Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: ""
- [*] MalScore: 10.0
- [*] File Name: "Exes_a7ccedee.exe"
- [*] File Size: 458752
- [*] File Type: "PE32 executable (console) Intel 80386, for MS Windows"
- [*] SHA256: "3d6bc146d5338159005ae3d66c7fda67a6ada1dc1a66b4ab17301ef4ec1b665b"
- [*] MD5: "44a765fe57dea1ae7b642010c7209932"
- [*] SHA1: "3e97fc2183c9af4d8f71d0a546b6c2611495a46c"
- [*] SHA512: "6ecba354b1cd685588cf7aa44092d99e227a7e99bfd1c9b8811960a556e556b555853560271b1cc4f8744dbbd95c726b6ce183ae9fdd298efaf7bcd551d1edae"
- [*] CRC32: "A7CCEDEE"
- [*] SSDEEP: "6144:S8afWfuCiCEfwdciYYx8+W52q1BPf4/TsynXMPBc11Pw3ozkfRV4UszE7hvriHi:S6ueEMPvWTBPfMsBPCRzUMUszE7hvIi"
- [*] Process Execution: [
- "Exes_a7ccedee.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "Creates RWX memory",
- "Details": []
- },
- {
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details": [
- {
- "section": "name: .rsrc, entropy: 6.88, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x0003de00, virtual_size: 0x0003dcb5"
- }
- ]
- },
- {
- "Description": "File has been identified by 44 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "MicroWorld-eScan": "Gen:Variant.Ulise.38716"
- },
- {
- "ALYac": "Gen:Variant.Ser.Mikey.443"
- },
- {
- "Cylance": "Unsafe"
- },
- {
- "Alibaba": "Trojan:Win32/Kryptik.ed97f86e"
- },
- {
- "K7GW": "Trojan ( 0054ff161 )"
- },
- {
- "Arcabit": "Trojan.Ulise.D973C"
- },
- {
- "TrendMicro": "Trojan.Win32.FUERBOOS.USXVPFD19"
- },
- {
- "Cyren": "W32/Trojan.ZPHJ-2234"
- },
- {
- "Symantec": "ML.Attribute.HighConfidence"
- },
- {
- "APEX": "Malicious"
- },
- {
- "Avast": "Win32:PWSX-gen [Trj]"
- },
- {
- "Kaspersky": "Trojan.Win32.NetWire.fax"
- },
- {
- "BitDefender": "Gen:Variant.Ulise.38716"
- },
- {
- "NANO-Antivirus": "Trojan.Win32.Kryptik.frghxh"
- },
- {
- "Paloalto": "generic.ml"
- },
- {
- "AegisLab": "Trojan.Multi.Generic.4!c"
- },
- {
- "Rising": "Trojan.Kryptik!8.8 (CLOUD)"
- },
- {
- "Ad-Aware": "Gen:Variant.Ulise.38716"
- },
- {
- "Emsisoft": "Gen:Variant.Ulise.38716 (B)"
- },
- {
- "F-Secure": "Trojan.TR/AD.NetWiredRc.joxan"
- },
- {
- "Invincea": "heuristic"
- },
- {
- "McAfee-GW-Edition": "BehavesLike.Win32.BadFile.gh"
- },
- {
- "Trapmine": "malicious.high.ml.score"
- },
- {
- "FireEye": "Generic.mg.44a765fe57dea1ae"
- },
- {
- "SentinelOne": "DFI - Suspicious PE"
- },
- {
- "ESET-NOD32": "a variant of Win32/Kryptik.GTXI"
- },
- {
- "Avira": "TR/AD.NetWiredRc.joxan"
- },
- {
- "Microsoft": "TrojanSpy:Win32/Loyeetro.B!bit"
- },
- {
- "Endgame": "malicious (high confidence)"
- },
- {
- "ViRobot": "Trojan.Win32.Z.Ulise.458752"
- },
- {
- "ZoneAlarm": "Trojan.Win32.NetWire.fax"
- },
- {
- "GData": "Gen:Variant.Ulise.38716"
- },
- {
- "Acronis": "suspicious"
- },
- {
- "McAfee": "GenericRXHT-XX!44A765FE57DE"
- },
- {
- "VBA32": "BScope.Trojan.Inject"
- },
- {
- "Malwarebytes": "Trojan.MalPack.RES"
- },
- {
- "TrendMicro-HouseCall": "TROJ_GEN.R002H0CFD19"
- },
- {
- "Ikarus": "Win32.Outbreak"
- },
- {
- "Fortinet": "W32/Kryptik.GTWJ!tr"
- },
- {
- "Webroot": "W32.Trojan.Gen"
- },
- {
- "AVG": "Win32:PWSX-gen [Trj]"
- },
- {
- "Panda": "Trj/CI.A"
- },
- {
- "CrowdStrike": "win/malicious_confidence_100% (W)"
- },
- {
- "Qihoo-360": "Win32/Trojan.0c6"
- }
- ]
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: []
- [*] Mutexes: [
- "DBWinMutex"
- ]
- [*] Modified Files: []
- [*] Deleted Files: []
- [*] Modified Registry Keys: []
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "GetProcessHeap",
- "address": "0x41c078"
- },
- {
- "name": "FreeEnvironmentStringsW",
- "address": "0x41c07c"
- },
- {
- "name": "GetEnvironmentStringsW",
- "address": "0x41c080"
- },
- {
- "name": "GetCPInfo",
- "address": "0x41c084"
- },
- {
- "name": "GetOEMCP",
- "address": "0x41c088"
- },
- {
- "name": "IsValidCodePage",
- "address": "0x41c08c"
- },
- {
- "name": "GetConsoleCP",
- "address": "0x41c090"
- },
- {
- "name": "FindNextFileA",
- "address": "0x41c094"
- },
- {
- "name": "FindFirstFileExA",
- "address": "0x41c098"
- },
- {
- "name": "DecodePointer",
- "address": "0x41c09c"
- },
- {
- "name": "GetFileAttributesA",
- "address": "0x41c0a0"
- },
- {
- "name": "WriteConsoleW",
- "address": "0x41c0a4"
- },
- {
- "name": "HeapSize",
- "address": "0x41c0a8"
- },
- {
- "name": "HeapReAlloc",
- "address": "0x41c0ac"
- },
- {
- "name": "FlushFileBuffers",
- "address": "0x41c0b0"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x41c0b4"
- },
- {
- "name": "ReadFile",
- "address": "0x41c0b8"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x41c0bc"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x41c0c0"
- },
- {
- "name": "VirtualFree",
- "address": "0x41c0c4"
- },
- {
- "name": "VirtualProtect",
- "address": "0x41c0c8"
- },
- {
- "name": "GetPrivateProfileStructA",
- "address": "0x41c0cc"
- },
- {
- "name": "GetEnvironmentVariableW",
- "address": "0x41c0d0"
- },
- {
- "name": "FindClose",
- "address": "0x41c0d4"
- },
- {
- "name": "GetConsoleAliasExesLengthW",
- "address": "0x41c0d8"
- },
- {
- "name": "SetComputerNameA",
- "address": "0x41c0dc"
- },
- {
- "name": "_hread",
- "address": "0x41c0e0"
- },
- {
- "name": "CopyFileExW",
- "address": "0x41c0e4"
- },
- {
- "name": "TlsFree",
- "address": "0x41c0e8"
- },
- {
- "name": "UnregisterWait",
- "address": "0x41c0ec"
- },
- {
- "name": "FillConsoleOutputCharacterW",
- "address": "0x41c0f0"
- },
- {
- "name": "SetConsoleTitleW",
- "address": "0x41c0f4"
- },
- {
- "name": "Process32First",
- "address": "0x41c0f8"
- },
- {
- "name": "RequestWakeupLatency",
- "address": "0x41c0fc"
- },
- {
- "name": "FindNextChangeNotification",
- "address": "0x41c100"
- },
- {
- "name": "SetLocaleInfoA",
- "address": "0x41c104"
- },
- {
- "name": "DisableThreadLibraryCalls",
- "address": "0x41c108"
- },
- {
- "name": "LCMapStringW",
- "address": "0x41c10c"
- },
- {
- "name": "CompareStringW",
- "address": "0x41c110"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x41c114"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x41c118"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x41c11c"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x41c120"
- },
- {
- "name": "InitializeSListHead",
- "address": "0x41c124"
- },
- {
- "name": "IsDebuggerPresent",
- "address": "0x41c128"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x41c12c"
- },
- {
- "name": "SetUnhandledExceptionFilter",
- "address": "0x41c130"
- },
- {
- "name": "GetStartupInfoW",
- "address": "0x41c134"
- },
- {
- "name": "IsProcessorFeaturePresent",
- "address": "0x41c138"
- },
- {
- "name": "GetModuleHandleW",
- "address": "0x41c13c"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x41c140"
- },
- {
- "name": "TerminateProcess",
- "address": "0x41c144"
- },
- {
- "name": "RtlUnwind",
- "address": "0x41c148"
- },
- {
- "name": "VirtualQuery",
- "address": "0x41c14c"
- },
- {
- "name": "GetLastError",
- "address": "0x41c150"
- },
- {
- "name": "SetLastError",
- "address": "0x41c154"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x41c158"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x41c15c"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x41c160"
- },
- {
- "name": "InitializeCriticalSectionAndSpinCount",
- "address": "0x41c164"
- },
- {
- "name": "TlsAlloc",
- "address": "0x41c168"
- },
- {
- "name": "TlsGetValue",
- "address": "0x41c16c"
- },
- {
- "name": "TlsSetValue",
- "address": "0x41c170"
- },
- {
- "name": "FreeLibrary",
- "address": "0x41c174"
- },
- {
- "name": "GetProcAddress",
- "address": "0x41c178"
- },
- {
- "name": "LoadLibraryExW",
- "address": "0x41c17c"
- },
- {
- "name": "SetEnvironmentVariableA",
- "address": "0x41c180"
- },
- {
- "name": "SetEnvironmentVariableW",
- "address": "0x41c184"
- },
- {
- "name": "SetCurrentDirectoryW",
- "address": "0x41c188"
- },
- {
- "name": "GetCurrentDirectoryW",
- "address": "0x41c18c"
- },
- {
- "name": "SetFilePointerEx",
- "address": "0x41c190"
- },
- {
- "name": "GetConsoleMode",
- "address": "0x41c194"
- },
- {
- "name": "ReadConsoleInputA",
- "address": "0x41c198"
- },
- {
- "name": "SetConsoleMode",
- "address": "0x41c19c"
- },
- {
- "name": "CloseHandle",
- "address": "0x41c1a0"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x41c1a4"
- },
- {
- "name": "GetExitCodeProcess",
- "address": "0x41c1a8"
- },
- {
- "name": "CreateProcessA",
- "address": "0x41c1ac"
- },
- {
- "name": "GetLocalTime",
- "address": "0x41c1b0"
- },
- {
- "name": "SetStdHandle",
- "address": "0x41c1b4"
- },
- {
- "name": "GetFileType",
- "address": "0x41c1b8"
- },
- {
- "name": "GetStdHandle",
- "address": "0x41c1bc"
- },
- {
- "name": "WriteFile",
- "address": "0x41c1c0"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x41c1c4"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x41c1c8"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x41c1cc"
- },
- {
- "name": "ExitProcess",
- "address": "0x41c1d0"
- },
- {
- "name": "GetModuleHandleExW",
- "address": "0x41c1d4"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x41c1d8"
- },
- {
- "name": "GetCommandLineW",
- "address": "0x41c1dc"
- },
- {
- "name": "GetACP",
- "address": "0x41c1e0"
- },
- {
- "name": "HeapFree",
- "address": "0x41c1e4"
- },
- {
- "name": "HeapAlloc",
- "address": "0x41c1e8"
- },
- {
- "name": "GetStringTypeW",
- "address": "0x41c1ec"
- },
- {
- "name": "RaiseException",
- "address": "0x41c1f0"
- },
- {
- "name": "CreateFileW",
- "address": "0x41c1f4"
- },
- {
- "name": "GetFileAttributesExW",
- "address": "0x41c1f8"
- },
- {
- "name": "ReadConsoleW",
- "address": "0x41c1fc"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "GetUpdateRect",
- "address": "0x41c204"
- },
- {
- "name": "GetSystemMenu",
- "address": "0x41c208"
- },
- {
- "name": "SetMenuItemBitmaps",
- "address": "0x41c20c"
- },
- {
- "name": "MoveWindow",
- "address": "0x41c210"
- },
- {
- "name": "CallNextHookEx",
- "address": "0x41c214"
- },
- {
- "name": "SetProcessWindowStation",
- "address": "0x41c218"
- },
- {
- "name": "PostThreadMessageW",
- "address": "0x41c21c"
- },
- {
- "name": "GetTabbedTextExtentW",
- "address": "0x41c220"
- },
- {
- "name": "DeleteMenu",
- "address": "0x41c224"
- },
- {
- "name": "RealGetWindowClass",
- "address": "0x41c228"
- },
- {
- "name": "BroadcastSystemMessageW",
- "address": "0x41c22c"
- },
- {
- "name": "GetClassInfoExW",
- "address": "0x41c230"
- },
- {
- "name": "WINNLSEnableIME",
- "address": "0x41c234"
- },
- {
- "name": "SetWindowsHookA",
- "address": "0x41c238"
- },
- {
- "name": "WaitForInputIdle",
- "address": "0x41c23c"
- },
- {
- "name": "DdeDisconnect",
- "address": "0x41c240"
- },
- {
- "name": "FlashWindowEx",
- "address": "0x41c244"
- },
- {
- "name": "InSendMessage",
- "address": "0x41c248"
- },
- {
- "name": "GetNextDlgTabItem",
- "address": "0x41c24c"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateFontIndirectExA",
- "address": "0x41c038"
- },
- {
- "name": "GetColorSpace",
- "address": "0x41c03c"
- },
- {
- "name": "UpdateColors",
- "address": "0x41c040"
- },
- {
- "name": "CreatePalette",
- "address": "0x41c044"
- },
- {
- "name": "EqualRgn",
- "address": "0x41c048"
- },
- {
- "name": "GetRgnBox",
- "address": "0x41c04c"
- },
- {
- "name": "SetPixel",
- "address": "0x41c050"
- },
- {
- "name": "RemoveFontResourceExW",
- "address": "0x41c054"
- },
- {
- "name": "GetTextFaceW",
- "address": "0x41c058"
- },
- {
- "name": "GetGraphicsMode",
- "address": "0x41c05c"
- },
- {
- "name": "SelectObject",
- "address": "0x41c060"
- },
- {
- "name": "GetGlyphOutlineA",
- "address": "0x41c064"
- },
- {
- "name": "SetWindowExtEx",
- "address": "0x41c068"
- },
- {
- "name": "GdiGetPageHandle",
- "address": "0x41c06c"
- },
- {
- "name": "GetFontLanguageInfo",
- "address": "0x41c070"
- }
- ],
- "dll": "GDI32.dll"
- },
- {
- "imports": [
- {
- "name": "SetPrinterW",
- "address": "0x41c254"
- },
- {
- "name": "GetPrinterDataExW",
- "address": "0x41c258"
- },
- {
- "name": "EnumPortsW",
- "address": "0x41c25c"
- }
- ],
- "dll": "WINSPOOL.DRV"
- },
- {
- "imports": [
- {
- "name": "GetOpenFileNameA",
- "address": "0x41c030"
- }
- ],
- "dll": "COMDLG32.dll"
- },
- {
- "imports": [
- {
- "name": "LsaOpenTrustedDomain",
- "address": "0x41c000"
- },
- {
- "name": "AreAnyAccessesGranted",
- "address": "0x41c004"
- },
- {
- "name": "LsaLookupPrivilegeName",
- "address": "0x41c008"
- },
- {
- "name": "QueryServiceConfigA",
- "address": "0x41c00c"
- },
- {
- "name": "LookupAccountNameW",
- "address": "0x41c010"
- },
- {
- "name": "SystemFunction031",
- "address": "0x41c014"
- },
- {
- "name": "AllocateAndInitializeSid",
- "address": "0x41c018"
- },
- {
- "name": "RegSaveKeyA",
- "address": "0x41c01c"
- },
- {
- "name": "BuildExplicitAccessWithNameW",
- "address": "0x41c020"
- },
- {
- "name": "CryptEnumProvidersA",
- "address": "0x41c024"
- },
- {
- "name": "AddUsersToEncryptedFile",
- "address": "0x41c028"
- }
- ],
- "dll": "ADVAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "CLSIDFromString",
- "address": "0x41c264"
- },
- {
- "name": "HWND_UserUnmarshal",
- "address": "0x41c268"
- },
- {
- "name": "OleCreateFromData",
- "address": "0x41c26c"
- },
- {
- "name": "CoAddRefServerProcess",
- "address": "0x41c270"
- },
- {
- "name": "ReadClassStg",
- "address": "0x41c274"
- },
- {
- "name": "WriteClassStg",
- "address": "0x41c278"
- }
- ],
- "dll": "ole32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x0007566a",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x00403bf9",
- "timestamp": "2019-06-11 13:23:14",
- "osversion": "5.1",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x0001b000",
- "entropy": "6.69",
- "raw_address": "0x00000400",
- "virtual_size": "0x0001af27",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0001c000",
- "size_of_data": "0x00008c00",
- "entropy": "5.16",
- "raw_address": "0x0001b400",
- "virtual_size": "0x00008b96",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00025000",
- "size_of_data": "0x0000b800",
- "entropy": "6.27",
- "raw_address": "0x00024000",
- "virtual_size": "0x0000c280",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".gfids",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00032000",
- "size_of_data": "0x00000600",
- "entropy": "2.89",
- "raw_address": "0x0002f800",
- "virtual_size": "0x000004b0",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00033000",
- "size_of_data": "0x0003de00",
- "entropy": "6.88",
- "raw_address": "0x0002fe00",
- "virtual_size": "0x0003dcb5",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00071000",
- "size_of_data": "0x00002400",
- "entropy": "6.62",
- "raw_address": "0x0006dc00",
- "virtual_size": "0x00002300",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00023c9c",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x000000a0"
- },
- {
- "virtual_address": "0x00033000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x0003dcb5"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00071000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00002300"
- },
- {
- "virtual_address": "0x00023410",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00023430",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000040"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0001c000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000280"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "f9828a7115467336fc1f5ae8124ddad0",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 7,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "kernel32.dll.FlsAlloc",
- "kernel32.dll.FlsSetValue",
- "kernel32.dll.FlsGetValue",
- "kernel32.dll.LCMapStringEx"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "GetProcessHeap",
- "address": "0x41c078"
- },
- {
- "name": "FreeEnvironmentStringsW",
- "address": "0x41c07c"
- },
- {
- "name": "GetEnvironmentStringsW",
- "address": "0x41c080"
- },
- {
- "name": "GetCPInfo",
- "address": "0x41c084"
- },
- {
- "name": "GetOEMCP",
- "address": "0x41c088"
- },
- {
- "name": "IsValidCodePage",
- "address": "0x41c08c"
- },
- {
- "name": "GetConsoleCP",
- "address": "0x41c090"
- },
- {
- "name": "FindNextFileA",
- "address": "0x41c094"
- },
- {
- "name": "FindFirstFileExA",
- "address": "0x41c098"
- },
- {
- "name": "DecodePointer",
- "address": "0x41c09c"
- },
- {
- "name": "GetFileAttributesA",
- "address": "0x41c0a0"
- },
- {
- "name": "WriteConsoleW",
- "address": "0x41c0a4"
- },
- {
- "name": "HeapSize",
- "address": "0x41c0a8"
- },
- {
- "name": "HeapReAlloc",
- "address": "0x41c0ac"
- },
- {
- "name": "FlushFileBuffers",
- "address": "0x41c0b0"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x41c0b4"
- },
- {
- "name": "ReadFile",
- "address": "0x41c0b8"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x41c0bc"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x41c0c0"
- },
- {
- "name": "VirtualFree",
- "address": "0x41c0c4"
- },
- {
- "name": "VirtualProtect",
- "address": "0x41c0c8"
- },
- {
- "name": "GetPrivateProfileStructA",
- "address": "0x41c0cc"
- },
- {
- "name": "GetEnvironmentVariableW",
- "address": "0x41c0d0"
- },
- {
- "name": "FindClose",
- "address": "0x41c0d4"
- },
- {
- "name": "GetConsoleAliasExesLengthW",
- "address": "0x41c0d8"
- },
- {
- "name": "SetComputerNameA",
- "address": "0x41c0dc"
- },
- {
- "name": "_hread",
- "address": "0x41c0e0"
- },
- {
- "name": "CopyFileExW",
- "address": "0x41c0e4"
- },
- {
- "name": "TlsFree",
- "address": "0x41c0e8"
- },
- {
- "name": "UnregisterWait",
- "address": "0x41c0ec"
- },
- {
- "name": "FillConsoleOutputCharacterW",
- "address": "0x41c0f0"
- },
- {
- "name": "SetConsoleTitleW",
- "address": "0x41c0f4"
- },
- {
- "name": "Process32First",
- "address": "0x41c0f8"
- },
- {
- "name": "RequestWakeupLatency",
- "address": "0x41c0fc"
- },
- {
- "name": "FindNextChangeNotification",
- "address": "0x41c100"
- },
- {
- "name": "SetLocaleInfoA",
- "address": "0x41c104"
- },
- {
- "name": "DisableThreadLibraryCalls",
- "address": "0x41c108"
- },
- {
- "name": "LCMapStringW",
- "address": "0x41c10c"
- },
- {
- "name": "CompareStringW",
- "address": "0x41c110"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x41c114"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x41c118"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x41c11c"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x41c120"
- },
- {
- "name": "InitializeSListHead",
- "address": "0x41c124"
- },
- {
- "name": "IsDebuggerPresent",
- "address": "0x41c128"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x41c12c"
- },
- {
- "name": "SetUnhandledExceptionFilter",
- "address": "0x41c130"
- },
- {
- "name": "GetStartupInfoW",
- "address": "0x41c134"
- },
- {
- "name": "IsProcessorFeaturePresent",
- "address": "0x41c138"
- },
- {
- "name": "GetModuleHandleW",
- "address": "0x41c13c"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x41c140"
- },
- {
- "name": "TerminateProcess",
- "address": "0x41c144"
- },
- {
- "name": "RtlUnwind",
- "address": "0x41c148"
- },
- {
- "name": "VirtualQuery",
- "address": "0x41c14c"
- },
- {
- "name": "GetLastError",
- "address": "0x41c150"
- },
- {
- "name": "SetLastError",
- "address": "0x41c154"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x41c158"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x41c15c"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x41c160"
- },
- {
- "name": "InitializeCriticalSectionAndSpinCount",
- "address": "0x41c164"
- },
- {
- "name": "TlsAlloc",
- "address": "0x41c168"
- },
- {
- "name": "TlsGetValue",
- "address": "0x41c16c"
- },
- {
- "name": "TlsSetValue",
- "address": "0x41c170"
- },
- {
- "name": "FreeLibrary",
- "address": "0x41c174"
- },
- {
- "name": "GetProcAddress",
- "address": "0x41c178"
- },
- {
- "name": "LoadLibraryExW",
- "address": "0x41c17c"
- },
- {
- "name": "SetEnvironmentVariableA",
- "address": "0x41c180"
- },
- {
- "name": "SetEnvironmentVariableW",
- "address": "0x41c184"
- },
- {
- "name": "SetCurrentDirectoryW",
- "address": "0x41c188"
- },
- {
- "name": "GetCurrentDirectoryW",
- "address": "0x41c18c"
- },
- {
- "name": "SetFilePointerEx",
- "address": "0x41c190"
- },
- {
- "name": "GetConsoleMode",
- "address": "0x41c194"
- },
- {
- "name": "ReadConsoleInputA",
- "address": "0x41c198"
- },
- {
- "name": "SetConsoleMode",
- "address": "0x41c19c"
- },
- {
- "name": "CloseHandle",
- "address": "0x41c1a0"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x41c1a4"
- },
- {
- "name": "GetExitCodeProcess",
- "address": "0x41c1a8"
- },
- {
- "name": "CreateProcessA",
- "address": "0x41c1ac"
- },
- {
- "name": "GetLocalTime",
- "address": "0x41c1b0"
- },
- {
- "name": "SetStdHandle",
- "address": "0x41c1b4"
- },
- {
- "name": "GetFileType",
- "address": "0x41c1b8"
- },
- {
- "name": "GetStdHandle",
- "address": "0x41c1bc"
- },
- {
- "name": "WriteFile",
- "address": "0x41c1c0"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x41c1c4"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x41c1c8"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x41c1cc"
- },
- {
- "name": "ExitProcess",
- "address": "0x41c1d0"
- },
- {
- "name": "GetModuleHandleExW",
- "address": "0x41c1d4"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x41c1d8"
- },
- {
- "name": "GetCommandLineW",
- "address": "0x41c1dc"
- },
- {
- "name": "GetACP",
- "address": "0x41c1e0"
- },
- {
- "name": "HeapFree",
- "address": "0x41c1e4"
- },
- {
- "name": "HeapAlloc",
- "address": "0x41c1e8"
- },
- {
- "name": "GetStringTypeW",
- "address": "0x41c1ec"
- },
- {
- "name": "RaiseException",
- "address": "0x41c1f0"
- },
- {
- "name": "CreateFileW",
- "address": "0x41c1f4"
- },
- {
- "name": "GetFileAttributesExW",
- "address": "0x41c1f8"
- },
- {
- "name": "ReadConsoleW",
- "address": "0x41c1fc"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "GetUpdateRect",
- "address": "0x41c204"
- },
- {
- "name": "GetSystemMenu",
- "address": "0x41c208"
- },
- {
- "name": "SetMenuItemBitmaps",
- "address": "0x41c20c"
- },
- {
- "name": "MoveWindow",
- "address": "0x41c210"
- },
- {
- "name": "CallNextHookEx",
- "address": "0x41c214"
- },
- {
- "name": "SetProcessWindowStation",
- "address": "0x41c218"
- },
- {
- "name": "PostThreadMessageW",
- "address": "0x41c21c"
- },
- {
- "name": "GetTabbedTextExtentW",
- "address": "0x41c220"
- },
- {
- "name": "DeleteMenu",
- "address": "0x41c224"
- },
- {
- "name": "RealGetWindowClass",
- "address": "0x41c228"
- },
- {
- "name": "BroadcastSystemMessageW",
- "address": "0x41c22c"
- },
- {
- "name": "GetClassInfoExW",
- "address": "0x41c230"
- },
- {
- "name": "WINNLSEnableIME",
- "address": "0x41c234"
- },
- {
- "name": "SetWindowsHookA",
- "address": "0x41c238"
- },
- {
- "name": "WaitForInputIdle",
- "address": "0x41c23c"
- },
- {
- "name": "DdeDisconnect",
- "address": "0x41c240"
- },
- {
- "name": "FlashWindowEx",
- "address": "0x41c244"
- },
- {
- "name": "InSendMessage",
- "address": "0x41c248"
- },
- {
- "name": "GetNextDlgTabItem",
- "address": "0x41c24c"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateFontIndirectExA",
- "address": "0x41c038"
- },
- {
- "name": "GetColorSpace",
- "address": "0x41c03c"
- },
- {
- "name": "UpdateColors",
- "address": "0x41c040"
- },
- {
- "name": "CreatePalette",
- "address": "0x41c044"
- },
- {
- "name": "EqualRgn",
- "address": "0x41c048"
- },
- {
- "name": "GetRgnBox",
- "address": "0x41c04c"
- },
- {
- "name": "SetPixel",
- "address": "0x41c050"
- },
- {
- "name": "RemoveFontResourceExW",
- "address": "0x41c054"
- },
- {
- "name": "GetTextFaceW",
- "address": "0x41c058"
- },
- {
- "name": "GetGraphicsMode",
- "address": "0x41c05c"
- },
- {
- "name": "SelectObject",
- "address": "0x41c060"
- },
- {
- "name": "GetGlyphOutlineA",
- "address": "0x41c064"
- },
- {
- "name": "SetWindowExtEx",
- "address": "0x41c068"
- },
- {
- "name": "GdiGetPageHandle",
- "address": "0x41c06c"
- },
- {
- "name": "GetFontLanguageInfo",
- "address": "0x41c070"
- }
- ],
- "dll": "GDI32.dll"
- },
- {
- "imports": [
- {
- "name": "SetPrinterW",
- "address": "0x41c254"
- },
- {
- "name": "GetPrinterDataExW",
- "address": "0x41c258"
- },
- {
- "name": "EnumPortsW",
- "address": "0x41c25c"
- }
- ],
- "dll": "WINSPOOL.DRV"
- },
- {
- "imports": [
- {
- "name": "GetOpenFileNameA",
- "address": "0x41c030"
- }
- ],
- "dll": "COMDLG32.dll"
- },
- {
- "imports": [
- {
- "name": "LsaOpenTrustedDomain",
- "address": "0x41c000"
- },
- {
- "name": "AreAnyAccessesGranted",
- "address": "0x41c004"
- },
- {
- "name": "LsaLookupPrivilegeName",
- "address": "0x41c008"
- },
- {
- "name": "QueryServiceConfigA",
- "address": "0x41c00c"
- },
- {
- "name": "LookupAccountNameW",
- "address": "0x41c010"
- },
- {
- "name": "SystemFunction031",
- "address": "0x41c014"
- },
- {
- "name": "AllocateAndInitializeSid",
- "address": "0x41c018"
- },
- {
- "name": "RegSaveKeyA",
- "address": "0x41c01c"
- },
- {
- "name": "BuildExplicitAccessWithNameW",
- "address": "0x41c020"
- },
- {
- "name": "CryptEnumProvidersA",
- "address": "0x41c024"
- },
- {
- "name": "AddUsersToEncryptedFile",
- "address": "0x41c028"
- }
- ],
- "dll": "ADVAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "CLSIDFromString",
- "address": "0x41c264"
- },
- {
- "name": "HWND_UserUnmarshal",
- "address": "0x41c268"
- },
- {
- "name": "OleCreateFromData",
- "address": "0x41c26c"
- },
- {
- "name": "CoAddRefServerProcess",
- "address": "0x41c270"
- },
- {
- "name": "ReadClassStg",
- "address": "0x41c274"
- },
- {
- "name": "WriteClassStg",
- "address": "0x41c278"
- }
- ],
- "dll": "ole32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x0007566a",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x00403bf9",
- "timestamp": "2019-06-11 13:23:14",
- "osversion": "5.1",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x0001b000",
- "entropy": "6.69",
- "raw_address": "0x00000400",
- "virtual_size": "0x0001af27",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0001c000",
- "size_of_data": "0x00008c00",
- "entropy": "5.16",
- "raw_address": "0x0001b400",
- "virtual_size": "0x00008b96",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00025000",
- "size_of_data": "0x0000b800",
- "entropy": "6.27",
- "raw_address": "0x00024000",
- "virtual_size": "0x0000c280",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".gfids",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00032000",
- "size_of_data": "0x00000600",
- "entropy": "2.89",
- "raw_address": "0x0002f800",
- "virtual_size": "0x000004b0",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00033000",
- "size_of_data": "0x0003de00",
- "entropy": "6.88",
- "raw_address": "0x0002fe00",
- "virtual_size": "0x0003dcb5",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00071000",
- "size_of_data": "0x00002400",
- "entropy": "6.62",
- "raw_address": "0x0006dc00",
- "virtual_size": "0x00002300",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00023c9c",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x000000a0"
- },
- {
- "virtual_address": "0x00033000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x0003dcb5"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00071000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00002300"
- },
- {
- "virtual_address": "0x00023410",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00023430",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000040"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0001c000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000280"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "f9828a7115467336fc1f5ae8124ddad0",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 7,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement