Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: "Malicious"
- [*] MalScore: 10.0
- [*] File Name: "NetWire_2e7fb3fa2ab2b15c301c7317775c9768.exe"
- [*] File Size: 174080
- [*] File Type: "PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows"
- [*] SHA256: "ca5fabbc12530df1f80de91524306c853b76300398169da124ad80e756993eb5"
- [*] MD5: "2e7fb3fa2ab2b15c301c7317775c9768"
- [*] SHA1: "4562720dfedc51e2d0dffee31262a11fa0cc2c38"
- [*] SHA512: "d2494adf3309f9db58e194f40efb52c7f9b73b4f5943876aaf9ff626f98b7283e504c4362a07ffebf39b1bc8b4471665cf791e0a7443e97c1f04ce6bc464e31d"
- [*] CRC32: "7DE86739"
- [*] SSDEEP: "3072:mjc/2QVfrRY41zB2niK+qbj053rCxxv2GDp5ZchWF5GvGt/MCM8s:mU2QBrRY4Cnd0+j/ZIypMCMP"
- [*] Process Execution: [
- "NetWire_2e7fb3fa2ab2b15c301c7317775c9768.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details": [
- {
- "section": "name: .text, entropy: 7.74, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x00029200, virtual_size: 0x00029044"
- }
- ]
- },
- {
- "Description": "Anomalous .NET characteristics",
- "Details": [
- {
- "anomalous_version": "Assembly version is set to 0"
- }
- ]
- },
- {
- "Description": "File has been identified by 14 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "FireEye": "Generic.mg.2e7fb3fa2ab2b15c"
- },
- {
- "Cylance": "Unsafe"
- },
- {
- "Symantec": "ML.Attribute.HighConfidence"
- },
- {
- "APEX": "Malicious"
- },
- {
- "Kaspersky": "HEUR:Trojan.Win32.Generic"
- },
- {
- "Endgame": "malicious (high confidence)"
- },
- {
- "Invincea": "heuristic"
- },
- {
- "McAfee-GW-Edition": "BehavesLike.Win32.Generic.cc"
- },
- {
- "Trapmine": "malicious.high.ml.score"
- },
- {
- "SentinelOne": "DFI - Suspicious PE"
- },
- {
- "ZoneAlarm": "HEUR:Trojan.Win32.Generic"
- },
- {
- "AhnLab-V3": "Trojan/Win32.RL_Generic.R277346"
- },
- {
- "Cybereason": "malicious.dfedc5"
- },
- {
- "Qihoo-360": "HEUR/QVM03.0.1591.Malware.Gen"
- }
- ]
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: []
- [*] Mutexes: []
- [*] Modified Files: []
- [*] Deleted Files: []
- [*] Modified Registry Keys: []
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "dotnet": {
- "customattrs": [],
- "assemblyinfo": {
- "version": "0.0.0.0",
- "name": "XCkghoVkEa_repack"
- },
- "assemblyrefs": [
- {
- "version": "4.0.0.0",
- "name": "mscorlib"
- },
- {
- "version": "4.0.0.0",
- "name": "System"
- },
- {
- "version": "2.0.0.0",
- "name": "netstandard"
- },
- {
- "version": "0.0.0.0",
- "name": "XQuTpvyQwz"
- }
- ],
- "typerefs": [
- {
- "typename": "System.Diagnostics.Trace",
- "assembly": "System"
- },
- {
- "typename": "System.IO.Compression.CompressionMode",
- "assembly": "System"
- },
- {
- "typename": "System.IO.Compression.DeflateStream",
- "assembly": "System"
- },
- {
- "typename": "System.Text.RegularExpressions.Capture",
- "assembly": "System"
- },
- {
- "typename": "System.Text.RegularExpressions.Group",
- "assembly": "System"
- },
- {
- "typename": "System.Text.RegularExpressions.GroupCollection",
- "assembly": "System"
- },
- {
- "typename": "System.Text.RegularExpressions.Match",
- "assembly": "System"
- },
- {
- "typename": "System.Text.RegularExpressions.Regex",
- "assembly": "System"
- },
- {
- "typename": "System.Text.RegularExpressions.RegexOptions",
- "assembly": "System"
- },
- {
- "typename": "StubSite.get_HmacKey",
- "assembly": "XQuTpvyQwz"
- },
- {
- "typename": "Microsoft.Win32.Registry",
- "assembly": "mscorlib"
- },
- {
- "typename": "Microsoft.Win32.RegistryKey",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.AppDomain",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Byte",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.Dictionary`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Convert",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Exception",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Guid",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IDisposable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.Directory",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.DirectoryInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.File",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.FileInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.FileSystemInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.Path",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.Stream",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Int32",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IntPtr",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Nullable`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Object",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Assembly",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyName",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MemberInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ResolveEventArgs",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ResolveEventHandler",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilationRelaxationsAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.RuntimeCompatibilityAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.RuntimeTypeHandle",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.STAThreadAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Security.Cryptography.HashAlgorithm",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Security.Cryptography.MD5",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.String",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Text.Encoding",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Interlocked",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Monitor",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Type",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Action`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Array",
- "assembly": "netstandard"
- },
- {
- "typename": "System.BitConverter",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Byte",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Char",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.Dictionary`2",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.Dictionary`2/Enumerator",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.Dictionary`2/KeyCollection",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.Dictionary`2/KeyCollection/Enumerator",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.EqualityComparer`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.HashSet`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.HashSet`1/Enumerator",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.IEnumerable`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.IEnumerator`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.IReadOnlyCollection`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.IReadOnlyDictionary`2",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.IReadOnlyList`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.KeyValuePair`2",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.List`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.List`1/Enumerator",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.Queue`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.IEnumerable",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.IEnumerator",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Console",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Convert",
- "assembly": "netstandard"
- },
- {
- "typename": "System.DateTime",
- "assembly": "netstandard"
- },
- {
- "typename": "System.DateTimeOffset",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Diagnostics.DebuggerBrowsableAttribute",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Diagnostics.DebuggerBrowsableState",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Diagnostics.DebuggerHiddenAttribute",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Enum",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Environment",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Exception",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Func`2",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Func`3",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Func`4",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IDisposable",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IFormatProvider",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.Compression.CompressionMode",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.Compression.DeflateStream",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.Directory",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.File",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.FileStream",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.MemoryStream",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.Path",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.SeekOrigin",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.Stream",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.StreamReader",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.TextReader",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Int32",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Int64",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Linq.Enumerable",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Linq.IGrouping`2",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Linq.IOrderedEnumerable`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Math",
- "assembly": "netstandard"
- },
- {
- "typename": "System.NotSupportedException",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Nullable`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Object",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilerGeneratedAttribute",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Runtime.CompilerServices.IteratorStateMachineAttribute",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Runtime.CompilerServices.TupleElementNamesAttribute",
- "assembly": "netstandard"
- },
- {
- "typename": "System.String",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Text.Encoding",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Text.RegularExpressions.Capture",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Text.RegularExpressions.Group",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Text.RegularExpressions.GroupCollection",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Text.RegularExpressions.Match",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Text.RegularExpressions.Regex",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Text.RegularExpressions.RegexOptions",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Text.StringBuilder",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Type",
- "assembly": "netstandard"
- },
- {
- "typename": "System.UInt32",
- "assembly": "netstandard"
- },
- {
- "typename": "System.ValueTuple`2",
- "assembly": "netstandard"
- }
- ]
- },
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "_CorExeMain",
- "address": "0x402000"
- }
- ],
- "dll": "mscoree.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00032488",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x0042b03e",
- "timestamp": "2019-06-24 18:24:33",
- "osversion": "4.0",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00002000",
- "size_of_data": "0x00029200",
- "entropy": "7.74",
- "raw_address": "0x00000200",
- "virtual_size": "0x00029044",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0002c000",
- "size_of_data": "0x00001200",
- "entropy": "4.52",
- "raw_address": "0x00029400",
- "virtual_size": "0x00001184",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0002e000",
- "size_of_data": "0x00000200",
- "entropy": "0.10",
- "raw_address": "0x0002a600",
- "virtual_size": "0x0000000c",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0002aff0",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000004b"
- },
- {
- "virtual_address": "0x0002c000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00001184"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0002e000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x0000000c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000008"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002008",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000048"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "f34d5f2d4577ed6d9ceec516c1f5a744",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 1,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegQueryInfoKeyW",
- "advapi32.dll.RegEnumKeyExW",
- "advapi32.dll.RegEnumValueW",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.RegQueryValueExW",
- "kernel32.dll.QueryActCtxW",
- "shlwapi.dll.UrlIsW"
- ]
- [*] Static Analysis: {
- "dotnet": {
- "customattrs": [],
- "assemblyinfo": {
- "version": "0.0.0.0",
- "name": "XCkghoVkEa_repack"
- },
- "assemblyrefs": [
- {
- "version": "4.0.0.0",
- "name": "mscorlib"
- },
- {
- "version": "4.0.0.0",
- "name": "System"
- },
- {
- "version": "2.0.0.0",
- "name": "netstandard"
- },
- {
- "version": "0.0.0.0",
- "name": "XQuTpvyQwz"
- }
- ],
- "typerefs": [
- {
- "typename": "System.Diagnostics.Trace",
- "assembly": "System"
- },
- {
- "typename": "System.IO.Compression.CompressionMode",
- "assembly": "System"
- },
- {
- "typename": "System.IO.Compression.DeflateStream",
- "assembly": "System"
- },
- {
- "typename": "System.Text.RegularExpressions.Capture",
- "assembly": "System"
- },
- {
- "typename": "System.Text.RegularExpressions.Group",
- "assembly": "System"
- },
- {
- "typename": "System.Text.RegularExpressions.GroupCollection",
- "assembly": "System"
- },
- {
- "typename": "System.Text.RegularExpressions.Match",
- "assembly": "System"
- },
- {
- "typename": "System.Text.RegularExpressions.Regex",
- "assembly": "System"
- },
- {
- "typename": "System.Text.RegularExpressions.RegexOptions",
- "assembly": "System"
- },
- {
- "typename": "StubSite.get_HmacKey",
- "assembly": "XQuTpvyQwz"
- },
- {
- "typename": "Microsoft.Win32.Registry",
- "assembly": "mscorlib"
- },
- {
- "typename": "Microsoft.Win32.RegistryKey",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.AppDomain",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Byte",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.Dictionary`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Convert",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Exception",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Guid",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IDisposable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.Directory",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.DirectoryInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.File",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.FileInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.FileSystemInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.Path",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.Stream",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Int32",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IntPtr",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Nullable`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Object",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Assembly",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyName",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MemberInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ResolveEventArgs",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ResolveEventHandler",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilationRelaxationsAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.RuntimeCompatibilityAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.RuntimeTypeHandle",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.STAThreadAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Security.Cryptography.HashAlgorithm",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Security.Cryptography.MD5",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.String",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Text.Encoding",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Interlocked",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Monitor",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Type",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Action`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Array",
- "assembly": "netstandard"
- },
- {
- "typename": "System.BitConverter",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Byte",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Char",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.Dictionary`2",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.Dictionary`2/Enumerator",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.Dictionary`2/KeyCollection",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.Dictionary`2/KeyCollection/Enumerator",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.EqualityComparer`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.HashSet`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.HashSet`1/Enumerator",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.IEnumerable`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.IEnumerator`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.IReadOnlyCollection`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.IReadOnlyDictionary`2",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.IReadOnlyList`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.KeyValuePair`2",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.List`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.List`1/Enumerator",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.Generic.Queue`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.IEnumerable",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Collections.IEnumerator",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Console",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Convert",
- "assembly": "netstandard"
- },
- {
- "typename": "System.DateTime",
- "assembly": "netstandard"
- },
- {
- "typename": "System.DateTimeOffset",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Diagnostics.DebuggerBrowsableAttribute",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Diagnostics.DebuggerBrowsableState",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Diagnostics.DebuggerHiddenAttribute",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Enum",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Environment",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Exception",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Func`2",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Func`3",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Func`4",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IDisposable",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IFormatProvider",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.Compression.CompressionMode",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.Compression.DeflateStream",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.Directory",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.File",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.FileStream",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.MemoryStream",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.Path",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.SeekOrigin",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.Stream",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.StreamReader",
- "assembly": "netstandard"
- },
- {
- "typename": "System.IO.TextReader",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Int32",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Int64",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Linq.Enumerable",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Linq.IGrouping`2",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Linq.IOrderedEnumerable`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Math",
- "assembly": "netstandard"
- },
- {
- "typename": "System.NotSupportedException",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Nullable`1",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Object",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilerGeneratedAttribute",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Runtime.CompilerServices.IteratorStateMachineAttribute",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Runtime.CompilerServices.TupleElementNamesAttribute",
- "assembly": "netstandard"
- },
- {
- "typename": "System.String",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Text.Encoding",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Text.RegularExpressions.Capture",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Text.RegularExpressions.Group",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Text.RegularExpressions.GroupCollection",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Text.RegularExpressions.Match",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Text.RegularExpressions.Regex",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Text.RegularExpressions.RegexOptions",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Text.StringBuilder",
- "assembly": "netstandard"
- },
- {
- "typename": "System.Type",
- "assembly": "netstandard"
- },
- {
- "typename": "System.UInt32",
- "assembly": "netstandard"
- },
- {
- "typename": "System.ValueTuple`2",
- "assembly": "netstandard"
- }
- ]
- },
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "_CorExeMain",
- "address": "0x402000"
- }
- ],
- "dll": "mscoree.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00032488",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x0042b03e",
- "timestamp": "2019-06-24 18:24:33",
- "osversion": "4.0",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00002000",
- "size_of_data": "0x00029200",
- "entropy": "7.74",
- "raw_address": "0x00000200",
- "virtual_size": "0x00029044",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0002c000",
- "size_of_data": "0x00001200",
- "entropy": "4.52",
- "raw_address": "0x00029400",
- "virtual_size": "0x00001184",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0002e000",
- "size_of_data": "0x00000200",
- "entropy": "0.10",
- "raw_address": "0x0002a600",
- "virtual_size": "0x0000000c",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0002aff0",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000004b"
- },
- {
- "virtual_address": "0x0002c000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00001184"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0002e000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x0000000c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000008"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002008",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000048"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "f34d5f2d4577ed6d9ceec516c1f5a744",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 1,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement