Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: ""
- [*] MalScore: 10.0
- [*] File Name: "rdp.dll"
- [*] File Size: 692736
- [*] File Type: "PE32 executable (DLL) (GUI) Intel 80386, for MS Windows"
- [*] SHA256: "289676a9f765bb76e644a91ad2bcc1412fa62138dc025a28bc4e3fec2d8aa96d"
- [*] MD5: "78bf017381b6488ab7282e5af8bda9cd"
- [*] SHA1: "bf4c9aebb58421194e3f6e19cbc5cee2de1499b3"
- [*] SHA512: "af53db798d997e3b373b1898cb19733e30c5230b32b0e8a370483d3e0c50f483c53ceb7ad0609afa43f06723991eee269c49cbe28e89e655f3bd9f40b73bcf84"
- [*] CRC32: "0A2C0BAC"
- [*] SSDEEP: "12288:Cn7lv2NmRxsTE4ycC5xS0tgo8yZ1AVEw0D8eBUpPuC8PhyQk2:KvnRxsTTycC9Cor+VEwihBUpPuxhJ"
- [*] Process Execution: [
- "rundll32.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "Creates RWX memory",
- "Details": []
- },
- {
- "Description": "File has been identified by 44 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "Bkav": "W32.CalremyLTM.Trojan"
- },
- {
- "MicroWorld-eScan": "Trojan.Generic.6658377"
- },
- {
- "nProtect": "Backdoor/W32.Agent.692736.F"
- },
- {
- "McAfee": "Artemis!78BF017381B6"
- },
- {
- "Malwarebytes": "Trojan.SpyEyes"
- },
- {
- "VIPRE": "Trojan.Win32.Generic!BT"
- },
- {
- "TheHacker": "Trojan/Agent.hnmn"
- },
- {
- "BitDefender": "Trojan.Generic.6658377"
- },
- {
- "K7GW": "Trojan ( 0022ce641 )"
- },
- {
- "K7AntiVirus": "Trojan ( 0022ce641 )"
- },
- {
- "Baidu": "Win32.Trojan.WisdomEyes.151026.9950.9991"
- },
- {
- "Symantec": "Trojan.Gen"
- },
- {
- "ESET-NOD32": "Win32/TrojanDownloader.Carberp.AS"
- },
- {
- "Avast": "Win32:SpyeyePlugin-E [Trj]"
- },
- {
- "ClamAV": "Win.Trojan.Agent-983883"
- },
- {
- "Kaspersky": "UDS:DangerousObject.Multi.Generic"
- },
- {
- "NANO-Antivirus": "Trojan.Win32.Agent.xeauv"
- },
- {
- "Tencent": "Win32.Trojan.Hijacker.btsx"
- },
- {
- "Ad-Aware": "Trojan.Generic.6658377"
- },
- {
- "Sophos": "Mal/Behav-010"
- },
- {
- "Comodo": "UnclassifiedMalware"
- },
- {
- "F-Secure": "Trojan.Generic.6658377"
- },
- {
- "DrWeb": "Trojan.Siggen4.16780"
- },
- {
- "Zillya": "Trojan.Agent.Win32.180949"
- },
- {
- "McAfee-GW-Edition": "BehavesLike.Win32.PWSZbot.jh"
- },
- {
- "Emsisoft": "Trojan.Generic.6658377 (B)"
- },
- {
- "Jiangmin": "Trojan/Agent.emrv"
- },
- {
- "Avira": "TR/Hijacker.Gen"
- },
- {
- "Fortinet": "W32/Agent.HNMN!tr"
- },
- {
- "Antiy-AVL": "Trojan/Win32.SGeneric"
- },
- {
- "Kingsoft": "Win32.Troj.Undef.(kcloud)"
- },
- {
- "Arcabit": "Trojan.Generic.D659949"
- },
- {
- "Microsoft": "Trojan:Win32/EyeStye.plugin"
- },
- {
- "AhnLab-V3": "Trojan/Win32.Agent"
- },
- {
- "ALYac": "Trojan.Generic.6658377"
- },
- {
- "AVware": "Trojan.Win32.Generic!BT"
- },
- {
- "Panda": "Trj/Genetic.gen"
- },
- {
- "Rising": "PE:Malware.Generic(Thunder)!1.A1C4 [F]"
- },
- {
- "Yandex": "Trojan.Agent!eOSN0NWHXas"
- },
- {
- "Ikarus": "Trojan.Win32.Agent"
- },
- {
- "GData": "Trojan.Generic.6658377"
- },
- {
- "AVG": "Agent2.CJFH"
- },
- {
- "Baidu-International": "Trojan.Win32.Carberp.AS"
- },
- {
- "Qihoo-360": "Win32/Trojan.Spy.7b3"
- }
- ]
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: []
- [*] Mutexes: []
- [*] Modified Files: []
- [*] Deleted Files: []
- [*] Modified Registry Keys: []
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "_errno",
- "address": "0x10077318"
- },
- {
- "name": "_initterm",
- "address": "0x1007731c"
- },
- {
- "name": "_amsg_exit",
- "address": "0x10077320"
- },
- {
- "name": "_adjust_fdiv",
- "address": "0x10077324"
- },
- {
- "name": "isdigit",
- "address": "0x10077328"
- },
- {
- "name": "isxdigit",
- "address": "0x1007732c"
- },
- {
- "name": "_XcptFilter",
- "address": "0x10077330"
- },
- {
- "name": "isspace",
- "address": "0x10077334"
- },
- {
- "name": "free",
- "address": "0x10077338"
- },
- {
- "name": "malloc",
- "address": "0x1007733c"
- },
- {
- "name": "memmove",
- "address": "0x10077340"
- },
- {
- "name": "atoi",
- "address": "0x10077344"
- },
- {
- "name": "_snprintf",
- "address": "0x10077348"
- },
- {
- "name": "strcat",
- "address": "0x1007734c"
- },
- {
- "name": "memset",
- "address": "0x10077350"
- },
- {
- "name": "strcpy",
- "address": "0x10077354"
- },
- {
- "name": "strstr",
- "address": "0x10077358"
- },
- {
- "name": "strlen",
- "address": "0x1007735c"
- },
- {
- "name": "memcpy",
- "address": "0x10077360"
- },
- {
- "name": "_iob",
- "address": "0x10077364"
- },
- {
- "name": "strchr",
- "address": "0x10077368"
- },
- {
- "name": "_vsnprintf",
- "address": "0x1007736c"
- },
- {
- "name": "_getch",
- "address": "0x10077370"
- },
- {
- "name": "signal",
- "address": "0x10077374"
- },
- {
- "name": "fputs",
- "address": "0x10077378"
- },
- {
- "name": "_gmtime64",
- "address": "0x1007737c"
- },
- {
- "name": "raise",
- "address": "0x10077380"
- },
- {
- "name": "_exit",
- "address": "0x10077384"
- },
- {
- "name": "vfprintf",
- "address": "0x10077388"
- },
- {
- "name": "getenv",
- "address": "0x1007738c"
- },
- {
- "name": "fprintf",
- "address": "0x10077390"
- },
- {
- "name": "_wfopen",
- "address": "0x10077394"
- },
- {
- "name": "fgets",
- "address": "0x10077398"
- },
- {
- "name": "fseek",
- "address": "0x1007739c"
- },
- {
- "name": "ftell",
- "address": "0x100773a0"
- },
- {
- "name": "_setmode",
- "address": "0x100773a4"
- },
- {
- "name": "fflush",
- "address": "0x100773a8"
- },
- {
- "name": "fwrite",
- "address": "0x100773ac"
- },
- {
- "name": "_time64",
- "address": "0x100773b0"
- },
- {
- "name": "fopen",
- "address": "0x100773b4"
- },
- {
- "name": "feof",
- "address": "0x100773b8"
- },
- {
- "name": "fclose",
- "address": "0x100773bc"
- },
- {
- "name": "fread",
- "address": "0x100773c0"
- },
- {
- "name": "ferror",
- "address": "0x100773c4"
- },
- {
- "name": "realloc",
- "address": "0x100773c8"
- },
- {
- "name": "_fileno",
- "address": "0x100773cc"
- }
- ],
- "dll": "msvcrt.dll"
- },
- {
- "imports": [
- {
- "name": "SetBitmapBits",
- "address": "0x10077070"
- },
- {
- "name": "CreateDIBSection",
- "address": "0x10077074"
- },
- {
- "name": "DeleteObject",
- "address": "0x10077078"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x1007707c"
- }
- ],
- "dll": "GDI32.dll"
- },
- {
- "imports": [
- {
- "name": "GetOpenFileNameA",
- "address": "0x10077310"
- }
- ],
- "dll": "comdlg32.dll"
- },
- {
- "imports": [
- {
- "name": "CoGetObject",
- "address": "0x1007745c"
- },
- {
- "name": "CoInitialize",
- "address": "0x10077460"
- },
- {
- "name": "CoUninitialize",
- "address": "0x10077464"
- },
- {
- "name": "CoCreateInstance",
- "address": "0x10077468"
- },
- {
- "name": "CoInitializeEx",
- "address": "0x1007746c"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "SetupDiCreateDeviceInfoW",
- "address": "0x100771bc"
- },
- {
- "name": "SetupDiCallClassInstaller",
- "address": "0x100771c0"
- },
- {
- "name": "SetupDiGetDeviceRegistryPropertyW",
- "address": "0x100771c4"
- },
- {
- "name": "SetupDiDestroyDeviceInfoList",
- "address": "0x100771c8"
- },
- {
- "name": "SetupDiEnumDeviceInfo",
- "address": "0x100771cc"
- },
- {
- "name": "SetupDiGetINFClassW",
- "address": "0x100771d0"
- },
- {
- "name": "SetupDiSetDeviceRegistryPropertyW",
- "address": "0x100771d4"
- },
- {
- "name": "SetupDiGetClassDevsW",
- "address": "0x100771d8"
- },
- {
- "name": "SetupDiCreateDeviceInfoList",
- "address": "0x100771dc"
- }
- ],
- "dll": "SETUPAPI.dll"
- },
- {
- "imports": [
- {
- "name": "StrPBrkA",
- "address": "0x100771f8"
- },
- {
- "name": "StrSpnA",
- "address": "0x100771fc"
- },
- {
- "name": "StrRStrIA",
- "address": "0x10077200"
- }
- ],
- "dll": "SHLWAPI.dll"
- },
- {
- "imports": [
- {
- "name": "inet_addr",
- "address": "0x100772bc"
- },
- {
- "name": "gethostbyaddr",
- "address": "0x100772c0"
- },
- {
- "name": "closesocket",
- "address": "0x100772c4"
- },
- {
- "name": "__WSAFDIsSet",
- "address": "0x100772c8"
- },
- {
- "name": "socket",
- "address": "0x100772cc"
- },
- {
- "name": "getsockopt",
- "address": "0x100772d0"
- },
- {
- "name": "ioctlsocket",
- "address": "0x100772d4"
- },
- {
- "name": "connect",
- "address": "0x100772d8"
- },
- {
- "name": "WSAStartup",
- "address": "0x100772dc"
- },
- {
- "name": "send",
- "address": "0x100772e0"
- },
- {
- "name": "select",
- "address": "0x100772e4"
- },
- {
- "name": "WSAGetLastError",
- "address": "0x100772e8"
- },
- {
- "name": "htons",
- "address": "0x100772ec"
- },
- {
- "name": "recv",
- "address": "0x100772f0"
- }
- ],
- "dll": "WS2_32.dll"
- },
- {
- "imports": [
- {
- "name": "SHFileOperationA",
- "address": "0x100771e4"
- },
- {
- "name": "ShellExecuteExW",
- "address": "0x100771e8"
- },
- {
- "name": "DragAcceptFiles",
- "address": "0x100771ec"
- },
- {
- "name": "DragQueryFileA",
- "address": "0x100771f0"
- }
- ],
- "dll": "SHELL32.dll"
- },
- {
- "imports": [
- {
- "name": "WTSEnumerateSessionsA",
- "address": "0x100772f8"
- },
- {
- "name": "WTSQueryUserToken",
- "address": "0x100772fc"
- },
- {
- "name": "WTSFreeMemory",
- "address": "0x10077300"
- },
- {
- "name": "WTSQuerySessionInformationA",
- "address": "0x10077304"
- },
- {
- "name": "WTSLogoffSession",
- "address": "0x10077308"
- }
- ],
- "dll": "WTSAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "GetProfilesDirectoryA",
- "address": "0x10077280"
- },
- {
- "name": "CreateEnvironmentBlock",
- "address": "0x10077284"
- },
- {
- "name": "DestroyEnvironmentBlock",
- "address": "0x10077288"
- }
- ],
- "dll": "USERENV.dll"
- },
- {
- "imports": [
- {
- "name": "NetUserDel",
- "address": "0x100771a4"
- },
- {
- "name": "NetLocalGroupEnum",
- "address": "0x100771a8"
- },
- {
- "name": "NetApiBufferFree",
- "address": "0x100771ac"
- },
- {
- "name": "NetUserAdd",
- "address": "0x100771b0"
- },
- {
- "name": "NetLocalGroupAddMembers",
- "address": "0x100771b4"
- }
- ],
- "dll": "NETAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x10077084"
- },
- {
- "name": "GetTickCount",
- "address": "0x10077088"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x1007708c"
- },
- {
- "name": "SetUnhandledExceptionFilter",
- "address": "0x10077090"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x10077094"
- },
- {
- "name": "InterlockedCompareExchange",
- "address": "0x10077098"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x1007709c"
- },
- {
- "name": "RtlUnwind",
- "address": "0x100770a0"
- },
- {
- "name": "lstrcatA",
- "address": "0x100770a4"
- },
- {
- "name": "TerminateThread",
- "address": "0x100770a8"
- },
- {
- "name": "WriteProcessMemory",
- "address": "0x100770ac"
- },
- {
- "name": "VirtualAllocEx",
- "address": "0x100770b0"
- },
- {
- "name": "GetTempPathW",
- "address": "0x100770b4"
- },
- {
- "name": "TerminateProcess",
- "address": "0x100770b8"
- },
- {
- "name": "lstrcpynW",
- "address": "0x100770bc"
- },
- {
- "name": "CopyFileW",
- "address": "0x100770c0"
- },
- {
- "name": "VirtualFreeEx",
- "address": "0x100770c4"
- },
- {
- "name": "OpenProcess",
- "address": "0x100770c8"
- },
- {
- "name": "CreateRemoteThread",
- "address": "0x100770cc"
- },
- {
- "name": "VirtualFree",
- "address": "0x100770d0"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x100770d4"
- },
- {
- "name": "ProcessIdToSessionId",
- "address": "0x100770d8"
- },
- {
- "name": "GetStdHandle",
- "address": "0x100770dc"
- },
- {
- "name": "GlobalMemoryStatus",
- "address": "0x100770e0"
- },
- {
- "name": "FlushConsoleInputBuffer",
- "address": "0x100770e4"
- },
- {
- "name": "GetFileType",
- "address": "0x100770e8"
- },
- {
- "name": "lstrcmpiA",
- "address": "0x100770ec"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x100770f0"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x100770f4"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x100770f8"
- },
- {
- "name": "lstrcpynA",
- "address": "0x100770fc"
- },
- {
- "name": "TryEnterCriticalSection",
- "address": "0x10077100"
- },
- {
- "name": "LocalFree",
- "address": "0x10077104"
- },
- {
- "name": "lstrcmpiW",
- "address": "0x10077108"
- },
- {
- "name": "LocalAlloc",
- "address": "0x1007710c"
- },
- {
- "name": "lstrlenW",
- "address": "0x10077110"
- },
- {
- "name": "FreeLibrary",
- "address": "0x10077114"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x10077118"
- },
- {
- "name": "lstrcpyA",
- "address": "0x1007711c"
- },
- {
- "name": "CreateThread",
- "address": "0x10077120"
- },
- {
- "name": "lstrcpyW",
- "address": "0x10077124"
- },
- {
- "name": "GetWindowsDirectoryW",
- "address": "0x10077128"
- },
- {
- "name": "CloseHandle",
- "address": "0x1007712c"
- },
- {
- "name": "GetVersionExA",
- "address": "0x10077130"
- },
- {
- "name": "CreateMutexA",
- "address": "0x10077134"
- },
- {
- "name": "lstrcatW",
- "address": "0x10077138"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x1007713c"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x10077140"
- },
- {
- "name": "CreateFileMappingA",
- "address": "0x10077144"
- },
- {
- "name": "SetLastError",
- "address": "0x10077148"
- },
- {
- "name": "ExitThread",
- "address": "0x1007714c"
- },
- {
- "name": "CreateFileW",
- "address": "0x10077150"
- },
- {
- "name": "Sleep",
- "address": "0x10077154"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x10077158"
- },
- {
- "name": "UnmapViewOfFile",
- "address": "0x1007715c"
- },
- {
- "name": "MapViewOfFile",
- "address": "0x10077160"
- },
- {
- "name": "lstrlenA",
- "address": "0x10077164"
- },
- {
- "name": "ExitProcess",
- "address": "0x10077168"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x1007716c"
- },
- {
- "name": "OutputDebugStringA",
- "address": "0x10077170"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x10077174"
- },
- {
- "name": "GetLastError",
- "address": "0x10077178"
- },
- {
- "name": "HeapValidate",
- "address": "0x1007717c"
- },
- {
- "name": "GetVersion",
- "address": "0x10077180"
- },
- {
- "name": "VirtualQuery",
- "address": "0x10077184"
- },
- {
- "name": "GetProcAddress",
- "address": "0x10077188"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x1007718c"
- },
- {
- "name": "VirtualProtect",
- "address": "0x10077190"
- },
- {
- "name": "GetProcessHeap",
- "address": "0x10077194"
- },
- {
- "name": "HeapFree",
- "address": "0x10077198"
- },
- {
- "name": "HeapAlloc",
- "address": "0x1007719c"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "TranslateMessage",
- "address": "0x10077208"
- },
- {
- "name": "GetWindowTextA",
- "address": "0x1007720c"
- },
- {
- "name": "RegisterClassExA",
- "address": "0x10077210"
- },
- {
- "name": "MessageBoxA",
- "address": "0x10077214"
- },
- {
- "name": "CreateWindowExA",
- "address": "0x10077218"
- },
- {
- "name": "DefWindowProcA",
- "address": "0x1007721c"
- },
- {
- "name": "ShowWindow",
- "address": "0x10077220"
- },
- {
- "name": "DispatchMessageA",
- "address": "0x10077224"
- },
- {
- "name": "SetWindowTextA",
- "address": "0x10077228"
- },
- {
- "name": "UpdateWindow",
- "address": "0x1007722c"
- },
- {
- "name": "SendMessageA",
- "address": "0x10077230"
- },
- {
- "name": "SetFocus",
- "address": "0x10077234"
- },
- {
- "name": "LoadIconA",
- "address": "0x10077238"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x1007723c"
- },
- {
- "name": "SetWindowLongA",
- "address": "0x10077240"
- },
- {
- "name": "GetMessageA",
- "address": "0x10077244"
- },
- {
- "name": "CharLowerW",
- "address": "0x10077248"
- },
- {
- "name": "GetUserObjectInformationW",
- "address": "0x1007724c"
- },
- {
- "name": "GetProcessWindowStation",
- "address": "0x10077250"
- },
- {
- "name": "GetDC",
- "address": "0x10077254"
- },
- {
- "name": "ReleaseDC",
- "address": "0x10077258"
- },
- {
- "name": "GetDesktopWindow",
- "address": "0x1007725c"
- },
- {
- "name": "wsprintfA",
- "address": "0x10077260"
- },
- {
- "name": "IsDialogMessageA",
- "address": "0x10077264"
- },
- {
- "name": "CallWindowProcA",
- "address": "0x10077268"
- },
- {
- "name": "LoadCursorA",
- "address": "0x1007726c"
- },
- {
- "name": "MoveWindow",
- "address": "0x10077270"
- },
- {
- "name": "wsprintfW",
- "address": "0x10077274"
- },
- {
- "name": "wvsprintfA",
- "address": "0x10077278"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x10077000"
- },
- {
- "name": "SetSecurityDescriptorDacl",
- "address": "0x10077004"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x10077008"
- },
- {
- "name": "RegCloseKey",
- "address": "0x1007700c"
- },
- {
- "name": "OpenServiceA",
- "address": "0x10077010"
- },
- {
- "name": "LookupAccountNameA",
- "address": "0x10077014"
- },
- {
- "name": "GetTokenInformation",
- "address": "0x10077018"
- },
- {
- "name": "RegisterEventSourceA",
- "address": "0x1007701c"
- },
- {
- "name": "ReportEventA",
- "address": "0x10077020"
- },
- {
- "name": "DeregisterEventSource",
- "address": "0x10077024"
- },
- {
- "name": "GetLengthSid",
- "address": "0x10077028"
- },
- {
- "name": "GetUserNameA",
- "address": "0x1007702c"
- },
- {
- "name": "QueryServiceConfigA",
- "address": "0x10077030"
- },
- {
- "name": "RevertToSelf",
- "address": "0x10077034"
- },
- {
- "name": "OpenSCManagerA",
- "address": "0x10077038"
- },
- {
- "name": "AllocateLocallyUniqueId",
- "address": "0x1007703c"
- },
- {
- "name": "RegDeleteValueA",
- "address": "0x10077040"
- },
- {
- "name": "ChangeServiceConfigW",
- "address": "0x10077044"
- },
- {
- "name": "ImpersonateLoggedOnUser",
- "address": "0x10077048"
- },
- {
- "name": "QueryServiceStatus",
- "address": "0x1007704c"
- },
- {
- "name": "RegCreateKeyExA",
- "address": "0x10077050"
- },
- {
- "name": "StartServiceA",
- "address": "0x10077054"
- },
- {
- "name": "SetTokenInformation",
- "address": "0x10077058"
- },
- {
- "name": "CreateProcessAsUserW",
- "address": "0x1007705c"
- },
- {
- "name": "RegSetValueExA",
- "address": "0x10077060"
- },
- {
- "name": "CopySid",
- "address": "0x10077064"
- },
- {
- "name": "InitializeSecurityDescriptor",
- "address": "0x10077068"
- }
- ],
- "dll": "ADVAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "sscanf",
- "address": "0x100773d4"
- },
- {
- "name": "isupper",
- "address": "0x100773d8"
- },
- {
- "name": "_strnicmp",
- "address": "0x100773dc"
- },
- {
- "name": "tolower",
- "address": "0x100773e0"
- },
- {
- "name": "_aullshr",
- "address": "0x100773e4"
- },
- {
- "name": "qsort",
- "address": "0x100773e8"
- },
- {
- "name": "strncpy",
- "address": "0x100773ec"
- },
- {
- "name": "wcsstr",
- "address": "0x100773f0"
- },
- {
- "name": "strtoul",
- "address": "0x100773f4"
- },
- {
- "name": "strcmp",
- "address": "0x100773f8"
- },
- {
- "name": "memcmp",
- "address": "0x100773fc"
- },
- {
- "name": "_aulldiv",
- "address": "0x10077400"
- },
- {
- "name": "_aullrem",
- "address": "0x10077404"
- },
- {
- "name": "strncmp",
- "address": "0x10077408"
- },
- {
- "name": "sprintf",
- "address": "0x1007740c"
- },
- {
- "name": "NtCreateToken",
- "address": "0x10077410"
- },
- {
- "name": "RtlCompareMemory",
- "address": "0x10077414"
- },
- {
- "name": "RtlCreateUserThread",
- "address": "0x10077418"
- },
- {
- "name": "NtOpenProcess",
- "address": "0x1007741c"
- },
- {
- "name": "NtReadVirtualMemory",
- "address": "0x10077420"
- },
- {
- "name": "NtQuerySystemInformation",
- "address": "0x10077424"
- },
- {
- "name": "NtAllocateVirtualMemory",
- "address": "0x10077428"
- },
- {
- "name": "NtFreeVirtualMemory",
- "address": "0x1007742c"
- },
- {
- "name": "LdrLoadDll",
- "address": "0x10077430"
- },
- {
- "name": "NtDelayExecution",
- "address": "0x10077434"
- },
- {
- "name": "RtlAdjustPrivilege",
- "address": "0x10077438"
- },
- {
- "name": "NtClose",
- "address": "0x1007743c"
- },
- {
- "name": "RtlFreeUnicodeString",
- "address": "0x10077440"
- },
- {
- "name": "LdrGetProcedureAddress",
- "address": "0x10077444"
- },
- {
- "name": "RtlInitAnsiString",
- "address": "0x10077448"
- },
- {
- "name": "RtlAnsiStringToUnicodeString",
- "address": "0x1007744c"
- },
- {
- "name": "NtProtectVirtualMemory",
- "address": "0x10077450"
- },
- {
- "name": "RtlExitUserThread",
- "address": "0x10077454"
- }
- ],
- "dll": "ntdll.dll"
- },
- {
- "imports": [
- {
- "name": "InternetCanonicalizeUrlA",
- "address": "0x10077290"
- },
- {
- "name": "InternetConnectA",
- "address": "0x10077294"
- },
- {
- "name": "InternetQueryDataAvailable",
- "address": "0x10077298"
- },
- {
- "name": "InternetCrackUrlA",
- "address": "0x1007729c"
- },
- {
- "name": "InternetReadFile",
- "address": "0x100772a0"
- },
- {
- "name": "InternetSetOptionA",
- "address": "0x100772a4"
- },
- {
- "name": "HttpOpenRequestA",
- "address": "0x100772a8"
- },
- {
- "name": "HttpSendRequestA",
- "address": "0x100772ac"
- },
- {
- "name": "InternetOpenA",
- "address": "0x100772b0"
- },
- {
- "name": "InternetCloseHandle",
- "address": "0x100772b4"
- }
- ],
- "dll": "WININET.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": "rdp.dll",
- "actual_checksum": "0x000ad933",
- "overlay": null,
- "imagebase": "0x10000000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x10001840",
- "timestamp": "2011-02-07 01:14:47",
- "osversion": "5.1",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00075a00",
- "entropy": "6.71",
- "raw_address": "0x00000400",
- "virtual_size": "0x00075850",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00077000",
- "size_of_data": "0x00028800",
- "entropy": "6.02",
- "raw_address": "0x00075e00",
- "virtual_size": "0x000286d4",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x000a0000",
- "size_of_data": "0x00002c00",
- "entropy": "5.11",
- "raw_address": "0x0009e600",
- "virtual_size": "0x00005fb8",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x000a6000",
- "size_of_data": "0x00008000",
- "entropy": "5.67",
- "raw_address": "0x000a1200",
- "virtual_size": "0x00007f50",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x0009f630",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x000000a4"
- },
- {
- "virtual_address": "0x0009deb4",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000154"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x000a6000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00006104"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00077000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000474"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [
- {
- "ordinal": 1,
- "name": "GetPluginId",
- "address": "0x1006528b"
- },
- {
- "ordinal": 2,
- "name": "Init",
- "address": "0x10065962"
- },
- {
- "ordinal": 3,
- "name": "RdpGetLastError",
- "address": "0x100652a3"
- },
- {
- "ordinal": 4,
- "name": "Start",
- "address": "0x1006574d"
- },
- {
- "ordinal": 5,
- "name": "Stop",
- "address": "0x10065739"
- },
- {
- "ordinal": 6,
- "name": "TakeBotGuid",
- "address": "0x1006528e"
- }
- ],
- "guest_signers": {},
- "imphash": "1029db349f713aef4385f023c10d8e2e",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 16,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "_errno",
- "address": "0x10077318"
- },
- {
- "name": "_initterm",
- "address": "0x1007731c"
- },
- {
- "name": "_amsg_exit",
- "address": "0x10077320"
- },
- {
- "name": "_adjust_fdiv",
- "address": "0x10077324"
- },
- {
- "name": "isdigit",
- "address": "0x10077328"
- },
- {
- "name": "isxdigit",
- "address": "0x1007732c"
- },
- {
- "name": "_XcptFilter",
- "address": "0x10077330"
- },
- {
- "name": "isspace",
- "address": "0x10077334"
- },
- {
- "name": "free",
- "address": "0x10077338"
- },
- {
- "name": "malloc",
- "address": "0x1007733c"
- },
- {
- "name": "memmove",
- "address": "0x10077340"
- },
- {
- "name": "atoi",
- "address": "0x10077344"
- },
- {
- "name": "_snprintf",
- "address": "0x10077348"
- },
- {
- "name": "strcat",
- "address": "0x1007734c"
- },
- {
- "name": "memset",
- "address": "0x10077350"
- },
- {
- "name": "strcpy",
- "address": "0x10077354"
- },
- {
- "name": "strstr",
- "address": "0x10077358"
- },
- {
- "name": "strlen",
- "address": "0x1007735c"
- },
- {
- "name": "memcpy",
- "address": "0x10077360"
- },
- {
- "name": "_iob",
- "address": "0x10077364"
- },
- {
- "name": "strchr",
- "address": "0x10077368"
- },
- {
- "name": "_vsnprintf",
- "address": "0x1007736c"
- },
- {
- "name": "_getch",
- "address": "0x10077370"
- },
- {
- "name": "signal",
- "address": "0x10077374"
- },
- {
- "name": "fputs",
- "address": "0x10077378"
- },
- {
- "name": "_gmtime64",
- "address": "0x1007737c"
- },
- {
- "name": "raise",
- "address": "0x10077380"
- },
- {
- "name": "_exit",
- "address": "0x10077384"
- },
- {
- "name": "vfprintf",
- "address": "0x10077388"
- },
- {
- "name": "getenv",
- "address": "0x1007738c"
- },
- {
- "name": "fprintf",
- "address": "0x10077390"
- },
- {
- "name": "_wfopen",
- "address": "0x10077394"
- },
- {
- "name": "fgets",
- "address": "0x10077398"
- },
- {
- "name": "fseek",
- "address": "0x1007739c"
- },
- {
- "name": "ftell",
- "address": "0x100773a0"
- },
- {
- "name": "_setmode",
- "address": "0x100773a4"
- },
- {
- "name": "fflush",
- "address": "0x100773a8"
- },
- {
- "name": "fwrite",
- "address": "0x100773ac"
- },
- {
- "name": "_time64",
- "address": "0x100773b0"
- },
- {
- "name": "fopen",
- "address": "0x100773b4"
- },
- {
- "name": "feof",
- "address": "0x100773b8"
- },
- {
- "name": "fclose",
- "address": "0x100773bc"
- },
- {
- "name": "fread",
- "address": "0x100773c0"
- },
- {
- "name": "ferror",
- "address": "0x100773c4"
- },
- {
- "name": "realloc",
- "address": "0x100773c8"
- },
- {
- "name": "_fileno",
- "address": "0x100773cc"
- }
- ],
- "dll": "msvcrt.dll"
- },
- {
- "imports": [
- {
- "name": "SetBitmapBits",
- "address": "0x10077070"
- },
- {
- "name": "CreateDIBSection",
- "address": "0x10077074"
- },
- {
- "name": "DeleteObject",
- "address": "0x10077078"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x1007707c"
- }
- ],
- "dll": "GDI32.dll"
- },
- {
- "imports": [
- {
- "name": "GetOpenFileNameA",
- "address": "0x10077310"
- }
- ],
- "dll": "comdlg32.dll"
- },
- {
- "imports": [
- {
- "name": "CoGetObject",
- "address": "0x1007745c"
- },
- {
- "name": "CoInitialize",
- "address": "0x10077460"
- },
- {
- "name": "CoUninitialize",
- "address": "0x10077464"
- },
- {
- "name": "CoCreateInstance",
- "address": "0x10077468"
- },
- {
- "name": "CoInitializeEx",
- "address": "0x1007746c"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "SetupDiCreateDeviceInfoW",
- "address": "0x100771bc"
- },
- {
- "name": "SetupDiCallClassInstaller",
- "address": "0x100771c0"
- },
- {
- "name": "SetupDiGetDeviceRegistryPropertyW",
- "address": "0x100771c4"
- },
- {
- "name": "SetupDiDestroyDeviceInfoList",
- "address": "0x100771c8"
- },
- {
- "name": "SetupDiEnumDeviceInfo",
- "address": "0x100771cc"
- },
- {
- "name": "SetupDiGetINFClassW",
- "address": "0x100771d0"
- },
- {
- "name": "SetupDiSetDeviceRegistryPropertyW",
- "address": "0x100771d4"
- },
- {
- "name": "SetupDiGetClassDevsW",
- "address": "0x100771d8"
- },
- {
- "name": "SetupDiCreateDeviceInfoList",
- "address": "0x100771dc"
- }
- ],
- "dll": "SETUPAPI.dll"
- },
- {
- "imports": [
- {
- "name": "StrPBrkA",
- "address": "0x100771f8"
- },
- {
- "name": "StrSpnA",
- "address": "0x100771fc"
- },
- {
- "name": "StrRStrIA",
- "address": "0x10077200"
- }
- ],
- "dll": "SHLWAPI.dll"
- },
- {
- "imports": [
- {
- "name": "inet_addr",
- "address": "0x100772bc"
- },
- {
- "name": "gethostbyaddr",
- "address": "0x100772c0"
- },
- {
- "name": "closesocket",
- "address": "0x100772c4"
- },
- {
- "name": "__WSAFDIsSet",
- "address": "0x100772c8"
- },
- {
- "name": "socket",
- "address": "0x100772cc"
- },
- {
- "name": "getsockopt",
- "address": "0x100772d0"
- },
- {
- "name": "ioctlsocket",
- "address": "0x100772d4"
- },
- {
- "name": "connect",
- "address": "0x100772d8"
- },
- {
- "name": "WSAStartup",
- "address": "0x100772dc"
- },
- {
- "name": "send",
- "address": "0x100772e0"
- },
- {
- "name": "select",
- "address": "0x100772e4"
- },
- {
- "name": "WSAGetLastError",
- "address": "0x100772e8"
- },
- {
- "name": "htons",
- "address": "0x100772ec"
- },
- {
- "name": "recv",
- "address": "0x100772f0"
- }
- ],
- "dll": "WS2_32.dll"
- },
- {
- "imports": [
- {
- "name": "SHFileOperationA",
- "address": "0x100771e4"
- },
- {
- "name": "ShellExecuteExW",
- "address": "0x100771e8"
- },
- {
- "name": "DragAcceptFiles",
- "address": "0x100771ec"
- },
- {
- "name": "DragQueryFileA",
- "address": "0x100771f0"
- }
- ],
- "dll": "SHELL32.dll"
- },
- {
- "imports": [
- {
- "name": "WTSEnumerateSessionsA",
- "address": "0x100772f8"
- },
- {
- "name": "WTSQueryUserToken",
- "address": "0x100772fc"
- },
- {
- "name": "WTSFreeMemory",
- "address": "0x10077300"
- },
- {
- "name": "WTSQuerySessionInformationA",
- "address": "0x10077304"
- },
- {
- "name": "WTSLogoffSession",
- "address": "0x10077308"
- }
- ],
- "dll": "WTSAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "GetProfilesDirectoryA",
- "address": "0x10077280"
- },
- {
- "name": "CreateEnvironmentBlock",
- "address": "0x10077284"
- },
- {
- "name": "DestroyEnvironmentBlock",
- "address": "0x10077288"
- }
- ],
- "dll": "USERENV.dll"
- },
- {
- "imports": [
- {
- "name": "NetUserDel",
- "address": "0x100771a4"
- },
- {
- "name": "NetLocalGroupEnum",
- "address": "0x100771a8"
- },
- {
- "name": "NetApiBufferFree",
- "address": "0x100771ac"
- },
- {
- "name": "NetUserAdd",
- "address": "0x100771b0"
- },
- {
- "name": "NetLocalGroupAddMembers",
- "address": "0x100771b4"
- }
- ],
- "dll": "NETAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x10077084"
- },
- {
- "name": "GetTickCount",
- "address": "0x10077088"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x1007708c"
- },
- {
- "name": "SetUnhandledExceptionFilter",
- "address": "0x10077090"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x10077094"
- },
- {
- "name": "InterlockedCompareExchange",
- "address": "0x10077098"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x1007709c"
- },
- {
- "name": "RtlUnwind",
- "address": "0x100770a0"
- },
- {
- "name": "lstrcatA",
- "address": "0x100770a4"
- },
- {
- "name": "TerminateThread",
- "address": "0x100770a8"
- },
- {
- "name": "WriteProcessMemory",
- "address": "0x100770ac"
- },
- {
- "name": "VirtualAllocEx",
- "address": "0x100770b0"
- },
- {
- "name": "GetTempPathW",
- "address": "0x100770b4"
- },
- {
- "name": "TerminateProcess",
- "address": "0x100770b8"
- },
- {
- "name": "lstrcpynW",
- "address": "0x100770bc"
- },
- {
- "name": "CopyFileW",
- "address": "0x100770c0"
- },
- {
- "name": "VirtualFreeEx",
- "address": "0x100770c4"
- },
- {
- "name": "OpenProcess",
- "address": "0x100770c8"
- },
- {
- "name": "CreateRemoteThread",
- "address": "0x100770cc"
- },
- {
- "name": "VirtualFree",
- "address": "0x100770d0"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x100770d4"
- },
- {
- "name": "ProcessIdToSessionId",
- "address": "0x100770d8"
- },
- {
- "name": "GetStdHandle",
- "address": "0x100770dc"
- },
- {
- "name": "GlobalMemoryStatus",
- "address": "0x100770e0"
- },
- {
- "name": "FlushConsoleInputBuffer",
- "address": "0x100770e4"
- },
- {
- "name": "GetFileType",
- "address": "0x100770e8"
- },
- {
- "name": "lstrcmpiA",
- "address": "0x100770ec"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x100770f0"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x100770f4"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x100770f8"
- },
- {
- "name": "lstrcpynA",
- "address": "0x100770fc"
- },
- {
- "name": "TryEnterCriticalSection",
- "address": "0x10077100"
- },
- {
- "name": "LocalFree",
- "address": "0x10077104"
- },
- {
- "name": "lstrcmpiW",
- "address": "0x10077108"
- },
- {
- "name": "LocalAlloc",
- "address": "0x1007710c"
- },
- {
- "name": "lstrlenW",
- "address": "0x10077110"
- },
- {
- "name": "FreeLibrary",
- "address": "0x10077114"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x10077118"
- },
- {
- "name": "lstrcpyA",
- "address": "0x1007711c"
- },
- {
- "name": "CreateThread",
- "address": "0x10077120"
- },
- {
- "name": "lstrcpyW",
- "address": "0x10077124"
- },
- {
- "name": "GetWindowsDirectoryW",
- "address": "0x10077128"
- },
- {
- "name": "CloseHandle",
- "address": "0x1007712c"
- },
- {
- "name": "GetVersionExA",
- "address": "0x10077130"
- },
- {
- "name": "CreateMutexA",
- "address": "0x10077134"
- },
- {
- "name": "lstrcatW",
- "address": "0x10077138"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x1007713c"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x10077140"
- },
- {
- "name": "CreateFileMappingA",
- "address": "0x10077144"
- },
- {
- "name": "SetLastError",
- "address": "0x10077148"
- },
- {
- "name": "ExitThread",
- "address": "0x1007714c"
- },
- {
- "name": "CreateFileW",
- "address": "0x10077150"
- },
- {
- "name": "Sleep",
- "address": "0x10077154"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x10077158"
- },
- {
- "name": "UnmapViewOfFile",
- "address": "0x1007715c"
- },
- {
- "name": "MapViewOfFile",
- "address": "0x10077160"
- },
- {
- "name": "lstrlenA",
- "address": "0x10077164"
- },
- {
- "name": "ExitProcess",
- "address": "0x10077168"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x1007716c"
- },
- {
- "name": "OutputDebugStringA",
- "address": "0x10077170"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x10077174"
- },
- {
- "name": "GetLastError",
- "address": "0x10077178"
- },
- {
- "name": "HeapValidate",
- "address": "0x1007717c"
- },
- {
- "name": "GetVersion",
- "address": "0x10077180"
- },
- {
- "name": "VirtualQuery",
- "address": "0x10077184"
- },
- {
- "name": "GetProcAddress",
- "address": "0x10077188"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x1007718c"
- },
- {
- "name": "VirtualProtect",
- "address": "0x10077190"
- },
- {
- "name": "GetProcessHeap",
- "address": "0x10077194"
- },
- {
- "name": "HeapFree",
- "address": "0x10077198"
- },
- {
- "name": "HeapAlloc",
- "address": "0x1007719c"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "TranslateMessage",
- "address": "0x10077208"
- },
- {
- "name": "GetWindowTextA",
- "address": "0x1007720c"
- },
- {
- "name": "RegisterClassExA",
- "address": "0x10077210"
- },
- {
- "name": "MessageBoxA",
- "address": "0x10077214"
- },
- {
- "name": "CreateWindowExA",
- "address": "0x10077218"
- },
- {
- "name": "DefWindowProcA",
- "address": "0x1007721c"
- },
- {
- "name": "ShowWindow",
- "address": "0x10077220"
- },
- {
- "name": "DispatchMessageA",
- "address": "0x10077224"
- },
- {
- "name": "SetWindowTextA",
- "address": "0x10077228"
- },
- {
- "name": "UpdateWindow",
- "address": "0x1007722c"
- },
- {
- "name": "SendMessageA",
- "address": "0x10077230"
- },
- {
- "name": "SetFocus",
- "address": "0x10077234"
- },
- {
- "name": "LoadIconA",
- "address": "0x10077238"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x1007723c"
- },
- {
- "name": "SetWindowLongA",
- "address": "0x10077240"
- },
- {
- "name": "GetMessageA",
- "address": "0x10077244"
- },
- {
- "name": "CharLowerW",
- "address": "0x10077248"
- },
- {
- "name": "GetUserObjectInformationW",
- "address": "0x1007724c"
- },
- {
- "name": "GetProcessWindowStation",
- "address": "0x10077250"
- },
- {
- "name": "GetDC",
- "address": "0x10077254"
- },
- {
- "name": "ReleaseDC",
- "address": "0x10077258"
- },
- {
- "name": "GetDesktopWindow",
- "address": "0x1007725c"
- },
- {
- "name": "wsprintfA",
- "address": "0x10077260"
- },
- {
- "name": "IsDialogMessageA",
- "address": "0x10077264"
- },
- {
- "name": "CallWindowProcA",
- "address": "0x10077268"
- },
- {
- "name": "LoadCursorA",
- "address": "0x1007726c"
- },
- {
- "name": "MoveWindow",
- "address": "0x10077270"
- },
- {
- "name": "wsprintfW",
- "address": "0x10077274"
- },
- {
- "name": "wvsprintfA",
- "address": "0x10077278"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x10077000"
- },
- {
- "name": "SetSecurityDescriptorDacl",
- "address": "0x10077004"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x10077008"
- },
- {
- "name": "RegCloseKey",
- "address": "0x1007700c"
- },
- {
- "name": "OpenServiceA",
- "address": "0x10077010"
- },
- {
- "name": "LookupAccountNameA",
- "address": "0x10077014"
- },
- {
- "name": "GetTokenInformation",
- "address": "0x10077018"
- },
- {
- "name": "RegisterEventSourceA",
- "address": "0x1007701c"
- },
- {
- "name": "ReportEventA",
- "address": "0x10077020"
- },
- {
- "name": "DeregisterEventSource",
- "address": "0x10077024"
- },
- {
- "name": "GetLengthSid",
- "address": "0x10077028"
- },
- {
- "name": "GetUserNameA",
- "address": "0x1007702c"
- },
- {
- "name": "QueryServiceConfigA",
- "address": "0x10077030"
- },
- {
- "name": "RevertToSelf",
- "address": "0x10077034"
- },
- {
- "name": "OpenSCManagerA",
- "address": "0x10077038"
- },
- {
- "name": "AllocateLocallyUniqueId",
- "address": "0x1007703c"
- },
- {
- "name": "RegDeleteValueA",
- "address": "0x10077040"
- },
- {
- "name": "ChangeServiceConfigW",
- "address": "0x10077044"
- },
- {
- "name": "ImpersonateLoggedOnUser",
- "address": "0x10077048"
- },
- {
- "name": "QueryServiceStatus",
- "address": "0x1007704c"
- },
- {
- "name": "RegCreateKeyExA",
- "address": "0x10077050"
- },
- {
- "name": "StartServiceA",
- "address": "0x10077054"
- },
- {
- "name": "SetTokenInformation",
- "address": "0x10077058"
- },
- {
- "name": "CreateProcessAsUserW",
- "address": "0x1007705c"
- },
- {
- "name": "RegSetValueExA",
- "address": "0x10077060"
- },
- {
- "name": "CopySid",
- "address": "0x10077064"
- },
- {
- "name": "InitializeSecurityDescriptor",
- "address": "0x10077068"
- }
- ],
- "dll": "ADVAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "sscanf",
- "address": "0x100773d4"
- },
- {
- "name": "isupper",
- "address": "0x100773d8"
- },
- {
- "name": "_strnicmp",
- "address": "0x100773dc"
- },
- {
- "name": "tolower",
- "address": "0x100773e0"
- },
- {
- "name": "_aullshr",
- "address": "0x100773e4"
- },
- {
- "name": "qsort",
- "address": "0x100773e8"
- },
- {
- "name": "strncpy",
- "address": "0x100773ec"
- },
- {
- "name": "wcsstr",
- "address": "0x100773f0"
- },
- {
- "name": "strtoul",
- "address": "0x100773f4"
- },
- {
- "name": "strcmp",
- "address": "0x100773f8"
- },
- {
- "name": "memcmp",
- "address": "0x100773fc"
- },
- {
- "name": "_aulldiv",
- "address": "0x10077400"
- },
- {
- "name": "_aullrem",
- "address": "0x10077404"
- },
- {
- "name": "strncmp",
- "address": "0x10077408"
- },
- {
- "name": "sprintf",
- "address": "0x1007740c"
- },
- {
- "name": "NtCreateToken",
- "address": "0x10077410"
- },
- {
- "name": "RtlCompareMemory",
- "address": "0x10077414"
- },
- {
- "name": "RtlCreateUserThread",
- "address": "0x10077418"
- },
- {
- "name": "NtOpenProcess",
- "address": "0x1007741c"
- },
- {
- "name": "NtReadVirtualMemory",
- "address": "0x10077420"
- },
- {
- "name": "NtQuerySystemInformation",
- "address": "0x10077424"
- },
- {
- "name": "NtAllocateVirtualMemory",
- "address": "0x10077428"
- },
- {
- "name": "NtFreeVirtualMemory",
- "address": "0x1007742c"
- },
- {
- "name": "LdrLoadDll",
- "address": "0x10077430"
- },
- {
- "name": "NtDelayExecution",
- "address": "0x10077434"
- },
- {
- "name": "RtlAdjustPrivilege",
- "address": "0x10077438"
- },
- {
- "name": "NtClose",
- "address": "0x1007743c"
- },
- {
- "name": "RtlFreeUnicodeString",
- "address": "0x10077440"
- },
- {
- "name": "LdrGetProcedureAddress",
- "address": "0x10077444"
- },
- {
- "name": "RtlInitAnsiString",
- "address": "0x10077448"
- },
- {
- "name": "RtlAnsiStringToUnicodeString",
- "address": "0x1007744c"
- },
- {
- "name": "NtProtectVirtualMemory",
- "address": "0x10077450"
- },
- {
- "name": "RtlExitUserThread",
- "address": "0x10077454"
- }
- ],
- "dll": "ntdll.dll"
- },
- {
- "imports": [
- {
- "name": "InternetCanonicalizeUrlA",
- "address": "0x10077290"
- },
- {
- "name": "InternetConnectA",
- "address": "0x10077294"
- },
- {
- "name": "InternetQueryDataAvailable",
- "address": "0x10077298"
- },
- {
- "name": "InternetCrackUrlA",
- "address": "0x1007729c"
- },
- {
- "name": "InternetReadFile",
- "address": "0x100772a0"
- },
- {
- "name": "InternetSetOptionA",
- "address": "0x100772a4"
- },
- {
- "name": "HttpOpenRequestA",
- "address": "0x100772a8"
- },
- {
- "name": "HttpSendRequestA",
- "address": "0x100772ac"
- },
- {
- "name": "InternetOpenA",
- "address": "0x100772b0"
- },
- {
- "name": "InternetCloseHandle",
- "address": "0x100772b4"
- }
- ],
- "dll": "WININET.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": "rdp.dll",
- "actual_checksum": "0x000ad933",
- "overlay": null,
- "imagebase": "0x10000000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x10001840",
- "timestamp": "2011-02-07 01:14:47",
- "osversion": "5.1",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00075a00",
- "entropy": "6.71",
- "raw_address": "0x00000400",
- "virtual_size": "0x00075850",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00077000",
- "size_of_data": "0x00028800",
- "entropy": "6.02",
- "raw_address": "0x00075e00",
- "virtual_size": "0x000286d4",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x000a0000",
- "size_of_data": "0x00002c00",
- "entropy": "5.11",
- "raw_address": "0x0009e600",
- "virtual_size": "0x00005fb8",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x000a6000",
- "size_of_data": "0x00008000",
- "entropy": "5.67",
- "raw_address": "0x000a1200",
- "virtual_size": "0x00007f50",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x0009f630",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x000000a4"
- },
- {
- "virtual_address": "0x0009deb4",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000154"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x000a6000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00006104"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00077000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000474"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [
- {
- "ordinal": 1,
- "name": "GetPluginId",
- "address": "0x1006528b"
- },
- {
- "ordinal": 2,
- "name": "Init",
- "address": "0x10065962"
- },
- {
- "ordinal": 3,
- "name": "RdpGetLastError",
- "address": "0x100652a3"
- },
- {
- "ordinal": 4,
- "name": "Start",
- "address": "0x1006574d"
- },
- {
- "ordinal": 5,
- "name": "Stop",
- "address": "0x10065739"
- },
- {
- "ordinal": 6,
- "name": "TakeBotGuid",
- "address": "0x1006528e"
- }
- ],
- "guest_signers": {},
- "imphash": "1029db349f713aef4385f023c10d8e2e",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 16,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement