
  145. "CrowdStrike": "win/malicious_confidence_90% (D)"
  146.  
  147.  
  148. "Qihoo-360": "HEUR/QVM10.1.4FFD.Malware.Gen"
  149.  
  150.  
  151.  
  152.  
  153. "Description": "Harvests credentials from local FTP client softwares",
  154. "Details":
  155.  
  156. "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\sitemanager.xml"
  157.  
  158.  
  159. "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\recentservers.xml"
  160.  
  161.  
  162. "file": "C:\\Users\\user\\AppData\\Roaming\\Far Manager\\Profile\\PluginsData\\42E4AEB1-A230-44F4-B33C-F195BB654931.db"
  163.  
  164.  
  165. "file": "C:\\Program Files (x86)\\FTPGetter\\Profile\\servers.xml"
  166.  
  167.  
  168. "file": "C:\\Users\\user\\AppData\\Roaming\\FTPGetter\\servers.xml"
  169.  
  170.  
  171. "file": "C:\\Users\\user\\AppData\\Roaming\\Estsoft\\ALFTP\\ESTdb2.dat"
  172.  
  173.  
  174. "key": "HKEY_CURRENT_USER\\Software\\Far\\Plugins\\FTP\\Hosts"
  175.  
  176.  
  177. "key": "HKEY_CURRENT_USER\\Software\\Far2\\Plugins\\FTP\\Hosts"
  178.  
  179.  
  180. "key": "HKEY_CURRENT_USER\\Software\\Ghisler\\Total Commander"
  181.  
  182.  
  183. "key": "HKEY_CURRENT_USER\\Software\\LinasFTP\\Site Manager"
  184.  
  185.  
  186.  
  187.  
  188. "Description": "Harvests information related to installed instant messenger clients",
  189. "Details":
  190.  
  191. "file": "C:\\Users\\user\\AppData\\Roaming\\.purple\\accounts.xml"
  192.  
  193.  
  194.  
  195.  
  196. "Description": "Harvests information related to installed mail clients",
  197. "Details":
  198.  
  199. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook"
  200.  
  201.  
  202. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046\\Email"
  203.  
  204.  
  205. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046"
  206.  
  207.  
  208. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9234ed9445f8fa418a542f350f18f326"
  209.  
  210.  
  211. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8408552e6dae7d45a0ba01520b6221ff\\Email"
  212.  
  213.  
  214. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9234ed9445f8fa418a542f350f18f326\\Email"
  215.  
  216.  
  217. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001"
  218.  
  219.  
  220. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002"
  221.  
  222.  
  223. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\Email"
  224.  
  225.  
  226. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\c02ebc5353d9cd11975200aa004ae40e\\Email"
  227.  
  228.  
  229. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8f92b60606058348930a96946cf329e1\\Email"
  230.  
  231.  
  232. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8408552e6dae7d45a0ba01520b6221ff"
  233.  
  234.  
  235. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2"
  236.  
  237.  
  238. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\240a97d961ed46428e29a3f1f1c23670"
  239.  
  240.  
  241. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b22783abb139fe46b0aad551d64b60e7\\Email"
  242.  
  243.  
  244. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\c02ebc5353d9cd11975200aa004ae40e"
  245.  
  246.  
  247. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2\\Email"
  248.  
  249.  
  250. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\Email"
  251.  
  252.  
  253. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a\\Email"
  254.  
  255.  
  256. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001\\Email"
  257.  
  258.  
  259. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
  260.  
  261.  
  262. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\cb23f8734d88734ca66c47c4527fd259"
  263.  
  264.  
  265. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001"
  266.  
  267.  
  268. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Outlook\\Profiles\\Outlook"
  269.  
  270.  
  271. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\cb23f8734d88734ca66c47c4527fd259\\Email"
  272.  
  273.  
  274. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook"
  275.  
  276.  
  277. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b22783abb139fe46b0aad551d64b60e7"
  278.  
  279.  
  280. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\240a97d961ed46428e29a3f1f1c23670\\Email"
  281.  
  282.  
  283. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604\\Email"
  284.  
  285.  
  286. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\Email"
  287.  
  288.  
  289. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a"
  290.  
  291.  
  292. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046"
  293.  
  294.  
  295. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604"
  296.  
  297.  
  298. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8f92b60606058348930a96946cf329e1"
  299.  
  300.  
  301. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046\\Email"
  302.  
  303.  
  304.  
  305.  
  306. "Description": "Collects information to fingerprint the system",
  307. "Details":
  308.  
  309.  
  310.  
  311. * Started Service:
  312. "VaultSvc",
  313. "W32Time"
  314.  
  315.  
  316. * Executed Commands:
  317. "C:\\Windows\\system32\\lsass.exe",
  318. "C:\\Windows\\system32\\sc.exe start w32time task_started",
  319. "C:\\Windows\\system32\\svchost.exe -k LocalService"
  320.  
  321.  
  322. * Mutexes:
  323. "6EFA73A4746045B65DEE781E"
  324.  
  325.  
  326. * Modified Files:
  327. "C:\\Users\\user\\AppData\\Local\\Temp\\tmp61B9.tmp",
  328. "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.lck",
  329. "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.exe",
  330. "C:\\Windows\\sysnative\\LogFiles\\Scm\\7bbc503c-5977-4798-a4ae-61483a7e030d",
  331. "C:\\Windows\\sysnative\\LogFiles\\Scm\\afa4ac94-b8b7-4216-a9d0-97ae4def7b11",
  332. "\\??\\PIPE\\lsarpc"
  333.  
  334.  
  335. * Deleted Files:
  336. "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.lck",
  337. "C:\\Users\\user\\AppData\\Local\\Temp\\loki_e27462c1f63121d12b1159950e279000.exe"
  338.  
  339.  
  340. * Modified Registry Keys:
  341. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
  342. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\TimeProviders\\NtpClient\\SpecialPollTimeRemaining"
  343.  
  344.  
  345. * Deleted Registry Keys:
  346.  
  347. * DNS Communications:
  348.  
  349. * Domains:
  350.  
  351. * Network Communication - ICMP:
  352.  
  353. * Network Communication - HTTP:
  354.  
  355. "count": 2,
  356. "body": "",
  357. "uri": "http://54.39.161.153/wp/web/html/upload/log/test/Panel/five/fre.php",
  358. "user-agent": "Mozilla/4.08 (Charon; Inferno)",
  359. "method": "POST",
  360. "host": "54.39.161.153",
  361. "version": "1.0",
  362. "path": "/wp/web/html/upload/log/test/Panel/five/fre.php",
  363. "data": "POST /wp/web/html/upload/log/test/Panel/five/fre.php HTTP/1.0\r\nUser-Agent: Mozilla/4.08 (Charon; Inferno)\r\nHost: 54.39.161.153\r\nAccept: */*\r\nContent-Type: application/octet-stream\r\nContent-Encoding: binary\r\nContent-Key: B74F6EC6\r\nContent-Length: 176\r\nConnection: close\r\n\r\n",
  364. "port": 80
  365.  
  366.  
  367. "count": 24,
  368. "body": "",
  369. "uri": "http://54.39.161.153/wp/web/html/upload/log/test/Panel/five/fre.php",
  370. "user-agent": "Mozilla/4.08 (Charon; Inferno)",
  371. "method": "POST",
  372. "host": "54.39.161.153",
  373. "version": "1.0",
  374. "path": "/wp/web/html/upload/log/test/Panel/five/fre.php",
  375. "data": "POST /wp/web/html/upload/log/test/Panel/five/fre.php HTTP/1.0\r\nUser-Agent: Mozilla/4.08 (Charon; Inferno)\r\nHost: 54.39.161.153\r\nAccept: */*\r\nContent-Type: application/octet-stream\r\nContent-Encoding: binary\r\nContent-Key: B74F6EC6\r\nContent-Length: 149\r\nConnection: close\r\n\r\n",
  376. "port": 80
  377.  
  378.  
  379.  
  380. * Network Communication - SMTP:
  381.  
  382. * Network Communication - Hosts:
  383.  
  384. * Network Communication - IRC:
  385.  
  386. * Static Analysis:
  387. "pe":
  388. "peid_signatures": null,
  389. "imports":
  390.  
  391. "imports":
  392.  
  393. "name": "LCMapStringW",
  394. "address": "0x4490b0"
  395.  
  396.  
  397. "name": "CompareStringW",
  398. "address": "0x4490b4"
  399.  
  400.  
  401. "name": "FreeEnvironmentStringsW",
  402. "address": "0x4490b8"
  403.  
  404.  
  405. "name": "GetEnvironmentStringsW",
  406. "address": "0x4490bc"
  407.  
  408.  
  409. "name": "GetSystemTimeAsFileTime",
  410. "address": "0x4490c0"
  411.  
  412.  
  413. "name": "GetCurrentProcessId",
  414. "address": "0x4490c4"
  415.  
  416.  
  417. "name": "QueryPerformanceCounter",
  418. "address": "0x4490c8"
  419.  
  420.  
  421. "name": "GetModuleFileNameA",
  422. "address": "0x4490cc"
  423.  
  424.  
  425. "name": "GetProcessHeap",
  426. "address": "0x4490d0"
  427.  
  428.  
  429. "name": "LoadLibraryW",
  430. "address": "0x4490d4"
  431.  
  432.  
  433. "name": "OutputDebugStringW",
  434. "address": "0x4490d8"
  435.  
  436.  
  437. "name": "GetCurrentThreadId",
  438. "address": "0x4490dc"
  439.  
  440.  
  441. "name": "GetCPInfo",
  442. "address": "0x4490e0"
  443.  
  444.  
  445. "name": "GetOEMCP",
  446. "address": "0x4490e4"
  447.  
  448.  
  449. "name": "GetACP",
  450. "address": "0x4490e8"
  451.  
  452.  
  453. "name": "IsValidCodePage",
  454. "address": "0x4490ec"
  455.  
  456.  
  457. "name": "LoadLibraryExW",
  458. "address": "0x4490f0"
  459.  
  460.  
  461. "name": "GetModuleHandleW",
  462. "address": "0x4490f4"
  463.  
  464.  
  465. "name": "GetStartupInfoW",
  466. "address": "0x4490f8"
  467.  
  468.  
  469. "name": "TlsFree",
  470. "address": "0x4490fc"
  471.  
  472.  
  473. "name": "TlsSetValue",
  474. "address": "0x449100"
  475.  
  476.  
  477. "name": "TlsGetValue",
  478. "address": "0x449104"
  479.  
  480.  
  481. "name": "TlsAlloc",
  482. "address": "0x449108"
  483.  
  484.  
  485. "name": "SetStdHandle",
  486. "address": "0x44910c"
  487.  
  488.  
  489. "name": "FlushFileBuffers",
  490. "address": "0x449110"
  491.  
  492.  
  493. "name": "SetFilePointerEx",
  494. "address": "0x449114"
  495.  
  496.  
  497. "name": "HeapReAlloc",
  498. "address": "0x449118"
  499.  
  500.  
  501. "name": "GetStringTypeW",
  502. "address": "0x44911c"
  503.  
  504.  
  505. "name": "CreateFileW",
  506. "address": "0x449120"
  507.  
  508.  
  509. "name": "SetEndOfFile",
  510. "address": "0x449124"
  511.  
  512.  
  513. "name": "ReadConsoleW",
  514. "address": "0x449128"
  515.  
  516.  
  517. "name": "GlobalSize",
  518. "address": "0x44912c"
  519.  
  520.  
  521. "name": "CreateFileA",
  522. "address": "0x449130"
  523.  
  524.  
  525. "name": "CloseHandle",
  526. "address": "0x449134"
  527.  
  528.  
  529. "name": "ReadFile",
  530. "address": "0x449138"
  531.  
  532.  
  533. "name": "GetFileSize",
  534. "address": "0x44913c"
  535.  
  536.  
  537. "name": "GlobalFree",
  538. "address": "0x449140"
  539.  
  540.  
  541. "name": "GlobalUnlock",
  542. "address": "0x449144"
  543.  
  544.  
  545. "name": "GlobalLock",
  546. "address": "0x449148"
  547.  
  548.  
  549. "name": "GlobalAlloc",
  550. "address": "0x44914c"
  551.  
  552.  
  553. "name": "GetModuleHandleA",
  554. "address": "0x449150"
  555.  
  556.  
  557. "name": "CreateToolhelp32Snapshot",
  558. "address": "0x449154"
  559.  
  560.  
  561. "name": "GetConsoleWindow",
  562. "address": "0x449158"
  563.  
  564.  
  565. "name": "UpdateResourceA",
  566. "address": "0x44915c"
  567.  
  568.  
  569. "name": "GetTempPathA",
  570. "address": "0x449160"
  571.  
  572.  
  573. "name": "EnumResourceTypesA",
  574. "address": "0x449164"
  575.  
  576.  
  577. "name": "FindResourceExA",
  578. "address": "0x449168"
  579.  
  580.  
  581. "name": "CreateEventA",
  582. "address": "0x44916c"
  583.  
  584.  
  585. "name": "MulDiv",
  586. "address": "0x449170"
  587.  
  588.  
  589. "name": "SizeofResource",
  590. "address": "0x449174"
  591.  
  592.  
  593. "name": "TerminateProcess",
  594. "address": "0x449178"
  595.  
  596.  
  597. "name": "GetCurrentProcess",
  598. "address": "0x44917c"
  599.  
  600.  
  601. "name": "SetUnhandledExceptionFilter",
  602. "address": "0x449180"
  603.  
  604.  
  605. "name": "UnhandledExceptionFilter",
  606. "address": "0x449184"
  607.  
  608.  
  609. "name": "DeleteCriticalSection",
  610. "address": "0x449188"
  611.  
  612.  
  613. "name": "Sleep",
  614. "address": "0x44918c"
  615.  
  616.  
  617. "name": "LoadResource",
  618. "address": "0x449190"
  619.  
  620.  
  621. "name": "WaitForSingleObject",
  622. "address": "0x449194"
  623.  
  624.  
  625. "name": "SetLastError",
  626. "address": "0x449198"
  627.  
  628.  
  629. "name": "GetLastError",
  630. "address": "0x44919c"
  631.  
  632.  
  633. "name": "VirtualAlloc",
  634. "address": "0x4491a0"
  635.  
  636.  
  637. "name": "LockResource",
  638. "address": "0x4491a4"
  639.  
  640.  
  641. "name": "FreeResource",
  642. "address": "0x4491a8"
  643.  
  644.  
  645. "name": "GetTempFileNameA",
  646. "address": "0x4491ac"
  647.  
  648.  
  649. "name": "InterlockedIncrement",
  650. "address": "0x4491b0"
  651.  
  652.  
  653. "name": "EncodePointer",
  654. "address": "0x4491b4"
  655.  
  656.  
  657. "name": "DecodePointer",
  658. "address": "0x4491b8"
  659.  
  660.  
  661. "name": "InterlockedDecrement",
  662. "address": "0x4491bc"
  663.  
  664.  
  665. "name": "ExitProcess",
  666. "address": "0x4491c0"
  667.  
  668.  
  669. "name": "GetModuleHandleExW",
  670. "address": "0x4491c4"
  671.  
  672.  
  673. "name": "GetProcAddress",
  674. "address": "0x4491c8"
  675.  
  676.  
  677. "name": "AreFileApisANSI",
  678. "address": "0x4491cc"
  679.  
  680.  
  681. "name": "MultiByteToWideChar",
  682. "address": "0x4491d0"
  683.  
  684.  
  685. "name": "RaiseException",
  686. "address": "0x4491d4"
  687.  
  688.  
  689. "name": "RtlUnwind",
  690. "address": "0x4491d8"
  691.  
  692.  
  693. "name": "GetStdHandle",
  694. "address": "0x4491dc"
  695.  
  696.  
  697. "name": "GetFileType",
  698. "address": "0x4491e0"
  699.  
  700.  
  701. "name": "GetModuleFileNameW",
  702. "address": "0x4491e4"
  703.  
  704.  
  705. "name": "WriteConsoleW",
  706. "address": "0x4491e8"
  707.  
  708.  
  709. "name": "GetCommandLineA",
  710. "address": "0x4491ec"
  711.  
  712.  
  713. "name": "WriteFile",
  714. "address": "0x4491f0"
  715.  
  716.  
  717. "name": "IsProcessorFeaturePresent",
  718. "address": "0x4491f4"
  719.  
  720.  
  721. "name": "HeapAlloc",
  722. "address": "0x4491f8"
  723.  
  724.  
  725. "name": "HeapFree",
  726. "address": "0x4491fc"
  727.  
  728.  
  729. "name": "IsDebuggerPresent",
  730. "address": "0x449200"
  731.  
  732.  
  733. "name": "EnterCriticalSection",
  734. "address": "0x449204"
  735.  
  736.  
  737. "name": "LeaveCriticalSection",
  738. "address": "0x449208"
  739.  
  740.  
  741. "name": "InitializeCriticalSectionAndSpinCount",
  742. "address": "0x44920c"
  743.  
  744.  
  745. "name": "WideCharToMultiByte",
  746. "address": "0x449210"
  747.  
  748.  
  749. "name": "GetConsoleCP",
  750. "address": "0x449214"
  751.  
  752.  
  753. "name": "GetConsoleMode",
  754. "address": "0x449218"
  755.  
  756.  
  757. "name": "HeapSize",
  758. "address": "0x44921c"
  759.  
  760.  
  761. "name": "SetEnvironmentVariableA",
  762. "address": "0x449220"
  763.  
  764. ,
  765. "dll": "KERNEL32.dll"
  766.  
  767.  
  768. "imports":
  769.  
  770. "name": "SetMenu",
  771. "address": "0x449234"
  772.  
  773.  
  774. "name": "GetMessageA",
  775. "address": "0x449238"
  776.  
  777.  
  778. "name": "TranslateMessage",
  779. "address": "0x44923c"
  780.  
  781.  
  782. "name": "GetWindowInfo",
  783. "address": "0x449240"
  784.  
  785.  
  786. "name": "SetWindowLongA",
  787. "address": "0x449244"
  788.  
  789.  
  790. "name": "AdjustWindowRectEx",
  791. "address": "0x449248"
  792.  
  793.  
  794. "name": "MoveWindow",
  795. "address": "0x44924c"
  796.  
  797.  
  798. "name": "CreateWindowExA",
  799. "address": "0x449250"
  800.  
  801.  
  802. "name": "LoadImageA",
  803. "address": "0x449254"
  804.  
  805.  
  806. "name": "LoadCursorA",
  807. "address": "0x449258"
  808.  
  809.  
  810. "name": "LoadBitmapA",
  811. "address": "0x44925c"
  812.  
  813.  
  814. "name": "UnhookWindowsHookEx",
  815. "address": "0x449260"
  816.  
  817.  
  818. "name": "GetParent",
  819. "address": "0x449264"
  820.  
  821.  
  822. "name": "GetWindowLongA",
  823. "address": "0x449268"
  824.  
  825.  
  826. "name": "MapWindowPoints",
  827. "address": "0x44926c"
  828.  
  829.  
  830. "name": "GetCursorPos",
  831. "address": "0x449270"
  832.  
  833.  
  834. "name": "MessageBoxA",
  835. "address": "0x449274"
  836.  
  837.  
  838. "name": "GetWindowRect",
  839. "address": "0x449278"
  840.  
  841.  
  842. "name": "EndPaint",
  843. "address": "0x44927c"
  844.  
  845.  
  846. "name": "BeginPaint",
  847. "address": "0x449280"
  848.  
  849.  
  850. "name": "SetForegroundWindow",
  851. "address": "0x449284"
  852.  
  853.  
  854. "name": "DrawTextExW",
  855. "address": "0x449288"
  856.  
  857.  
  858. "name": "DrawTextA",
  859. "address": "0x44928c"
  860.  
  861.  
  862. "name": "DispatchMessageA",
  863. "address": "0x449290"
  864.  
  865.  
  866. "name": "GetSystemMenu",
  867. "address": "0x449294"
  868.  
  869.  
  870. "name": "AppendMenuA",
  871. "address": "0x449298"
  872.  
  873.  
  874. "name": "GetSystemMetrics",
  875. "address": "0x44929c"
  876.  
  877.  
  878. "name": "CreateAcceleratorTableA",
  879. "address": "0x4492a0"
  880.  
  881.  
  882. "name": "GetDlgItem",
  883. "address": "0x4492a4"
  884.  
  885.  
  886. "name": "DestroyWindow",
  887. "address": "0x4492a8"
  888.  
  889.  
  890. "name": "DefWindowProcA",
  891. "address": "0x4492ac"
  892.  
  893.  
  894. "name": "AttachThreadInput",
  895. "address": "0x4492b0"
  896.  
  897.  
  898. "name": "SendMessageA",
  899. "address": "0x4492b4"
  900.  
  901.  
  902. "name": "DrawFrameControl",
  903. "address": "0x4492b8"
  904.  
  905.  
  906. "name": "GetClientRect",
  907. "address": "0x4492bc"
  908.  
  909.  
  910. "name": "InvalidateRect",
  911. "address": "0x4492c0"
  912.  
  913.  
  914. "name": "ReleaseDC",
  915. "address": "0x4492c4"
  916.  
  917.  
  918. "name": "GetDC",
  919. "address": "0x4492c8"
  920.  
  921.  
  922. "name": "UpdateWindow",
  923. "address": "0x4492cc"
  924.  
  925.  
  926. "name": "KillTimer",
  927. "address": "0x4492d0"
  928.  
  929.  
  930. "name": "SetTimer",
  931. "address": "0x4492d4"
  932.  
  933.  
  934. "name": "GetKeyState",
  935. "address": "0x4492d8"
  936.  
  937.  
  938. "name": "SetFocus",
  939. "address": "0x4492dc"
  940.  
  941.  
  942. "name": "SetWindowPos",
  943. "address": "0x4492e0"
  944.  
  945.  
  946. "name": "ShowWindow",
  947. "address": "0x4492e4"
  948.  
  949.  
  950. "name": "RegisterClassA",
  951. "address": "0x4492e8"
  952.  
  953.  
  954. "name": "PostQuitMessage",
  955. "address": "0x4492ec"
  956.  
  957. ,
  958. "dll": "USER32.dll"
  959.  
  960.  
  961. "imports":
  962.  
  963. "name": "SetWindowExtEx",
  964. "address": "0x449034"
  965.  
  966.  
  967. "name": "TextOutA",
  968. "address": "0x449038"
  969.  
  970.  
  971. "name": "MoveToEx",
  972. "address": "0x44903c"
  973.  
  974.  
  975. "name": "GetObjectA",
  976. "address": "0x449040"
  977.  
  978.  
  979. "name": "BeginPath",
  980. "address": "0x449044"
  981.  
  982.  
  983. "name": "GetTextMetricsA",
  984. "address": "0x449048"
  985.  
  986.  
  987. "name": "SetTextJustification",
  988. "address": "0x44904c"
  989.  
  990.  
  991. "name": "SetTextColor",
  992. "address": "0x449050"
  993.  
  994.  
  995. "name": "SetPixel",
  996. "address": "0x449054"
  997.  
  998.  
  999. "name": "SetMapMode",
  1000. "address": "0x449058"
  1001.  
  1002.  
  1003. "name": "SetBkMode",
  1004. "address": "0x44905c"
  1005.  
  1006.  
  1007. "name": "SetBkColor",
  1008. "address": "0x449060"
  1009.  
  1010.  
  1011. "name": "Rectangle",
  1012. "address": "0x449064"
  1013.  
  1014.  
  1015. "name": "LineDDA",
  1016. "address": "0x449068"
  1017.  
  1018.  
  1019. "name": "GetMapMode",
  1020. "address": "0x44906c"
  1021.  
  1022.  
  1023. "name": "GetCurrentObject",
  1024. "address": "0x449070"
  1025.  
  1026.  
  1027. "name": "GetROP2",
  1028. "address": "0x449074"
  1029.  
  1030.  
  1031. "name": "CreateSolidBrush",
  1032. "address": "0x449078"
  1033.  
  1034.  
  1035. "name": "CreatePatternBrush",
  1036. "address": "0x44907c"
  1037.  
  1038.  
  1039. "name": "CreatePen",
  1040. "address": "0x449080"
  1041.  
  1042.  
  1043. "name": "CreateFontA",
  1044. "address": "0x449084"
  1045.  
  1046.  
  1047. "name": "CreateFontIndirectA",
  1048. "address": "0x449088"
  1049.  
  1050.  
  1051. "name": "CreateEllipticRgn",
  1052. "address": "0x44908c"
  1053.  
  1054.  
  1055. "name": "SelectObject",
  1056. "address": "0x449090"
  1057.  
  1058.  
  1059. "name": "DeleteObject",
  1060. "address": "0x449094"
  1061.  
  1062.  
  1063. "name": "DeleteDC",
  1064. "address": "0x449098"
  1065.  
  1066.  
  1067. "name": "CreateCompatibleDC",
  1068. "address": "0x44909c"
  1069.  
  1070.  
  1071. "name": "CreateCompatibleBitmap",
  1072. "address": "0x4490a0"
  1073.  
  1074.  
  1075. "name": "BitBlt",
  1076. "address": "0x4490a4"
  1077.  
  1078.  
  1079. "name": "GetDeviceCaps",
  1080. "address": "0x4490a8"
  1081.  
  1082. ,
  1083. "dll": "GDI32.dll"
  1084.  
  1085.  
  1086. "imports":
  1087.  
  1088. "name": "CryptReleaseContext",
  1089. "address": "0x449000"
  1090.  
  1091.  
  1092. "name": "CryptGetProvParam",
  1093. "address": "0x449004"
  1094.  
  1095.  
  1096. "name": "CryptAcquireContextA",
  1097. "address": "0x449008"
  1098.  
  1099. ,
  1100. "dll": "ADVAPI32.dll"
  1101.  
  1102.  
  1103. "imports":
  1104.  
  1105. "name": "CoInitialize",
  1106. "address": "0x4492f4"
  1107.  
  1108.  
  1109. "name": "CoUninitialize",
  1110. "address": "0x4492f8"
  1111.  
  1112.  
  1113. "name": "CreateStreamOnHGlobal",
  1114. "address": "0x4492fc"
  1115.  
  1116. ,
  1117. "dll": "ole32.dll"
  1118.  
  1119.  
  1120. "imports":
  1121.  
  1122. "name": "OleLoadPicture",
  1123. "address": "0x449228"
  1124.  
  1125.  
  1126. "name": "OleSavePictureFile",
  1127. "address": "0x44922c"
  1128.  
  1129. ,
  1130. "dll": "OLEAUT32.dll"
  1131.  
  1132.  
  1133. "imports":
  1134.  
  1135. "name": "CertGetNameStringA",
  1136. "address": "0x44901c"
  1137.  
  1138. ,
  1139. "dll": "CRYPT32.dll"
  1140.  
  1141.  
  1142. "imports":
  1143.  
  1144. "name": "ImageList_Create",
  1145. "address": "0x449010"
  1146.  
  1147.  
  1148. "name": null,
  1149. "address": "0x449014"
  1150.  
  1151. ,
  1152. "dll": "COMCTL32.dll"
  1153.  
  1154.  
  1155. "imports":
  1156.  
  1157. "name": "GetWindowRegionData",
  1158. "address": "0x449024"
  1159.  
  1160.  
  1161. "name": "GetDCRegionData",
  1162. "address": "0x449028"
  1163.  
  1164.  
  1165. "name": "DCISetSrcDestClip",
  1166. "address": "0x44902c"
  1167.  
  1168. ,
  1169. "dll": "DCIMAN32.dll"
  1170.  
  1171. ,
  1172. "digital_signers": null,
  1173. "exported_dll_name": null,
  1174. "actual_checksum": "0x000c3853",
  1175. "overlay": null,
  1176. "imagebase": "0x00400000",
  1177. "reported_checksum": "0x000c3853",
  1178. "icon_hash": null,
  1179. "entrypoint": "0x00408297",
  1180. "timestamp": "2019-07-04 21:07:05",
  1181. "osversion": "6.0",
  1182. "sections":
  1183.  
  1184. "name": ".text",
  1185. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
  1186. "virtual_address": "0x00001000",
  1187. "size_of_data": "0x00047a00",
  1188. "entropy": "6.68",
  1189. "raw_address": "0x00000400",
  1190. "virtual_size": "0x00047895",
  1191. "characteristics_raw": "0x60000020"
  1192.  
  1193.  
  1194. "name": ".rdata",
  1195. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  1196. "virtual_address": "0x00049000",
  1197. "size_of_data": "0x00030a00",
  1198. "entropy": "4.70",
  1199. "raw_address": "0x00047e00",
  1200. "virtual_size": "0x00030922",
  1201. "characteristics_raw": "0x40000040"
  1202.  
  1203.  
  1204. "name": ".data",
  1205. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  1206. "virtual_address": "0x0007a000",
  1207. "size_of_data": "0x00001c00",
  1208. "entropy": "4.54",
  1209. "raw_address": "0x00078800",
  1210. "virtual_size": "0x000049f8",
  1211. "characteristics_raw": "0xc0000040"
  1212.  
  1213.  
  1214. "name": ".rsrc",
  1215. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  1216. "virtual_address": "0x0007f000",
  1217. "size_of_data": "0x00039c00",
  1218. "entropy": "7.32",
  1219. "raw_address": "0x0007a400",
  1220. "virtual_size": "0x00039b0c",
  1221. "characteristics_raw": "0x40000040"
  1222.  
  1223. ,
  1224. "resources": ,
  1225. "dirents":
  1226.  
  1227. "virtual_address": "0x00000000",
  1228. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  1229. "size": "0x00000000"
  1230.  
  1231.  
  1232. "virtual_address": "0x000788a4",
  1233. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  1234. "size": "0x000000c8"
  1235.  
  1236.  
  1237. "virtual_address": "0x0007f000",
  1238. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  1239. "size": "0x00039b0c"
  1240.  
  1241.  
  1242. "virtual_address": "0x00000000",
  1243. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  1244. "size": "0x00000000"
  1245.  
  1246.  
  1247. "virtual_address": "0x00000000",
  1248. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  1249. "size": "0x00000000"
  1250.  
  1251.  
  1252. "virtual_address": "0x00000000",
  1253. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  1254. "size": "0x00000000"
  1255.  
  1256.  
  1257. "virtual_address": "0x00049360",
  1258. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  1259. "size": "0x00000038"
  1260.  
  1261.  
  1262. "virtual_address": "0x00000000",
  1263. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  1264. "size": "0x00000000"
  1265.  
  1266.  
  1267. "virtual_address": "0x00000000",
  1268. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  1269. "size": "0x00000000"
  1270.  
  1271.  
  1272. "virtual_address": "0x00000000",
  1273. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  1274. "size": "0x00000000"
  1275.  
  1276.  
  1277. "virtual_address": "0x00077c00",
  1278. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  1279. "size": "0x00000040"
  1280.  
  1281.  
  1282. "virtual_address": "0x00000000",
  1283. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  1284. "size": "0x00000000"
  1285.  
  1286.  
  1287. "virtual_address": "0x00049000",
  1288. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  1289. "size": "0x00000304"
  1290.  
  1291.  
  1292. "virtual_address": "0x00000000",
  1293. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  1294. "size": "0x00000000"
  1295.  
  1296.  
  1297. "virtual_address": "0x00000000",
  1298. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  1299. "size": "0x00000000"
  1300.  
  1301.  
  1302. "virtual_address": "0x00000000",
  1303. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  1304. "size": "0x00000000"
  1305.  
  1306. ,
  1307. "exports": ,
  1308. "guest_signers":
  1309. "imphash": "8b6d3d6285ec33cbfedbed016e4280f6",
  1310. "icon_fuzzy": null,
  1311. "icon": null,
  1312. "pdbpath": "C:\\Ins\\ad\\IFRA\\Release\\black.pdb",
  1313. "imported_dll_count": 9,
  1314. "versioninfo":
  1315.  
  1316.  
  1317.  
  1318. * Resolved APIs:
  1319. "kernel32.dll.FlsAlloc",
  1320. "kernel32.dll.FlsFree",
  1321. "kernel32.dll.FlsGetValue",
  1322. "kernel32.dll.FlsSetValue",
  1323. "kernel32.dll.InitializeCriticalSectionEx",
  1324. "kernel32.dll.CreateSemaphoreExW",
  1325. "kernel32.dll.SetThreadStackGuarantee",
  1326. "kernel32.dll.CreateThreadpoolTimer",
  1327. "kernel32.dll.SetThreadpoolTimer",
  1328. "kernel32.dll.WaitForThreadpoolTimerCallbacks",
  1329. "kernel32.dll.CloseThreadpoolTimer",
  1330. "kernel32.dll.CreateThreadpoolWait",
  1331. "kernel32.dll.SetThreadpoolWait",
  1332. "kernel32.dll.CloseThreadpoolWait",
  1333. "kernel32.dll.FlushProcessWriteBuffers",
  1334. "kernel32.dll.FreeLibraryWhenCallbackReturns",
  1335. "kernel32.dll.GetCurrentProcessorNumber",
  1336. "kernel32.dll.GetLogicalProcessorInformation",
  1337. "kernel32.dll.CreateSymbolicLinkW",
  1338. "kernel32.dll.EnumSystemLocalesEx",
  1339. "kernel32.dll.CompareStringEx",
  1340. "kernel32.dll.GetDateFormatEx",
  1341. "kernel32.dll.GetLocaleInfoEx",
  1342. "kernel32.dll.GetTimeFormatEx",
  1343. "kernel32.dll.GetUserDefaultLocaleName",
  1344. "kernel32.dll.IsValidLocaleName",
  1345. "kernel32.dll.LCMapStringEx",
  1346. "cryptbase.dll.SystemFunction036",
  1347. "uxtheme.dll.ThemeInitApiHook",
  1348. "user32.dll.IsProcessDPIAware",
  1349. "dwmapi.dll.DwmIsCompositionEnabled",
  1350. "gdi32.dll.GetLayout",
  1351. "gdi32.dll.GdiRealizationInfo",
  1352. "gdi32.dll.FontIsLinked",
  1353. "advapi32.dll.RegOpenKeyExW",
  1354. "advapi32.dll.RegQueryInfoKeyW",
  1355. "gdi32.dll.GetTextFaceAliasW",
  1356. "advapi32.dll.RegEnumValueW",
  1357. "advapi32.dll.RegCloseKey",
  1358. "advapi32.dll.RegQueryValueExW",
  1359. "gdi32.dll.GetFontAssocStatus",
  1360. "advapi32.dll.RegQueryValueExA",
  1361. "advapi32.dll.RegEnumKeyExW",
  1362. "cryptsp.dll.CryptAcquireContextA",
  1363. "ws2_32.dll.getaddrinfo",
  1364. "ws2_32.dll.freeaddrinfo",
  1365. "ws2_32.dll.#3",
  1366. "ws2_32.dll.#115",
  1367. "ws2_32.dll.#23",
  1368. "ws2_32.dll.#19",
  1369. "ws2_32.dll.#16",
  1370. "ws2_32.dll.#4",
  1371. "kernel32.dll.GetProcessHeap",
  1372. "kernel32.dll.HeapFree",
  1373. "kernel32.dll.HeapAlloc",
  1374. "kernel32.dll.SetLastError",
  1375. "kernel32.dll.GetLastError",
  1376. "ole32.dll.CoCreateInstance",
  1377. "ole32.dll.CoInitialize",
  1378. "ole32.dll.CoUninitialize",
  1379. "oleaut32.dll.#8",
  1380. "oleaut32.dll.#6",
  1381. "oleaut32.dll.#2",
  1382. "cryptsp.dll.CryptAcquireContextW",
  1383. "cryptsp.dll.CryptCreateHash",
  1384. "cryptsp.dll.CryptHashData",
  1385. "cryptsp.dll.CryptGetHashParam",
  1386. "cryptsp.dll.CryptDestroyHash",
  1387. "cryptsp.dll.CryptReleaseContext",
  1388. "vaultcli.dll.VaultEnumerateItems",
  1389. "vaultcli.dll.VaultEnumerateVaults",
  1390. "vaultcli.dll.VaultFree",
  1391. "vaultcli.dll.VaultGetItem",
  1392. "vaultcli.dll.VaultOpenVault",
  1393. "vaultcli.dll.VaultCloseVault",
  1394. "sechost.dll.LookupAccountSidLocalW",
  1395. "netapi32.dll.NetUserGetInfo",
  1396. "cryptsp.dll.CryptImportKey",
  1397. "cryptsp.dll.CryptSetKeyParam",
  1398. "cryptsp.dll.CryptDecrypt",
  1399. "cryptsp.dll.CryptDestroyKey",
  1400. "ole32.dll.CoInitializeEx",
  1401. "ole32.dll.CoInitializeSecurity",
  1402. "sechost.dll.LookupAccountNameLocalW",
  1403. "advapi32.dll.LookupAccountSidW",
  1404. "kernel32.dll.SortGetHandle",
  1405. "kernel32.dll.SortCloseHandle",
  1406. "w32time.dll.SvchostEntry_W32Time",
  1407. "w32time.dll.SvchostPushServiceGlobals",
  1408. "sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW",
  1409. "ws2_32.dll.WSASocketW",
  1410. "ws2_32.dll.WSAIoctl",
  1411. "ws2_32.dll.#111",
  1412. "userenv.dll.RegisterGPNotification",
  1413. "gpapi.dll.RegisterGPNotificationInternal",
  1414. "sechost.dll.OpenSCManagerW",
  1415. "sechost.dll.OpenServiceW",
  1416. "sechost.dll.CloseServiceHandle",
  1417. "sechost.dll.QueryServiceConfigW",
  1418. "dsrole.dll.DsRoleGetPrimaryDomainInformation",
  1419. "dsrole.dll.DsRoleFreeMemory",
  1420. "sspicli.dll.LsaRegisterPolicyChangeNotification",
  1421. "w32time.dll.TimeProvClose",
  1422. "w32time.dll.TimeProvCommand",
  1423. "w32time.dll.TimeProvOpen",
  1424. "ws2_32.dll.#21",
  1425. "ws2_32.dll.#2",
  1426. "ws2_32.dll.WSAEventSelect",
  1427. "vmictimeprovider.dll.TimeProvClose",
  1428. "vmictimeprovider.dll.TimeProvCommand",
  1429. "vmictimeprovider.dll.TimeProvOpen",
  1430. "advapi32.dll.EventRegister",
  1431. "advapi32.dll.EventEnabled",
  1432. "advapi32.dll.EventWrite",
  1433. "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
  1434. "ws2_32.dll.GetAddrInfoW",
  1435. "ws2_32.dll.FreeAddrInfoW",
  1436. "ws2_32.dll.WSAAddressToStringW",
  1437. "ws2_32.dll.#116",
  1438. "advapi32.dll.EventUnregister",
  1439. "sspicli.dll.LsaUnregisterPolicyChangeNotification",
  1440. "userenv.dll.UnregisterGPNotification",
  1441. "gpapi.dll.UnregisterGPNotificationInternal"
  1442.  
  1443.  
  1444. * Static Analysis:
  1445. "pe":
  1446. "peid_signatures": null,
  1447. "imports":
  1448.  
  1449. "imports":
  1450.  
  1451. "name": "LCMapStringW",
  1452. "address": "0x4490b0"
  1453.  
  1454.  
  1455. "name": "CompareStringW",
  1456. "address": "0x4490b4"
  1457.  
  1458.  
  1459. "name": "FreeEnvironmentStringsW",
  1460. "address": "0x4490b8"
  1461.  
  1462.  
  1463. "name": "GetEnvironmentStringsW",
  1464. "address": "0x4490bc"
  1465.  
  1466.  
  1467. "name": "GetSystemTimeAsFileTime",
  1468. "address": "0x4490c0"
  1469.  
  1470.  
  1471. "name": "GetCurrentProcessId",
  1472. "address": "0x4490c4"
  1473.  
  1474.  
  1475. "name": "QueryPerformanceCounter",
  1476. "address": "0x4490c8"
  1477.  
  1478.  
  1479. "name": "GetModuleFileNameA",
  1480. "address": "0x4490cc"
  1481.  
  1482.  
  1483. "name": "GetProcessHeap",
  1484. "address": "0x4490d0"
  1485.  
  1486.  
  1487. "name": "LoadLibraryW",
  1488. "address": "0x4490d4"
  1489.  
  1490.  
  1491. "name": "OutputDebugStringW",
  1492. "address": "0x4490d8"
  1493.  
  1494.  
  1495. "name": "GetCurrentThreadId",
  1496. "address": "0x4490dc"
  1497.  
  1498.  
  1499. "name": "GetCPInfo",
  1500. "address": "0x4490e0"
  1501.  
  1502.  
  1503. "name": "GetOEMCP",
  1504. "address": "0x4490e4"
  1505.  
  1506.  
  1507. "name": "GetACP",
  1508. "address": "0x4490e8"
  1509.  
  1510.  
  1511. "name": "IsValidCodePage",
  1512. "address": "0x4490ec"
  1513.  
  1514.  
  1515. "name": "LoadLibraryExW",
  1516. "address": "0x4490f0"
  1517.  
  1518.  
  1519. "name": "GetModuleHandleW",
  1520. "address": "0x4490f4"
  1521.  
  1522.  
  1523. "name": "GetStartupInfoW",
  1524. "address": "0x4490f8"
  1525.  
  1526.  
  1527. "name": "TlsFree",
  1528. "address": "0x4490fc"
  1529.  
  1530.  
  1531. "name": "TlsSetValue",
  1532. "address": "0x449100"
  1533.  
  1534.  
  1535. "name": "TlsGetValue",
  1536. "address": "0x449104"
  1537.  
  1538.  
  1539. "name": "TlsAlloc",
  1540. "address": "0x449108"
  1541.  
  1542.  
  1543. "name": "SetStdHandle",
  1544. "address": "0x44910c"
  1545.  
  1546.  
  1547. "name": "FlushFileBuffers",
  1548. "address": "0x449110"
  1549.  
  1550.  
  1551. "name": "SetFilePointerEx",
  1552. "address": "0x449114"
  1553.  
  1554.  
  1555. "name": "HeapReAlloc",
  1556. "address": "0x449118"
  1557.  
  1558.  
  1559. "name": "GetStringTypeW",
  1560. "address": "0x44911c"
  1561.  
  1562.  
  1563. "name": "CreateFileW",
  1564. "address": "0x449120"
  1565.  
  1566.  
  1567. "name": "SetEndOfFile",
  1568. "address": "0x449124"
  1569.  
  1570.  
  1571. "name": "ReadConsoleW",
  1572. "address": "0x449128"
  1573.  
  1574.  
  1575. "name": "GlobalSize",
  1576. "address": "0x44912c"
  1577.  
  1578.  
  1579. "name": "CreateFileA",
  1580. "address": "0x449130"
  1581.  
  1582.  
  1583. "name": "CloseHandle",
  1584. "address": "0x449134"
  1585.  
  1586.  
  1587. "name": "ReadFile",
  1588. "address": "0x449138"
  1589.  
  1590.  
  1591. "name": "GetFileSize",
  1592. "address": "0x44913c"
  1593.  
  1594.  
  1595. "name": "GlobalFree",
  1596. "address": "0x449140"
  1597.  
  1598.  
  1599. "name": "GlobalUnlock",
  1600. "address": "0x449144"
  1601.  
  1602.  
  1603. "name": "GlobalLock",
  1604. "address": "0x449148"
  1605.  
  1606.  
  1607. "name": "GlobalAlloc",
  1608. "address": "0x44914c"
  1609.  
  1610.  
  1611. "name": "GetModuleHandleA",
  1612. "address": "0x449150"
  1613.  
  1614.  
  1615. "name": "CreateToolhelp32Snapshot",
  1616. "address": "0x449154"
  1617.  
  1618.  
  1619. "name": "GetConsoleWindow",
  1620. "address": "0x449158"
  1621.  
  1622.  
  1623. "name": "UpdateResourceA",
  1624. "address": "0x44915c"
  1625.  
  1626.  
  1627. "name": "GetTempPathA",
  1628. "address": "0x449160"
  1629.  
  1630.  
  1631. "name": "EnumResourceTypesA",
  1632. "address": "0x449164"
  1633.  
  1634.  
  1635. "name": "FindResourceExA",
  1636. "address": "0x449168"
  1637.  
  1638.  
  1639. "name": "CreateEventA",
  1640. "address": "0x44916c"
  1641.  
  1642.  
  1643. "name": "MulDiv",
  1644. "address": "0x449170"
  1645.  
  1646.  
  1647. "name": "SizeofResource",
  1648. "address": "0x449174"
  1649.  
  1650.  
  1651. "name": "TerminateProcess",
  1652. "address": "0x449178"
  1653.  
  1654.  
  1655. "name": "GetCurrentProcess",
  1656. "address": "0x44917c"
  1657.  
  1658.  
  1659. "name": "SetUnhandledExceptionFilter",
  1660. "address": "0x449180"
  1661.  
  1662.  
  1663. "name": "UnhandledExceptionFilter",
  1664. "address": "0x449184"
  1665.  
  1666.  
  1667. "name": "DeleteCriticalSection",
  1668. "address": "0x449188"
  1669.  
  1670.  
  1671. "name": "Sleep",
  1672. "address": "0x44918c"
  1673.  
  1674.  
  1675. "name": "LoadResource",
  1676. "address": "0x449190"
  1677.  
  1678.  
  1679. "name": "WaitForSingleObject",
  1680. "address": "0x449194"
  1681.  
  1682.  
  1683. "name": "SetLastError",
  1684. "address": "0x449198"
  1685.  
  1686.  
  1687. "name": "GetLastError",
  1688. "address": "0x44919c"
  1689.  
  1690.  
  1691. "name": "VirtualAlloc",
  1692. "address": "0x4491a0"
  1693.  
  1694.  
  1695. "name": "LockResource",
  1696. "address": "0x4491a4"
  1697.  
  1698.  
  1699. "name": "FreeResource",
  1700. "address": "0x4491a8"
  1701.  
  1702.  
  1703. "name": "GetTempFileNameA",
  1704. "address": "0x4491ac"
  1705.  
  1706.  
  1707. "name": "InterlockedIncrement",
  1708. "address": "0x4491b0"
  1709.  
  1710.  
  1711. "name": "EncodePointer",
  1712. "address": "0x4491b4"
  1713.  
  1714.  
  1715. "name": "DecodePointer",
  1716. "address": "0x4491b8"
  1717.  
  1718.  
  1719. "name": "InterlockedDecrement",
  1720. "address": "0x4491bc"
  1721.  
  1722.  
  1723. "name": "ExitProcess",
  1724. "address": "0x4491c0"
  1725.  
  1726.  
  1727. "name": "GetModuleHandleExW",
  1728. "address": "0x4491c4"
  1729.  
  1730.  
  1731. "name": "GetProcAddress",
  1732. "address": "0x4491c8"
  1733.  
  1734.  
  1735. "name": "AreFileApisANSI",
  1736. "address": "0x4491cc"
  1737.  
  1738.  
  1739. "name": "MultiByteToWideChar",
  1740. "address": "0x4491d0"
  1741.  
  1742.  
  1743. "name": "RaiseException",
  1744. "address": "0x4491d4"
  1745.  
  1746.  
  1747. "name": "RtlUnwind",
  1748. "address": "0x4491d8"
  1749.  
  1750.  
  1751. "name": "GetStdHandle",
  1752. "address": "0x4491dc"
  1753.  
  1754.  
  1755. "name": "GetFileType",
  1756. "address": "0x4491e0"
  1757.  
  1758.  
  1759. "name": "GetModuleFileNameW",
  1760. "address": "0x4491e4"
  1761.  
  1762.  
  1763. "name": "WriteConsoleW",
  1764. "address": "0x4491e8"
  1765.  
  1766.  
  1767. "name": "GetCommandLineA",
  1768. "address": "0x4491ec"
  1769.  
  1770.  
  1771. "name": "WriteFile",
  1772. "address": "0x4491f0"
  1773.  
  1774.  
  1775. "name": "IsProcessorFeaturePresent",
  1776. "address": "0x4491f4"
  1777.  
  1778.  
  1779. "name": "HeapAlloc",
  1780. "address": "0x4491f8"
  1781.  
  1782.  
  1783. "name": "HeapFree",
  1784. "address": "0x4491fc"
  1785.  
  1786.  
  1787. "name": "IsDebuggerPresent",
  1788. "address": "0x449200"
  1789.  
  1790.  
  1791. "name": "EnterCriticalSection",
  1792. "address": "0x449204"
  1793.  
  1794.  
  1795. "name": "LeaveCriticalSection",
  1796. "address": "0x449208"
  1797.  
  1798.  
  1799. "name": "InitializeCriticalSectionAndSpinCount",
  1800. "address": "0x44920c"
  1801.  
  1802.  
  1803. "name": "WideCharToMultiByte",
  1804. "address": "0x449210"
  1805.  
  1806.  
  1807. "name": "GetConsoleCP",
  1808. "address": "0x449214"
  1809.  
  1810.  
  1811. "name": "GetConsoleMode",
  1812. "address": "0x449218"
  1813.  
  1814.  
  1815. "name": "HeapSize",
  1816. "address": "0x44921c"
  1817.  
  1818.  
  1819. "name": "SetEnvironmentVariableA",
  1820. "address": "0x449220"
  1821.  
  1822. ,
  1823. "dll": "KERNEL32.dll"
  1824.  
  1825.  
  1826. "imports":
  1827.  
  1828. "name": "SetMenu",
  1829. "address": "0x449234"
  1830.  
  1831.  
  1832. "name": "GetMessageA",
  1833. "address": "0x449238"
  1834.  
  1835.  
  1836. "name": "TranslateMessage",
  1837. "address": "0x44923c"
  1838.  
  1839.  
  1840. "name": "GetWindowInfo",
  1841. "address": "0x449240"
  1842.  
  1843.  
  1844. "name": "SetWindowLongA",
  1845. "address": "0x449244"
  1846.  
  1847.  
  1848. "name": "AdjustWindowRectEx",
  1849. "address": "0x449248"
  1850.  
  1851.  
  1852. "name": "MoveWindow",
  1853. "address": "0x44924c"
  1854.  
  1855.  
  1856. "name": "CreateWindowExA",
  1857. "address": "0x449250"
  1858.  
  1859.  
  1860. "name": "LoadImageA",
  1861. "address": "0x449254"
  1862.  
  1863.  
  1864. "name": "LoadCursorA",
  1865. "address": "0x449258"
  1866.  
  1867.  
  1868. "name": "LoadBitmapA",
  1869. "address": "0x44925c"
  1870.  
  1871.  
  1872. "name": "UnhookWindowsHookEx",
  1873. "address": "0x449260"
  1874.  
  1875.  
  1876. "name": "GetParent",
  1877. "address": "0x449264"
  1878.  
  1879.  
  1880. "name": "GetWindowLongA",
  1881. "address": "0x449268"
  1882.  
  1883.  
  1884. "name": "MapWindowPoints",
  1885. "address": "0x44926c"
  1886.  
  1887.  
  1888. "name": "GetCursorPos",
  1889. "address": "0x449270"
  1890.  
  1891.  
  1892. "name": "MessageBoxA",
  1893. "address": "0x449274"
  1894.  
  1895.  
  1896. "name": "GetWindowRect",
  1897. "address": "0x449278"
  1898.  
  1899.  
  1900. "name": "EndPaint",
  1901. "address": "0x44927c"
  1902.  
  1903.  
  1904. "name": "BeginPaint",
  1905. "address": "0x449280"
  1906.  
  1907.  
  1908. "name": "SetForegroundWindow",
  1909. "address": "0x449284"
  1910.  
  1911.  
  1912. "name": "DrawTextExW",
  1913. "address": "0x449288"
  1914.  
  1915.  
  1916. "name": "DrawTextA",
  1917. "address": "0x44928c"
  1918.  
  1919.  
  1920. "name": "DispatchMessageA",
  1921. "address": "0x449290"
  1922.  
  1923.  
  1924. "name": "GetSystemMenu",
  1925. "address": "0x449294"
  1926.  
  1927.  
  1928. "name": "AppendMenuA",
  1929. "address": "0x449298"
  1930.  
  1931.  
  1932. "name": "GetSystemMetrics",
  1933. "address": "0x44929c"
  1934.  
  1935.  
  1936. "name": "CreateAcceleratorTableA",
  1937. "address": "0x4492a0"
  1938.  
  1939.  
  1940. "name": "GetDlgItem",
  1941. "address": "0x4492a4"
  1942.  
  1943.  
  1944. "name": "DestroyWindow",
  1945. "address": "0x4492a8"
  1946.  
  1947.  
  1948. "name": "DefWindowProcA",
  1949. "address": "0x4492ac"
  1950.  
  1951.  
  1952. "name": "AttachThreadInput",
  1953. "address": "0x4492b0"
  1954.  
  1955.  
  1956. "name": "SendMessageA",
  1957. "address": "0x4492b4"
  1958.  
  1959.  
  1960. "name": "DrawFrameControl",
  1961. "address": "0x4492b8"
  1962.  
  1963.  
  1964. "name": "GetClientRect",
  1965. "address": "0x4492bc"
  1966.  
  1967.  
  1968. "name": "InvalidateRect",
  1969. "address": "0x4492c0"
  1970.  
  1971.  
  1972. "name": "ReleaseDC",
  1973. "address": "0x4492c4"
  1974.  
  1975.  
  1976. "name": "GetDC",
  1977. "address": "0x4492c8"
  1978.  
  1979.  
  1980. "name": "UpdateWindow",
  1981. "address": "0x4492cc"
  1982.  
  1983.  
  1984. "name": "KillTimer",
  1985. "address": "0x4492d0"
  1986.  
  1987.  
  1988. "name": "SetTimer",
  1989. "address": "0x4492d4"
  1990.  
  1991.  
  1992. "name": "GetKeyState",
  1993. "address": "0x4492d8"
  1994.  
  1995.  
  1996. "name": "SetFocus",
  1997. "address": "0x4492dc"
  1998.  
  1999.  
  2000. "name": "SetWindowPos",
  2001. "address": "0x4492e0"
  2002.  
  2003.  
  2004. "name": "ShowWindow",
  2005. "address": "0x4492e4"
  2006.  
  2007.  
  2008. "name": "RegisterClassA",
  2009. "address": "0x4492e8"
  2010.  
  2011.  
  2012. "name": "PostQuitMessage",
  2013. "address": "0x4492ec"
  2014.  
  2015. ,
  2016. "dll": "USER32.dll"
  2017.  
  2018.  
  2019. "imports":
  2020.  
  2021. "name": "SetWindowExtEx",
  2022. "address": "0x449034"
  2023.  
  2024.  
  2025. "name": "TextOutA",
  2026. "address": "0x449038"
  2027.  
  2028.  
  2029. "name": "MoveToEx",
  2030. "address": "0x44903c"
  2031.  
  2032.  
  2033. "name": "GetObjectA",
  2034. "address": "0x449040"
  2035.  
  2036.  
  2037. "name": "BeginPath",
  2038. "address": "0x449044"
  2039.  
  2040.  
  2041. "name": "GetTextMetricsA",
  2042. "address": "0x449048"
  2043.  
  2044.  
  2045. "name": "SetTextJustification",
  2046. "address": "0x44904c"
  2047.  
  2048.  
  2049. "name": "SetTextColor",
  2050. "address": "0x449050"
  2051.  
  2052.  
  2053. "name": "SetPixel",
  2054. "address": "0x449054"
  2055.  
  2056.  
  2057. "name": "SetMapMode",
  2058. "address": "0x449058"
  2059.  
  2060.  
  2061. "name": "SetBkMode",
  2062. "address": "0x44905c"
  2063.  
  2064.  
  2065. "name": "SetBkColor",
  2066. "address": "0x449060"
  2067.  
  2068.  
  2069. "name": "Rectangle",
  2070. "address": "0x449064"
  2071.  
  2072.  
  2073. "name": "LineDDA",
  2074. "address": "0x449068"
  2075.  
  2076.  
  2077. "name": "GetMapMode",
  2078. "address": "0x44906c"
  2079.  
  2080.  
  2081. "name": "GetCurrentObject",
  2082. "address": "0x449070"
  2083.  
  2084.  
  2085. "name": "GetROP2",
  2086. "address": "0x449074"
  2087.  
  2088.  
  2089. "name": "CreateSolidBrush",
  2090. "address": "0x449078"
  2091.  
  2092.  
  2093. "name": "CreatePatternBrush",
  2094. "address": "0x44907c"
  2095.  
  2096.  
  2097. "name": "CreatePen",
  2098. "address": "0x449080"
  2099.  
  2100.  
  2101. "name": "CreateFontA",
  2102. "address": "0x449084"
  2103.  
  2104.  
  2105. "name": "CreateFontIndirectA",
  2106. "address": "0x449088"
  2107.  
  2108.  
  2109. "name": "CreateEllipticRgn",
  2110. "address": "0x44908c"
  2111.  
  2112.  
  2113. "name": "SelectObject",
  2114. "address": "0x449090"
  2115.  
  2116.  
  2117. "name": "DeleteObject",
  2118. "address": "0x449094"
  2119.  
  2120.  
  2121. "name": "DeleteDC",
  2122. "address": "0x449098"
  2123.  
  2124.  
  2125. "name": "CreateCompatibleDC",
  2126. "address": "0x44909c"
  2127.  
  2128.  
  2129. "name": "CreateCompatibleBitmap",
  2130. "address": "0x4490a0"
  2131.  
  2132.  
  2133. "name": "BitBlt",
  2134. "address": "0x4490a4"
  2135.  
  2136.  
  2137. "name": "GetDeviceCaps",
  2138. "address": "0x4490a8"
  2139.  
  2140. ,
  2141. "dll": "GDI32.dll"
  2142.  
  2143.  
  2144. "imports":
  2145.  
  2146. "name": "CryptReleaseContext",
  2147. "address": "0x449000"
  2148.  
  2149.  
  2150. "name": "CryptGetProvParam",
  2151. "address": "0x449004"
  2152.  
  2153.  
  2154. "name": "CryptAcquireContextA",
  2155. "address": "0x449008"
  2156.  
  2157. ,
  2158. "dll": "ADVAPI32.dll"
  2159.  
  2160.  
  2161. "imports":
  2162.  
  2163. "name": "CoInitialize",
  2164. "address": "0x4492f4"
  2165.  
  2166.  
  2167. "name": "CoUninitialize",
  2168. "address": "0x4492f8"
  2169.  
  2170.  
  2171. "name": "CreateStreamOnHGlobal",
  2172. "address": "0x4492fc"
  2173.  
  2174. ,
  2175. "dll": "ole32.dll"
  2176.  
  2177.  
  2178. "imports":
  2179.  
  2180. "name": "OleLoadPicture",
  2181. "address": "0x449228"
  2182.  
  2183.  
  2184. "name": "OleSavePictureFile",
  2185. "address": "0x44922c"
  2186.  
  2187. ,
  2188. "dll": "OLEAUT32.dll"
  2189.  
  2190.  
  2191. "imports":
  2192.  
  2193. "name": "CertGetNameStringA",
  2194. "address": "0x44901c"
  2195.  
  2196. ,
  2197. "dll": "CRYPT32.dll"
  2198.  
  2199.  
  2200. "imports":
  2201.  
  2202. "name": "ImageList_Create",
  2203. "address": "0x449010"
  2204.  
  2205.  
  2206. "name": null,
  2207. "address": "0x449014"
  2208.  
  2209. ,
  2210. "dll": "COMCTL32.dll"
  2211.  
  2212.  
  2213. "imports":
  2214.  
  2215. "name": "GetWindowRegionData",
  2216. "address": "0x449024"
  2217.  
  2218.  
  2219. "name": "GetDCRegionData",
  2220. "address": "0x449028"
  2221.  
  2222.  
  2223. "name": "DCISetSrcDestClip",
  2224. "address": "0x44902c"
  2225.  
  2226. ,
  2227. "dll": "DCIMAN32.dll"
  2228.  
  2229. ,
  2230. "digital_signers": null,
  2231. "exported_dll_name": null,
  2232. "actual_checksum": "0x000c3853",
  2233. "overlay": null,
  2234. "imagebase": "0x00400000",
  2235. "reported_checksum": "0x000c3853",
  2236. "icon_hash": null,
  2237. "entrypoint": "0x00408297",
  2238. "timestamp": "2019-07-04 21:07:05",
  2239. "osversion": "6.0",
  2240. "sections":
  2241.  
  2242. "name": ".text",
  2243. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
  2244. "virtual_address": "0x00001000",
  2245. "size_of_data": "0x00047a00",
  2246. "entropy": "6.68",
  2247. "raw_address": "0x00000400",
  2248. "virtual_size": "0x00047895",
  2249. "characteristics_raw": "0x60000020"
  2250.  
  2251.  
  2252. "name": ".rdata",
  2253. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  2254. "virtual_address": "0x00049000",
  2255. "size_of_data": "0x00030a00",
  2256. "entropy": "4.70",
  2257. "raw_address": "0x00047e00",
  2258. "virtual_size": "0x00030922",
  2259. "characteristics_raw": "0x40000040"
  2260.  
  2261.  
  2262. "name": ".data",
  2263. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  2264. "virtual_address": "0x0007a000",
  2265. "size_of_data": "0x00001c00",
  2266. "entropy": "4.54",
  2267. "raw_address": "0x00078800",
  2268. "virtual_size": "0x000049f8",
  2269. "characteristics_raw": "0xc0000040"
  2270.  
  2271.  
  2272. "name": ".rsrc",
  2273. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  2274. "virtual_address": "0x0007f000",
  2275. "size_of_data": "0x00039c00",
  2276. "entropy": "7.32",
  2277. "raw_address": "0x0007a400",
  2278. "virtual_size": "0x00039b0c",
  2279. "characteristics_raw": "0x40000040"
  2280.  
  2281. ,
  2282. "resources": ,
  2283. "dirents":
  2284.  
  2285. "virtual_address": "0x00000000",
  2286. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  2287. "size": "0x00000000"
  2288.  
  2289.  
  2290. "virtual_address": "0x000788a4",
  2291. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  2292. "size": "0x000000c8"
  2293.  
  2294.  
  2295. "virtual_address": "0x0007f000",
  2296. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  2297. "size": "0x00039b0c"
  2298.  
  2299.  
  2300. "virtual_address": "0x00000000",
  2301. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  2302. "size": "0x00000000"
  2303.  
  2304.  
  2305. "virtual_address": "0x00000000",
  2306. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  2307. "size": "0x00000000"
  2308.  
  2309.  
  2310. "virtual_address": "0x00000000",
  2311. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  2312. "size": "0x00000000"
  2313.  
  2314.  
  2315. "virtual_address": "0x00049360",
  2316. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  2317. "size": "0x00000038"
  2318.  
  2319.  
  2320. "virtual_address": "0x00000000",
  2321. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  2322. "size": "0x00000000"
  2323.  
  2324.  
  2325. "virtual_address": "0x00000000",
  2326. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  2327. "size": "0x00000000"
  2328.  
  2329.  
  2330. "virtual_address": "0x00000000",
  2331. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  2332. "size": "0x00000000"
  2333.  
  2334.  
  2335. "virtual_address": "0x00077c00",
  2336. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  2337. "size": "0x00000040"
  2338.  
  2339.  
  2340. "virtual_address": "0x00000000",
  2341. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  2342. "size": "0x00000000"
  2343.  
  2344.  
  2345. "virtual_address": "0x00049000",
  2346. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  2347. "size": "0x00000304"
  2348.  
  2349.  
  2350. "virtual_address": "0x00000000",
  2351. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  2352. "size": "0x00000000"
  2353.  
  2354.  
  2355. "virtual_address": "0x00000000",
  2356. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  2357. "size": "0x00000000"
  2358.  
  2359.  
  2360. "virtual_address": "0x00000000",
  2361. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  2362. "size": "0x00000000"
  2363.  
  2364. ,
  2365. "exports": ,
  2366. "guest_signers":
  2367. "imphash": "8b6d3d6285ec33cbfedbed016e4280f6",
  2368. "icon_fuzzy": null,
  2369. "icon": null,
  2370. "pdbpath": "C:\\Ins\\ad\\IFRA\\Release\\black.pdb",
  2371. "imported_dll_count": 9,
  2372. "versioninfo":
Advertisement
Add Comment
Please, Sign In to add comment