Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: ""
- [*] MalScore: 0.0
- [*] File Name: "Desktops.exe"
- [*] File Size: 116824
- [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- [*] SHA256: "5a4605c2bd6e363d92723bf54b0ae2c131ea9741373e66558e42220d2f79ba9c"
- [*] MD5: "1b389656d41d458413fb9e09f42105f5"
- [*] SHA1: "c415d6904ac23599ea53b4f8ee4acbba8bfeb0f2"
- [*] SHA512: "46a340986d6c1b77ba67a366edfff2d24419803c3f1177967cbf294af543729d7f34e93605cdb7a3dcb2e8cc00fb29259faf968b9f91562a5610c095c30700ea"
- [*] CRC32: "B51CBEC6"
- [*] SSDEEP: "1536:GeBT/Xgp1/wARe4wf10R72GRh1DPRtkFnFK/lXpXWFE2Ys+40RjlpRZHl+:GeB7gIB4HKm/lgYs+4ylD+"
- [*] Process Execution: [
- "Desktops.exe"
- ]
- [*] Signatures Detected: []
- [*] Started Service: []
- [*] Executed Commands: []
- [*] Mutexes: [
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1"
- ]
- [*] Modified Files: []
- [*] Deleted Files: []
- [*] Modified Registry Keys: [
- "HKEY_CURRENT_USER\\Software\\Sysinternals\\Desktops",
- "HKEY_CURRENT_USER\\Software\\Sysinternals\\Desktops\\EulaAccepted",
- "HKEY_CURRENT_USER\\Software\\Sysinternals\\Desktops\\OptionsShown",
- "HKEY_CURRENT_USER\\Software\\Sysinternals\\Desktops\\HotkeyModifiers",
- "HKEY_CURRENT_USER\\Software\\Sysinternals\\Desktops\\HotkeyIsFunction"
- ]
- [*] Deleted Registry Keys: [
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Sysinternals Desktops"
- ]
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "GetStringTypeA",
- "address": "0x412088"
- },
- {
- "name": "LCMapStringW",
- "address": "0x41208c"
- },
- {
- "name": "LCMapStringA",
- "address": "0x412090"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x412094"
- },
- {
- "name": "RtlUnwind",
- "address": "0x412098"
- },
- {
- "name": "InitializeCriticalSectionAndSpinCount",
- "address": "0x41209c"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x4120a0"
- },
- {
- "name": "GetConsoleMode",
- "address": "0x4120a4"
- },
- {
- "name": "GetConsoleCP",
- "address": "0x4120a8"
- },
- {
- "name": "SetFilePointer",
- "address": "0x4120ac"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x4120b0"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x4120b4"
- },
- {
- "name": "GetTickCount",
- "address": "0x4120b8"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x4120bc"
- },
- {
- "name": "GetFileType",
- "address": "0x4120c0"
- },
- {
- "name": "SetHandleCount",
- "address": "0x4120c4"
- },
- {
- "name": "GetEnvironmentStringsW",
- "address": "0x4120c8"
- },
- {
- "name": "GetStringTypeW",
- "address": "0x4120cc"
- },
- {
- "name": "GetCommandLineW",
- "address": "0x4120d0"
- },
- {
- "name": "GetEnvironmentStrings",
- "address": "0x4120d4"
- },
- {
- "name": "FreeEnvironmentStringsA",
- "address": "0x4120d8"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x4120dc"
- },
- {
- "name": "GetStdHandle",
- "address": "0x4120e0"
- },
- {
- "name": "WriteFile",
- "address": "0x4120e4"
- },
- {
- "name": "IsValidCodePage",
- "address": "0x4120e8"
- },
- {
- "name": "GetOEMCP",
- "address": "0x4120ec"
- },
- {
- "name": "GetACP",
- "address": "0x4120f0"
- },
- {
- "name": "GetCPInfo",
- "address": "0x4120f4"
- },
- {
- "name": "HeapSize",
- "address": "0x4120f8"
- },
- {
- "name": "ExitProcess",
- "address": "0x4120fc"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x412100"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x412104"
- },
- {
- "name": "SetLastError",
- "address": "0x412108"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x41210c"
- },
- {
- "name": "TlsFree",
- "address": "0x412110"
- },
- {
- "name": "TlsSetValue",
- "address": "0x412114"
- },
- {
- "name": "TlsAlloc",
- "address": "0x412118"
- },
- {
- "name": "TlsGetValue",
- "address": "0x41211c"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x412120"
- },
- {
- "name": "SetStdHandle",
- "address": "0x412124"
- },
- {
- "name": "WriteConsoleA",
- "address": "0x412128"
- },
- {
- "name": "GetConsoleOutputCP",
- "address": "0x41212c"
- },
- {
- "name": "WriteConsoleW",
- "address": "0x412130"
- },
- {
- "name": "CreateFileA",
- "address": "0x412134"
- },
- {
- "name": "FlushFileBuffers",
- "address": "0x412138"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x41213c"
- },
- {
- "name": "LocalAlloc",
- "address": "0x412140"
- },
- {
- "name": "LocalFree",
- "address": "0x412144"
- },
- {
- "name": "CreateProcessW",
- "address": "0x412148"
- },
- {
- "name": "GetVersion",
- "address": "0x41214c"
- },
- {
- "name": "CloseHandle",
- "address": "0x412150"
- },
- {
- "name": "CreateEventW",
- "address": "0x412154"
- },
- {
- "name": "GetProcAddress",
- "address": "0x412158"
- },
- {
- "name": "GetLastError",
- "address": "0x41215c"
- },
- {
- "name": "GetModuleFileNameW",
- "address": "0x412160"
- },
- {
- "name": "FormatMessageW",
- "address": "0x412164"
- },
- {
- "name": "Sleep",
- "address": "0x412168"
- },
- {
- "name": "LoadLibraryW",
- "address": "0x41216c"
- },
- {
- "name": "GetModuleHandleW",
- "address": "0x412170"
- },
- {
- "name": "GetSystemWindowsDirectoryW",
- "address": "0x412174"
- },
- {
- "name": "FreeEnvironmentStringsW",
- "address": "0x412178"
- },
- {
- "name": "HeapReAlloc",
- "address": "0x41217c"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x412180"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x412184"
- },
- {
- "name": "HeapFree",
- "address": "0x412188"
- },
- {
- "name": "ExitThread",
- "address": "0x41218c"
- },
- {
- "name": "ResumeThread",
- "address": "0x412190"
- },
- {
- "name": "CreateThread",
- "address": "0x412194"
- },
- {
- "name": "HeapAlloc",
- "address": "0x412198"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x41219c"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x4121a0"
- },
- {
- "name": "TerminateProcess",
- "address": "0x4121a4"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x4121a8"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x4121ac"
- },
- {
- "name": "SetUnhandledExceptionFilter",
- "address": "0x4121b0"
- },
- {
- "name": "IsDebuggerPresent",
- "address": "0x4121b4"
- },
- {
- "name": "HeapCreate",
- "address": "0x4121b8"
- },
- {
- "name": "VirtualFree",
- "address": "0x4121bc"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x4121c0"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x4121c4"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x4121c8"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "DialogBoxIndirectParamW",
- "address": "0x4121dc"
- },
- {
- "name": "InflateRect",
- "address": "0x4121e0"
- },
- {
- "name": "SetWindowTextW",
- "address": "0x4121e4"
- },
- {
- "name": "CreateDesktopW",
- "address": "0x4121e8"
- },
- {
- "name": "DestroyWindow",
- "address": "0x4121ec"
- },
- {
- "name": "SetCursor",
- "address": "0x4121f0"
- },
- {
- "name": "TranslateAcceleratorW",
- "address": "0x4121f4"
- },
- {
- "name": "GetWindowRect",
- "address": "0x4121f8"
- },
- {
- "name": "SetActiveWindow",
- "address": "0x4121fc"
- },
- {
- "name": "GetMessageW",
- "address": "0x412200"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x412204"
- },
- {
- "name": "TrackPopupMenu",
- "address": "0x412208"
- },
- {
- "name": "RegisterWindowMessageW",
- "address": "0x41220c"
- },
- {
- "name": "PostMessageW",
- "address": "0x412210"
- },
- {
- "name": "GetKeyState",
- "address": "0x412214"
- },
- {
- "name": "SetForegroundWindow",
- "address": "0x412218"
- },
- {
- "name": "DialogBoxParamW",
- "address": "0x41221c"
- },
- {
- "name": "LoadCursorW",
- "address": "0x412220"
- },
- {
- "name": "CallNextHookEx",
- "address": "0x412224"
- },
- {
- "name": "OpenDesktopW",
- "address": "0x412228"
- },
- {
- "name": "FindWindowW",
- "address": "0x41222c"
- },
- {
- "name": "GetClientRect",
- "address": "0x412230"
- },
- {
- "name": "SetFocus",
- "address": "0x412234"
- },
- {
- "name": "GetDC",
- "address": "0x412238"
- },
- {
- "name": "TranslateMessage",
- "address": "0x41223c"
- },
- {
- "name": "LoadAcceleratorsW",
- "address": "0x412240"
- },
- {
- "name": "ChildWindowFromPoint",
- "address": "0x412244"
- },
- {
- "name": "LoadIconW",
- "address": "0x412248"
- },
- {
- "name": "OffsetRect",
- "address": "0x41224c"
- },
- {
- "name": "InvalidateRect",
- "address": "0x412250"
- },
- {
- "name": "BringWindowToTop",
- "address": "0x412254"
- },
- {
- "name": "SystemParametersInfoW",
- "address": "0x412258"
- },
- {
- "name": "ReleaseDC",
- "address": "0x41225c"
- },
- {
- "name": "GetDlgItem",
- "address": "0x412260"
- },
- {
- "name": "EndDialog",
- "address": "0x412264"
- },
- {
- "name": "GetSysColor",
- "address": "0x412268"
- },
- {
- "name": "SetWindowPos",
- "address": "0x41226c"
- },
- {
- "name": "GetCursorPos",
- "address": "0x412270"
- },
- {
- "name": "CheckDlgButton",
- "address": "0x412274"
- },
- {
- "name": "ShowWindow",
- "address": "0x412278"
- },
- {
- "name": "CreatePopupMenu",
- "address": "0x41227c"
- },
- {
- "name": "GetSysColorBrush",
- "address": "0x412280"
- },
- {
- "name": "IsDlgButtonChecked",
- "address": "0x412284"
- },
- {
- "name": "SwitchDesktop",
- "address": "0x412288"
- },
- {
- "name": "SetThreadDesktop",
- "address": "0x41228c"
- },
- {
- "name": "CreateWindowExW",
- "address": "0x412290"
- },
- {
- "name": "InsertMenuW",
- "address": "0x412294"
- },
- {
- "name": "SetWindowsHookExW",
- "address": "0x412298"
- },
- {
- "name": "MessageBoxW",
- "address": "0x41229c"
- },
- {
- "name": "RegisterClassW",
- "address": "0x4122a0"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x4122a4"
- },
- {
- "name": "SendMessageW",
- "address": "0x4122a8"
- },
- {
- "name": "UnregisterHotKey",
- "address": "0x4122ac"
- },
- {
- "name": "DestroyMenu",
- "address": "0x4122b0"
- },
- {
- "name": "RegisterHotKey",
- "address": "0x4122b4"
- },
- {
- "name": "DefWindowProcW",
- "address": "0x4122b8"
- },
- {
- "name": "MoveWindow",
- "address": "0x4122bc"
- },
- {
- "name": "DispatchMessageW",
- "address": "0x4122c0"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x4122c4"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "StartPage",
- "address": "0x412038"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x41203c"
- },
- {
- "name": "SetMapMode",
- "address": "0x412040"
- },
- {
- "name": "StartDocW",
- "address": "0x412044"
- },
- {
- "name": "EndDoc",
- "address": "0x412048"
- },
- {
- "name": "BitBlt",
- "address": "0x41204c"
- },
- {
- "name": "SetTextColor",
- "address": "0x412050"
- },
- {
- "name": "DeleteDC",
- "address": "0x412054"
- },
- {
- "name": "CreateFontIndirectW",
- "address": "0x412058"
- },
- {
- "name": "StretchBlt",
- "address": "0x41205c"
- },
- {
- "name": "SetBkMode",
- "address": "0x412060"
- },
- {
- "name": "DeleteObject",
- "address": "0x412064"
- },
- {
- "name": "SelectObject",
- "address": "0x412068"
- },
- {
- "name": "CreateCompatibleDC",
- "address": "0x41206c"
- },
- {
- "name": "CreateCompatibleBitmap",
- "address": "0x412070"
- },
- {
- "name": "GetObjectW",
- "address": "0x412074"
- },
- {
- "name": "SetStretchBltMode",
- "address": "0x412078"
- },
- {
- "name": "GetStockObject",
- "address": "0x41207c"
- },
- {
- "name": "EndPage",
- "address": "0x412080"
- }
- ],
- "dll": "GDI32.dll"
- },
- {
- "imports": [
- {
- "name": "PrintDlgW",
- "address": "0x412030"
- }
- ],
- "dll": "COMDLG32.dll"
- },
- {
- "imports": [
- {
- "name": "RegCreateKeyW",
- "address": "0x412000"
- },
- {
- "name": "RegSetValueExW",
- "address": "0x412004"
- },
- {
- "name": "RegCloseKey",
- "address": "0x412008"
- },
- {
- "name": "GetSecurityDescriptorSacl",
- "address": "0x41200c"
- },
- {
- "name": "RegOpenKeyExW",
- "address": "0x412010"
- },
- {
- "name": "SetSecurityInfo",
- "address": "0x412014"
- },
- {
- "name": "ConvertStringSecurityDescriptorToSecurityDescriptorW",
- "address": "0x412018"
- },
- {
- "name": "RegDeleteValueW",
- "address": "0x41201c"
- },
- {
- "name": "RegOpenKeyW",
- "address": "0x412020"
- },
- {
- "name": "RegQueryValueExW",
- "address": "0x412024"
- },
- {
- "name": "RegCreateKeyExW",
- "address": "0x412028"
- }
- ],
- "dll": "ADVAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "ShellExecuteW",
- "address": "0x4121d0"
- },
- {
- "name": "Shell_NotifyIconW",
- "address": "0x4121d4"
- }
- ],
- "dll": "SHELL32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00025bb5",
- "overlay": {
- "size": "0x00001a58",
- "offset": "0x0001ae00"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x00025bb5",
- "icon_hash": null,
- "entrypoint": "0x004046c6",
- "timestamp": "2012-10-16 23:17:52",
- "osversion": "5.0",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00010200",
- "entropy": "6.66",
- "raw_address": "0x00000400",
- "virtual_size": "0x0001014d",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00012000",
- "size_of_data": "0x00005800",
- "entropy": "5.39",
- "raw_address": "0x00010600",
- "virtual_size": "0x000056a6",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00018000",
- "size_of_data": "0x00001400",
- "entropy": "3.32",
- "raw_address": "0x00015e00",
- "virtual_size": "0x00002fd8",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0001b000",
- "size_of_data": "0x00002400",
- "entropy": "3.87",
- "raw_address": "0x00017200",
- "virtual_size": "0x000023c4",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0001e000",
- "size_of_data": "0x00001800",
- "entropy": "4.86",
- "raw_address": "0x00019600",
- "virtual_size": "0x00001684",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0001670c",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000008c"
- },
- {
- "virtual_address": "0x0001b000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x000023c4"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0001ae00",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00001a58"
- },
- {
- "virtual_address": "0x0001e000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000e5c"
- },
- {
- "virtual_address": "0x00012320",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00016280",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000040"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00012000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x000002cc"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "c8681af63c4b3bc7041fe674efea6dd2",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "c:\\src\\Desktops\\Release\\Desktops.pdb",
- "imported_dll_count": 6,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "kernel32.dll.FlsAlloc",
- "kernel32.dll.FlsGetValue",
- "kernel32.dll.FlsSetValue",
- "kernel32.dll.FlsFree",
- "kernel32.dll.IsProcessorFeaturePresent",
- "shell32.dll.CommandLineToArgvW",
- "uxtheme.dll.ThemeInitApiHook",
- "user32.dll.IsProcessDPIAware",
- "dwmapi.dll.DwmIsCompositionEnabled",
- "comctl32.dll.RegisterClassNameW",
- "uxtheme.dll.EnableThemeDialogTexture",
- "uxtheme.dll.OpenThemeData",
- "uxtheme.dll.GetThemeBool",
- "comctl32.dll.HIMAGELIST_QueryInterface",
- "comctl32.dll.DrawShadowText",
- "comctl32.dll.DrawSizeBox",
- "comctl32.dll.DrawScrollBar",
- "comctl32.dll.SizeBoxHwnd",
- "comctl32.dll.ScrollBar_MouseMove",
- "comctl32.dll.ScrollBar_Menu",
- "comctl32.dll.HandleScrollCmd",
- "comctl32.dll.DetachScrollBars",
- "comctl32.dll.AttachScrollBars",
- "comctl32.dll.CCSetScrollInfo",
- "comctl32.dll.CCGetScrollInfo",
- "comctl32.dll.CCEnableScrollBar",
- "comctl32.dll.QuerySystemGestureStatus",
- "uxtheme.dll.#49",
- "uxtheme.dll.CloseThemeData",
- "gdi32.dll.GetLayout",
- "gdi32.dll.GdiRealizationInfo",
- "gdi32.dll.FontIsLinked",
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegQueryInfoKeyW",
- "gdi32.dll.GetTextFaceAliasW",
- "advapi32.dll.RegEnumValueW",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.RegQueryValueExW",
- "gdi32.dll.GetFontAssocStatus",
- "advapi32.dll.RegQueryValueExA",
- "advapi32.dll.RegEnumKeyExW",
- "gdi32.dll.GdiIsMetaPrintDC",
- "ole32.dll.CoInitializeEx",
- "ole32.dll.CoUninitialize",
- "cryptbase.dll.SystemFunction036",
- "ole32.dll.CoRegisterInitializeSpy",
- "ole32.dll.CoRevokeInitializeSpy",
- "uxtheme.dll.BufferedPaintInit",
- "uxtheme.dll.BufferedPaintRenderAnimation",
- "uxtheme.dll.GetThemeTransitionDuration",
- "uxtheme.dll.BeginBufferedAnimation",
- "uxtheme.dll.IsThemeBackgroundPartiallyTransparent",
- "uxtheme.dll.DrawThemeParentBackground",
- "uxtheme.dll.DrawThemeBackground",
- "uxtheme.dll.GetThemeBackgroundContentRect",
- "uxtheme.dll.DrawThemeText",
- "uxtheme.dll.EndBufferedAnimation",
- "uxtheme.dll.GetThemePartSize",
- "uxtheme.dll.BufferedPaintStopAllAnimations",
- "uxtheme.dll.BufferedPaintUnInit",
- "user32.dll.SetProcessDPIAware",
- "shell32.dll.#66",
- "ole32.dll.CoTaskMemFree",
- "kernel32.dll.Wow64EnableWow64FsRedirection",
- "kernel32.dll.Wow64DisableWow64FsRedirection",
- "user32.dll.SwitchDesktopWithFade"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "GetStringTypeA",
- "address": "0x412088"
- },
- {
- "name": "LCMapStringW",
- "address": "0x41208c"
- },
- {
- "name": "LCMapStringA",
- "address": "0x412090"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x412094"
- },
- {
- "name": "RtlUnwind",
- "address": "0x412098"
- },
- {
- "name": "InitializeCriticalSectionAndSpinCount",
- "address": "0x41209c"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x4120a0"
- },
- {
- "name": "GetConsoleMode",
- "address": "0x4120a4"
- },
- {
- "name": "GetConsoleCP",
- "address": "0x4120a8"
- },
- {
- "name": "SetFilePointer",
- "address": "0x4120ac"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x4120b0"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x4120b4"
- },
- {
- "name": "GetTickCount",
- "address": "0x4120b8"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x4120bc"
- },
- {
- "name": "GetFileType",
- "address": "0x4120c0"
- },
- {
- "name": "SetHandleCount",
- "address": "0x4120c4"
- },
- {
- "name": "GetEnvironmentStringsW",
- "address": "0x4120c8"
- },
- {
- "name": "GetStringTypeW",
- "address": "0x4120cc"
- },
- {
- "name": "GetCommandLineW",
- "address": "0x4120d0"
- },
- {
- "name": "GetEnvironmentStrings",
- "address": "0x4120d4"
- },
- {
- "name": "FreeEnvironmentStringsA",
- "address": "0x4120d8"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x4120dc"
- },
- {
- "name": "GetStdHandle",
- "address": "0x4120e0"
- },
- {
- "name": "WriteFile",
- "address": "0x4120e4"
- },
- {
- "name": "IsValidCodePage",
- "address": "0x4120e8"
- },
- {
- "name": "GetOEMCP",
- "address": "0x4120ec"
- },
- {
- "name": "GetACP",
- "address": "0x4120f0"
- },
- {
- "name": "GetCPInfo",
- "address": "0x4120f4"
- },
- {
- "name": "HeapSize",
- "address": "0x4120f8"
- },
- {
- "name": "ExitProcess",
- "address": "0x4120fc"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x412100"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x412104"
- },
- {
- "name": "SetLastError",
- "address": "0x412108"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x41210c"
- },
- {
- "name": "TlsFree",
- "address": "0x412110"
- },
- {
- "name": "TlsSetValue",
- "address": "0x412114"
- },
- {
- "name": "TlsAlloc",
- "address": "0x412118"
- },
- {
- "name": "TlsGetValue",
- "address": "0x41211c"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x412120"
- },
- {
- "name": "SetStdHandle",
- "address": "0x412124"
- },
- {
- "name": "WriteConsoleA",
- "address": "0x412128"
- },
- {
- "name": "GetConsoleOutputCP",
- "address": "0x41212c"
- },
- {
- "name": "WriteConsoleW",
- "address": "0x412130"
- },
- {
- "name": "CreateFileA",
- "address": "0x412134"
- },
- {
- "name": "FlushFileBuffers",
- "address": "0x412138"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x41213c"
- },
- {
- "name": "LocalAlloc",
- "address": "0x412140"
- },
- {
- "name": "LocalFree",
- "address": "0x412144"
- },
- {
- "name": "CreateProcessW",
- "address": "0x412148"
- },
- {
- "name": "GetVersion",
- "address": "0x41214c"
- },
- {
- "name": "CloseHandle",
- "address": "0x412150"
- },
- {
- "name": "CreateEventW",
- "address": "0x412154"
- },
- {
- "name": "GetProcAddress",
- "address": "0x412158"
- },
- {
- "name": "GetLastError",
- "address": "0x41215c"
- },
- {
- "name": "GetModuleFileNameW",
- "address": "0x412160"
- },
- {
- "name": "FormatMessageW",
- "address": "0x412164"
- },
- {
- "name": "Sleep",
- "address": "0x412168"
- },
- {
- "name": "LoadLibraryW",
- "address": "0x41216c"
- },
- {
- "name": "GetModuleHandleW",
- "address": "0x412170"
- },
- {
- "name": "GetSystemWindowsDirectoryW",
- "address": "0x412174"
- },
- {
- "name": "FreeEnvironmentStringsW",
- "address": "0x412178"
- },
- {
- "name": "HeapReAlloc",
- "address": "0x41217c"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x412180"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x412184"
- },
- {
- "name": "HeapFree",
- "address": "0x412188"
- },
- {
- "name": "ExitThread",
- "address": "0x41218c"
- },
- {
- "name": "ResumeThread",
- "address": "0x412190"
- },
- {
- "name": "CreateThread",
- "address": "0x412194"
- },
- {
- "name": "HeapAlloc",
- "address": "0x412198"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x41219c"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x4121a0"
- },
- {
- "name": "TerminateProcess",
- "address": "0x4121a4"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x4121a8"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x4121ac"
- },
- {
- "name": "SetUnhandledExceptionFilter",
- "address": "0x4121b0"
- },
- {
- "name": "IsDebuggerPresent",
- "address": "0x4121b4"
- },
- {
- "name": "HeapCreate",
- "address": "0x4121b8"
- },
- {
- "name": "VirtualFree",
- "address": "0x4121bc"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x4121c0"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x4121c4"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x4121c8"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "DialogBoxIndirectParamW",
- "address": "0x4121dc"
- },
- {
- "name": "InflateRect",
- "address": "0x4121e0"
- },
- {
- "name": "SetWindowTextW",
- "address": "0x4121e4"
- },
- {
- "name": "CreateDesktopW",
- "address": "0x4121e8"
- },
- {
- "name": "DestroyWindow",
- "address": "0x4121ec"
- },
- {
- "name": "SetCursor",
- "address": "0x4121f0"
- },
- {
- "name": "TranslateAcceleratorW",
- "address": "0x4121f4"
- },
- {
- "name": "GetWindowRect",
- "address": "0x4121f8"
- },
- {
- "name": "SetActiveWindow",
- "address": "0x4121fc"
- },
- {
- "name": "GetMessageW",
- "address": "0x412200"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x412204"
- },
- {
- "name": "TrackPopupMenu",
- "address": "0x412208"
- },
- {
- "name": "RegisterWindowMessageW",
- "address": "0x41220c"
- },
- {
- "name": "PostMessageW",
- "address": "0x412210"
- },
- {
- "name": "GetKeyState",
- "address": "0x412214"
- },
- {
- "name": "SetForegroundWindow",
- "address": "0x412218"
- },
- {
- "name": "DialogBoxParamW",
- "address": "0x41221c"
- },
- {
- "name": "LoadCursorW",
- "address": "0x412220"
- },
- {
- "name": "CallNextHookEx",
- "address": "0x412224"
- },
- {
- "name": "OpenDesktopW",
- "address": "0x412228"
- },
- {
- "name": "FindWindowW",
- "address": "0x41222c"
- },
- {
- "name": "GetClientRect",
- "address": "0x412230"
- },
- {
- "name": "SetFocus",
- "address": "0x412234"
- },
- {
- "name": "GetDC",
- "address": "0x412238"
- },
- {
- "name": "TranslateMessage",
- "address": "0x41223c"
- },
- {
- "name": "LoadAcceleratorsW",
- "address": "0x412240"
- },
- {
- "name": "ChildWindowFromPoint",
- "address": "0x412244"
- },
- {
- "name": "LoadIconW",
- "address": "0x412248"
- },
- {
- "name": "OffsetRect",
- "address": "0x41224c"
- },
- {
- "name": "InvalidateRect",
- "address": "0x412250"
- },
- {
- "name": "BringWindowToTop",
- "address": "0x412254"
- },
- {
- "name": "SystemParametersInfoW",
- "address": "0x412258"
- },
- {
- "name": "ReleaseDC",
- "address": "0x41225c"
- },
- {
- "name": "GetDlgItem",
- "address": "0x412260"
- },
- {
- "name": "EndDialog",
- "address": "0x412264"
- },
- {
- "name": "GetSysColor",
- "address": "0x412268"
- },
- {
- "name": "SetWindowPos",
- "address": "0x41226c"
- },
- {
- "name": "GetCursorPos",
- "address": "0x412270"
- },
- {
- "name": "CheckDlgButton",
- "address": "0x412274"
- },
- {
- "name": "ShowWindow",
- "address": "0x412278"
- },
- {
- "name": "CreatePopupMenu",
- "address": "0x41227c"
- },
- {
- "name": "GetSysColorBrush",
- "address": "0x412280"
- },
- {
- "name": "IsDlgButtonChecked",
- "address": "0x412284"
- },
- {
- "name": "SwitchDesktop",
- "address": "0x412288"
- },
- {
- "name": "SetThreadDesktop",
- "address": "0x41228c"
- },
- {
- "name": "CreateWindowExW",
- "address": "0x412290"
- },
- {
- "name": "InsertMenuW",
- "address": "0x412294"
- },
- {
- "name": "SetWindowsHookExW",
- "address": "0x412298"
- },
- {
- "name": "MessageBoxW",
- "address": "0x41229c"
- },
- {
- "name": "RegisterClassW",
- "address": "0x4122a0"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x4122a4"
- },
- {
- "name": "SendMessageW",
- "address": "0x4122a8"
- },
- {
- "name": "UnregisterHotKey",
- "address": "0x4122ac"
- },
- {
- "name": "DestroyMenu",
- "address": "0x4122b0"
- },
- {
- "name": "RegisterHotKey",
- "address": "0x4122b4"
- },
- {
- "name": "DefWindowProcW",
- "address": "0x4122b8"
- },
- {
- "name": "MoveWindow",
- "address": "0x4122bc"
- },
- {
- "name": "DispatchMessageW",
- "address": "0x4122c0"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x4122c4"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "StartPage",
- "address": "0x412038"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x41203c"
- },
- {
- "name": "SetMapMode",
- "address": "0x412040"
- },
- {
- "name": "StartDocW",
- "address": "0x412044"
- },
- {
- "name": "EndDoc",
- "address": "0x412048"
- },
- {
- "name": "BitBlt",
- "address": "0x41204c"
- },
- {
- "name": "SetTextColor",
- "address": "0x412050"
- },
- {
- "name": "DeleteDC",
- "address": "0x412054"
- },
- {
- "name": "CreateFontIndirectW",
- "address": "0x412058"
- },
- {
- "name": "StretchBlt",
- "address": "0x41205c"
- },
- {
- "name": "SetBkMode",
- "address": "0x412060"
- },
- {
- "name": "DeleteObject",
- "address": "0x412064"
- },
- {
- "name": "SelectObject",
- "address": "0x412068"
- },
- {
- "name": "CreateCompatibleDC",
- "address": "0x41206c"
- },
- {
- "name": "CreateCompatibleBitmap",
- "address": "0x412070"
- },
- {
- "name": "GetObjectW",
- "address": "0x412074"
- },
- {
- "name": "SetStretchBltMode",
- "address": "0x412078"
- },
- {
- "name": "GetStockObject",
- "address": "0x41207c"
- },
- {
- "name": "EndPage",
- "address": "0x412080"
- }
- ],
- "dll": "GDI32.dll"
- },
- {
- "imports": [
- {
- "name": "PrintDlgW",
- "address": "0x412030"
- }
- ],
- "dll": "COMDLG32.dll"
- },
- {
- "imports": [
- {
- "name": "RegCreateKeyW",
- "address": "0x412000"
- },
- {
- "name": "RegSetValueExW",
- "address": "0x412004"
- },
- {
- "name": "RegCloseKey",
- "address": "0x412008"
- },
- {
- "name": "GetSecurityDescriptorSacl",
- "address": "0x41200c"
- },
- {
- "name": "RegOpenKeyExW",
- "address": "0x412010"
- },
- {
- "name": "SetSecurityInfo",
- "address": "0x412014"
- },
- {
- "name": "ConvertStringSecurityDescriptorToSecurityDescriptorW",
- "address": "0x412018"
- },
- {
- "name": "RegDeleteValueW",
- "address": "0x41201c"
- },
- {
- "name": "RegOpenKeyW",
- "address": "0x412020"
- },
- {
- "name": "RegQueryValueExW",
- "address": "0x412024"
- },
- {
- "name": "RegCreateKeyExW",
- "address": "0x412028"
- }
- ],
- "dll": "ADVAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "ShellExecuteW",
- "address": "0x4121d0"
- },
- {
- "name": "Shell_NotifyIconW",
- "address": "0x4121d4"
- }
- ],
- "dll": "SHELL32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00025bb5",
- "overlay": {
- "size": "0x00001a58",
- "offset": "0x0001ae00"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x00025bb5",
- "icon_hash": null,
- "entrypoint": "0x004046c6",
- "timestamp": "2012-10-16 23:17:52",
- "osversion": "5.0",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00010200",
- "entropy": "6.66",
- "raw_address": "0x00000400",
- "virtual_size": "0x0001014d",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00012000",
- "size_of_data": "0x00005800",
- "entropy": "5.39",
- "raw_address": "0x00010600",
- "virtual_size": "0x000056a6",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00018000",
- "size_of_data": "0x00001400",
- "entropy": "3.32",
- "raw_address": "0x00015e00",
- "virtual_size": "0x00002fd8",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0001b000",
- "size_of_data": "0x00002400",
- "entropy": "3.87",
- "raw_address": "0x00017200",
- "virtual_size": "0x000023c4",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0001e000",
- "size_of_data": "0x00001800",
- "entropy": "4.86",
- "raw_address": "0x00019600",
- "virtual_size": "0x00001684",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0001670c",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000008c"
- },
- {
- "virtual_address": "0x0001b000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x000023c4"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0001ae00",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00001a58"
- },
- {
- "virtual_address": "0x0001e000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000e5c"
- },
- {
- "virtual_address": "0x00012320",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00016280",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000040"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00012000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x000002cc"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "c8681af63c4b3bc7041fe674efea6dd2",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "c:\\src\\Desktops\\Release\\Desktops.pdb",
- "imported_dll_count": 6,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement