Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: "Zpevdo"
- [*] MalScore: 10.0
- [*] File Name: "bpxssh.exe"
- [*] File Size: 411648
- [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- [*] SHA256: "2b6e601265b592e3b0ef36d1935dde61d3f288d37537819e86d287dd5ab41bb1"
- [*] MD5: "a58831e6442b94e9de7b8c5f1c2e3227"
- [*] SHA1: "b8ed2f2a3471134e9200ffd750998b43d3a4b41d"
- [*] SHA512: "ff3610ff7e2e4de9232b307f7fb441d9be48fbeb85e5c1b551eae25da2b5c27583797a0c64c9a18806c69ac001c39c78b95ea2e2b1762f7833ccd3c0922b0a79"
- [*] CRC32: "3770A46F"
- [*] SSDEEP: "6144:UITQ/KBP1PdBo6bj2uVAcNc9w5bjeo3+PmoEtcXod6/x9kPdioaKhsK1zHmdBFv:zk/KBPFdBV2Hn9AulGt0tUPIkmBB"
- [*] Process Execution: [
- "bpxssh.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "Creates RWX memory",
- "Details": []
- },
- {
- "Description": "Checks for the presence of known windows from debuggers and forensic tools",
- "Details": [
- {
- "Window": "TfrmMain"
- }
- ]
- },
- {
- "Description": "File has been identified by 24 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "MicroWorld-eScan": "Gen:Variant.Graftor.611876"
- },
- {
- "ALYac": "Gen:Variant.Graftor.611876"
- },
- {
- "CrowdStrike": "win/malicious_confidence_60% (W)"
- },
- {
- "BitDefender": "Gen:Variant.Graftor.611876"
- },
- {
- "Arcabit": "Trojan.Graftor.D95624"
- },
- {
- "ESET-NOD32": "a variant of Win32/Injector.EGFN"
- },
- {
- "Avast": "Win32:Trojan-gen"
- },
- {
- "Ad-Aware": "Gen:Variant.Graftor.611876"
- },
- {
- "F-Secure": "Trojan.TR/Injector.hjqwr"
- },
- {
- "McAfee-GW-Edition": "BehavesLike.Win32.Worm.gh"
- },
- {
- "FireEye": "Generic.mg.a58831e6442b94e9"
- },
- {
- "Emsisoft": "Gen:Variant.Graftor.611876 (B)"
- },
- {
- "Microsoft": "Trojan:Win32/Zpevdo.B"
- },
- {
- "AegisLab": "Trojan.Win32.Graftor.4!c"
- },
- {
- "GData": "Gen:Variant.Graftor.611876"
- },
- {
- "AhnLab-V3": "Trojan/Win32.Agent.C3299124"
- },
- {
- "McAfee": "RDN/Generic.grp"
- },
- {
- "TACHYON": "Trojan/W32.DP-Agent.411648.AB"
- },
- {
- "Cylance": "Unsafe"
- },
- {
- "Tencent": "Win32.Backdoor.Remcos.Auto"
- },
- {
- "Ikarus": "Trojan.Win32.Injector"
- },
- {
- "Fortinet": "W32/Injector.DOUH!tr"
- },
- {
- "AVG": "Win32:Trojan-gen"
- },
- {
- "Panda": "Trj/GdSda.A"
- }
- ]
- },
- {
- "Description": "Anomalous binary characteristics",
- "Details": [
- {
- "anomaly": "Timestamp on binary predates the release date of the OS version it requires by at least a year"
- }
- ]
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: []
- [*] Mutexes: []
- [*] Modified Files: []
- [*] Deleted Files: []
- [*] Modified Registry Keys: []
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DeleteCriticalSection",
- "address": "0x45b118"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x45b11c"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x45b120"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x45b124"
- },
- {
- "name": "VirtualFree",
- "address": "0x45b128"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x45b12c"
- },
- {
- "name": "LocalFree",
- "address": "0x45b130"
- },
- {
- "name": "LocalAlloc",
- "address": "0x45b134"
- },
- {
- "name": "GetVersion",
- "address": "0x45b138"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x45b13c"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x45b140"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x45b144"
- },
- {
- "name": "VirtualQuery",
- "address": "0x45b148"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x45b14c"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x45b150"
- },
- {
- "name": "lstrlenA",
- "address": "0x45b154"
- },
- {
- "name": "lstrcpynA",
- "address": "0x45b158"
- },
- {
- "name": "LoadLibraryExA",
- "address": "0x45b15c"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x45b160"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x45b164"
- },
- {
- "name": "GetProcAddress",
- "address": "0x45b168"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x45b16c"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x45b170"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x45b174"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x45b178"
- },
- {
- "name": "FreeLibrary",
- "address": "0x45b17c"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x45b180"
- },
- {
- "name": "FindClose",
- "address": "0x45b184"
- },
- {
- "name": "ExitProcess",
- "address": "0x45b188"
- },
- {
- "name": "WriteFile",
- "address": "0x45b18c"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x45b190"
- },
- {
- "name": "RtlUnwind",
- "address": "0x45b194"
- },
- {
- "name": "RaiseException",
- "address": "0x45b198"
- },
- {
- "name": "GetStdHandle",
- "address": "0x45b19c"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "GetKeyboardType",
- "address": "0x45b1a4"
- },
- {
- "name": "LoadStringA",
- "address": "0x45b1a8"
- },
- {
- "name": "MessageBoxA",
- "address": "0x45b1ac"
- },
- {
- "name": "CharNextA",
- "address": "0x45b1b0"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x45b1b8"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x45b1bc"
- },
- {
- "name": "RegCloseKey",
- "address": "0x45b1c0"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "SysFreeString",
- "address": "0x45b1c8"
- },
- {
- "name": "SysReAllocStringLen",
- "address": "0x45b1cc"
- },
- {
- "name": "SysAllocStringLen",
- "address": "0x45b1d0"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "TlsSetValue",
- "address": "0x45b1d8"
- },
- {
- "name": "TlsGetValue",
- "address": "0x45b1dc"
- },
- {
- "name": "LocalAlloc",
- "address": "0x45b1e0"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x45b1e4"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x45b1ec"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x45b1f0"
- },
- {
- "name": "RegCloseKey",
- "address": "0x45b1f4"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "lstrcpyA",
- "address": "0x45b1fc"
- },
- {
- "name": "WriteFile",
- "address": "0x45b200"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x45b204"
- },
- {
- "name": "VirtualQuery",
- "address": "0x45b208"
- },
- {
- "name": "VirtualProtect",
- "address": "0x45b20c"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x45b210"
- },
- {
- "name": "Sleep",
- "address": "0x45b214"
- },
- {
- "name": "SizeofResource",
- "address": "0x45b218"
- },
- {
- "name": "SetThreadLocale",
- "address": "0x45b21c"
- },
- {
- "name": "SetFilePointer",
- "address": "0x45b220"
- },
- {
- "name": "SetEvent",
- "address": "0x45b224"
- },
- {
- "name": "SetErrorMode",
- "address": "0x45b228"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x45b22c"
- },
- {
- "name": "ResetEvent",
- "address": "0x45b230"
- },
- {
- "name": "ReadFile",
- "address": "0x45b234"
- },
- {
- "name": "MulDiv",
- "address": "0x45b238"
- },
- {
- "name": "LockResource",
- "address": "0x45b23c"
- },
- {
- "name": "LoadResource",
- "address": "0x45b240"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x45b244"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x45b248"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x45b24c"
- },
- {
- "name": "GlobalUnlock",
- "address": "0x45b250"
- },
- {
- "name": "GlobalReAlloc",
- "address": "0x45b254"
- },
- {
- "name": "GlobalMemoryStatus",
- "address": "0x45b258"
- },
- {
- "name": "GlobalHandle",
- "address": "0x45b25c"
- },
- {
- "name": "GlobalLock",
- "address": "0x45b260"
- },
- {
- "name": "GlobalFree",
- "address": "0x45b264"
- },
- {
- "name": "GlobalFindAtomA",
- "address": "0x45b268"
- },
- {
- "name": "GlobalDeleteAtom",
- "address": "0x45b26c"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x45b270"
- },
- {
- "name": "GlobalAddAtomA",
- "address": "0x45b274"
- },
- {
- "name": "GetVersionExA",
- "address": "0x45b278"
- },
- {
- "name": "GetVersion",
- "address": "0x45b27c"
- },
- {
- "name": "GetTickCount",
- "address": "0x45b280"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x45b284"
- },
- {
- "name": "GetTempPathA",
- "address": "0x45b288"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x45b28c"
- },
- {
- "name": "GetStringTypeExA",
- "address": "0x45b290"
- },
- {
- "name": "GetStdHandle",
- "address": "0x45b294"
- },
- {
- "name": "GetProcAddress",
- "address": "0x45b298"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x45b29c"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x45b2a0"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x45b2a4"
- },
- {
- "name": "GetLocalTime",
- "address": "0x45b2a8"
- },
- {
- "name": "GetLastError",
- "address": "0x45b2ac"
- },
- {
- "name": "GetFullPathNameA",
- "address": "0x45b2b0"
- },
- {
- "name": "GetDiskFreeSpaceA",
- "address": "0x45b2b4"
- },
- {
- "name": "GetDateFormatA",
- "address": "0x45b2b8"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x45b2bc"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x45b2c0"
- },
- {
- "name": "GetCPInfo",
- "address": "0x45b2c4"
- },
- {
- "name": "GetACP",
- "address": "0x45b2c8"
- },
- {
- "name": "FreeResource",
- "address": "0x45b2cc"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x45b2d0"
- },
- {
- "name": "FreeLibrary",
- "address": "0x45b2d4"
- },
- {
- "name": "FormatMessageA",
- "address": "0x45b2d8"
- },
- {
- "name": "FindResourceA",
- "address": "0x45b2dc"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x45b2e0"
- },
- {
- "name": "FindClose",
- "address": "0x45b2e4"
- },
- {
- "name": "FileTimeToLocalFileTime",
- "address": "0x45b2e8"
- },
- {
- "name": "FileTimeToDosDateTime",
- "address": "0x45b2ec"
- },
- {
- "name": "ExitProcess",
- "address": "0x45b2f0"
- },
- {
- "name": "EnumCalendarInfoA",
- "address": "0x45b2f4"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x45b2f8"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x45b2fc"
- },
- {
- "name": "CreateThread",
- "address": "0x45b300"
- },
- {
- "name": "CreateFileA",
- "address": "0x45b304"
- },
- {
- "name": "CreateEventA",
- "address": "0x45b308"
- },
- {
- "name": "CompareStringA",
- "address": "0x45b30c"
- },
- {
- "name": "CloseHandle",
- "address": "0x45b310"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "VerQueryValueA",
- "address": "0x45b318"
- },
- {
- "name": "GetFileVersionInfoSizeA",
- "address": "0x45b31c"
- },
- {
- "name": "GetFileVersionInfoA",
- "address": "0x45b320"
- }
- ],
- "dll": "version.dll"
- },
- {
- "imports": [
- {
- "name": "UnrealizeObject",
- "address": "0x45b328"
- },
- {
- "name": "StretchBlt",
- "address": "0x45b32c"
- },
- {
- "name": "SetWindowOrgEx",
- "address": "0x45b330"
- },
- {
- "name": "SetViewportOrgEx",
- "address": "0x45b334"
- },
- {
- "name": "SetTextColor",
- "address": "0x45b338"
- },
- {
- "name": "SetStretchBltMode",
- "address": "0x45b33c"
- },
- {
- "name": "SetROP2",
- "address": "0x45b340"
- },
- {
- "name": "SetPixel",
- "address": "0x45b344"
- },
- {
- "name": "SetDIBColorTable",
- "address": "0x45b348"
- },
- {
- "name": "SetBrushOrgEx",
- "address": "0x45b34c"
- },
- {
- "name": "SetBkMode",
- "address": "0x45b350"
- },
- {
- "name": "SetBkColor",
- "address": "0x45b354"
- },
- {
- "name": "SelectPalette",
- "address": "0x45b358"
- },
- {
- "name": "SelectObject",
- "address": "0x45b35c"
- },
- {
- "name": "SaveDC",
- "address": "0x45b360"
- },
- {
- "name": "RestoreDC",
- "address": "0x45b364"
- },
- {
- "name": "RectVisible",
- "address": "0x45b368"
- },
- {
- "name": "RealizePalette",
- "address": "0x45b36c"
- },
- {
- "name": "Polyline",
- "address": "0x45b370"
- },
- {
- "name": "Pie",
- "address": "0x45b374"
- },
- {
- "name": "PatBlt",
- "address": "0x45b378"
- },
- {
- "name": "MoveToEx",
- "address": "0x45b37c"
- },
- {
- "name": "MaskBlt",
- "address": "0x45b380"
- },
- {
- "name": "LineTo",
- "address": "0x45b384"
- },
- {
- "name": "IntersectClipRect",
- "address": "0x45b388"
- },
- {
- "name": "GetWindowOrgEx",
- "address": "0x45b38c"
- },
- {
- "name": "GetTextMetricsA",
- "address": "0x45b390"
- },
- {
- "name": "GetTextExtentPoint32A",
- "address": "0x45b394"
- },
- {
- "name": "GetTextAlign",
- "address": "0x45b398"
- },
- {
- "name": "GetSystemPaletteEntries",
- "address": "0x45b39c"
- },
- {
- "name": "GetStockObject",
- "address": "0x45b3a0"
- },
- {
- "name": "GetPixel",
- "address": "0x45b3a4"
- },
- {
- "name": "GetPaletteEntries",
- "address": "0x45b3a8"
- },
- {
- "name": "GetObjectA",
- "address": "0x45b3ac"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x45b3b0"
- },
- {
- "name": "GetDIBits",
- "address": "0x45b3b4"
- },
- {
- "name": "GetDIBColorTable",
- "address": "0x45b3b8"
- },
- {
- "name": "GetDCOrgEx",
- "address": "0x45b3bc"
- },
- {
- "name": "GetDCPenColor",
- "address": "0x45b3c0"
- },
- {
- "name": "GetDCBrushColor",
- "address": "0x45b3c4"
- },
- {
- "name": "GetCurrentPositionEx",
- "address": "0x45b3c8"
- },
- {
- "name": "GetClipBox",
- "address": "0x45b3cc"
- },
- {
- "name": "GetBrushOrgEx",
- "address": "0x45b3d0"
- },
- {
- "name": "GetBitmapBits",
- "address": "0x45b3d4"
- },
- {
- "name": "ExtTextOutA",
- "address": "0x45b3d8"
- },
- {
- "name": "ExcludeClipRect",
- "address": "0x45b3dc"
- },
- {
- "name": "Ellipse",
- "address": "0x45b3e0"
- },
- {
- "name": "DeleteObject",
- "address": "0x45b3e4"
- },
- {
- "name": "DeleteDC",
- "address": "0x45b3e8"
- },
- {
- "name": "CreateSolidBrush",
- "address": "0x45b3ec"
- },
- {
- "name": "CreatePenIndirect",
- "address": "0x45b3f0"
- },
- {
- "name": "CreatePalette",
- "address": "0x45b3f4"
- },
- {
- "name": "CreateHalftonePalette",
- "address": "0x45b3f8"
- },
- {
- "name": "CreateFontIndirectA",
- "address": "0x45b3fc"
- },
- {
- "name": "CreateDIBitmap",
- "address": "0x45b400"
- },
- {
- "name": "CreateDIBSection",
- "address": "0x45b404"
- },
- {
- "name": "CreateCompatibleDC",
- "address": "0x45b408"
- },
- {
- "name": "CreateCompatibleBitmap",
- "address": "0x45b40c"
- },
- {
- "name": "CreateBrushIndirect",
- "address": "0x45b410"
- },
- {
- "name": "CreateBitmap",
- "address": "0x45b414"
- },
- {
- "name": "BitBlt",
- "address": "0x45b418"
- }
- ],
- "dll": "gdi32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateWindowExA",
- "address": "0x45b420"
- },
- {
- "name": "WindowFromPoint",
- "address": "0x45b424"
- },
- {
- "name": "WinHelpA",
- "address": "0x45b428"
- },
- {
- "name": "WaitMessage",
- "address": "0x45b42c"
- },
- {
- "name": "UpdateWindow",
- "address": "0x45b430"
- },
- {
- "name": "UnregisterClassA",
- "address": "0x45b434"
- },
- {
- "name": "UnhookWindowsHookEx",
- "address": "0x45b438"
- },
- {
- "name": "TranslateMessage",
- "address": "0x45b43c"
- },
- {
- "name": "TranslateMDISysAccel",
- "address": "0x45b440"
- },
- {
- "name": "TrackPopupMenu",
- "address": "0x45b444"
- },
- {
- "name": "SystemParametersInfoA",
- "address": "0x45b448"
- },
- {
- "name": "ShowWindow",
- "address": "0x45b44c"
- },
- {
- "name": "ShowScrollBar",
- "address": "0x45b450"
- },
- {
- "name": "ShowOwnedPopups",
- "address": "0x45b454"
- },
- {
- "name": "ShowCursor",
- "address": "0x45b458"
- },
- {
- "name": "SetWindowsHookExA",
- "address": "0x45b45c"
- },
- {
- "name": "SetWindowTextA",
- "address": "0x45b460"
- },
- {
- "name": "SetWindowPos",
- "address": "0x45b464"
- },
- {
- "name": "SetWindowPlacement",
- "address": "0x45b468"
- },
- {
- "name": "SetWindowLongA",
- "address": "0x45b46c"
- },
- {
- "name": "SetTimer",
- "address": "0x45b470"
- },
- {
- "name": "SetScrollRange",
- "address": "0x45b474"
- },
- {
- "name": "SetScrollPos",
- "address": "0x45b478"
- },
- {
- "name": "SetScrollInfo",
- "address": "0x45b47c"
- },
- {
- "name": "SetRect",
- "address": "0x45b480"
- },
- {
- "name": "SetPropA",
- "address": "0x45b484"
- },
- {
- "name": "SetParent",
- "address": "0x45b488"
- },
- {
- "name": "SetMenuItemInfoA",
- "address": "0x45b48c"
- },
- {
- "name": "SetMenu",
- "address": "0x45b490"
- },
- {
- "name": "SetForegroundWindow",
- "address": "0x45b494"
- },
- {
- "name": "SetFocus",
- "address": "0x45b498"
- },
- {
- "name": "SetCursor",
- "address": "0x45b49c"
- },
- {
- "name": "SetClassLongA",
- "address": "0x45b4a0"
- },
- {
- "name": "SetCapture",
- "address": "0x45b4a4"
- },
- {
- "name": "SetActiveWindow",
- "address": "0x45b4a8"
- },
- {
- "name": "SendMessageA",
- "address": "0x45b4ac"
- },
- {
- "name": "ScrollWindow",
- "address": "0x45b4b0"
- },
- {
- "name": "ScreenToClient",
- "address": "0x45b4b4"
- },
- {
- "name": "RemovePropA",
- "address": "0x45b4b8"
- },
- {
- "name": "RemoveMenu",
- "address": "0x45b4bc"
- },
- {
- "name": "ReleaseDC",
- "address": "0x45b4c0"
- },
- {
- "name": "ReleaseCapture",
- "address": "0x45b4c4"
- },
- {
- "name": "RegisterWindowMessageA",
- "address": "0x45b4c8"
- },
- {
- "name": "RegisterClipboardFormatA",
- "address": "0x45b4cc"
- },
- {
- "name": "RegisterClassA",
- "address": "0x45b4d0"
- },
- {
- "name": "RedrawWindow",
- "address": "0x45b4d4"
- },
- {
- "name": "PtInRect",
- "address": "0x45b4d8"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x45b4dc"
- },
- {
- "name": "PostMessageA",
- "address": "0x45b4e0"
- },
- {
- "name": "PeekMessageA",
- "address": "0x45b4e4"
- },
- {
- "name": "OffsetRect",
- "address": "0x45b4e8"
- },
- {
- "name": "OemToCharA",
- "address": "0x45b4ec"
- },
- {
- "name": "MessageBoxA",
- "address": "0x45b4f0"
- },
- {
- "name": "MapWindowPoints",
- "address": "0x45b4f4"
- },
- {
- "name": "MapVirtualKeyA",
- "address": "0x45b4f8"
- },
- {
- "name": "LoadStringA",
- "address": "0x45b4fc"
- },
- {
- "name": "LoadKeyboardLayoutA",
- "address": "0x45b500"
- },
- {
- "name": "LoadIconA",
- "address": "0x45b504"
- },
- {
- "name": "LoadCursorA",
- "address": "0x45b508"
- },
- {
- "name": "LoadBitmapA",
- "address": "0x45b50c"
- },
- {
- "name": "KillTimer",
- "address": "0x45b510"
- },
- {
- "name": "IsZoomed",
- "address": "0x45b514"
- },
- {
- "name": "IsWindowVisible",
- "address": "0x45b518"
- },
- {
- "name": "IsWindowEnabled",
- "address": "0x45b51c"
- },
- {
- "name": "IsWindow",
- "address": "0x45b520"
- },
- {
- "name": "IsRectEmpty",
- "address": "0x45b524"
- },
- {
- "name": "IsIconic",
- "address": "0x45b528"
- },
- {
- "name": "IsDialogMessageA",
- "address": "0x45b52c"
- },
- {
- "name": "IsChild",
- "address": "0x45b530"
- },
- {
- "name": "InvalidateRect",
- "address": "0x45b534"
- },
- {
- "name": "IntersectRect",
- "address": "0x45b538"
- },
- {
- "name": "InsertMenuItemA",
- "address": "0x45b53c"
- },
- {
- "name": "InsertMenuA",
- "address": "0x45b540"
- },
- {
- "name": "InflateRect",
- "address": "0x45b544"
- },
- {
- "name": "GetWindowThreadProcessId",
- "address": "0x45b548"
- },
- {
- "name": "GetWindowTextA",
- "address": "0x45b54c"
- },
- {
- "name": "GetWindowRect",
- "address": "0x45b550"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x45b554"
- },
- {
- "name": "GetWindowLongA",
- "address": "0x45b558"
- },
- {
- "name": "GetWindowDC",
- "address": "0x45b55c"
- },
- {
- "name": "GetTopWindow",
- "address": "0x45b560"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x45b564"
- },
- {
- "name": "GetSystemMenu",
- "address": "0x45b568"
- },
- {
- "name": "GetSysColorBrush",
- "address": "0x45b56c"
- },
- {
- "name": "GetSysColor",
- "address": "0x45b570"
- },
- {
- "name": "GetSubMenu",
- "address": "0x45b574"
- },
- {
- "name": "GetScrollRange",
- "address": "0x45b578"
- },
- {
- "name": "GetScrollPos",
- "address": "0x45b57c"
- },
- {
- "name": "GetScrollInfo",
- "address": "0x45b580"
- },
- {
- "name": "GetPropA",
- "address": "0x45b584"
- },
- {
- "name": "GetParent",
- "address": "0x45b588"
- },
- {
- "name": "GetWindow",
- "address": "0x45b58c"
- },
- {
- "name": "GetMenuStringA",
- "address": "0x45b590"
- },
- {
- "name": "GetMenuState",
- "address": "0x45b594"
- },
- {
- "name": "GetMenuItemInfoA",
- "address": "0x45b598"
- },
- {
- "name": "GetMenuItemID",
- "address": "0x45b59c"
- },
- {
- "name": "GetMenuItemCount",
- "address": "0x45b5a0"
- },
- {
- "name": "GetMenu",
- "address": "0x45b5a4"
- },
- {
- "name": "GetLastActivePopup",
- "address": "0x45b5a8"
- },
- {
- "name": "GetKeyboardState",
- "address": "0x45b5ac"
- },
- {
- "name": "GetKeyboardLayoutList",
- "address": "0x45b5b0"
- },
- {
- "name": "GetKeyboardLayout",
- "address": "0x45b5b4"
- },
- {
- "name": "GetKeyState",
- "address": "0x45b5b8"
- },
- {
- "name": "GetKeyNameTextA",
- "address": "0x45b5bc"
- },
- {
- "name": "GetIconInfo",
- "address": "0x45b5c0"
- },
- {
- "name": "GetForegroundWindow",
- "address": "0x45b5c4"
- },
- {
- "name": "GetFocus",
- "address": "0x45b5c8"
- },
- {
- "name": "GetDesktopWindow",
- "address": "0x45b5cc"
- },
- {
- "name": "GetDCEx",
- "address": "0x45b5d0"
- },
- {
- "name": "GetDC",
- "address": "0x45b5d4"
- },
- {
- "name": "GetCursorPos",
- "address": "0x45b5d8"
- },
- {
- "name": "GetCursor",
- "address": "0x45b5dc"
- },
- {
- "name": "GetClientRect",
- "address": "0x45b5e0"
- },
- {
- "name": "GetClassNameA",
- "address": "0x45b5e4"
- },
- {
- "name": "GetClassInfoA",
- "address": "0x45b5e8"
- },
- {
- "name": "GetCapture",
- "address": "0x45b5ec"
- },
- {
- "name": "GetActiveWindow",
- "address": "0x45b5f0"
- },
- {
- "name": "FrameRect",
- "address": "0x45b5f4"
- },
- {
- "name": "FindWindowA",
- "address": "0x45b5f8"
- },
- {
- "name": "FillRect",
- "address": "0x45b5fc"
- },
- {
- "name": "EqualRect",
- "address": "0x45b600"
- },
- {
- "name": "EnumWindows",
- "address": "0x45b604"
- },
- {
- "name": "EnumThreadWindows",
- "address": "0x45b608"
- },
- {
- "name": "EndPaint",
- "address": "0x45b60c"
- },
- {
- "name": "EnableWindow",
- "address": "0x45b610"
- },
- {
- "name": "EnableScrollBar",
- "address": "0x45b614"
- },
- {
- "name": "EnableMenuItem",
- "address": "0x45b618"
- },
- {
- "name": "DrawTextA",
- "address": "0x45b61c"
- },
- {
- "name": "DrawMenuBar",
- "address": "0x45b620"
- },
- {
- "name": "DrawIconEx",
- "address": "0x45b624"
- },
- {
- "name": "DrawIcon",
- "address": "0x45b628"
- },
- {
- "name": "DrawFrameControl",
- "address": "0x45b62c"
- },
- {
- "name": "DrawEdge",
- "address": "0x45b630"
- },
- {
- "name": "DispatchMessageA",
- "address": "0x45b634"
- },
- {
- "name": "DestroyWindow",
- "address": "0x45b638"
- },
- {
- "name": "DestroyMenu",
- "address": "0x45b63c"
- },
- {
- "name": "DestroyIcon",
- "address": "0x45b640"
- },
- {
- "name": "DestroyCursor",
- "address": "0x45b644"
- },
- {
- "name": "DeleteMenu",
- "address": "0x45b648"
- },
- {
- "name": "DefWindowProcA",
- "address": "0x45b64c"
- },
- {
- "name": "DefMDIChildProcA",
- "address": "0x45b650"
- },
- {
- "name": "DefFrameProcA",
- "address": "0x45b654"
- },
- {
- "name": "CreatePopupMenu",
- "address": "0x45b658"
- },
- {
- "name": "CreateMenu",
- "address": "0x45b65c"
- },
- {
- "name": "CreateIcon",
- "address": "0x45b660"
- },
- {
- "name": "ClientToScreen",
- "address": "0x45b664"
- },
- {
- "name": "CheckMenuItem",
- "address": "0x45b668"
- },
- {
- "name": "CallWindowProcA",
- "address": "0x45b66c"
- },
- {
- "name": "CallNextHookEx",
- "address": "0x45b670"
- },
- {
- "name": "BeginPaint",
- "address": "0x45b674"
- },
- {
- "name": "CharNextA",
- "address": "0x45b678"
- },
- {
- "name": "CharLowerA",
- "address": "0x45b67c"
- },
- {
- "name": "CharToOemA",
- "address": "0x45b680"
- },
- {
- "name": "AdjustWindowRectEx",
- "address": "0x45b684"
- },
- {
- "name": "ActivateKeyboardLayout",
- "address": "0x45b688"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "Sleep",
- "address": "0x45b690"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "SafeArrayPtrOfIndex",
- "address": "0x45b698"
- },
- {
- "name": "SafeArrayGetUBound",
- "address": "0x45b69c"
- },
- {
- "name": "SafeArrayGetLBound",
- "address": "0x45b6a0"
- },
- {
- "name": "SafeArrayCreate",
- "address": "0x45b6a4"
- },
- {
- "name": "VariantChangeType",
- "address": "0x45b6a8"
- },
- {
- "name": "VariantCopy",
- "address": "0x45b6ac"
- },
- {
- "name": "VariantClear",
- "address": "0x45b6b0"
- },
- {
- "name": "VariantInit",
- "address": "0x45b6b4"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "ImageList_SetIconSize",
- "address": "0x45b6bc"
- },
- {
- "name": "ImageList_GetIconSize",
- "address": "0x45b6c0"
- },
- {
- "name": "ImageList_Write",
- "address": "0x45b6c4"
- },
- {
- "name": "ImageList_Read",
- "address": "0x45b6c8"
- },
- {
- "name": "ImageList_GetDragImage",
- "address": "0x45b6cc"
- },
- {
- "name": "ImageList_DragShowNolock",
- "address": "0x45b6d0"
- },
- {
- "name": "ImageList_SetDragCursorImage",
- "address": "0x45b6d4"
- },
- {
- "name": "ImageList_DragMove",
- "address": "0x45b6d8"
- },
- {
- "name": "ImageList_DragLeave",
- "address": "0x45b6dc"
- },
- {
- "name": "ImageList_DragEnter",
- "address": "0x45b6e0"
- },
- {
- "name": "ImageList_EndDrag",
- "address": "0x45b6e4"
- },
- {
- "name": "ImageList_BeginDrag",
- "address": "0x45b6e8"
- },
- {
- "name": "ImageList_Remove",
- "address": "0x45b6ec"
- },
- {
- "name": "ImageList_DrawEx",
- "address": "0x45b6f0"
- },
- {
- "name": "ImageList_Draw",
- "address": "0x45b6f4"
- },
- {
- "name": "ImageList_GetBkColor",
- "address": "0x45b6f8"
- },
- {
- "name": "ImageList_SetBkColor",
- "address": "0x45b6fc"
- },
- {
- "name": "ImageList_ReplaceIcon",
- "address": "0x45b700"
- },
- {
- "name": "ImageList_Add",
- "address": "0x45b704"
- },
- {
- "name": "ImageList_SetImageCount",
- "address": "0x45b708"
- },
- {
- "name": "ImageList_GetImageCount",
- "address": "0x45b70c"
- },
- {
- "name": "ImageList_Destroy",
- "address": "0x45b710"
- },
- {
- "name": "ImageList_Create",
- "address": "0x45b714"
- }
- ],
- "dll": "comctl32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x0006f600",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x004571c8",
- "timestamp": "1992-06-19 22:22:17",
- "osversion": "4.0",
- "sections": [
- {
- "name": "CODE",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00056400",
- "entropy": "6.51",
- "raw_address": "0x00000400",
- "virtual_size": "0x0005623c",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": "DATA",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00058000",
- "size_of_data": "0x00001200",
- "entropy": "3.99",
- "raw_address": "0x00056800",
- "virtual_size": "0x0000113c",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": "BSS",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0005a000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00057a00",
- "virtual_size": "0x00000b79",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".idata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0005b000",
- "size_of_data": "0x00002200",
- "entropy": "4.92",
- "raw_address": "0x00057a00",
- "virtual_size": "0x0000208c",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0005e000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00059c00",
- "virtual_size": "0x00000010",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0005f000",
- "size_of_data": "0x00000200",
- "entropy": "0.20",
- "raw_address": "0x00059c00",
- "virtual_size": "0x00000018",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00060000",
- "size_of_data": "0x00006200",
- "entropy": "6.67",
- "raw_address": "0x00059e00",
- "virtual_size": "0x00006198",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00067000",
- "size_of_data": "0x00004800",
- "entropy": "4.38",
- "raw_address": "0x00060000",
- "virtual_size": "0x00004800",
- "characteristics_raw": "0x50000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0005b000",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000208c"
- },
- {
- "virtual_address": "0x00067000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00004800"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00060000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00006198"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0005f000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "3d14c36d144d8e05489ac5489a77dc6d",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 13,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "kernel32.dll.GetDiskFreeSpaceExA",
- "oleaut32.dll.VariantChangeTypeEx",
- "oleaut32.dll.VarNeg",
- "oleaut32.dll.VarNot",
- "oleaut32.dll.VarAdd",
- "oleaut32.dll.VarSub",
- "oleaut32.dll.VarMul",
- "oleaut32.dll.VarDiv",
- "oleaut32.dll.VarIdiv",
- "oleaut32.dll.VarMod",
- "oleaut32.dll.VarAnd",
- "oleaut32.dll.VarOr",
- "oleaut32.dll.VarXor",
- "oleaut32.dll.VarCmp",
- "oleaut32.dll.VarI4FromStr",
- "oleaut32.dll.VarR4FromStr",
- "oleaut32.dll.VarR8FromStr",
- "oleaut32.dll.VarDateFromStr",
- "oleaut32.dll.VarCyFromStr",
- "oleaut32.dll.VarBoolFromStr",
- "oleaut32.dll.VarBstrFromCy",
- "oleaut32.dll.VarBstrFromDate",
- "oleaut32.dll.VarBstrFromBool",
- "user32.dll.GetMonitorInfoA",
- "user32.dll.GetSystemMetrics",
- "user32.dll.EnumDisplayMonitors",
- "dwmapi.dll.DwmIsCompositionEnabled",
- "gdi32.dll.GetLayout",
- "gdi32.dll.GdiRealizationInfo",
- "gdi32.dll.FontIsLinked",
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegQueryInfoKeyW",
- "gdi32.dll.GetTextFaceAliasW",
- "advapi32.dll.RegEnumValueW",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.RegQueryValueExW",
- "gdi32.dll.GetFontAssocStatus",
- "advapi32.dll.RegQueryValueExA",
- "advapi32.dll.RegEnumKeyExW",
- "gdi32.dll.GdiIsMetaPrintDC",
- "user32.dll.AnimateWindow",
- "comctl32.dll.InitializeFlatSB",
- "comctl32.dll.UninitializeFlatSB",
- "comctl32.dll.FlatSB_GetScrollProp",
- "comctl32.dll.FlatSB_SetScrollProp",
- "comctl32.dll.FlatSB_EnableScrollBar",
- "comctl32.dll.FlatSB_ShowScrollBar",
- "comctl32.dll.FlatSB_GetScrollRange",
- "comctl32.dll.FlatSB_GetScrollInfo",
- "comctl32.dll.FlatSB_GetScrollPos",
- "comctl32.dll.FlatSB_SetScrollPos",
- "comctl32.dll.FlatSB_SetScrollInfo",
- "comctl32.dll.FlatSB_SetScrollRange",
- "user32.dll.SetLayeredWindowAttributes",
- "uxtheme.dll.OpenThemeData",
- "uxtheme.dll.CloseThemeData",
- "uxtheme.dll.DrawThemeBackground",
- "uxtheme.dll.DrawThemeText",
- "uxtheme.dll.GetThemeBackgroundContentRect",
- "uxtheme.dll.GetThemePartSize",
- "uxtheme.dll.GetThemeTextExtent",
- "uxtheme.dll.GetThemeTextMetrics",
- "uxtheme.dll.GetThemeBackgroundRegion",
- "uxtheme.dll.HitTestThemeBackground",
- "uxtheme.dll.DrawThemeEdge",
- "uxtheme.dll.DrawThemeIcon",
- "uxtheme.dll.IsThemePartDefined",
- "uxtheme.dll.IsThemeBackgroundPartiallyTransparent",
- "uxtheme.dll.GetThemeColor",
- "uxtheme.dll.GetThemeMetric",
- "uxtheme.dll.GetThemeString",
- "uxtheme.dll.GetThemeBool",
- "uxtheme.dll.GetThemeInt",
- "uxtheme.dll.GetThemeEnumValue",
- "uxtheme.dll.GetThemePosition",
- "uxtheme.dll.GetThemeFont",
- "uxtheme.dll.GetThemeRect",
- "uxtheme.dll.GetThemeMargins",
- "uxtheme.dll.GetThemeIntList",
- "uxtheme.dll.GetThemePropertyOrigin",
- "uxtheme.dll.SetWindowTheme",
- "uxtheme.dll.GetThemeFilename",
- "uxtheme.dll.GetThemeSysColor",
- "uxtheme.dll.GetThemeSysColorBrush",
- "uxtheme.dll.GetThemeSysBool",
- "uxtheme.dll.GetThemeSysSize",
- "uxtheme.dll.GetThemeSysFont",
- "uxtheme.dll.GetThemeSysString",
- "uxtheme.dll.GetThemeSysInt",
- "uxtheme.dll.IsThemeActive",
- "uxtheme.dll.IsAppThemed",
- "uxtheme.dll.GetWindowTheme",
- "uxtheme.dll.EnableThemeDialogTexture",
- "uxtheme.dll.IsThemeDialogTextureEnabled",
- "uxtheme.dll.GetThemeAppProperties",
- "uxtheme.dll.SetThemeAppProperties",
- "uxtheme.dll.GetCurrentThemeName",
- "uxtheme.dll.GetThemeDocumentationProperty",
- "uxtheme.dll.DrawThemeParentBackground",
- "uxtheme.dll.EnableTheming",
- "kernel32.dll.SortGetHandle",
- "kernel32.dll.SortCloseHandle",
- "gdi32.dll.GetTextExtentExPointWPri",
- "lpk.dll.LpkEditControl",
- "comctl32.dll.HIMAGELIST_QueryInterface",
- "comctl32.dll.DrawShadowText",
- "comctl32.dll.DrawSizeBox",
- "comctl32.dll.DrawScrollBar",
- "comctl32.dll.SizeBoxHwnd",
- "comctl32.dll.ScrollBar_MouseMove",
- "comctl32.dll.ScrollBar_Menu",
- "comctl32.dll.HandleScrollCmd",
- "comctl32.dll.DetachScrollBars",
- "comctl32.dll.AttachScrollBars",
- "comctl32.dll.CCSetScrollInfo",
- "comctl32.dll.CCGetScrollInfo",
- "comctl32.dll.CCEnableScrollBar",
- "comctl32.dll.QuerySystemGestureStatus",
- "uxtheme.dll.#49"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DeleteCriticalSection",
- "address": "0x45b118"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x45b11c"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x45b120"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x45b124"
- },
- {
- "name": "VirtualFree",
- "address": "0x45b128"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x45b12c"
- },
- {
- "name": "LocalFree",
- "address": "0x45b130"
- },
- {
- "name": "LocalAlloc",
- "address": "0x45b134"
- },
- {
- "name": "GetVersion",
- "address": "0x45b138"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x45b13c"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x45b140"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x45b144"
- },
- {
- "name": "VirtualQuery",
- "address": "0x45b148"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x45b14c"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x45b150"
- },
- {
- "name": "lstrlenA",
- "address": "0x45b154"
- },
- {
- "name": "lstrcpynA",
- "address": "0x45b158"
- },
- {
- "name": "LoadLibraryExA",
- "address": "0x45b15c"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x45b160"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x45b164"
- },
- {
- "name": "GetProcAddress",
- "address": "0x45b168"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x45b16c"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x45b170"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x45b174"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x45b178"
- },
- {
- "name": "FreeLibrary",
- "address": "0x45b17c"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x45b180"
- },
- {
- "name": "FindClose",
- "address": "0x45b184"
- },
- {
- "name": "ExitProcess",
- "address": "0x45b188"
- },
- {
- "name": "WriteFile",
- "address": "0x45b18c"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x45b190"
- },
- {
- "name": "RtlUnwind",
- "address": "0x45b194"
- },
- {
- "name": "RaiseException",
- "address": "0x45b198"
- },
- {
- "name": "GetStdHandle",
- "address": "0x45b19c"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "GetKeyboardType",
- "address": "0x45b1a4"
- },
- {
- "name": "LoadStringA",
- "address": "0x45b1a8"
- },
- {
- "name": "MessageBoxA",
- "address": "0x45b1ac"
- },
- {
- "name": "CharNextA",
- "address": "0x45b1b0"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x45b1b8"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x45b1bc"
- },
- {
- "name": "RegCloseKey",
- "address": "0x45b1c0"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "SysFreeString",
- "address": "0x45b1c8"
- },
- {
- "name": "SysReAllocStringLen",
- "address": "0x45b1cc"
- },
- {
- "name": "SysAllocStringLen",
- "address": "0x45b1d0"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "TlsSetValue",
- "address": "0x45b1d8"
- },
- {
- "name": "TlsGetValue",
- "address": "0x45b1dc"
- },
- {
- "name": "LocalAlloc",
- "address": "0x45b1e0"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x45b1e4"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x45b1ec"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x45b1f0"
- },
- {
- "name": "RegCloseKey",
- "address": "0x45b1f4"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "lstrcpyA",
- "address": "0x45b1fc"
- },
- {
- "name": "WriteFile",
- "address": "0x45b200"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x45b204"
- },
- {
- "name": "VirtualQuery",
- "address": "0x45b208"
- },
- {
- "name": "VirtualProtect",
- "address": "0x45b20c"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x45b210"
- },
- {
- "name": "Sleep",
- "address": "0x45b214"
- },
- {
- "name": "SizeofResource",
- "address": "0x45b218"
- },
- {
- "name": "SetThreadLocale",
- "address": "0x45b21c"
- },
- {
- "name": "SetFilePointer",
- "address": "0x45b220"
- },
- {
- "name": "SetEvent",
- "address": "0x45b224"
- },
- {
- "name": "SetErrorMode",
- "address": "0x45b228"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x45b22c"
- },
- {
- "name": "ResetEvent",
- "address": "0x45b230"
- },
- {
- "name": "ReadFile",
- "address": "0x45b234"
- },
- {
- "name": "MulDiv",
- "address": "0x45b238"
- },
- {
- "name": "LockResource",
- "address": "0x45b23c"
- },
- {
- "name": "LoadResource",
- "address": "0x45b240"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x45b244"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x45b248"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x45b24c"
- },
- {
- "name": "GlobalUnlock",
- "address": "0x45b250"
- },
- {
- "name": "GlobalReAlloc",
- "address": "0x45b254"
- },
- {
- "name": "GlobalMemoryStatus",
- "address": "0x45b258"
- },
- {
- "name": "GlobalHandle",
- "address": "0x45b25c"
- },
- {
- "name": "GlobalLock",
- "address": "0x45b260"
- },
- {
- "name": "GlobalFree",
- "address": "0x45b264"
- },
- {
- "name": "GlobalFindAtomA",
- "address": "0x45b268"
- },
- {
- "name": "GlobalDeleteAtom",
- "address": "0x45b26c"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x45b270"
- },
- {
- "name": "GlobalAddAtomA",
- "address": "0x45b274"
- },
- {
- "name": "GetVersionExA",
- "address": "0x45b278"
- },
- {
- "name": "GetVersion",
- "address": "0x45b27c"
- },
- {
- "name": "GetTickCount",
- "address": "0x45b280"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x45b284"
- },
- {
- "name": "GetTempPathA",
- "address": "0x45b288"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x45b28c"
- },
- {
- "name": "GetStringTypeExA",
- "address": "0x45b290"
- },
- {
- "name": "GetStdHandle",
- "address": "0x45b294"
- },
- {
- "name": "GetProcAddress",
- "address": "0x45b298"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x45b29c"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x45b2a0"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x45b2a4"
- },
- {
- "name": "GetLocalTime",
- "address": "0x45b2a8"
- },
- {
- "name": "GetLastError",
- "address": "0x45b2ac"
- },
- {
- "name": "GetFullPathNameA",
- "address": "0x45b2b0"
- },
- {
- "name": "GetDiskFreeSpaceA",
- "address": "0x45b2b4"
- },
- {
- "name": "GetDateFormatA",
- "address": "0x45b2b8"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x45b2bc"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x45b2c0"
- },
- {
- "name": "GetCPInfo",
- "address": "0x45b2c4"
- },
- {
- "name": "GetACP",
- "address": "0x45b2c8"
- },
- {
- "name": "FreeResource",
- "address": "0x45b2cc"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x45b2d0"
- },
- {
- "name": "FreeLibrary",
- "address": "0x45b2d4"
- },
- {
- "name": "FormatMessageA",
- "address": "0x45b2d8"
- },
- {
- "name": "FindResourceA",
- "address": "0x45b2dc"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x45b2e0"
- },
- {
- "name": "FindClose",
- "address": "0x45b2e4"
- },
- {
- "name": "FileTimeToLocalFileTime",
- "address": "0x45b2e8"
- },
- {
- "name": "FileTimeToDosDateTime",
- "address": "0x45b2ec"
- },
- {
- "name": "ExitProcess",
- "address": "0x45b2f0"
- },
- {
- "name": "EnumCalendarInfoA",
- "address": "0x45b2f4"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x45b2f8"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x45b2fc"
- },
- {
- "name": "CreateThread",
- "address": "0x45b300"
- },
- {
- "name": "CreateFileA",
- "address": "0x45b304"
- },
- {
- "name": "CreateEventA",
- "address": "0x45b308"
- },
- {
- "name": "CompareStringA",
- "address": "0x45b30c"
- },
- {
- "name": "CloseHandle",
- "address": "0x45b310"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "VerQueryValueA",
- "address": "0x45b318"
- },
- {
- "name": "GetFileVersionInfoSizeA",
- "address": "0x45b31c"
- },
- {
- "name": "GetFileVersionInfoA",
- "address": "0x45b320"
- }
- ],
- "dll": "version.dll"
- },
- {
- "imports": [
- {
- "name": "UnrealizeObject",
- "address": "0x45b328"
- },
- {
- "name": "StretchBlt",
- "address": "0x45b32c"
- },
- {
- "name": "SetWindowOrgEx",
- "address": "0x45b330"
- },
- {
- "name": "SetViewportOrgEx",
- "address": "0x45b334"
- },
- {
- "name": "SetTextColor",
- "address": "0x45b338"
- },
- {
- "name": "SetStretchBltMode",
- "address": "0x45b33c"
- },
- {
- "name": "SetROP2",
- "address": "0x45b340"
- },
- {
- "name": "SetPixel",
- "address": "0x45b344"
- },
- {
- "name": "SetDIBColorTable",
- "address": "0x45b348"
- },
- {
- "name": "SetBrushOrgEx",
- "address": "0x45b34c"
- },
- {
- "name": "SetBkMode",
- "address": "0x45b350"
- },
- {
- "name": "SetBkColor",
- "address": "0x45b354"
- },
- {
- "name": "SelectPalette",
- "address": "0x45b358"
- },
- {
- "name": "SelectObject",
- "address": "0x45b35c"
- },
- {
- "name": "SaveDC",
- "address": "0x45b360"
- },
- {
- "name": "RestoreDC",
- "address": "0x45b364"
- },
- {
- "name": "RectVisible",
- "address": "0x45b368"
- },
- {
- "name": "RealizePalette",
- "address": "0x45b36c"
- },
- {
- "name": "Polyline",
- "address": "0x45b370"
- },
- {
- "name": "Pie",
- "address": "0x45b374"
- },
- {
- "name": "PatBlt",
- "address": "0x45b378"
- },
- {
- "name": "MoveToEx",
- "address": "0x45b37c"
- },
- {
- "name": "MaskBlt",
- "address": "0x45b380"
- },
- {
- "name": "LineTo",
- "address": "0x45b384"
- },
- {
- "name": "IntersectClipRect",
- "address": "0x45b388"
- },
- {
- "name": "GetWindowOrgEx",
- "address": "0x45b38c"
- },
- {
- "name": "GetTextMetricsA",
- "address": "0x45b390"
- },
- {
- "name": "GetTextExtentPoint32A",
- "address": "0x45b394"
- },
- {
- "name": "GetTextAlign",
- "address": "0x45b398"
- },
- {
- "name": "GetSystemPaletteEntries",
- "address": "0x45b39c"
- },
- {
- "name": "GetStockObject",
- "address": "0x45b3a0"
- },
- {
- "name": "GetPixel",
- "address": "0x45b3a4"
- },
- {
- "name": "GetPaletteEntries",
- "address": "0x45b3a8"
- },
- {
- "name": "GetObjectA",
- "address": "0x45b3ac"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x45b3b0"
- },
- {
- "name": "GetDIBits",
- "address": "0x45b3b4"
- },
- {
- "name": "GetDIBColorTable",
- "address": "0x45b3b8"
- },
- {
- "name": "GetDCOrgEx",
- "address": "0x45b3bc"
- },
- {
- "name": "GetDCPenColor",
- "address": "0x45b3c0"
- },
- {
- "name": "GetDCBrushColor",
- "address": "0x45b3c4"
- },
- {
- "name": "GetCurrentPositionEx",
- "address": "0x45b3c8"
- },
- {
- "name": "GetClipBox",
- "address": "0x45b3cc"
- },
- {
- "name": "GetBrushOrgEx",
- "address": "0x45b3d0"
- },
- {
- "name": "GetBitmapBits",
- "address": "0x45b3d4"
- },
- {
- "name": "ExtTextOutA",
- "address": "0x45b3d8"
- },
- {
- "name": "ExcludeClipRect",
- "address": "0x45b3dc"
- },
- {
- "name": "Ellipse",
- "address": "0x45b3e0"
- },
- {
- "name": "DeleteObject",
- "address": "0x45b3e4"
- },
- {
- "name": "DeleteDC",
- "address": "0x45b3e8"
- },
- {
- "name": "CreateSolidBrush",
- "address": "0x45b3ec"
- },
- {
- "name": "CreatePenIndirect",
- "address": "0x45b3f0"
- },
- {
- "name": "CreatePalette",
- "address": "0x45b3f4"
- },
- {
- "name": "CreateHalftonePalette",
- "address": "0x45b3f8"
- },
- {
- "name": "CreateFontIndirectA",
- "address": "0x45b3fc"
- },
- {
- "name": "CreateDIBitmap",
- "address": "0x45b400"
- },
- {
- "name": "CreateDIBSection",
- "address": "0x45b404"
- },
- {
- "name": "CreateCompatibleDC",
- "address": "0x45b408"
- },
- {
- "name": "CreateCompatibleBitmap",
- "address": "0x45b40c"
- },
- {
- "name": "CreateBrushIndirect",
- "address": "0x45b410"
- },
- {
- "name": "CreateBitmap",
- "address": "0x45b414"
- },
- {
- "name": "BitBlt",
- "address": "0x45b418"
- }
- ],
- "dll": "gdi32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateWindowExA",
- "address": "0x45b420"
- },
- {
- "name": "WindowFromPoint",
- "address": "0x45b424"
- },
- {
- "name": "WinHelpA",
- "address": "0x45b428"
- },
- {
- "name": "WaitMessage",
- "address": "0x45b42c"
- },
- {
- "name": "UpdateWindow",
- "address": "0x45b430"
- },
- {
- "name": "UnregisterClassA",
- "address": "0x45b434"
- },
- {
- "name": "UnhookWindowsHookEx",
- "address": "0x45b438"
- },
- {
- "name": "TranslateMessage",
- "address": "0x45b43c"
- },
- {
- "name": "TranslateMDISysAccel",
- "address": "0x45b440"
- },
- {
- "name": "TrackPopupMenu",
- "address": "0x45b444"
- },
- {
- "name": "SystemParametersInfoA",
- "address": "0x45b448"
- },
- {
- "name": "ShowWindow",
- "address": "0x45b44c"
- },
- {
- "name": "ShowScrollBar",
- "address": "0x45b450"
- },
- {
- "name": "ShowOwnedPopups",
- "address": "0x45b454"
- },
- {
- "name": "ShowCursor",
- "address": "0x45b458"
- },
- {
- "name": "SetWindowsHookExA",
- "address": "0x45b45c"
- },
- {
- "name": "SetWindowTextA",
- "address": "0x45b460"
- },
- {
- "name": "SetWindowPos",
- "address": "0x45b464"
- },
- {
- "name": "SetWindowPlacement",
- "address": "0x45b468"
- },
- {
- "name": "SetWindowLongA",
- "address": "0x45b46c"
- },
- {
- "name": "SetTimer",
- "address": "0x45b470"
- },
- {
- "name": "SetScrollRange",
- "address": "0x45b474"
- },
- {
- "name": "SetScrollPos",
- "address": "0x45b478"
- },
- {
- "name": "SetScrollInfo",
- "address": "0x45b47c"
- },
- {
- "name": "SetRect",
- "address": "0x45b480"
- },
- {
- "name": "SetPropA",
- "address": "0x45b484"
- },
- {
- "name": "SetParent",
- "address": "0x45b488"
- },
- {
- "name": "SetMenuItemInfoA",
- "address": "0x45b48c"
- },
- {
- "name": "SetMenu",
- "address": "0x45b490"
- },
- {
- "name": "SetForegroundWindow",
- "address": "0x45b494"
- },
- {
- "name": "SetFocus",
- "address": "0x45b498"
- },
- {
- "name": "SetCursor",
- "address": "0x45b49c"
- },
- {
- "name": "SetClassLongA",
- "address": "0x45b4a0"
- },
- {
- "name": "SetCapture",
- "address": "0x45b4a4"
- },
- {
- "name": "SetActiveWindow",
- "address": "0x45b4a8"
- },
- {
- "name": "SendMessageA",
- "address": "0x45b4ac"
- },
- {
- "name": "ScrollWindow",
- "address": "0x45b4b0"
- },
- {
- "name": "ScreenToClient",
- "address": "0x45b4b4"
- },
- {
- "name": "RemovePropA",
- "address": "0x45b4b8"
- },
- {
- "name": "RemoveMenu",
- "address": "0x45b4bc"
- },
- {
- "name": "ReleaseDC",
- "address": "0x45b4c0"
- },
- {
- "name": "ReleaseCapture",
- "address": "0x45b4c4"
- },
- {
- "name": "RegisterWindowMessageA",
- "address": "0x45b4c8"
- },
- {
- "name": "RegisterClipboardFormatA",
- "address": "0x45b4cc"
- },
- {
- "name": "RegisterClassA",
- "address": "0x45b4d0"
- },
- {
- "name": "RedrawWindow",
- "address": "0x45b4d4"
- },
- {
- "name": "PtInRect",
- "address": "0x45b4d8"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x45b4dc"
- },
- {
- "name": "PostMessageA",
- "address": "0x45b4e0"
- },
- {
- "name": "PeekMessageA",
- "address": "0x45b4e4"
- },
- {
- "name": "OffsetRect",
- "address": "0x45b4e8"
- },
- {
- "name": "OemToCharA",
- "address": "0x45b4ec"
- },
- {
- "name": "MessageBoxA",
- "address": "0x45b4f0"
- },
- {
- "name": "MapWindowPoints",
- "address": "0x45b4f4"
- },
- {
- "name": "MapVirtualKeyA",
- "address": "0x45b4f8"
- },
- {
- "name": "LoadStringA",
- "address": "0x45b4fc"
- },
- {
- "name": "LoadKeyboardLayoutA",
- "address": "0x45b500"
- },
- {
- "name": "LoadIconA",
- "address": "0x45b504"
- },
- {
- "name": "LoadCursorA",
- "address": "0x45b508"
- },
- {
- "name": "LoadBitmapA",
- "address": "0x45b50c"
- },
- {
- "name": "KillTimer",
- "address": "0x45b510"
- },
- {
- "name": "IsZoomed",
- "address": "0x45b514"
- },
- {
- "name": "IsWindowVisible",
- "address": "0x45b518"
- },
- {
- "name": "IsWindowEnabled",
- "address": "0x45b51c"
- },
- {
- "name": "IsWindow",
- "address": "0x45b520"
- },
- {
- "name": "IsRectEmpty",
- "address": "0x45b524"
- },
- {
- "name": "IsIconic",
- "address": "0x45b528"
- },
- {
- "name": "IsDialogMessageA",
- "address": "0x45b52c"
- },
- {
- "name": "IsChild",
- "address": "0x45b530"
- },
- {
- "name": "InvalidateRect",
- "address": "0x45b534"
- },
- {
- "name": "IntersectRect",
- "address": "0x45b538"
- },
- {
- "name": "InsertMenuItemA",
- "address": "0x45b53c"
- },
- {
- "name": "InsertMenuA",
- "address": "0x45b540"
- },
- {
- "name": "InflateRect",
- "address": "0x45b544"
- },
- {
- "name": "GetWindowThreadProcessId",
- "address": "0x45b548"
- },
- {
- "name": "GetWindowTextA",
- "address": "0x45b54c"
- },
- {
- "name": "GetWindowRect",
- "address": "0x45b550"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x45b554"
- },
- {
- "name": "GetWindowLongA",
- "address": "0x45b558"
- },
- {
- "name": "GetWindowDC",
- "address": "0x45b55c"
- },
- {
- "name": "GetTopWindow",
- "address": "0x45b560"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x45b564"
- },
- {
- "name": "GetSystemMenu",
- "address": "0x45b568"
- },
- {
- "name": "GetSysColorBrush",
- "address": "0x45b56c"
- },
- {
- "name": "GetSysColor",
- "address": "0x45b570"
- },
- {
- "name": "GetSubMenu",
- "address": "0x45b574"
- },
- {
- "name": "GetScrollRange",
- "address": "0x45b578"
- },
- {
- "name": "GetScrollPos",
- "address": "0x45b57c"
- },
- {
- "name": "GetScrollInfo",
- "address": "0x45b580"
- },
- {
- "name": "GetPropA",
- "address": "0x45b584"
- },
- {
- "name": "GetParent",
- "address": "0x45b588"
- },
- {
- "name": "GetWindow",
- "address": "0x45b58c"
- },
- {
- "name": "GetMenuStringA",
- "address": "0x45b590"
- },
- {
- "name": "GetMenuState",
- "address": "0x45b594"
- },
- {
- "name": "GetMenuItemInfoA",
- "address": "0x45b598"
- },
- {
- "name": "GetMenuItemID",
- "address": "0x45b59c"
- },
- {
- "name": "GetMenuItemCount",
- "address": "0x45b5a0"
- },
- {
- "name": "GetMenu",
- "address": "0x45b5a4"
- },
- {
- "name": "GetLastActivePopup",
- "address": "0x45b5a8"
- },
- {
- "name": "GetKeyboardState",
- "address": "0x45b5ac"
- },
- {
- "name": "GetKeyboardLayoutList",
- "address": "0x45b5b0"
- },
- {
- "name": "GetKeyboardLayout",
- "address": "0x45b5b4"
- },
- {
- "name": "GetKeyState",
- "address": "0x45b5b8"
- },
- {
- "name": "GetKeyNameTextA",
- "address": "0x45b5bc"
- },
- {
- "name": "GetIconInfo",
- "address": "0x45b5c0"
- },
- {
- "name": "GetForegroundWindow",
- "address": "0x45b5c4"
- },
- {
- "name": "GetFocus",
- "address": "0x45b5c8"
- },
- {
- "name": "GetDesktopWindow",
- "address": "0x45b5cc"
- },
- {
- "name": "GetDCEx",
- "address": "0x45b5d0"
- },
- {
- "name": "GetDC",
- "address": "0x45b5d4"
- },
- {
- "name": "GetCursorPos",
- "address": "0x45b5d8"
- },
- {
- "name": "GetCursor",
- "address": "0x45b5dc"
- },
- {
- "name": "GetClientRect",
- "address": "0x45b5e0"
- },
- {
- "name": "GetClassNameA",
- "address": "0x45b5e4"
- },
- {
- "name": "GetClassInfoA",
- "address": "0x45b5e8"
- },
- {
- "name": "GetCapture",
- "address": "0x45b5ec"
- },
- {
- "name": "GetActiveWindow",
- "address": "0x45b5f0"
- },
- {
- "name": "FrameRect",
- "address": "0x45b5f4"
- },
- {
- "name": "FindWindowA",
- "address": "0x45b5f8"
- },
- {
- "name": "FillRect",
- "address": "0x45b5fc"
- },
- {
- "name": "EqualRect",
- "address": "0x45b600"
- },
- {
- "name": "EnumWindows",
- "address": "0x45b604"
- },
- {
- "name": "EnumThreadWindows",
- "address": "0x45b608"
- },
- {
- "name": "EndPaint",
- "address": "0x45b60c"
- },
- {
- "name": "EnableWindow",
- "address": "0x45b610"
- },
- {
- "name": "EnableScrollBar",
- "address": "0x45b614"
- },
- {
- "name": "EnableMenuItem",
- "address": "0x45b618"
- },
- {
- "name": "DrawTextA",
- "address": "0x45b61c"
- },
- {
- "name": "DrawMenuBar",
- "address": "0x45b620"
- },
- {
- "name": "DrawIconEx",
- "address": "0x45b624"
- },
- {
- "name": "DrawIcon",
- "address": "0x45b628"
- },
- {
- "name": "DrawFrameControl",
- "address": "0x45b62c"
- },
- {
- "name": "DrawEdge",
- "address": "0x45b630"
- },
- {
- "name": "DispatchMessageA",
- "address": "0x45b634"
- },
- {
- "name": "DestroyWindow",
- "address": "0x45b638"
- },
- {
- "name": "DestroyMenu",
- "address": "0x45b63c"
- },
- {
- "name": "DestroyIcon",
- "address": "0x45b640"
- },
- {
- "name": "DestroyCursor",
- "address": "0x45b644"
- },
- {
- "name": "DeleteMenu",
- "address": "0x45b648"
- },
- {
- "name": "DefWindowProcA",
- "address": "0x45b64c"
- },
- {
- "name": "DefMDIChildProcA",
- "address": "0x45b650"
- },
- {
- "name": "DefFrameProcA",
- "address": "0x45b654"
- },
- {
- "name": "CreatePopupMenu",
- "address": "0x45b658"
- },
- {
- "name": "CreateMenu",
- "address": "0x45b65c"
- },
- {
- "name": "CreateIcon",
- "address": "0x45b660"
- },
- {
- "name": "ClientToScreen",
- "address": "0x45b664"
- },
- {
- "name": "CheckMenuItem",
- "address": "0x45b668"
- },
- {
- "name": "CallWindowProcA",
- "address": "0x45b66c"
- },
- {
- "name": "CallNextHookEx",
- "address": "0x45b670"
- },
- {
- "name": "BeginPaint",
- "address": "0x45b674"
- },
- {
- "name": "CharNextA",
- "address": "0x45b678"
- },
- {
- "name": "CharLowerA",
- "address": "0x45b67c"
- },
- {
- "name": "CharToOemA",
- "address": "0x45b680"
- },
- {
- "name": "AdjustWindowRectEx",
- "address": "0x45b684"
- },
- {
- "name": "ActivateKeyboardLayout",
- "address": "0x45b688"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "Sleep",
- "address": "0x45b690"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "SafeArrayPtrOfIndex",
- "address": "0x45b698"
- },
- {
- "name": "SafeArrayGetUBound",
- "address": "0x45b69c"
- },
- {
- "name": "SafeArrayGetLBound",
- "address": "0x45b6a0"
- },
- {
- "name": "SafeArrayCreate",
- "address": "0x45b6a4"
- },
- {
- "name": "VariantChangeType",
- "address": "0x45b6a8"
- },
- {
- "name": "VariantCopy",
- "address": "0x45b6ac"
- },
- {
- "name": "VariantClear",
- "address": "0x45b6b0"
- },
- {
- "name": "VariantInit",
- "address": "0x45b6b4"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "ImageList_SetIconSize",
- "address": "0x45b6bc"
- },
- {
- "name": "ImageList_GetIconSize",
- "address": "0x45b6c0"
- },
- {
- "name": "ImageList_Write",
- "address": "0x45b6c4"
- },
- {
- "name": "ImageList_Read",
- "address": "0x45b6c8"
- },
- {
- "name": "ImageList_GetDragImage",
- "address": "0x45b6cc"
- },
- {
- "name": "ImageList_DragShowNolock",
- "address": "0x45b6d0"
- },
- {
- "name": "ImageList_SetDragCursorImage",
- "address": "0x45b6d4"
- },
- {
- "name": "ImageList_DragMove",
- "address": "0x45b6d8"
- },
- {
- "name": "ImageList_DragLeave",
- "address": "0x45b6dc"
- },
- {
- "name": "ImageList_DragEnter",
- "address": "0x45b6e0"
- },
- {
- "name": "ImageList_EndDrag",
- "address": "0x45b6e4"
- },
- {
- "name": "ImageList_BeginDrag",
- "address": "0x45b6e8"
- },
- {
- "name": "ImageList_Remove",
- "address": "0x45b6ec"
- },
- {
- "name": "ImageList_DrawEx",
- "address": "0x45b6f0"
- },
- {
- "name": "ImageList_Draw",
- "address": "0x45b6f4"
- },
- {
- "name": "ImageList_GetBkColor",
- "address": "0x45b6f8"
- },
- {
- "name": "ImageList_SetBkColor",
- "address": "0x45b6fc"
- },
- {
- "name": "ImageList_ReplaceIcon",
- "address": "0x45b700"
- },
- {
- "name": "ImageList_Add",
- "address": "0x45b704"
- },
- {
- "name": "ImageList_SetImageCount",
- "address": "0x45b708"
- },
- {
- "name": "ImageList_GetImageCount",
- "address": "0x45b70c"
- },
- {
- "name": "ImageList_Destroy",
- "address": "0x45b710"
- },
- {
- "name": "ImageList_Create",
- "address": "0x45b714"
- }
- ],
- "dll": "comctl32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x0006f600",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x004571c8",
- "timestamp": "1992-06-19 22:22:17",
- "osversion": "4.0",
- "sections": [
- {
- "name": "CODE",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00056400",
- "entropy": "6.51",
- "raw_address": "0x00000400",
- "virtual_size": "0x0005623c",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": "DATA",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00058000",
- "size_of_data": "0x00001200",
- "entropy": "3.99",
- "raw_address": "0x00056800",
- "virtual_size": "0x0000113c",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": "BSS",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0005a000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00057a00",
- "virtual_size": "0x00000b79",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".idata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0005b000",
- "size_of_data": "0x00002200",
- "entropy": "4.92",
- "raw_address": "0x00057a00",
- "virtual_size": "0x0000208c",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0005e000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00059c00",
- "virtual_size": "0x00000010",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0005f000",
- "size_of_data": "0x00000200",
- "entropy": "0.20",
- "raw_address": "0x00059c00",
- "virtual_size": "0x00000018",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00060000",
- "size_of_data": "0x00006200",
- "entropy": "6.67",
- "raw_address": "0x00059e00",
- "virtual_size": "0x00006198",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00067000",
- "size_of_data": "0x00004800",
- "entropy": "4.38",
- "raw_address": "0x00060000",
- "virtual_size": "0x00004800",
- "characteristics_raw": "0x50000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0005b000",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000208c"
- },
- {
- "virtual_address": "0x00067000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00004800"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00060000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00006198"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0005f000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "3d14c36d144d8e05489ac5489a77dc6d",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 13,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement