paladin316

Exes_ce854dd32e1d931cd6a791b30dcd9458_exe.json

Jun 19th, 2019
2,140
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 58.38 KB | None | 0 0
  1.  
  2. [*] MalFamily: ""
  3.  
  4. [*] MalScore: 9.399999999999999
  5.  
  6. [*] File Name: "Exes_ce854dd32e1d931cd6a791b30dcd9458.exe"
  7. [*] File Size: 1345024
  8. [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. [*] SHA256: "ac4daabcc33e6d296965a9e4b5af21fa43e47f49c58da62c420ebb66694b819a"
  10. [*] MD5: "ce854dd32e1d931cd6a791b30dcd9458"
  11. [*] SHA1: "0b247814ee8be3926e0dd64e749d7a4f174f96b7"
  12. [*] SHA512: "12cc6264daa1deaf81d59153f8cb9f9ed5b67dd45d6c954706c4a9052807384395ceb008b082e9bf903493dc9e52769fcf91a8295be9beae95655691a72c7e42"
  13. [*] CRC32: "E8983C06"
  14. [*] SSDEEP: "24576:fLz8dhwdpThXXqJP5JsO569Trwzy7rgUr+ZDgTkIWSk8s9ifWTbY0OXLtzkiphmA:fLYQDUxJ/5iky7rg08DghFsfYJIm8A"
  15.  
  16. [*] Process Execution: [
  17. "Exes_ce854dd32e1d931cd6a791b30dcd9458.exe",
  18. "notepad.exe",
  19. "cmd.exe",
  20. "wscript.exe",
  21. "notepad.exe"
  22. ]
  23.  
  24. [*] Signatures Detected: [
  25. {
  26. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  27. "Details": [
  28. {
  29. "IP": "37.59.162.30:5790"
  30. }
  31. ]
  32. },
  33. {
  34. "Description": "Creates RWX memory",
  35. "Details": []
  36. },
  37. {
  38. "Description": "Detected script timer window indicative of sleep style evasion",
  39. "Details": [
  40. {
  41. "Window": "WSH-Timer"
  42. }
  43. ]
  44. },
  45. {
  46. "Description": "A process attempted to delay the analysis task.",
  47. "Details": [
  48. {
  49. "Process": "Exes_ce854dd32e1d931cd6a791b30dcd9458.exe tried to sleep 293 seconds, actually delayed analysis time by 0 seconds"
  50. }
  51. ]
  52. },
  53. {
  54. "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
  55. "Details": [
  56. {
  57. "ioc": "nvcuda.dll"
  58. },
  59. {
  60. "ioc": "opencl.dll"
  61. },
  62. {
  63. "ioc": "ntdll.dll"
  64. },
  65. {
  66. "ioc": "nicehash.com"
  67. },
  68. {
  69. "ioc": "isassx.exe"
  70. },
  71. {
  72. "ioc": "taskmgr.exe"
  73. },
  74. {
  75. "ioc": "bdagent.exe"
  76. },
  77. {
  78. "ioc": "vsserv.exe"
  79. },
  80. {
  81. "ioc": "cfp.exe"
  82. },
  83. {
  84. "ioc": "ccavsrv.exe"
  85. },
  86. {
  87. "ioc": "cmdagent.exe"
  88. },
  89. {
  90. "ioc": "avp.exe"
  91. },
  92. {
  93. "ioc": "avpui.exe"
  94. },
  95. {
  96. "ioc": "ksde.exe"
  97. },
  98. {
  99. "ioc": "a2guard.exe"
  100. },
  101. {
  102. "ioc": "a2service.exe"
  103. },
  104. {
  105. "ioc": "a2start.exe"
  106. },
  107. {
  108. "ioc": "hell32.dll"
  109. },
  110. {
  111. "ioc": "kernel32.dll"
  112. },
  113. {
  114. "ioc": "csrss.exe"
  115. },
  116. {
  117. "ioc": "winlogon.exe"
  118. },
  119. {
  120. "ioc": "explorer.exe"
  121. },
  122. {
  123. "ioc": "32.dll"
  124. },
  125. {
  126. "ioc": "ole32.dll"
  127. },
  128. {
  129. "ioc": "t.69O2"
  130. },
  131. {
  132. "ioc": "8.x9"
  133. },
  134. {
  135. "ioc": "a.y8"
  136. },
  137. {
  138. "ioc": "c.i7"
  139. },
  140. {
  141. "ioc": "3.5dn"
  142. },
  143. {
  144. "ioc": "p.9f"
  145. },
  146. {
  147. "ioc": "g.f3"
  148. },
  149. {
  150. "ioc": "dd.4c7"
  151. },
  152. {
  153. "ioc": "x2.mb"
  154. },
  155. {
  156. "ioc": "9.r1"
  157. },
  158. {
  159. "ioc": "9.rs"
  160. },
  161. {
  162. "ioc": "s.8.P"
  163. },
  164. {
  165. "ioc": "h.3b"
  166. },
  167. {
  168. "ioc": "p5.xqn"
  169. },
  170. {
  171. "ioc": "2.282B2L2V2"
  172. },
  173. {
  174. "ioc": "6.6n6"
  175. }
  176. ]
  177. },
  178. {
  179. "Description": "Network anomalies occured during the analysis.",
  180. "Details": [
  181. {
  182. "Anomaly": "'37.59.162.30' getaddrinfo with no actual connection to the IP."
  183. }
  184. ]
  185. },
  186. {
  187. "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
  188. "Details": []
  189. },
  190. {
  191. "Description": "Reads data out of its own binary image",
  192. "Details": [
  193. {
  194. "self_read": "process: Exes_ce854dd32e1d931cd6a791b30dcd9458.exe, pid: 1648, offset: 0x00000000, length: 0x00148600"
  195. },
  196. {
  197. "self_read": "process: wscript.exe, pid: 2496, offset: 0x00000000, length: 0x00000040"
  198. },
  199. {
  200. "self_read": "process: wscript.exe, pid: 2496, offset: 0x000000f0, length: 0x00000018"
  201. },
  202. {
  203. "self_read": "process: wscript.exe, pid: 2496, offset: 0x000001e8, length: 0x00000078"
  204. },
  205. {
  206. "self_read": "process: wscript.exe, pid: 2496, offset: 0x00018000, length: 0x00000020"
  207. },
  208. {
  209. "self_read": "process: wscript.exe, pid: 2496, offset: 0x00018058, length: 0x00000018"
  210. },
  211. {
  212. "self_read": "process: wscript.exe, pid: 2496, offset: 0x000181a8, length: 0x00000018"
  213. },
  214. {
  215. "self_read": "process: wscript.exe, pid: 2496, offset: 0x00018470, length: 0x00000010"
  216. },
  217. {
  218. "self_read": "process: wscript.exe, pid: 2496, offset: 0x00018640, length: 0x00000012"
  219. }
  220. ]
  221. },
  222. {
  223. "Description": "A process created a hidden window",
  224. "Details": [
  225. {
  226. "Process": "Exes_ce854dd32e1d931cd6a791b30dcd9458.exe -> cmd.exe /C WScript \"C:\\ProgramData\\iEtHqNVRGt\\r.vbs\""
  227. }
  228. ]
  229. },
  230. {
  231. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  232. "Details": [
  233. {
  234. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  235. },
  236. {
  237. "suspicious_request": "http://37.44.212.223/xdxd.txt"
  238. },
  239. {
  240. "suspicious_request": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D"
  241. },
  242. {
  243. "suspicious_request": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D"
  244. },
  245. {
  246. "suspicious_request": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D"
  247. }
  248. ]
  249. },
  250. {
  251. "Description": "Performs some HTTP requests",
  252. "Details": [
  253. {
  254. "url": "http://37.44.212.223/xdxd.txt"
  255. },
  256. {
  257. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D"
  258. },
  259. {
  260. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D"
  261. },
  262. {
  263. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D"
  264. }
  265. ]
  266. },
  267. {
  268. "Description": "The binary likely contains encrypted or compressed data.",
  269. "Details": [
  270. {
  271. "section": "name: .data, entropy: 7.97, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x0013de00, virtual_size: 0x0013f920"
  272. }
  273. ]
  274. },
  275. {
  276. "Description": "Installs itself for autorun at Windows startup",
  277. "Details": [
  278. {
  279. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\zylUYKzaGy.url"
  280. },
  281. {
  282. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\zylUYKzaGy.url"
  283. }
  284. ]
  285. }
  286. ]
  287.  
  288. [*] Started Service: []
  289.  
  290. [*] Executed Commands: [
  291. "\"C:\\Windows\\notepad.exe\" -c \"C:\\ProgramData\\iEtHqNVRGt\\cfgi\"",
  292. "cmd.exe /C WScript \"C:\\ProgramData\\iEtHqNVRGt\\r.vbs\"",
  293. "\"C:\\Windows\\notepad.exe\" -c \"C:\\ProgramData\\iEtHqNVRGt\\cfg\"",
  294. "C:\\Windows\\system32\\wscript.exe WScript \"C:\\ProgramData\\iEtHqNVRGt\\r.vbs\""
  295. ]
  296.  
  297. [*] Mutexes: [
  298. "4e064bee1f3860fd606a"
  299. ]
  300.  
  301. [*] Modified Files: [
  302. "C:\\ProgramData\\iEtHqNVRGt\\isassx.exe",
  303. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\zylUYKzaGy.url"
  304. ]
  305.  
  306. [*] Deleted Files: [
  307. "C:\\ProgramData\\iEtHqNVRGt\\r.vbs",
  308. "C:\\ProgramData\\iEtHqNVRGt\\isassx.exe",
  309. "C:\\ProgramData\\iEtHqNVRGt\\isassx"
  310. ]
  311.  
  312. [*] Modified Registry Keys: []
  313.  
  314. [*] Deleted Registry Keys: []
  315.  
  316. [*] DNS Communications: []
  317.  
  318. [*] Domains: []
  319.  
  320. [*] Network Communication - ICMP: []
  321.  
  322. [*] Network Communication - HTTP: [
  323. {
  324. "count": 1,
  325. "body": "",
  326. "uri": "http://37.44.212.223/xdxd.txt",
  327. "user-agent": "WinInetGet/0.1",
  328. "method": "GET",
  329. "host": "37.44.212.223",
  330. "version": "1.1",
  331. "path": "/xdxd.txt",
  332. "data": "GET /xdxd.txt HTTP/1.1\r\nAccept: text/*, application/exe, application/zlib, application/gzip, application/applefile\r\nUser-Agent: WinInetGet/0.1\r\nHost: 37.44.212.223\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  333. "port": 80
  334. },
  335. {
  336. "count": 1,
  337. "body": "",
  338. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D",
  339. "user-agent": "Microsoft-CryptoAPI/6.1",
  340. "method": "GET",
  341. "host": "ocsp.digicert.com",
  342. "version": "1.1",
  343. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D",
  344. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D HTTP/1.1\r\nCache-Control: max-age = 150849\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Tue, 28 May 2019 10:50:30 GMT\r\nIf-None-Match: \"5ced1276-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  345. "port": 80
  346. },
  347. {
  348. "count": 1,
  349. "body": "",
  350. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D",
  351. "user-agent": "Microsoft-CryptoAPI/6.1",
  352. "method": "GET",
  353. "host": "ocsp.digicert.com",
  354. "version": "1.1",
  355. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D",
  356. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D HTTP/1.1\r\nCache-Control: max-age = 135176\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Tue, 28 May 2019 05:30:18 GMT\r\nIf-None-Match: \"5cecc76a-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  357. "port": 80
  358. },
  359. {
  360. "count": 1,
  361. "body": "",
  362. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D",
  363. "user-agent": "Microsoft-CryptoAPI/6.1",
  364. "method": "GET",
  365. "host": "ocsp.digicert.com",
  366. "version": "1.1",
  367. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D",
  368. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D HTTP/1.1\r\nCache-Control: max-age = 168744\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Tue, 28 May 2019 15:00:08 GMT\r\nIf-None-Match: \"5ced4cf8-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  369. "port": 80
  370. }
  371. ]
  372.  
  373. [*] Network Communication - SMTP: []
  374.  
  375. [*] Network Communication - Hosts: []
  376.  
  377. [*] Network Communication - IRC: []
  378.  
  379. [*] Static Analysis: {
  380. "pe": {
  381. "peid_signatures": null,
  382. "imports": [
  383. {
  384. "imports": [
  385. {
  386. "name": "HttpSendRequestA",
  387. "address": "0x40911c"
  388. },
  389. {
  390. "name": "HttpOpenRequestA",
  391. "address": "0x409120"
  392. },
  393. {
  394. "name": "InternetSetOptionA",
  395. "address": "0x409124"
  396. },
  397. {
  398. "name": "InternetReadFile",
  399. "address": "0x409128"
  400. },
  401. {
  402. "name": "InternetConnectA",
  403. "address": "0x40912c"
  404. },
  405. {
  406. "name": "InternetCloseHandle",
  407. "address": "0x409130"
  408. },
  409. {
  410. "name": "InternetOpenA",
  411. "address": "0x409134"
  412. },
  413. {
  414. "name": "InternetCrackUrlA",
  415. "address": "0x409138"
  416. },
  417. {
  418. "name": "InternetQueryOptionA",
  419. "address": "0x40913c"
  420. }
  421. ],
  422. "dll": "WININET.dll"
  423. },
  424. {
  425. "imports": [
  426. {
  427. "name": "MultiByteToWideChar",
  428. "address": "0x409038"
  429. },
  430. {
  431. "name": "WideCharToMultiByte",
  432. "address": "0x40903c"
  433. },
  434. {
  435. "name": "FreeLibrary",
  436. "address": "0x409040"
  437. },
  438. {
  439. "name": "GetProcAddress",
  440. "address": "0x409044"
  441. },
  442. {
  443. "name": "LoadLibraryA",
  444. "address": "0x409048"
  445. },
  446. {
  447. "name": "VirtualAlloc",
  448. "address": "0x40904c"
  449. },
  450. {
  451. "name": "VirtualFree",
  452. "address": "0x409050"
  453. },
  454. {
  455. "name": "TerminateThread",
  456. "address": "0x409054"
  457. },
  458. {
  459. "name": "GetExitCodeThread",
  460. "address": "0x409058"
  461. },
  462. {
  463. "name": "Sleep",
  464. "address": "0x40905c"
  465. },
  466. {
  467. "name": "LocalFree",
  468. "address": "0x409060"
  469. },
  470. {
  471. "name": "GetCurrentProcess",
  472. "address": "0x409064"
  473. },
  474. {
  475. "name": "ExitProcess",
  476. "address": "0x409068"
  477. },
  478. {
  479. "name": "CreateThread",
  480. "address": "0x40906c"
  481. },
  482. {
  483. "name": "SetThreadExecutionState",
  484. "address": "0x409070"
  485. },
  486. {
  487. "name": "GetLastError",
  488. "address": "0x409074"
  489. },
  490. {
  491. "name": "SetErrorMode",
  492. "address": "0x409078"
  493. },
  494. {
  495. "name": "GetFileSizeEx",
  496. "address": "0x40907c"
  497. },
  498. {
  499. "name": "GetSystemInfo",
  500. "address": "0x409080"
  501. },
  502. {
  503. "name": "GetTickCount",
  504. "address": "0x409084"
  505. },
  506. {
  507. "name": "CreateMutexA",
  508. "address": "0x409088"
  509. },
  510. {
  511. "name": "GetModuleFileNameW",
  512. "address": "0x40908c"
  513. },
  514. {
  515. "name": "GetProcessHeap",
  516. "address": "0x409090"
  517. },
  518. {
  519. "name": "GetWindowsDirectoryW",
  520. "address": "0x409094"
  521. },
  522. {
  523. "name": "CreateDirectoryW",
  524. "address": "0x409098"
  525. },
  526. {
  527. "name": "TerminateProcess",
  528. "address": "0x40909c"
  529. },
  530. {
  531. "name": "ExitThread",
  532. "address": "0x4090a0"
  533. },
  534. {
  535. "name": "ReadProcessMemory",
  536. "address": "0x4090a4"
  537. },
  538. {
  539. "name": "GetThreadContext",
  540. "address": "0x4090a8"
  541. },
  542. {
  543. "name": "SetThreadContext",
  544. "address": "0x4090ac"
  545. },
  546. {
  547. "name": "HeapFree",
  548. "address": "0x4090b0"
  549. },
  550. {
  551. "name": "CreateProcessW",
  552. "address": "0x4090b4"
  553. },
  554. {
  555. "name": "GetCurrentProcessId",
  556. "address": "0x4090b8"
  557. },
  558. {
  559. "name": "DeleteFileW",
  560. "address": "0x4090bc"
  561. },
  562. {
  563. "name": "MoveFileW",
  564. "address": "0x4090c0"
  565. },
  566. {
  567. "name": "GetLongPathNameW",
  568. "address": "0x4090c4"
  569. },
  570. {
  571. "name": "WaitForSingleObject",
  572. "address": "0x4090c8"
  573. },
  574. {
  575. "name": "GetTempPathW",
  576. "address": "0x4090cc"
  577. },
  578. {
  579. "name": "OpenProcess",
  580. "address": "0x4090d0"
  581. },
  582. {
  583. "name": "GetExitCodeProcess",
  584. "address": "0x4090d4"
  585. },
  586. {
  587. "name": "ReadFile",
  588. "address": "0x4090d8"
  589. },
  590. {
  591. "name": "GetModuleHandleA",
  592. "address": "0x4090dc"
  593. },
  594. {
  595. "name": "GetModuleHandleW",
  596. "address": "0x4090e0"
  597. },
  598. {
  599. "name": "CreateFileW",
  600. "address": "0x4090e4"
  601. },
  602. {
  603. "name": "GetFileAttributesW",
  604. "address": "0x4090e8"
  605. },
  606. {
  607. "name": "CreateToolhelp32Snapshot",
  608. "address": "0x4090ec"
  609. },
  610. {
  611. "name": "Process32First",
  612. "address": "0x4090f0"
  613. },
  614. {
  615. "name": "Process32Next",
  616. "address": "0x4090f4"
  617. },
  618. {
  619. "name": "HeapReAlloc",
  620. "address": "0x4090f8"
  621. },
  622. {
  623. "name": "HeapAlloc",
  624. "address": "0x4090fc"
  625. },
  626. {
  627. "name": "GetCommandLineW",
  628. "address": "0x409100"
  629. },
  630. {
  631. "name": "CloseHandle",
  632. "address": "0x409104"
  633. }
  634. ],
  635. "dll": "KERNEL32.dll"
  636. },
  637. {
  638. "imports": [
  639. {
  640. "name": "GetLastInputInfo",
  641. "address": "0x409114"
  642. }
  643. ],
  644. "dll": "USER32.dll"
  645. },
  646. {
  647. "imports": [
  648. {
  649. "name": "RegOpenKeyExW",
  650. "address": "0x409000"
  651. },
  652. {
  653. "name": "ConvertSidToStringSidW",
  654. "address": "0x409004"
  655. },
  656. {
  657. "name": "CryptDestroyHash",
  658. "address": "0x409008"
  659. },
  660. {
  661. "name": "CryptHashData",
  662. "address": "0x40900c"
  663. },
  664. {
  665. "name": "CryptCreateHash",
  666. "address": "0x409010"
  667. },
  668. {
  669. "name": "CryptGetHashParam",
  670. "address": "0x409014"
  671. },
  672. {
  673. "name": "CryptReleaseContext",
  674. "address": "0x409018"
  675. },
  676. {
  677. "name": "CryptAcquireContextW",
  678. "address": "0x40901c"
  679. },
  680. {
  681. "name": "IsValidSid",
  682. "address": "0x409020"
  683. },
  684. {
  685. "name": "RegSetValueExW",
  686. "address": "0x409024"
  687. },
  688. {
  689. "name": "OpenProcessToken",
  690. "address": "0x409028"
  691. },
  692. {
  693. "name": "GetTokenInformation",
  694. "address": "0x40902c"
  695. },
  696. {
  697. "name": "RegCloseKey",
  698. "address": "0x409030"
  699. }
  700. ],
  701. "dll": "ADVAPI32.dll"
  702. },
  703. {
  704. "imports": [
  705. {
  706. "name": "CommandLineToArgvW",
  707. "address": "0x40910c"
  708. }
  709. ],
  710. "dll": "SHELL32.dll"
  711. },
  712. {
  713. "imports": [
  714. {
  715. "name": "CoTaskMemFree",
  716. "address": "0x409144"
  717. }
  718. ],
  719. "dll": "ole32.dll"
  720. }
  721. ],
  722. "digital_signers": null,
  723. "exported_dll_name": null,
  724. "actual_checksum": "0x00148ad8",
  725. "overlay": null,
  726. "imagebase": "0x00400000",
  727. "reported_checksum": "0x00000000",
  728. "icon_hash": null,
  729. "entrypoint": "0x00404250",
  730. "timestamp": "2019-03-04 01:08:35",
  731. "osversion": "5.1",
  732. "sections": [
  733. {
  734. "name": ".text",
  735. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
  736. "virtual_address": "0x00001000",
  737. "size_of_data": "0x00007c00",
  738. "entropy": "6.23",
  739. "raw_address": "0x00000400",
  740. "virtual_size": "0x00007b44",
  741. "characteristics_raw": "0x60000020"
  742. },
  743. {
  744. "name": ".rdata",
  745. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  746. "virtual_address": "0x00009000",
  747. "size_of_data": "0x00002000",
  748. "entropy": "5.22",
  749. "raw_address": "0x00008000",
  750. "virtual_size": "0x00001fbc",
  751. "characteristics_raw": "0x40000040"
  752. },
  753. {
  754. "name": ".data",
  755. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  756. "virtual_address": "0x0000b000",
  757. "size_of_data": "0x0013de00",
  758. "entropy": "7.97",
  759. "raw_address": "0x0000a000",
  760. "virtual_size": "0x0013f920",
  761. "characteristics_raw": "0xc0000040"
  762. },
  763. {
  764. "name": ".reloc",
  765. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
  766. "virtual_address": "0x0014b000",
  767. "size_of_data": "0x00000800",
  768. "entropy": "6.61",
  769. "raw_address": "0x00147e00",
  770. "virtual_size": "0x000007b8",
  771. "characteristics_raw": "0x42000040"
  772. }
  773. ],
  774. "resources": [],
  775. "dirents": [
  776. {
  777. "virtual_address": "0x00000000",
  778. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  779. "size": "0x00000000"
  780. },
  781. {
  782. "virtual_address": "0x0000a820",
  783. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  784. "size": "0x0000008c"
  785. },
  786. {
  787. "virtual_address": "0x00000000",
  788. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  789. "size": "0x00000000"
  790. },
  791. {
  792. "virtual_address": "0x00000000",
  793. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  794. "size": "0x00000000"
  795. },
  796. {
  797. "virtual_address": "0x00000000",
  798. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  799. "size": "0x00000000"
  800. },
  801. {
  802. "virtual_address": "0x0014b000",
  803. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  804. "size": "0x000007b8"
  805. },
  806. {
  807. "virtual_address": "0x0000a740",
  808. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  809. "size": "0x0000001c"
  810. },
  811. {
  812. "virtual_address": "0x00000000",
  813. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  814. "size": "0x00000000"
  815. },
  816. {
  817. "virtual_address": "0x00000000",
  818. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  819. "size": "0x00000000"
  820. },
  821. {
  822. "virtual_address": "0x00000000",
  823. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  824. "size": "0x00000000"
  825. },
  826. {
  827. "virtual_address": "0x00000000",
  828. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  829. "size": "0x00000000"
  830. },
  831. {
  832. "virtual_address": "0x00000000",
  833. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  834. "size": "0x00000000"
  835. },
  836. {
  837. "virtual_address": "0x00009000",
  838. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  839. "size": "0x00000150"
  840. },
  841. {
  842. "virtual_address": "0x00000000",
  843. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  844. "size": "0x00000000"
  845. },
  846. {
  847. "virtual_address": "0x00000000",
  848. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  849. "size": "0x00000000"
  850. },
  851. {
  852. "virtual_address": "0x00000000",
  853. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  854. "size": "0x00000000"
  855. }
  856. ],
  857. "exports": [],
  858. "guest_signers": {},
  859. "imphash": "ded6c839e7f7258224ae021602258361",
  860. "icon_fuzzy": null,
  861. "icon": null,
  862. "pdbpath": null,
  863. "imported_dll_count": 6,
  864. "versioninfo": []
  865. }
  866. }
  867.  
  868. [*] Resolved APIs: [
  869. "kernel32.dll.IsWow64Process",
  870. "ntdll.dll.RtlGetVersion",
  871. "cryptsp.dll.CryptAcquireContextW",
  872. "cryptsp.dll.CryptCreateHash",
  873. "cryptsp.dll.CryptHashData",
  874. "cryptsp.dll.CryptGetHashParam",
  875. "cryptsp.dll.CryptDestroyHash",
  876. "cryptsp.dll.CryptReleaseContext",
  877. "shell32.dll.SHGetKnownFolderPath",
  878. "rasapi32.dll.RasConnectionNotificationW",
  879. "sechost.dll.NotifyServiceStatusChangeA",
  880. "cryptbase.dll.SystemFunction036",
  881. "kernel32.dll.AddVectoredExceptionHandler",
  882. "kernel32.dll.AssignProcessToJobObject",
  883. "kernel32.dll.CancelIo",
  884. "kernel32.dll.CloseHandle",
  885. "kernel32.dll.ConnectNamedPipe",
  886. "kernel32.dll.CopyFileW",
  887. "kernel32.dll.CreateDirectoryW",
  888. "kernel32.dll.CreateEventA",
  889. "kernel32.dll.CreateFileA",
  890. "kernel32.dll.CreateFileW",
  891. "kernel32.dll.CreateHardLinkW",
  892. "kernel32.dll.CreateIoCompletionPort",
  893. "kernel32.dll.CreateJobObjectW",
  894. "kernel32.dll.CreateNamedPipeA",
  895. "kernel32.dll.CreateNamedPipeW",
  896. "kernel32.dll.CreateProcessW",
  897. "kernel32.dll.CreateSemaphoreA",
  898. "kernel32.dll.CreateSemaphoreW",
  899. "kernel32.dll.CreateToolhelp32Snapshot",
  900. "kernel32.dll.DebugBreak",
  901. "kernel32.dll.DeleteCriticalSection",
  902. "kernel32.dll.DeviceIoControl",
  903. "kernel32.dll.DuplicateHandle",
  904. "kernel32.dll.EnterCriticalSection",
  905. "kernel32.dll.FileTimeToSystemTime",
  906. "kernel32.dll.FillConsoleOutputAttribute",
  907. "kernel32.dll.FillConsoleOutputCharacterW",
  908. "kernel32.dll.FlushFileBuffers",
  909. "kernel32.dll.FlushInstructionCache",
  910. "kernel32.dll.FormatMessageA",
  911. "kernel32.dll.FreeConsole",
  912. "kernel32.dll.GetConsoleCursorInfo",
  913. "kernel32.dll.GetConsoleMode",
  914. "kernel32.dll.GetConsoleScreenBufferInfo",
  915. "kernel32.dll.GetConsoleTitleW",
  916. "kernel32.dll.GetConsoleWindow",
  917. "kernel32.dll.GetCurrentDirectoryW",
  918. "kernel32.dll.GetCurrentProcess",
  919. "kernel32.dll.GetCurrentProcessId",
  920. "kernel32.dll.GetCurrentThread",
  921. "kernel32.dll.GetCurrentThreadId",
  922. "kernel32.dll.GetEnvironmentVariableW",
  923. "kernel32.dll.GetExitCodeProcess",
  924. "kernel32.dll.GetFileAttributesW",
  925. "kernel32.dll.GetFileInformationByHandle",
  926. "kernel32.dll.GetFileSizeEx",
  927. "kernel32.dll.GetFileType",
  928. "kernel32.dll.GetHandleInformation",
  929. "kernel32.dll.GetLastError",
  930. "kernel32.dll.GetLongPathNameW",
  931. "kernel32.dll.GetModuleFileNameW",
  932. "kernel32.dll.GetModuleHandleA",
  933. "kernel32.dll.GetModuleHandleW",
  934. "kernel32.dll.GetNamedPipeHandleStateA",
  935. "kernel32.dll.GetNumberOfConsoleInputEvents",
  936. "kernel32.dll.GetProcAddress",
  937. "kernel32.dll.GetProcessAffinityMask",
  938. "kernel32.dll.GetProcessIoCounters",
  939. "kernel32.dll.GetProcessTimes",
  940. "kernel32.dll.GetQueuedCompletionStatus",
  941. "kernel32.dll.GetShortPathNameW",
  942. "kernel32.dll.GetStartupInfoA",
  943. "kernel32.dll.GetStartupInfoW",
  944. "kernel32.dll.GetStdHandle",
  945. "kernel32.dll.GetSystemInfo",
  946. "kernel32.dll.GetSystemTimeAdjustment",
  947. "kernel32.dll.GetSystemTimeAsFileTime",
  948. "kernel32.dll.GetTempPathW",
  949. "kernel32.dll.GetThreadContext",
  950. "kernel32.dll.GetThreadPriority",
  951. "kernel32.dll.GetThreadTimes",
  952. "kernel32.dll.GetTickCount",
  953. "kernel32.dll.GlobalMemoryStatusEx",
  954. "kernel32.dll.InitializeCriticalSection",
  955. "kernel32.dll.IsDBCSLeadByteEx",
  956. "kernel32.dll.IsDebuggerPresent",
  957. "kernel32.dll.LCMapStringW",
  958. "kernel32.dll.LeaveCriticalSection",
  959. "kernel32.dll.LoadLibraryA",
  960. "kernel32.dll.LocalAlloc",
  961. "kernel32.dll.LocalFree",
  962. "kernel32.dll.MoveFileExW",
  963. "kernel32.dll.MultiByteToWideChar",
  964. "kernel32.dll.OpenProcess",
  965. "kernel32.dll.OutputDebugStringA",
  966. "kernel32.dll.PeekNamedPipe",
  967. "kernel32.dll.PostQueuedCompletionStatus",
  968. "kernel32.dll.Process32First",
  969. "kernel32.dll.Process32Next",
  970. "kernel32.dll.QueryPerformanceCounter",
  971. "kernel32.dll.QueryPerformanceFrequency",
  972. "kernel32.dll.QueueUserWorkItem",
  973. "kernel32.dll.RaiseException",
  974. "kernel32.dll.ReadConsoleInputW",
  975. "kernel32.dll.ReadConsoleW",
  976. "kernel32.dll.ReadDirectoryChangesW",
  977. "kernel32.dll.ReadFile",
  978. "kernel32.dll.RegisterWaitForSingleObject",
  979. "kernel32.dll.ReleaseSemaphore",
  980. "kernel32.dll.RemoveDirectoryW",
  981. "kernel32.dll.RemoveVectoredExceptionHandler",
  982. "kernel32.dll.ResetEvent",
  983. "kernel32.dll.ResumeThread",
  984. "kernel32.dll.RtlAddFunctionTable",
  985. "kernel32.dll.RtlCaptureContext",
  986. "kernel32.dll.RtlLookupFunctionEntry",
  987. "kernel32.dll.RtlUnwindEx",
  988. "kernel32.dll.RtlVirtualUnwind",
  989. "kernel32.dll.SetConsoleCtrlHandler",
  990. "kernel32.dll.SetConsoleCursorInfo",
  991. "kernel32.dll.SetConsoleCursorPosition",
  992. "kernel32.dll.SetConsoleMode",
  993. "kernel32.dll.SetConsoleTextAttribute",
  994. "kernel32.dll.SetConsoleTitleW",
  995. "kernel32.dll.SetCurrentDirectoryW",
  996. "kernel32.dll.SetEnvironmentVariableW",
  997. "kernel32.dll.SetErrorMode",
  998. "kernel32.dll.SetEvent",
  999. "kernel32.dll.SetFilePointerEx",
  1000. "kernel32.dll.SetFileTime",
  1001. "kernel32.dll.SetHandleInformation",
  1002. "kernel32.dll.SetInformationJobObject",
  1003. "kernel32.dll.SetLastError",
  1004. "kernel32.dll.SetNamedPipeHandleState",
  1005. "kernel32.dll.SetPriorityClass",
  1006. "kernel32.dll.SetProcessAffinityMask",
  1007. "kernel32.dll.SetSystemTime",
  1008. "kernel32.dll.SetThreadAffinityMask",
  1009. "kernel32.dll.SetThreadContext",
  1010. "kernel32.dll.SetThreadPriority",
  1011. "kernel32.dll.SetUnhandledExceptionFilter",
  1012. "kernel32.dll.Sleep",
  1013. "kernel32.dll.SuspendThread",
  1014. "kernel32.dll.SwitchToThread",
  1015. "kernel32.dll.TerminateProcess",
  1016. "kernel32.dll.TlsAlloc",
  1017. "kernel32.dll.TlsFree",
  1018. "kernel32.dll.TlsGetValue",
  1019. "kernel32.dll.TlsSetValue",
  1020. "kernel32.dll.TryEnterCriticalSection",
  1021. "kernel32.dll.UnhandledExceptionFilter",
  1022. "kernel32.dll.UnregisterWait",
  1023. "kernel32.dll.UnregisterWaitEx",
  1024. "kernel32.dll.VerSetConditionMask",
  1025. "kernel32.dll.VerifyVersionInfoA",
  1026. "kernel32.dll.VirtualAlloc",
  1027. "kernel32.dll.VirtualFree",
  1028. "kernel32.dll.VirtualProtect",
  1029. "kernel32.dll.VirtualQuery",
  1030. "kernel32.dll.WaitForMultipleObjects",
  1031. "kernel32.dll.WaitForSingleObject",
  1032. "kernel32.dll.WaitNamedPipeW",
  1033. "kernel32.dll.WideCharToMultiByte",
  1034. "kernel32.dll.WriteConsoleInputW",
  1035. "kernel32.dll.WriteConsoleW",
  1036. "kernel32.dll.WriteFile",
  1037. "kernel32.dll.__C_specific_handler",
  1038. "advapi32.dll.AdjustTokenPrivileges",
  1039. "advapi32.dll.AllocateAndInitializeSid",
  1040. "advapi32.dll.CryptAcquireContextA",
  1041. "advapi32.dll.CryptGenRandom",
  1042. "advapi32.dll.CryptReleaseContext",
  1043. "advapi32.dll.FreeSid",
  1044. "advapi32.dll.GetSecurityInfo",
  1045. "advapi32.dll.GetTokenInformation",
  1046. "advapi32.dll.GetUserNameW",
  1047. "advapi32.dll.LookupPrivilegeValueW",
  1048. "advapi32.dll.LsaAddAccountRights",
  1049. "advapi32.dll.LsaClose",
  1050. "advapi32.dll.LsaOpenPolicy",
  1051. "advapi32.dll.OpenProcessToken",
  1052. "advapi32.dll.RegCloseKey",
  1053. "advapi32.dll.RegOpenKeyExW",
  1054. "advapi32.dll.RegQueryValueExW",
  1055. "advapi32.dll.SetEntriesInAclA",
  1056. "advapi32.dll.SetSecurityInfo",
  1057. "iphlpapi.dll.GetAdaptersAddresses",
  1058. "msvcrt.dll.___lc_codepage_func",
  1059. "msvcrt.dll.___mb_cur_max_func",
  1060. "msvcrt.dll.__argv",
  1061. "msvcrt.dll.__doserrno",
  1062. "msvcrt.dll.__getmainargs",
  1063. "msvcrt.dll.__initenv",
  1064. "msvcrt.dll.__iob_func",
  1065. "msvcrt.dll.__lconv_init",
  1066. "msvcrt.dll.__set_app_type",
  1067. "msvcrt.dll.__setusermatherr",
  1068. "msvcrt.dll._acmdln",
  1069. "msvcrt.dll._amsg_exit",
  1070. "msvcrt.dll._beginthreadex",
  1071. "msvcrt.dll._cexit",
  1072. "msvcrt.dll._close",
  1073. "msvcrt.dll._endthreadex",
  1074. "msvcrt.dll._errno",
  1075. "msvcrt.dll._exit",
  1076. "msvcrt.dll._fdopen",
  1077. "msvcrt.dll._fileno",
  1078. "msvcrt.dll._fmode",
  1079. "msvcrt.dll._fstat64",
  1080. "msvcrt.dll._get_osfhandle",
  1081. "msvcrt.dll._initterm",
  1082. "msvcrt.dll._localtime64",
  1083. "msvcrt.dll._lock",
  1084. "msvcrt.dll._lseeki64",
  1085. "msvcrt.dll._onexit",
  1086. "msvcrt.dll._open_osfhandle",
  1087. "msvcrt.dll._read",
  1088. "msvcrt.dll._setjmp",
  1089. "msvcrt.dll._snwprintf",
  1090. "msvcrt.dll._strdup",
  1091. "msvcrt.dll._stricmp",
  1092. "msvcrt.dll._strnicmp",
  1093. "msvcrt.dll._time64",
  1094. "msvcrt.dll._ultoa",
  1095. "msvcrt.dll._umask",
  1096. "msvcrt.dll._unlock",
  1097. "msvcrt.dll._vsnprintf",
  1098. "msvcrt.dll._wchmod",
  1099. "msvcrt.dll._wcsdup",
  1100. "msvcrt.dll._wcsnicmp",
  1101. "msvcrt.dll._wcsrev",
  1102. "msvcrt.dll._wfopen",
  1103. "msvcrt.dll._wmkdir",
  1104. "msvcrt.dll._wopen",
  1105. "msvcrt.dll._write",
  1106. "msvcrt.dll._wrmdir",
  1107. "msvcrt.dll.abort",
  1108. "msvcrt.dll.atoi",
  1109. "msvcrt.dll.calloc",
  1110. "msvcrt.dll.exit",
  1111. "msvcrt.dll.fclose",
  1112. "msvcrt.dll.fflush",
  1113. "msvcrt.dll.fopen",
  1114. "msvcrt.dll.fprintf",
  1115. "msvcrt.dll.fputc",
  1116. "msvcrt.dll.fputs",
  1117. "msvcrt.dll.fread",
  1118. "msvcrt.dll.free",
  1119. "msvcrt.dll.fwprintf",
  1120. "msvcrt.dll.fwrite",
  1121. "msvcrt.dll.getenv",
  1122. "msvcrt.dll.islower",
  1123. "msvcrt.dll.isspace",
  1124. "msvcrt.dll.isupper",
  1125. "msvcrt.dll.iswctype",
  1126. "msvcrt.dll.localeconv",
  1127. "msvcrt.dll.longjmp",
  1128. "msvcrt.dll.malloc",
  1129. "msvcrt.dll.memchr",
  1130. "msvcrt.dll.memcmp",
  1131. "msvcrt.dll.memcpy",
  1132. "msvcrt.dll.memmove",
  1133. "msvcrt.dll.memset",
  1134. "msvcrt.dll.printf",
  1135. "msvcrt.dll.qsort",
  1136. "msvcrt.dll.raise",
  1137. "msvcrt.dll.rand",
  1138. "msvcrt.dll.realloc",
  1139. "msvcrt.dll.setlocale",
  1140. "msvcrt.dll.setvbuf",
  1141. "msvcrt.dll.signal",
  1142. "msvcrt.dll.sprintf",
  1143. "msvcrt.dll.srand",
  1144. "msvcrt.dll.strchr",
  1145. "msvcrt.dll.strcmp",
  1146. "msvcrt.dll.strcoll",
  1147. "msvcrt.dll.strcpy",
  1148. "msvcrt.dll.strerror",
  1149. "msvcrt.dll.strftime",
  1150. "msvcrt.dll.strlen",
  1151. "msvcrt.dll.strncmp",
  1152. "msvcrt.dll.strncpy",
  1153. "msvcrt.dll.strrchr",
  1154. "msvcrt.dll.strstr",
  1155. "msvcrt.dll.strtol",
  1156. "msvcrt.dll.strtoul",
  1157. "msvcrt.dll.strxfrm",
  1158. "msvcrt.dll.towlower",
  1159. "msvcrt.dll.towupper",
  1160. "msvcrt.dll.vfprintf",
  1161. "msvcrt.dll.wcschr",
  1162. "msvcrt.dll.wcscoll",
  1163. "msvcrt.dll.wcscpy",
  1164. "msvcrt.dll.wcsftime",
  1165. "msvcrt.dll.wcslen",
  1166. "msvcrt.dll.wcsncmp",
  1167. "msvcrt.dll.wcsncpy",
  1168. "msvcrt.dll.wcspbrk",
  1169. "msvcrt.dll.wcsrchr",
  1170. "msvcrt.dll.wcstombs",
  1171. "msvcrt.dll.wcsxfrm",
  1172. "psapi.dll.GetProcessMemoryInfo",
  1173. "user32.dll.DispatchMessageA",
  1174. "user32.dll.GetMessageA",
  1175. "user32.dll.MapVirtualKeyW",
  1176. "user32.dll.MessageBoxW",
  1177. "user32.dll.ShowWindow",
  1178. "user32.dll.TranslateMessage",
  1179. "userenv.dll.GetUserProfileDirectoryW",
  1180. "ws2_32.dll.FreeAddrInfoW",
  1181. "ws2_32.dll.GetAddrInfoW",
  1182. "ws2_32.dll.WSADuplicateSocketW",
  1183. "ws2_32.dll.WSAGetLastError",
  1184. "ws2_32.dll.WSAIoctl",
  1185. "ws2_32.dll.WSARecv",
  1186. "ws2_32.dll.WSARecvFrom",
  1187. "ws2_32.dll.WSASend",
  1188. "ws2_32.dll.WSASendTo",
  1189. "ws2_32.dll.WSASetLastError",
  1190. "ws2_32.dll.WSASocketW",
  1191. "ws2_32.dll.WSAStartup",
  1192. "ws2_32.dll.bind",
  1193. "ws2_32.dll.closesocket",
  1194. "ws2_32.dll.gethostname",
  1195. "ws2_32.dll.getpeername",
  1196. "ws2_32.dll.getsockname",
  1197. "ws2_32.dll.getsockopt",
  1198. "ws2_32.dll.htonl",
  1199. "ws2_32.dll.htons",
  1200. "ws2_32.dll.ioctlsocket",
  1201. "ws2_32.dll.listen",
  1202. "ws2_32.dll.select",
  1203. "ws2_32.dll.setsockopt",
  1204. "ws2_32.dll.shutdown",
  1205. "ws2_32.dll.socket",
  1206. "ntdll.dll.RtlNtStatusToDosError",
  1207. "ntdll.dll.NtDeviceIoControlFile",
  1208. "ntdll.dll.NtQueryInformationFile",
  1209. "ntdll.dll.NtSetInformationFile",
  1210. "ntdll.dll.NtQueryVolumeInformationFile",
  1211. "ntdll.dll.NtQueryDirectoryFile",
  1212. "ntdll.dll.NtQuerySystemInformation",
  1213. "kernel32.dll.GetQueuedCompletionStatusEx",
  1214. "kernel32.dll.SetFileCompletionNotificationModes",
  1215. "kernel32.dll.CreateSymbolicLinkW",
  1216. "kernel32.dll.CancelIoEx",
  1217. "kernel32.dll.InitializeConditionVariable",
  1218. "kernel32.dll.SleepConditionVariableCS",
  1219. "kernel32.dll.SleepConditionVariableSRW",
  1220. "kernel32.dll.WakeAllConditionVariable",
  1221. "kernel32.dll.WakeConditionVariable",
  1222. "kernel32.dll.CancelSynchronousIo",
  1223. "kernel32.dll.GetFinalPathNameByHandleW",
  1224. "user32.dll.SetWinEventHook",
  1225. "iphlpapi.dll.ConvertInterfaceIndexToLuid",
  1226. "iphlpapi.dll.ConvertInterfaceLuidToNameW",
  1227. "msvcrt.dll._localtime64_s",
  1228. "kernel32.dll.SetThreadUILanguage",
  1229. "kernel32.dll.CopyFileExW",
  1230. "kernel32.dll.SetConsoleInputExeNameW",
  1231. "kernel32.dll.SortGetHandle",
  1232. "kernel32.dll.SortCloseHandle",
  1233. "uxtheme.dll.ThemeInitApiHook",
  1234. "user32.dll.IsProcessDPIAware",
  1235. "sechost.dll.LookupAccountNameLocalW",
  1236. "advapi32.dll.LookupAccountSidW",
  1237. "sechost.dll.LookupAccountSidLocalW",
  1238. "kernel32.dll.HeapSetInformation",
  1239. "sxs.dll.SxsOleAut32MapConfiguredClsidToReferenceClsid",
  1240. "dwmapi.dll.DwmIsCompositionEnabled",
  1241. "ole32.dll.CoCreateInstance",
  1242. "advapi32.dll.SaferIdentifyLevel",
  1243. "advapi32.dll.SaferComputeTokenFromLevel",
  1244. "advapi32.dll.SaferCloseLevel",
  1245. "ole32.dll.CLSIDFromProgIDEx",
  1246. "ole32.dll.CoGetClassObject",
  1247. "oleaut32.dll.#500"
  1248. ]
  1249.  
  1250. [*] Static Analysis: {
  1251. "pe": {
  1252. "peid_signatures": null,
  1253. "imports": [
  1254. {
  1255. "imports": [
  1256. {
  1257. "name": "HttpSendRequestA",
  1258. "address": "0x40911c"
  1259. },
  1260. {
  1261. "name": "HttpOpenRequestA",
  1262. "address": "0x409120"
  1263. },
  1264. {
  1265. "name": "InternetSetOptionA",
  1266. "address": "0x409124"
  1267. },
  1268. {
  1269. "name": "InternetReadFile",
  1270. "address": "0x409128"
  1271. },
  1272. {
  1273. "name": "InternetConnectA",
  1274. "address": "0x40912c"
  1275. },
  1276. {
  1277. "name": "InternetCloseHandle",
  1278. "address": "0x409130"
  1279. },
  1280. {
  1281. "name": "InternetOpenA",
  1282. "address": "0x409134"
  1283. },
  1284. {
  1285. "name": "InternetCrackUrlA",
  1286. "address": "0x409138"
  1287. },
  1288. {
  1289. "name": "InternetQueryOptionA",
  1290. "address": "0x40913c"
  1291. }
  1292. ],
  1293. "dll": "WININET.dll"
  1294. },
  1295. {
  1296. "imports": [
  1297. {
  1298. "name": "MultiByteToWideChar",
  1299. "address": "0x409038"
  1300. },
  1301. {
  1302. "name": "WideCharToMultiByte",
  1303. "address": "0x40903c"
  1304. },
  1305. {
  1306. "name": "FreeLibrary",
  1307. "address": "0x409040"
  1308. },
  1309. {
  1310. "name": "GetProcAddress",
  1311. "address": "0x409044"
  1312. },
  1313. {
  1314. "name": "LoadLibraryA",
  1315. "address": "0x409048"
  1316. },
  1317. {
  1318. "name": "VirtualAlloc",
  1319. "address": "0x40904c"
  1320. },
  1321. {
  1322. "name": "VirtualFree",
  1323. "address": "0x409050"
  1324. },
  1325. {
  1326. "name": "TerminateThread",
  1327. "address": "0x409054"
  1328. },
  1329. {
  1330. "name": "GetExitCodeThread",
  1331. "address": "0x409058"
  1332. },
  1333. {
  1334. "name": "Sleep",
  1335. "address": "0x40905c"
  1336. },
  1337. {
  1338. "name": "LocalFree",
  1339. "address": "0x409060"
  1340. },
  1341. {
  1342. "name": "GetCurrentProcess",
  1343. "address": "0x409064"
  1344. },
  1345. {
  1346. "name": "ExitProcess",
  1347. "address": "0x409068"
  1348. },
  1349. {
  1350. "name": "CreateThread",
  1351. "address": "0x40906c"
  1352. },
  1353. {
  1354. "name": "SetThreadExecutionState",
  1355. "address": "0x409070"
  1356. },
  1357. {
  1358. "name": "GetLastError",
  1359. "address": "0x409074"
  1360. },
  1361. {
  1362. "name": "SetErrorMode",
  1363. "address": "0x409078"
  1364. },
  1365. {
  1366. "name": "GetFileSizeEx",
  1367. "address": "0x40907c"
  1368. },
  1369. {
  1370. "name": "GetSystemInfo",
  1371. "address": "0x409080"
  1372. },
  1373. {
  1374. "name": "GetTickCount",
  1375. "address": "0x409084"
  1376. },
  1377. {
  1378. "name": "CreateMutexA",
  1379. "address": "0x409088"
  1380. },
  1381. {
  1382. "name": "GetModuleFileNameW",
  1383. "address": "0x40908c"
  1384. },
  1385. {
  1386. "name": "GetProcessHeap",
  1387. "address": "0x409090"
  1388. },
  1389. {
  1390. "name": "GetWindowsDirectoryW",
  1391. "address": "0x409094"
  1392. },
  1393. {
  1394. "name": "CreateDirectoryW",
  1395. "address": "0x409098"
  1396. },
  1397. {
  1398. "name": "TerminateProcess",
  1399. "address": "0x40909c"
  1400. },
  1401. {
  1402. "name": "ExitThread",
  1403. "address": "0x4090a0"
  1404. },
  1405. {
  1406. "name": "ReadProcessMemory",
  1407. "address": "0x4090a4"
  1408. },
  1409. {
  1410. "name": "GetThreadContext",
  1411. "address": "0x4090a8"
  1412. },
  1413. {
  1414. "name": "SetThreadContext",
  1415. "address": "0x4090ac"
  1416. },
  1417. {
  1418. "name": "HeapFree",
  1419. "address": "0x4090b0"
  1420. },
  1421. {
  1422. "name": "CreateProcessW",
  1423. "address": "0x4090b4"
  1424. },
  1425. {
  1426. "name": "GetCurrentProcessId",
  1427. "address": "0x4090b8"
  1428. },
  1429. {
  1430. "name": "DeleteFileW",
  1431. "address": "0x4090bc"
  1432. },
  1433. {
  1434. "name": "MoveFileW",
  1435. "address": "0x4090c0"
  1436. },
  1437. {
  1438. "name": "GetLongPathNameW",
  1439. "address": "0x4090c4"
  1440. },
  1441. {
  1442. "name": "WaitForSingleObject",
  1443. "address": "0x4090c8"
  1444. },
  1445. {
  1446. "name": "GetTempPathW",
  1447. "address": "0x4090cc"
  1448. },
  1449. {
  1450. "name": "OpenProcess",
  1451. "address": "0x4090d0"
  1452. },
  1453. {
  1454. "name": "GetExitCodeProcess",
  1455. "address": "0x4090d4"
  1456. },
  1457. {
  1458. "name": "ReadFile",
  1459. "address": "0x4090d8"
  1460. },
  1461. {
  1462. "name": "GetModuleHandleA",
  1463. "address": "0x4090dc"
  1464. },
  1465. {
  1466. "name": "GetModuleHandleW",
  1467. "address": "0x4090e0"
  1468. },
  1469. {
  1470. "name": "CreateFileW",
  1471. "address": "0x4090e4"
  1472. },
  1473. {
  1474. "name": "GetFileAttributesW",
  1475. "address": "0x4090e8"
  1476. },
  1477. {
  1478. "name": "CreateToolhelp32Snapshot",
  1479. "address": "0x4090ec"
  1480. },
  1481. {
  1482. "name": "Process32First",
  1483. "address": "0x4090f0"
  1484. },
  1485. {
  1486. "name": "Process32Next",
  1487. "address": "0x4090f4"
  1488. },
  1489. {
  1490. "name": "HeapReAlloc",
  1491. "address": "0x4090f8"
  1492. },
  1493. {
  1494. "name": "HeapAlloc",
  1495. "address": "0x4090fc"
  1496. },
  1497. {
  1498. "name": "GetCommandLineW",
  1499. "address": "0x409100"
  1500. },
  1501. {
  1502. "name": "CloseHandle",
  1503. "address": "0x409104"
  1504. }
  1505. ],
  1506. "dll": "KERNEL32.dll"
  1507. },
  1508. {
  1509. "imports": [
  1510. {
  1511. "name": "GetLastInputInfo",
  1512. "address": "0x409114"
  1513. }
  1514. ],
  1515. "dll": "USER32.dll"
  1516. },
  1517. {
  1518. "imports": [
  1519. {
  1520. "name": "RegOpenKeyExW",
  1521. "address": "0x409000"
  1522. },
  1523. {
  1524. "name": "ConvertSidToStringSidW",
  1525. "address": "0x409004"
  1526. },
  1527. {
  1528. "name": "CryptDestroyHash",
  1529. "address": "0x409008"
  1530. },
  1531. {
  1532. "name": "CryptHashData",
  1533. "address": "0x40900c"
  1534. },
  1535. {
  1536. "name": "CryptCreateHash",
  1537. "address": "0x409010"
  1538. },
  1539. {
  1540. "name": "CryptGetHashParam",
  1541. "address": "0x409014"
  1542. },
  1543. {
  1544. "name": "CryptReleaseContext",
  1545. "address": "0x409018"
  1546. },
  1547. {
  1548. "name": "CryptAcquireContextW",
  1549. "address": "0x40901c"
  1550. },
  1551. {
  1552. "name": "IsValidSid",
  1553. "address": "0x409020"
  1554. },
  1555. {
  1556. "name": "RegSetValueExW",
  1557. "address": "0x409024"
  1558. },
  1559. {
  1560. "name": "OpenProcessToken",
  1561. "address": "0x409028"
  1562. },
  1563. {
  1564. "name": "GetTokenInformation",
  1565. "address": "0x40902c"
  1566. },
  1567. {
  1568. "name": "RegCloseKey",
  1569. "address": "0x409030"
  1570. }
  1571. ],
  1572. "dll": "ADVAPI32.dll"
  1573. },
  1574. {
  1575. "imports": [
  1576. {
  1577. "name": "CommandLineToArgvW",
  1578. "address": "0x40910c"
  1579. }
  1580. ],
  1581. "dll": "SHELL32.dll"
  1582. },
  1583. {
  1584. "imports": [
  1585. {
  1586. "name": "CoTaskMemFree",
  1587. "address": "0x409144"
  1588. }
  1589. ],
  1590. "dll": "ole32.dll"
  1591. }
  1592. ],
  1593. "digital_signers": null,
  1594. "exported_dll_name": null,
  1595. "actual_checksum": "0x00148ad8",
  1596. "overlay": null,
  1597. "imagebase": "0x00400000",
  1598. "reported_checksum": "0x00000000",
  1599. "icon_hash": null,
  1600. "entrypoint": "0x00404250",
  1601. "timestamp": "2019-03-04 01:08:35",
  1602. "osversion": "5.1",
  1603. "sections": [
  1604. {
  1605. "name": ".text",
  1606. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
  1607. "virtual_address": "0x00001000",
  1608. "size_of_data": "0x00007c00",
  1609. "entropy": "6.23",
  1610. "raw_address": "0x00000400",
  1611. "virtual_size": "0x00007b44",
  1612. "characteristics_raw": "0x60000020"
  1613. },
  1614. {
  1615. "name": ".rdata",
  1616. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  1617. "virtual_address": "0x00009000",
  1618. "size_of_data": "0x00002000",
  1619. "entropy": "5.22",
  1620. "raw_address": "0x00008000",
  1621. "virtual_size": "0x00001fbc",
  1622. "characteristics_raw": "0x40000040"
  1623. },
  1624. {
  1625. "name": ".data",
  1626. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  1627. "virtual_address": "0x0000b000",
  1628. "size_of_data": "0x0013de00",
  1629. "entropy": "7.97",
  1630. "raw_address": "0x0000a000",
  1631. "virtual_size": "0x0013f920",
  1632. "characteristics_raw": "0xc0000040"
  1633. },
  1634. {
  1635. "name": ".reloc",
  1636. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
  1637. "virtual_address": "0x0014b000",
  1638. "size_of_data": "0x00000800",
  1639. "entropy": "6.61",
  1640. "raw_address": "0x00147e00",
  1641. "virtual_size": "0x000007b8",
  1642. "characteristics_raw": "0x42000040"
  1643. }
  1644. ],
  1645. "resources": [],
  1646. "dirents": [
  1647. {
  1648. "virtual_address": "0x00000000",
  1649. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  1650. "size": "0x00000000"
  1651. },
  1652. {
  1653. "virtual_address": "0x0000a820",
  1654. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  1655. "size": "0x0000008c"
  1656. },
  1657. {
  1658. "virtual_address": "0x00000000",
  1659. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  1660. "size": "0x00000000"
  1661. },
  1662. {
  1663. "virtual_address": "0x00000000",
  1664. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  1665. "size": "0x00000000"
  1666. },
  1667. {
  1668. "virtual_address": "0x00000000",
  1669. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  1670. "size": "0x00000000"
  1671. },
  1672. {
  1673. "virtual_address": "0x0014b000",
  1674. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  1675. "size": "0x000007b8"
  1676. },
  1677. {
  1678. "virtual_address": "0x0000a740",
  1679. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  1680. "size": "0x0000001c"
  1681. },
  1682. {
  1683. "virtual_address": "0x00000000",
  1684. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  1685. "size": "0x00000000"
  1686. },
  1687. {
  1688. "virtual_address": "0x00000000",
  1689. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  1690. "size": "0x00000000"
  1691. },
  1692. {
  1693. "virtual_address": "0x00000000",
  1694. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  1695. "size": "0x00000000"
  1696. },
  1697. {
  1698. "virtual_address": "0x00000000",
  1699. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  1700. "size": "0x00000000"
  1701. },
  1702. {
  1703. "virtual_address": "0x00000000",
  1704. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  1705. "size": "0x00000000"
  1706. },
  1707. {
  1708. "virtual_address": "0x00009000",
  1709. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  1710. "size": "0x00000150"
  1711. },
  1712. {
  1713. "virtual_address": "0x00000000",
  1714. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  1715. "size": "0x00000000"
  1716. },
  1717. {
  1718. "virtual_address": "0x00000000",
  1719. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  1720. "size": "0x00000000"
  1721. },
  1722. {
  1723. "virtual_address": "0x00000000",
  1724. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  1725. "size": "0x00000000"
  1726. }
  1727. ],
  1728. "exports": [],
  1729. "guest_signers": {},
  1730. "imphash": "ded6c839e7f7258224ae021602258361",
  1731. "icon_fuzzy": null,
  1732. "icon": null,
  1733. "pdbpath": null,
  1734. "imported_dll_count": 6,
  1735. "versioninfo": []
  1736. }
  1737. }
Advertisement
Add Comment
Please, Sign In to add comment