Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: "Malicious"
- [*] MalScore: 10.0
- [*] File Name: "Exes_41791113.exe"
- [*] File Size: 249424
- [*] File Type: "PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows"
- [*] SHA256: "361bd552b278cf0d956b787abd984b6c86413d668492613782f856040d8200a0"
- [*] MD5: "e222299ef243f72a0d45db64601146d3"
- [*] SHA1: "e87bdc834dddd85b5b9b931eaccac03a5caabf81"
- [*] SHA512: "683c5879edd98b9ed0b71c11bfc0857b2fe2a240d73105e78600c24352c094ceb0cdb6eb78fe22a721d4d1946c034afc0d0240b61f62038a5fd4c1bfb80dae14"
- [*] CRC32: "41791113"
- [*] SSDEEP: "6144:nz8PozQ7aGHY0E/p0VTJq+9wm0/UH0Of:nz8QJGHY0ExGq+9wmV"
- [*] Process Execution: [
- "Exes_41791113.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "Performs some HTTP requests",
- "Details": [
- {
- "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D"
- },
- {
- "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D"
- },
- {
- "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D"
- }
- ]
- },
- {
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details": [
- {
- "section": "name: .text, entropy: 7.55, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x0003a800, virtual_size: 0x0003a734"
- }
- ]
- },
- {
- "Description": "File has been identified by 24 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "FireEye": "Generic.mg.e222299ef243f72a"
- },
- {
- "Qihoo-360": "HEUR/QVM03.0.CD1F.Malware.Gen"
- },
- {
- "McAfee": "RDN/Generic.dx"
- },
- {
- "Cylance": "Unsafe"
- },
- {
- "AegisLab": "Trojan.Multi.Generic.4!c"
- },
- {
- "Alibaba": "Trojan:Win32/Malmail.ali1000112"
- },
- {
- "Cybereason": "malicious.34dddd"
- },
- {
- "Symantec": "ML.Attribute.HighConfidence"
- },
- {
- "APEX": "Malicious"
- },
- {
- "Paloalto": "generic.ml"
- },
- {
- "Kaspersky": "UDS:DangerousObject.Multi.Generic"
- },
- {
- "Endgame": "malicious (high confidence)"
- },
- {
- "Invincea": "heuristic"
- },
- {
- "McAfee-GW-Edition": "Artemis!Trojan"
- },
- {
- "Trapmine": "suspicious.low.ml.score"
- },
- {
- "SentinelOne": "DFI - Malicious PE"
- },
- {
- "Microsoft": "Trojan:Win32/Fuerboos.A!cl"
- },
- {
- "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
- },
- {
- "ESET-NOD32": "a variant of MSIL/Kryptik.RPQ"
- },
- {
- "Acronis": "suspicious"
- },
- {
- "Panda": "Trj/Genetic.gen"
- },
- {
- "eGambit": "PE.Heur.InvalidSig"
- },
- {
- "AVG": "FileRepMalware"
- },
- {
- "CrowdStrike": "win/malicious_confidence_90% (W)"
- }
- ]
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: []
- [*] Mutexes: []
- [*] Modified Files: []
- [*] Deleted Files: []
- [*] Modified Registry Keys: []
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: [
- {
- "count": 1,
- "body": "",
- "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "ocsp.digicert.com",
- "version": "1.1",
- "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D",
- "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D HTTP/1.1\r\nCache-Control: max-age = 150849\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Tue, 28 May 2019 10:50:30 GMT\r\nIf-None-Match: \"5ced1276-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
- "port": 80
- },
- {
- "count": 1,
- "body": "",
- "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "ocsp.digicert.com",
- "version": "1.1",
- "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D",
- "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D HTTP/1.1\r\nCache-Control: max-age = 135176\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Tue, 28 May 2019 05:30:18 GMT\r\nIf-None-Match: \"5cecc76a-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
- "port": 80
- },
- {
- "count": 1,
- "body": "",
- "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "ocsp.digicert.com",
- "version": "1.1",
- "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D",
- "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D HTTP/1.1\r\nCache-Control: max-age = 168744\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Tue, 28 May 2019 15:00:08 GMT\r\nIf-None-Match: \"5ced4cf8-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
- "port": 80
- }
- ]
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "dotnet": {
- "customattrs": [
- {
- "type": "Assembly",
- "name": "[mscorlib]System.Reflection.AssemblyFileVersionAttribute",
- "value": "3.5.6"
- },
- {
- "type": "Assembly",
- "name": "[mscorlib]System.Runtime.InteropServices.GuidAttribute",
- "value": "a81bbd62-66f2-4cca-875a-d8f4e7d254"
- },
- {
- "type": "Assembly",
- "name": "[mscorlib]System.Reflection.AssemblyTitleAttribute",
- "value": "ocajetuq"
- },
- {
- "type": "Assembly",
- "name": "[mscorlib]System.Reflection.AssemblyProductAttribute",
- "value": "ocajetuq"
- },
- {
- "type": "Assembly",
- "name": "[mscorlib]System.Reflection.AssemblyCopyrightAttribute",
- "value": "Copyright \\xc2\\xa9 20"
- },
- {
- "type": "Assembly",
- "name": "[mscorlib]System.Reflection.AssemblyCompanyAttribute",
- "value": "itenobadoqutixaq"
- },
- {
- "type": "Assembly",
- "name": "[mscorlib]System.Reflection.AssemblyDescriptionAttribute",
- "value": "egagigotefowic"
- },
- {
- "type": "Property",
- "name": "[System]System.Configuration.DefaultSettingValueAttribute",
- "value": ""
- },
- {
- "type": "Property",
- "name": "[System]System.Configuration.DefaultSettingValueAttribute",
- "value": "10"
- }
- ],
- "assemblyinfo": {
- "version": "1.0.0.0",
- "name": "Ee5wspujSyfTSwNplYaweoOnKA=="
- },
- "assemblyrefs": [
- {
- "version": "4.0.0.0",
- "name": "mscorlib"
- },
- {
- "version": "4.0.0.0",
- "name": "System"
- },
- {
- "version": "1.0.0.1",
- "name": "gdi32"
- }
- ],
- "typerefs": [
- {
- "typename": "System.CodeDom.Compiler.GeneratedCodeAttribute",
- "assembly": "System"
- },
- {
- "typename": "System.Collections.Specialized.StringDictionary",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.EditorBrowsableAttribute",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.EditorBrowsableState",
- "assembly": "System"
- },
- {
- "typename": "System.Configuration.ApplicationSettingsBase",
- "assembly": "System"
- },
- {
- "typename": "System.Configuration.DefaultSettingValueAttribute",
- "assembly": "System"
- },
- {
- "typename": "System.Configuration.SettingsBase",
- "assembly": "System"
- },
- {
- "typename": "System.Configuration.UserScopedSettingAttribute",
- "assembly": "System"
- },
- {
- "typename": "gdi32.Program",
- "assembly": "gdi32"
- },
- {
- "typename": "System.AppDomain",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Array",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.AsyncCallback",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Boolean",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Buffer",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Byte",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Char",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.CharEnumerator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.ICollection",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IEnumerable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Console",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.DBNull",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.DateTime",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Delegate",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggerNonUserCodeAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Enum",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Exception",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.CultureInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.NumberStyles",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.UnicodeCategory",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IAsyncResult",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IComparable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IFormatProvider",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Int16",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Int32",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Int64",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.MulticastDelegate",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.NotSupportedException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Object",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Assembly",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyCompanyAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyConfigurationAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyCopyrightAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyDescriptionAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyFileVersionAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyProductAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyTitleAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyTrademarkAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.BindingFlags",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.CallingConventions",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MethodBase",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MethodInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.ParameterInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.ParameterModifier",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.PropertyInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ResolveEventArgs",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ResolveEventHandler",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Resources.ResourceManager",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilationRelaxationsAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilerGeneratedAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.RuntimeCompatibilityAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.RuntimeHelpers",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.InteropServices.ComVisibleAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.InteropServices.GuidAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.InteropServices._Type",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.Remoting.ObjectHandle",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.Serialization.ISerializable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.Versioning.TargetFrameworkAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.RuntimeFieldHandle",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.RuntimeTypeHandle",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.SByte",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.STAThreadAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.String",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.StringComparison",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.StringSplitOptions",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Text.StringBuilder",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Thread",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.TimeSpan",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Type",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.TypeCode",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.UInt16",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.UInt32",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.UInt64",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ValueType",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Void",
- "assembly": "mscorlib"
- }
- ]
- },
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "_CorExeMain",
- "address": "0x402000"
- }
- ],
- "dll": "mscoree.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x000435b0",
- "overlay": {
- "size": "0x00001c50",
- "offset": "0x0003b200"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x0043c72e",
- "timestamp": "2006-04-13 05:55:54",
- "osversion": "4.0",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00002000",
- "size_of_data": "0x0003a800",
- "entropy": "7.55",
- "raw_address": "0x00000200",
- "virtual_size": "0x0003a734",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0003e000",
- "size_of_data": "0x00000600",
- "entropy": "4.45",
- "raw_address": "0x0003aa00",
- "virtual_size": "0x00000600",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00040000",
- "size_of_data": "0x00000200",
- "entropy": "0.10",
- "raw_address": "0x0003b000",
- "virtual_size": "0x0000000c",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0003c6dc",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000004f"
- },
- {
- "virtual_address": "0x0003e000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00000600"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0003b200",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00001c50"
- },
- {
- "virtual_address": "0x00040000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x0000000c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000008"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002008",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000048"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "f34d5f2d4577ed6d9ceec516c1f5a744",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 1,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegQueryInfoKeyW",
- "advapi32.dll.RegEnumKeyExW",
- "advapi32.dll.RegEnumValueW",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.RegQueryValueExW",
- "kernel32.dll.QueryActCtxW",
- "shlwapi.dll.UrlIsW"
- ]
- [*] Static Analysis: {
- "dotnet": {
- "customattrs": [
- {
- "type": "Assembly",
- "name": "[mscorlib]System.Reflection.AssemblyFileVersionAttribute",
- "value": "3.5.6"
- },
- {
- "type": "Assembly",
- "name": "[mscorlib]System.Runtime.InteropServices.GuidAttribute",
- "value": "a81bbd62-66f2-4cca-875a-d8f4e7d254"
- },
- {
- "type": "Assembly",
- "name": "[mscorlib]System.Reflection.AssemblyTitleAttribute",
- "value": "ocajetuq"
- },
- {
- "type": "Assembly",
- "name": "[mscorlib]System.Reflection.AssemblyProductAttribute",
- "value": "ocajetuq"
- },
- {
- "type": "Assembly",
- "name": "[mscorlib]System.Reflection.AssemblyCopyrightAttribute",
- "value": "Copyright \\xc2\\xa9 20"
- },
- {
- "type": "Assembly",
- "name": "[mscorlib]System.Reflection.AssemblyCompanyAttribute",
- "value": "itenobadoqutixaq"
- },
- {
- "type": "Assembly",
- "name": "[mscorlib]System.Reflection.AssemblyDescriptionAttribute",
- "value": "egagigotefowic"
- },
- {
- "type": "Property",
- "name": "[System]System.Configuration.DefaultSettingValueAttribute",
- "value": ""
- },
- {
- "type": "Property",
- "name": "[System]System.Configuration.DefaultSettingValueAttribute",
- "value": "10"
- }
- ],
- "assemblyinfo": {
- "version": "1.0.0.0",
- "name": "Ee5wspujSyfTSwNplYaweoOnKA=="
- },
- "assemblyrefs": [
- {
- "version": "4.0.0.0",
- "name": "mscorlib"
- },
- {
- "version": "4.0.0.0",
- "name": "System"
- },
- {
- "version": "1.0.0.1",
- "name": "gdi32"
- }
- ],
- "typerefs": [
- {
- "typename": "System.CodeDom.Compiler.GeneratedCodeAttribute",
- "assembly": "System"
- },
- {
- "typename": "System.Collections.Specialized.StringDictionary",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.EditorBrowsableAttribute",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.EditorBrowsableState",
- "assembly": "System"
- },
- {
- "typename": "System.Configuration.ApplicationSettingsBase",
- "assembly": "System"
- },
- {
- "typename": "System.Configuration.DefaultSettingValueAttribute",
- "assembly": "System"
- },
- {
- "typename": "System.Configuration.SettingsBase",
- "assembly": "System"
- },
- {
- "typename": "System.Configuration.UserScopedSettingAttribute",
- "assembly": "System"
- },
- {
- "typename": "gdi32.Program",
- "assembly": "gdi32"
- },
- {
- "typename": "System.AppDomain",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Array",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.AsyncCallback",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Boolean",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Buffer",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Byte",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Char",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.CharEnumerator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.ICollection",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IEnumerable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Console",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.DBNull",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.DateTime",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Delegate",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggerNonUserCodeAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Enum",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Exception",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.CultureInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.NumberStyles",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.UnicodeCategory",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IAsyncResult",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IComparable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IFormatProvider",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Int16",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Int32",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Int64",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.MulticastDelegate",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.NotSupportedException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Object",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Assembly",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyCompanyAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyConfigurationAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyCopyrightAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyDescriptionAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyFileVersionAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyProductAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyTitleAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyTrademarkAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.BindingFlags",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.CallingConventions",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MethodBase",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MethodInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.ParameterInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.ParameterModifier",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.PropertyInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ResolveEventArgs",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ResolveEventHandler",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Resources.ResourceManager",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilationRelaxationsAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilerGeneratedAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.RuntimeCompatibilityAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.RuntimeHelpers",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.InteropServices.ComVisibleAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.InteropServices.GuidAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.InteropServices._Type",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.Remoting.ObjectHandle",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.Serialization.ISerializable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.Versioning.TargetFrameworkAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.RuntimeFieldHandle",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.RuntimeTypeHandle",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.SByte",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.STAThreadAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.String",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.StringComparison",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.StringSplitOptions",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Text.StringBuilder",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Thread",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.TimeSpan",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Type",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.TypeCode",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.UInt16",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.UInt32",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.UInt64",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ValueType",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Void",
- "assembly": "mscorlib"
- }
- ]
- },
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "_CorExeMain",
- "address": "0x402000"
- }
- ],
- "dll": "mscoree.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x000435b0",
- "overlay": {
- "size": "0x00001c50",
- "offset": "0x0003b200"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x0043c72e",
- "timestamp": "2006-04-13 05:55:54",
- "osversion": "4.0",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00002000",
- "size_of_data": "0x0003a800",
- "entropy": "7.55",
- "raw_address": "0x00000200",
- "virtual_size": "0x0003a734",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0003e000",
- "size_of_data": "0x00000600",
- "entropy": "4.45",
- "raw_address": "0x0003aa00",
- "virtual_size": "0x00000600",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00040000",
- "size_of_data": "0x00000200",
- "entropy": "0.10",
- "raw_address": "0x0003b000",
- "virtual_size": "0x0000000c",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0003c6dc",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000004f"
- },
- {
- "virtual_address": "0x0003e000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00000600"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0003b200",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00001c50"
- },
- {
- "virtual_address": "0x00040000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x0000000c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000008"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002008",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000048"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "f34d5f2d4577ed6d9ceec516c1f5a744",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 1,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement