Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: ""
- [*] MalScore: 10.0
- [*] File Name: "Exes_a627d8d6e3da2421657e0bcc35e7527f.exe"
- [*] File Size: 561152
- [*] File Type: "PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows"
- [*] SHA256: "a5aeb90fcd527f8bf9544a9bbeb9cecce804f28cd5b3d36281c258c5b534681d"
- [*] MD5: "a627d8d6e3da2421657e0bcc35e7527f"
- [*] SHA1: "718ba94cdd34b1ac2f9f9138eaa8b0b7117bd51a"
- [*] SHA512: "f82ab554ebb10ee7d9cc1293f93e8648aaf7a059c9110ea8aaaff85c32159c66c0bccc2f75033cce04d97423845239223a01fccbfba0220f9af54306ccfa93a3"
- [*] CRC32: "DE2BB65E"
- [*] SSDEEP: "6144:To7xXy3JlgwjYxkwMFSizoHkDrnQCrN5WSZbNiUJDQ3lNDqC4R6AI5z:sFeo8+MJbVx5rZcGDolNDqr6Aqz"
- [*] Process Execution: [
- "Exes_a627d8d6e3da2421657e0bcc35e7527f.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details": [
- {
- "section": "name: .rsrc, entropy: 7.15, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x00058600, virtual_size: 0x00058440"
- }
- ]
- },
- {
- "Description": "Anomalous .NET characteristics",
- "Details": [
- {
- "anomalous_version": "Assembly version is set to 0"
- }
- ]
- },
- {
- "Description": "File has been identified by 28 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "Qihoo-360": "Win32/Sorter.AVE.DotNetFile.A"
- },
- {
- "McAfee": "Artemis!A627D8D6E3DA"
- },
- {
- "Alibaba": "Trojan:MSIL/Kryptik.4c9ee46b"
- },
- {
- "ESET-NOD32": "a variant of MSIL/Kryptik.SAE"
- },
- {
- "Avast": "Win32:CrypterX-gen [Trj]"
- },
- {
- "GData": "Win32.Backdoor.Remcos.I1498B"
- },
- {
- "Kaspersky": "HEUR:Trojan.MSIL.Crypt.gen"
- },
- {
- "Paloalto": "generic.ml"
- },
- {
- "AegisLab": "Trojan.Win32.Generic.4!c"
- },
- {
- "Endgame": "malicious (high confidence)"
- },
- {
- "Sophos": "Troj/DownLd-BQ"
- },
- {
- "F-Secure": "Trojan.TR/AD.Remcos.wpzxa"
- },
- {
- "Invincea": "heuristic"
- },
- {
- "McAfee-GW-Edition": "BehavesLike.Win32.Generic.hh"
- },
- {
- "Cyren": "W32/Trojan.WIFA-1401"
- },
- {
- "Webroot": "W32.Trojan.Gen"
- },
- {
- "Avira": "TR/AD.Remcos.wpzxa"
- },
- {
- "ZoneAlarm": "HEUR:Trojan.MSIL.Crypt.gen"
- },
- {
- "Microsoft": "Trojan:Win32/Zpevdo.B"
- },
- {
- "AhnLab-V3": "Trojan/Win32.RL_Kryptik.R276695"
- },
- {
- "Acronis": "suspicious"
- },
- {
- "MAX": "malware (ai score=100)"
- },
- {
- "Malwarebytes": "Trojan.Crypt.XMP"
- },
- {
- "Rising": "Trojan.MSIL/Kryptik!1.B1DC (CLOUD)"
- },
- {
- "Ikarus": "Win32.Outbreak"
- },
- {
- "Fortinet": "MSIL/GenKryptik.DKXI!tr"
- },
- {
- "AVG": "Win32:CrypterX-gen [Trj]"
- },
- {
- "CrowdStrike": "win/malicious_confidence_100% (W)"
- }
- ]
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: []
- [*] Mutexes: []
- [*] Modified Files: []
- [*] Deleted Files: []
- [*] Modified Registry Keys: []
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "dotnet": {
- "customattrs": [
- {
- "type": "TypeDef",
- "name": "[mscorlib]System.Reflection.DefaultMemberAttribute",
- "value": "It"
- },
- {
- "type": "TypeDef",
- "name": "[mscorlib]System.Reflection.DefaultMemberAttribute",
- "value": "It"
- },
- {
- "type": "TypeDef",
- "name": "[mscorlib]System.Reflection.DefaultMemberAttribute",
- "value": "It"
- },
- {
- "type": "TypeDef",
- "name": "[mscorlib]System.Diagnostics.DebuggerDisplayAttribute",
- "value": "{DebuggerToString("
- }
- ],
- "assemblyinfo": {
- "version": "0.0.0.0",
- "name": "mjVldNrVlNQdCgXuma"
- },
- "assemblyrefs": [
- {
- "version": "4.0.0.0",
- "name": "mscorlib"
- },
- {
- "version": "4.0.0.0",
- "name": "System"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Net.Http"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Core"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Runtime.Serialization"
- },
- {
- "version": "6.0.0.0",
- "name": "Newtonsoft.Json"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Xml"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Xml.Linq"
- }
- ],
- "typerefs": [
- {
- "typename": "Newtonsoft.Json.Bson.BsonReader",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Bson.BsonWriter",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.DefaultValueHandling",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Formatting",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.JsonReader",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.JsonSerializer",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.JsonSerializerSettings",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.JsonTextReader",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.JsonTextWriter",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.JsonWriter",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Linq.JArray",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Linq.JContainer",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Linq.JObject",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Linq.JToken",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Linq.JTokenReader",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Linq.JTokenType",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Linq.JValue",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.MemberSerialization",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.MissingMemberHandling",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.NullValueHandling",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Required",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Serialization.DefaultContractResolver",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Serialization.ErrorContext",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Serialization.ErrorEventArgs",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Serialization.IContractResolver",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Serialization.JsonProperty",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.TypeNameHandling",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "System.CodeDom.Compiler.GeneratedCodeAttribute",
- "assembly": "System"
- },
- {
- "typename": "System.Collections.Specialized.NameObjectCollectionBase",
- "assembly": "System"
- },
- {
- "typename": "System.Collections.Specialized.NameValueCollection",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.DefaultValueAttribute",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.EditorBrowsableAttribute",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.EditorBrowsableState",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.InvalidEnumArgumentException",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.ProgressChangedEventArgs",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.TypeConverter",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.TypeDescriptor",
- "assembly": "System"
- },
- {
- "typename": "System.Net.Cookie",
- "assembly": "System"
- },
- {
- "typename": "System.Net.HttpStatusCode",
- "assembly": "System"
- },
- {
- "typename": "System.Net.TransportContext",
- "assembly": "System"
- },
- {
- "typename": "System.Uri",
- "assembly": "System"
- },
- {
- "typename": "System.Collections.Generic.HashSet`1",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.Enumerable",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.IOrderedEnumerable`1",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.IQueryable`1",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Net.Http.DelegatingHandler",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.ContentDispositionHeaderValue",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.ContentRangeHeaderValue",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.HttpContentHeaders",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.HttpHeaderValueCollection`1",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.HttpHeaders",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.HttpRequestHeaders",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.HttpResponseHeaders",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.MediaTypeHeaderValue",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.MediaTypeWithQualityHeaderValue",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.NameValueHeaderValue",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.RangeHeaderValue",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.RangeItemHeaderValue",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.StringWithQualityHeaderValue",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.HttpClient",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.HttpClientHandler",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.HttpContent",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.HttpMessageHandler",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.HttpMethod",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.HttpRequestMessage",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.HttpResponseMessage",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.MultipartContent",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.StreamContent",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.StringContent",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Runtime.Serialization.DataContractSerializer",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Runtime.Serialization.Json.DataContractJsonSerializer",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Runtime.Serialization.Json.JsonReaderWriterFactory",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Runtime.Serialization.XmlObjectSerializer",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Runtime.Serialization.XsdDataContractExporter",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Xml.OnXmlDictionaryReaderClose",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Xml.XmlDictionaryReader",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Xml.XmlDictionaryReaderQuotas",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Xml.XmlDictionaryWriter",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Xml.Serialization.XmlSerializer",
- "assembly": "System.Xml"
- },
- {
- "typename": "System.Xml.XmlNode",
- "assembly": "System.Xml"
- },
- {
- "typename": "System.Xml.XmlQualifiedName",
- "assembly": "System.Xml"
- },
- {
- "typename": "System.Xml.XmlReader",
- "assembly": "System.Xml"
- },
- {
- "typename": "System.Xml.XmlWriter",
- "assembly": "System.Xml"
- },
- {
- "typename": "System.Xml.XmlWriterSettings",
- "assembly": "System.Xml"
- },
- {
- "typename": "System.Xml.Linq.XObject",
- "assembly": "System.Xml.Linq"
- },
- {
- "typename": "System.Action`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Action`3",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Activator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ArgumentException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ArgumentNullException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ArgumentOutOfRangeException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Array",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ArraySegment`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.AsyncCallback",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Buffer",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Byte",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Char",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Concurrent.ConcurrentDictionary`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.DictionaryEntry",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.Dictionary`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.ICollection`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.IComparer`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.IDictionary`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.IEnumerable`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.IEnumerator`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.IEqualityComparer`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.IList`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.KeyNotFoundException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.KeyValuePair`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.List`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.List`1/Enumerator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.ICollection",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IDictionary",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IDictionaryEnumerator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IEnumerable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IEnumerator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IEqualityComparer",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.ObjectModel.Collection`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Comparison`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Convert",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.DBNull",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.DateTimeOffset",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Delegate",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggableAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggableAttribute/DebuggingModes",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggerDisplayAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggerHiddenAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggerNonUserCodeAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Enum",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Environment",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.EventArgs",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.EventHandler",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.EventHandler`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Exception",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.FormatException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`3",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`4",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.GC",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.CultureInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.DateTimeFormatInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.DateTimeStyles",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.NumberFormatInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.NumberStyles",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Guid",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IAsyncResult",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ICloneable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IDisposable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IFormatProvider",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.BinaryReader",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.BinaryWriter",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.BufferedStream",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.File",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.FileOptions",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.FileStream",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.IOException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.MemoryStream",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.Path",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.SeekOrigin",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.Stream",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.StreamReader",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.StreamWriter",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.TextReader",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.TextWriter",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Int32",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Int64",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.InvalidOperationException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Lazy`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Math",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.NotImplementedException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.NotSupportedException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Nullable`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Object",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ObjectDisposedException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.OperationCanceledException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ParamArrayAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Assembly",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.ConstructorInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.DefaultMemberAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MemberInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MethodBase",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MethodInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Resources.ResourceManager",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.AsyncStateMachineAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.AsyncTaskMethodBuilder",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.AsyncTaskMethodBuilder`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilationRelaxationsAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilerGeneratedAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.ExtensionAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.IAsyncStateMachine",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.IteratorStateMachineAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.RuntimeCompatibilityAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.TaskAwaiter",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.TaskAwaiter`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.Serialization.SerializationInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.Serialization.StreamingContext",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.RuntimeTypeHandle",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.String",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.StringComparer",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.StringComparison",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Text.Encoding",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Text.StringBuilder",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Text.UTF8Encoding",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Text.UnicodeEncoding",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.CancellationToken",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Interlocked",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Tasks.Task",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Tasks.TaskCompletionSource`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Tasks.TaskStatus",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Tasks.Task`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.WaitHandle",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.TimeSpan",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Type",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ValueType",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Version",
- "assembly": "mscorlib"
- }
- ]
- },
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "_CorExeMain",
- "address": "0x402000"
- }
- ],
- "dll": "mscoree.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x0008f37b",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x0008f37b",
- "icon_hash": null,
- "entrypoint": "0x0043241e",
- "timestamp": "2019-05-15 12:33:59",
- "osversion": "4.0",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00002000",
- "size_of_data": "0x00030600",
- "entropy": "6.05",
- "raw_address": "0x00000200",
- "virtual_size": "0x00030424",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00034000",
- "size_of_data": "0x00058600",
- "entropy": "7.15",
- "raw_address": "0x00030800",
- "virtual_size": "0x00058440",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0008e000",
- "size_of_data": "0x00000200",
- "entropy": "0.10",
- "raw_address": "0x00088e00",
- "virtual_size": "0x0000000c",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x000323c8",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000053"
- },
- {
- "virtual_address": "0x00034000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00058440"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0008e000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x0000000c"
- },
- {
- "virtual_address": "0x0003233c",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000008"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002008",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000048"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "f34d5f2d4577ed6d9ceec516c1f5a744",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "C:\\xampp\\htdocs\\Aspire\\files\\darklorddyagi07_mjVldNrVlNQdCgXu\\mjVldNrVlNQdCgXuma.pdb",
- "imported_dll_count": 1,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegQueryInfoKeyW",
- "advapi32.dll.RegEnumKeyExW",
- "advapi32.dll.RegEnumValueW",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.RegQueryValueExW",
- "kernel32.dll.QueryActCtxW",
- "shlwapi.dll.UrlIsW"
- ]
- [*] Static Analysis: {
- "dotnet": {
- "customattrs": [
- {
- "type": "TypeDef",
- "name": "[mscorlib]System.Reflection.DefaultMemberAttribute",
- "value": "It"
- },
- {
- "type": "TypeDef",
- "name": "[mscorlib]System.Reflection.DefaultMemberAttribute",
- "value": "It"
- },
- {
- "type": "TypeDef",
- "name": "[mscorlib]System.Reflection.DefaultMemberAttribute",
- "value": "It"
- },
- {
- "type": "TypeDef",
- "name": "[mscorlib]System.Diagnostics.DebuggerDisplayAttribute",
- "value": "{DebuggerToString("
- }
- ],
- "assemblyinfo": {
- "version": "0.0.0.0",
- "name": "mjVldNrVlNQdCgXuma"
- },
- "assemblyrefs": [
- {
- "version": "4.0.0.0",
- "name": "mscorlib"
- },
- {
- "version": "4.0.0.0",
- "name": "System"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Net.Http"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Core"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Runtime.Serialization"
- },
- {
- "version": "6.0.0.0",
- "name": "Newtonsoft.Json"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Xml"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Xml.Linq"
- }
- ],
- "typerefs": [
- {
- "typename": "Newtonsoft.Json.Bson.BsonReader",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Bson.BsonWriter",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.DefaultValueHandling",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Formatting",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.JsonReader",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.JsonSerializer",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.JsonSerializerSettings",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.JsonTextReader",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.JsonTextWriter",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.JsonWriter",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Linq.JArray",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Linq.JContainer",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Linq.JObject",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Linq.JToken",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Linq.JTokenReader",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Linq.JTokenType",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Linq.JValue",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.MemberSerialization",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.MissingMemberHandling",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.NullValueHandling",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Required",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Serialization.DefaultContractResolver",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Serialization.ErrorContext",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Serialization.ErrorEventArgs",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Serialization.IContractResolver",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.Serialization.JsonProperty",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "Newtonsoft.Json.TypeNameHandling",
- "assembly": "Newtonsoft.Json"
- },
- {
- "typename": "System.CodeDom.Compiler.GeneratedCodeAttribute",
- "assembly": "System"
- },
- {
- "typename": "System.Collections.Specialized.NameObjectCollectionBase",
- "assembly": "System"
- },
- {
- "typename": "System.Collections.Specialized.NameValueCollection",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.DefaultValueAttribute",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.EditorBrowsableAttribute",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.EditorBrowsableState",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.InvalidEnumArgumentException",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.ProgressChangedEventArgs",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.TypeConverter",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.TypeDescriptor",
- "assembly": "System"
- },
- {
- "typename": "System.Net.Cookie",
- "assembly": "System"
- },
- {
- "typename": "System.Net.HttpStatusCode",
- "assembly": "System"
- },
- {
- "typename": "System.Net.TransportContext",
- "assembly": "System"
- },
- {
- "typename": "System.Uri",
- "assembly": "System"
- },
- {
- "typename": "System.Collections.Generic.HashSet`1",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.Enumerable",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.IOrderedEnumerable`1",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.IQueryable`1",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Net.Http.DelegatingHandler",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.ContentDispositionHeaderValue",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.ContentRangeHeaderValue",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.HttpContentHeaders",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.HttpHeaderValueCollection`1",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.HttpHeaders",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.HttpRequestHeaders",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.HttpResponseHeaders",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.MediaTypeHeaderValue",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.MediaTypeWithQualityHeaderValue",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.NameValueHeaderValue",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.RangeHeaderValue",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.RangeItemHeaderValue",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.Headers.StringWithQualityHeaderValue",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.HttpClient",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.HttpClientHandler",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.HttpContent",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.HttpMessageHandler",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.HttpMethod",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.HttpRequestMessage",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.HttpResponseMessage",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.MultipartContent",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.StreamContent",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Net.Http.StringContent",
- "assembly": "System.Net.Http"
- },
- {
- "typename": "System.Runtime.Serialization.DataContractSerializer",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Runtime.Serialization.Json.DataContractJsonSerializer",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Runtime.Serialization.Json.JsonReaderWriterFactory",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Runtime.Serialization.XmlObjectSerializer",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Runtime.Serialization.XsdDataContractExporter",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Xml.OnXmlDictionaryReaderClose",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Xml.XmlDictionaryReader",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Xml.XmlDictionaryReaderQuotas",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Xml.XmlDictionaryWriter",
- "assembly": "System.Runtime.Serialization"
- },
- {
- "typename": "System.Xml.Serialization.XmlSerializer",
- "assembly": "System.Xml"
- },
- {
- "typename": "System.Xml.XmlNode",
- "assembly": "System.Xml"
- },
- {
- "typename": "System.Xml.XmlQualifiedName",
- "assembly": "System.Xml"
- },
- {
- "typename": "System.Xml.XmlReader",
- "assembly": "System.Xml"
- },
- {
- "typename": "System.Xml.XmlWriter",
- "assembly": "System.Xml"
- },
- {
- "typename": "System.Xml.XmlWriterSettings",
- "assembly": "System.Xml"
- },
- {
- "typename": "System.Xml.Linq.XObject",
- "assembly": "System.Xml.Linq"
- },
- {
- "typename": "System.Action`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Action`3",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Activator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ArgumentException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ArgumentNullException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ArgumentOutOfRangeException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Array",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ArraySegment`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.AsyncCallback",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Buffer",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Byte",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Char",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Concurrent.ConcurrentDictionary`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.DictionaryEntry",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.Dictionary`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.ICollection`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.IComparer`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.IDictionary`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.IEnumerable`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.IEnumerator`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.IEqualityComparer`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.IList`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.KeyNotFoundException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.KeyValuePair`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.List`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.List`1/Enumerator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.ICollection",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IDictionary",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IDictionaryEnumerator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IEnumerable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IEnumerator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IEqualityComparer",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.ObjectModel.Collection`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Comparison`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Convert",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.DBNull",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.DateTimeOffset",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Delegate",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggableAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggableAttribute/DebuggingModes",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggerDisplayAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggerHiddenAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggerNonUserCodeAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Enum",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Environment",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.EventArgs",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.EventHandler",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.EventHandler`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Exception",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.FormatException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`3",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`4",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.GC",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.CultureInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.DateTimeFormatInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.DateTimeStyles",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.NumberFormatInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.NumberStyles",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Guid",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IAsyncResult",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ICloneable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IDisposable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IFormatProvider",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.BinaryReader",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.BinaryWriter",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.BufferedStream",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.File",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.FileOptions",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.FileStream",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.IOException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.MemoryStream",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.Path",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.SeekOrigin",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.Stream",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.StreamReader",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.StreamWriter",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.TextReader",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IO.TextWriter",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Int32",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Int64",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.InvalidOperationException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Lazy`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Math",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.NotImplementedException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.NotSupportedException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Nullable`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Object",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ObjectDisposedException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.OperationCanceledException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ParamArrayAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Assembly",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.ConstructorInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.DefaultMemberAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MemberInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MethodBase",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MethodInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Resources.ResourceManager",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.AsyncStateMachineAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.AsyncTaskMethodBuilder",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.AsyncTaskMethodBuilder`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilationRelaxationsAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilerGeneratedAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.ExtensionAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.IAsyncStateMachine",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.IteratorStateMachineAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.RuntimeCompatibilityAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.TaskAwaiter",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.TaskAwaiter`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.Serialization.SerializationInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.Serialization.StreamingContext",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.RuntimeTypeHandle",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.String",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.StringComparer",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.StringComparison",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Text.Encoding",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Text.StringBuilder",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Text.UTF8Encoding",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Text.UnicodeEncoding",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.CancellationToken",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Interlocked",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Tasks.Task",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Tasks.TaskCompletionSource`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Tasks.TaskStatus",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Tasks.Task`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.WaitHandle",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.TimeSpan",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Type",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ValueType",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Version",
- "assembly": "mscorlib"
- }
- ]
- },
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "_CorExeMain",
- "address": "0x402000"
- }
- ],
- "dll": "mscoree.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x0008f37b",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x0008f37b",
- "icon_hash": null,
- "entrypoint": "0x0043241e",
- "timestamp": "2019-05-15 12:33:59",
- "osversion": "4.0",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00002000",
- "size_of_data": "0x00030600",
- "entropy": "6.05",
- "raw_address": "0x00000200",
- "virtual_size": "0x00030424",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00034000",
- "size_of_data": "0x00058600",
- "entropy": "7.15",
- "raw_address": "0x00030800",
- "virtual_size": "0x00058440",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0008e000",
- "size_of_data": "0x00000200",
- "entropy": "0.10",
- "raw_address": "0x00088e00",
- "virtual_size": "0x0000000c",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x000323c8",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000053"
- },
- {
- "virtual_address": "0x00034000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00058440"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0008e000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x0000000c"
- },
- {
- "virtual_address": "0x0003233c",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000008"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002008",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000048"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "f34d5f2d4577ed6d9ceec516c1f5a744",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "C:\\xampp\\htdocs\\Aspire\\files\\darklorddyagi07_mjVldNrVlNQdCgXu\\mjVldNrVlNQdCgXuma.pdb",
- "imported_dll_count": 1,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement