Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: ""
- [*] MalScore: 0.5
- [*] File Name: "socks5.dll"
- [*] File Size: 286720
- [*] File Type: "PE32 executable (DLL) (console) Intel 80386, for MS Windows"
- [*] SHA256: "d6394cbc1bbaf302169525838409325da63560b3d8a83c563c1d62166e20b7f8"
- [*] MD5: "394415eaed866c5ed8c6587b40e640b7"
- [*] SHA1: "f2404d097eb9713c489a788b96dc4832415b4c42"
- [*] SHA512: "1cb3962c1f26e5a49a4009c691ae0206edc542f0b2610d989f4a3ed970c7c82d346fa38222ffb77caf57d986c64451932bb2ad363c6da2fee44cfe3f5a0c52dd"
- [*] CRC32: "F27BA635"
- [*] SSDEEP: "6144:kstP7OknvSRqSPlcUdPr1aGaUYb1pcMp:kstP7Ogv8cOPrkGaU5g"
- [*] Process Execution: [
- "rundll32.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "Creates RWX memory",
- "Details": []
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: []
- [*] Mutexes: []
- [*] Modified Files: []
- [*] Deleted Files: []
- [*] Modified Registry Keys: []
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "atoi",
- "address": "0x100341d8"
- },
- {
- "name": "RtlUnwind",
- "address": "0x100341dc"
- },
- {
- "name": "memmove",
- "address": "0x100341e0"
- }
- ],
- "dll": "ntdll.dll"
- },
- {
- "imports": [
- {
- "name": "SetWaitableTimer",
- "address": "0x10034000"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x10034004"
- },
- {
- "name": "GetQueuedCompletionStatus",
- "address": "0x10034008"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x1003400c"
- },
- {
- "name": "InterlockedCompareExchange",
- "address": "0x10034010"
- },
- {
- "name": "SleepEx",
- "address": "0x10034014"
- },
- {
- "name": "TerminateThread",
- "address": "0x10034018"
- },
- {
- "name": "InitializeCriticalSectionAndSpinCount",
- "address": "0x1003401c"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x10034020"
- },
- {
- "name": "SetEvent",
- "address": "0x10034024"
- },
- {
- "name": "Sleep",
- "address": "0x10034028"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x1003402c"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x10034030"
- },
- {
- "name": "GetLastError",
- "address": "0x10034034"
- },
- {
- "name": "QueueUserAPC",
- "address": "0x10034038"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x1003403c"
- },
- {
- "name": "InterlockedExchangeAdd",
- "address": "0x10034040"
- },
- {
- "name": "CreateEventW",
- "address": "0x10034044"
- },
- {
- "name": "PostQueuedCompletionStatus",
- "address": "0x10034048"
- },
- {
- "name": "WaitForMultipleObjects",
- "address": "0x1003404c"
- },
- {
- "name": "CreateIoCompletionPort",
- "address": "0x10034050"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x10034054"
- },
- {
- "name": "TlsAlloc",
- "address": "0x10034058"
- },
- {
- "name": "CloseHandle",
- "address": "0x1003405c"
- },
- {
- "name": "TlsFree",
- "address": "0x10034060"
- },
- {
- "name": "TlsGetValue",
- "address": "0x10034064"
- },
- {
- "name": "TlsSetValue",
- "address": "0x10034068"
- },
- {
- "name": "GetProcessHeap",
- "address": "0x1003406c"
- },
- {
- "name": "HeapAlloc",
- "address": "0x10034070"
- },
- {
- "name": "CreateEventA",
- "address": "0x10034074"
- },
- {
- "name": "HeapFree",
- "address": "0x10034078"
- },
- {
- "name": "SetLastError",
- "address": "0x1003407c"
- },
- {
- "name": "CreateThread",
- "address": "0x10034080"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x10034084"
- },
- {
- "name": "CreateWaitableTimerW",
- "address": "0x10034088"
- },
- {
- "name": "CreateWaitableTimerA",
- "address": "0x1003408c"
- },
- {
- "name": "GetLocaleInfoW",
- "address": "0x10034090"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x10034094"
- },
- {
- "name": "IsValidLocale",
- "address": "0x10034098"
- },
- {
- "name": "EnumSystemLocalesA",
- "address": "0x1003409c"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x100340a0"
- },
- {
- "name": "GetUserDefaultLCID",
- "address": "0x100340a4"
- },
- {
- "name": "GetStringTypeW",
- "address": "0x100340a8"
- },
- {
- "name": "GetStringTypeA",
- "address": "0x100340ac"
- },
- {
- "name": "IsValidCodePage",
- "address": "0x100340b0"
- },
- {
- "name": "GetOEMCP",
- "address": "0x100340b4"
- },
- {
- "name": "GetACP",
- "address": "0x100340b8"
- },
- {
- "name": "HeapReAlloc",
- "address": "0x100340bc"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x100340c0"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x100340c4"
- },
- {
- "name": "VirtualFree",
- "address": "0x100340c8"
- },
- {
- "name": "HeapCreate",
- "address": "0x100340cc"
- },
- {
- "name": "HeapDestroy",
- "address": "0x100340d0"
- },
- {
- "name": "GetEnvironmentStringsW",
- "address": "0x100340d4"
- },
- {
- "name": "FreeEnvironmentStringsW",
- "address": "0x100340d8"
- },
- {
- "name": "GetEnvironmentStrings",
- "address": "0x100340dc"
- },
- {
- "name": "FreeEnvironmentStringsA",
- "address": "0x100340e0"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x100340e4"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x100340e8"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x100340ec"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x100340f0"
- },
- {
- "name": "LocalFree",
- "address": "0x100340f4"
- },
- {
- "name": "FormatMessageA",
- "address": "0x100340f8"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x100340fc"
- },
- {
- "name": "OpenEventA",
- "address": "0x10034100"
- },
- {
- "name": "ResetEvent",
- "address": "0x10034104"
- },
- {
- "name": "ResumeThread",
- "address": "0x10034108"
- },
- {
- "name": "GetTickCount",
- "address": "0x1003410c"
- },
- {
- "name": "SystemTimeToFileTime",
- "address": "0x10034110"
- },
- {
- "name": "ExitThread",
- "address": "0x10034114"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x10034118"
- },
- {
- "name": "TerminateProcess",
- "address": "0x1003411c"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x10034120"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x10034124"
- },
- {
- "name": "SetUnhandledExceptionFilter",
- "address": "0x10034128"
- },
- {
- "name": "IsDebuggerPresent",
- "address": "0x1003412c"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x10034130"
- },
- {
- "name": "GetVersionExA",
- "address": "0x10034134"
- },
- {
- "name": "RaiseException",
- "address": "0x10034138"
- },
- {
- "name": "GetCPInfo",
- "address": "0x1003413c"
- },
- {
- "name": "LCMapStringA",
- "address": "0x10034140"
- },
- {
- "name": "LCMapStringW",
- "address": "0x10034144"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x10034148"
- },
- {
- "name": "GetProcAddress",
- "address": "0x1003414c"
- },
- {
- "name": "HeapSize",
- "address": "0x10034150"
- },
- {
- "name": "ExitProcess",
- "address": "0x10034154"
- },
- {
- "name": "WriteFile",
- "address": "0x10034158"
- },
- {
- "name": "GetStdHandle",
- "address": "0x1003415c"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x10034160"
- },
- {
- "name": "SetHandleCount",
- "address": "0x10034164"
- },
- {
- "name": "GetFileType",
- "address": "0x10034168"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "WSAGetLastError",
- "address": "0x10034170"
- },
- {
- "name": "getaddrinfo",
- "address": "0x10034174"
- },
- {
- "name": "shutdown",
- "address": "0x10034178"
- },
- {
- "name": "freeaddrinfo",
- "address": "0x1003417c"
- },
- {
- "name": "ioctlsocket",
- "address": "0x10034180"
- },
- {
- "name": "connect",
- "address": "0x10034184"
- },
- {
- "name": "WSAStartup",
- "address": "0x10034188"
- },
- {
- "name": "ntohl",
- "address": "0x1003418c"
- },
- {
- "name": "inet_addr",
- "address": "0x10034190"
- },
- {
- "name": "htonl",
- "address": "0x10034194"
- },
- {
- "name": "WSARecv",
- "address": "0x10034198"
- },
- {
- "name": "WSASocketW",
- "address": "0x1003419c"
- },
- {
- "name": "WSASend",
- "address": "0x100341a0"
- },
- {
- "name": "select",
- "address": "0x100341a4"
- },
- {
- "name": "htons",
- "address": "0x100341a8"
- },
- {
- "name": "getsockname",
- "address": "0x100341ac"
- },
- {
- "name": "setsockopt",
- "address": "0x100341b0"
- },
- {
- "name": "WSACleanup",
- "address": "0x100341b4"
- },
- {
- "name": "bind",
- "address": "0x100341b8"
- },
- {
- "name": "__WSAFDIsSet",
- "address": "0x100341bc"
- },
- {
- "name": "WSASetLastError",
- "address": "0x100341c0"
- },
- {
- "name": "closesocket",
- "address": "0x100341c4"
- },
- {
- "name": "getsockopt",
- "address": "0x100341c8"
- },
- {
- "name": "listen",
- "address": "0x100341cc"
- },
- {
- "name": "accept",
- "address": "0x100341d0"
- }
- ],
- "dll": "WS2_32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": "socks5.dll",
- "actual_checksum": "0x00051ca8",
- "overlay": null,
- "imagebase": "0x10000000",
- "reported_checksum": "0x00051ca8",
- "icon_hash": null,
- "entrypoint": "0x10020cbb",
- "timestamp": "2011-02-05 07:00:43",
- "osversion": "5.1",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00032800",
- "entropy": "6.60",
- "raw_address": "0x00000400",
- "virtual_size": "0x00032662",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00034000",
- "size_of_data": "0x0000ac00",
- "entropy": "4.69",
- "raw_address": "0x00032c00",
- "virtual_size": "0x0000ab97",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0003f000",
- "size_of_data": "0x00003200",
- "entropy": "4.83",
- "raw_address": "0x0003d800",
- "virtual_size": "0x000041bc",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00044000",
- "size_of_data": "0x00000200",
- "entropy": "0.00",
- "raw_address": "0x00040a00",
- "virtual_size": "0x00000002",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00045000",
- "size_of_data": "0x00000200",
- "entropy": "5.10",
- "raw_address": "0x00040c00",
- "virtual_size": "0x000001b4",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00046000",
- "size_of_data": "0x00005200",
- "entropy": "5.11",
- "raw_address": "0x00040e00",
- "virtual_size": "0x000051fc",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x0003eb20",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000077"
- },
- {
- "virtual_address": "0x0003e1a4",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000050"
- },
- {
- "virtual_address": "0x00045000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x000001b4"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00046000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00003530"
- },
- {
- "virtual_address": "0x00034680",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00037900",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x000378b8",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000040"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00034000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x000001e8"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [
- {
- "ordinal": 1,
- "name": "GetPluginId",
- "address": "0x10008c00"
- },
- {
- "ordinal": 2,
- "name": "Init",
- "address": "0x10008c20"
- },
- {
- "ordinal": 3,
- "name": "Start",
- "address": "0x10008d10"
- },
- {
- "ordinal": 4,
- "name": "Stop",
- "address": "0x10008e20"
- }
- ],
- "guest_signers": {},
- "imphash": "767a502e07c59fb3145ffab2322e790c",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "C:\\Data\\Documents\\My Projects\\CC\\CardNet\\Progs\\Client\\SpyEye\\plugins\\BC\\Client\\Release\\socks5.pdb",
- "imported_dll_count": 3,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "kernel32.dll.FlsAlloc",
- "kernel32.dll.FlsGetValue",
- "kernel32.dll.FlsSetValue",
- "kernel32.dll.FlsFree",
- "kernel32.dll.InitializeCriticalSectionAndSpinCount",
- "kernel32.dll.IsProcessorFeaturePresent"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "atoi",
- "address": "0x100341d8"
- },
- {
- "name": "RtlUnwind",
- "address": "0x100341dc"
- },
- {
- "name": "memmove",
- "address": "0x100341e0"
- }
- ],
- "dll": "ntdll.dll"
- },
- {
- "imports": [
- {
- "name": "SetWaitableTimer",
- "address": "0x10034000"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x10034004"
- },
- {
- "name": "GetQueuedCompletionStatus",
- "address": "0x10034008"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x1003400c"
- },
- {
- "name": "InterlockedCompareExchange",
- "address": "0x10034010"
- },
- {
- "name": "SleepEx",
- "address": "0x10034014"
- },
- {
- "name": "TerminateThread",
- "address": "0x10034018"
- },
- {
- "name": "InitializeCriticalSectionAndSpinCount",
- "address": "0x1003401c"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x10034020"
- },
- {
- "name": "SetEvent",
- "address": "0x10034024"
- },
- {
- "name": "Sleep",
- "address": "0x10034028"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x1003402c"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x10034030"
- },
- {
- "name": "GetLastError",
- "address": "0x10034034"
- },
- {
- "name": "QueueUserAPC",
- "address": "0x10034038"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x1003403c"
- },
- {
- "name": "InterlockedExchangeAdd",
- "address": "0x10034040"
- },
- {
- "name": "CreateEventW",
- "address": "0x10034044"
- },
- {
- "name": "PostQueuedCompletionStatus",
- "address": "0x10034048"
- },
- {
- "name": "WaitForMultipleObjects",
- "address": "0x1003404c"
- },
- {
- "name": "CreateIoCompletionPort",
- "address": "0x10034050"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x10034054"
- },
- {
- "name": "TlsAlloc",
- "address": "0x10034058"
- },
- {
- "name": "CloseHandle",
- "address": "0x1003405c"
- },
- {
- "name": "TlsFree",
- "address": "0x10034060"
- },
- {
- "name": "TlsGetValue",
- "address": "0x10034064"
- },
- {
- "name": "TlsSetValue",
- "address": "0x10034068"
- },
- {
- "name": "GetProcessHeap",
- "address": "0x1003406c"
- },
- {
- "name": "HeapAlloc",
- "address": "0x10034070"
- },
- {
- "name": "CreateEventA",
- "address": "0x10034074"
- },
- {
- "name": "HeapFree",
- "address": "0x10034078"
- },
- {
- "name": "SetLastError",
- "address": "0x1003407c"
- },
- {
- "name": "CreateThread",
- "address": "0x10034080"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x10034084"
- },
- {
- "name": "CreateWaitableTimerW",
- "address": "0x10034088"
- },
- {
- "name": "CreateWaitableTimerA",
- "address": "0x1003408c"
- },
- {
- "name": "GetLocaleInfoW",
- "address": "0x10034090"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x10034094"
- },
- {
- "name": "IsValidLocale",
- "address": "0x10034098"
- },
- {
- "name": "EnumSystemLocalesA",
- "address": "0x1003409c"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x100340a0"
- },
- {
- "name": "GetUserDefaultLCID",
- "address": "0x100340a4"
- },
- {
- "name": "GetStringTypeW",
- "address": "0x100340a8"
- },
- {
- "name": "GetStringTypeA",
- "address": "0x100340ac"
- },
- {
- "name": "IsValidCodePage",
- "address": "0x100340b0"
- },
- {
- "name": "GetOEMCP",
- "address": "0x100340b4"
- },
- {
- "name": "GetACP",
- "address": "0x100340b8"
- },
- {
- "name": "HeapReAlloc",
- "address": "0x100340bc"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x100340c0"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x100340c4"
- },
- {
- "name": "VirtualFree",
- "address": "0x100340c8"
- },
- {
- "name": "HeapCreate",
- "address": "0x100340cc"
- },
- {
- "name": "HeapDestroy",
- "address": "0x100340d0"
- },
- {
- "name": "GetEnvironmentStringsW",
- "address": "0x100340d4"
- },
- {
- "name": "FreeEnvironmentStringsW",
- "address": "0x100340d8"
- },
- {
- "name": "GetEnvironmentStrings",
- "address": "0x100340dc"
- },
- {
- "name": "FreeEnvironmentStringsA",
- "address": "0x100340e0"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x100340e4"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x100340e8"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x100340ec"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x100340f0"
- },
- {
- "name": "LocalFree",
- "address": "0x100340f4"
- },
- {
- "name": "FormatMessageA",
- "address": "0x100340f8"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x100340fc"
- },
- {
- "name": "OpenEventA",
- "address": "0x10034100"
- },
- {
- "name": "ResetEvent",
- "address": "0x10034104"
- },
- {
- "name": "ResumeThread",
- "address": "0x10034108"
- },
- {
- "name": "GetTickCount",
- "address": "0x1003410c"
- },
- {
- "name": "SystemTimeToFileTime",
- "address": "0x10034110"
- },
- {
- "name": "ExitThread",
- "address": "0x10034114"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x10034118"
- },
- {
- "name": "TerminateProcess",
- "address": "0x1003411c"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x10034120"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x10034124"
- },
- {
- "name": "SetUnhandledExceptionFilter",
- "address": "0x10034128"
- },
- {
- "name": "IsDebuggerPresent",
- "address": "0x1003412c"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x10034130"
- },
- {
- "name": "GetVersionExA",
- "address": "0x10034134"
- },
- {
- "name": "RaiseException",
- "address": "0x10034138"
- },
- {
- "name": "GetCPInfo",
- "address": "0x1003413c"
- },
- {
- "name": "LCMapStringA",
- "address": "0x10034140"
- },
- {
- "name": "LCMapStringW",
- "address": "0x10034144"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x10034148"
- },
- {
- "name": "GetProcAddress",
- "address": "0x1003414c"
- },
- {
- "name": "HeapSize",
- "address": "0x10034150"
- },
- {
- "name": "ExitProcess",
- "address": "0x10034154"
- },
- {
- "name": "WriteFile",
- "address": "0x10034158"
- },
- {
- "name": "GetStdHandle",
- "address": "0x1003415c"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x10034160"
- },
- {
- "name": "SetHandleCount",
- "address": "0x10034164"
- },
- {
- "name": "GetFileType",
- "address": "0x10034168"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "WSAGetLastError",
- "address": "0x10034170"
- },
- {
- "name": "getaddrinfo",
- "address": "0x10034174"
- },
- {
- "name": "shutdown",
- "address": "0x10034178"
- },
- {
- "name": "freeaddrinfo",
- "address": "0x1003417c"
- },
- {
- "name": "ioctlsocket",
- "address": "0x10034180"
- },
- {
- "name": "connect",
- "address": "0x10034184"
- },
- {
- "name": "WSAStartup",
- "address": "0x10034188"
- },
- {
- "name": "ntohl",
- "address": "0x1003418c"
- },
- {
- "name": "inet_addr",
- "address": "0x10034190"
- },
- {
- "name": "htonl",
- "address": "0x10034194"
- },
- {
- "name": "WSARecv",
- "address": "0x10034198"
- },
- {
- "name": "WSASocketW",
- "address": "0x1003419c"
- },
- {
- "name": "WSASend",
- "address": "0x100341a0"
- },
- {
- "name": "select",
- "address": "0x100341a4"
- },
- {
- "name": "htons",
- "address": "0x100341a8"
- },
- {
- "name": "getsockname",
- "address": "0x100341ac"
- },
- {
- "name": "setsockopt",
- "address": "0x100341b0"
- },
- {
- "name": "WSACleanup",
- "address": "0x100341b4"
- },
- {
- "name": "bind",
- "address": "0x100341b8"
- },
- {
- "name": "__WSAFDIsSet",
- "address": "0x100341bc"
- },
- {
- "name": "WSASetLastError",
- "address": "0x100341c0"
- },
- {
- "name": "closesocket",
- "address": "0x100341c4"
- },
- {
- "name": "getsockopt",
- "address": "0x100341c8"
- },
- {
- "name": "listen",
- "address": "0x100341cc"
- },
- {
- "name": "accept",
- "address": "0x100341d0"
- }
- ],
- "dll": "WS2_32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": "socks5.dll",
- "actual_checksum": "0x00051ca8",
- "overlay": null,
- "imagebase": "0x10000000",
- "reported_checksum": "0x00051ca8",
- "icon_hash": null,
- "entrypoint": "0x10020cbb",
- "timestamp": "2011-02-05 07:00:43",
- "osversion": "5.1",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00032800",
- "entropy": "6.60",
- "raw_address": "0x00000400",
- "virtual_size": "0x00032662",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00034000",
- "size_of_data": "0x0000ac00",
- "entropy": "4.69",
- "raw_address": "0x00032c00",
- "virtual_size": "0x0000ab97",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0003f000",
- "size_of_data": "0x00003200",
- "entropy": "4.83",
- "raw_address": "0x0003d800",
- "virtual_size": "0x000041bc",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00044000",
- "size_of_data": "0x00000200",
- "entropy": "0.00",
- "raw_address": "0x00040a00",
- "virtual_size": "0x00000002",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00045000",
- "size_of_data": "0x00000200",
- "entropy": "5.10",
- "raw_address": "0x00040c00",
- "virtual_size": "0x000001b4",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00046000",
- "size_of_data": "0x00005200",
- "entropy": "5.11",
- "raw_address": "0x00040e00",
- "virtual_size": "0x000051fc",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x0003eb20",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000077"
- },
- {
- "virtual_address": "0x0003e1a4",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000050"
- },
- {
- "virtual_address": "0x00045000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x000001b4"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00046000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00003530"
- },
- {
- "virtual_address": "0x00034680",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00037900",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x000378b8",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000040"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00034000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x000001e8"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [
- {
- "ordinal": 1,
- "name": "GetPluginId",
- "address": "0x10008c00"
- },
- {
- "ordinal": 2,
- "name": "Init",
- "address": "0x10008c20"
- },
- {
- "ordinal": 3,
- "name": "Start",
- "address": "0x10008d10"
- },
- {
- "ordinal": 4,
- "name": "Stop",
- "address": "0x10008e20"
- }
- ],
- "guest_signers": {},
- "imphash": "767a502e07c59fb3145ffab2322e790c",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "C:\\Data\\Documents\\My Projects\\CC\\CardNet\\Progs\\Client\\SpyEye\\plugins\\BC\\Client\\Release\\socks5.pdb",
- "imported_dll_count": 3,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement