Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: ""
- [*] MalScore: 1.0
- [*] File Name: "45B65D.exe"
- [*] File Size: 179712
- [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- [*] SHA256: "c4232ddd4d37b9c0884bd44d8476578c54d7f98d58945728e425736a6a07e102"
- [*] MD5: "d378bffb70923139d6a4f546864aa61c"
- [*] SHA1: "f00aa51c2ed8b2f656318fdc01ee1cf5441011a4"
- [*] SHA512: "7c09ec193d91d3cadb7e58c634b8666d8d6243b3ee7d4d4755eeb82bac62b9508e78aa3c53106bfe72d7a437f650b29a54116663e1b4da11613a30656cccc663"
- [*] CRC32: "5D47D00E"
- [*] SSDEEP: "3072:9VexzTMlI0frxJLgf7nDVF6PUp1Yo3ICgxgV:9ExJex5gfzDVlVXgaV"
- [*] Process Execution: [
- "45B65D.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details": [
- {
- "section": "name: .rsrc, entropy: 7.37, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x0001f200, virtual_size: 0x0001f160"
- }
- ]
- }
- ]
- [*] Started Service: []
- [*] Created Services: []
- [*] Mutexes: []
- [*] Modified Files: []
- [*] Deleted Files: []
- [*] Modified Registry Keys: []
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "RegSetValueExW",
- "address": "0x1001000"
- },
- {
- "name": "RegQueryValueExW",
- "address": "0x1001004"
- },
- {
- "name": "RegCloseKey",
- "address": "0x1001008"
- },
- {
- "name": "RegCreateKeyW",
- "address": "0x100100c"
- },
- {
- "name": "RegOpenKeyExW",
- "address": "0x1001010"
- },
- {
- "name": "IsTextUnicode",
- "address": "0x1001014"
- },
- {
- "name": "CloseServiceHandle",
- "address": "0x1001018"
- },
- {
- "name": "QueryServiceConfigW",
- "address": "0x100101c"
- },
- {
- "name": "OpenServiceW",
- "address": "0x1001020"
- },
- {
- "name": "OpenSCManagerW",
- "address": "0x1001024"
- }
- ],
- "dll": "ADVAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "FindNLSString",
- "address": "0x100102c"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x1001030"
- },
- {
- "name": "GlobalUnlock",
- "address": "0x1001034"
- },
- {
- "name": "GlobalLock",
- "address": "0x1001038"
- },
- {
- "name": "GetTimeFormatW",
- "address": "0x100103c"
- },
- {
- "name": "GetDateFormatW",
- "address": "0x1001040"
- },
- {
- "name": "GetLocalTime",
- "address": "0x1001044"
- },
- {
- "name": "GetUserDefaultUILanguage",
- "address": "0x1001048"
- },
- {
- "name": "HeapFree",
- "address": "0x100104c"
- },
- {
- "name": "HeapAlloc",
- "address": "0x1001050"
- },
- {
- "name": "GetProcessHeap",
- "address": "0x1001054"
- },
- {
- "name": "GetFileInformationByHandle",
- "address": "0x1001058"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x100105c"
- },
- {
- "name": "FreeLibraryAndExitThread",
- "address": "0x1001060"
- },
- {
- "name": "GetFileAttributesW",
- "address": "0x1001064"
- },
- {
- "name": "Wow64RevertWow64FsRedirection",
- "address": "0x1001068"
- },
- {
- "name": "Wow64DisableWow64FsRedirection",
- "address": "0x100106c"
- },
- {
- "name": "IsWow64Process",
- "address": "0x1001070"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x1001074"
- },
- {
- "name": "CreateThread",
- "address": "0x1001078"
- },
- {
- "name": "LoadLibraryW",
- "address": "0x100107c"
- },
- {
- "name": "GetModuleFileNameW",
- "address": "0x1001080"
- },
- {
- "name": "CreateFileMappingW",
- "address": "0x1001084"
- },
- {
- "name": "FormatMessageW",
- "address": "0x1001088"
- },
- {
- "name": "MapViewOfFile",
- "address": "0x100108c"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x1001090"
- },
- {
- "name": "UnmapViewOfFile",
- "address": "0x1001094"
- },
- {
- "name": "LocalReAlloc",
- "address": "0x1001098"
- },
- {
- "name": "GetACP",
- "address": "0x100109c"
- },
- {
- "name": "DeleteFileW",
- "address": "0x10010a0"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x10010a4"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x10010a8"
- },
- {
- "name": "SetLastError",
- "address": "0x10010ac"
- },
- {
- "name": "WriteFile",
- "address": "0x10010b0"
- },
- {
- "name": "GetLastError",
- "address": "0x10010b4"
- },
- {
- "name": "LocalSize",
- "address": "0x10010b8"
- },
- {
- "name": "GetFullPathNameW",
- "address": "0x10010bc"
- },
- {
- "name": "MulDiv",
- "address": "0x10010c0"
- },
- {
- "name": "GetCommandLineW",
- "address": "0x10010c4"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x10010c8"
- },
- {
- "name": "FoldStringW",
- "address": "0x10010cc"
- },
- {
- "name": "lstrcmpW",
- "address": "0x10010d0"
- },
- {
- "name": "FindFirstFileW",
- "address": "0x10010d4"
- },
- {
- "name": "FindClose",
- "address": "0x10010d8"
- },
- {
- "name": "HeapSetInformation",
- "address": "0x10010dc"
- },
- {
- "name": "TerminateProcess",
- "address": "0x10010e0"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x10010e4"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x10010e8"
- },
- {
- "name": "GetTickCount",
- "address": "0x10010ec"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x10010f0"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x10010f4"
- },
- {
- "name": "SetUnhandledExceptionFilter",
- "address": "0x10010f8"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x10010fc"
- },
- {
- "name": "InterlockedCompareExchange",
- "address": "0x1001100"
- },
- {
- "name": "Sleep",
- "address": "0x1001104"
- },
- {
- "name": "LocalLock",
- "address": "0x1001108"
- },
- {
- "name": "LocalUnlock",
- "address": "0x100110c"
- },
- {
- "name": "lstrlenW",
- "address": "0x1001110"
- },
- {
- "name": "GetLocaleInfoW",
- "address": "0x1001114"
- },
- {
- "name": "GlobalFree",
- "address": "0x1001118"
- },
- {
- "name": "lstrcmpiW",
- "address": "0x100111c"
- },
- {
- "name": "SetErrorMode",
- "address": "0x1001120"
- },
- {
- "name": "CreateFileW",
- "address": "0x1001124"
- },
- {
- "name": "ReadFile",
- "address": "0x1001128"
- },
- {
- "name": "CloseHandle",
- "address": "0x100112c"
- },
- {
- "name": "LocalAlloc",
- "address": "0x1001130"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x1001134"
- },
- {
- "name": "LocalFree",
- "address": "0x1001138"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x100113c"
- },
- {
- "name": "GetVersionExW",
- "address": "0x1001140"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x1001144"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateFontIndirectW",
- "address": "0x100114c"
- },
- {
- "name": "SetMapMode",
- "address": "0x1001150"
- },
- {
- "name": "SetViewportExtEx",
- "address": "0x1001154"
- },
- {
- "name": "SetWindowExtEx",
- "address": "0x1001158"
- },
- {
- "name": "LPtoDP",
- "address": "0x100115c"
- },
- {
- "name": "SetBkMode",
- "address": "0x1001160"
- },
- {
- "name": "GetTextMetricsW",
- "address": "0x1001164"
- },
- {
- "name": "SetAbortProc",
- "address": "0x1001168"
- },
- {
- "name": "StartDocW",
- "address": "0x100116c"
- },
- {
- "name": "StartPage",
- "address": "0x1001170"
- },
- {
- "name": "EndPage",
- "address": "0x1001174"
- },
- {
- "name": "AbortDoc",
- "address": "0x1001178"
- },
- {
- "name": "EndDoc",
- "address": "0x100117c"
- },
- {
- "name": "DeleteDC",
- "address": "0x1001180"
- },
- {
- "name": "TextOutW",
- "address": "0x1001184"
- },
- {
- "name": "GetTextExtentPoint32W",
- "address": "0x1001188"
- },
- {
- "name": "CreateDCW",
- "address": "0x100118c"
- },
- {
- "name": "SelectObject",
- "address": "0x1001190"
- },
- {
- "name": "GetTextFaceW",
- "address": "0x1001194"
- },
- {
- "name": "EnumFontsW",
- "address": "0x1001198"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x100119c"
- },
- {
- "name": "DeleteObject",
- "address": "0x10011a0"
- }
- ],
- "dll": "GDI32.dll"
- },
- {
- "imports": [
- {
- "name": "SetActiveWindow",
- "address": "0x10011a8"
- },
- {
- "name": "GetKeyboardLayout",
- "address": "0x10011ac"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x10011b0"
- },
- {
- "name": "DefWindowProcW",
- "address": "0x10011b4"
- },
- {
- "name": "GetForegroundWindow",
- "address": "0x10011b8"
- },
- {
- "name": "IsIconic",
- "address": "0x10011bc"
- },
- {
- "name": "DestroyWindow",
- "address": "0x10011c0"
- },
- {
- "name": "MessageBeep",
- "address": "0x10011c4"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x10011c8"
- },
- {
- "name": "CharUpperW",
- "address": "0x10011cc"
- },
- {
- "name": "RegisterClassExW",
- "address": "0x10011d0"
- },
- {
- "name": "LoadImageW",
- "address": "0x10011d4"
- },
- {
- "name": "LoadCursorW",
- "address": "0x10011d8"
- },
- {
- "name": "SetWindowLongW",
- "address": "0x10011dc"
- },
- {
- "name": "LoadAcceleratorsW",
- "address": "0x10011e0"
- },
- {
- "name": "GetSystemMenu",
- "address": "0x10011e4"
- },
- {
- "name": "SetWindowPlacement",
- "address": "0x10011e8"
- },
- {
- "name": "CreateWindowExW",
- "address": "0x10011ec"
- },
- {
- "name": "RegisterWindowMessageW",
- "address": "0x10011f0"
- },
- {
- "name": "UpdateWindow",
- "address": "0x10011f4"
- },
- {
- "name": "InvalidateRect",
- "address": "0x10011f8"
- },
- {
- "name": "SetScrollPos",
- "address": "0x10011fc"
- },
- {
- "name": "GetWindowTextLengthW",
- "address": "0x1001200"
- },
- {
- "name": "GetWindowLongW",
- "address": "0x1001204"
- },
- {
- "name": "PeekMessageW",
- "address": "0x1001208"
- },
- {
- "name": "EnableWindow",
- "address": "0x100120c"
- },
- {
- "name": "DialogBoxParamW",
- "address": "0x1001210"
- },
- {
- "name": "CreateDialogParamW",
- "address": "0x1001214"
- },
- {
- "name": "GetWindowTextW",
- "address": "0x1001218"
- },
- {
- "name": "SetWindowPos",
- "address": "0x100121c"
- },
- {
- "name": "SetCursor",
- "address": "0x1001220"
- },
- {
- "name": "SetForegroundWindow",
- "address": "0x1001224"
- },
- {
- "name": "FindWindowW",
- "address": "0x1001228"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x100122c"
- },
- {
- "name": "MoveWindow",
- "address": "0x1001230"
- },
- {
- "name": "SendMessageW",
- "address": "0x1001234"
- },
- {
- "name": "CharNextW",
- "address": "0x1001238"
- },
- {
- "name": "CheckMenuItem",
- "address": "0x100123c"
- },
- {
- "name": "CloseClipboard",
- "address": "0x1001240"
- },
- {
- "name": "IsClipboardFormatAvailable",
- "address": "0x1001244"
- },
- {
- "name": "OpenClipboard",
- "address": "0x1001248"
- },
- {
- "name": "GetMenuState",
- "address": "0x100124c"
- },
- {
- "name": "EnableMenuItem",
- "address": "0x1001250"
- },
- {
- "name": "GetSubMenu",
- "address": "0x1001254"
- },
- {
- "name": "GetClientRect",
- "address": "0x1001258"
- },
- {
- "name": "UnhookWinEvent",
- "address": "0x100125c"
- },
- {
- "name": "GetFocus",
- "address": "0x1001260"
- },
- {
- "name": "GetMenu",
- "address": "0x1001264"
- },
- {
- "name": "MessageBoxW",
- "address": "0x1001268"
- },
- {
- "name": "WinHelpW",
- "address": "0x100126c"
- },
- {
- "name": "GetDlgCtrlID",
- "address": "0x1001270"
- },
- {
- "name": "ChildWindowFromPoint",
- "address": "0x1001274"
- },
- {
- "name": "GetDC",
- "address": "0x1001278"
- },
- {
- "name": "ShowWindow",
- "address": "0x100127c"
- },
- {
- "name": "DrawTextExW",
- "address": "0x1001280"
- },
- {
- "name": "ReleaseDC",
- "address": "0x1001284"
- },
- {
- "name": "LoadIconW",
- "address": "0x1001288"
- },
- {
- "name": "SetWinEventHook",
- "address": "0x100128c"
- },
- {
- "name": "GetMessageW",
- "address": "0x1001290"
- },
- {
- "name": "PostMessageW",
- "address": "0x1001294"
- },
- {
- "name": "IsDialogMessageW",
- "address": "0x1001298"
- },
- {
- "name": "TranslateAcceleratorW",
- "address": "0x100129c"
- },
- {
- "name": "EndDialog",
- "address": "0x10012a0"
- },
- {
- "name": "GetDlgItemTextW",
- "address": "0x10012a4"
- },
- {
- "name": "SetDlgItemTextW",
- "address": "0x10012a8"
- },
- {
- "name": "SetFocus",
- "address": "0x10012ac"
- },
- {
- "name": "SetWindowTextW",
- "address": "0x10012b0"
- },
- {
- "name": "GetParent",
- "address": "0x10012b4"
- },
- {
- "name": "LoadStringW",
- "address": "0x10012b8"
- },
- {
- "name": "SendDlgItemMessageW",
- "address": "0x10012bc"
- },
- {
- "name": "GetCursorPos",
- "address": "0x10012c0"
- },
- {
- "name": "ScreenToClient",
- "address": "0x10012c4"
- },
- {
- "name": "TranslateMessage",
- "address": "0x10012c8"
- },
- {
- "name": "GetAncestor",
- "address": "0x10012cc"
- },
- {
- "name": "DispatchMessageW",
- "address": "0x10012d0"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "_controlfp",
- "address": "0x10012d8"
- },
- {
- "name": "_vsnwprintf",
- "address": "0x10012dc"
- },
- {
- "name": "memset",
- "address": "0x10012e0"
- },
- {
- "name": "_wtol",
- "address": "0x10012e4"
- },
- {
- "name": "memcpy",
- "address": "0x10012e8"
- },
- {
- "name": "iswctype",
- "address": "0x10012ec"
- },
- {
- "name": "wcsncmp",
- "address": "0x10012f0"
- },
- {
- "name": "wcsrchr",
- "address": "0x10012f4"
- },
- {
- "name": "_except_handler4_common",
- "address": "0x10012f8"
- },
- {
- "name": "__p__fmode",
- "address": "0x10012fc"
- },
- {
- "name": "__p__commode",
- "address": "0x1001300"
- },
- {
- "name": "__setusermatherr",
- "address": "0x1001304"
- },
- {
- "name": "_amsg_exit",
- "address": "0x1001308"
- },
- {
- "name": "_initterm",
- "address": "0x100130c"
- },
- {
- "name": "_acmdln",
- "address": "0x1001310"
- },
- {
- "name": "exit",
- "address": "0x1001314"
- },
- {
- "name": "_ismbblead",
- "address": "0x1001318"
- },
- {
- "name": "_XcptFilter",
- "address": "0x100131c"
- },
- {
- "name": "__getmainargs",
- "address": "0x1001320"
- },
- {
- "name": "_cexit",
- "address": "0x1001324"
- },
- {
- "name": "_exit",
- "address": "0x1001328"
- },
- {
- "name": "?terminate@@YAXXZ",
- "address": "0x100132c"
- },
- {
- "name": "__set_app_type",
- "address": "0x1001330"
- }
- ],
- "dll": "msvcrt.dll"
- },
- {
- "imports": [
- {
- "name": "ReplaceTextW",
- "address": "0x1001338"
- },
- {
- "name": "PageSetupDlgW",
- "address": "0x100133c"
- },
- {
- "name": "PrintDlgExW",
- "address": "0x1001340"
- },
- {
- "name": "FindTextW",
- "address": "0x1001344"
- },
- {
- "name": "ChooseFontW",
- "address": "0x1001348"
- },
- {
- "name": "GetSaveFileNameW",
- "address": "0x100134c"
- },
- {
- "name": "CommDlgExtendedError",
- "address": "0x1001350"
- },
- {
- "name": "GetOpenFileNameW",
- "address": "0x1001354"
- },
- {
- "name": "GetFileTitleW",
- "address": "0x1001358"
- }
- ],
- "dll": "COMDLG32.dll"
- },
- {
- "imports": [
- {
- "name": "DragAcceptFiles",
- "address": "0x1001360"
- },
- {
- "name": "SHAddToRecentDocs",
- "address": "0x1001364"
- },
- {
- "name": "SHGetFolderPathW",
- "address": "0x1001368"
- },
- {
- "name": "SHCreateItemFromParsingName",
- "address": "0x100136c"
- },
- {
- "name": "ShellExecuteExW",
- "address": "0x1001370"
- },
- {
- "name": "DragQueryFileW",
- "address": "0x1001374"
- },
- {
- "name": "DragFinish",
- "address": "0x1001378"
- },
- {
- "name": "ShellAboutW",
- "address": "0x100137c"
- }
- ],
- "dll": "SHELL32.dll"
- },
- {
- "imports": [
- {
- "name": "OpenPrinterW",
- "address": "0x1001384"
- },
- {
- "name": "ClosePrinter",
- "address": "0x1001388"
- },
- {
- "name": "GetPrinterDriverW",
- "address": "0x100138c"
- }
- ],
- "dll": "WINSPOOL.DRV"
- },
- {
- "imports": [
- {
- "name": "CoInitializeEx",
- "address": "0x1001394"
- },
- {
- "name": "CoUninitialize",
- "address": "0x1001398"
- },
- {
- "name": "CoTaskMemAlloc",
- "address": "0x100139c"
- },
- {
- "name": "CoCreateInstance",
- "address": "0x10013a0"
- },
- {
- "name": "CoTaskMemFree",
- "address": "0x10013a4"
- },
- {
- "name": "CoInitialize",
- "address": "0x10013a8"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "PathIsFileSpecW",
- "address": "0x10013b0"
- },
- {
- "name": "SHStrDupW",
- "address": "0x10013b4"
- }
- ],
- "dll": "SHLWAPI.dll"
- },
- {
- "imports": [
- {
- "name": "CreatePropertySheetPageW",
- "address": "0x10013bc"
- },
- {
- "name": "PropertySheetW",
- "address": "0x10013c0"
- },
- {
- "name": "CreateStatusWindowW",
- "address": "0x10013c4"
- },
- {
- "name": null,
- "address": "0x10013c8"
- }
- ],
- "dll": "COMCTL32.dll"
- },
- {
- "imports": [
- {
- "name": "SysFreeString",
- "address": "0x10013d0"
- },
- {
- "name": "SysAllocString",
- "address": "0x10013d4"
- }
- ],
- "dll": "OLEAUT32.dll"
- },
- {
- "imports": [
- {
- "name": "WinSqmIncrementDWORD",
- "address": "0x10013dc"
- },
- {
- "name": "RtlInitUnicodeString",
- "address": "0x10013e0"
- },
- {
- "name": "NtQueryLicenseValue",
- "address": "0x10013e4"
- },
- {
- "name": "WinSqmAddToStream",
- "address": "0x10013e8"
- }
- ],
- "dll": "ntdll.dll"
- },
- {
- "imports": [
- {
- "name": "GetFileVersionInfoExW",
- "address": "0x10013f0"
- },
- {
- "name": "GetFileVersionInfoSizeExW",
- "address": "0x10013f4"
- },
- {
- "name": "VerQueryValueW",
- "address": "0x10013f8"
- }
- ],
- "dll": "VERSION.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00039741",
- "overlay": null,
- "imagebase": "0x01000000",
- "reported_checksum": "0x00039741",
- "icon_hash": null,
- "entrypoint": "0x01003689",
- "timestamp": "2009-07-13 23:41:03",
- "osversion": "6.1",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x0000a800",
- "entropy": "6.28",
- "raw_address": "0x00000400",
- "virtual_size": "0x0000a68c",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0000c000",
- "size_of_data": "0x00001000",
- "entropy": "0.76",
- "raw_address": "0x0000ac00",
- "virtual_size": "0x00002164",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0000f000",
- "size_of_data": "0x0001f200",
- "entropy": "7.37",
- "raw_address": "0x0000bc00",
- "virtual_size": "0x0001f160",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0002f000",
- "size_of_data": "0x00001000",
- "entropy": "6.43",
- "raw_address": "0x0002ae00",
- "virtual_size": "0x00000e34",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0000a048",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000012c"
- },
- {
- "virtual_address": "0x0000f000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x0001f160"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0002f000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000e34"
- },
- {
- "virtual_address": "0x0000b62c",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000038"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00006d58",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000040"
- },
- {
- "virtual_address": "0x00000278",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000128"
- },
- {
- "virtual_address": "0x00001000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000400"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "2a141685bec588fb7b12c50a8a40eb2b",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "notepad.pdb",
- "imported_dll_count": 14,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "cryptbase.dll.SystemFunction036",
- "uxtheme.dll.ThemeInitApiHook",
- "user32.dll.IsProcessDPIAware",
- "oleaut32.dll.#500"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "RegSetValueExW",
- "address": "0x1001000"
- },
- {
- "name": "RegQueryValueExW",
- "address": "0x1001004"
- },
- {
- "name": "RegCloseKey",
- "address": "0x1001008"
- },
- {
- "name": "RegCreateKeyW",
- "address": "0x100100c"
- },
- {
- "name": "RegOpenKeyExW",
- "address": "0x1001010"
- },
- {
- "name": "IsTextUnicode",
- "address": "0x1001014"
- },
- {
- "name": "CloseServiceHandle",
- "address": "0x1001018"
- },
- {
- "name": "QueryServiceConfigW",
- "address": "0x100101c"
- },
- {
- "name": "OpenServiceW",
- "address": "0x1001020"
- },
- {
- "name": "OpenSCManagerW",
- "address": "0x1001024"
- }
- ],
- "dll": "ADVAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "FindNLSString",
- "address": "0x100102c"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x1001030"
- },
- {
- "name": "GlobalUnlock",
- "address": "0x1001034"
- },
- {
- "name": "GlobalLock",
- "address": "0x1001038"
- },
- {
- "name": "GetTimeFormatW",
- "address": "0x100103c"
- },
- {
- "name": "GetDateFormatW",
- "address": "0x1001040"
- },
- {
- "name": "GetLocalTime",
- "address": "0x1001044"
- },
- {
- "name": "GetUserDefaultUILanguage",
- "address": "0x1001048"
- },
- {
- "name": "HeapFree",
- "address": "0x100104c"
- },
- {
- "name": "HeapAlloc",
- "address": "0x1001050"
- },
- {
- "name": "GetProcessHeap",
- "address": "0x1001054"
- },
- {
- "name": "GetFileInformationByHandle",
- "address": "0x1001058"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x100105c"
- },
- {
- "name": "FreeLibraryAndExitThread",
- "address": "0x1001060"
- },
- {
- "name": "GetFileAttributesW",
- "address": "0x1001064"
- },
- {
- "name": "Wow64RevertWow64FsRedirection",
- "address": "0x1001068"
- },
- {
- "name": "Wow64DisableWow64FsRedirection",
- "address": "0x100106c"
- },
- {
- "name": "IsWow64Process",
- "address": "0x1001070"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x1001074"
- },
- {
- "name": "CreateThread",
- "address": "0x1001078"
- },
- {
- "name": "LoadLibraryW",
- "address": "0x100107c"
- },
- {
- "name": "GetModuleFileNameW",
- "address": "0x1001080"
- },
- {
- "name": "CreateFileMappingW",
- "address": "0x1001084"
- },
- {
- "name": "FormatMessageW",
- "address": "0x1001088"
- },
- {
- "name": "MapViewOfFile",
- "address": "0x100108c"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x1001090"
- },
- {
- "name": "UnmapViewOfFile",
- "address": "0x1001094"
- },
- {
- "name": "LocalReAlloc",
- "address": "0x1001098"
- },
- {
- "name": "GetACP",
- "address": "0x100109c"
- },
- {
- "name": "DeleteFileW",
- "address": "0x10010a0"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x10010a4"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x10010a8"
- },
- {
- "name": "SetLastError",
- "address": "0x10010ac"
- },
- {
- "name": "WriteFile",
- "address": "0x10010b0"
- },
- {
- "name": "GetLastError",
- "address": "0x10010b4"
- },
- {
- "name": "LocalSize",
- "address": "0x10010b8"
- },
- {
- "name": "GetFullPathNameW",
- "address": "0x10010bc"
- },
- {
- "name": "MulDiv",
- "address": "0x10010c0"
- },
- {
- "name": "GetCommandLineW",
- "address": "0x10010c4"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x10010c8"
- },
- {
- "name": "FoldStringW",
- "address": "0x10010cc"
- },
- {
- "name": "lstrcmpW",
- "address": "0x10010d0"
- },
- {
- "name": "FindFirstFileW",
- "address": "0x10010d4"
- },
- {
- "name": "FindClose",
- "address": "0x10010d8"
- },
- {
- "name": "HeapSetInformation",
- "address": "0x10010dc"
- },
- {
- "name": "TerminateProcess",
- "address": "0x10010e0"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x10010e4"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x10010e8"
- },
- {
- "name": "GetTickCount",
- "address": "0x10010ec"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x10010f0"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x10010f4"
- },
- {
- "name": "SetUnhandledExceptionFilter",
- "address": "0x10010f8"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x10010fc"
- },
- {
- "name": "InterlockedCompareExchange",
- "address": "0x1001100"
- },
- {
- "name": "Sleep",
- "address": "0x1001104"
- },
- {
- "name": "LocalLock",
- "address": "0x1001108"
- },
- {
- "name": "LocalUnlock",
- "address": "0x100110c"
- },
- {
- "name": "lstrlenW",
- "address": "0x1001110"
- },
- {
- "name": "GetLocaleInfoW",
- "address": "0x1001114"
- },
- {
- "name": "GlobalFree",
- "address": "0x1001118"
- },
- {
- "name": "lstrcmpiW",
- "address": "0x100111c"
- },
- {
- "name": "SetErrorMode",
- "address": "0x1001120"
- },
- {
- "name": "CreateFileW",
- "address": "0x1001124"
- },
- {
- "name": "ReadFile",
- "address": "0x1001128"
- },
- {
- "name": "CloseHandle",
- "address": "0x100112c"
- },
- {
- "name": "LocalAlloc",
- "address": "0x1001130"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x1001134"
- },
- {
- "name": "LocalFree",
- "address": "0x1001138"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x100113c"
- },
- {
- "name": "GetVersionExW",
- "address": "0x1001140"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x1001144"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateFontIndirectW",
- "address": "0x100114c"
- },
- {
- "name": "SetMapMode",
- "address": "0x1001150"
- },
- {
- "name": "SetViewportExtEx",
- "address": "0x1001154"
- },
- {
- "name": "SetWindowExtEx",
- "address": "0x1001158"
- },
- {
- "name": "LPtoDP",
- "address": "0x100115c"
- },
- {
- "name": "SetBkMode",
- "address": "0x1001160"
- },
- {
- "name": "GetTextMetricsW",
- "address": "0x1001164"
- },
- {
- "name": "SetAbortProc",
- "address": "0x1001168"
- },
- {
- "name": "StartDocW",
- "address": "0x100116c"
- },
- {
- "name": "StartPage",
- "address": "0x1001170"
- },
- {
- "name": "EndPage",
- "address": "0x1001174"
- },
- {
- "name": "AbortDoc",
- "address": "0x1001178"
- },
- {
- "name": "EndDoc",
- "address": "0x100117c"
- },
- {
- "name": "DeleteDC",
- "address": "0x1001180"
- },
- {
- "name": "TextOutW",
- "address": "0x1001184"
- },
- {
- "name": "GetTextExtentPoint32W",
- "address": "0x1001188"
- },
- {
- "name": "CreateDCW",
- "address": "0x100118c"
- },
- {
- "name": "SelectObject",
- "address": "0x1001190"
- },
- {
- "name": "GetTextFaceW",
- "address": "0x1001194"
- },
- {
- "name": "EnumFontsW",
- "address": "0x1001198"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x100119c"
- },
- {
- "name": "DeleteObject",
- "address": "0x10011a0"
- }
- ],
- "dll": "GDI32.dll"
- },
- {
- "imports": [
- {
- "name": "SetActiveWindow",
- "address": "0x10011a8"
- },
- {
- "name": "GetKeyboardLayout",
- "address": "0x10011ac"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x10011b0"
- },
- {
- "name": "DefWindowProcW",
- "address": "0x10011b4"
- },
- {
- "name": "GetForegroundWindow",
- "address": "0x10011b8"
- },
- {
- "name": "IsIconic",
- "address": "0x10011bc"
- },
- {
- "name": "DestroyWindow",
- "address": "0x10011c0"
- },
- {
- "name": "MessageBeep",
- "address": "0x10011c4"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x10011c8"
- },
- {
- "name": "CharUpperW",
- "address": "0x10011cc"
- },
- {
- "name": "RegisterClassExW",
- "address": "0x10011d0"
- },
- {
- "name": "LoadImageW",
- "address": "0x10011d4"
- },
- {
- "name": "LoadCursorW",
- "address": "0x10011d8"
- },
- {
- "name": "SetWindowLongW",
- "address": "0x10011dc"
- },
- {
- "name": "LoadAcceleratorsW",
- "address": "0x10011e0"
- },
- {
- "name": "GetSystemMenu",
- "address": "0x10011e4"
- },
- {
- "name": "SetWindowPlacement",
- "address": "0x10011e8"
- },
- {
- "name": "CreateWindowExW",
- "address": "0x10011ec"
- },
- {
- "name": "RegisterWindowMessageW",
- "address": "0x10011f0"
- },
- {
- "name": "UpdateWindow",
- "address": "0x10011f4"
- },
- {
- "name": "InvalidateRect",
- "address": "0x10011f8"
- },
- {
- "name": "SetScrollPos",
- "address": "0x10011fc"
- },
- {
- "name": "GetWindowTextLengthW",
- "address": "0x1001200"
- },
- {
- "name": "GetWindowLongW",
- "address": "0x1001204"
- },
- {
- "name": "PeekMessageW",
- "address": "0x1001208"
- },
- {
- "name": "EnableWindow",
- "address": "0x100120c"
- },
- {
- "name": "DialogBoxParamW",
- "address": "0x1001210"
- },
- {
- "name": "CreateDialogParamW",
- "address": "0x1001214"
- },
- {
- "name": "GetWindowTextW",
- "address": "0x1001218"
- },
- {
- "name": "SetWindowPos",
- "address": "0x100121c"
- },
- {
- "name": "SetCursor",
- "address": "0x1001220"
- },
- {
- "name": "SetForegroundWindow",
- "address": "0x1001224"
- },
- {
- "name": "FindWindowW",
- "address": "0x1001228"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x100122c"
- },
- {
- "name": "MoveWindow",
- "address": "0x1001230"
- },
- {
- "name": "SendMessageW",
- "address": "0x1001234"
- },
- {
- "name": "CharNextW",
- "address": "0x1001238"
- },
- {
- "name": "CheckMenuItem",
- "address": "0x100123c"
- },
- {
- "name": "CloseClipboard",
- "address": "0x1001240"
- },
- {
- "name": "IsClipboardFormatAvailable",
- "address": "0x1001244"
- },
- {
- "name": "OpenClipboard",
- "address": "0x1001248"
- },
- {
- "name": "GetMenuState",
- "address": "0x100124c"
- },
- {
- "name": "EnableMenuItem",
- "address": "0x1001250"
- },
- {
- "name": "GetSubMenu",
- "address": "0x1001254"
- },
- {
- "name": "GetClientRect",
- "address": "0x1001258"
- },
- {
- "name": "UnhookWinEvent",
- "address": "0x100125c"
- },
- {
- "name": "GetFocus",
- "address": "0x1001260"
- },
- {
- "name": "GetMenu",
- "address": "0x1001264"
- },
- {
- "name": "MessageBoxW",
- "address": "0x1001268"
- },
- {
- "name": "WinHelpW",
- "address": "0x100126c"
- },
- {
- "name": "GetDlgCtrlID",
- "address": "0x1001270"
- },
- {
- "name": "ChildWindowFromPoint",
- "address": "0x1001274"
- },
- {
- "name": "GetDC",
- "address": "0x1001278"
- },
- {
- "name": "ShowWindow",
- "address": "0x100127c"
- },
- {
- "name": "DrawTextExW",
- "address": "0x1001280"
- },
- {
- "name": "ReleaseDC",
- "address": "0x1001284"
- },
- {
- "name": "LoadIconW",
- "address": "0x1001288"
- },
- {
- "name": "SetWinEventHook",
- "address": "0x100128c"
- },
- {
- "name": "GetMessageW",
- "address": "0x1001290"
- },
- {
- "name": "PostMessageW",
- "address": "0x1001294"
- },
- {
- "name": "IsDialogMessageW",
- "address": "0x1001298"
- },
- {
- "name": "TranslateAcceleratorW",
- "address": "0x100129c"
- },
- {
- "name": "EndDialog",
- "address": "0x10012a0"
- },
- {
- "name": "GetDlgItemTextW",
- "address": "0x10012a4"
- },
- {
- "name": "SetDlgItemTextW",
- "address": "0x10012a8"
- },
- {
- "name": "SetFocus",
- "address": "0x10012ac"
- },
- {
- "name": "SetWindowTextW",
- "address": "0x10012b0"
- },
- {
- "name": "GetParent",
- "address": "0x10012b4"
- },
- {
- "name": "LoadStringW",
- "address": "0x10012b8"
- },
- {
- "name": "SendDlgItemMessageW",
- "address": "0x10012bc"
- },
- {
- "name": "GetCursorPos",
- "address": "0x10012c0"
- },
- {
- "name": "ScreenToClient",
- "address": "0x10012c4"
- },
- {
- "name": "TranslateMessage",
- "address": "0x10012c8"
- },
- {
- "name": "GetAncestor",
- "address": "0x10012cc"
- },
- {
- "name": "DispatchMessageW",
- "address": "0x10012d0"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "_controlfp",
- "address": "0x10012d8"
- },
- {
- "name": "_vsnwprintf",
- "address": "0x10012dc"
- },
- {
- "name": "memset",
- "address": "0x10012e0"
- },
- {
- "name": "_wtol",
- "address": "0x10012e4"
- },
- {
- "name": "memcpy",
- "address": "0x10012e8"
- },
- {
- "name": "iswctype",
- "address": "0x10012ec"
- },
- {
- "name": "wcsncmp",
- "address": "0x10012f0"
- },
- {
- "name": "wcsrchr",
- "address": "0x10012f4"
- },
- {
- "name": "_except_handler4_common",
- "address": "0x10012f8"
- },
- {
- "name": "__p__fmode",
- "address": "0x10012fc"
- },
- {
- "name": "__p__commode",
- "address": "0x1001300"
- },
- {
- "name": "__setusermatherr",
- "address": "0x1001304"
- },
- {
- "name": "_amsg_exit",
- "address": "0x1001308"
- },
- {
- "name": "_initterm",
- "address": "0x100130c"
- },
- {
- "name": "_acmdln",
- "address": "0x1001310"
- },
- {
- "name": "exit",
- "address": "0x1001314"
- },
- {
- "name": "_ismbblead",
- "address": "0x1001318"
- },
- {
- "name": "_XcptFilter",
- "address": "0x100131c"
- },
- {
- "name": "__getmainargs",
- "address": "0x1001320"
- },
- {
- "name": "_cexit",
- "address": "0x1001324"
- },
- {
- "name": "_exit",
- "address": "0x1001328"
- },
- {
- "name": "?terminate@@YAXXZ",
- "address": "0x100132c"
- },
- {
- "name": "__set_app_type",
- "address": "0x1001330"
- }
- ],
- "dll": "msvcrt.dll"
- },
- {
- "imports": [
- {
- "name": "ReplaceTextW",
- "address": "0x1001338"
- },
- {
- "name": "PageSetupDlgW",
- "address": "0x100133c"
- },
- {
- "name": "PrintDlgExW",
- "address": "0x1001340"
- },
- {
- "name": "FindTextW",
- "address": "0x1001344"
- },
- {
- "name": "ChooseFontW",
- "address": "0x1001348"
- },
- {
- "name": "GetSaveFileNameW",
- "address": "0x100134c"
- },
- {
- "name": "CommDlgExtendedError",
- "address": "0x1001350"
- },
- {
- "name": "GetOpenFileNameW",
- "address": "0x1001354"
- },
- {
- "name": "GetFileTitleW",
- "address": "0x1001358"
- }
- ],
- "dll": "COMDLG32.dll"
- },
- {
- "imports": [
- {
- "name": "DragAcceptFiles",
- "address": "0x1001360"
- },
- {
- "name": "SHAddToRecentDocs",
- "address": "0x1001364"
- },
- {
- "name": "SHGetFolderPathW",
- "address": "0x1001368"
- },
- {
- "name": "SHCreateItemFromParsingName",
- "address": "0x100136c"
- },
- {
- "name": "ShellExecuteExW",
- "address": "0x1001370"
- },
- {
- "name": "DragQueryFileW",
- "address": "0x1001374"
- },
- {
- "name": "DragFinish",
- "address": "0x1001378"
- },
- {
- "name": "ShellAboutW",
- "address": "0x100137c"
- }
- ],
- "dll": "SHELL32.dll"
- },
- {
- "imports": [
- {
- "name": "OpenPrinterW",
- "address": "0x1001384"
- },
- {
- "name": "ClosePrinter",
- "address": "0x1001388"
- },
- {
- "name": "GetPrinterDriverW",
- "address": "0x100138c"
- }
- ],
- "dll": "WINSPOOL.DRV"
- },
- {
- "imports": [
- {
- "name": "CoInitializeEx",
- "address": "0x1001394"
- },
- {
- "name": "CoUninitialize",
- "address": "0x1001398"
- },
- {
- "name": "CoTaskMemAlloc",
- "address": "0x100139c"
- },
- {
- "name": "CoCreateInstance",
- "address": "0x10013a0"
- },
- {
- "name": "CoTaskMemFree",
- "address": "0x10013a4"
- },
- {
- "name": "CoInitialize",
- "address": "0x10013a8"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "PathIsFileSpecW",
- "address": "0x10013b0"
- },
- {
- "name": "SHStrDupW",
- "address": "0x10013b4"
- }
- ],
- "dll": "SHLWAPI.dll"
- },
- {
- "imports": [
- {
- "name": "CreatePropertySheetPageW",
- "address": "0x10013bc"
- },
- {
- "name": "PropertySheetW",
- "address": "0x10013c0"
- },
- {
- "name": "CreateStatusWindowW",
- "address": "0x10013c4"
- },
- {
- "name": null,
- "address": "0x10013c8"
- }
- ],
- "dll": "COMCTL32.dll"
- },
- {
- "imports": [
- {
- "name": "SysFreeString",
- "address": "0x10013d0"
- },
- {
- "name": "SysAllocString",
- "address": "0x10013d4"
- }
- ],
- "dll": "OLEAUT32.dll"
- },
- {
- "imports": [
- {
- "name": "WinSqmIncrementDWORD",
- "address": "0x10013dc"
- },
- {
- "name": "RtlInitUnicodeString",
- "address": "0x10013e0"
- },
- {
- "name": "NtQueryLicenseValue",
- "address": "0x10013e4"
- },
- {
- "name": "WinSqmAddToStream",
- "address": "0x10013e8"
- }
- ],
- "dll": "ntdll.dll"
- },
- {
- "imports": [
- {
- "name": "GetFileVersionInfoExW",
- "address": "0x10013f0"
- },
- {
- "name": "GetFileVersionInfoSizeExW",
- "address": "0x10013f4"
- },
- {
- "name": "VerQueryValueW",
- "address": "0x10013f8"
- }
- ],
- "dll": "VERSION.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00039741",
- "overlay": null,
- "imagebase": "0x01000000",
- "reported_checksum": "0x00039741",
- "icon_hash": null,
- "entrypoint": "0x01003689",
- "timestamp": "2009-07-13 23:41:03",
- "osversion": "6.1",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x0000a800",
- "entropy": "6.28",
- "raw_address": "0x00000400",
- "virtual_size": "0x0000a68c",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0000c000",
- "size_of_data": "0x00001000",
- "entropy": "0.76",
- "raw_address": "0x0000ac00",
- "virtual_size": "0x00002164",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0000f000",
- "size_of_data": "0x0001f200",
- "entropy": "7.37",
- "raw_address": "0x0000bc00",
- "virtual_size": "0x0001f160",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0002f000",
- "size_of_data": "0x00001000",
- "entropy": "6.43",
- "raw_address": "0x0002ae00",
- "virtual_size": "0x00000e34",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0000a048",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000012c"
- },
- {
- "virtual_address": "0x0000f000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x0001f160"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0002f000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000e34"
- },
- {
- "virtual_address": "0x0000b62c",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000038"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00006d58",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000040"
- },
- {
- "virtual_address": "0x00000278",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000128"
- },
- {
- "virtual_address": "0x00001000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000400"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "2a141685bec588fb7b12c50a8a40eb2b",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "notepad.pdb",
- "imported_dll_count": 14,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement