Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: ""
- [*] MalScore: 10.0
- [*] File Name: "Exes_d071887d9e9af01d3ee009dffe1be16d.exe"
- [*] File Size: 2617697
- [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- [*] SHA256: "044d234d96ba4d2c8d6b75dce9f3b778137708ed2fd39edfab8711d3431f8763"
- [*] MD5: "d071887d9e9af01d3ee009dffe1be16d"
- [*] SHA1: "140edb4850081d890fa7267efe002129ff2c5067"
- [*] SHA512: "2dda346899ad643efb00ab2a820261ac9215ae8758189a105cf3ee8deeff8d2891e3b8183f746a7b85d8fba55b2096312008164b6ab9ec3069edfe500f2a708f"
- [*] CRC32: "1965D99B"
- [*] SSDEEP: "49152:RxH3KTyEJdyyUa6PrvMrKQHBhzFrBRucp2uBUYYs2aoywX7AqomhDH0vOL:RZ3KOMFkxQHBBZOtuBUg2aKXTJZL"
- [*] Process Execution: [
- "Exes_d071887d9e9af01d3ee009dffe1be16d.exe",
- "ctfmon.exe",
- "cmd.exe",
- "net.exe",
- "net1.exe",
- "net.exe",
- "net1.exe",
- "svchost.exe",
- "svchost.exe",
- "sc.exe",
- "sc.exe",
- "svchost.exe",
- "svchost.exe",
- "svchost.exe",
- "PING.EXE",
- "svchost.exe",
- "net.exe",
- "net1.exe",
- "cmd.exe",
- "schtasks.exe",
- "cmd.exe",
- "schtasks.exe",
- "attrib.exe",
- "attrib.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "sc.exe",
- "net.exe",
- "net1.exe",
- "taskkill.exe",
- "xsfxdel~.exe",
- "services.exe",
- "svchost.exe",
- "cmd.exe",
- "mode.com",
- "sc.exe",
- "sc.exe",
- "sc.exe",
- "sc.exe",
- "net.exe",
- "net1.exe",
- "net.exe",
- "net1.exe",
- "net.exe",
- "net1.exe",
- "net.exe",
- "net1.exe",
- "taskkill.exe",
- "svchost.exe",
- "WmiPrvSE.exe",
- "taskhost.exe",
- "taskeng.exe",
- "taskeng.exe",
- "taskeng.exe",
- "msoia.exe",
- "taskeng.exe",
- "msoia.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "Possible date expiration check, exits too soon after checking local time",
- "Details": [
- {
- "process": "Exes_d071887d9e9af01d3ee009dffe1be16d.exe, PID 3020"
- }
- ]
- },
- {
- "Description": "Creates RWX memory",
- "Details": []
- },
- {
- "Description": "A process attempted to delay the analysis task.",
- "Details": [
- {
- "Process": "taskeng.exe tried to sleep 540 seconds, actually delayed analysis time by 0 seconds"
- }
- ]
- },
- {
- "Description": "Reads data out of its own binary image",
- "Details": [
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x00000000, length: 0x00000002"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x0000003c, length: 0x00000002"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x00000100, length: 0x00000004"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x00000106, length: 0x00000002"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x00000114, length: 0x00000002"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x00000208, length: 0x00000008"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x00000230, length: 0x00000008"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x00000258, length: 0x00000008"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x00000280, length: 0x00000008"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x000002a8, length: 0x00000008"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x000002d0, length: 0x00000008"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x000002f8, length: 0x00000008"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x00000320, length: 0x00000008"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x00025600, length: 0x000001ab"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x0002579a, length: 0x00000025"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x000257b7, length: 0x00004f95"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x0002a73b, length: 0x00000023"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x0002a756, length: 0x0023a95d"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x002650a2, length: 0x00000029"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x002650c3, length: 0x00006a83"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x0026bb35, length: 0x0000002a"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x0026bb57, length: 0x00006a83"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x002725c9, length: 0x00000028"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x002725e9, length: 0x000065b4"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x00278b8c, length: 0x00000029"
- },
- {
- "self_read": "process: Exes_d071887d9e9af01d3ee009dffe1be16d.exe, pid: 3020, offset: 0x00278bad, length: 0x000065b4"
- }
- ]
- },
- {
- "Description": "A process created a hidden window",
- "Details": [
- {
- "Process": "Exes_d071887d9e9af01d3ee009dffe1be16d.exe -> C:\\Users\\user\\AppData\\Local\\Temp\\xsfxdel~.exe"
- },
- {
- "Process": "ctfmon.exe -> C:\\Windows\\Fonts\\Mysql\\same.bat"
- }
- ]
- },
- {
- "Description": "Drops a binary and executes it",
- "Details": [
- {
- "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\xsfxdel~.exe"
- }
- ]
- },
- {
- "Description": "Deletes its original binary from disk",
- "Details": []
- },
- {
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details": [
- {
- "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 6968369 times"
- }
- ]
- },
- {
- "Description": "Attempts to execute a Living Off The Land Binary command for post exeploitation",
- "Details": [
- {
- "MITRE T1078 - schtask": "(Tactic: Execution, Persistence, Privilege Escalation)"
- }
- ]
- },
- {
- "Description": "Installs itself for autorun at Windows startup",
- "Details": [
- {
- "service name": "MicrosoftMysql"
- },
- {
- "service path": "C:\\Windows\\Fonts\\Mysql\\svchost.exe"
- },
- {
- "task": "schtasks /create /TN \"At1\" /TR \"C:\\Windows\\Fonts\\Mysql\\nei.bat\" /SC daily /ST 11:30:00 /RU SYSTEM"
- }
- ]
- },
- {
- "Description": "Creates a hidden or system file",
- "Details": [
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\Doublepulsar.dll"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\Doublepulsar2.dll"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\Eternalblue.dll"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\Eternalblue2.dll"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\nei.bat"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\wai.bat"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\bat.bat"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\cmd.bat"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\loab.bat"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\load.bat"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\poab.bat"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\poad.bat"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\taskhost.exe"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\wget.exe"
- }
- ]
- },
- {
- "Description": "File has been identified by 58 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "Bkav": "HW32.Packed."
- },
- {
- "MicroWorld-eScan": "Dropped:Trojan.GenericKD.41102453"
- },
- {
- "FireEye": "Generic.mg.d071887d9e9af01d"
- },
- {
- "CAT-QuickHeal": "TrojanDownloader.Win64"
- },
- {
- "McAfee": "Artemis!D071887D9E9A"
- },
- {
- "Cylance": "Unsafe"
- },
- {
- "BitDefender": "Dropped:Trojan.GenericKD.41102453"
- },
- {
- "K7GW": "Riskware ( 0040eff71 )"
- },
- {
- "K7AntiVirus": "Riskware ( 0040eff71 )"
- },
- {
- "Invincea": "heuristic"
- },
- {
- "F-Prot": "W32/Agent.AQS.gen!Eldorado"
- },
- {
- "Symantec": "Trojan.Gen.2"
- },
- {
- "Paloalto": "generic.ml"
- },
- {
- "ClamAV": "Win.Malware.Johnnie-6858836-0"
- },
- {
- "Kaspersky": "Trojan.Win32.Reconyc.jmjd"
- },
- {
- "Alibaba": "TrojanDownloader:Win32/Reconyc.793feeb2"
- },
- {
- "NANO-Antivirus": "Trojan.Win32.Reconyc.fpuwhn"
- },
- {
- "ViRobot": "Trojan.Win32.Z.Agent.2617697"
- },
- {
- "AegisLab": "Trojan.Win32.Reconyc.4!c"
- },
- {
- "Rising": "Dropper.Agent!8.2F (CLOUD)"
- },
- {
- "Ad-Aware": "Dropped:Trojan.GenericKD.41102453"
- },
- {
- "Emsisoft": "Dropped:Trojan.GenericKD.41102453 (B)"
- },
- {
- "Comodo": "Malware@#qf148j19q481"
- },
- {
- "F-Secure": "Trojan.TR/AD.DoublePulsarShellcode.AA"
- },
- {
- "DrWeb": "Trojan.PWS.Panda.8062"
- },
- {
- "TrendMicro": "TROJ_GEN.R002C0GE419"
- },
- {
- "McAfee-GW-Edition": "BehavesLike.Win32.Generic.vc"
- },
- {
- "Fortinet": "W32/Generic.AC.3C3695"
- },
- {
- "Trapmine": "malicious.moderate.ml.score"
- },
- {
- "Sophos": "Mal/Generic-S"
- },
- {
- "Ikarus": "Trojan-Dropper.Win32.Agent"
- },
- {
- "Cyren": "W32/Agent.AQS.gen!Eldorado"
- },
- {
- "Jiangmin": "Trojan.Qhost.it"
- },
- {
- "MaxSecure": "Trojan.Malware.74280749.susgen"
- },
- {
- "Avira": "TR/AD.DoublePulsarShellcode.AA"
- },
- {
- "MAX": "malware (ai score=100)"
- },
- {
- "Antiy-AVL": "Trojan/Win32.Shadowbrokers.gg"
- },
- {
- "Endgame": "malicious (moderate confidence)"
- },
- {
- "Arcabit": "Trojan.Generic.D2732C75"
- },
- {
- "ZoneAlarm": "Trojan.Win32.Reconyc.jmjd"
- },
- {
- "Microsoft": "Trojan:Win32/Eqtonex"
- },
- {
- "AhnLab-V3": "Malware/Win32.Generic.C3185729"
- },
- {
- "Acronis": "suspicious"
- },
- {
- "VBA32": "TScope.Trojan.Delf"
- },
- {
- "ALYac": "Dropped:Trojan.GenericKD.41102453"
- },
- {
- "Malwarebytes": "Trojan.DoublePulsar"
- },
- {
- "Panda": "Trj/CI.A"
- },
- {
- "ESET-NOD32": "a variant of Win32/TrojanDropper.Agent.QBR"
- },
- {
- "TrendMicro-HouseCall": "TROJ_GEN.R002C0GE419"
- },
- {
- "Tencent": "Win32.Trojan.Reconyc.Woyz"
- },
- {
- "Yandex": "Trojan.Rogue!Sp6Z5pCPcQ0"
- },
- {
- "SentinelOne": "DFI - Suspicious PE"
- },
- {
- "GData": "Dropped:Trojan.GenericKD.41102453"
- },
- {
- "Webroot": "W32.Trojan.Gen"
- },
- {
- "AVG": "FileRepMetagen [DRP]"
- },
- {
- "Cybereason": "malicious.d9e9af"
- },
- {
- "CrowdStrike": "win/malicious_confidence_80% (W)"
- },
- {
- "Qihoo-360": "Win32/Backdoor.6e0"
- }
- ]
- },
- {
- "Description": "The sample wrote data to the system hosts file.",
- "Details": []
- },
- {
- "Description": "Anomalous binary characteristics",
- "Details": [
- {
- "anomaly": "Timestamp on binary predates the release date of the OS version it requires by at least a year"
- },
- {
- "anomaly": "Actual checksum does not match that reported in PE header"
- }
- ]
- }
- ]
- [*] Started Service: [
- "MicrosoftMysql",
- "Browser",
- "LanmanWorkstation",
- "LanmanServer",
- "Schedule"
- ]
- [*] Executed Commands: [
- "\"C:\\Windows\\Fonts\\Mysql\\ctfmon.exe\"",
- "C:\\Windows\\Fonts\\Mysql\\ctfmon.exe ",
- "C:\\Users\\user\\AppData\\Local\\Temp\\xsfxdel~.exe \"C:\\Users\\user\\AppData\\Local\\Temp\\Exes_d071887d9e9af01d3ee009dffe1be16d.exe\"",
- "C:\\Windows\\Fonts\\Mysql\\same.bat ",
- "net stop \"MicrosoftMysql\"",
- "net stop \"MicrosoftMssql\"",
- "svchost stop \"MicrosoftFonts\"",
- "svchost stop \"MicrosoftMysql\"",
- "sc delete \"MicrosoftMysql\"",
- "sc delete \"MicrosoftMssql\"",
- "svchost install MicrosoftMysql \"C:\\Windows\\Fonts\\Mysql\\cmd.bat\"",
- "svchost install MicrosoftMysql C:\\Windows\\Fonts\\Mysql\\cmd.bat",
- "svchost install \"MicrosoftMysql\" C:\\Windows\\Fonts\\Mysql\\cmd.bat",
- "C:\\Windows\\system32\\PING.EXE ping 127.0.0.1 -n 20",
- "svchost start \"MicrosoftMysql\"",
- "net start \"MicrosoftMysql\"",
- "C:\\Windows\\system32\\cmd.exe /S /D /c\" echo y\"",
- "schtasks /create /TN \"At1\" /TR \"C:\\Windows\\Fonts\\Mysql\\nei.bat\" /SC daily /ST 11:30:00 /RU SYSTEM",
- "schtasks /create /TN \"At2\" /TR \"C:\\Windows\\Fonts\\Mysql\\wai.bat\" /SC daily /ST 01:00:00 /RU SYSTEM",
- "attrib +h +s -r C:\\windows\\tasks\\At*.job",
- "attrib +h +s -r C:\\Windows\\System32\\Tasks\\At*",
- "cacls C:\\windows\\tasks\\At1.job /c /e /t /g system:F",
- "cacls C:\\windows\\tasks\\At2.job /c /e /t /g system:F",
- "cacls C:\\windows\\tasks\\At1.job /c /e /t /g everyone:F",
- "cacls C:\\windows\\tasks\\At2.job /c /e /t /g everyone:F",
- "cacls C:\\Windows\\System32\\Tasks\\At1 /c /e /t /g system:F",
- "cacls C:\\Windows\\System32\\Tasks\\At2 /c /e /t /g system:F",
- "cacls C:\\Windows\\System32\\Tasks\\At1 /c /e /t /g everyone:F",
- "cacls C:\\Windows\\System32\\Tasks\\At2 /c /e /t /g everyone:F",
- "cacls C:\\Windows\\Tasks\\MiscfostNsi /p system:n",
- "cacls C:\\Windows\\Tasks\\HomeGroupProvider /p system:n",
- "cacls C:\\Windows\\Tasks\\WwANsvc /p system:n",
- "cacls C:\\Windows\\Tasks\\*fost* /p system:n",
- "cacls C:\\Windows\\Tasks\\*Group* /p system:n",
- "cacls C:\\Windows\\Tasks\\*sa* /p system:n",
- "cacls C:\\Windows\\Tasks\\*ok* /p system:n",
- "cacls C:\\Windows\\Tasks\\*my* /p system:n",
- "cacls C:\\Windows\\System32\\Tasks\\MiscfostNsi /p system:n",
- "cacls C:\\Windows\\System32\\Tasks\\HomeGroupProvider /p system:n",
- "cacls C:\\Windows\\System32\\Tasks\\WwANsvc /p system:n",
- "cacls C:\\Windows\\System32\\Tasks\\*fost* /p system:n",
- "cacls C:\\Windows\\System32\\Tasks\\*Group* /p system:n",
- "cacls C:\\Windows\\System32\\Tasks\\*sa* /p system:n",
- "cacls C:\\Windows\\System32\\Tasks\\*ok* /p system:n",
- "cacls C:\\Windows\\System32\\Tasks\\*my* /p system:n",
- "sc start Schedule",
- "net start Schedule",
- "C:\\Windows\\system32\\net1 stop \"MicrosoftMysql\"",
- "C:\\Windows\\system32\\net1 stop \"MicrosoftMssql\"",
- "C:\\Windows\\Fonts\\Mysql\\svchost.exe",
- "mode con cols=50 lines=40",
- "sc config Browser start= auto",
- "sc config lanmanworkstation start= auto",
- "sc config lanmanserver start= auto",
- "sc config SharedAccess start= disabled",
- "net start Browser",
- "net start lanmanworkstation",
- "net start lanmanserver",
- "net stop SharedAccess",
- "C:\\Windows\\system32\\net1 start \"MicrosoftMysql\"",
- "C:\\Windows\\system32\\net1 start Browser",
- "C:\\Windows\\system32\\net1 start lanmanworkstation",
- "C:\\Windows\\system32\\net1 start lanmanserver",
- "C:\\Windows\\system32\\net1 stop SharedAccess",
- "C:\\Windows\\system32\\net1 start Schedule",
- "\"C:\\Program Files\\Microsoft Office\\Office15\\msoia.exe\" scan upload mininterval:2880",
- "\"C:\\Program Files\\Microsoft Office\\Office15\\msoia.exe\" scan upload"
- ]
- [*] Mutexes: [
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex"
- ]
- [*] Modified Files: [
- "C:\\Users\\user\\AppData\\Local\\Temp\\xsfxdel~.exe",
- "C:\\Windows\\Fonts\\Mysql\\ctfmon.exe",
- "C:\\Windows\\Fonts\\Mysql\\Doublepulsar.dll",
- "C:\\Windows\\Fonts\\Mysql\\Doublepulsar2.dll",
- "C:\\Windows\\Fonts\\Mysql\\Eternalblue.dll",
- "C:\\Windows\\Fonts\\Mysql\\Eternalblue2.dll",
- "C:\\Windows\\Fonts\\Mysql\\nei.bat",
- "C:\\Windows\\Fonts\\Mysql\\wai.bat",
- "C:\\Windows\\Fonts\\Mysql\\same.bat",
- "C:\\Windows\\Fonts\\Mysql\\bat.bat",
- "C:\\Windows\\Fonts\\Mysql\\cmd.bat",
- "C:\\Windows\\Fonts\\Mysql\\file.txt",
- "C:\\Windows\\Fonts\\Mysql\\cnli-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\coli-0.dll",
- "C:\\Windows\\Fonts\\Mysql\\crli-0.dll",
- "C:\\Windows\\Fonts\\Mysql\\dmgd-4.dll",
- "C:\\Windows\\Fonts\\Mysql\\Eter.exe",
- "C:\\Windows\\Fonts\\Mysql\\Eter.xml",
- "C:\\Windows\\Fonts\\Mysql\\exma-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\libeay32.dll",
- "C:\\Windows\\Fonts\\Mysql\\libxml2.dll",
- "C:\\Windows\\Fonts\\Mysql\\loab.bat",
- "C:\\Windows\\Fonts\\Mysql\\load.bat",
- "C:\\Windows\\Fonts\\Mysql\\mance.exe",
- "C:\\Windows\\Fonts\\Mysql\\mance.xml",
- "C:\\Windows\\Fonts\\Mysql\\NansHou.dll",
- "C:\\Windows\\Fonts\\Mysql\\p.txt",
- "C:\\Windows\\Fonts\\Mysql\\poab.bat",
- "C:\\Windows\\Fonts\\Mysql\\poad.bat",
- "C:\\Windows\\Fonts\\Mysql\\posh-0.dll",
- "C:\\Windows\\Fonts\\Mysql\\puls.exe",
- "C:\\Windows\\Fonts\\Mysql\\puls.xml",
- "C:\\Windows\\Fonts\\Mysql\\ssleay32.dll",
- "C:\\Windows\\Fonts\\Mysql\\svchost.exe",
- "C:\\Windows\\Fonts\\Mysql\\taskhost.exe",
- "C:\\Windows\\Fonts\\Mysql\\tibe-2.dll",
- "C:\\Windows\\Fonts\\Mysql\\tich-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\trch-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\trfo-2.dll",
- "C:\\Windows\\Fonts\\Mysql\\tucl-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\tufo-2.dll",
- "C:\\Windows\\Fonts\\Mysql\\ucl.dll",
- "C:\\Windows\\Fonts\\Mysql\\wget.exe",
- "C:\\Windows\\Fonts\\Mysql\\xdvl-0.dll",
- "C:\\Windows\\Fonts\\Mysql\\zlib1.dll",
- "\\??\\nul",
- "\\Device\\NamedPipe",
- "C:\\Windows\\System32\\drivers\\etc\\hosts",
- "C:\\Windows\\sysnative\\LogFiles\\Scm\\5869f1c1-01d7-41f7-84b7-715672259fa8",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM"
- ]
- [*] Deleted Files: [
- "C:\\Users\\user\\AppData\\Local\\Temp\\xsfxdel~.exe",
- "C:\\Windows\\Fonts\\Mysql\\nei.bat",
- "C:\\Windows\\Fonts\\Mysql\\wai.bat",
- "C:\\Windows\\Fonts\\Mysql\\same.bat",
- "C:\\Windows\\Fonts\\Mysql\\bat.bat",
- "C:\\Windows\\Fonts\\Mysql\\cmd.bat",
- "C:\\Windows\\Fonts\\Mysql\\file.txt",
- "C:\\Windows\\Fonts\\Mysql\\cnli-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\coli-0.dll",
- "C:\\Windows\\Fonts\\Mysql\\crli-0.dll",
- "C:\\Windows\\Fonts\\Mysql\\dmgd-4.dll",
- "C:\\Windows\\Fonts\\Mysql\\Doublepulsar.dll",
- "C:\\Windows\\Fonts\\Mysql\\Doublepulsar2.dll",
- "C:\\Windows\\Fonts\\Mysql\\Eter.exe",
- "C:\\Windows\\Fonts\\Mysql\\Eter.xml",
- "C:\\Windows\\Fonts\\Mysql\\Eternalblue.dll",
- "C:\\Windows\\Fonts\\Mysql\\Eternalblue2.dll",
- "C:\\Windows\\Fonts\\Mysql\\exma-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\libeay32.dll",
- "C:\\Windows\\Fonts\\Mysql\\libxml2.dll",
- "C:\\Windows\\Fonts\\Mysql\\loab.bat",
- "C:\\Windows\\Fonts\\Mysql\\load.bat",
- "C:\\Windows\\Fonts\\Mysql\\mance.exe",
- "C:\\Windows\\Fonts\\Mysql\\mance.xml",
- "C:\\Windows\\Fonts\\Mysql\\NansHou.dll",
- "C:\\Windows\\Fonts\\Mysql\\p.txt",
- "C:\\Windows\\Fonts\\Mysql\\poab.bat",
- "C:\\Windows\\Fonts\\Mysql\\poad.bat",
- "C:\\Windows\\Fonts\\Mysql\\posh-0.dll",
- "C:\\Windows\\Fonts\\Mysql\\puls.exe",
- "C:\\Windows\\Fonts\\Mysql\\puls.xml",
- "C:\\Windows\\Fonts\\Mysql\\ssleay32.dll",
- "C:\\Windows\\Fonts\\Mysql\\svchost.exe",
- "C:\\Windows\\Fonts\\Mysql\\taskhost.exe",
- "C:\\Windows\\Fonts\\Mysql\\tibe-2.dll",
- "C:\\Windows\\Fonts\\Mysql\\tich-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\trch-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\trfo-2.dll",
- "C:\\Windows\\Fonts\\Mysql\\tucl-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\tufo-2.dll",
- "C:\\Windows\\Fonts\\Mysql\\ucl.dll",
- "C:\\Windows\\Fonts\\Mysql\\wget.exe",
- "C:\\Windows\\Fonts\\Mysql\\xdvl-0.dll",
- "C:\\Windows\\Fonts\\Mysql\\zlib1.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_d071887d9e9af01d3ee009dffe1be16d.exe"
- ]
- [*] Modified Registry Keys: [
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MicrosoftMysql\\Parameters",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Parameters\\Application",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Parameters\\AppParameters",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Parameters\\AppDirectory",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MicrosoftMysql\\Parameters\\AppExit",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Parameters\\AppExit\\(Default)",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\FailureActionsOnNonCrashFailures",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Start",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Start",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Start",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Start",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventLog\\Application\\NSSM",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Application\\NSSM\\EventMessageFile",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Application\\NSSM\\TypesSupported",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\{DB92B6F7-A485-4740-BB6D-6BBD2F13B2A9}\\data",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\{2279DCFF-0DF2-4F03-8662-0EC68B4311F2}\\data",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\{AC74B934-4740-42B3-A226-2390A546F1FD}\\data",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\{7815B269-60B2-455C-9A30-C18FD66EB7B2}\\data"
- ]
- [*] Deleted Registry Keys: [
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
- ]
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DeleteCriticalSection",
- "address": "0xe1f104"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0xe1f108"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0xe1f10c"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0xe1f110"
- },
- {
- "name": "VirtualFree",
- "address": "0xe1f114"
- },
- {
- "name": "VirtualAlloc",
- "address": "0xe1f118"
- },
- {
- "name": "LocalFree",
- "address": "0xe1f11c"
- },
- {
- "name": "LocalAlloc",
- "address": "0xe1f120"
- },
- {
- "name": "GetVersion",
- "address": "0xe1f124"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0xe1f128"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0xe1f12c"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0xe1f130"
- },
- {
- "name": "VirtualQuery",
- "address": "0xe1f134"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0xe1f138"
- },
- {
- "name": "SetCurrentDirectoryA",
- "address": "0xe1f13c"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0xe1f140"
- },
- {
- "name": "lstrlenA",
- "address": "0xe1f144"
- },
- {
- "name": "lstrcpynA",
- "address": "0xe1f148"
- },
- {
- "name": "LoadLibraryExA",
- "address": "0xe1f14c"
- },
- {
- "name": "GetThreadLocale",
- "address": "0xe1f150"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0xe1f154"
- },
- {
- "name": "GetProcAddress",
- "address": "0xe1f158"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0xe1f15c"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0xe1f160"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0xe1f164"
- },
- {
- "name": "GetLastError",
- "address": "0xe1f168"
- },
- {
- "name": "GetCurrentDirectoryA",
- "address": "0xe1f16c"
- },
- {
- "name": "GetCommandLineA",
- "address": "0xe1f170"
- },
- {
- "name": "FreeLibrary",
- "address": "0xe1f174"
- },
- {
- "name": "FindFirstFileA",
- "address": "0xe1f178"
- },
- {
- "name": "FindClose",
- "address": "0xe1f17c"
- },
- {
- "name": "ExitProcess",
- "address": "0xe1f180"
- },
- {
- "name": "WriteFile",
- "address": "0xe1f184"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0xe1f188"
- },
- {
- "name": "SetFilePointer",
- "address": "0xe1f18c"
- },
- {
- "name": "SetEndOfFile",
- "address": "0xe1f190"
- },
- {
- "name": "RtlUnwind",
- "address": "0xe1f194"
- },
- {
- "name": "ReadFile",
- "address": "0xe1f198"
- },
- {
- "name": "RaiseException",
- "address": "0xe1f19c"
- },
- {
- "name": "GetStdHandle",
- "address": "0xe1f1a0"
- },
- {
- "name": "GetFileSize",
- "address": "0xe1f1a4"
- },
- {
- "name": "GetFileType",
- "address": "0xe1f1a8"
- },
- {
- "name": "CreateFileA",
- "address": "0xe1f1ac"
- },
- {
- "name": "CloseHandle",
- "address": "0xe1f1b0"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "GetKeyboardType",
- "address": "0xe1f1b8"
- },
- {
- "name": "LoadStringA",
- "address": "0xe1f1bc"
- },
- {
- "name": "MessageBoxA",
- "address": "0xe1f1c0"
- },
- {
- "name": "CharNextA",
- "address": "0xe1f1c4"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0xe1f1cc"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0xe1f1d0"
- },
- {
- "name": "RegCloseKey",
- "address": "0xe1f1d4"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "SysFreeString",
- "address": "0xe1f1dc"
- },
- {
- "name": "SysReAllocStringLen",
- "address": "0xe1f1e0"
- },
- {
- "name": "SysAllocStringLen",
- "address": "0xe1f1e4"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "TlsSetValue",
- "address": "0xe1f1ec"
- },
- {
- "name": "TlsGetValue",
- "address": "0xe1f1f0"
- },
- {
- "name": "LocalAlloc",
- "address": "0xe1f1f4"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0xe1f1f8"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "WriteFile",
- "address": "0xe1f200"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0xe1f204"
- },
- {
- "name": "VirtualQuery",
- "address": "0xe1f208"
- },
- {
- "name": "SetFileTime",
- "address": "0xe1f20c"
- },
- {
- "name": "SetFilePointer",
- "address": "0xe1f210"
- },
- {
- "name": "SetFileAttributesA",
- "address": "0xe1f214"
- },
- {
- "name": "SetEvent",
- "address": "0xe1f218"
- },
- {
- "name": "SetEndOfFile",
- "address": "0xe1f21c"
- },
- {
- "name": "ResetEvent",
- "address": "0xe1f220"
- },
- {
- "name": "RemoveDirectoryA",
- "address": "0xe1f224"
- },
- {
- "name": "ReadFile",
- "address": "0xe1f228"
- },
- {
- "name": "MoveFileExA",
- "address": "0xe1f22c"
- },
- {
- "name": "LocalFileTimeToFileTime",
- "address": "0xe1f230"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0xe1f234"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0xe1f238"
- },
- {
- "name": "GlobalUnlock",
- "address": "0xe1f23c"
- },
- {
- "name": "GlobalHandle",
- "address": "0xe1f240"
- },
- {
- "name": "GlobalFree",
- "address": "0xe1f244"
- },
- {
- "name": "GetVersionExA",
- "address": "0xe1f248"
- },
- {
- "name": "GetThreadLocale",
- "address": "0xe1f24c"
- },
- {
- "name": "GetTempPathA",
- "address": "0xe1f250"
- },
- {
- "name": "GetSystemDefaultLangID",
- "address": "0xe1f254"
- },
- {
- "name": "GetStringTypeExA",
- "address": "0xe1f258"
- },
- {
- "name": "GetStdHandle",
- "address": "0xe1f25c"
- },
- {
- "name": "GetProcAddress",
- "address": "0xe1f260"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0xe1f264"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0xe1f268"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0xe1f26c"
- },
- {
- "name": "GetLocalTime",
- "address": "0xe1f270"
- },
- {
- "name": "GetLastError",
- "address": "0xe1f274"
- },
- {
- "name": "GetFullPathNameA",
- "address": "0xe1f278"
- },
- {
- "name": "GetFileAttributesA",
- "address": "0xe1f27c"
- },
- {
- "name": "GetExitCodeProcess",
- "address": "0xe1f280"
- },
- {
- "name": "GetDiskFreeSpaceA",
- "address": "0xe1f284"
- },
- {
- "name": "GetDateFormatA",
- "address": "0xe1f288"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0xe1f28c"
- },
- {
- "name": "GetCPInfo",
- "address": "0xe1f290"
- },
- {
- "name": "GetACP",
- "address": "0xe1f294"
- },
- {
- "name": "FormatMessageA",
- "address": "0xe1f298"
- },
- {
- "name": "FindNextFileA",
- "address": "0xe1f29c"
- },
- {
- "name": "FindFirstFileA",
- "address": "0xe1f2a0"
- },
- {
- "name": "FindClose",
- "address": "0xe1f2a4"
- },
- {
- "name": "FileTimeToLocalFileTime",
- "address": "0xe1f2a8"
- },
- {
- "name": "FileTimeToDosDateTime",
- "address": "0xe1f2ac"
- },
- {
- "name": "ExpandEnvironmentStringsA",
- "address": "0xe1f2b0"
- },
- {
- "name": "EnumCalendarInfoA",
- "address": "0xe1f2b4"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0xe1f2b8"
- },
- {
- "name": "DosDateTimeToFileTime",
- "address": "0xe1f2bc"
- },
- {
- "name": "DeleteFileA",
- "address": "0xe1f2c0"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0xe1f2c4"
- },
- {
- "name": "CreateMutexA",
- "address": "0xe1f2c8"
- },
- {
- "name": "CreateFileA",
- "address": "0xe1f2cc"
- },
- {
- "name": "CreateEventA",
- "address": "0xe1f2d0"
- },
- {
- "name": "CreateDirectoryA",
- "address": "0xe1f2d4"
- },
- {
- "name": "CompareStringA",
- "address": "0xe1f2d8"
- },
- {
- "name": "CloseHandle",
- "address": "0xe1f2dc"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "TextOutA",
- "address": "0xe1f2e4"
- },
- {
- "name": "SetTextColor",
- "address": "0xe1f2e8"
- },
- {
- "name": "SetBkColor",
- "address": "0xe1f2ec"
- },
- {
- "name": "SelectObject",
- "address": "0xe1f2f0"
- },
- {
- "name": "GetTextExtentPoint32A",
- "address": "0xe1f2f4"
- },
- {
- "name": "ExtTextOutA",
- "address": "0xe1f2f8"
- },
- {
- "name": "DeleteObject",
- "address": "0xe1f2fc"
- },
- {
- "name": "CreateFontA",
- "address": "0xe1f300"
- }
- ],
- "dll": "gdi32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateWindowExA",
- "address": "0xe1f308"
- },
- {
- "name": "RegisterClassExA",
- "address": "0xe1f30c"
- },
- {
- "name": "PeekMessageA",
- "address": "0xe1f310"
- },
- {
- "name": "MessageBoxA",
- "address": "0xe1f314"
- },
- {
- "name": "LoadStringA",
- "address": "0xe1f318"
- },
- {
- "name": "InvalidateRect",
- "address": "0xe1f31c"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0xe1f320"
- },
- {
- "name": "GetSysColor",
- "address": "0xe1f324"
- },
- {
- "name": "EndPaint",
- "address": "0xe1f328"
- },
- {
- "name": "DrawEdge",
- "address": "0xe1f32c"
- },
- {
- "name": "DispatchMessageA",
- "address": "0xe1f330"
- },
- {
- "name": "DestroyWindow",
- "address": "0xe1f334"
- },
- {
- "name": "DefWindowProcA",
- "address": "0xe1f338"
- },
- {
- "name": "BeginPaint",
- "address": "0xe1f33c"
- },
- {
- "name": "CharNextA",
- "address": "0xe1f340"
- },
- {
- "name": "CharUpperBuffA",
- "address": "0xe1f344"
- },
- {
- "name": "CharToOemA",
- "address": "0xe1f348"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "Sleep",
- "address": "0xe1f350"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "ShellExecuteExA",
- "address": "0xe1f358"
- },
- {
- "name": "ShellExecuteA",
- "address": "0xe1f35c"
- }
- ],
- "dll": "shell32.dll"
- },
- {
- "imports": [
- {
- "name": "SHGetSpecialFolderLocation",
- "address": "0xe1f364"
- },
- {
- "name": "SHGetPathFromIDListA",
- "address": "0xe1f368"
- },
- {
- "name": "SHBrowseForFolderA",
- "address": "0xe1f36c"
- }
- ],
- "dll": "shell32.dll"
- },
- {
- "imports": [
- {
- "name": "SafeArrayPtrOfIndex",
- "address": "0xe1f374"
- },
- {
- "name": "SafeArrayGetUBound",
- "address": "0xe1f378"
- },
- {
- "name": "SafeArrayGetLBound",
- "address": "0xe1f37c"
- },
- {
- "name": "SafeArrayCreate",
- "address": "0xe1f380"
- },
- {
- "name": "VariantChangeType",
- "address": "0xe1f384"
- },
- {
- "name": "VariantCopy",
- "address": "0xe1f388"
- },
- {
- "name": "VariantClear",
- "address": "0xe1f38c"
- },
- {
- "name": "VariantInit",
- "address": "0xe1f390"
- }
- ],
- "dll": "oleaut32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00281949",
- "overlay": {
- "size": "0x00259b61",
- "offset": "0x00025600"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x0003084f",
- "icon_hash": null,
- "entrypoint": "0x0041a238",
- "timestamp": "1992-06-19 22:22:17",
- "osversion": "4.0",
- "sections": [
- {
- "name": "CODE",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x0001a400",
- "entropy": "6.51",
- "raw_address": "0x00000400",
- "virtual_size": "0x0001a3b0",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": "DATA",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0001c000",
- "size_of_data": "0x00000e00",
- "entropy": "4.44",
- "raw_address": "0x0001a800",
- "virtual_size": "0x00000d1c",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": "BSS",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0001d000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x0001b600",
- "virtual_size": "0x00a01e05",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".idata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00a1f000",
- "size_of_data": "0x00001000",
- "entropy": "4.63",
- "raw_address": "0x0001b600",
- "virtual_size": "0x00000ec4",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00a20000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x0001c600",
- "virtual_size": "0x0000000c",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00a21000",
- "size_of_data": "0x00000200",
- "entropy": "0.41",
- "raw_address": "0x0001c600",
- "virtual_size": "0x00000025",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00a22000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x0001c800",
- "virtual_size": "0x00001e0c",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00a24000",
- "size_of_data": "0x00008e00",
- "entropy": "5.72",
- "raw_address": "0x0001c800",
- "virtual_size": "0x00008cf4",
- "characteristics_raw": "0x50000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00a1f000",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000ec4"
- },
- {
- "virtual_address": "0x00a24000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00008cf4"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00a22000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00a21018",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x0000000d"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00a21000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "de1fa96ad5bc81910ffb7ed552e29d0d",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 12,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "kernel32.dll.GetDiskFreeSpaceExA",
- "oleaut32.dll.VariantChangeTypeEx",
- "oleaut32.dll.VarNeg",
- "oleaut32.dll.VarNot",
- "oleaut32.dll.VarAdd",
- "oleaut32.dll.VarSub",
- "oleaut32.dll.VarMul",
- "oleaut32.dll.VarDiv",
- "oleaut32.dll.VarIdiv",
- "oleaut32.dll.VarMod",
- "oleaut32.dll.VarAnd",
- "oleaut32.dll.VarOr",
- "oleaut32.dll.VarXor",
- "oleaut32.dll.VarCmp",
- "oleaut32.dll.VarI4FromStr",
- "oleaut32.dll.VarR4FromStr",
- "oleaut32.dll.VarR8FromStr",
- "oleaut32.dll.VarDateFromStr",
- "oleaut32.dll.VarCyFromStr",
- "oleaut32.dll.VarBoolFromStr",
- "oleaut32.dll.VarBstrFromCy",
- "oleaut32.dll.VarBstrFromDate",
- "oleaut32.dll.VarBstrFromBool",
- "ole32.dll.OleInitialize",
- "cryptbase.dll.SystemFunction036",
- "uxtheme.dll.ThemeInitApiHook",
- "user32.dll.IsProcessDPIAware",
- "ole32.dll.CreateBindCtx",
- "ole32.dll.CoTaskMemAlloc",
- "propsys.dll.PSCreateMemoryPropertyStore",
- "propsys.dll.PSPropertyBag_WriteDWORD",
- "ole32.dll.CoGetApartmentType",
- "ole32.dll.CoRegisterInitializeSpy",
- "ole32.dll.CoTaskMemFree",
- "comctl32.dll.#236",
- "oleaut32.dll.#6",
- "ole32.dll.CoGetMalloc",
- "propsys.dll.PSPropertyBag_ReadDWORD",
- "comctl32.dll.#320",
- "ole32.dll.StringFromGUID2",
- "comctl32.dll.#324",
- "comctl32.dll.#323",
- "advapi32.dll.RegEnumKeyW",
- "oleaut32.dll.#2",
- "propsys.dll.PSPropertyBag_ReadBSTR",
- "propsys.dll.PSPropertyBag_ReadStrAlloc",
- "shell32.dll.#102",
- "advapi32.dll.OpenThreadToken",
- "ole32.dll.CoInitializeEx",
- "ole32.dll.CoCreateInstance",
- "advapi32.dll.InitializeSecurityDescriptor",
- "advapi32.dll.SetEntriesInAclW",
- "ntmarta.dll.GetMartaExtensionInterface",
- "advapi32.dll.SetSecurityDescriptorDacl",
- "advapi32.dll.IsTextUnicode",
- "comctl32.dll.#328",
- "comctl32.dll.#334",
- "comctl32.dll.#332",
- "comctl32.dll.#338",
- "ole32.dll.CoUninitialize",
- "sechost.dll.ConvertSidToStringSidW",
- "profapi.dll.#104",
- "propsys.dll.#430",
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegGetValueW",
- "advapi32.dll.RegCloseKey",
- "ole32.dll.CoTaskMemRealloc",
- "propsys.dll.InitPropVariantFromStringAsVector",
- "propsys.dll.PSCoerceToCanonicalValue",
- "propsys.dll.PropVariantToStringAlloc",
- "ole32.dll.PropVariantClear",
- "ole32.dll.CoAllowSetForegroundWindow",
- "kernel32.dll.InitializeSRWLock",
- "kernel32.dll.AcquireSRWLockExclusive",
- "kernel32.dll.AcquireSRWLockShared",
- "kernel32.dll.ReleaseSRWLockExclusive",
- "kernel32.dll.ReleaseSRWLockShared",
- "shell32.dll.SHGetFolderPathW",
- "advapi32.dll.SaferGetPolicyInformation",
- "setupapi.dll.CM_Get_Device_Interface_List_Size_ExW",
- "setupapi.dll.CM_Get_Device_Interface_List_ExW",
- "comctl32.dll.#386",
- "ntdll.dll.RtlDllShutdownInProgress",
- "comctl32.dll.#329",
- "ole32.dll.OleUninitialize",
- "ole32.dll.CoRevokeInitializeSpy",
- "comctl32.dll.#388",
- "oleaut32.dll.#500",
- "advapi32.dll.UnregisterTraceGuids",
- "comctl32.dll.#321",
- "user32.dll.MessageBoxA",
- "kernel32.dll.Sleep",
- "kernel32.dll.VirtualFree",
- "kernel32.dll.VirtualAlloc",
- "kernel32.dll.VirtualQuery",
- "kernel32.dll.GetSystemInfo",
- "kernel32.dll.GetVersion",
- "kernel32.dll.SetThreadLocale",
- "kernel32.dll.GetACP",
- "kernel32.dll.GetStartupInfoW",
- "kernel32.dll.GetProcAddress",
- "kernel32.dll.GetModuleHandleW",
- "kernel32.dll.GetCommandLineW",
- "kernel32.dll.FreeLibrary",
- "kernel32.dll.UnhandledExceptionFilter",
- "kernel32.dll.RtlUnwind",
- "kernel32.dll.RaiseException",
- "kernel32.dll.ExitProcess",
- "kernel32.dll.GetCurrentThreadId",
- "kernel32.dll.DeleteCriticalSection",
- "kernel32.dll.InitializeCriticalSection",
- "kernel32.dll.WriteFile",
- "kernel32.dll.GetStdHandle",
- "kernel32.dll.CloseHandle",
- "kernel32.dll.LoadLibraryA",
- "kernel32.dll.GetLastError",
- "kernel32.dll.TlsSetValue",
- "kernel32.dll.TlsGetValue",
- "kernel32.dll.LocalFree",
- "kernel32.dll.LocalAlloc",
- "kernel32.dll.VirtualProtect",
- "kernel32.dll.SizeofResource",
- "kernel32.dll.LockResource",
- "kernel32.dll.LoadResource",
- "kernel32.dll.GetVersionExW",
- "kernel32.dll.FindResourceW",
- "kernel32.dll.GetThreadPreferredUILanguages",
- "kernel32.dll.SetThreadPreferredUILanguages",
- "kernel32.dll.GetThreadUILanguage",
- "kernel32.dll.#829",
- "kernel32.dll.#693",
- "kernel32.dll.#700",
- "kernel32.dll.#760",
- "kernel32.dll.#763",
- "kernel32.dll.#1112",
- "kernel32.dll.#1358",
- "kernel32.dll.#1359",
- "kernel32.dll.#871",
- "kernel32.dll.#283",
- "kernel32.dll.#84",
- "kernel32.dll.#145",
- "kernel32.dll.#1318",
- "kernel32.dll.#1129",
- "kernel32.dll.#532",
- "kernel32.dll.#216",
- "kernel32.dll.#131",
- "kernel32.dll.#449",
- "kernel32.dll.#625",
- "kernel32.dll.#688",
- "kernel32.dll.#644",
- "kernel32.dll.#646",
- "user32.dll.#2039",
- "user32.dll.#2046",
- "user32.dll.#2332",
- "shell32.dll.#437",
- "kernel32.dll.SortGetHandle",
- "kernel32.dll.SortCloseHandle",
- "kernel32.dll.SetThreadUILanguage",
- "kernel32.dll.CopyFileExW",
- "kernel32.dll.IsDebuggerPresent",
- "kernel32.dll.SetConsoleInputExeNameW",
- "advapi32.dll.SaferIdentifyLevel",
- "advapi32.dll.SaferComputeTokenFromLevel",
- "advapi32.dll.SaferCloseLevel",
- "rpcrt4.dll.I_RpcSNCHOption",
- "sechost.dll.OpenSCManagerW",
- "sechost.dll.OpenServiceW",
- "sechost.dll.CloseServiceHandle",
- "kernel32.dll.FlsAlloc",
- "kernel32.dll.FlsGetValue",
- "kernel32.dll.FlsSetValue",
- "kernel32.dll.FlsFree",
- "kernel32.dll.AttachConsole",
- "kernel32.dll.SleepConditionVariableCS",
- "kernel32.dll.WakeConditionVariable",
- "advapi32.dll.CreateWellKnownSid",
- "advapi32.dll.IsWellKnownSid",
- "cryptbase.dll.SystemFunction028",
- "rpcrt4.dll.NDRCContextBinding",
- "rpcrt4.dll.RpcBindingToStringBindingW",
- "rpcrt4.dll.I_RpcMapWin32Status",
- "rpcrt4.dll.RpcStringBindingParseW",
- "rpcrt4.dll.RpcStringFreeW",
- "cryptbase.dll.SystemFunction004",
- "mswsock.dll.WSPStartup",
- "wshtcpip.dll.WSHOpenSocket",
- "wshtcpip.dll.WSHOpenSocket2",
- "wshtcpip.dll.WSHJoinLeaf",
- "wshtcpip.dll.WSHNotify",
- "wshtcpip.dll.WSHGetSocketInformation",
- "wshtcpip.dll.WSHSetSocketInformation",
- "wshtcpip.dll.WSHGetSockaddrType",
- "wshtcpip.dll.WSHGetWildcardSockaddr",
- "wshtcpip.dll.WSHGetBroadcastSockaddr",
- "wshtcpip.dll.WSHAddressToString",
- "wshtcpip.dll.WSHStringToAddress",
- "wshtcpip.dll.WSHIoctl",
- "sechost.dll.ControlService",
- "sechost.dll.StartServiceW",
- "version.dll.GetFileVersionInfoSizeW",
- "version.dll.GetFileVersionInfoW",
- "version.dll.VerQueryValueW",
- "sechost.dll.LookupAccountNameLocalW",
- "advapi32.dll.LookupAccountSidW",
- "sechost.dll.LookupAccountSidLocalW",
- "sspicli.dll.GetUserNameExW",
- "advapi32.dll.GetUserNameW",
- "xmllite.dll.CreateXmlWriter",
- "xmllite.dll.CreateXmlWriterOutputWithEncodingName",
- "sechost.dll.QueryServiceStatus",
- "winsta.dll.WinStationFreeMemory",
- "winsta.dll.WinStationCloseServer",
- "winsta.dll.WinStationOpenServerW",
- "winsta.dll.WinStationFreeGAPMemory",
- "winsta.dll.WinStationGetAllProcesses",
- "winsta.dll.WinStationEnumerateProcesses",
- "kernel32.dll.LocaleNameToLCID",
- "kernel32.dll.GetLocaleInfoEx",
- "kernel32.dll.LCIDToLocaleName",
- "kernel32.dll.GetSystemDefaultLocaleName",
- "oleaut32.dll.#283",
- "oleaut32.dll.#284",
- "advapi32.dll.CryptAcquireContextW",
- "advapi32.dll.RegCreateKeyExW",
- "shlwapi.dll.PathIsDirectoryW",
- "advapi32.dll.RegQueryValueExW",
- "advapi32.dll.RegNotifyChangeKeyValue",
- "cryptsp.dll.CryptAcquireContextW",
- "cryptsp.dll.CryptGenRandom",
- "ole32.dll.NdrOleInitializeExtension",
- "ole32.dll.CoGetClassObject",
- "ole32.dll.CoGetMarshalSizeMax",
- "ole32.dll.CoMarshalInterface",
- "ole32.dll.CoUnmarshalInterface",
- "ole32.dll.StringFromIID",
- "ole32.dll.CoGetPSClsid",
- "ole32.dll.CoReleaseMarshalData",
- "ole32.dll.DcomChannelSetHResult",
- "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
- "ole32.dll.CLSIDFromOle1Class",
- "clbcatq.dll.GetCatalogObject",
- "clbcatq.dll.GetCatalogObject2",
- "tschannel.dll.DllGetClassObject",
- "tschannel.dll.DllCanUnloadNow",
- "advapi32.dll.RegSetValueExW",
- "advapi32.dll.CryptReleaseContext",
- "cryptsp.dll.CryptReleaseContext",
- "dwmapi.dll.DwmIsCompositionEnabled",
- "shlwapi.dll.PathIsPrefixW",
- "advapi32.dll.CryptCreateHash",
- "advapi32.dll.CryptGetHashParam",
- "cryptsp.dll.CryptGetHashParam",
- "advapi32.dll.CryptHashData",
- "cryptsp.dll.CryptHashData",
- "advapi32.dll.CryptDestroyHash",
- "cryptsp.dll.CryptDestroyHash",
- "xmllite.dll.CreateXmlReader",
- "fastprox.dll.DllGetClassObject",
- "fastprox.dll.DllCanUnloadNow",
- "kernel32.dll.RegOpenKeyExW",
- "kernel32.dll.RegQueryValueExW",
- "kernel32.dll.RegCloseKey",
- "kernel32.dll.WerRegisterMemoryBlock",
- "advapi32.dll.EventWrite",
- "advapi32.dll.EventRegister",
- "advapi32.dll.EventUnregister"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DeleteCriticalSection",
- "address": "0xe1f104"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0xe1f108"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0xe1f10c"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0xe1f110"
- },
- {
- "name": "VirtualFree",
- "address": "0xe1f114"
- },
- {
- "name": "VirtualAlloc",
- "address": "0xe1f118"
- },
- {
- "name": "LocalFree",
- "address": "0xe1f11c"
- },
- {
- "name": "LocalAlloc",
- "address": "0xe1f120"
- },
- {
- "name": "GetVersion",
- "address": "0xe1f124"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0xe1f128"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0xe1f12c"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0xe1f130"
- },
- {
- "name": "VirtualQuery",
- "address": "0xe1f134"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0xe1f138"
- },
- {
- "name": "SetCurrentDirectoryA",
- "address": "0xe1f13c"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0xe1f140"
- },
- {
- "name": "lstrlenA",
- "address": "0xe1f144"
- },
- {
- "name": "lstrcpynA",
- "address": "0xe1f148"
- },
- {
- "name": "LoadLibraryExA",
- "address": "0xe1f14c"
- },
- {
- "name": "GetThreadLocale",
- "address": "0xe1f150"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0xe1f154"
- },
- {
- "name": "GetProcAddress",
- "address": "0xe1f158"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0xe1f15c"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0xe1f160"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0xe1f164"
- },
- {
- "name": "GetLastError",
- "address": "0xe1f168"
- },
- {
- "name": "GetCurrentDirectoryA",
- "address": "0xe1f16c"
- },
- {
- "name": "GetCommandLineA",
- "address": "0xe1f170"
- },
- {
- "name": "FreeLibrary",
- "address": "0xe1f174"
- },
- {
- "name": "FindFirstFileA",
- "address": "0xe1f178"
- },
- {
- "name": "FindClose",
- "address": "0xe1f17c"
- },
- {
- "name": "ExitProcess",
- "address": "0xe1f180"
- },
- {
- "name": "WriteFile",
- "address": "0xe1f184"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0xe1f188"
- },
- {
- "name": "SetFilePointer",
- "address": "0xe1f18c"
- },
- {
- "name": "SetEndOfFile",
- "address": "0xe1f190"
- },
- {
- "name": "RtlUnwind",
- "address": "0xe1f194"
- },
- {
- "name": "ReadFile",
- "address": "0xe1f198"
- },
- {
- "name": "RaiseException",
- "address": "0xe1f19c"
- },
- {
- "name": "GetStdHandle",
- "address": "0xe1f1a0"
- },
- {
- "name": "GetFileSize",
- "address": "0xe1f1a4"
- },
- {
- "name": "GetFileType",
- "address": "0xe1f1a8"
- },
- {
- "name": "CreateFileA",
- "address": "0xe1f1ac"
- },
- {
- "name": "CloseHandle",
- "address": "0xe1f1b0"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "GetKeyboardType",
- "address": "0xe1f1b8"
- },
- {
- "name": "LoadStringA",
- "address": "0xe1f1bc"
- },
- {
- "name": "MessageBoxA",
- "address": "0xe1f1c0"
- },
- {
- "name": "CharNextA",
- "address": "0xe1f1c4"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0xe1f1cc"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0xe1f1d0"
- },
- {
- "name": "RegCloseKey",
- "address": "0xe1f1d4"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "SysFreeString",
- "address": "0xe1f1dc"
- },
- {
- "name": "SysReAllocStringLen",
- "address": "0xe1f1e0"
- },
- {
- "name": "SysAllocStringLen",
- "address": "0xe1f1e4"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "TlsSetValue",
- "address": "0xe1f1ec"
- },
- {
- "name": "TlsGetValue",
- "address": "0xe1f1f0"
- },
- {
- "name": "LocalAlloc",
- "address": "0xe1f1f4"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0xe1f1f8"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "WriteFile",
- "address": "0xe1f200"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0xe1f204"
- },
- {
- "name": "VirtualQuery",
- "address": "0xe1f208"
- },
- {
- "name": "SetFileTime",
- "address": "0xe1f20c"
- },
- {
- "name": "SetFilePointer",
- "address": "0xe1f210"
- },
- {
- "name": "SetFileAttributesA",
- "address": "0xe1f214"
- },
- {
- "name": "SetEvent",
- "address": "0xe1f218"
- },
- {
- "name": "SetEndOfFile",
- "address": "0xe1f21c"
- },
- {
- "name": "ResetEvent",
- "address": "0xe1f220"
- },
- {
- "name": "RemoveDirectoryA",
- "address": "0xe1f224"
- },
- {
- "name": "ReadFile",
- "address": "0xe1f228"
- },
- {
- "name": "MoveFileExA",
- "address": "0xe1f22c"
- },
- {
- "name": "LocalFileTimeToFileTime",
- "address": "0xe1f230"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0xe1f234"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0xe1f238"
- },
- {
- "name": "GlobalUnlock",
- "address": "0xe1f23c"
- },
- {
- "name": "GlobalHandle",
- "address": "0xe1f240"
- },
- {
- "name": "GlobalFree",
- "address": "0xe1f244"
- },
- {
- "name": "GetVersionExA",
- "address": "0xe1f248"
- },
- {
- "name": "GetThreadLocale",
- "address": "0xe1f24c"
- },
- {
- "name": "GetTempPathA",
- "address": "0xe1f250"
- },
- {
- "name": "GetSystemDefaultLangID",
- "address": "0xe1f254"
- },
- {
- "name": "GetStringTypeExA",
- "address": "0xe1f258"
- },
- {
- "name": "GetStdHandle",
- "address": "0xe1f25c"
- },
- {
- "name": "GetProcAddress",
- "address": "0xe1f260"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0xe1f264"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0xe1f268"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0xe1f26c"
- },
- {
- "name": "GetLocalTime",
- "address": "0xe1f270"
- },
- {
- "name": "GetLastError",
- "address": "0xe1f274"
- },
- {
- "name": "GetFullPathNameA",
- "address": "0xe1f278"
- },
- {
- "name": "GetFileAttributesA",
- "address": "0xe1f27c"
- },
- {
- "name": "GetExitCodeProcess",
- "address": "0xe1f280"
- },
- {
- "name": "GetDiskFreeSpaceA",
- "address": "0xe1f284"
- },
- {
- "name": "GetDateFormatA",
- "address": "0xe1f288"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0xe1f28c"
- },
- {
- "name": "GetCPInfo",
- "address": "0xe1f290"
- },
- {
- "name": "GetACP",
- "address": "0xe1f294"
- },
- {
- "name": "FormatMessageA",
- "address": "0xe1f298"
- },
- {
- "name": "FindNextFileA",
- "address": "0xe1f29c"
- },
- {
- "name": "FindFirstFileA",
- "address": "0xe1f2a0"
- },
- {
- "name": "FindClose",
- "address": "0xe1f2a4"
- },
- {
- "name": "FileTimeToLocalFileTime",
- "address": "0xe1f2a8"
- },
- {
- "name": "FileTimeToDosDateTime",
- "address": "0xe1f2ac"
- },
- {
- "name": "ExpandEnvironmentStringsA",
- "address": "0xe1f2b0"
- },
- {
- "name": "EnumCalendarInfoA",
- "address": "0xe1f2b4"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0xe1f2b8"
- },
- {
- "name": "DosDateTimeToFileTime",
- "address": "0xe1f2bc"
- },
- {
- "name": "DeleteFileA",
- "address": "0xe1f2c0"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0xe1f2c4"
- },
- {
- "name": "CreateMutexA",
- "address": "0xe1f2c8"
- },
- {
- "name": "CreateFileA",
- "address": "0xe1f2cc"
- },
- {
- "name": "CreateEventA",
- "address": "0xe1f2d0"
- },
- {
- "name": "CreateDirectoryA",
- "address": "0xe1f2d4"
- },
- {
- "name": "CompareStringA",
- "address": "0xe1f2d8"
- },
- {
- "name": "CloseHandle",
- "address": "0xe1f2dc"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "TextOutA",
- "address": "0xe1f2e4"
- },
- {
- "name": "SetTextColor",
- "address": "0xe1f2e8"
- },
- {
- "name": "SetBkColor",
- "address": "0xe1f2ec"
- },
- {
- "name": "SelectObject",
- "address": "0xe1f2f0"
- },
- {
- "name": "GetTextExtentPoint32A",
- "address": "0xe1f2f4"
- },
- {
- "name": "ExtTextOutA",
- "address": "0xe1f2f8"
- },
- {
- "name": "DeleteObject",
- "address": "0xe1f2fc"
- },
- {
- "name": "CreateFontA",
- "address": "0xe1f300"
- }
- ],
- "dll": "gdi32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateWindowExA",
- "address": "0xe1f308"
- },
- {
- "name": "RegisterClassExA",
- "address": "0xe1f30c"
- },
- {
- "name": "PeekMessageA",
- "address": "0xe1f310"
- },
- {
- "name": "MessageBoxA",
- "address": "0xe1f314"
- },
- {
- "name": "LoadStringA",
- "address": "0xe1f318"
- },
- {
- "name": "InvalidateRect",
- "address": "0xe1f31c"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0xe1f320"
- },
- {
- "name": "GetSysColor",
- "address": "0xe1f324"
- },
- {
- "name": "EndPaint",
- "address": "0xe1f328"
- },
- {
- "name": "DrawEdge",
- "address": "0xe1f32c"
- },
- {
- "name": "DispatchMessageA",
- "address": "0xe1f330"
- },
- {
- "name": "DestroyWindow",
- "address": "0xe1f334"
- },
- {
- "name": "DefWindowProcA",
- "address": "0xe1f338"
- },
- {
- "name": "BeginPaint",
- "address": "0xe1f33c"
- },
- {
- "name": "CharNextA",
- "address": "0xe1f340"
- },
- {
- "name": "CharUpperBuffA",
- "address": "0xe1f344"
- },
- {
- "name": "CharToOemA",
- "address": "0xe1f348"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "Sleep",
- "address": "0xe1f350"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "ShellExecuteExA",
- "address": "0xe1f358"
- },
- {
- "name": "ShellExecuteA",
- "address": "0xe1f35c"
- }
- ],
- "dll": "shell32.dll"
- },
- {
- "imports": [
- {
- "name": "SHGetSpecialFolderLocation",
- "address": "0xe1f364"
- },
- {
- "name": "SHGetPathFromIDListA",
- "address": "0xe1f368"
- },
- {
- "name": "SHBrowseForFolderA",
- "address": "0xe1f36c"
- }
- ],
- "dll": "shell32.dll"
- },
- {
- "imports": [
- {
- "name": "SafeArrayPtrOfIndex",
- "address": "0xe1f374"
- },
- {
- "name": "SafeArrayGetUBound",
- "address": "0xe1f378"
- },
- {
- "name": "SafeArrayGetLBound",
- "address": "0xe1f37c"
- },
- {
- "name": "SafeArrayCreate",
- "address": "0xe1f380"
- },
- {
- "name": "VariantChangeType",
- "address": "0xe1f384"
- },
- {
- "name": "VariantCopy",
- "address": "0xe1f388"
- },
- {
- "name": "VariantClear",
- "address": "0xe1f38c"
- },
- {
- "name": "VariantInit",
- "address": "0xe1f390"
- }
- ],
- "dll": "oleaut32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00281949",
- "overlay": {
- "size": "0x00259b61",
- "offset": "0x00025600"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x0003084f",
- "icon_hash": null,
- "entrypoint": "0x0041a238",
- "timestamp": "1992-06-19 22:22:17",
- "osversion": "4.0",
- "sections": [
- {
- "name": "CODE",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x0001a400",
- "entropy": "6.51",
- "raw_address": "0x00000400",
- "virtual_size": "0x0001a3b0",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": "DATA",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0001c000",
- "size_of_data": "0x00000e00",
- "entropy": "4.44",
- "raw_address": "0x0001a800",
- "virtual_size": "0x00000d1c",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": "BSS",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0001d000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x0001b600",
- "virtual_size": "0x00a01e05",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".idata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00a1f000",
- "size_of_data": "0x00001000",
- "entropy": "4.63",
- "raw_address": "0x0001b600",
- "virtual_size": "0x00000ec4",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00a20000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x0001c600",
- "virtual_size": "0x0000000c",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00a21000",
- "size_of_data": "0x00000200",
- "entropy": "0.41",
- "raw_address": "0x0001c600",
- "virtual_size": "0x00000025",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00a22000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x0001c800",
- "virtual_size": "0x00001e0c",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00a24000",
- "size_of_data": "0x00008e00",
- "entropy": "5.72",
- "raw_address": "0x0001c800",
- "virtual_size": "0x00008cf4",
- "characteristics_raw": "0x50000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00a1f000",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000ec4"
- },
- {
- "virtual_address": "0x00a24000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00008cf4"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00a22000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00a21018",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x0000000d"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00a21000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "de1fa96ad5bc81910ffb7ed552e29d0d",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 12,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment