Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: "Malicious"
- [*] MalScore: 10.0
- [*] File Name: "Exes_1041a40ae942bac15568c6adcb433e95.exe"
- [*] File Size: 224768
- [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- [*] SHA256: "0e5833cdcd2deb3e8ea043637fb0bd2305bc2ac30b81bac9479c21f7cd038933"
- [*] MD5: "1041a40ae942bac15568c6adcb433e95"
- [*] SHA1: "44ec41b9af513a812eabd50a999120630188f0e1"
- [*] SHA512: "3b65ce57781812830cbd18dd468d7d6e832c7e226307925cd6b9d078d95e95533b95ca9c03702b3e2cd96ee88576ee9a06cc8c001f8b20ceb25fbcefc8b60553"
- [*] CRC32: "DA9767EE"
- [*] SSDEEP: "3072:Isor0OB/v5O2iw2Wy0ufU9gnHBnGYkxIclJ5hNli9rxaBNEXhX5f+l5xRp0:FmB/42iInqHdBkeWNli9rU2Crxr"
- [*] Process Execution: [
- "Exes_1041a40ae942bac15568c6adcb433e95.exe",
- "svchost.exe",
- "WmiPrvSE.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "iexplore.exe",
- "svchost.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details": [
- {
- "IP": "37.10.71.253:80"
- }
- ]
- },
- {
- "Description": "Creates RWX memory",
- "Details": []
- },
- {
- "Description": "A process attempted to delay the analysis task.",
- "Details": [
- {
- "Process": "Exes_1041a40ae942bac15568c6adcb433e95.exe tried to sleep 1680 seconds, actually delayed analysis time by 0 seconds"
- },
- {
- "Process": "WmiPrvSE.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
- }
- ]
- },
- {
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details": [
- {
- "section": "name: .text, entropy: 7.02, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x00028000, virtual_size: 0x00027e2c"
- }
- ]
- },
- {
- "Description": "Crashed cuckoomon during analysis. Report this error to the Github repo.",
- "Details": [
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x1967e in cuckoomon itself while accessing 0x3fd0c4 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19681 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19681 in cuckoomon itself while accessing 0x3fd0c8 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19684 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19684 in cuckoomon itself while accessing 0x3fd0c0 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19687 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19687 in cuckoomon itself while accessing 0x3fd0bc from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19689 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19699 in cuckoomon itself while accessing 0x3fd0cc from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x1969b in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x1969f in cuckoomon itself while accessing 0x3fd0d0 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x196a2 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x196aa in cuckoomon itself while accessing 0x3fd0d4 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x196ad in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x196bd in cuckoomon itself while accessing 0x3fd0d8 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x196c0 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19bfc in cuckoomon itself while accessing 0x3fd0bc from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19bfe in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19bfe in cuckoomon itself while accessing 0x3fd0c0 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19c01 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19c01 in cuckoomon itself while accessing 0x3fd0c4 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19c04 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19c04 in cuckoomon itself while accessing 0x3fd0c8 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19c07 in cuckoomon itself while accessing 0x0 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x1967e in cuckoomon itself while accessing 0x3fd030 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19681 in cuckoomon itself while accessing 0x3fd034 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19684 in cuckoomon itself while accessing 0x3fd02c from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19687 in cuckoomon itself while accessing 0x3fd028 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19699 in cuckoomon itself while accessing 0x3fd048 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x1969f in cuckoomon itself while accessing 0x3fd04c from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x196aa in cuckoomon itself while accessing 0x3fd050 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x196bd in cuckoomon itself while accessing 0x3fd054 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19bfc in cuckoomon itself while accessing 0x3fd028 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19bfe in cuckoomon itself while accessing 0x3fd02c from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19c01 in cuckoomon itself while accessing 0x3fd030 from hook RtlDispatchException"
- },
- {
- "pid": 1644
- },
- {
- "message": "Exception reported at offset 0x19c04 in cuckoomon itself while accessing 0x3fd034 from hook RtlDispatchException"
- }
- ]
- },
- {
- "Description": "Creates a hidden or system file",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\IETldCache\\Low"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF16e296d.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF16fef29.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF16f70a2.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF17131cb.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF170b6af.TMP"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF1727fb7.TMP"
- }
- ]
- },
- {
- "Description": "File has been identified by 18 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "FireEye": "Generic.mg.1041a40ae942bac1"
- },
- {
- "Cylance": "Unsafe"
- },
- {
- "APEX": "Malicious"
- },
- {
- "Kaspersky": "UDS:DangerousObject.Multi.Generic"
- },
- {
- "Rising": "Trojan.Fuery!8.EAFB (TFE:6:9oQ0c2nvfYB)"
- },
- {
- "Endgame": "malicious (high confidence)"
- },
- {
- "Comodo": "TrojWare.Win32.Fakecsrss.AV@88nqyj"
- },
- {
- "Fortinet": "W32/GenKryptik.DMEL!tr"
- },
- {
- "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
- },
- {
- "Microsoft": "Trojan:Win32/Wacatac.B!ml"
- },
- {
- "AhnLab-V3": "Win-Trojan/MalPe14.Suspicious"
- },
- {
- "Acronis": "suspicious"
- },
- {
- "VBA32": "BScope.Trojan.Chapak"
- },
- {
- "Malwarebytes": "Trojan.MalPack.GS"
- },
- {
- "SentinelOne": "DFI - Suspicious PE"
- },
- {
- "Cybereason": "malicious.9af513"
- },
- {
- "CrowdStrike": "win/malicious_confidence_100% (D)"
- },
- {
- "Qihoo-360": "HEUR/QVM10.1.468D.Malware.Gen"
- }
- ]
- },
- {
- "Description": "Attempts to modify proxy settings",
- "Details": []
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: [
- "C:\\Windows\\sysWOW64\\wbem\\wmiprvse.exe -secured -Embedding",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" -Embedding",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2660 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2568 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2476 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1860 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2580 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:1216 CREDAT:79873",
- "\"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe\" SCODEF:2976 CREDAT:79873"
- ]
- [*] Mutexes: [
- "Local\\_!MSFTHISTORY!_",
- "Local\\c:!users!user!appdata!local!microsoft!windows!temporary internet files!content.ie5!",
- "Local\\c:!users!user!appdata!roaming!microsoft!windows!cookies!",
- "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!",
- "Local\\WininetStartupMutex",
- "Local\\WininetConnectionMutex",
- "Local\\WininetProxyRegistryMutex",
- "Local\\!IETld!Mutex",
- "Local\\!BrowserEmulation!SharedMemory!Mutex",
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex",
- "ConnHashTable<2660>_HashTable_Mutex",
- "Local\\ZonesCounterMutex",
- "Local\\RSS Eventing Connection Database Mutex 00000a64",
- "Local\\Feed Eventing Shared Memory Mutex S-1-5-21-0000000000-0000000000-0000000000-1000",
- "Local\\c:!users!user!appdata!local!microsoft!feeds cache!",
- "Local\\Feed Arbitration Shared Memory Mutex [ User : S-1-5-21-0000000000-0000000000-0000000000-1000 ]",
- "Local\\Feeds Store Mutex S-1-5-21-0000000000-0000000000-0000000000-1000",
- "Local\\c:!users!user!appdata!roaming!microsoft!windows!privacie!",
- "ConnHashTable<2568>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 00000a08",
- "ConnHashTable<2476>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 000009ac",
- "ConnHashTable<1860>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 00000744",
- "ConnHashTable<2580>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 00000a14",
- "ConnHashTable<1216>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 000004c0",
- "ConnHashTable<2976>_HashTable_Mutex",
- "Local\\RSS Eventing Connection Database Mutex 00000ba0"
- ]
- [*] Modified Files: [
- "\\??\\PIPE\\samr",
- "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
- "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\index.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\index.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{B77711AB-9D89-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF5BC20EE18C8A4301.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{B77711AC-9D89-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF66A69E9F015BDE61.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Feeds Cache\\index.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Feeds\\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\\WebSlices~\\Suggested Sites~.feed-ms",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF812574474DC9815F.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFFD04397F93B1FBFA.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF8968750AB14A3065.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF5FD0A12469A71414.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Feeds\\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\\WebSlices~\\Web Slice Gallery~.feed-ms",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFE50F800843C99E22.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB87935AB60A8F292.TMP",
- "\\??\\pipe\\MsFteWds",
- "\\??\\PIPE\\srvsvc",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\6IJOKUK0TZKPG07T1L9X.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF16e296d.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\dnserror[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\dnserror[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\ErrorPageTemplate[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\ErrorPageTemplate[2]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\PrivacIE\\index.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\errorPageStrings[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\httpErrorPagesScripts[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\httpErrorPagesScripts[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\noConnect[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\noConnect[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\background_gradient[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\down[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\favcenter[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\tools[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{CEB5FF2B-9D89-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFA0040182A9BD9E43.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{CEB5FF2C-9D89-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF93C5AB754866E51C.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF8A254AE18FBD023B.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF4D51F8944394E54B.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFD9B26D3636ED010E.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF4E0A17C2F15DAB7D.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF89CC6FFC14F6C20B.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFE29098B9ACD2F5F1.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\1ZBV1RLMRQJAMGHQI3WR.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF16fef29.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\dnserror[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\errorPageStrings[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\httpErrorPagesScripts[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\background_gradient[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\down[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\favcenter[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\tools[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{EA2F5847-9D89-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF745A15DB1CC26EAD.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{EA2F5848-9D89-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF396763DE98B0ADBA.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF1893F2DDD73BD92F.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFBD40AAF188108C70.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF1EB1A0B54AB0868E.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF22EB62F3CA4B4318.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF4B0F39CC91BF682C.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFA2AD1F8C4B60CAD8.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\9NK1DO4BXNHF6IKMLGE8.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF16f70a2.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\dnserror[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\ErrorPageTemplate[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\httpErrorPagesScripts[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\noConnect[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\down[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\tools[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{00AF89A7-9D8A-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF689D28D62C77C0A0.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{00AF89A8-9D8A-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF33BBF0C596F82614.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF3E1FFCA05C8A5297.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF354C6E11CD8B0183.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFA8C98BCF9E649581.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB708E6520DAD3C6C.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFA7F123886746C91B.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF62D090EEA952728B.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\RUIG9LP9S0UXB0VK1014.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF17131cb.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\dnserror[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\ErrorPageTemplate[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\errorPageStrings[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\noConnect[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\background_gradient[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\favcenter[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{1BAA8621-9D8A-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFD0A56C16F58E1E8D.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{1BAA8622-9D8A-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF9837D42DA01E2D5E.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF989E8DFD0196F6BF.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFD90FAC6FAF5A6E9F.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF56AEC8C2298892FD.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF89E93AE28A497139.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF85DA59EAE521CBD9.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB46600E259E9BF4B.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\BVREMS2OKAG42L0XJ6G1.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF170b6af.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\ErrorPageTemplate[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\errorPageStrings[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\httpErrorPagesScripts[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\background_gradient[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\down[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\tools[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{326B16FF-9D8A-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFBAD0DA99E3765DC4.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{326B1700-9D8A-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF479A483B3E26125A.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB287C0BC6C924E8D.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB3A0E65D6C51B063.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFECABD0C70A6D0950.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF0EB4A27CD6D50678.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF5E9448E89F60F88C.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFF2522EACBF2852E0.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\D26G95PHZLC0FLB97MZT.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF1727fb7.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\errorPageStrings[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\httpErrorPagesScripts[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\noConnect[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\down[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\favcenter[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{4EC22ACD-9D8A-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB5E20859E2A5D709.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{4EC22ACE-9D8A-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF9860E153C4522E65.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF494CAC105B05B06F.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFF314AEE672AF49CE.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFC73AA2480E24B4F0.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF04A814494DD1FD0A.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF468BED688D68AF91.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF4F4DB8CCA600F00E.TMP"
- ]
- [*] Deleted Files: [
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF16e296d.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{B77711AC-9D89-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{B77711AB-9D89-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\dnserror[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\ErrorPageTemplate[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\errorPageStrings[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\httpErrorPagesScripts[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\noConnect[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\background_gradient[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\down[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\favcenter[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\tools[1]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF16fef29.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{CEB5FF2C-9D89-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{CEB5FF2B-9D89-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\dnserror[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\ErrorPageTemplate[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\errorPageStrings[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\httpErrorPagesScripts[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\noConnect[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\background_gradient[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\down[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\favcenter[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\tools[1]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF16f70a2.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{EA2F5848-9D89-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{EA2F5847-9D89-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\dnserror[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\errorPageStrings[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\httpErrorPagesScripts[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\background_gradient[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\favcenter[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\tools[1]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF17131cb.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{00AF89A8-9D8A-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{00AF89A7-9D8A-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\dnserror[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\ErrorPageTemplate[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\httpErrorPagesScripts[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\noConnect[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\down[2]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF170b6af.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{1BAA8622-9D8A-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{1BAA8621-9D8A-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\dnserror[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\ErrorPageTemplate[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\errorPageStrings[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\background_gradient[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\noConnect[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\favcenter[2]",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\28c8b86deab549a1.customDestinations-ms~RF1727fb7.TMP",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\{326B1700-9D8A-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Internet Explorer\\Recovery\\High\\Active\\RecoveryStore.{326B16FF-9D8A-11E9-9533-18C086CD4731}.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\ErrorPageTemplate[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\errorPageStrings[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\httpErrorPagesScripts[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\background_gradient[2]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\down[1]",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\tools[2]"
- ]
- [*] Modified Registry Keys: [
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE10RunOnceLastShown",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE10RunOnceLastShown_TIMESTAMP",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE8RunOnceLastShown",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\IE8RunOnceLastShown_TIMESTAMP",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Internet Explorer\\Main\\Check_Associations",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\\VerCache",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\\VerCache",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Settings\\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\\VerCache",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\CompatibilityFlags",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\SecuritySafe",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyServer",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\SavedLegacySettings",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{B77711AB-9D89-11E9-9533-18C086CD4731}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{2670000A-7350-4F3C-8081-5663EE0C6C49}\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{2670000A-7350-4F3C-8081-5663EE0C6C49}\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{2670000A-7350-4F3C-8081-5663EE0C6C49}\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FullScreen",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MenuOrder\\Favorites\\Links\\Order",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\Path",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\Handler",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\FeedUrl",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\DisplayName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\ErrorState",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\DisplayMask",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\Path",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\Handler",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\FeedUrl",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\DisplayName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\ErrorState",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\DisplayMask",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\Expiration",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\Expiration",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}\\iexplore\\LoadTime",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\\iexplore\\LoadTime",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}\\iexplore\\LoadTime",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\\iexplore\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\\iexplore\\Count",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\\iexplore\\Time",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{CEB5FF2B-9D89-11E9-9533-18C086CD4731}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{EA2F5847-9D89-11E9-9533-18C086CD4731}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{00AF89A7-9D8A-11E9-9533-18C086CD4731}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\User Preferences\\88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\SearchScopes\\DefaultScope",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\User Preferences\\2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{1BAA8621-9D8A-11E9-9533-18C086CD4731}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{326B16FF-9D8A-11E9-9533-18C086CD4731}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{4EC22ACD-9D8A-11E9-9533-18C086CD4731}"
- ]
- [*] Deleted Registry Keys: [
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyOverride",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigURL",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\0\\Expiration",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LinksBar\\ItemCache\\1\\Expiration",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{B77711AB-9D89-11E9-9533-18C086CD4731}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFavoritesInitialSelection",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFeedsInitialSelection",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{CEB5FF2B-9D89-11E9-9533-18C086CD4731}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{EA2F5847-9D89-11E9-9533-18C086CD4731}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{00AF89A7-9D8A-11E9-9533-18C086CD4731}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{1BAA8621-9D8A-11E9-9533-18C086CD4731}",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AdminActive\\{326B16FF-9D8A-11E9-9533-18C086CD4731}"
- ]
- [*] DNS Communications: [
- {
- "type": "A",
- "request": "www.bing.com",
- "answers": []
- },
- {
- "type": "A",
- "request": "junglestyle.xyz",
- "answers": []
- }
- ]
- [*] Domains: [
- {
- "ip": "13.107.21.200",
- "domain": "www.bing.com"
- },
- {
- "ip": "37.10.71.253",
- "domain": "junglestyle.xyz"
- }
- ]
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "GetDriveTypeW",
- "address": "0x429000"
- },
- {
- "name": "WaitNamedPipeA",
- "address": "0x429004"
- },
- {
- "name": "SetEnvironmentVariableW",
- "address": "0x429008"
- },
- {
- "name": "MoveFileWithProgressA",
- "address": "0x42900c"
- },
- {
- "name": "GetModuleHandleW",
- "address": "0x429010"
- },
- {
- "name": "ExpandEnvironmentStringsA",
- "address": "0x429014"
- },
- {
- "name": "ReadConsoleW",
- "address": "0x429018"
- },
- {
- "name": "EnumTimeFormatsA",
- "address": "0x42901c"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x429020"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x429024"
- },
- {
- "name": "GetSystemDirectoryW",
- "address": "0x429028"
- },
- {
- "name": "AddRefActCtx",
- "address": "0x42902c"
- },
- {
- "name": "FormatMessageW",
- "address": "0x429030"
- },
- {
- "name": "SetConsoleCP",
- "address": "0x429034"
- },
- {
- "name": "IsProcessorFeaturePresent",
- "address": "0x429038"
- },
- {
- "name": "ReplaceFileW",
- "address": "0x42903c"
- },
- {
- "name": "GetStringTypeExA",
- "address": "0x429040"
- },
- {
- "name": "GetLastError",
- "address": "0x429044"
- },
- {
- "name": "DefineDosDeviceW",
- "address": "0x429048"
- },
- {
- "name": "GetFirmwareEnvironmentVariableW",
- "address": "0x42904c"
- },
- {
- "name": "GetProcessVersion",
- "address": "0x429050"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x429054"
- },
- {
- "name": "FindFirstVolumeMountPointW",
- "address": "0x429058"
- },
- {
- "name": "HeapLock",
- "address": "0x42905c"
- },
- {
- "name": "WaitForMultipleObjects",
- "address": "0x429060"
- },
- {
- "name": "GetVolumePathNamesForVolumeNameA",
- "address": "0x429064"
- },
- {
- "name": "WaitCommEvent",
- "address": "0x429068"
- },
- {
- "name": "VirtualProtect",
- "address": "0x42906c"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x429070"
- },
- {
- "name": "EnumSystemLocalesA",
- "address": "0x429074"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x429078"
- },
- {
- "name": "GetUserDefaultLCID",
- "address": "0x42907c"
- },
- {
- "name": "GetStringTypeW",
- "address": "0x429080"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x429084"
- },
- {
- "name": "LCMapStringW",
- "address": "0x429088"
- },
- {
- "name": "HeapReAlloc",
- "address": "0x42908c"
- },
- {
- "name": "HeapFree",
- "address": "0x429090"
- },
- {
- "name": "GetProcAddress",
- "address": "0x429094"
- },
- {
- "name": "ExitProcess",
- "address": "0x429098"
- },
- {
- "name": "DecodePointer",
- "address": "0x42909c"
- },
- {
- "name": "GetCommandLineW",
- "address": "0x4290a0"
- },
- {
- "name": "HeapSetInformation",
- "address": "0x4290a4"
- },
- {
- "name": "GetStartupInfoW",
- "address": "0x4290a8"
- },
- {
- "name": "HeapCreate",
- "address": "0x4290ac"
- },
- {
- "name": "HeapDestroy",
- "address": "0x4290b0"
- },
- {
- "name": "HeapAlloc",
- "address": "0x4290b4"
- },
- {
- "name": "InitializeCriticalSectionAndSpinCount",
- "address": "0x4290b8"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x4290bc"
- },
- {
- "name": "FatalAppExitA",
- "address": "0x4290c0"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x4290c4"
- },
- {
- "name": "EncodePointer",
- "address": "0x4290c8"
- },
- {
- "name": "SetConsoleCtrlHandler",
- "address": "0x4290cc"
- },
- {
- "name": "FreeLibrary",
- "address": "0x4290d0"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x4290d4"
- },
- {
- "name": "LoadLibraryW",
- "address": "0x4290d8"
- },
- {
- "name": "GetLocaleInfoW",
- "address": "0x4290dc"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x4290e0"
- },
- {
- "name": "SetUnhandledExceptionFilter",
- "address": "0x4290e4"
- },
- {
- "name": "IsDebuggerPresent",
- "address": "0x4290e8"
- },
- {
- "name": "TerminateProcess",
- "address": "0x4290ec"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x4290f0"
- },
- {
- "name": "TlsAlloc",
- "address": "0x4290f4"
- },
- {
- "name": "TlsGetValue",
- "address": "0x4290f8"
- },
- {
- "name": "TlsSetValue",
- "address": "0x4290fc"
- },
- {
- "name": "TlsFree",
- "address": "0x429100"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x429104"
- },
- {
- "name": "SetLastError",
- "address": "0x429108"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x42910c"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x429110"
- },
- {
- "name": "GetCurrentThread",
- "address": "0x429114"
- },
- {
- "name": "WriteFile",
- "address": "0x429118"
- },
- {
- "name": "GetStdHandle",
- "address": "0x42911c"
- },
- {
- "name": "GetModuleFileNameW",
- "address": "0x429120"
- },
- {
- "name": "FreeEnvironmentStringsW",
- "address": "0x429124"
- },
- {
- "name": "GetEnvironmentStringsW",
- "address": "0x429128"
- },
- {
- "name": "SetHandleCount",
- "address": "0x42912c"
- },
- {
- "name": "GetFileType",
- "address": "0x429130"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x429134"
- },
- {
- "name": "GetTickCount",
- "address": "0x429138"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x42913c"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x429140"
- },
- {
- "name": "Sleep",
- "address": "0x429144"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x429148"
- },
- {
- "name": "GetCPInfo",
- "address": "0x42914c"
- },
- {
- "name": "GetACP",
- "address": "0x429150"
- },
- {
- "name": "GetOEMCP",
- "address": "0x429154"
- },
- {
- "name": "IsValidCodePage",
- "address": "0x429158"
- },
- {
- "name": "HeapSize",
- "address": "0x42915c"
- },
- {
- "name": "RtlUnwind",
- "address": "0x429160"
- },
- {
- "name": "RaiseException",
- "address": "0x429164"
- },
- {
- "name": "IsValidLocale",
- "address": "0x429168"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "SetUserObjectSecurity",
- "address": "0x429178"
- },
- {
- "name": "GetCaretPos",
- "address": "0x42917c"
- },
- {
- "name": "GetMessageTime",
- "address": "0x429180"
- },
- {
- "name": "GetMenuBarInfo",
- "address": "0x429184"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "AlphaBlend",
- "address": "0x429170"
- }
- ],
- "dll": "MSIMG32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": "rodupe.exe",
- "actual_checksum": "0x000382db",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x000382db",
- "icon_hash": null,
- "entrypoint": "0x00403f03",
- "timestamp": "2018-11-05 04:16:03",
- "osversion": "5.1",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00028000",
- "entropy": "7.02",
- "raw_address": "0x00000400",
- "virtual_size": "0x00027e2c",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00029000",
- "size_of_data": "0x00006800",
- "entropy": "6.09",
- "raw_address": "0x00028400",
- "virtual_size": "0x0000661a",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00030000",
- "size_of_data": "0x00001e00",
- "entropy": "2.34",
- "raw_address": "0x0002ec00",
- "virtual_size": "0x000136e4",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00044000",
- "size_of_data": "0x00005200",
- "entropy": "5.16",
- "raw_address": "0x00030a00",
- "virtual_size": "0x000051c0",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0004a000",
- "size_of_data": "0x00001200",
- "entropy": "5.86",
- "raw_address": "0x00035c00",
- "virtual_size": "0x0000105c",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x0002f5d0",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x0000004a"
- },
- {
- "virtual_address": "0x0002eca4",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000050"
- },
- {
- "virtual_address": "0x00044000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x000051c0"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0004a000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000e5c"
- },
- {
- "virtual_address": "0x000291d0",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00029000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x0000018c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [
- {
- "ordinal": 1,
- "name": "_MyFunc124@4",
- "address": "0x401090"
- }
- ],
- "guest_signers": {},
- "imphash": "23cc1e3ff134c4170cc955068bf04f41",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "C:\\fimar-wo.pdb\\x00t_server\\runtime\\crypt\\tmp_864677763\\bin\\rodupe.pdb\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00a\\x00\\x00\\xf0\\x95\\x00\\x00\\x10\\xd2\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\xff\\xff\\xff",
- "imported_dll_count": 3,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "kernel32.dll.FlsAlloc",
- "kernel32.dll.FlsGetValue",
- "kernel32.dll.FlsSetValue",
- "kernel32.dll.FlsFree",
- "kernel32.dll.LoadLibraryA",
- "kernel32.dll.VirtualAlloc",
- "kernel32.dll.VirtualProtect",
- "kernel32.dll.VirtualFree",
- "kernel32.dll.GetVersionExA",
- "kernel32.dll.TerminateProcess",
- "kernel32.dll.ExitProcess",
- "kernel32.dll.SetErrorMode",
- "kernel32.dll.GetModuleHandleA",
- "kernel32.dll.GetCommandLineW",
- "kernel32.dll.HeapDestroy",
- "kernel32.dll.HeapCreate",
- "kernel32.dll.GetLastError",
- "kernel32.dll.AddVectoredExceptionHandler",
- "kernel32.dll.RemoveVectoredExceptionHandler",
- "kernel32.dll.lstrlenW",
- "kernel32.dll.MapViewOfFile",
- "kernel32.dll.UnmapViewOfFile",
- "kernel32.dll.GetCurrentProcessId",
- "kernel32.dll.lstrcpyW",
- "kernel32.dll.HeapAlloc",
- "kernel32.dll.HeapFree",
- "kernel32.dll.CreateFileMappingW",
- "kernel32.dll.TlsGetValue",
- "kernel32.dll.GetModuleFileNameW",
- "kernel32.dll.OpenProcess",
- "kernel32.dll.GetVersion",
- "kernel32.dll.CreateEventA",
- "kernel32.dll.GetLongPathNameW",
- "kernel32.dll.lstrlenA",
- "kernel32.dll.GetProcAddress",
- "kernel32.dll.DeleteCriticalSection",
- "kernel32.dll.InitializeCriticalSection",
- "kernel32.dll.TlsAlloc",
- "kernel32.dll.TlsSetValue",
- "kernel32.dll.TlsFree",
- "kernel32.dll.LeaveCriticalSection",
- "kernel32.dll.EnterCriticalSection",
- "user32.dll.wsprintfW",
- "ntdll.dll.memcpy",
- "ntdll.dll.memset",
- "msvcr100.dll.atexit",
- "ntdll.dll.ZwQueryInformationToken",
- "ntdll.dll.wcstombs",
- "ntdll.dll.ZwOpenProcessToken",
- "ntdll.dll.ZwOpenProcess",
- "ntdll.dll.ZwClose",
- "ntdll.dll.strcpy",
- "ntdll.dll.mbstowcs",
- "ntdll.dll._snprintf",
- "ntdll.dll.sprintf",
- "ntdll.dll._aulldiv",
- "ntdll.dll._allmul",
- "ntdll.dll.RtlUnwind",
- "ntdll.dll.NtQueryVirtualMemory",
- "kernel32.dll.InterlockedExchange",
- "kernel32.dll.LocalAlloc",
- "kernel32.dll.InterlockedIncrement",
- "kernel32.dll.InterlockedDecrement",
- "kernel32.dll.SetEvent",
- "kernel32.dll.GetTickCount",
- "kernel32.dll.WaitForSingleObject",
- "kernel32.dll.CloseHandle",
- "kernel32.dll.SleepEx",
- "kernel32.dll.CreateWaitableTimerA",
- "kernel32.dll.lstrcpyA",
- "kernel32.dll.GetSystemTimeAsFileTime",
- "kernel32.dll.SetWaitableTimer",
- "kernel32.dll.WaitForMultipleObjects",
- "kernel32.dll.OpenFileMappingW",
- "kernel32.dll.lstrcmpW",
- "kernel32.dll.ResetEvent",
- "kernel32.dll.GetComputerNameW",
- "kernel32.dll.Sleep",
- "kernel32.dll.FreeLibrary",
- "kernel32.dll.GetFileTime",
- "kernel32.dll.FindNextFileA",
- "kernel32.dll.CompareFileTime",
- "kernel32.dll.FindClose",
- "kernel32.dll.QueryPerformanceCounter",
- "kernel32.dll.CreateFileA",
- "kernel32.dll.lstrcatA",
- "kernel32.dll.QueryPerformanceFrequency",
- "kernel32.dll.lstrcmpA",
- "kernel32.dll.ExpandEnvironmentStringsA",
- "kernel32.dll.FindFirstFileA",
- "kernel32.dll.RaiseException",
- "oleaut32.dll.#2",
- "oleaut32.dll.#16",
- "oleaut32.dll.#15",
- "oleaut32.dll.#6",
- "kernel32.dll.IsWow64Process",
- "ole32.dll.CoInitializeEx",
- "cryptbase.dll.SystemFunction036",
- "uxtheme.dll.ThemeInitApiHook",
- "user32.dll.IsProcessDPIAware",
- "user32.dll.wsprintfA",
- "advapi32.dll.GetUserNameW",
- "shlwapi.dll.StrToIntExA",
- "shlwapi.dll.StrChrA",
- "shlwapi.dll.StrTrimA",
- "ole32.dll.CoCreateInstance",
- "kernel32.dll.GetThreadPreferredUILanguages",
- "kernel32.dll.SetThreadPreferredUILanguages",
- "kernel32.dll.LocaleNameToLCID",
- "kernel32.dll.GetLocaleInfoEx",
- "kernel32.dll.LCIDToLocaleName",
- "kernel32.dll.GetSystemDefaultLocaleName",
- "ole32.dll.CoSetProxyBlanket",
- "oleaut32.dll.#283",
- "oleaut32.dll.#284",
- "kernel32.dll.RegOpenKeyExW",
- "oleaut32.dll.BSTR_UserSize",
- "oleaut32.dll.BSTR_UserMarshal",
- "oleaut32.dll.BSTR_UserUnmarshal",
- "oleaut32.dll.BSTR_UserFree",
- "oleaut32.dll.VARIANT_UserSize",
- "oleaut32.dll.VARIANT_UserMarshal",
- "oleaut32.dll.VARIANT_UserUnmarshal",
- "oleaut32.dll.VARIANT_UserFree",
- "oleaut32.dll.LPSAFEARRAY_UserSize",
- "oleaut32.dll.LPSAFEARRAY_UserMarshal",
- "oleaut32.dll.LPSAFEARRAY_UserUnmarshal",
- "oleaut32.dll.LPSAFEARRAY_UserFree",
- "shlwapi.dll.StrStrIW",
- "ole32.dll.CoGetClassObject",
- "ole32.dll.CoGetMarshalSizeMax",
- "ole32.dll.CoMarshalInterface",
- "ole32.dll.CoUnmarshalInterface",
- "ole32.dll.StringFromIID",
- "ole32.dll.CoGetPSClsid",
- "ole32.dll.CoTaskMemAlloc",
- "ole32.dll.CoTaskMemFree",
- "ole32.dll.CoReleaseMarshalData",
- "ole32.dll.DcomChannelSetHResult",
- "vssapi.dll.CreateWriter",
- "advapi32.dll.LookupAccountNameW",
- "sechost.dll.LookupAccountNameLocalW",
- "advapi32.dll.LookupAccountSidW",
- "samcli.dll.NetLocalGroupGetMembers",
- "samlib.dll.SamConnect",
- "rpcrt4.dll.NdrClientCall3",
- "rpcrt4.dll.RpcStringBindingComposeW",
- "rpcrt4.dll.RpcBindingFromStringBindingW",
- "rpcrt4.dll.RpcStringFreeW",
- "rpcrt4.dll.RpcBindingFree",
- "samlib.dll.SamOpenDomain",
- "samlib.dll.SamLookupNamesInDomain",
- "samlib.dll.SamOpenAlias",
- "samlib.dll.SamFreeMemory",
- "samlib.dll.SamCloseHandle",
- "samlib.dll.SamGetMembersInAlias",
- "netutils.dll.NetApiBufferFree",
- "samlib.dll.SamEnumerateDomainsInSamServer",
- "samlib.dll.SamLookupDomainInSamServer",
- "ole32.dll.CoCreateGuid",
- "ole32.dll.StringFromCLSID",
- "oleaut32.dll.#4",
- "oleaut32.dll.#7",
- "propsys.dll.VariantToPropVariant",
- "wbemcore.dll.Reinitialize",
- "wbemsvc.dll.DllGetClassObject",
- "wbemsvc.dll.DllCanUnloadNow",
- "authz.dll.AuthzInitializeContextFromToken",
- "authz.dll.AuthzInitializeObjectAccessAuditEvent2",
- "authz.dll.AuthzAccessCheck",
- "authz.dll.AuthzFreeAuditEvent",
- "authz.dll.AuthzFreeContext",
- "authz.dll.AuthzInitializeResourceManager",
- "authz.dll.AuthzFreeResourceManager",
- "rpcrt4.dll.RpcBindingCreateW",
- "rpcrt4.dll.RpcBindingBind",
- "rpcrt4.dll.I_RpcMapWin32Status",
- "advapi32.dll.EventRegister",
- "advapi32.dll.EventUnregister",
- "advapi32.dll.EventWrite",
- "kernel32.dll.RegCloseKey",
- "kernel32.dll.RegSetValueExW",
- "kernel32.dll.RegQueryValueExW",
- "wmisvc.dll.IsImproperShutdownDetected",
- "wevtapi.dll.EvtRender",
- "wevtapi.dll.EvtNext",
- "wevtapi.dll.EvtClose",
- "wevtapi.dll.EvtQuery",
- "wevtapi.dll.EvtCreateRenderContext",
- "rpcrt4.dll.RpcBindingSetAuthInfoExW",
- "rpcrt4.dll.RpcBindingSetOption",
- "ole32.dll.CoCreateFreeThreadedMarshaler",
- "ole32.dll.CreateStreamOnHGlobal",
- "advapi32.dll.RegCreateKeyExW",
- "advapi32.dll.RegSetValueExW",
- "cryptsp.dll.CryptAcquireContextW",
- "cryptsp.dll.CryptGenRandom",
- "cryptsp.dll.CryptReleaseContext",
- "kernelbase.dll.InitializeAcl",
- "kernelbase.dll.AddAce",
- "sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW",
- "kernel32.dll.IsThreadAFiber",
- "sechost.dll.LookupAccountSidLocalW",
- "kernel32.dll.OpenProcessToken",
- "kernelbase.dll.GetTokenInformation",
- "kernelbase.dll.DuplicateTokenEx",
- "kernelbase.dll.AdjustTokenPrivileges",
- "kernelbase.dll.AllocateAndInitializeSid",
- "kernelbase.dll.CheckTokenMembership",
- "kernel32.dll.SetThreadToken",
- "oleaut32.dll.#285",
- "advapi32.dll.RegOpenKeyW",
- "oleaut32.dll.#12",
- "oleaut32.dll.#286",
- "ole32.dll.CLSIDFromString",
- "oleaut32.dll.#17",
- "oleaut32.dll.#20",
- "oleaut32.dll.#19",
- "oleaut32.dll.#25",
- "ole32.dll.CoRevertToSelf",
- "advapi32.dll.LogonUserExExW",
- "sspicli.dll.LogonUserExExW",
- "authz.dll.AuthzInitializeContextFromSid",
- "ole32.dll.CoGetCallContext",
- "ole32.dll.CoImpersonateClient",
- "advapi32.dll.OpenThreadToken",
- "ole32.dll.CoSwitchCallContext",
- "oleaut32.dll.#8",
- "oleaut32.dll.#9",
- "oleaut32.dll.#500",
- "ole32.dll.CoUninitialize",
- "kernel32.dll.SortGetHandle",
- "kernel32.dll.SortCloseHandle",
- "ntmarta.dll.GetMartaExtensionInterface",
- "sechost.dll.ConvertSidToStringSidW",
- "ntdll.dll.EtwUnregisterTraceGuids",
- "kernel32.dll.InitializeSRWLock",
- "kernel32.dll.AcquireSRWLockExclusive",
- "kernel32.dll.AcquireSRWLockShared",
- "kernel32.dll.ReleaseSRWLockExclusive",
- "kernel32.dll.ReleaseSRWLockShared",
- "kernel32.dll.SetProcessDEPPolicy",
- "user32.dll.SetProcessDPIAware",
- "shell32.dll.SetCurrentProcessExplicitAppUserModelID",
- "user32.dll.GetShellWindow",
- "user32.dll.GetWindowThreadProcessId",
- "ieframe.dll.#250",
- "wininet.dll.InternetQueryOptionW",
- "advapi32.dll.EventActivityIdControl",
- "advapi32.dll.EventWriteTransfer",
- "kernel32.dll.SetFileInformationByHandle",
- "shell32.dll.SHGetFolderPathW",
- "kernel32.dll.GetModuleHandleW",
- "advapi32.dll.AddMandatoryAce",
- "ws2_32.dll.accept",
- "ws2_32.dll.bind",
- "ws2_32.dll.closesocket",
- "ws2_32.dll.connect",
- "ws2_32.dll.getpeername",
- "ws2_32.dll.getsockname",
- "ws2_32.dll.getsockopt",
- "ws2_32.dll.ntohl",
- "ws2_32.dll.htonl",
- "ws2_32.dll.htons",
- "ws2_32.dll.inet_addr",
- "ws2_32.dll.inet_ntoa",
- "ws2_32.dll.ioctlsocket",
- "ws2_32.dll.listen",
- "ws2_32.dll.ntohs",
- "ws2_32.dll.recv",
- "ws2_32.dll.recvfrom",
- "ws2_32.dll.select",
- "ws2_32.dll.send",
- "ws2_32.dll.sendto",
- "ws2_32.dll.setsockopt",
- "ws2_32.dll.shutdown",
- "ws2_32.dll.socket",
- "ws2_32.dll.gethostbyname",
- "ws2_32.dll.gethostname",
- "ws2_32.dll.WSAIoctl",
- "ws2_32.dll.WSAGetLastError",
- "ws2_32.dll.WSASetLastError",
- "ws2_32.dll.WSAStartup",
- "ws2_32.dll.WSACleanup",
- "ws2_32.dll.__WSAFDIsSet",
- "ws2_32.dll.getaddrinfo",
- "ws2_32.dll.freeaddrinfo",
- "ws2_32.dll.getnameinfo",
- "ws2_32.dll.WSALookupServiceBeginW",
- "ws2_32.dll.WSALookupServiceNextW",
- "ws2_32.dll.WSALookupServiceEnd",
- "ws2_32.dll.WSANSPIoctl",
- "ws2_32.dll.WSAStringToAddressA",
- "ws2_32.dll.WSAStringToAddressW",
- "ws2_32.dll.WSAAddressToStringA",
- "dnsapi.dll.DnsGetProxyInformation",
- "dnsapi.dll.DnsFreeProxyName",
- "iphlpapi.dll.GetIpForwardTable2",
- "iphlpapi.dll.FreeMibTable",
- "iphlpapi.dll.GetIfEntry2",
- "iphlpapi.dll.ConvertInterfaceGuidToLuid",
- "iphlpapi.dll.ResolveIpNetEntry2",
- "iphlpapi.dll.GetIpNetEntry2",
- "shlwapi.dll.#260",
- "ws2_32.dll.#115",
- "urlmon.dll.CreateUri",
- "version.dll.GetFileVersionInfoSizeW",
- "version.dll.GetFileVersionInfoW",
- "version.dll.VerQueryValueW",
- "ws2_32.dll.GetAddrInfoW",
- "comctl32.dll.PropertySheetW",
- "comctl32.dll.PropertySheetA",
- "comdlg32.dll.PageSetupDlgW",
- "comdlg32.dll.PrintDlgW",
- "urlmon.dll.#101",
- "urlmon.dll.#400",
- "advapi32.dll.TraceMessage",
- "advapi32.dll.TraceMessageVa",
- "sqmapi.dll.SqmGetSession",
- "sqmapi.dll.SqmEndSession",
- "sqmapi.dll.SqmStartSession",
- "sqmapi.dll.SqmStartUpload",
- "sqmapi.dll.SqmWaitForUploadComplete",
- "sqmapi.dll.SqmSet",
- "sqmapi.dll.SqmSetBool",
- "sqmapi.dll.SqmSetBits",
- "sqmapi.dll.SqmSetString",
- "sqmapi.dll.SqmIncrement",
- "sqmapi.dll.SqmSetIfMax",
- "sqmapi.dll.SqmSetIfMin",
- "sqmapi.dll.SqmAddToAverage",
- "sqmapi.dll.SqmAddToStreamDWord",
- "sqmapi.dll.SqmAddToStreamString",
- "sqmapi.dll.SqmSetAppId",
- "sqmapi.dll.SqmSetAppVersion",
- "sqmapi.dll.SqmSetMachineId",
- "sqmapi.dll.SqmSetUserId",
- "sqmapi.dll.SqmCreateNewId",
- "sqmapi.dll.SqmReadSharedMachineId",
- "sqmapi.dll.SqmReadSharedUserId",
- "sqmapi.dll.SqmWriteSharedMachineId",
- "sqmapi.dll.SqmWriteSharedUserId",
- "sqmapi.dll.SqmIsWindowsOptedIn",
- "urlmon.dll.#442",
- "kernel32.dll.WerRegisterMemoryBlock",
- "kernel32.dll.WerUnregisterMemoryBlock",
- "user32.dll.RegisterWindowMessageW",
- "rpcrt4.dll.UuidCreateSequential",
- "rpcrt4.dll.RpcServerUseProtseqW",
- "rpcrt4.dll.RpcServerRegisterIfEx",
- "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
- "rpcrt4.dll.RpcServerInqBindings",
- "rpcrt4.dll.RpcEpRegisterW",
- "rpcrt4.dll.RpcServerListen",
- "ntdll.dll.NtQuerySystemInformation",
- "user32.dll.RegisterClassExW",
- "user32.dll.CreateWindowExW",
- "user32.dll.DefWindowProcW",
- "user32.dll.SetWindowLongW",
- "dwmapi.dll.DwmIsCompositionEnabled",
- "urlmon.dll.#416",
- "kernel32.dll.RegisterApplicationRestart",
- "shell32.dll.#165",
- "urlmon.dll.CoInternetCreateZoneManager",
- "user32.dll.AllowSetForegroundWindow",
- "wininet.dll.InternetInitializeAutoProxyDll",
- "rasapi32.dll.RasEnumEntriesW",
- "rasapi32.dll.RasConnectionNotificationW",
- "rtutils.dll.TraceRegisterExA",
- "rtutils.dll.TracePrintfExA",
- "profapi.dll.#104",
- "shlwapi.dll.PathCanonicalizeW",
- "shlwapi.dll.PathRemoveFileSpecW",
- "shlwapi.dll.PathFindFileNameW",
- "sensapi.dll.IsNetworkAlive",
- "rpcrt4.dll.NdrClientCall2",
- "nlaapi.dll.NSPStartup",
- "sechost.dll.NotifyServiceStatusChangeA",
- "iphlpapi.dll.GetAdapterIndex",
- "user32.dll.PostThreadMessageW",
- "comctl32.dll.LoadIconWithScaleDown",
- "ieui.dll.InitGadgets",
- "ieproxy.dll.DllGetClassObject",
- "ieproxy.dll.DllCanUnloadNow",
- "gdi32.dll.GetLayout",
- "gdi32.dll.GdiRealizationInfo",
- "gdi32.dll.FontIsLinked",
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegQueryInfoKeyW",
- "gdi32.dll.GetTextFaceAliasW",
- "advapi32.dll.RegEnumValueW",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.RegQueryValueExW",
- "gdi32.dll.GetFontAssocStatus",
- "advapi32.dll.RegQueryValueExA",
- "advapi32.dll.RegEnumKeyExW",
- "gdi32.dll.GdiIsMetaPrintDC",
- "user32.dll.MsgWaitForMultipleObjectsEx",
- "uxtheme.dll.OpenThemeData",
- "uxtheme.dll.GetThemeMargins",
- "uxtheme.dll.GetThemePartSize",
- "uxtheme.dll.GetThemeTextMetrics",
- "uxtheme.dll.GetThemeBool",
- "comctl32.dll.#410",
- "comctl32.dll.#413",
- "uxtheme.dll.IsAppThemed",
- "uxtheme.dll.GetThemeBackgroundExtent",
- "comctl32.dll.ImageList_LoadImageW",
- "comctl32.dll.ImageList_GetIconSize",
- "uxtheme.dll.GetThemeFont",
- "uxtheme.dll.IsCompositionActive",
- "uxtheme.dll.SetWindowTheme",
- "comctl32.dll.ImageList_Create",
- "comctl32.dll.ImageList_ReplaceIcon",
- "oleaut32.dll.#10",
- "comctl32.dll.ImageList_AddMasked",
- "uxtheme.dll.IsThemePartDefined",
- "uxtheme.dll.GetThemeColor",
- "imm32.dll.ImmIsIME",
- "urlmon.dll.CoInternetCreateSecurityManager",
- "msctf.dll.SetInputScopes2",
- "uxtheme.dll.CloseThemeData",
- "uxtheme.dll.GetThemeBackgroundContentRect",
- "uxtheme.dll.GetThemeTextExtent",
- "uxtheme.dll.EnableThemeDialogTexture",
- "urlmon.dll.#408",
- "uxtheme.dll.IsThemeActive",
- "ole32.dll.CreateBindCtx",
- "ole32.dll.CoGetApartmentType",
- "ole32.dll.CoRegisterInitializeSpy",
- "ieui.dll.CreateGadget",
- "ieui.dll.SetGadgetMessageFilter",
- "ieui.dll.SetGadgetStyle",
- "ieui.dll.SetGadgetRootInfo",
- "comctl32.dll.#236",
- "ole32.dll.CoGetMalloc",
- "comctl32.dll.#320",
- "comctl32.dll.#324",
- "comctl32.dll.#323",
- "comctl32.dll.#328",
- "uxtheme.dll.GetThemeAppProperties",
- "xmllite.dll.CreateXmlReader",
- "xmllite.dll.CreateXmlReaderInputWithEncodingName",
- "comctl32.dll.#334",
- "advapi32.dll.RegEnumKeyW",
- "advapi32.dll.InitializeSecurityDescriptor",
- "advapi32.dll.SetEntriesInAclW",
- "advapi32.dll.SetSecurityDescriptorDacl",
- "advapi32.dll.IsTextUnicode",
- "comctl32.dll.#332",
- "comctl32.dll.#338",
- "comctl32.dll.#339",
- "shell32.dll.#102",
- "propsys.dll.PSCreateMemoryPropertyStore",
- "propsys.dll.PSPropertyBag_WriteStr",
- "ole32.dll.PropVariantClear",
- "propsys.dll.PSPropertyBag_WriteGUID",
- "propsys.dll.PSPropertyBag_ReadGUID",
- "ieui.dll.FindStdColor",
- "setupapi.dll.CM_Get_Device_Interface_List_Size_ExW",
- "ieui.dll.InvalidateGadget",
- "ieui.dll.SetGadgetParent",
- "ieui.dll.GetGadgetTicket",
- "ieui.dll.SetGadgetRect",
- "comctl32.dll.ImageList_Read",
- "urlmon.dll.#103",
- "comctl32.dll.ImageList_GetImageCount",
- "ole32.dll.CoRevokeInitializeSpy",
- "comctl32.dll.#388",
- "urlmon.dll.#105",
- "setupapi.dll.CM_Get_Device_Interface_List_ExW",
- "kernel32.dll.GetThreadUILanguage",
- "comctl32.dll.#386",
- "shell32.dll.SHGetInstanceExplorer",
- "wininet.dll.InternetSetOptionW",
- "user32.dll.PeekMessageW",
- "user32.dll.TranslateMessage",
- "rpcrt4.dll.RpcBindingToStringBindingW",
- "rpcrt4.dll.RpcStringBindingParseW",
- "rpcrt4.dll.I_RpcBindingInqLocalClientPID",
- "rpcrt4.dll.RpcServerInqCallAttributesW",
- "rpcrt4.dll.RpcImpersonateClient",
- "rpcrt4.dll.RpcRevertToSelf",
- "rpcrt4.dll.NdrServerCall2",
- "rpcrt4.dll.RpcBindingInqObject",
- "user32.dll.PostMessageW",
- "oleaut32.dll.DllGetClassObject",
- "oleaut32.dll.DllCanUnloadNow",
- "sxs.dll.SxsOleAut32MapIIDToProxyStubCLSID",
- "advapi32.dll.RegQueryValueW",
- "sxs.dll.SxsOleAut32MapIIDToTLBPath",
- "sxs.dll.SxsOleAut32MapConfiguredClsidToReferenceClsid",
- "sxs.dll.SxsOleAut32RedirectTypeLibrary",
- "ieui.dll.PeekMessageExW",
- "ole32.dll.CoInitialize",
- "ole32.dll.RegisterDragDrop",
- "msfeeds.dll.MsfeedsCreateInstance",
- "shell32.dll.SHGetSpecialFolderPathW",
- "shell32.dll.#66",
- "shell32.dll.SHCreateDirectoryExW",
- "wininet.dll.FindFirstUrlCacheContainerW",
- "wininet.dll.FindNextUrlCacheContainerW",
- "wininet.dll.FindCloseUrlCache",
- "user32.dll.GetWindowLongW",
- "user32.dll.IsWindow",
- "user32.dll.SendMessageW",
- "propsys.dll.PSStringFromPropertyKey",
- "propsys.dll.PSGetPropertyDescription",
- "propsys.dll.PropVariantToString",
- "propsys.dll.InitPropVariantFromStringAsVector",
- "propsys.dll.PSCoerceToCanonicalValue",
- "shell32.dll.SHGetKnownFolderPath",
- "urlmon.dll.#458",
- "urlmon.dll.URLDownloadToFileW",
- "ieui.dll.WaitMessageEx",
- "urlmon.dll.CoInternetIsFeatureEnabledForUrl",
- "urlmon.dll.#326",
- "urlmon.dll.#327",
- "wininet.dll.GetUrlCacheEntryInfoW",
- "ole32.dll.StgOpenStorageEx",
- "oleaut32.dll.#23",
- "oleaut32.dll.#22",
- "urlmon.dll.#441",
- "urlmon.dll.#395",
- "urlmon.dll.#351",
- "mlang.dll.#112",
- "wininet.dll.GetUrlCacheEntryInfoA",
- "wininet.dll.GetUrlCacheEntryInfoExW",
- "wininet.dll.GetUrlCacheEntryInfoExA",
- "uxtheme.dll.BufferedPaintInit",
- "uxtheme.dll.BeginBufferedPaint",
- "uxtheme.dll.DrawThemeParentBackgroundEx",
- "uxtheme.dll.DrawThemeParentBackground",
- "uxtheme.dll.IsThemeBackgroundPartiallyTransparent",
- "uxtheme.dll.DrawThemeBackground",
- "uxtheme.dll.EndBufferedPaint",
- "usp10.dll.ScriptIsComplex",
- "urlmon.dll.#420",
- "user32.dll.DispatchMessageW",
- "ieui.dll.DUserPostEvent",
- "ieui.dll.DeleteHandle",
- "comctl32.dll.#412",
- "uxtheme.dll.BufferedPaintUnInit",
- "ieui.dll.DUserFlushMessages",
- "ieui.dll.DUserFlushDeferredMessages",
- "comctl32.dll.ImageList_Destroy",
- "ole32.dll.RevokeDragDrop",
- "ieui.dll.DisableContainerHwnd",
- "ole32.dll.CoWaitForMultipleHandles",
- "urlmon.dll.#412",
- "urlmon.dll.#414",
- "ntdll.dll.RtlDllShutdownInProgress",
- "comctl32.dll.#329",
- "linkinfo.dll.IsValidLinkInfo",
- "propsys.dll.#417",
- "propsys.dll.PSGetNameFromPropertyKey",
- "propsys.dll.InitVariantFromBuffer",
- "propsys.dll.PropVariantToGUID",
- "apphelp.dll.ApphelpCheckShellObject",
- "user32.dll.DestroyWindow",
- "comctl32.dll.#326",
- "advapi32.dll.OpenProcessToken",
- "propsys.dll.PSGetPropertyDescriptionByName",
- "urlmon.dll.#325",
- "user32.dll.PostQuitMessage",
- "sechost.dll.ConvertStringSidToSidW",
- "samcli.dll.NetUserGetLocalGroups",
- "advapi32.dll.LsaOpenPolicy",
- "advapi32.dll.LsaLookupNames2",
- "advapi32.dll.LsaClose",
- "advapi32.dll.LsaFreeMemory",
- "samlib.dll.SamGetAliasMembership",
- "samlib.dll.SamLookupIdsInDomain",
- "linkinfo.dll.CreateLinkInfoW",
- "user32.dll.IsCharAlphaW",
- "user32.dll.CharPrevW",
- "ntshrui.dll.GetNetResourceFromLocalPathW",
- "srvcli.dll.NetShareEnum",
- "cscapi.dll.CscNetApiGetInterface",
- "slc.dll.SLGetWindowsInformationDWORD",
- "linkinfo.dll.DestroyLinkInfo",
- "propsys.dll.PropVariantToBoolean",
- "urlmon.dll.#364",
- "shell32.dll.SHCreateShellItemArrayFromIDLists",
- "ole32.dll.CoTaskMemRealloc",
- "shell32.dll.SHAssocEnumHandlersForProtocolByApplication",
- "urlmon.dll.#397",
- "urlmon.dll.#398",
- "propsys.dll.PSPropertyBag_ReadBOOL",
- "advapi32.dll.GetSecurityInfo",
- "advapi32.dll.SetSecurityInfo",
- "advapi32.dll.GetSecurityDescriptorControl",
- "urlmon.dll.#456",
- "urlmon.dll.#451",
- "user32.dll.UnregisterClassW",
- "rpcrt4.dll.RpcEpUnregister",
- "rpcrt4.dll.RpcBindingVectorFree",
- "rpcrt4.dll.RpcServerUnregisterIf",
- "urlmon.dll.#401",
- "ws2_32.dll.#116",
- "advapi32.dll.UnregisterTraceGuids",
- "comctl32.dll.#321",
- "ieframe.dll.#251",
- "kernel32.dll.WerSetFlags",
- "ieshims.dll.IEShims_Initialize",
- "user32.dll.SetWindowsHookExW",
- "user32.dll.FindWindowExA",
- "kernel32.dll.CreateProcessW",
- "kernel32.dll.CreateProcessA",
- "advapi32.dll.RegQueryValueA",
- "ntdll.dll.LdrRegisterDllNotification",
- "ole32.dll.NdrOleInitializeExtension",
- "shell32.dll.SHChangeNotifyRegisterThread",
- "comctl32.dll.#4",
- "comctl32.dll.ImageList_Add",
- "wininet.dll.InternetQueryOptionA",
- "gdi32.dll.GetTextExtentExPointWPri",
- "urlmon.dll.#104",
- "user32.dll.LoadCursorW",
- "user32.dll.GetClassInfoExW",
- "kernel32.dll.QueryActCtxW",
- "kernel32.dll.ActivateActCtx",
- "kernel32.dll.FindActCtxSectionStringW",
- "kernel32.dll.DeactivateActCtx",
- "user32.dll.CallWindowProcW",
- "user32.dll.ChangeWindowMessageFilter",
- "dwmapi.dll.DwmSetWindowAttribute",
- "urlmon.dll.#111",
- "shlwapi.dll.AssocQueryStringW",
- "propsys.dll.#430",
- "advapi32.dll.RegGetValueW",
- "propsys.dll.PropVariantToStringAlloc",
- "oleaut32.dll.#11",
- "ieshims.dll.IEShims_SetRedirectRegistryForThread",
- "comctl32.dll.#8",
- "uxtheme.dll.GetThemeInt",
- "urlmon.dll.CreateURLMonikerEx",
- "urlmon.dll.CreateAsyncBindCtxEx",
- "urlmon.dll.RegisterBindStatusCallback",
- "urlmon.dll.CreateFormatEnumerator",
- "urlmon.dll.UrlMkGetSessionOption",
- "rasadhlp.dll.WSAttemptAutodialAddr",
- "rasadhlp.dll.WSAttemptAutodialName",
- "rasadhlp.dll.WSNoteSuccessfulHostentLookup",
- "mlang.dll.#121",
- "urlmon.dll.#444",
- "urlmon.dll.#445",
- "dwmapi.dll.DwmInvalidateIconicBitmaps",
- "urlmon.dll.RevokeBindStatusCallback",
- "urlmon.dll.CreateIUriBuilder",
- "urlmon.dll.#330",
- "urlmon.dll.RegisterFormatEnumerator",
- "oleaut32.dll.#201",
- "oleaut32.dll.#3",
- "wininet.dll.CreateUrlCacheEntryA",
- "wininet.dll.CommitUrlCacheEntryA",
- "urlmon.dll.CoInternetIsFeatureEnabled",
- "ieframe.dll.#302",
- "wininet.dll.CreateUrlCacheContainerW",
- "oleaut32.dll.VariantClear",
- "urlmon.dll.IntlPercentEncodeNormalize",
- "shlwapi.dll.PathGetDriveNumberW",
- "urlmon.dll.#335",
- "ole32.dll.CoGetObjectContext",
- "imgutil.dll.DecodeImage",
- "uxtheme.dll.#61",
- "oleaut32.dll.#147",
- "ieshims.dll.IEShims_GetOriginatingThreadId",
- "user32.dll.UnregisterClassA",
- "ieshims.dll.IEShims_Uninitialize",
- "ntdll.dll.LdrUnregisterDllNotification",
- "advapi32.dll.EventEnabled",
- "user32.dll.CharLowerW",
- "cryptsp.dll.CryptCreateHash",
- "cryptsp.dll.CryptHashData",
- "cryptsp.dll.CryptGetHashParam",
- "cryptsp.dll.CryptDestroyHash",
- "crypt32.dll.CryptUnprotectData",
- "crypt32.dll.CryptProtectData",
- "cryptbase.dll.SystemFunction040",
- "cryptbase.dll.SystemFunction041"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "GetDriveTypeW",
- "address": "0x429000"
- },
- {
- "name": "WaitNamedPipeA",
- "address": "0x429004"
- },
- {
- "name": "SetEnvironmentVariableW",
- "address": "0x429008"
- },
- {
- "name": "MoveFileWithProgressA",
- "address": "0x42900c"
- },
- {
- "name": "GetModuleHandleW",
- "address": "0x429010"
- },
- {
- "name": "ExpandEnvironmentStringsA",
- "address": "0x429014"
- },
- {
- "name": "ReadConsoleW",
- "address": "0x429018"
- },
- {
- "name": "EnumTimeFormatsA",
- "address": "0x42901c"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x429020"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x429024"
- },
- {
- "name": "GetSystemDirectoryW",
- "address": "0x429028"
- },
- {
- "name": "AddRefActCtx",
- "address": "0x42902c"
- },
- {
- "name": "FormatMessageW",
- "address": "0x429030"
- },
- {
- "name": "SetConsoleCP",
- "address": "0x429034"
- },
- {
- "name": "IsProcessorFeaturePresent",
- "address": "0x429038"
- },
- {
- "name": "ReplaceFileW",
- "address": "0x42903c"
- },
- {
- "name": "GetStringTypeExA",
- "address": "0x429040"
- },
- {
- "name": "GetLastError",
- "address": "0x429044"
- },
- {
- "name": "DefineDosDeviceW",
- "address": "0x429048"
- },
- {
- "name": "GetFirmwareEnvironmentVariableW",
- "address": "0x42904c"
- },
- {
- "name": "GetProcessVersion",
- "address": "0x429050"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x429054"
- },
- {
- "name": "FindFirstVolumeMountPointW",
- "address": "0x429058"
- },
- {
- "name": "HeapLock",
- "address": "0x42905c"
- },
- {
- "name": "WaitForMultipleObjects",
- "address": "0x429060"
- },
- {
- "name": "GetVolumePathNamesForVolumeNameA",
- "address": "0x429064"
- },
- {
- "name": "WaitCommEvent",
- "address": "0x429068"
- },
- {
- "name": "VirtualProtect",
- "address": "0x42906c"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x429070"
- },
- {
- "name": "EnumSystemLocalesA",
- "address": "0x429074"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x429078"
- },
- {
- "name": "GetUserDefaultLCID",
- "address": "0x42907c"
- },
- {
- "name": "GetStringTypeW",
- "address": "0x429080"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x429084"
- },
- {
- "name": "LCMapStringW",
- "address": "0x429088"
- },
- {
- "name": "HeapReAlloc",
- "address": "0x42908c"
- },
- {
- "name": "HeapFree",
- "address": "0x429090"
- },
- {
- "name": "GetProcAddress",
- "address": "0x429094"
- },
- {
- "name": "ExitProcess",
- "address": "0x429098"
- },
- {
- "name": "DecodePointer",
- "address": "0x42909c"
- },
- {
- "name": "GetCommandLineW",
- "address": "0x4290a0"
- },
- {
- "name": "HeapSetInformation",
- "address": "0x4290a4"
- },
- {
- "name": "GetStartupInfoW",
- "address": "0x4290a8"
- },
- {
- "name": "HeapCreate",
- "address": "0x4290ac"
- },
- {
- "name": "HeapDestroy",
- "address": "0x4290b0"
- },
- {
- "name": "HeapAlloc",
- "address": "0x4290b4"
- },
- {
- "name": "InitializeCriticalSectionAndSpinCount",
- "address": "0x4290b8"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x4290bc"
- },
- {
- "name": "FatalAppExitA",
- "address": "0x4290c0"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x4290c4"
- },
- {
- "name": "EncodePointer",
- "address": "0x4290c8"
- },
- {
- "name": "SetConsoleCtrlHandler",
- "address": "0x4290cc"
- },
- {
- "name": "FreeLibrary",
- "address": "0x4290d0"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x4290d4"
- },
- {
- "name": "LoadLibraryW",
- "address": "0x4290d8"
- },
- {
- "name": "GetLocaleInfoW",
- "address": "0x4290dc"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x4290e0"
- },
- {
- "name": "SetUnhandledExceptionFilter",
- "address": "0x4290e4"
- },
- {
- "name": "IsDebuggerPresent",
- "address": "0x4290e8"
- },
- {
- "name": "TerminateProcess",
- "address": "0x4290ec"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x4290f0"
- },
- {
- "name": "TlsAlloc",
- "address": "0x4290f4"
- },
- {
- "name": "TlsGetValue",
- "address": "0x4290f8"
- },
- {
- "name": "TlsSetValue",
- "address": "0x4290fc"
- },
- {
- "name": "TlsFree",
- "address": "0x429100"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x429104"
- },
- {
- "name": "SetLastError",
- "address": "0x429108"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x42910c"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x429110"
- },
- {
- "name": "GetCurrentThread",
- "address": "0x429114"
- },
- {
- "name": "WriteFile",
- "address": "0x429118"
- },
- {
- "name": "GetStdHandle",
- "address": "0x42911c"
- },
- {
- "name": "GetModuleFileNameW",
- "address": "0x429120"
- },
- {
- "name": "FreeEnvironmentStringsW",
- "address": "0x429124"
- },
- {
- "name": "GetEnvironmentStringsW",
- "address": "0x429128"
- },
- {
- "name": "SetHandleCount",
- "address": "0x42912c"
- },
- {
- "name": "GetFileType",
- "address": "0x429130"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x429134"
- },
- {
- "name": "GetTickCount",
- "address": "0x429138"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x42913c"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x429140"
- },
- {
- "name": "Sleep",
- "address": "0x429144"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x429148"
- },
- {
- "name": "GetCPInfo",
- "address": "0x42914c"
- },
- {
- "name": "GetACP",
- "address": "0x429150"
- },
- {
- "name": "GetOEMCP",
- "address": "0x429154"
- },
- {
- "name": "IsValidCodePage",
- "address": "0x429158"
- },
- {
- "name": "HeapSize",
- "address": "0x42915c"
- },
- {
- "name": "RtlUnwind",
- "address": "0x429160"
- },
- {
- "name": "RaiseException",
- "address": "0x429164"
- },
- {
- "name": "IsValidLocale",
- "address": "0x429168"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "SetUserObjectSecurity",
- "address": "0x429178"
- },
- {
- "name": "GetCaretPos",
- "address": "0x42917c"
- },
- {
- "name": "GetMessageTime",
- "address": "0x429180"
- },
- {
- "name": "GetMenuBarInfo",
- "address": "0x429184"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "AlphaBlend",
- "address": "0x429170"
- }
- ],
- "dll": "MSIMG32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": "rodupe.exe",
- "actual_checksum": "0x000382db",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x000382db",
- "icon_hash": null,
- "entrypoint": "0x00403f03",
- "timestamp": "2018-11-05 04:16:03",
- "osversion": "5.1",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00028000",
- "entropy": "7.02",
- "raw_address": "0x00000400",
- "virtual_size": "0x00027e2c",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00029000",
- "size_of_data": "0x00006800",
- "entropy": "6.09",
- "raw_address": "0x00028400",
- "virtual_size": "0x0000661a",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00030000",
- "size_of_data": "0x00001e00",
- "entropy": "2.34",
- "raw_address": "0x0002ec00",
- "virtual_size": "0x000136e4",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00044000",
- "size_of_data": "0x00005200",
- "entropy": "5.16",
- "raw_address": "0x00030a00",
- "virtual_size": "0x000051c0",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0004a000",
- "size_of_data": "0x00001200",
- "entropy": "5.86",
- "raw_address": "0x00035c00",
- "virtual_size": "0x0000105c",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x0002f5d0",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x0000004a"
- },
- {
- "virtual_address": "0x0002eca4",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000050"
- },
- {
- "virtual_address": "0x00044000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x000051c0"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0004a000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000e5c"
- },
- {
- "virtual_address": "0x000291d0",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00029000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x0000018c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [
- {
- "ordinal": 1,
- "name": "_MyFunc124@4",
- "address": "0x401090"
- }
- ],
- "guest_signers": {},
- "imphash": "23cc1e3ff134c4170cc955068bf04f41",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "C:\\fimar-wo.pdb\\x00t_server\\runtime\\crypt\\tmp_864677763\\bin\\rodupe.pdb\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00a\\x00\\x00\\xf0\\x95\\x00\\x00\\x10\\xd2\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xfe\\xff\\xff\\xff",
- "imported_dll_count": 3,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment