Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: "Azorult"
- [*] MalScore: 10.0
- [*] File Name: "AZORult_7e737724659016819f1ba63b01e5732a.exe"
- [*] File Size: 689664
- [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- [*] SHA256: "4eb0099736e377d14e5fdc8a4cd6c2cf9de70b531c75ce53621c315695365df6"
- [*] MD5: "7e737724659016819f1ba63b01e5732a"
- [*] SHA1: "9c3f443d5a304a69b50d97c67d2142f7c018e289"
- [*] SHA512: "984a04cc2c2b12bdc80379b1bd80fdceb0c11d729865dda6e696bf674b1c9c742a79265d4fde50b3fe79768021fd27078b6161ecc461aa85ee22f71813ffd156"
- [*] CRC32: "17548FAE"
- [*] SSDEEP: "12288:H0f1JN1W7i2ku4Na0L4CIzxL5zrd7k8vG:He/N1oku4/cZbzxI8u"
- [*] Process Execution: [
- "AZORult_7e737724659016819f1ba63b01e5732a.exe",
- "jeffohn.exe",
- "jeffohn.exe",
- "cmd.exe",
- "timeout.exe",
- "services.exe",
- "lsass.exe",
- "taskhost.exe",
- "sc.exe",
- "svchost.exe",
- "WerFault.exe",
- "wermgr.exe",
- "svchost.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "At least one process apparently crashed during execution",
- "Details": []
- },
- {
- "Description": "Creates RWX memory",
- "Details": []
- },
- {
- "Description": "A process created a hidden window",
- "Details": [
- {
- "Process": "jeffohn.exe -> C:\\Windows\\System32\\cmd.exe"
- }
- ]
- },
- {
- "Description": "Drops a binary and executes it",
- "Details": [
- {
- "binary": "C:\\Users\\user\\AppData\\Roaming\\jeffoth\\jeffohn.exe"
- }
- ]
- },
- {
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details": [
- {
- "post_no_referer": "HTTP traffic contains a POST request with no referer header"
- },
- {
- "suspicious_request": "http://hst.fidelityinvest.online/index.php"
- }
- ]
- },
- {
- "Description": "Performs some HTTP requests",
- "Details": [
- {
- "url": "http://hst.fidelityinvest.online/index.php"
- }
- ]
- },
- {
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details": [
- {
- "section": "name: .rsrc, entropy: 6.96, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ, raw_size: 0x0002a000, virtual_size: 0x00029e20"
- }
- ]
- },
- {
- "Description": "Executed a process and injected code into it, probably while unpacking",
- "Details": [
- {
- "Injection": "jeffohn.exe(2432) -> jeffohn.exe(1396)"
- }
- ]
- },
- {
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details": [
- {
- "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 9756914 times"
- }
- ]
- },
- {
- "Description": "Steals private information from local Internet browsers",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@doubleclick[1].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@advertising[1].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@c.bing[2].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@media[2].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@www.google[1].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@google[5].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@google[4].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@google[3].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@google[1].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@c.msn[2].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Web Data"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@msn[1].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@www.msn[2].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@3lift[1].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\History"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@bing[2].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@scorecardresearch[2].txt"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cookies"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\user@atwola[2].txt"
- }
- ]
- },
- {
- "Description": "Collects information about installed applications",
- "Details": [
- {
- "Program": "Google Update Helper"
- },
- {
- },
- {
- "Program": "Microsoft Excel MUI 2013"
- },
- {
- "Program": "Microsoft Outlook MUI 2013"
- },
- {
- },
- {
- "Program": "Google Chrome"
- },
- {
- "Program": "Adobe Flash Player 29 NPAPI"
- },
- {
- "Program": "Adobe Flash Player 29 ActiveX"
- },
- {
- "Program": "Microsoft DCF MUI 2013"
- },
- {
- "Program": "Microsoft Access MUI 2013"
- },
- {
- "Program": "Microsoft Office Proofing Tools 2013 - English"
- },
- {
- "Program": "Adobe Acrobat Reader DC"
- },
- {
- "Program": "Microsoft Publisher MUI 2013"
- },
- {
- "Program": "Microsoft Office Shared MUI 2013"
- },
- {
- "Program": "Microsoft Office OSM MUI 2013"
- },
- {
- "Program": "Microsoft InfoPath MUI 2013"
- },
- {
- "Program": "Microsoft Office Shared Setup Metadata MUI 2013"
- },
- {
- "Program": "Outils de v\\xc3\\xa9rification linguistique 2013 de Microsoft Office\\xc2\\xa0- Fran\\xc3\\xa7ais"
- },
- {
- "Program": "Microsoft Word MUI 2013"
- },
- {
- "Program": "Microsoft OneDrive"
- },
- {
- "Program": "Microsoft Groove MUI 2013"
- },
- {
- "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xc3\\xb1ol"
- },
- {
- },
- {
- "Program": "Microsoft Access Setup Metadata MUI 2013"
- },
- {
- "Program": "Microsoft Office OSM UX MUI 2013"
- },
- {
- "Program": "Java Auto Updater"
- },
- {
- "Program": "Microsoft PowerPoint MUI 2013"
- },
- {
- "Program": "Microsoft Office Professional Plus 2013"
- },
- {
- "Program": "Adobe Refresh Manager"
- },
- {
- "Program": "Microsoft Office Proofing 2013"
- },
- {
- "Program": "Microsoft Lync MUI 2013"
- },
- {
- },
- {
- "Program": "Microsoft OneNote MUI 2013"
- }
- ]
- },
- {
- "Description": "Checks the CPU name from registry, possibly for anti-virtualization",
- "Details": []
- },
- {
- "Description": "Checks the system manufacturer, likely for anti-virtualization",
- "Details": []
- },
- {
- "Description": "Creates a copy of itself",
- "Details": [
- {
- "copy": "C:\\Users\\user\\AppData\\Roaming\\jeffoth\\jeffohn.exe"
- }
- ]
- },
- {
- "Description": "Attempts to access Bitcoin/ALTCoin wallets",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Adobe\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Sun\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\jeffoth\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Identities\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Macromedia\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Notepad++\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\wallet.dat"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Electrum\\wallets\\*"
- }
- ]
- },
- {
- "Description": "Harvests credentials from local FTP client softwares",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\filezilla\\recentservers.xml"
- }
- ]
- },
- {
- "Description": "Harvests information related to installed instant messenger clients",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\.purple\\accounts.xml"
- }
- ]
- },
- {
- "Description": "Harvests information related to installed mail clients",
- "Details": [
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b22783abb139fe46b0aad551d64b60e7"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9234ed9445f8fa418a542f350f18f326"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\Email"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\cb23f8734d88734ca66c47c4527fd259"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\Email"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8408552e6dae7d45a0ba01520b6221ff"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\c02ebc5353d9cd11975200aa004ae40e"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Outlook\\Profiles\\Outlook"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\240a97d961ed46428e29a3f1f1c23670"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8f92b60606058348930a96946cf329e1"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002"
- }
- ]
- },
- {
- "Description": "Attempts to interact with an Alternate Data Stream (ADS)",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\jeffoth\\jeffohn.exe:ZoneIdentifier"
- }
- ]
- },
- {
- "Description": "Collects information to fingerprint the system",
- "Details": []
- },
- {
- "Description": "Anomalous binary characteristics",
- "Details": [
- {
- "anomaly": "Timestamp on binary predates the release date of the OS version it requires by at least a year"
- }
- ]
- },
- {
- "Description": "Created network traffic indicative of malicious activity",
- "Details": [
- {
- "signature": "ET TROJAN Generic - POST To .php w/Extended ASCII Characters (Likely Zeus Derivative)"
- },
- {
- "signature": "ET TROJAN AZORult Variant.4 Checkin M2"
- }
- ]
- }
- ]
- [*] Started Service: [
- "VaultSvc",
- "WerSvc",
- "W32Time"
- ]
- [*] Executed Commands: [
- "\"C:\\Users\\user\\AppData\\Roaming\\jeffoth\\jeffohn.exe\"",
- "C:\\Windows\\System32\\cmd.exe /c C:\\Windows\\system32\\timeout.exe 3 & del \"jeffohn.exe\"",
- "C:\\Windows\\system32\\lsass.exe",
- "taskhost.exe $(Arg0)",
- "C:\\Windows\\system32\\sc.exe start w32time task_started",
- "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
- "C:\\Windows\\system32\\svchost.exe -k LocalService",
- "C:\\Windows\\system32\\timeout.exe 3",
- "C:\\Windows\\system32\\WerFault.exe -u -p 2940 -s 288",
- "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_075c152c\""
- ]
- [*] Mutexes: [
- "A81FB8C6-0BBE6E18-6FC9B5DB-536DA455-933946726",
- "Local\\WERReportingForProcess2940",
- "Global\\\\xe5\\x88\\x90\\xc2\\x8a",
- "Global\\\\xed\\x95\\xb0\\xc7\\x99",
- "WERUI_BEX64-eb71ef964c95de5826f5dbf6417783430b96dd1"
- ]
- [*] Modified Files: [
- "C:\\Users\\user\\AppData\\Roaming\\jeffoth\\jeffohn.exe",
- "C:\\Users\\user\\AppData\\Roaming\\jeffoth\\jeffohn.exe:ZoneIdentifier",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-console-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-datetime-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-debug-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-errorhandling-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-file-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-file-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-file-l2-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-handle-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-heap-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-interlocked-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-libraryloader-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-localization-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-memory-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-namedpipe-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-processenvironment-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-processthreads-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-processthreads-l1-1-1.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-profile-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-rtlsupport-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-string-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-synch-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-synch-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-sysinfo-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-timezone-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-util-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-conio-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-convert-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-environment-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-filesystem-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-heap-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-locale-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-math-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-multibyte-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-private-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-process-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-runtime-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-stdio-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-string-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-time-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-utility-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\freebl3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\mozglue.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\msvcp140.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\nss3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\nssdbm3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\softokn3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\ucrtbase.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\vcruntime140.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\266007348176247098012788.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\266520789491450436885344.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\266521563234303010243891.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\266522037512321030435368.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\266522657853713039354893.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\curbuf.dat",
- "C:\\Windows\\sysnative\\LogFiles\\Scm\\4963ad21-c4a5-42a5-b9bd-e441d57204fe",
- "C:\\Windows\\sysnative\\LogFiles\\Scm\\7bbc503c-5977-4798-a4ae-61483a7e030d",
- "\\??\\PIPE\\lsarpc",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAE77.tmp.appcompat.txt",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERB1D4.tmp.WERInternalMetadata.xml",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERB223.tmp.hdmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERBCE2.tmp.mdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_075c152c\\WERAE77.tmp.appcompat.txt",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_075c152c\\WERB1D4.tmp.WERInternalMetadata.xml",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_075c152c\\WERB223.tmp.hdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_075c152c\\WERBCE2.tmp.mdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_075c152c\\Report.wer",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_075c152c\\Report.wer.tmp"
- ]
- [*] Deleted Files: [
- "C:\\Users\\user\\AppData\\Roaming\\jeffoth\\jeffohn.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\266007348176247098012788.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\266520789491450436885344.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\266521563234303010243891.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\266522037512321030435368.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\266522657853713039354893.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\curbuf.dat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-console-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-datetime-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-debug-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-errorhandling-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-file-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-file-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-file-l2-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-handle-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-heap-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-interlocked-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-libraryloader-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-localization-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-memory-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-namedpipe-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-processenvironment-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-processthreads-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-processthreads-l1-1-1.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-profile-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-rtlsupport-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-string-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-synch-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-synch-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-sysinfo-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-timezone-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-core-util-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-conio-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-convert-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-environment-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-filesystem-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-heap-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-locale-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-math-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-multibyte-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-private-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-process-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-runtime-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-stdio-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-string-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-time-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\api-ms-win-crt-utility-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\freebl3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\mozglue.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\msvcp140.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\nss3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\nssdbm3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\softokn3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\ucrtbase.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\vcruntime140.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2fda\\",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAE77.tmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAE77.tmp.appcompat.txt",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERB1D4.tmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERB1D4.tmp.WERInternalMetadata.xml",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERB223.tmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERB223.tmp.hdmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERBCE2.tmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERBCE2.tmp.mdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_075c152c\\Report.wer.tmp"
- ]
- [*] Modified Registry Keys: [
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\TimeProviders\\NtpClient\\SpecialPollTimeRemaining",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent\\DefaultConsent"
- ]
- [*] Deleted Registry Keys: []
- [*] DNS Communications: [
- {
- "type": "A",
- "request": "hst.fidelityinvest.online",
- "answers": [
- {
- "data": "185.229.239.28",
- "type": "A"
- }
- ]
- }
- ]
- [*] Domains: [
- {
- "ip": "185.229.239.28",
- "domain": "hst.fidelityinvest.online"
- }
- ]
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: [
- {
- "count": 1,
- "body": "J/\\xfb5/\\xfb<L\\x8a(9\\xf0N/\\xfb;/\\xfaI/\\xfb=H\\x8aH/\\xfb;O\\xed>;\\xed>2\\xed?N\\xed><\\x8eN/\\xfb4H\\xed>?\\x8cO/\\xfaI/\\xfb8/\\xfb>/\\xfb;N\\x89(9\\xfc(9\\xfd(9\\xfd(8\\x8c(9\\xf1(9\\xfb(9\\xfb(9\\xf1(9\\xfc(9\\xfe(9\\xff(9\\xfa(9\\xfe",
- "uri": "http://hst.fidelityinvest.online/index.php",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.1)",
- "method": "POST",
- "host": "hst.fidelityinvest.online",
- "version": "1.1",
- "path": "/index.php",
- "data": "POST /index.php HTTP/1.1\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.1)\r\nHost: hst.fidelityinvest.online\r\nContent-Length: 105\r\nCache-Control: no-cache\r\n\r\nJ/\\xfb5/\\xfb<L\\x8a(9\\xf0N/\\xfb;/\\xfaI/\\xfb=H\\x8aH/\\xfb;O\\xed>;\\xed>2\\xed?N\\xed><\\x8eN/\\xfb4H\\xed>?\\x8cO/\\xfaI/\\xfb8/\\xfb>/\\xfb;N\\x89(9\\xfc(9\\xfd(9\\xfd(8\\x8c(9\\xf1(9\\xfb(9\\xfb(9\\xf1(9\\xfc(9\\xfe(9\\xff(9\\xfa(9\\xfe",
- "port": 80
- },
- {
- "count": 1,
- "body": "",
- "uri": "http://hst.fidelityinvest.online/index.php",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.1)",
- "method": "POST",
- "host": "hst.fidelityinvest.online",
- "version": "1.1",
- "path": "/index.php",
- "data": "POST /index.php HTTP/1.1\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.1)\r\nHost: hst.fidelityinvest.online\r\nContent-Length: 64378\r\nCache-Control: no-cache\r\n\r\n",
- "port": 80
- }
- ]
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DeleteCriticalSection",
- "address": "0x476168"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x47616c"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x476170"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x476174"
- },
- {
- "name": "VirtualFree",
- "address": "0x476178"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x47617c"
- },
- {
- "name": "LocalFree",
- "address": "0x476180"
- },
- {
- "name": "LocalAlloc",
- "address": "0x476184"
- },
- {
- "name": "GetVersion",
- "address": "0x476188"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x47618c"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x476190"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x476194"
- },
- {
- "name": "VirtualQuery",
- "address": "0x476198"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x47619c"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x4761a0"
- },
- {
- "name": "lstrlenA",
- "address": "0x4761a4"
- },
- {
- "name": "lstrcpynA",
- "address": "0x4761a8"
- },
- {
- "name": "LoadLibraryExA",
- "address": "0x4761ac"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x4761b0"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x4761b4"
- },
- {
- "name": "GetProcAddress",
- "address": "0x4761b8"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x4761bc"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x4761c0"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x4761c4"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x4761c8"
- },
- {
- "name": "FreeLibrary",
- "address": "0x4761cc"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x4761d0"
- },
- {
- "name": "FindClose",
- "address": "0x4761d4"
- },
- {
- "name": "ExitProcess",
- "address": "0x4761d8"
- },
- {
- "name": "ExitThread",
- "address": "0x4761dc"
- },
- {
- "name": "CreateThread",
- "address": "0x4761e0"
- },
- {
- "name": "WriteFile",
- "address": "0x4761e4"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x4761e8"
- },
- {
- "name": "RtlUnwind",
- "address": "0x4761ec"
- },
- {
- "name": "RaiseException",
- "address": "0x4761f0"
- },
- {
- "name": "GetStdHandle",
- "address": "0x4761f4"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "GetKeyboardType",
- "address": "0x4761fc"
- },
- {
- "name": "LoadStringA",
- "address": "0x476200"
- },
- {
- "name": "MessageBoxA",
- "address": "0x476204"
- },
- {
- "name": "CharNextA",
- "address": "0x476208"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x476210"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x476214"
- },
- {
- "name": "RegCloseKey",
- "address": "0x476218"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "SysFreeString",
- "address": "0x476220"
- },
- {
- "name": "SysReAllocStringLen",
- "address": "0x476224"
- },
- {
- "name": "SysAllocStringLen",
- "address": "0x476228"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "TlsSetValue",
- "address": "0x476230"
- },
- {
- "name": "TlsGetValue",
- "address": "0x476234"
- },
- {
- "name": "LocalAlloc",
- "address": "0x476238"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x47623c"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x476244"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x476248"
- },
- {
- "name": "RegCloseKey",
- "address": "0x47624c"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "lstrcpyA",
- "address": "0x476254"
- },
- {
- "name": "WriteFile",
- "address": "0x476258"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x47625c"
- },
- {
- "name": "VirtualQuery",
- "address": "0x476260"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x476264"
- },
- {
- "name": "SuspendThread",
- "address": "0x476268"
- },
- {
- "name": "Sleep",
- "address": "0x47626c"
- },
- {
- "name": "SizeofResource",
- "address": "0x476270"
- },
- {
- "name": "SetThreadPriority",
- "address": "0x476274"
- },
- {
- "name": "SetThreadLocale",
- "address": "0x476278"
- },
- {
- "name": "SetFilePointer",
- "address": "0x47627c"
- },
- {
- "name": "SetEvent",
- "address": "0x476280"
- },
- {
- "name": "SetErrorMode",
- "address": "0x476284"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x476288"
- },
- {
- "name": "ResumeThread",
- "address": "0x47628c"
- },
- {
- "name": "ResetEvent",
- "address": "0x476290"
- },
- {
- "name": "ReadFile",
- "address": "0x476294"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x476298"
- },
- {
- "name": "MulDiv",
- "address": "0x47629c"
- },
- {
- "name": "LockResource",
- "address": "0x4762a0"
- },
- {
- "name": "LoadResource",
- "address": "0x4762a4"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x4762a8"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x4762ac"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x4762b0"
- },
- {
- "name": "GlobalUnlock",
- "address": "0x4762b4"
- },
- {
- "name": "GlobalSize",
- "address": "0x4762b8"
- },
- {
- "name": "GlobalReAlloc",
- "address": "0x4762bc"
- },
- {
- "name": "GlobalHandle",
- "address": "0x4762c0"
- },
- {
- "name": "GlobalLock",
- "address": "0x4762c4"
- },
- {
- "name": "GlobalFree",
- "address": "0x4762c8"
- },
- {
- "name": "GlobalFindAtomA",
- "address": "0x4762cc"
- },
- {
- "name": "GlobalDeleteAtom",
- "address": "0x4762d0"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x4762d4"
- },
- {
- "name": "GlobalAddAtomA",
- "address": "0x4762d8"
- },
- {
- "name": "GetVersionExA",
- "address": "0x4762dc"
- },
- {
- "name": "GetVersion",
- "address": "0x4762e0"
- },
- {
- "name": "GetUserDefaultLCID",
- "address": "0x4762e4"
- },
- {
- "name": "GetTickCount",
- "address": "0x4762e8"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x4762ec"
- },
- {
- "name": "GetTempPathA",
- "address": "0x4762f0"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x4762f4"
- },
- {
- "name": "GetStringTypeExA",
- "address": "0x4762f8"
- },
- {
- "name": "GetStdHandle",
- "address": "0x4762fc"
- },
- {
- "name": "GetProfileStringA",
- "address": "0x476300"
- },
- {
- "name": "GetProcAddress",
- "address": "0x476304"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x476308"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x47630c"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x476310"
- },
- {
- "name": "GetLocalTime",
- "address": "0x476314"
- },
- {
- "name": "GetLastError",
- "address": "0x476318"
- },
- {
- "name": "GetFullPathNameA",
- "address": "0x47631c"
- },
- {
- "name": "GetFileSize",
- "address": "0x476320"
- },
- {
- "name": "GetExitCodeThread",
- "address": "0x476324"
- },
- {
- "name": "GetDiskFreeSpaceA",
- "address": "0x476328"
- },
- {
- "name": "GetDateFormatA",
- "address": "0x47632c"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x476330"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x476334"
- },
- {
- "name": "GetCPInfo",
- "address": "0x476338"
- },
- {
- "name": "GetACP",
- "address": "0x47633c"
- },
- {
- "name": "FreeResource",
- "address": "0x476340"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x476344"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x476348"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x47634c"
- },
- {
- "name": "FreeLibrary",
- "address": "0x476350"
- },
- {
- "name": "FormatMessageA",
- "address": "0x476354"
- },
- {
- "name": "FindResourceA",
- "address": "0x476358"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x47635c"
- },
- {
- "name": "FindClose",
- "address": "0x476360"
- },
- {
- "name": "FileTimeToLocalFileTime",
- "address": "0x476364"
- },
- {
- "name": "FileTimeToDosDateTime",
- "address": "0x476368"
- },
- {
- "name": "EnumCalendarInfoA",
- "address": "0x47636c"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x476370"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x476374"
- },
- {
- "name": "CreateThread",
- "address": "0x476378"
- },
- {
- "name": "CreateFileA",
- "address": "0x47637c"
- },
- {
- "name": "CreateEventA",
- "address": "0x476380"
- },
- {
- "name": "CompareStringA",
- "address": "0x476384"
- },
- {
- "name": "CloseHandle",
- "address": "0x476388"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "VerQueryValueA",
- "address": "0x476390"
- },
- {
- "name": "GetFileVersionInfoSizeA",
- "address": "0x476394"
- },
- {
- "name": "GetFileVersionInfoA",
- "address": "0x476398"
- }
- ],
- "dll": "version.dll"
- },
- {
- "imports": [
- {
- "name": "UnrealizeObject",
- "address": "0x4763a0"
- },
- {
- "name": "StretchBlt",
- "address": "0x4763a4"
- },
- {
- "name": "SetWindowOrgEx",
- "address": "0x4763a8"
- },
- {
- "name": "SetWinMetaFileBits",
- "address": "0x4763ac"
- },
- {
- "name": "SetViewportOrgEx",
- "address": "0x4763b0"
- },
- {
- "name": "SetTextColor",
- "address": "0x4763b4"
- },
- {
- "name": "SetStretchBltMode",
- "address": "0x4763b8"
- },
- {
- "name": "SetROP2",
- "address": "0x4763bc"
- },
- {
- "name": "SetPixel",
- "address": "0x4763c0"
- },
- {
- "name": "SetMapMode",
- "address": "0x4763c4"
- },
- {
- "name": "SetEnhMetaFileBits",
- "address": "0x4763c8"
- },
- {
- "name": "SetDIBColorTable",
- "address": "0x4763cc"
- },
- {
- "name": "SetBrushOrgEx",
- "address": "0x4763d0"
- },
- {
- "name": "SetBkMode",
- "address": "0x4763d4"
- },
- {
- "name": "SetBkColor",
- "address": "0x4763d8"
- },
- {
- "name": "SelectPalette",
- "address": "0x4763dc"
- },
- {
- "name": "SelectObject",
- "address": "0x4763e0"
- },
- {
- "name": "ScaleWindowExtEx",
- "address": "0x4763e4"
- },
- {
- "name": "SaveDC",
- "address": "0x4763e8"
- },
- {
- "name": "RestoreDC",
- "address": "0x4763ec"
- },
- {
- "name": "RectVisible",
- "address": "0x4763f0"
- },
- {
- "name": "RealizePalette",
- "address": "0x4763f4"
- },
- {
- "name": "PlayEnhMetaFile",
- "address": "0x4763f8"
- },
- {
- "name": "PatBlt",
- "address": "0x4763fc"
- },
- {
- "name": "MoveToEx",
- "address": "0x476400"
- },
- {
- "name": "MaskBlt",
- "address": "0x476404"
- },
- {
- "name": "LineTo",
- "address": "0x476408"
- },
- {
- "name": "LPtoDP",
- "address": "0x47640c"
- },
- {
- "name": "IntersectClipRect",
- "address": "0x476410"
- },
- {
- "name": "GetWindowOrgEx",
- "address": "0x476414"
- },
- {
- "name": "GetWinMetaFileBits",
- "address": "0x476418"
- },
- {
- "name": "GetTextMetricsA",
- "address": "0x47641c"
- },
- {
- "name": "GetTextExtentPoint32A",
- "address": "0x476420"
- },
- {
- "name": "GetSystemPaletteEntries",
- "address": "0x476424"
- },
- {
- "name": "GetStockObject",
- "address": "0x476428"
- },
- {
- "name": "GetPixel",
- "address": "0x47642c"
- },
- {
- "name": "GetPaletteEntries",
- "address": "0x476430"
- },
- {
- "name": "GetObjectA",
- "address": "0x476434"
- },
- {
- "name": "GetEnhMetaFilePaletteEntries",
- "address": "0x476438"
- },
- {
- "name": "GetEnhMetaFileHeader",
- "address": "0x47643c"
- },
- {
- "name": "GetEnhMetaFileDescriptionA",
- "address": "0x476440"
- },
- {
- "name": "GetEnhMetaFileBits",
- "address": "0x476444"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x476448"
- },
- {
- "name": "GetDIBits",
- "address": "0x47644c"
- },
- {
- "name": "GetDIBColorTable",
- "address": "0x476450"
- },
- {
- "name": "GetDCOrgEx",
- "address": "0x476454"
- },
- {
- "name": "GetCurrentPositionEx",
- "address": "0x476458"
- },
- {
- "name": "GetClipBox",
- "address": "0x47645c"
- },
- {
- "name": "GetBrushOrgEx",
- "address": "0x476460"
- },
- {
- "name": "GetBitmapBits",
- "address": "0x476464"
- },
- {
- "name": "ExcludeClipRect",
- "address": "0x476468"
- },
- {
- "name": "EndPage",
- "address": "0x47646c"
- },
- {
- "name": "EndDoc",
- "address": "0x476470"
- },
- {
- "name": "DeleteObject",
- "address": "0x476474"
- },
- {
- "name": "DeleteEnhMetaFile",
- "address": "0x476478"
- },
- {
- "name": "DeleteDC",
- "address": "0x47647c"
- },
- {
- "name": "CreateSolidBrush",
- "address": "0x476480"
- },
- {
- "name": "CreatePenIndirect",
- "address": "0x476484"
- },
- {
- "name": "CreatePalette",
- "address": "0x476488"
- },
- {
- "name": "CreateICA",
- "address": "0x47648c"
- },
- {
- "name": "CreateHalftonePalette",
- "address": "0x476490"
- },
- {
- "name": "CreateFontIndirectA",
- "address": "0x476494"
- },
- {
- "name": "CreateEnhMetaFileA",
- "address": "0x476498"
- },
- {
- "name": "CreateDIBitmap",
- "address": "0x47649c"
- },
- {
- "name": "CreateDIBSection",
- "address": "0x4764a0"
- },
- {
- "name": "CreateDCA",
- "address": "0x4764a4"
- },
- {
- "name": "CreateCompatibleDC",
- "address": "0x4764a8"
- },
- {
- "name": "CreateCompatibleBitmap",
- "address": "0x4764ac"
- },
- {
- "name": "CreateBrushIndirect",
- "address": "0x4764b0"
- },
- {
- "name": "CreateBitmap",
- "address": "0x4764b4"
- },
- {
- "name": "CopyEnhMetaFileA",
- "address": "0x4764b8"
- },
- {
- "name": "CloseEnhMetaFile",
- "address": "0x4764bc"
- },
- {
- "name": "BitBlt",
- "address": "0x4764c0"
- }
- ],
- "dll": "gdi32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateWindowExA",
- "address": "0x4764c8"
- },
- {
- "name": "WindowFromPoint",
- "address": "0x4764cc"
- },
- {
- "name": "WinHelpA",
- "address": "0x4764d0"
- },
- {
- "name": "WaitMessage",
- "address": "0x4764d4"
- },
- {
- "name": "UpdateWindow",
- "address": "0x4764d8"
- },
- {
- "name": "UnregisterClassA",
- "address": "0x4764dc"
- },
- {
- "name": "UnhookWindowsHookEx",
- "address": "0x4764e0"
- },
- {
- "name": "TranslateMessage",
- "address": "0x4764e4"
- },
- {
- "name": "TranslateMDISysAccel",
- "address": "0x4764e8"
- },
- {
- "name": "TrackPopupMenu",
- "address": "0x4764ec"
- },
- {
- "name": "SystemParametersInfoA",
- "address": "0x4764f0"
- },
- {
- "name": "ShowWindow",
- "address": "0x4764f4"
- },
- {
- "name": "ShowScrollBar",
- "address": "0x4764f8"
- },
- {
- "name": "ShowOwnedPopups",
- "address": "0x4764fc"
- },
- {
- "name": "ShowCursor",
- "address": "0x476500"
- },
- {
- "name": "SetWindowsHookExA",
- "address": "0x476504"
- },
- {
- "name": "SetWindowPos",
- "address": "0x476508"
- },
- {
- "name": "SetWindowPlacement",
- "address": "0x47650c"
- },
- {
- "name": "SetWindowLongA",
- "address": "0x476510"
- },
- {
- "name": "SetTimer",
- "address": "0x476514"
- },
- {
- "name": "SetScrollRange",
- "address": "0x476518"
- },
- {
- "name": "SetScrollPos",
- "address": "0x47651c"
- },
- {
- "name": "SetScrollInfo",
- "address": "0x476520"
- },
- {
- "name": "SetRect",
- "address": "0x476524"
- },
- {
- "name": "SetPropA",
- "address": "0x476528"
- },
- {
- "name": "SetParent",
- "address": "0x47652c"
- },
- {
- "name": "SetMenuItemInfoA",
- "address": "0x476530"
- },
- {
- "name": "SetMenu",
- "address": "0x476534"
- },
- {
- "name": "SetForegroundWindow",
- "address": "0x476538"
- },
- {
- "name": "SetFocus",
- "address": "0x47653c"
- },
- {
- "name": "SetCursor",
- "address": "0x476540"
- },
- {
- "name": "SetClassLongA",
- "address": "0x476544"
- },
- {
- "name": "SetCapture",
- "address": "0x476548"
- },
- {
- "name": "SetActiveWindow",
- "address": "0x47654c"
- },
- {
- "name": "SendMessageA",
- "address": "0x476550"
- },
- {
- "name": "ScrollWindow",
- "address": "0x476554"
- },
- {
- "name": "ScreenToClient",
- "address": "0x476558"
- },
- {
- "name": "RemovePropA",
- "address": "0x47655c"
- },
- {
- "name": "RemoveMenu",
- "address": "0x476560"
- },
- {
- "name": "ReleaseDC",
- "address": "0x476564"
- },
- {
- "name": "ReleaseCapture",
- "address": "0x476568"
- },
- {
- "name": "RegisterWindowMessageA",
- "address": "0x47656c"
- },
- {
- "name": "RegisterClipboardFormatA",
- "address": "0x476570"
- },
- {
- "name": "RegisterClassA",
- "address": "0x476574"
- },
- {
- "name": "RedrawWindow",
- "address": "0x476578"
- },
- {
- "name": "PtInRect",
- "address": "0x47657c"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x476580"
- },
- {
- "name": "PostMessageA",
- "address": "0x476584"
- },
- {
- "name": "PeekMessageA",
- "address": "0x476588"
- },
- {
- "name": "OffsetRect",
- "address": "0x47658c"
- },
- {
- "name": "OemToCharA",
- "address": "0x476590"
- },
- {
- "name": "MsgWaitForMultipleObjects",
- "address": "0x476594"
- },
- {
- "name": "MessageBoxA",
- "address": "0x476598"
- },
- {
- "name": "MapWindowPoints",
- "address": "0x47659c"
- },
- {
- "name": "MapVirtualKeyA",
- "address": "0x4765a0"
- },
- {
- "name": "LoadStringA",
- "address": "0x4765a4"
- },
- {
- "name": "LoadKeyboardLayoutA",
- "address": "0x4765a8"
- },
- {
- "name": "LoadIconA",
- "address": "0x4765ac"
- },
- {
- "name": "LoadCursorA",
- "address": "0x4765b0"
- },
- {
- "name": "LoadBitmapA",
- "address": "0x4765b4"
- },
- {
- "name": "KillTimer",
- "address": "0x4765b8"
- },
- {
- "name": "IsZoomed",
- "address": "0x4765bc"
- },
- {
- "name": "IsWindowVisible",
- "address": "0x4765c0"
- },
- {
- "name": "IsWindowEnabled",
- "address": "0x4765c4"
- },
- {
- "name": "IsWindow",
- "address": "0x4765c8"
- },
- {
- "name": "IsRectEmpty",
- "address": "0x4765cc"
- },
- {
- "name": "IsIconic",
- "address": "0x4765d0"
- },
- {
- "name": "IsDialogMessageA",
- "address": "0x4765d4"
- },
- {
- "name": "IsChild",
- "address": "0x4765d8"
- },
- {
- "name": "InvalidateRect",
- "address": "0x4765dc"
- },
- {
- "name": "IntersectRect",
- "address": "0x4765e0"
- },
- {
- "name": "InsertMenuItemA",
- "address": "0x4765e4"
- },
- {
- "name": "InsertMenuA",
- "address": "0x4765e8"
- },
- {
- "name": "InflateRect",
- "address": "0x4765ec"
- },
- {
- "name": "GetWindowThreadProcessId",
- "address": "0x4765f0"
- },
- {
- "name": "GetWindowTextA",
- "address": "0x4765f4"
- },
- {
- "name": "GetWindowRect",
- "address": "0x4765f8"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x4765fc"
- },
- {
- "name": "GetWindowLongA",
- "address": "0x476600"
- },
- {
- "name": "GetWindowDC",
- "address": "0x476604"
- },
- {
- "name": "GetTopWindow",
- "address": "0x476608"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x47660c"
- },
- {
- "name": "GetSystemMenu",
- "address": "0x476610"
- },
- {
- "name": "GetSysColorBrush",
- "address": "0x476614"
- },
- {
- "name": "GetSysColor",
- "address": "0x476618"
- },
- {
- "name": "GetSubMenu",
- "address": "0x47661c"
- },
- {
- "name": "GetScrollRange",
- "address": "0x476620"
- },
- {
- "name": "GetScrollPos",
- "address": "0x476624"
- },
- {
- "name": "GetScrollInfo",
- "address": "0x476628"
- },
- {
- "name": "GetPropA",
- "address": "0x47662c"
- },
- {
- "name": "GetParent",
- "address": "0x476630"
- },
- {
- "name": "GetWindow",
- "address": "0x476634"
- },
- {
- "name": "GetMessageTime",
- "address": "0x476638"
- },
- {
- "name": "GetMenuStringA",
- "address": "0x47663c"
- },
- {
- "name": "GetMenuState",
- "address": "0x476640"
- },
- {
- "name": "GetMenuItemInfoA",
- "address": "0x476644"
- },
- {
- "name": "GetMenuItemID",
- "address": "0x476648"
- },
- {
- "name": "GetMenuItemCount",
- "address": "0x47664c"
- },
- {
- "name": "GetMenu",
- "address": "0x476650"
- },
- {
- "name": "GetLastActivePopup",
- "address": "0x476654"
- },
- {
- "name": "GetKeyboardState",
- "address": "0x476658"
- },
- {
- "name": "GetKeyboardLayoutList",
- "address": "0x47665c"
- },
- {
- "name": "GetKeyboardLayout",
- "address": "0x476660"
- },
- {
- "name": "GetKeyState",
- "address": "0x476664"
- },
- {
- "name": "GetKeyNameTextA",
- "address": "0x476668"
- },
- {
- "name": "GetIconInfo",
- "address": "0x47666c"
- },
- {
- "name": "GetForegroundWindow",
- "address": "0x476670"
- },
- {
- "name": "GetFocus",
- "address": "0x476674"
- },
- {
- "name": "GetDesktopWindow",
- "address": "0x476678"
- },
- {
- "name": "GetDCEx",
- "address": "0x47667c"
- },
- {
- "name": "GetDC",
- "address": "0x476680"
- },
- {
- "name": "GetCursorPos",
- "address": "0x476684"
- },
- {
- "name": "GetCursor",
- "address": "0x476688"
- },
- {
- "name": "GetClipboardData",
- "address": "0x47668c"
- },
- {
- "name": "GetClientRect",
- "address": "0x476690"
- },
- {
- "name": "GetClassNameA",
- "address": "0x476694"
- },
- {
- "name": "GetClassInfoA",
- "address": "0x476698"
- },
- {
- "name": "GetCapture",
- "address": "0x47669c"
- },
- {
- "name": "GetActiveWindow",
- "address": "0x4766a0"
- },
- {
- "name": "FrameRect",
- "address": "0x4766a4"
- },
- {
- "name": "FindWindowA",
- "address": "0x4766a8"
- },
- {
- "name": "FillRect",
- "address": "0x4766ac"
- },
- {
- "name": "EqualRect",
- "address": "0x4766b0"
- },
- {
- "name": "EnumWindows",
- "address": "0x4766b4"
- },
- {
- "name": "EnumThreadWindows",
- "address": "0x4766b8"
- },
- {
- "name": "EndPaint",
- "address": "0x4766bc"
- },
- {
- "name": "EnableWindow",
- "address": "0x4766c0"
- },
- {
- "name": "EnableScrollBar",
- "address": "0x4766c4"
- },
- {
- "name": "EnableMenuItem",
- "address": "0x4766c8"
- },
- {
- "name": "DrawTextA",
- "address": "0x4766cc"
- },
- {
- "name": "DrawMenuBar",
- "address": "0x4766d0"
- },
- {
- "name": "DrawIconEx",
- "address": "0x4766d4"
- },
- {
- "name": "DrawIcon",
- "address": "0x4766d8"
- },
- {
- "name": "DrawFrameControl",
- "address": "0x4766dc"
- },
- {
- "name": "DrawEdge",
- "address": "0x4766e0"
- },
- {
- "name": "DispatchMessageA",
- "address": "0x4766e4"
- },
- {
- "name": "DestroyWindow",
- "address": "0x4766e8"
- },
- {
- "name": "DestroyMenu",
- "address": "0x4766ec"
- },
- {
- "name": "DestroyIcon",
- "address": "0x4766f0"
- },
- {
- "name": "DestroyCursor",
- "address": "0x4766f4"
- },
- {
- "name": "DeleteMenu",
- "address": "0x4766f8"
- },
- {
- "name": "DefWindowProcA",
- "address": "0x4766fc"
- },
- {
- "name": "DefMDIChildProcA",
- "address": "0x476700"
- },
- {
- "name": "DefFrameProcA",
- "address": "0x476704"
- },
- {
- "name": "CreatePopupMenu",
- "address": "0x476708"
- },
- {
- "name": "CreateMenu",
- "address": "0x47670c"
- },
- {
- "name": "CreateIcon",
- "address": "0x476710"
- },
- {
- "name": "ClientToScreen",
- "address": "0x476714"
- },
- {
- "name": "CheckMenuItem",
- "address": "0x476718"
- },
- {
- "name": "CallWindowProcA",
- "address": "0x47671c"
- },
- {
- "name": "CallNextHookEx",
- "address": "0x476720"
- },
- {
- "name": "BeginPaint",
- "address": "0x476724"
- },
- {
- "name": "CharNextA",
- "address": "0x476728"
- },
- {
- "name": "CharLowerBuffA",
- "address": "0x47672c"
- },
- {
- "name": "CharLowerA",
- "address": "0x476730"
- },
- {
- "name": "CharToOemA",
- "address": "0x476734"
- },
- {
- "name": "AdjustWindowRectEx",
- "address": "0x476738"
- },
- {
- "name": "ActivateKeyboardLayout",
- "address": "0x47673c"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "Sleep",
- "address": "0x476744"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "SafeArrayPtrOfIndex",
- "address": "0x47674c"
- },
- {
- "name": "SafeArrayGetUBound",
- "address": "0x476750"
- },
- {
- "name": "SafeArrayGetLBound",
- "address": "0x476754"
- },
- {
- "name": "SafeArrayCreate",
- "address": "0x476758"
- },
- {
- "name": "VariantChangeType",
- "address": "0x47675c"
- },
- {
- "name": "VariantCopy",
- "address": "0x476760"
- },
- {
- "name": "VariantClear",
- "address": "0x476764"
- },
- {
- "name": "VariantInit",
- "address": "0x476768"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateStreamOnHGlobal",
- "address": "0x476770"
- },
- {
- "name": "IsAccelerator",
- "address": "0x476774"
- },
- {
- "name": "OleDraw",
- "address": "0x476778"
- },
- {
- "name": "OleSetMenuDescriptor",
- "address": "0x47677c"
- },
- {
- "name": "CoCreateInstance",
- "address": "0x476780"
- },
- {
- "name": "CoGetClassObject",
- "address": "0x476784"
- },
- {
- "name": "CoUninitialize",
- "address": "0x476788"
- },
- {
- "name": "CoInitialize",
- "address": "0x47678c"
- },
- {
- "name": "IsEqualGUID",
- "address": "0x476790"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "GetErrorInfo",
- "address": "0x476798"
- },
- {
- "name": "SysFreeString",
- "address": "0x47679c"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "ImageList_SetIconSize",
- "address": "0x4767a4"
- },
- {
- "name": "ImageList_GetIconSize",
- "address": "0x4767a8"
- },
- {
- "name": "ImageList_Write",
- "address": "0x4767ac"
- },
- {
- "name": "ImageList_Read",
- "address": "0x4767b0"
- },
- {
- "name": "ImageList_GetDragImage",
- "address": "0x4767b4"
- },
- {
- "name": "ImageList_DragShowNolock",
- "address": "0x4767b8"
- },
- {
- "name": "ImageList_SetDragCursorImage",
- "address": "0x4767bc"
- },
- {
- "name": "ImageList_DragMove",
- "address": "0x4767c0"
- },
- {
- "name": "ImageList_DragLeave",
- "address": "0x4767c4"
- },
- {
- "name": "ImageList_DragEnter",
- "address": "0x4767c8"
- },
- {
- "name": "ImageList_EndDrag",
- "address": "0x4767cc"
- },
- {
- "name": "ImageList_BeginDrag",
- "address": "0x4767d0"
- },
- {
- "name": "ImageList_Remove",
- "address": "0x4767d4"
- },
- {
- "name": "ImageList_DrawEx",
- "address": "0x4767d8"
- },
- {
- "name": "ImageList_Draw",
- "address": "0x4767dc"
- },
- {
- "name": "ImageList_GetBkColor",
- "address": "0x4767e0"
- },
- {
- "name": "ImageList_SetBkColor",
- "address": "0x4767e4"
- },
- {
- "name": "ImageList_ReplaceIcon",
- "address": "0x4767e8"
- },
- {
- "name": "ImageList_Add",
- "address": "0x4767ec"
- },
- {
- "name": "ImageList_GetImageCount",
- "address": "0x4767f0"
- },
- {
- "name": "ImageList_Destroy",
- "address": "0x4767f4"
- },
- {
- "name": "ImageList_Create",
- "address": "0x4767f8"
- }
- ],
- "dll": "comctl32.dll"
- },
- {
- "imports": [
- {
- "name": "OpenPrinterA",
- "address": "0x476800"
- },
- {
- "name": "EnumPrintersA",
- "address": "0x476804"
- },
- {
- "name": "DocumentPropertiesA",
- "address": "0x476808"
- },
- {
- "name": "ClosePrinter",
- "address": "0x47680c"
- }
- ],
- "dll": "winspool.drv"
- },
- {
- "imports": [
- {
- "name": "PrintDlgA",
- "address": "0x476814"
- }
- ],
- "dll": "comdlg32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x000a8994",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x0046a7a0",
- "timestamp": "1992-04-26 01:18:37",
- "osversion": "4.0",
- "sections": [
- {
- "name": "CODE",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00069800",
- "entropy": "6.53",
- "raw_address": "0x00000400",
- "virtual_size": "0x000697e8",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": "DATA",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0006b000",
- "size_of_data": "0x00009e00",
- "entropy": "5.04",
- "raw_address": "0x00069c00",
- "virtual_size": "0x00009ca8",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": "BSS",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00075000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00073a00",
- "virtual_size": "0x00000fa9",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".idata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00076000",
- "size_of_data": "0x00002600",
- "entropy": "4.83",
- "raw_address": "0x00073a00",
- "virtual_size": "0x000024c6",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00079000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00076000",
- "virtual_size": "0x00000010",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0007a000",
- "size_of_data": "0x00000200",
- "entropy": "0.21",
- "raw_address": "0x00076000",
- "virtual_size": "0x00000018",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0007b000",
- "size_of_data": "0x00008400",
- "entropy": "6.65",
- "raw_address": "0x00076200",
- "virtual_size": "0x000083a4",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00084000",
- "size_of_data": "0x0002a000",
- "entropy": "6.96",
- "raw_address": "0x0007e600",
- "virtual_size": "0x00029e20",
- "characteristics_raw": "0x50000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00076000",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x000024c6"
- },
- {
- "virtual_address": "0x00084000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00029e20"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0007b000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x000083a4"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0007a000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "d553c8d26e9a2369ccc8481987fa6051",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 17,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "kernel32.dll.GetDiskFreeSpaceExA",
- "oleaut32.dll.VariantChangeTypeEx",
- "oleaut32.dll.VarNeg",
- "oleaut32.dll.VarNot",
- "oleaut32.dll.VarAdd",
- "oleaut32.dll.VarSub",
- "oleaut32.dll.VarMul",
- "oleaut32.dll.VarDiv",
- "oleaut32.dll.VarIdiv",
- "oleaut32.dll.VarMod",
- "oleaut32.dll.VarAnd",
- "oleaut32.dll.VarOr",
- "oleaut32.dll.VarXor",
- "oleaut32.dll.VarCmp",
- "oleaut32.dll.VarI4FromStr",
- "oleaut32.dll.VarR4FromStr",
- "oleaut32.dll.VarR8FromStr",
- "oleaut32.dll.VarDateFromStr",
- "oleaut32.dll.VarCyFromStr",
- "oleaut32.dll.VarBoolFromStr",
- "oleaut32.dll.VarBstrFromCy",
- "oleaut32.dll.VarBstrFromDate",
- "oleaut32.dll.VarBstrFromBool",
- "user32.dll.GetMonitorInfoA",
- "user32.dll.GetSystemMetrics",
- "user32.dll.EnumDisplayMonitors",
- "dwmapi.dll.DwmIsCompositionEnabled",
- "gdi32.dll.GetLayout",
- "gdi32.dll.GdiRealizationInfo",
- "gdi32.dll.FontIsLinked",
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegQueryInfoKeyW",
- "gdi32.dll.GetTextFaceAliasW",
- "advapi32.dll.RegEnumValueW",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.RegQueryValueExW",
- "gdi32.dll.GetFontAssocStatus",
- "advapi32.dll.RegQueryValueExA",
- "advapi32.dll.RegEnumKeyExW",
- "gdi32.dll.GdiIsMetaPrintDC",
- "user32.dll.AnimateWindow",
- "comctl32.dll.InitializeFlatSB",
- "comctl32.dll.UninitializeFlatSB",
- "comctl32.dll.FlatSB_GetScrollProp",
- "comctl32.dll.FlatSB_SetScrollProp",
- "comctl32.dll.FlatSB_EnableScrollBar",
- "comctl32.dll.FlatSB_ShowScrollBar",
- "comctl32.dll.FlatSB_GetScrollRange",
- "comctl32.dll.FlatSB_GetScrollInfo",
- "comctl32.dll.FlatSB_GetScrollPos",
- "comctl32.dll.FlatSB_SetScrollPos",
- "comctl32.dll.FlatSB_SetScrollInfo",
- "comctl32.dll.FlatSB_SetScrollRange",
- "user32.dll.SetLayeredWindowAttributes",
- "ole32.dll.CoCreateInstanceEx",
- "ole32.dll.CoInitializeEx",
- "ole32.dll.CoAddRefServerProcess",
- "ole32.dll.CoReleaseServerProcess",
- "ole32.dll.CoResumeClassObjects",
- "ole32.dll.CoSuspendClassObjects",
- "olepro32.dll.OleCreatePropertyFrame",
- "olepro32.dll.OleCreateFontIndirect",
- "olepro32.dll.OleCreatePictureIndirect",
- "olepro32.dll.OleLoadPicture",
- "crypt32.dll.CryptUnprotectData",
- "crtdll.dll.wcscmp",
- "gdiplus.dll.GdiplusStartup",
- "gdiplus.dll.GdiplusShutdown",
- "gdiplus.dll.GdipCreateBitmapFromHBITMAP",
- "gdiplus.dll.GdipGetImageEncodersSize",
- "gdiplus.dll.GdipGetImageEncoders",
- "gdiplus.dll.GdipDisposeImage",
- "gdiplus.dll.GdipSaveImageToStream",
- "ole32.dll.CreateStreamOnHGlobal",
- "ole32.dll.GetHGlobalFromStream",
- "kernel32.dll.ExpandEnvironmentStringsW",
- "kernel32.dll.GetComputerNameW",
- "kernel32.dll.GlobalMemoryStatus",
- "kernel32.dll.CreateFileW",
- "kernel32.dll.GetFileSize",
- "kernel32.dll.CloseHandle",
- "kernel32.dll.ReadFile",
- "kernel32.dll.GetFileAttributesW",
- "kernel32.dll.CreateMutexA",
- "kernel32.dll.ReleaseMutex",
- "kernel32.dll.GetLastError",
- "kernel32.dll.GetCurrentDirectoryW",
- "kernel32.dll.SetEnvironmentVariableW",
- "kernel32.dll.SetCurrentDirectoryW",
- "kernel32.dll.FindFirstFileW",
- "kernel32.dll.FindNextFileW",
- "kernel32.dll.LocalFree",
- "kernel32.dll.GetTickCount",
- "kernel32.dll.CopyFileW",
- "kernel32.dll.FindClose",
- "kernel32.dll.GlobalMemoryStatusEx",
- "kernel32.dll.CreateToolhelp32Snapshot",
- "kernel32.dll.Process32FirstW",
- "kernel32.dll.Process32NextW",
- "kernel32.dll.GetModuleFileNameW",
- "kernel32.dll.SetDllDirectoryW",
- "kernel32.dll.GetLocaleInfoA",
- "kernel32.dll.GetLocalTime",
- "kernel32.dll.GetTimeZoneInformation",
- "kernel32.dll.RemoveDirectoryW",
- "kernel32.dll.DeleteFileW",
- "kernel32.dll.GetLogicalDriveStringsA",
- "kernel32.dll.GetDriveTypeA",
- "kernel32.dll.CreateProcessW",
- "advapi32.dll.GetUserNameW",
- "advapi32.dll.RegCreateKeyExW",
- "advapi32.dll.AllocateAndInitializeSid",
- "advapi32.dll.LookupAccountSidA",
- "advapi32.dll.CreateProcessAsUserW",
- "advapi32.dll.CheckTokenMembership",
- "advapi32.dll.RegOpenKeyW",
- "advapi32.dll.RegEnumKeyW",
- "advapi32.dll.CryptAcquireContextA",
- "advapi32.dll.CryptCreateHash",
- "advapi32.dll.CryptHashData",
- "advapi32.dll.CryptGetHashParam",
- "advapi32.dll.CryptDestroyHash",
- "advapi32.dll.CryptReleaseContext",
- "user32.dll.EnumDisplayDevicesW",
- "user32.dll.wvsprintfA",
- "user32.dll.GetKeyboardLayoutList",
- "shell32.dll.ShellExecuteExW",
- "ntdll.dll.RtlComputeCrc32",
- "sechost.dll.LookupAccountSidLocalA",
- "wininet.dll.InternetOpenA",
- "wininet.dll.InternetConnectA",
- "wininet.dll.HttpOpenRequestA",
- "wininet.dll.HttpAddRequestHeadersA",
- "wininet.dll.HttpSendRequestA",
- "wininet.dll.InternetReadFile",
- "wininet.dll.InternetCloseHandle",
- "wininet.dll.InternetCrackUrlA",
- "wininet.dll.InternetSetOptionA",
- "rasapi32.dll.RasConnectionNotificationW",
- "sechost.dll.NotifyServiceStatusChangeA",
- "cryptbase.dll.SystemFunction036",
- "nss3.dll.sqlite3_open",
- "nss3.dll.sqlite3_close",
- "nss3.dll.sqlite3_prepare_v2",
- "nss3.dll.sqlite3_step",
- "nss3.dll.sqlite3_column_text",
- "nss3.dll.sqlite3_column_bytes",
- "nss3.dll.sqlite3_finalize",
- "nss3.dll.NSS_Init",
- "nss3.dll.PK11_GetInternalKeySlot",
- "nss3.dll.PK11_Authenticate",
- "nss3.dll.PK11SDR_Decrypt",
- "nss3.dll.NSS_Shutdown",
- "nss3.dll.PK11_FreeSlot",
- "kernel32.dll.InitializeCriticalSectionEx",
- "ole32.dll.CLSIDFromString",
- "vaultcli.dll.VaultOpenVault",
- "vaultcli.dll.VaultEnumerateItems",
- "vaultcli.dll.VaultGetItem",
- "uxtheme.dll.ThemeInitApiHook",
- "user32.dll.IsProcessDPIAware",
- "mlang.dll.#112",
- "wininet.dll.FindFirstUrlCacheEntryA",
- "urlmon.dll.CreateUri",
- "wininet.dll.FindNextUrlCacheEntryA",
- "urlmon.dll.CreateIUriBuilder",
- "urlmon.dll.IntlPercentEncodeNormalize",
- "wininet.dll.FindCloseUrlCache",
- "rpcrt4.dll.RpcStringBindingComposeW",
- "rpcrt4.dll.RpcBindingFromStringBindingW",
- "rpcrt4.dll.NdrClientCall2",
- "cryptbase.dll.SystemFunction041",
- "rpcrt4.dll.RpcStringFreeW",
- "rpcrt4.dll.RpcBindingFree",
- "kernel32.dll.IsProcessorFeaturePresent",
- "user32.dll.GetWindowInfo",
- "user32.dll.GetAncestor",
- "user32.dll.EnumDisplayDevicesA",
- "gdi32.dll.ExtTextOutW",
- "kernel32.dll.FlsGetValue",
- "windowscodecs.dll.DllGetClassObject",
- "kernel32.dll.WerRegisterMemoryBlock",
- "oleaut32.dll.#8",
- "oleaut32.dll.#9",
- "oleaut32.dll.#10",
- "kernel32.dll.IsWow64Process",
- "kernel32.dll.FlsFree",
- "setupapi.dll.CM_Get_Device_Interface_List_Size_ExW",
- "setupapi.dll.CM_Get_Device_Interface_List_ExW",
- "comctl32.dll.#386",
- "advapi32.dll.UnregisterTraceGuids",
- "comctl32.dll.#321",
- "kernel32.dll.SetThreadUILanguage",
- "kernel32.dll.CopyFileExW",
- "kernel32.dll.IsDebuggerPresent",
- "kernel32.dll.SetConsoleInputExeNameW",
- "kernel32.dll.SortGetHandle",
- "kernel32.dll.SortCloseHandle",
- "sechost.dll.LookupAccountNameLocalW",
- "advapi32.dll.LookupAccountSidW",
- "sechost.dll.LookupAccountSidLocalW",
- "wersvc.dll.ServiceMain",
- "wersvc.dll.SvchostPushServiceGlobals",
- "advapi32.dll.RegGetValueW",
- "sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW",
- "faultrep.dll.WerpInitiateCrashReporting",
- "wer.dll.WerpCreateMachineStore",
- "shell32.dll.SHGetFolderPathEx",
- "ole32.dll.StringFromGUID2",
- "profapi.dll.#104",
- "userenv.dll.CreateEnvironmentBlock",
- "sechost.dll.ConvertSidToStringSidW",
- "sspicli.dll.GetUserNameExW",
- "userenv.dll.DestroyEnvironmentBlock",
- "wer.dll.WerpSvcReportFromMachineQueue",
- "advapi32.dll.OpenProcessToken",
- "advapi32.dll.DuplicateToken",
- "advapi32.dll.FreeSid",
- "wtsapi32.dll.WTSQueryUserToken",
- "winsta.dll.WinStationQueryInformationW",
- "advapi32.dll.CreateWellKnownSid",
- "rpcrt4.dll.RpcBindingSetAuthInfoExW",
- "rpcrt4.dll.NdrClientCall3",
- "advapi32.dll.ImpersonateLoggedOnUser",
- "advapi32.dll.RevertToSelf",
- "ole32.dll.CoInitializeSecurity",
- "ole32.dll.CoCreateInstance",
- "w32time.dll.SvchostEntry_W32Time",
- "w32time.dll.SvchostPushServiceGlobals",
- "ws2_32.dll.#115",
- "ws2_32.dll.WSASocketW",
- "ws2_32.dll.WSAIoctl",
- "ws2_32.dll.#111",
- "userenv.dll.RegisterGPNotification",
- "gpapi.dll.RegisterGPNotificationInternal",
- "sechost.dll.OpenSCManagerW",
- "sechost.dll.OpenServiceW",
- "sechost.dll.CloseServiceHandle",
- "sechost.dll.QueryServiceConfigW",
- "dsrole.dll.DsRoleGetPrimaryDomainInformation",
- "dsrole.dll.DsRoleFreeMemory",
- "sspicli.dll.LsaRegisterPolicyChangeNotification",
- "w32time.dll.TimeProvClose",
- "w32time.dll.TimeProvCommand",
- "w32time.dll.TimeProvOpen",
- "ws2_32.dll.getaddrinfo",
- "ws2_32.dll.freeaddrinfo",
- "ws2_32.dll.#23",
- "ws2_32.dll.#21",
- "ws2_32.dll.#2",
- "ws2_32.dll.WSAEventSelect",
- "ws2_32.dll.GetAddrInfoW",
- "vmictimeprovider.dll.TimeProvClose",
- "vmictimeprovider.dll.TimeProvCommand",
- "vmictimeprovider.dll.TimeProvOpen",
- "advapi32.dll.EventRegister",
- "advapi32.dll.EventEnabled",
- "advapi32.dll.EventWrite",
- "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
- "ws2_32.dll.FreeAddrInfoW",
- "ws2_32.dll.WSAAddressToStringW",
- "ws2_32.dll.#3",
- "ws2_32.dll.#116",
- "advapi32.dll.EventUnregister",
- "sspicli.dll.LsaUnregisterPolicyChangeNotification",
- "userenv.dll.UnregisterGPNotification",
- "gpapi.dll.UnregisterGPNotificationInternal",
- "imm32.dll.ImmDisableIME",
- "psapi.dll.GetModuleFileNameExW",
- "version.dll.GetFileVersionInfoSizeW",
- "version.dll.GetFileVersionInfoW",
- "version.dll.VerQueryValueW",
- "wer.dll.WerpCreateIntegratorReportId",
- "wer.dll.WerReportCreate",
- "wer.dll.WerpSetIntegratorReportId",
- "wer.dll.WerReportSetParameter",
- "dbgeng.dll.DebugCreate",
- "ntdll.dll.CsrGetProcessId",
- "ntdll.dll.DbgBreakPoint",
- "ntdll.dll.DbgPrint",
- "ntdll.dll.DbgPrompt",
- "ntdll.dll.DbgUiConvertStateChangeStructure",
- "ntdll.dll.DbgUiGetThreadDebugObject",
- "ntdll.dll.DbgUiIssueRemoteBreakin",
- "ntdll.dll.DbgUiSetThreadDebugObject",
- "ntdll.dll.NtAllocateVirtualMemory",
- "ntdll.dll.NtClose",
- "ntdll.dll.NtCreateDebugObject",
- "ntdll.dll.NtCreateFile",
- "ntdll.dll.NtDebugActiveProcess",
- "ntdll.dll.NtDebugContinue",
- "ntdll.dll.NtFreeVirtualMemory",
- "ntdll.dll.NtOpenProcess",
- "ntdll.dll.NtOpenThread",
- "ntdll.dll.NtQueryInformationProcess",
- "ntdll.dll.NtQueryInformationThread",
- "ntdll.dll.NtQueryMutant",
- "ntdll.dll.NtQueryObject",
- "ntdll.dll.NtQuerySystemInformation",
- "ntdll.dll.NtRemoveProcessDebug",
- "ntdll.dll.NtResumeThread",
- "ntdll.dll.NtSetInformationDebugObject",
- "ntdll.dll.NtSetInformationProcess",
- "ntdll.dll.NtSystemDebugControl",
- "ntdll.dll.NtWaitForDebugEvent",
- "ntdll.dll.RtlAnsiStringToUnicodeString",
- "ntdll.dll.RtlCreateProcessParameters",
- "ntdll.dll.RtlCreateUserProcess",
- "ntdll.dll.RtlDestroyProcessParameters",
- "ntdll.dll.RtlDosPathNameToNtPathName_U",
- "ntdll.dll.RtlFindMessage",
- "ntdll.dll.RtlFreeHeap",
- "ntdll.dll.RtlFreeUnicodeString",
- "ntdll.dll.RtlGetFunctionTableListHead",
- "ntdll.dll.RtlGetUnloadEventTrace",
- "ntdll.dll.RtlGetUnloadEventTraceEx",
- "ntdll.dll.RtlInitAnsiString",
- "ntdll.dll.RtlInitUnicodeString",
- "ntdll.dll.RtlTryEnterCriticalSection",
- "ntdll.dll.RtlUnicodeStringToAnsiString",
- "ntdll.dll.NtOpenProcessToken",
- "ntdll.dll.NtOpenThreadToken",
- "ntdll.dll.NtQueryInformationToken",
- "kernel32.dll.CloseProfileUserMapping",
- "kernel32.dll.DebugActiveProcessStop",
- "kernel32.dll.DebugBreak",
- "kernel32.dll.DebugBreakProcess",
- "kernel32.dll.DebugSetProcessKillOnExit",
- "kernel32.dll.Module32First",
- "kernel32.dll.Module32FirstW",
- "kernel32.dll.Module32Next",
- "kernel32.dll.Module32NextW",
- "kernel32.dll.OpenThread",
- "kernel32.dll.Process32First",
- "kernel32.dll.Process32Next",
- "kernel32.dll.ProcessIdToSessionId",
- "kernel32.dll.SetProcessShutdownParameters",
- "kernel32.dll.Thread32First",
- "kernel32.dll.Thread32Next",
- "kernel32.dll.DuplicateHandle",
- "kernel32.dll.Wow64GetThreadSelectorEntry",
- "advapi32.dll.CloseServiceHandle",
- "advapi32.dll.ControlService",
- "advapi32.dll.CreateServiceA",
- "advapi32.dll.CreateServiceW",
- "advapi32.dll.DeleteService",
- "advapi32.dll.EnumServicesStatusExA",
- "advapi32.dll.EnumServicesStatusExW",
- "advapi32.dll.GetEventLogInformation",
- "advapi32.dll.GetTokenInformation",
- "advapi32.dll.OpenSCManagerA",
- "advapi32.dll.OpenSCManagerW",
- "advapi32.dll.OpenServiceA",
- "advapi32.dll.OpenServiceW",
- "advapi32.dll.StartServiceA",
- "advapi32.dll.StartServiceW",
- "advapi32.dll.GetSidSubAuthority",
- "advapi32.dll.GetSidSubAuthorityCount",
- "version.dll.GetFileVersionInfoSizeExW",
- "version.dll.GetFileVersionInfoExW",
- "dbghelp.dll.WinDbgExtensionDllInit",
- "dbghelp.dll.ExtensionApiVersion",
- "wer.dll.WerpSetDynamicParameter",
- "wer.dll.WerReportAddDump",
- "wer.dll.WerpSetCallBack",
- "wer.dll.WerReportSetUIOption",
- "wer.dll.WerpAddRegisteredDataToReport",
- "wer.dll.WerReportSubmit",
- "user32.dll.LoadStringW",
- "advapi32.dll.RegSetValueExW",
- "sensapi.dll.IsNetworkAlive",
- "user32.dll.CharUpperW",
- "wer.dll.WerpAddAppCompatData",
- "apphelp.dll.SdbGetFileAttributes",
- "apphelp.dll.SdbFormatAttribute",
- "apphelp.dll.SdbFreeFileAttributes",
- "cryptsp.dll.CryptAcquireContextW",
- "cryptsp.dll.CryptCreateHash",
- "cryptsp.dll.CryptHashData",
- "cryptsp.dll.CryptGetHashParam",
- "cryptsp.dll.CryptDestroyHash",
- "cryptsp.dll.CryptReleaseContext",
- "dbghelp.dll.MiniDumpWriteDump",
- "kernel32.dll.GetLongPathNameA",
- "kernel32.dll.GetLongPathNameW",
- "kernel32.dll.GetProcessTimes",
- "advapi32.dll.RegOpenKeyExA",
- "powrprof.dll.CallNtPowerInformation",
- "psapi.dll.EnumProcessModules",
- "version.dll.GetFileVersionInfoSizeA",
- "version.dll.GetFileVersionInfoA",
- "version.dll.VerQueryValueA",
- "verifier.dll.VerifierEnumerateResource",
- "ntdll.dll.NtSuspendProcess",
- "ntdll.dll.NtResumeProcess",
- "advapi32.dll.QueryTraceW",
- "advapi32.dll.IsValidSid",
- "advapi32.dll.GetLengthSid",
- "advapi32.dll.CopySid",
- "advapi32.dll.InitializeAcl",
- "advapi32.dll.AddAccessAllowedAceEx",
- "advapi32.dll.InitializeSecurityDescriptor",
- "advapi32.dll.SetSecurityDescriptorDacl",
- "advapi32.dll.RegisterEventSourceW",
- "advapi32.dll.ReportEventW",
- "advapi32.dll.DeregisterEventSource",
- "wer.dll.WerpGetStoreLocation",
- "wer.dll.WerpGetStoreType",
- "wer.dll.WerReportCloseHandle",
- "user32.dll.MsgWaitForMultipleObjects",
- "wer.dll.WerpFreeString",
- "user32.dll.GetProcessWindowStation",
- "user32.dll.GetThreadDesktop",
- "user32.dll.GetUserObjectInformationW",
- "werui.dll.WerUICreate",
- "werui.dll.WerUIStart",
- "werui.dll.WerUITerminate",
- "werui.dll.WerUIDelete"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DeleteCriticalSection",
- "address": "0x476168"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x47616c"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x476170"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x476174"
- },
- {
- "name": "VirtualFree",
- "address": "0x476178"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x47617c"
- },
- {
- "name": "LocalFree",
- "address": "0x476180"
- },
- {
- "name": "LocalAlloc",
- "address": "0x476184"
- },
- {
- "name": "GetVersion",
- "address": "0x476188"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x47618c"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x476190"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x476194"
- },
- {
- "name": "VirtualQuery",
- "address": "0x476198"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x47619c"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x4761a0"
- },
- {
- "name": "lstrlenA",
- "address": "0x4761a4"
- },
- {
- "name": "lstrcpynA",
- "address": "0x4761a8"
- },
- {
- "name": "LoadLibraryExA",
- "address": "0x4761ac"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x4761b0"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x4761b4"
- },
- {
- "name": "GetProcAddress",
- "address": "0x4761b8"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x4761bc"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x4761c0"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x4761c4"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x4761c8"
- },
- {
- "name": "FreeLibrary",
- "address": "0x4761cc"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x4761d0"
- },
- {
- "name": "FindClose",
- "address": "0x4761d4"
- },
- {
- "name": "ExitProcess",
- "address": "0x4761d8"
- },
- {
- "name": "ExitThread",
- "address": "0x4761dc"
- },
- {
- "name": "CreateThread",
- "address": "0x4761e0"
- },
- {
- "name": "WriteFile",
- "address": "0x4761e4"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x4761e8"
- },
- {
- "name": "RtlUnwind",
- "address": "0x4761ec"
- },
- {
- "name": "RaiseException",
- "address": "0x4761f0"
- },
- {
- "name": "GetStdHandle",
- "address": "0x4761f4"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "GetKeyboardType",
- "address": "0x4761fc"
- },
- {
- "name": "LoadStringA",
- "address": "0x476200"
- },
- {
- "name": "MessageBoxA",
- "address": "0x476204"
- },
- {
- "name": "CharNextA",
- "address": "0x476208"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x476210"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x476214"
- },
- {
- "name": "RegCloseKey",
- "address": "0x476218"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "SysFreeString",
- "address": "0x476220"
- },
- {
- "name": "SysReAllocStringLen",
- "address": "0x476224"
- },
- {
- "name": "SysAllocStringLen",
- "address": "0x476228"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "TlsSetValue",
- "address": "0x476230"
- },
- {
- "name": "TlsGetValue",
- "address": "0x476234"
- },
- {
- "name": "LocalAlloc",
- "address": "0x476238"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x47623c"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x476244"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x476248"
- },
- {
- "name": "RegCloseKey",
- "address": "0x47624c"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "lstrcpyA",
- "address": "0x476254"
- },
- {
- "name": "WriteFile",
- "address": "0x476258"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x47625c"
- },
- {
- "name": "VirtualQuery",
- "address": "0x476260"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x476264"
- },
- {
- "name": "SuspendThread",
- "address": "0x476268"
- },
- {
- "name": "Sleep",
- "address": "0x47626c"
- },
- {
- "name": "SizeofResource",
- "address": "0x476270"
- },
- {
- "name": "SetThreadPriority",
- "address": "0x476274"
- },
- {
- "name": "SetThreadLocale",
- "address": "0x476278"
- },
- {
- "name": "SetFilePointer",
- "address": "0x47627c"
- },
- {
- "name": "SetEvent",
- "address": "0x476280"
- },
- {
- "name": "SetErrorMode",
- "address": "0x476284"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x476288"
- },
- {
- "name": "ResumeThread",
- "address": "0x47628c"
- },
- {
- "name": "ResetEvent",
- "address": "0x476290"
- },
- {
- "name": "ReadFile",
- "address": "0x476294"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x476298"
- },
- {
- "name": "MulDiv",
- "address": "0x47629c"
- },
- {
- "name": "LockResource",
- "address": "0x4762a0"
- },
- {
- "name": "LoadResource",
- "address": "0x4762a4"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x4762a8"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x4762ac"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x4762b0"
- },
- {
- "name": "GlobalUnlock",
- "address": "0x4762b4"
- },
- {
- "name": "GlobalSize",
- "address": "0x4762b8"
- },
- {
- "name": "GlobalReAlloc",
- "address": "0x4762bc"
- },
- {
- "name": "GlobalHandle",
- "address": "0x4762c0"
- },
- {
- "name": "GlobalLock",
- "address": "0x4762c4"
- },
- {
- "name": "GlobalFree",
- "address": "0x4762c8"
- },
- {
- "name": "GlobalFindAtomA",
- "address": "0x4762cc"
- },
- {
- "name": "GlobalDeleteAtom",
- "address": "0x4762d0"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x4762d4"
- },
- {
- "name": "GlobalAddAtomA",
- "address": "0x4762d8"
- },
- {
- "name": "GetVersionExA",
- "address": "0x4762dc"
- },
- {
- "name": "GetVersion",
- "address": "0x4762e0"
- },
- {
- "name": "GetUserDefaultLCID",
- "address": "0x4762e4"
- },
- {
- "name": "GetTickCount",
- "address": "0x4762e8"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x4762ec"
- },
- {
- "name": "GetTempPathA",
- "address": "0x4762f0"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x4762f4"
- },
- {
- "name": "GetStringTypeExA",
- "address": "0x4762f8"
- },
- {
- "name": "GetStdHandle",
- "address": "0x4762fc"
- },
- {
- "name": "GetProfileStringA",
- "address": "0x476300"
- },
- {
- "name": "GetProcAddress",
- "address": "0x476304"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x476308"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x47630c"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x476310"
- },
- {
- "name": "GetLocalTime",
- "address": "0x476314"
- },
- {
- "name": "GetLastError",
- "address": "0x476318"
- },
- {
- "name": "GetFullPathNameA",
- "address": "0x47631c"
- },
- {
- "name": "GetFileSize",
- "address": "0x476320"
- },
- {
- "name": "GetExitCodeThread",
- "address": "0x476324"
- },
- {
- "name": "GetDiskFreeSpaceA",
- "address": "0x476328"
- },
- {
- "name": "GetDateFormatA",
- "address": "0x47632c"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x476330"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x476334"
- },
- {
- "name": "GetCPInfo",
- "address": "0x476338"
- },
- {
- "name": "GetACP",
- "address": "0x47633c"
- },
- {
- "name": "FreeResource",
- "address": "0x476340"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x476344"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x476348"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x47634c"
- },
- {
- "name": "FreeLibrary",
- "address": "0x476350"
- },
- {
- "name": "FormatMessageA",
- "address": "0x476354"
- },
- {
- "name": "FindResourceA",
- "address": "0x476358"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x47635c"
- },
- {
- "name": "FindClose",
- "address": "0x476360"
- },
- {
- "name": "FileTimeToLocalFileTime",
- "address": "0x476364"
- },
- {
- "name": "FileTimeToDosDateTime",
- "address": "0x476368"
- },
- {
- "name": "EnumCalendarInfoA",
- "address": "0x47636c"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x476370"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x476374"
- },
- {
- "name": "CreateThread",
- "address": "0x476378"
- },
- {
- "name": "CreateFileA",
- "address": "0x47637c"
- },
- {
- "name": "CreateEventA",
- "address": "0x476380"
- },
- {
- "name": "CompareStringA",
- "address": "0x476384"
- },
- {
- "name": "CloseHandle",
- "address": "0x476388"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "VerQueryValueA",
- "address": "0x476390"
- },
- {
- "name": "GetFileVersionInfoSizeA",
- "address": "0x476394"
- },
- {
- "name": "GetFileVersionInfoA",
- "address": "0x476398"
- }
- ],
- "dll": "version.dll"
- },
- {
- "imports": [
- {
- "name": "UnrealizeObject",
- "address": "0x4763a0"
- },
- {
- "name": "StretchBlt",
- "address": "0x4763a4"
- },
- {
- "name": "SetWindowOrgEx",
- "address": "0x4763a8"
- },
- {
- "name": "SetWinMetaFileBits",
- "address": "0x4763ac"
- },
- {
- "name": "SetViewportOrgEx",
- "address": "0x4763b0"
- },
- {
- "name": "SetTextColor",
- "address": "0x4763b4"
- },
- {
- "name": "SetStretchBltMode",
- "address": "0x4763b8"
- },
- {
- "name": "SetROP2",
- "address": "0x4763bc"
- },
- {
- "name": "SetPixel",
- "address": "0x4763c0"
- },
- {
- "name": "SetMapMode",
- "address": "0x4763c4"
- },
- {
- "name": "SetEnhMetaFileBits",
- "address": "0x4763c8"
- },
- {
- "name": "SetDIBColorTable",
- "address": "0x4763cc"
- },
- {
- "name": "SetBrushOrgEx",
- "address": "0x4763d0"
- },
- {
- "name": "SetBkMode",
- "address": "0x4763d4"
- },
- {
- "name": "SetBkColor",
- "address": "0x4763d8"
- },
- {
- "name": "SelectPalette",
- "address": "0x4763dc"
- },
- {
- "name": "SelectObject",
- "address": "0x4763e0"
- },
- {
- "name": "ScaleWindowExtEx",
- "address": "0x4763e4"
- },
- {
- "name": "SaveDC",
- "address": "0x4763e8"
- },
- {
- "name": "RestoreDC",
- "address": "0x4763ec"
- },
- {
- "name": "RectVisible",
- "address": "0x4763f0"
- },
- {
- "name": "RealizePalette",
- "address": "0x4763f4"
- },
- {
- "name": "PlayEnhMetaFile",
- "address": "0x4763f8"
- },
- {
- "name": "PatBlt",
- "address": "0x4763fc"
- },
- {
- "name": "MoveToEx",
- "address": "0x476400"
- },
- {
- "name": "MaskBlt",
- "address": "0x476404"
- },
- {
- "name": "LineTo",
- "address": "0x476408"
- },
- {
- "name": "LPtoDP",
- "address": "0x47640c"
- },
- {
- "name": "IntersectClipRect",
- "address": "0x476410"
- },
- {
- "name": "GetWindowOrgEx",
- "address": "0x476414"
- },
- {
- "name": "GetWinMetaFileBits",
- "address": "0x476418"
- },
- {
- "name": "GetTextMetricsA",
- "address": "0x47641c"
- },
- {
- "name": "GetTextExtentPoint32A",
- "address": "0x476420"
- },
- {
- "name": "GetSystemPaletteEntries",
- "address": "0x476424"
- },
- {
- "name": "GetStockObject",
- "address": "0x476428"
- },
- {
- "name": "GetPixel",
- "address": "0x47642c"
- },
- {
- "name": "GetPaletteEntries",
- "address": "0x476430"
- },
- {
- "name": "GetObjectA",
- "address": "0x476434"
- },
- {
- "name": "GetEnhMetaFilePaletteEntries",
- "address": "0x476438"
- },
- {
- "name": "GetEnhMetaFileHeader",
- "address": "0x47643c"
- },
- {
- "name": "GetEnhMetaFileDescriptionA",
- "address": "0x476440"
- },
- {
- "name": "GetEnhMetaFileBits",
- "address": "0x476444"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x476448"
- },
- {
- "name": "GetDIBits",
- "address": "0x47644c"
- },
- {
- "name": "GetDIBColorTable",
- "address": "0x476450"
- },
- {
- "name": "GetDCOrgEx",
- "address": "0x476454"
- },
- {
- "name": "GetCurrentPositionEx",
- "address": "0x476458"
- },
- {
- "name": "GetClipBox",
- "address": "0x47645c"
- },
- {
- "name": "GetBrushOrgEx",
- "address": "0x476460"
- },
- {
- "name": "GetBitmapBits",
- "address": "0x476464"
- },
- {
- "name": "ExcludeClipRect",
- "address": "0x476468"
- },
- {
- "name": "EndPage",
- "address": "0x47646c"
- },
- {
- "name": "EndDoc",
- "address": "0x476470"
- },
- {
- "name": "DeleteObject",
- "address": "0x476474"
- },
- {
- "name": "DeleteEnhMetaFile",
- "address": "0x476478"
- },
- {
- "name": "DeleteDC",
- "address": "0x47647c"
- },
- {
- "name": "CreateSolidBrush",
- "address": "0x476480"
- },
- {
- "name": "CreatePenIndirect",
- "address": "0x476484"
- },
- {
- "name": "CreatePalette",
- "address": "0x476488"
- },
- {
- "name": "CreateICA",
- "address": "0x47648c"
- },
- {
- "name": "CreateHalftonePalette",
- "address": "0x476490"
- },
- {
- "name": "CreateFontIndirectA",
- "address": "0x476494"
- },
- {
- "name": "CreateEnhMetaFileA",
- "address": "0x476498"
- },
- {
- "name": "CreateDIBitmap",
- "address": "0x47649c"
- },
- {
- "name": "CreateDIBSection",
- "address": "0x4764a0"
- },
- {
- "name": "CreateDCA",
- "address": "0x4764a4"
- },
- {
- "name": "CreateCompatibleDC",
- "address": "0x4764a8"
- },
- {
- "name": "CreateCompatibleBitmap",
- "address": "0x4764ac"
- },
- {
- "name": "CreateBrushIndirect",
- "address": "0x4764b0"
- },
- {
- "name": "CreateBitmap",
- "address": "0x4764b4"
- },
- {
- "name": "CopyEnhMetaFileA",
- "address": "0x4764b8"
- },
- {
- "name": "CloseEnhMetaFile",
- "address": "0x4764bc"
- },
- {
- "name": "BitBlt",
- "address": "0x4764c0"
- }
- ],
- "dll": "gdi32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateWindowExA",
- "address": "0x4764c8"
- },
- {
- "name": "WindowFromPoint",
- "address": "0x4764cc"
- },
- {
- "name": "WinHelpA",
- "address": "0x4764d0"
- },
- {
- "name": "WaitMessage",
- "address": "0x4764d4"
- },
- {
- "name": "UpdateWindow",
- "address": "0x4764d8"
- },
- {
- "name": "UnregisterClassA",
- "address": "0x4764dc"
- },
- {
- "name": "UnhookWindowsHookEx",
- "address": "0x4764e0"
- },
- {
- "name": "TranslateMessage",
- "address": "0x4764e4"
- },
- {
- "name": "TranslateMDISysAccel",
- "address": "0x4764e8"
- },
- {
- "name": "TrackPopupMenu",
- "address": "0x4764ec"
- },
- {
- "name": "SystemParametersInfoA",
- "address": "0x4764f0"
- },
- {
- "name": "ShowWindow",
- "address": "0x4764f4"
- },
- {
- "name": "ShowScrollBar",
- "address": "0x4764f8"
- },
- {
- "name": "ShowOwnedPopups",
- "address": "0x4764fc"
- },
- {
- "name": "ShowCursor",
- "address": "0x476500"
- },
- {
- "name": "SetWindowsHookExA",
- "address": "0x476504"
- },
- {
- "name": "SetWindowPos",
- "address": "0x476508"
- },
- {
- "name": "SetWindowPlacement",
- "address": "0x47650c"
- },
- {
- "name": "SetWindowLongA",
- "address": "0x476510"
- },
- {
- "name": "SetTimer",
- "address": "0x476514"
- },
- {
- "name": "SetScrollRange",
- "address": "0x476518"
- },
- {
- "name": "SetScrollPos",
- "address": "0x47651c"
- },
- {
- "name": "SetScrollInfo",
- "address": "0x476520"
- },
- {
- "name": "SetRect",
- "address": "0x476524"
- },
- {
- "name": "SetPropA",
- "address": "0x476528"
- },
- {
- "name": "SetParent",
- "address": "0x47652c"
- },
- {
- "name": "SetMenuItemInfoA",
- "address": "0x476530"
- },
- {
- "name": "SetMenu",
- "address": "0x476534"
- },
- {
- "name": "SetForegroundWindow",
- "address": "0x476538"
- },
- {
- "name": "SetFocus",
- "address": "0x47653c"
- },
- {
- "name": "SetCursor",
- "address": "0x476540"
- },
- {
- "name": "SetClassLongA",
- "address": "0x476544"
- },
- {
- "name": "SetCapture",
- "address": "0x476548"
- },
- {
- "name": "SetActiveWindow",
- "address": "0x47654c"
- },
- {
- "name": "SendMessageA",
- "address": "0x476550"
- },
- {
- "name": "ScrollWindow",
- "address": "0x476554"
- },
- {
- "name": "ScreenToClient",
- "address": "0x476558"
- },
- {
- "name": "RemovePropA",
- "address": "0x47655c"
- },
- {
- "name": "RemoveMenu",
- "address": "0x476560"
- },
- {
- "name": "ReleaseDC",
- "address": "0x476564"
- },
- {
- "name": "ReleaseCapture",
- "address": "0x476568"
- },
- {
- "name": "RegisterWindowMessageA",
- "address": "0x47656c"
- },
- {
- "name": "RegisterClipboardFormatA",
- "address": "0x476570"
- },
- {
- "name": "RegisterClassA",
- "address": "0x476574"
- },
- {
- "name": "RedrawWindow",
- "address": "0x476578"
- },
- {
- "name": "PtInRect",
- "address": "0x47657c"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x476580"
- },
- {
- "name": "PostMessageA",
- "address": "0x476584"
- },
- {
- "name": "PeekMessageA",
- "address": "0x476588"
- },
- {
- "name": "OffsetRect",
- "address": "0x47658c"
- },
- {
- "name": "OemToCharA",
- "address": "0x476590"
- },
- {
- "name": "MsgWaitForMultipleObjects",
- "address": "0x476594"
- },
- {
- "name": "MessageBoxA",
- "address": "0x476598"
- },
- {
- "name": "MapWindowPoints",
- "address": "0x47659c"
- },
- {
- "name": "MapVirtualKeyA",
- "address": "0x4765a0"
- },
- {
- "name": "LoadStringA",
- "address": "0x4765a4"
- },
- {
- "name": "LoadKeyboardLayoutA",
- "address": "0x4765a8"
- },
- {
- "name": "LoadIconA",
- "address": "0x4765ac"
- },
- {
- "name": "LoadCursorA",
- "address": "0x4765b0"
- },
- {
- "name": "LoadBitmapA",
- "address": "0x4765b4"
- },
- {
- "name": "KillTimer",
- "address": "0x4765b8"
- },
- {
- "name": "IsZoomed",
- "address": "0x4765bc"
- },
- {
- "name": "IsWindowVisible",
- "address": "0x4765c0"
- },
- {
- "name": "IsWindowEnabled",
- "address": "0x4765c4"
- },
- {
- "name": "IsWindow",
- "address": "0x4765c8"
- },
- {
- "name": "IsRectEmpty",
- "address": "0x4765cc"
- },
- {
- "name": "IsIconic",
- "address": "0x4765d0"
- },
- {
- "name": "IsDialogMessageA",
- "address": "0x4765d4"
- },
- {
- "name": "IsChild",
- "address": "0x4765d8"
- },
- {
- "name": "InvalidateRect",
- "address": "0x4765dc"
- },
- {
- "name": "IntersectRect",
- "address": "0x4765e0"
- },
- {
- "name": "InsertMenuItemA",
- "address": "0x4765e4"
- },
- {
- "name": "InsertMenuA",
- "address": "0x4765e8"
- },
- {
- "name": "InflateRect",
- "address": "0x4765ec"
- },
- {
- "name": "GetWindowThreadProcessId",
- "address": "0x4765f0"
- },
- {
- "name": "GetWindowTextA",
- "address": "0x4765f4"
- },
- {
- "name": "GetWindowRect",
- "address": "0x4765f8"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x4765fc"
- },
- {
- "name": "GetWindowLongA",
- "address": "0x476600"
- },
- {
- "name": "GetWindowDC",
- "address": "0x476604"
- },
- {
- "name": "GetTopWindow",
- "address": "0x476608"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x47660c"
- },
- {
- "name": "GetSystemMenu",
- "address": "0x476610"
- },
- {
- "name": "GetSysColorBrush",
- "address": "0x476614"
- },
- {
- "name": "GetSysColor",
- "address": "0x476618"
- },
- {
- "name": "GetSubMenu",
- "address": "0x47661c"
- },
- {
- "name": "GetScrollRange",
- "address": "0x476620"
- },
- {
- "name": "GetScrollPos",
- "address": "0x476624"
- },
- {
- "name": "GetScrollInfo",
- "address": "0x476628"
- },
- {
- "name": "GetPropA",
- "address": "0x47662c"
- },
- {
- "name": "GetParent",
- "address": "0x476630"
- },
- {
- "name": "GetWindow",
- "address": "0x476634"
- },
- {
- "name": "GetMessageTime",
- "address": "0x476638"
- },
- {
- "name": "GetMenuStringA",
- "address": "0x47663c"
- },
- {
- "name": "GetMenuState",
- "address": "0x476640"
- },
- {
- "name": "GetMenuItemInfoA",
- "address": "0x476644"
- },
- {
- "name": "GetMenuItemID",
- "address": "0x476648"
- },
- {
- "name": "GetMenuItemCount",
- "address": "0x47664c"
- },
- {
- "name": "GetMenu",
- "address": "0x476650"
- },
- {
- "name": "GetLastActivePopup",
- "address": "0x476654"
- },
- {
- "name": "GetKeyboardState",
- "address": "0x476658"
- },
- {
- "name": "GetKeyboardLayoutList",
- "address": "0x47665c"
- },
- {
- "name": "GetKeyboardLayout",
- "address": "0x476660"
- },
- {
- "name": "GetKeyState",
- "address": "0x476664"
- },
- {
- "name": "GetKeyNameTextA",
- "address": "0x476668"
- },
- {
- "name": "GetIconInfo",
- "address": "0x47666c"
- },
- {
- "name": "GetForegroundWindow",
- "address": "0x476670"
- },
- {
- "name": "GetFocus",
- "address": "0x476674"
- },
- {
- "name": "GetDesktopWindow",
- "address": "0x476678"
- },
- {
- "name": "GetDCEx",
- "address": "0x47667c"
- },
- {
- "name": "GetDC",
- "address": "0x476680"
- },
- {
- "name": "GetCursorPos",
- "address": "0x476684"
- },
- {
- "name": "GetCursor",
- "address": "0x476688"
- },
- {
- "name": "GetClipboardData",
- "address": "0x47668c"
- },
- {
- "name": "GetClientRect",
- "address": "0x476690"
- },
- {
- "name": "GetClassNameA",
- "address": "0x476694"
- },
- {
- "name": "GetClassInfoA",
- "address": "0x476698"
- },
- {
- "name": "GetCapture",
- "address": "0x47669c"
- },
- {
- "name": "GetActiveWindow",
- "address": "0x4766a0"
- },
- {
- "name": "FrameRect",
- "address": "0x4766a4"
- },
- {
- "name": "FindWindowA",
- "address": "0x4766a8"
- },
- {
- "name": "FillRect",
- "address": "0x4766ac"
- },
- {
- "name": "EqualRect",
- "address": "0x4766b0"
- },
- {
- "name": "EnumWindows",
- "address": "0x4766b4"
- },
- {
- "name": "EnumThreadWindows",
- "address": "0x4766b8"
- },
- {
- "name": "EndPaint",
- "address": "0x4766bc"
- },
- {
- "name": "EnableWindow",
- "address": "0x4766c0"
- },
- {
- "name": "EnableScrollBar",
- "address": "0x4766c4"
- },
- {
- "name": "EnableMenuItem",
- "address": "0x4766c8"
- },
- {
- "name": "DrawTextA",
- "address": "0x4766cc"
- },
- {
- "name": "DrawMenuBar",
- "address": "0x4766d0"
- },
- {
- "name": "DrawIconEx",
- "address": "0x4766d4"
- },
- {
- "name": "DrawIcon",
- "address": "0x4766d8"
- },
- {
- "name": "DrawFrameControl",
- "address": "0x4766dc"
- },
- {
- "name": "DrawEdge",
- "address": "0x4766e0"
- },
- {
- "name": "DispatchMessageA",
- "address": "0x4766e4"
- },
- {
- "name": "DestroyWindow",
- "address": "0x4766e8"
- },
- {
- "name": "DestroyMenu",
- "address": "0x4766ec"
- },
- {
- "name": "DestroyIcon",
- "address": "0x4766f0"
- },
- {
- "name": "DestroyCursor",
- "address": "0x4766f4"
- },
- {
- "name": "DeleteMenu",
- "address": "0x4766f8"
- },
- {
- "name": "DefWindowProcA",
- "address": "0x4766fc"
- },
- {
- "name": "DefMDIChildProcA",
- "address": "0x476700"
- },
- {
- "name": "DefFrameProcA",
- "address": "0x476704"
- },
- {
- "name": "CreatePopupMenu",
- "address": "0x476708"
- },
- {
- "name": "CreateMenu",
- "address": "0x47670c"
- },
- {
- "name": "CreateIcon",
- "address": "0x476710"
- },
- {
- "name": "ClientToScreen",
- "address": "0x476714"
- },
- {
- "name": "CheckMenuItem",
- "address": "0x476718"
- },
- {
- "name": "CallWindowProcA",
- "address": "0x47671c"
- },
- {
- "name": "CallNextHookEx",
- "address": "0x476720"
- },
- {
- "name": "BeginPaint",
- "address": "0x476724"
- },
- {
- "name": "CharNextA",
- "address": "0x476728"
- },
- {
- "name": "CharLowerBuffA",
- "address": "0x47672c"
- },
- {
- "name": "CharLowerA",
- "address": "0x476730"
- },
- {
- "name": "CharToOemA",
- "address": "0x476734"
- },
- {
- "name": "AdjustWindowRectEx",
- "address": "0x476738"
- },
- {
- "name": "ActivateKeyboardLayout",
- "address": "0x47673c"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "Sleep",
- "address": "0x476744"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "SafeArrayPtrOfIndex",
- "address": "0x47674c"
- },
- {
- "name": "SafeArrayGetUBound",
- "address": "0x476750"
- },
- {
- "name": "SafeArrayGetLBound",
- "address": "0x476754"
- },
- {
- "name": "SafeArrayCreate",
- "address": "0x476758"
- },
- {
- "name": "VariantChangeType",
- "address": "0x47675c"
- },
- {
- "name": "VariantCopy",
- "address": "0x476760"
- },
- {
- "name": "VariantClear",
- "address": "0x476764"
- },
- {
- "name": "VariantInit",
- "address": "0x476768"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateStreamOnHGlobal",
- "address": "0x476770"
- },
- {
- "name": "IsAccelerator",
- "address": "0x476774"
- },
- {
- "name": "OleDraw",
- "address": "0x476778"
- },
- {
- "name": "OleSetMenuDescriptor",
- "address": "0x47677c"
- },
- {
- "name": "CoCreateInstance",
- "address": "0x476780"
- },
- {
- "name": "CoGetClassObject",
- "address": "0x476784"
- },
- {
- "name": "CoUninitialize",
- "address": "0x476788"
- },
- {
- "name": "CoInitialize",
- "address": "0x47678c"
- },
- {
- "name": "IsEqualGUID",
- "address": "0x476790"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "GetErrorInfo",
- "address": "0x476798"
- },
- {
- "name": "SysFreeString",
- "address": "0x47679c"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "ImageList_SetIconSize",
- "address": "0x4767a4"
- },
- {
- "name": "ImageList_GetIconSize",
- "address": "0x4767a8"
- },
- {
- "name": "ImageList_Write",
- "address": "0x4767ac"
- },
- {
- "name": "ImageList_Read",
- "address": "0x4767b0"
- },
- {
- "name": "ImageList_GetDragImage",
- "address": "0x4767b4"
- },
- {
- "name": "ImageList_DragShowNolock",
- "address": "0x4767b8"
- },
- {
- "name": "ImageList_SetDragCursorImage",
- "address": "0x4767bc"
- },
- {
- "name": "ImageList_DragMove",
- "address": "0x4767c0"
- },
- {
- "name": "ImageList_DragLeave",
- "address": "0x4767c4"
- },
- {
- "name": "ImageList_DragEnter",
- "address": "0x4767c8"
- },
- {
- "name": "ImageList_EndDrag",
- "address": "0x4767cc"
- },
- {
- "name": "ImageList_BeginDrag",
- "address": "0x4767d0"
- },
- {
- "name": "ImageList_Remove",
- "address": "0x4767d4"
- },
- {
- "name": "ImageList_DrawEx",
- "address": "0x4767d8"
- },
- {
- "name": "ImageList_Draw",
- "address": "0x4767dc"
- },
- {
- "name": "ImageList_GetBkColor",
- "address": "0x4767e0"
- },
- {
- "name": "ImageList_SetBkColor",
- "address": "0x4767e4"
- },
- {
- "name": "ImageList_ReplaceIcon",
- "address": "0x4767e8"
- },
- {
- "name": "ImageList_Add",
- "address": "0x4767ec"
- },
- {
- "name": "ImageList_GetImageCount",
- "address": "0x4767f0"
- },
- {
- "name": "ImageList_Destroy",
- "address": "0x4767f4"
- },
- {
- "name": "ImageList_Create",
- "address": "0x4767f8"
- }
- ],
- "dll": "comctl32.dll"
- },
- {
- "imports": [
- {
- "name": "OpenPrinterA",
- "address": "0x476800"
- },
- {
- "name": "EnumPrintersA",
- "address": "0x476804"
- },
- {
- "name": "DocumentPropertiesA",
- "address": "0x476808"
- },
- {
- "name": "ClosePrinter",
- "address": "0x47680c"
- }
- ],
- "dll": "winspool.drv"
- },
- {
- "imports": [
- {
- "name": "PrintDlgA",
- "address": "0x476814"
- }
- ],
- "dll": "comdlg32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x000a8994",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x0046a7a0",
- "timestamp": "1992-04-26 01:18:37",
- "osversion": "4.0",
- "sections": [
- {
- "name": "CODE",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00069800",
- "entropy": "6.53",
- "raw_address": "0x00000400",
- "virtual_size": "0x000697e8",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": "DATA",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0006b000",
- "size_of_data": "0x00009e00",
- "entropy": "5.04",
- "raw_address": "0x00069c00",
- "virtual_size": "0x00009ca8",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": "BSS",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00075000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00073a00",
- "virtual_size": "0x00000fa9",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".idata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00076000",
- "size_of_data": "0x00002600",
- "entropy": "4.83",
- "raw_address": "0x00073a00",
- "virtual_size": "0x000024c6",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00079000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00076000",
- "virtual_size": "0x00000010",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0007a000",
- "size_of_data": "0x00000200",
- "entropy": "0.21",
- "raw_address": "0x00076000",
- "virtual_size": "0x00000018",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0007b000",
- "size_of_data": "0x00008400",
- "entropy": "6.65",
- "raw_address": "0x00076200",
- "virtual_size": "0x000083a4",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00084000",
- "size_of_data": "0x0002a000",
- "entropy": "6.96",
- "raw_address": "0x0007e600",
- "virtual_size": "0x00029e20",
- "characteristics_raw": "0x50000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00076000",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x000024c6"
- },
- {
- "virtual_address": "0x00084000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00029e20"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0007b000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x000083a4"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0007a000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "d553c8d26e9a2369ccc8481987fa6051",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 17,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement