Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: "Malicious"
- [*] MalScore: 10.0
- [*] File Name: "9874100"
- [*] File Size: 599040
- [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- [*] SHA256: "b4fc798fde165d6d17631a3c6c982a383f32d4abedc460fe8a650ace5f258fef"
- [*] MD5: "7b0c155d7ec7fcd784eeda3873ac3e51"
- [*] SHA1: "7750c072b0c37bb2c73c1f3b3c8f052b71e55616"
- [*] SHA512: "c451b5e52b2325683c5937257467528797f22b41cd3b057fc22535c49f2d73bea436455e742690412daaf789e6e08dab22cc6e17cc1bb4a1bb1f7ada2d4ec0be"
- [*] CRC32: "E0F57D3C"
- [*] SSDEEP: "12288:9fIKMF//5bkMof1NHR+SAlOOkS6tlKs0FQLHJ:VvMZ54MINHRFACZ/DuuJ"
- [*] Process Execution: [
- "9874100.exe",
- "isou.exe",
- "isou.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details": [
- {
- "IP": "185.79.156.23:80"
- }
- ]
- },
- {
- "Description": "Creates RWX memory",
- "Details": []
- },
- {
- "Description": "Possible date expiration check, exits too soon after checking local time",
- "Details": [
- {
- "process": "isou.exe, PID 200"
- }
- ]
- },
- {
- "Description": "Drops a binary and executes it",
- "Details": [
- {
- "binary": "C:\\Users\\user\\AppData\\Roaming\\lsiwk\\isou.exe"
- }
- ]
- },
- {
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details": [
- {
- "section": "name: .rsrc, entropy: 7.22, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ, raw_size: 0x00026c00, virtual_size: 0x00026ad4"
- }
- ]
- },
- {
- "Description": "Executed a process and injected code into it, probably while unpacking",
- "Details": [
- {
- "Injection": "isou.exe(1168) -> isou.exe(200)"
- }
- ]
- },
- {
- "Description": "Installs itself for autorun at Windows startup",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\lsiwk.vbs"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\lsiwk.vbs"
- }
- ]
- },
- {
- "Description": "File has been identified by 28 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "MicroWorld-eScan": "Gen:Variant.Strictor.198030"
- },
- {
- "FireEye": "Generic.mg.7b0c155d7ec7fcd7"
- },
- {
- "Qihoo-360": "HEUR/QVM05.1.CF1B.Malware.Gen"
- },
- {
- "McAfee": "Artemis!7B0C155D7EC7"
- },
- {
- "BitDefender": "Gen:Variant.Strictor.198030"
- },
- {
- "K7GW": "Riskware ( 0040eff71 )"
- },
- {
- "K7AntiVirus": "Riskware ( 0040eff71 )"
- },
- {
- "Invincea": "heuristic"
- },
- {
- "Symantec": "ML.Attribute.HighConfidence"
- },
- {
- "APEX": "Malicious"
- },
- {
- "Paloalto": "generic.ml"
- },
- {
- "Kaspersky": "UDS:DangerousObject.Multi.Generic"
- },
- {
- "Endgame": "malicious (high confidence)"
- },
- {
- "TrendMicro": "TSPY_HPFAREIT.SMROX"
- },
- {
- "McAfee-GW-Edition": "BehavesLike.Win32.Fareit.hh"
- },
- {
- "Webroot": "W32.Rogue.Gen"
- },
- {
- "Microsoft": "Trojan:Win32/Fuerboos.E!cl"
- },
- {
- "AhnLab-V3": "Win-Trojan/Delphiless.Exp"
- },
- {
- "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
- },
- {
- "ESET-NOD32": "a variant of Win32/Injector.EFYV"
- },
- {
- "Acronis": "suspicious"
- },
- {
- "Cylance": "Unsafe"
- },
- {
- "TrendMicro-HouseCall": "TSPY_HPFAREIT.SMROX"
- },
- {
- "Fortinet": "W32/GenKryptik.CEMY!tr"
- },
- {
- "AVG": "Win32:Malware-gen"
- },
- {
- "Cybereason": "malicious.2b0c37"
- },
- {
- "Avast": "Win32:Malware-gen"
- },
- {
- "CrowdStrike": "win/malicious_confidence_80% (D)"
- }
- ]
- },
- {
- "Description": "Creates a copy of itself",
- "Details": [
- {
- "copy": "C:\\Users\\user\\AppData\\Roaming\\lsiwk\\isou.exe"
- }
- ]
- },
- {
- "Description": "Attempts to interact with an Alternate Data Stream (ADS)",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\lsiwk\\isou.exe:ZoneIdentifier"
- }
- ]
- },
- {
- "Description": "Collects information to fingerprint the system",
- "Details": []
- },
- {
- "Description": "Anomalous binary characteristics",
- "Details": [
- {
- "anomaly": "Timestamp on binary predates the release date of the OS version it requires by at least a year"
- }
- ]
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: [
- "\"C:\\Users\\user\\AppData\\Roaming\\lsiwk\\isou.exe\""
- ]
- [*] Mutexes: [
- "A81FB8C6-0BBE6E18-6FC9B5DB-536DA455-933946726"
- ]
- [*] Modified Files: [
- "C:\\Users\\user\\AppData\\Roaming\\lsiwk\\isou.exe",
- "C:\\Users\\user\\AppData\\Roaming\\lsiwk\\isou.exe:ZoneIdentifier",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\lsiwk.vbs"
- ]
- [*] Deleted Files: [
- "C:\\Users\\user\\AppData\\Roaming\\lsiwk\\isou.exe",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\lsiwk.vbs"
- ]
- [*] Modified Registry Keys: []
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DeleteCriticalSection",
- "address": "0x466140"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x466144"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x466148"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x46614c"
- },
- {
- "name": "VirtualFree",
- "address": "0x466150"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x466154"
- },
- {
- "name": "LocalFree",
- "address": "0x466158"
- },
- {
- "name": "LocalAlloc",
- "address": "0x46615c"
- },
- {
- "name": "GetVersion",
- "address": "0x466160"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x466164"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x466168"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x46616c"
- },
- {
- "name": "VirtualQuery",
- "address": "0x466170"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x466174"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x466178"
- },
- {
- "name": "lstrlenA",
- "address": "0x46617c"
- },
- {
- "name": "lstrcpynA",
- "address": "0x466180"
- },
- {
- "name": "LoadLibraryExA",
- "address": "0x466184"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x466188"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x46618c"
- },
- {
- "name": "GetProcAddress",
- "address": "0x466190"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x466194"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x466198"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x46619c"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x4661a0"
- },
- {
- "name": "FreeLibrary",
- "address": "0x4661a4"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x4661a8"
- },
- {
- "name": "FindClose",
- "address": "0x4661ac"
- },
- {
- "name": "ExitProcess",
- "address": "0x4661b0"
- },
- {
- "name": "WriteFile",
- "address": "0x4661b4"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x4661b8"
- },
- {
- "name": "RtlUnwind",
- "address": "0x4661bc"
- },
- {
- "name": "RaiseException",
- "address": "0x4661c0"
- },
- {
- "name": "GetStdHandle",
- "address": "0x4661c4"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "GetKeyboardType",
- "address": "0x4661cc"
- },
- {
- "name": "LoadStringA",
- "address": "0x4661d0"
- },
- {
- "name": "MessageBoxA",
- "address": "0x4661d4"
- },
- {
- "name": "CharNextA",
- "address": "0x4661d8"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x4661e0"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x4661e4"
- },
- {
- "name": "RegCloseKey",
- "address": "0x4661e8"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "SysFreeString",
- "address": "0x4661f0"
- },
- {
- "name": "SysReAllocStringLen",
- "address": "0x4661f4"
- },
- {
- "name": "SysAllocStringLen",
- "address": "0x4661f8"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "TlsSetValue",
- "address": "0x466200"
- },
- {
- "name": "TlsGetValue",
- "address": "0x466204"
- },
- {
- "name": "LocalAlloc",
- "address": "0x466208"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x46620c"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x466214"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x466218"
- },
- {
- "name": "RegCloseKey",
- "address": "0x46621c"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "lstrcpyA",
- "address": "0x466224"
- },
- {
- "name": "WriteFile",
- "address": "0x466228"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x46622c"
- },
- {
- "name": "VirtualQuery",
- "address": "0x466230"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x466234"
- },
- {
- "name": "Sleep",
- "address": "0x466238"
- },
- {
- "name": "SizeofResource",
- "address": "0x46623c"
- },
- {
- "name": "SetThreadLocale",
- "address": "0x466240"
- },
- {
- "name": "SetFilePointer",
- "address": "0x466244"
- },
- {
- "name": "SetEvent",
- "address": "0x466248"
- },
- {
- "name": "SetErrorMode",
- "address": "0x46624c"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x466250"
- },
- {
- "name": "ResetEvent",
- "address": "0x466254"
- },
- {
- "name": "ReadFile",
- "address": "0x466258"
- },
- {
- "name": "MulDiv",
- "address": "0x46625c"
- },
- {
- "name": "LockResource",
- "address": "0x466260"
- },
- {
- "name": "LoadResource",
- "address": "0x466264"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x466268"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x46626c"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x466270"
- },
- {
- "name": "GlobalUnlock",
- "address": "0x466274"
- },
- {
- "name": "GlobalSize",
- "address": "0x466278"
- },
- {
- "name": "GlobalReAlloc",
- "address": "0x46627c"
- },
- {
- "name": "GlobalHandle",
- "address": "0x466280"
- },
- {
- "name": "GlobalLock",
- "address": "0x466284"
- },
- {
- "name": "GlobalFree",
- "address": "0x466288"
- },
- {
- "name": "GlobalFindAtomA",
- "address": "0x46628c"
- },
- {
- "name": "GlobalDeleteAtom",
- "address": "0x466290"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x466294"
- },
- {
- "name": "GlobalAddAtomA",
- "address": "0x466298"
- },
- {
- "name": "GetVersionExA",
- "address": "0x46629c"
- },
- {
- "name": "GetVersion",
- "address": "0x4662a0"
- },
- {
- "name": "GetTickCount",
- "address": "0x4662a4"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x4662a8"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x4662ac"
- },
- {
- "name": "GetStringTypeExA",
- "address": "0x4662b0"
- },
- {
- "name": "GetStdHandle",
- "address": "0x4662b4"
- },
- {
- "name": "GetProfileStringA",
- "address": "0x4662b8"
- },
- {
- "name": "GetProcAddress",
- "address": "0x4662bc"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x4662c0"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x4662c4"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x4662c8"
- },
- {
- "name": "GetLocalTime",
- "address": "0x4662cc"
- },
- {
- "name": "GetLastError",
- "address": "0x4662d0"
- },
- {
- "name": "GetFullPathNameA",
- "address": "0x4662d4"
- },
- {
- "name": "GetDiskFreeSpaceA",
- "address": "0x4662d8"
- },
- {
- "name": "GetDateFormatA",
- "address": "0x4662dc"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x4662e0"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x4662e4"
- },
- {
- "name": "GetCPInfo",
- "address": "0x4662e8"
- },
- {
- "name": "GetACP",
- "address": "0x4662ec"
- },
- {
- "name": "FreeResource",
- "address": "0x4662f0"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x4662f4"
- },
- {
- "name": "FreeLibrary",
- "address": "0x4662f8"
- },
- {
- "name": "FormatMessageA",
- "address": "0x4662fc"
- },
- {
- "name": "FindResourceA",
- "address": "0x466300"
- },
- {
- "name": "EnumCalendarInfoA",
- "address": "0x466304"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x466308"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x46630c"
- },
- {
- "name": "CreateThread",
- "address": "0x466310"
- },
- {
- "name": "CreateFileA",
- "address": "0x466314"
- },
- {
- "name": "CreateEventA",
- "address": "0x466318"
- },
- {
- "name": "CompareStringA",
- "address": "0x46631c"
- },
- {
- "name": "CloseHandle",
- "address": "0x466320"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "VerQueryValueA",
- "address": "0x466328"
- },
- {
- "name": "GetFileVersionInfoSizeA",
- "address": "0x46632c"
- },
- {
- "name": "GetFileVersionInfoA",
- "address": "0x466330"
- }
- ],
- "dll": "version.dll"
- },
- {
- "imports": [
- {
- "name": "UnrealizeObject",
- "address": "0x466338"
- },
- {
- "name": "StretchBlt",
- "address": "0x46633c"
- },
- {
- "name": "SetWindowOrgEx",
- "address": "0x466340"
- },
- {
- "name": "SetViewportOrgEx",
- "address": "0x466344"
- },
- {
- "name": "SetTextColor",
- "address": "0x466348"
- },
- {
- "name": "SetStretchBltMode",
- "address": "0x46634c"
- },
- {
- "name": "SetROP2",
- "address": "0x466350"
- },
- {
- "name": "SetPixel",
- "address": "0x466354"
- },
- {
- "name": "SetDIBColorTable",
- "address": "0x466358"
- },
- {
- "name": "SetBrushOrgEx",
- "address": "0x46635c"
- },
- {
- "name": "SetBkMode",
- "address": "0x466360"
- },
- {
- "name": "SetBkColor",
- "address": "0x466364"
- },
- {
- "name": "SelectPalette",
- "address": "0x466368"
- },
- {
- "name": "SelectObject",
- "address": "0x46636c"
- },
- {
- "name": "ScaleWindowExtEx",
- "address": "0x466370"
- },
- {
- "name": "SaveDC",
- "address": "0x466374"
- },
- {
- "name": "RestoreDC",
- "address": "0x466378"
- },
- {
- "name": "Rectangle",
- "address": "0x46637c"
- },
- {
- "name": "RectVisible",
- "address": "0x466380"
- },
- {
- "name": "RealizePalette",
- "address": "0x466384"
- },
- {
- "name": "PatBlt",
- "address": "0x466388"
- },
- {
- "name": "MoveToEx",
- "address": "0x46638c"
- },
- {
- "name": "MaskBlt",
- "address": "0x466390"
- },
- {
- "name": "LineTo",
- "address": "0x466394"
- },
- {
- "name": "IntersectClipRect",
- "address": "0x466398"
- },
- {
- "name": "GetWindowOrgEx",
- "address": "0x46639c"
- },
- {
- "name": "GetTextMetricsA",
- "address": "0x4663a0"
- },
- {
- "name": "GetTextExtentPoint32A",
- "address": "0x4663a4"
- },
- {
- "name": "GetSystemPaletteEntries",
- "address": "0x4663a8"
- },
- {
- "name": "GetStockObject",
- "address": "0x4663ac"
- },
- {
- "name": "GetPixel",
- "address": "0x4663b0"
- },
- {
- "name": "GetPaletteEntries",
- "address": "0x4663b4"
- },
- {
- "name": "GetObjectA",
- "address": "0x4663b8"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x4663bc"
- },
- {
- "name": "GetDIBits",
- "address": "0x4663c0"
- },
- {
- "name": "GetDIBColorTable",
- "address": "0x4663c4"
- },
- {
- "name": "GetDCOrgEx",
- "address": "0x4663c8"
- },
- {
- "name": "GetCurrentPositionEx",
- "address": "0x4663cc"
- },
- {
- "name": "GetClipBox",
- "address": "0x4663d0"
- },
- {
- "name": "GetBrushOrgEx",
- "address": "0x4663d4"
- },
- {
- "name": "GetBitmapBits",
- "address": "0x4663d8"
- },
- {
- "name": "ExtTextOutA",
- "address": "0x4663dc"
- },
- {
- "name": "ExcludeClipRect",
- "address": "0x4663e0"
- },
- {
- "name": "EndPage",
- "address": "0x4663e4"
- },
- {
- "name": "EndDoc",
- "address": "0x4663e8"
- },
- {
- "name": "DeleteObject",
- "address": "0x4663ec"
- },
- {
- "name": "DeleteDC",
- "address": "0x4663f0"
- },
- {
- "name": "CreateSolidBrush",
- "address": "0x4663f4"
- },
- {
- "name": "CreatePenIndirect",
- "address": "0x4663f8"
- },
- {
- "name": "CreatePen",
- "address": "0x4663fc"
- },
- {
- "name": "CreatePalette",
- "address": "0x466400"
- },
- {
- "name": "CreateICA",
- "address": "0x466404"
- },
- {
- "name": "CreateHalftonePalette",
- "address": "0x466408"
- },
- {
- "name": "CreateFontIndirectA",
- "address": "0x46640c"
- },
- {
- "name": "CreateDIBitmap",
- "address": "0x466410"
- },
- {
- "name": "CreateDIBSection",
- "address": "0x466414"
- },
- {
- "name": "CreateDCA",
- "address": "0x466418"
- },
- {
- "name": "CreateCompatibleDC",
- "address": "0x46641c"
- },
- {
- "name": "CreateCompatibleBitmap",
- "address": "0x466420"
- },
- {
- "name": "CreateBrushIndirect",
- "address": "0x466424"
- },
- {
- "name": "CreateBitmap",
- "address": "0x466428"
- },
- {
- "name": "BitBlt",
- "address": "0x46642c"
- }
- ],
- "dll": "gdi32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateWindowExA",
- "address": "0x466434"
- },
- {
- "name": "WindowFromPoint",
- "address": "0x466438"
- },
- {
- "name": "WinHelpA",
- "address": "0x46643c"
- },
- {
- "name": "WaitMessage",
- "address": "0x466440"
- },
- {
- "name": "ValidateRect",
- "address": "0x466444"
- },
- {
- "name": "UpdateWindow",
- "address": "0x466448"
- },
- {
- "name": "UnregisterClassA",
- "address": "0x46644c"
- },
- {
- "name": "UnhookWindowsHookEx",
- "address": "0x466450"
- },
- {
- "name": "TranslateMessage",
- "address": "0x466454"
- },
- {
- "name": "TranslateMDISysAccel",
- "address": "0x466458"
- },
- {
- "name": "TrackPopupMenu",
- "address": "0x46645c"
- },
- {
- "name": "SystemParametersInfoA",
- "address": "0x466460"
- },
- {
- "name": "ShowWindow",
- "address": "0x466464"
- },
- {
- "name": "ShowScrollBar",
- "address": "0x466468"
- },
- {
- "name": "ShowOwnedPopups",
- "address": "0x46646c"
- },
- {
- "name": "ShowCursor",
- "address": "0x466470"
- },
- {
- "name": "SetWindowsHookExA",
- "address": "0x466474"
- },
- {
- "name": "SetWindowTextA",
- "address": "0x466478"
- },
- {
- "name": "SetWindowPos",
- "address": "0x46647c"
- },
- {
- "name": "SetWindowPlacement",
- "address": "0x466480"
- },
- {
- "name": "SetWindowLongA",
- "address": "0x466484"
- },
- {
- "name": "SetTimer",
- "address": "0x466488"
- },
- {
- "name": "SetScrollRange",
- "address": "0x46648c"
- },
- {
- "name": "SetScrollPos",
- "address": "0x466490"
- },
- {
- "name": "SetScrollInfo",
- "address": "0x466494"
- },
- {
- "name": "SetRect",
- "address": "0x466498"
- },
- {
- "name": "SetPropA",
- "address": "0x46649c"
- },
- {
- "name": "SetParent",
- "address": "0x4664a0"
- },
- {
- "name": "SetMenuItemInfoA",
- "address": "0x4664a4"
- },
- {
- "name": "SetMenu",
- "address": "0x4664a8"
- },
- {
- "name": "SetForegroundWindow",
- "address": "0x4664ac"
- },
- {
- "name": "SetFocus",
- "address": "0x4664b0"
- },
- {
- "name": "SetCursor",
- "address": "0x4664b4"
- },
- {
- "name": "SetClassLongA",
- "address": "0x4664b8"
- },
- {
- "name": "SetCapture",
- "address": "0x4664bc"
- },
- {
- "name": "SetActiveWindow",
- "address": "0x4664c0"
- },
- {
- "name": "SendMessageA",
- "address": "0x4664c4"
- },
- {
- "name": "ScrollWindow",
- "address": "0x4664c8"
- },
- {
- "name": "ScreenToClient",
- "address": "0x4664cc"
- },
- {
- "name": "RemovePropA",
- "address": "0x4664d0"
- },
- {
- "name": "RemoveMenu",
- "address": "0x4664d4"
- },
- {
- "name": "ReleaseDC",
- "address": "0x4664d8"
- },
- {
- "name": "ReleaseCapture",
- "address": "0x4664dc"
- },
- {
- "name": "RegisterWindowMessageA",
- "address": "0x4664e0"
- },
- {
- "name": "RegisterClipboardFormatA",
- "address": "0x4664e4"
- },
- {
- "name": "RegisterClassA",
- "address": "0x4664e8"
- },
- {
- "name": "RedrawWindow",
- "address": "0x4664ec"
- },
- {
- "name": "PtInRect",
- "address": "0x4664f0"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x4664f4"
- },
- {
- "name": "PostMessageA",
- "address": "0x4664f8"
- },
- {
- "name": "PeekMessageA",
- "address": "0x4664fc"
- },
- {
- "name": "OffsetRect",
- "address": "0x466500"
- },
- {
- "name": "OemToCharA",
- "address": "0x466504"
- },
- {
- "name": "MessageBoxA",
- "address": "0x466508"
- },
- {
- "name": "MapWindowPoints",
- "address": "0x46650c"
- },
- {
- "name": "MapVirtualKeyA",
- "address": "0x466510"
- },
- {
- "name": "LoadStringA",
- "address": "0x466514"
- },
- {
- "name": "LoadKeyboardLayoutA",
- "address": "0x466518"
- },
- {
- "name": "LoadIconA",
- "address": "0x46651c"
- },
- {
- "name": "LoadCursorA",
- "address": "0x466520"
- },
- {
- "name": "LoadBitmapA",
- "address": "0x466524"
- },
- {
- "name": "KillTimer",
- "address": "0x466528"
- },
- {
- "name": "IsZoomed",
- "address": "0x46652c"
- },
- {
- "name": "IsWindowVisible",
- "address": "0x466530"
- },
- {
- "name": "IsWindowEnabled",
- "address": "0x466534"
- },
- {
- "name": "IsWindow",
- "address": "0x466538"
- },
- {
- "name": "IsRectEmpty",
- "address": "0x46653c"
- },
- {
- "name": "IsIconic",
- "address": "0x466540"
- },
- {
- "name": "IsDialogMessageA",
- "address": "0x466544"
- },
- {
- "name": "IsChild",
- "address": "0x466548"
- },
- {
- "name": "InvalidateRect",
- "address": "0x46654c"
- },
- {
- "name": "IntersectRect",
- "address": "0x466550"
- },
- {
- "name": "InsertMenuItemA",
- "address": "0x466554"
- },
- {
- "name": "InsertMenuA",
- "address": "0x466558"
- },
- {
- "name": "InflateRect",
- "address": "0x46655c"
- },
- {
- "name": "GetWindowThreadProcessId",
- "address": "0x466560"
- },
- {
- "name": "GetWindowTextA",
- "address": "0x466564"
- },
- {
- "name": "GetWindowRect",
- "address": "0x466568"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x46656c"
- },
- {
- "name": "GetWindowLongA",
- "address": "0x466570"
- },
- {
- "name": "GetWindowDC",
- "address": "0x466574"
- },
- {
- "name": "GetTopWindow",
- "address": "0x466578"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x46657c"
- },
- {
- "name": "GetSystemMenu",
- "address": "0x466580"
- },
- {
- "name": "GetSysColorBrush",
- "address": "0x466584"
- },
- {
- "name": "GetSysColor",
- "address": "0x466588"
- },
- {
- "name": "GetSubMenu",
- "address": "0x46658c"
- },
- {
- "name": "GetScrollRange",
- "address": "0x466590"
- },
- {
- "name": "GetScrollPos",
- "address": "0x466594"
- },
- {
- "name": "GetScrollInfo",
- "address": "0x466598"
- },
- {
- "name": "GetPropA",
- "address": "0x46659c"
- },
- {
- "name": "GetParent",
- "address": "0x4665a0"
- },
- {
- "name": "GetWindow",
- "address": "0x4665a4"
- },
- {
- "name": "GetMenuStringA",
- "address": "0x4665a8"
- },
- {
- "name": "GetMenuState",
- "address": "0x4665ac"
- },
- {
- "name": "GetMenuItemInfoA",
- "address": "0x4665b0"
- },
- {
- "name": "GetMenuItemID",
- "address": "0x4665b4"
- },
- {
- "name": "GetMenuItemCount",
- "address": "0x4665b8"
- },
- {
- "name": "GetMenu",
- "address": "0x4665bc"
- },
- {
- "name": "GetLastActivePopup",
- "address": "0x4665c0"
- },
- {
- "name": "GetKeyboardState",
- "address": "0x4665c4"
- },
- {
- "name": "GetKeyboardLayoutList",
- "address": "0x4665c8"
- },
- {
- "name": "GetKeyboardLayout",
- "address": "0x4665cc"
- },
- {
- "name": "GetKeyState",
- "address": "0x4665d0"
- },
- {
- "name": "GetKeyNameTextA",
- "address": "0x4665d4"
- },
- {
- "name": "GetIconInfo",
- "address": "0x4665d8"
- },
- {
- "name": "GetForegroundWindow",
- "address": "0x4665dc"
- },
- {
- "name": "GetFocus",
- "address": "0x4665e0"
- },
- {
- "name": "GetDesktopWindow",
- "address": "0x4665e4"
- },
- {
- "name": "GetDCEx",
- "address": "0x4665e8"
- },
- {
- "name": "GetDC",
- "address": "0x4665ec"
- },
- {
- "name": "GetCursorPos",
- "address": "0x4665f0"
- },
- {
- "name": "GetCursor",
- "address": "0x4665f4"
- },
- {
- "name": "GetClientRect",
- "address": "0x4665f8"
- },
- {
- "name": "GetClassNameA",
- "address": "0x4665fc"
- },
- {
- "name": "GetClassInfoA",
- "address": "0x466600"
- },
- {
- "name": "GetCapture",
- "address": "0x466604"
- },
- {
- "name": "GetActiveWindow",
- "address": "0x466608"
- },
- {
- "name": "FrameRect",
- "address": "0x46660c"
- },
- {
- "name": "FindWindowA",
- "address": "0x466610"
- },
- {
- "name": "FillRect",
- "address": "0x466614"
- },
- {
- "name": "EqualRect",
- "address": "0x466618"
- },
- {
- "name": "EnumWindows",
- "address": "0x46661c"
- },
- {
- "name": "EnumThreadWindows",
- "address": "0x466620"
- },
- {
- "name": "EndPaint",
- "address": "0x466624"
- },
- {
- "name": "EnableWindow",
- "address": "0x466628"
- },
- {
- "name": "EnableScrollBar",
- "address": "0x46662c"
- },
- {
- "name": "EnableMenuItem",
- "address": "0x466630"
- },
- {
- "name": "DrawTextA",
- "address": "0x466634"
- },
- {
- "name": "DrawMenuBar",
- "address": "0x466638"
- },
- {
- "name": "DrawIconEx",
- "address": "0x46663c"
- },
- {
- "name": "DrawIcon",
- "address": "0x466640"
- },
- {
- "name": "DrawFrameControl",
- "address": "0x466644"
- },
- {
- "name": "DrawFocusRect",
- "address": "0x466648"
- },
- {
- "name": "DrawEdge",
- "address": "0x46664c"
- },
- {
- "name": "DispatchMessageA",
- "address": "0x466650"
- },
- {
- "name": "DestroyWindow",
- "address": "0x466654"
- },
- {
- "name": "DestroyMenu",
- "address": "0x466658"
- },
- {
- "name": "DestroyIcon",
- "address": "0x46665c"
- },
- {
- "name": "DestroyCursor",
- "address": "0x466660"
- },
- {
- "name": "DeleteMenu",
- "address": "0x466664"
- },
- {
- "name": "DefWindowProcA",
- "address": "0x466668"
- },
- {
- "name": "DefMDIChildProcA",
- "address": "0x46666c"
- },
- {
- "name": "DefFrameProcA",
- "address": "0x466670"
- },
- {
- "name": "CreatePopupMenu",
- "address": "0x466674"
- },
- {
- "name": "CreateMenu",
- "address": "0x466678"
- },
- {
- "name": "CreateIcon",
- "address": "0x46667c"
- },
- {
- "name": "ClientToScreen",
- "address": "0x466680"
- },
- {
- "name": "CheckMenuItem",
- "address": "0x466684"
- },
- {
- "name": "CallWindowProcA",
- "address": "0x466688"
- },
- {
- "name": "CallNextHookEx",
- "address": "0x46668c"
- },
- {
- "name": "BeginPaint",
- "address": "0x466690"
- },
- {
- "name": "CharNextA",
- "address": "0x466694"
- },
- {
- "name": "CharLowerA",
- "address": "0x466698"
- },
- {
- "name": "CharToOemA",
- "address": "0x46669c"
- },
- {
- "name": "AdjustWindowRectEx",
- "address": "0x4666a0"
- },
- {
- "name": "ActivateKeyboardLayout",
- "address": "0x4666a4"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "Sleep",
- "address": "0x4666ac"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "SafeArrayPtrOfIndex",
- "address": "0x4666b4"
- },
- {
- "name": "SafeArrayGetUBound",
- "address": "0x4666b8"
- },
- {
- "name": "SafeArrayGetLBound",
- "address": "0x4666bc"
- },
- {
- "name": "SafeArrayCreate",
- "address": "0x4666c0"
- },
- {
- "name": "VariantChangeType",
- "address": "0x4666c4"
- },
- {
- "name": "VariantCopy",
- "address": "0x4666c8"
- },
- {
- "name": "VariantClear",
- "address": "0x4666cc"
- },
- {
- "name": "VariantInit",
- "address": "0x4666d0"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "ImageList_SetIconSize",
- "address": "0x4666d8"
- },
- {
- "name": "ImageList_GetIconSize",
- "address": "0x4666dc"
- },
- {
- "name": "ImageList_Write",
- "address": "0x4666e0"
- },
- {
- "name": "ImageList_Read",
- "address": "0x4666e4"
- },
- {
- "name": "ImageList_GetDragImage",
- "address": "0x4666e8"
- },
- {
- "name": "ImageList_DragShowNolock",
- "address": "0x4666ec"
- },
- {
- "name": "ImageList_SetDragCursorImage",
- "address": "0x4666f0"
- },
- {
- "name": "ImageList_DragMove",
- "address": "0x4666f4"
- },
- {
- "name": "ImageList_DragLeave",
- "address": "0x4666f8"
- },
- {
- "name": "ImageList_DragEnter",
- "address": "0x4666fc"
- },
- {
- "name": "ImageList_EndDrag",
- "address": "0x466700"
- },
- {
- "name": "ImageList_BeginDrag",
- "address": "0x466704"
- },
- {
- "name": "ImageList_Remove",
- "address": "0x466708"
- },
- {
- "name": "ImageList_DrawEx",
- "address": "0x46670c"
- },
- {
- "name": "ImageList_Draw",
- "address": "0x466710"
- },
- {
- "name": "ImageList_GetBkColor",
- "address": "0x466714"
- },
- {
- "name": "ImageList_SetBkColor",
- "address": "0x466718"
- },
- {
- "name": "ImageList_ReplaceIcon",
- "address": "0x46671c"
- },
- {
- "name": "ImageList_Add",
- "address": "0x466720"
- },
- {
- "name": "ImageList_GetImageCount",
- "address": "0x466724"
- },
- {
- "name": "ImageList_Destroy",
- "address": "0x466728"
- },
- {
- "name": "ImageList_Create",
- "address": "0x46672c"
- },
- {
- "name": "InitCommonControls",
- "address": "0x466730"
- }
- ],
- "dll": "comctl32.dll"
- },
- {
- "imports": [
- {
- "name": "OpenPrinterA",
- "address": "0x466738"
- },
- {
- "name": "EnumPrintersA",
- "address": "0x46673c"
- },
- {
- "name": "DocumentPropertiesA",
- "address": "0x466740"
- },
- {
- "name": "ClosePrinter",
- "address": "0x466744"
- }
- ],
- "dll": "winspool.drv"
- },
- {
- "imports": [
- {
- "name": "PrintDlgA",
- "address": "0x46674c"
- }
- ],
- "dll": "comdlg32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x0009b687",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x0045a020",
- "timestamp": "1991-12-25 14:06:39",
- "osversion": "4.0",
- "sections": [
- {
- "name": "CODE",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00059200",
- "entropy": "6.51",
- "raw_address": "0x00000400",
- "virtual_size": "0x00059068",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": "DATA",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0005b000",
- "size_of_data": "0x00009400",
- "entropy": "4.95",
- "raw_address": "0x00059600",
- "virtual_size": "0x00009224",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": "BSS",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00065000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00062a00",
- "virtual_size": "0x00000cfd",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".idata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00066000",
- "size_of_data": "0x00002200",
- "entropy": "4.80",
- "raw_address": "0x00062a00",
- "virtual_size": "0x000020e4",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00069000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00064c00",
- "virtual_size": "0x00000010",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0006a000",
- "size_of_data": "0x00000200",
- "entropy": "0.21",
- "raw_address": "0x00064c00",
- "virtual_size": "0x00000018",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0006b000",
- "size_of_data": "0x00006a00",
- "entropy": "6.66",
- "raw_address": "0x00064e00",
- "virtual_size": "0x000069a8",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00072000",
- "size_of_data": "0x00026c00",
- "entropy": "7.22",
- "raw_address": "0x0006b800",
- "virtual_size": "0x00026ad4",
- "characteristics_raw": "0x50000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00066000",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x000020e4"
- },
- {
- "virtual_address": "0x00072000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00026ad4"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0006b000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x000069a8"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0006a000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "a4c69f0c0a976ff6c66b234a50f95a0c",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 15,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "kernel32.dll.GetDiskFreeSpaceExA",
- "oleaut32.dll.VariantChangeTypeEx",
- "oleaut32.dll.VarNeg",
- "oleaut32.dll.VarNot",
- "oleaut32.dll.VarAdd",
- "oleaut32.dll.VarSub",
- "oleaut32.dll.VarMul",
- "oleaut32.dll.VarDiv",
- "oleaut32.dll.VarIdiv",
- "oleaut32.dll.VarMod",
- "oleaut32.dll.VarAnd",
- "oleaut32.dll.VarOr",
- "oleaut32.dll.VarXor",
- "oleaut32.dll.VarCmp",
- "oleaut32.dll.VarI4FromStr",
- "oleaut32.dll.VarR4FromStr",
- "oleaut32.dll.VarR8FromStr",
- "oleaut32.dll.VarDateFromStr",
- "oleaut32.dll.VarCyFromStr",
- "oleaut32.dll.VarBoolFromStr",
- "oleaut32.dll.VarBstrFromCy",
- "oleaut32.dll.VarBstrFromDate",
- "oleaut32.dll.VarBstrFromBool",
- "user32.dll.GetMonitorInfoA",
- "user32.dll.GetSystemMetrics",
- "user32.dll.EnumDisplayMonitors",
- "dwmapi.dll.DwmIsCompositionEnabled",
- "gdi32.dll.GetLayout",
- "gdi32.dll.GdiRealizationInfo",
- "gdi32.dll.FontIsLinked",
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegQueryInfoKeyW",
- "gdi32.dll.GetTextFaceAliasW",
- "advapi32.dll.RegEnumValueW",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.RegQueryValueExW",
- "gdi32.dll.GetFontAssocStatus",
- "advapi32.dll.RegQueryValueExA",
- "advapi32.dll.RegEnumKeyExW",
- "gdi32.dll.GdiIsMetaPrintDC",
- "user32.dll.AnimateWindow",
- "comctl32.dll.InitializeFlatSB",
- "comctl32.dll.UninitializeFlatSB",
- "comctl32.dll.FlatSB_GetScrollProp",
- "comctl32.dll.FlatSB_SetScrollProp",
- "comctl32.dll.FlatSB_EnableScrollBar",
- "comctl32.dll.FlatSB_ShowScrollBar",
- "comctl32.dll.FlatSB_GetScrollRange",
- "comctl32.dll.FlatSB_GetScrollInfo",
- "comctl32.dll.FlatSB_GetScrollPos",
- "comctl32.dll.FlatSB_SetScrollPos",
- "comctl32.dll.FlatSB_SetScrollInfo",
- "comctl32.dll.FlatSB_SetScrollRange",
- "user32.dll.SetLayeredWindowAttributes",
- "crypt32.dll.CryptUnprotectData",
- "crtdll.dll.wcscmp",
- "gdiplus.dll.GdiplusStartup",
- "gdiplus.dll.GdiplusShutdown",
- "gdiplus.dll.GdipCreateBitmapFromHBITMAP",
- "gdiplus.dll.GdipGetImageEncodersSize",
- "gdiplus.dll.GdipGetImageEncoders",
- "gdiplus.dll.GdipDisposeImage",
- "gdiplus.dll.GdipSaveImageToStream",
- "ole32.dll.CreateStreamOnHGlobal",
- "ole32.dll.GetHGlobalFromStream",
- "kernel32.dll.ExpandEnvironmentStringsW",
- "kernel32.dll.GetComputerNameW",
- "kernel32.dll.GlobalMemoryStatus",
- "kernel32.dll.CreateFileW",
- "kernel32.dll.GetFileSize",
- "kernel32.dll.CloseHandle",
- "kernel32.dll.ReadFile",
- "kernel32.dll.GetFileAttributesW",
- "kernel32.dll.CreateMutexA",
- "kernel32.dll.ReleaseMutex",
- "kernel32.dll.GetLastError",
- "kernel32.dll.GetCurrentDirectoryW",
- "kernel32.dll.SetEnvironmentVariableW",
- "kernel32.dll.SetCurrentDirectoryW",
- "kernel32.dll.FindFirstFileW",
- "kernel32.dll.FindNextFileW",
- "kernel32.dll.LocalFree",
- "kernel32.dll.GetTickCount",
- "kernel32.dll.CopyFileW",
- "kernel32.dll.FindClose",
- "kernel32.dll.GlobalMemoryStatusEx",
- "kernel32.dll.CreateToolhelp32Snapshot",
- "kernel32.dll.Process32FirstW",
- "kernel32.dll.Process32NextW",
- "kernel32.dll.GetModuleFileNameW",
- "kernel32.dll.SetDllDirectoryW",
- "kernel32.dll.GetLocaleInfoA",
- "kernel32.dll.GetLocalTime",
- "kernel32.dll.GetTimeZoneInformation",
- "kernel32.dll.RemoveDirectoryW",
- "kernel32.dll.DeleteFileW",
- "kernel32.dll.GetLogicalDriveStringsA",
- "kernel32.dll.GetDriveTypeA",
- "kernel32.dll.CreateProcessW",
- "advapi32.dll.GetUserNameW",
- "advapi32.dll.RegCreateKeyExW",
- "advapi32.dll.AllocateAndInitializeSid",
- "advapi32.dll.LookupAccountSidA",
- "advapi32.dll.CreateProcessAsUserW",
- "advapi32.dll.CheckTokenMembership",
- "advapi32.dll.RegOpenKeyW",
- "advapi32.dll.RegEnumKeyW",
- "advapi32.dll.CryptAcquireContextA",
- "advapi32.dll.CryptCreateHash",
- "advapi32.dll.CryptHashData",
- "advapi32.dll.CryptGetHashParam",
- "advapi32.dll.CryptDestroyHash",
- "advapi32.dll.CryptReleaseContext",
- "user32.dll.EnumDisplayDevicesW",
- "user32.dll.wvsprintfA",
- "user32.dll.GetKeyboardLayoutList",
- "shell32.dll.ShellExecuteExW",
- "ntdll.dll.RtlComputeCrc32",
- "sechost.dll.LookupAccountSidLocalA",
- "wininet.dll.InternetOpenA",
- "wininet.dll.InternetConnectA",
- "wininet.dll.HttpOpenRequestA",
- "wininet.dll.HttpAddRequestHeadersA",
- "wininet.dll.HttpSendRequestA",
- "wininet.dll.InternetReadFile",
- "wininet.dll.InternetCloseHandle",
- "wininet.dll.InternetCrackUrlA",
- "wininet.dll.InternetSetOptionA",
- "rasapi32.dll.RasConnectionNotificationW",
- "sechost.dll.NotifyServiceStatusChangeA",
- "cryptbase.dll.SystemFunction036",
- "wsock32.dll.WSAStartup",
- "wsock32.dll.gethostbyname",
- "wsock32.dll.socket",
- "wsock32.dll.send",
- "wsock32.dll.recv",
- "wsock32.dll.htons",
- "wsock32.dll.connect",
- "wsock32.dll.closesocket",
- "rpcrt4.dll.RpcBindingFree"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DeleteCriticalSection",
- "address": "0x466140"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x466144"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x466148"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x46614c"
- },
- {
- "name": "VirtualFree",
- "address": "0x466150"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x466154"
- },
- {
- "name": "LocalFree",
- "address": "0x466158"
- },
- {
- "name": "LocalAlloc",
- "address": "0x46615c"
- },
- {
- "name": "GetVersion",
- "address": "0x466160"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x466164"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x466168"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x46616c"
- },
- {
- "name": "VirtualQuery",
- "address": "0x466170"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x466174"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x466178"
- },
- {
- "name": "lstrlenA",
- "address": "0x46617c"
- },
- {
- "name": "lstrcpynA",
- "address": "0x466180"
- },
- {
- "name": "LoadLibraryExA",
- "address": "0x466184"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x466188"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x46618c"
- },
- {
- "name": "GetProcAddress",
- "address": "0x466190"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x466194"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x466198"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x46619c"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x4661a0"
- },
- {
- "name": "FreeLibrary",
- "address": "0x4661a4"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x4661a8"
- },
- {
- "name": "FindClose",
- "address": "0x4661ac"
- },
- {
- "name": "ExitProcess",
- "address": "0x4661b0"
- },
- {
- "name": "WriteFile",
- "address": "0x4661b4"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x4661b8"
- },
- {
- "name": "RtlUnwind",
- "address": "0x4661bc"
- },
- {
- "name": "RaiseException",
- "address": "0x4661c0"
- },
- {
- "name": "GetStdHandle",
- "address": "0x4661c4"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "GetKeyboardType",
- "address": "0x4661cc"
- },
- {
- "name": "LoadStringA",
- "address": "0x4661d0"
- },
- {
- "name": "MessageBoxA",
- "address": "0x4661d4"
- },
- {
- "name": "CharNextA",
- "address": "0x4661d8"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x4661e0"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x4661e4"
- },
- {
- "name": "RegCloseKey",
- "address": "0x4661e8"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "SysFreeString",
- "address": "0x4661f0"
- },
- {
- "name": "SysReAllocStringLen",
- "address": "0x4661f4"
- },
- {
- "name": "SysAllocStringLen",
- "address": "0x4661f8"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "TlsSetValue",
- "address": "0x466200"
- },
- {
- "name": "TlsGetValue",
- "address": "0x466204"
- },
- {
- "name": "LocalAlloc",
- "address": "0x466208"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x46620c"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x466214"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x466218"
- },
- {
- "name": "RegCloseKey",
- "address": "0x46621c"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "lstrcpyA",
- "address": "0x466224"
- },
- {
- "name": "WriteFile",
- "address": "0x466228"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x46622c"
- },
- {
- "name": "VirtualQuery",
- "address": "0x466230"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x466234"
- },
- {
- "name": "Sleep",
- "address": "0x466238"
- },
- {
- "name": "SizeofResource",
- "address": "0x46623c"
- },
- {
- "name": "SetThreadLocale",
- "address": "0x466240"
- },
- {
- "name": "SetFilePointer",
- "address": "0x466244"
- },
- {
- "name": "SetEvent",
- "address": "0x466248"
- },
- {
- "name": "SetErrorMode",
- "address": "0x46624c"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x466250"
- },
- {
- "name": "ResetEvent",
- "address": "0x466254"
- },
- {
- "name": "ReadFile",
- "address": "0x466258"
- },
- {
- "name": "MulDiv",
- "address": "0x46625c"
- },
- {
- "name": "LockResource",
- "address": "0x466260"
- },
- {
- "name": "LoadResource",
- "address": "0x466264"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x466268"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x46626c"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x466270"
- },
- {
- "name": "GlobalUnlock",
- "address": "0x466274"
- },
- {
- "name": "GlobalSize",
- "address": "0x466278"
- },
- {
- "name": "GlobalReAlloc",
- "address": "0x46627c"
- },
- {
- "name": "GlobalHandle",
- "address": "0x466280"
- },
- {
- "name": "GlobalLock",
- "address": "0x466284"
- },
- {
- "name": "GlobalFree",
- "address": "0x466288"
- },
- {
- "name": "GlobalFindAtomA",
- "address": "0x46628c"
- },
- {
- "name": "GlobalDeleteAtom",
- "address": "0x466290"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x466294"
- },
- {
- "name": "GlobalAddAtomA",
- "address": "0x466298"
- },
- {
- "name": "GetVersionExA",
- "address": "0x46629c"
- },
- {
- "name": "GetVersion",
- "address": "0x4662a0"
- },
- {
- "name": "GetTickCount",
- "address": "0x4662a4"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x4662a8"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x4662ac"
- },
- {
- "name": "GetStringTypeExA",
- "address": "0x4662b0"
- },
- {
- "name": "GetStdHandle",
- "address": "0x4662b4"
- },
- {
- "name": "GetProfileStringA",
- "address": "0x4662b8"
- },
- {
- "name": "GetProcAddress",
- "address": "0x4662bc"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x4662c0"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x4662c4"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x4662c8"
- },
- {
- "name": "GetLocalTime",
- "address": "0x4662cc"
- },
- {
- "name": "GetLastError",
- "address": "0x4662d0"
- },
- {
- "name": "GetFullPathNameA",
- "address": "0x4662d4"
- },
- {
- "name": "GetDiskFreeSpaceA",
- "address": "0x4662d8"
- },
- {
- "name": "GetDateFormatA",
- "address": "0x4662dc"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x4662e0"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x4662e4"
- },
- {
- "name": "GetCPInfo",
- "address": "0x4662e8"
- },
- {
- "name": "GetACP",
- "address": "0x4662ec"
- },
- {
- "name": "FreeResource",
- "address": "0x4662f0"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x4662f4"
- },
- {
- "name": "FreeLibrary",
- "address": "0x4662f8"
- },
- {
- "name": "FormatMessageA",
- "address": "0x4662fc"
- },
- {
- "name": "FindResourceA",
- "address": "0x466300"
- },
- {
- "name": "EnumCalendarInfoA",
- "address": "0x466304"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x466308"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x46630c"
- },
- {
- "name": "CreateThread",
- "address": "0x466310"
- },
- {
- "name": "CreateFileA",
- "address": "0x466314"
- },
- {
- "name": "CreateEventA",
- "address": "0x466318"
- },
- {
- "name": "CompareStringA",
- "address": "0x46631c"
- },
- {
- "name": "CloseHandle",
- "address": "0x466320"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "VerQueryValueA",
- "address": "0x466328"
- },
- {
- "name": "GetFileVersionInfoSizeA",
- "address": "0x46632c"
- },
- {
- "name": "GetFileVersionInfoA",
- "address": "0x466330"
- }
- ],
- "dll": "version.dll"
- },
- {
- "imports": [
- {
- "name": "UnrealizeObject",
- "address": "0x466338"
- },
- {
- "name": "StretchBlt",
- "address": "0x46633c"
- },
- {
- "name": "SetWindowOrgEx",
- "address": "0x466340"
- },
- {
- "name": "SetViewportOrgEx",
- "address": "0x466344"
- },
- {
- "name": "SetTextColor",
- "address": "0x466348"
- },
- {
- "name": "SetStretchBltMode",
- "address": "0x46634c"
- },
- {
- "name": "SetROP2",
- "address": "0x466350"
- },
- {
- "name": "SetPixel",
- "address": "0x466354"
- },
- {
- "name": "SetDIBColorTable",
- "address": "0x466358"
- },
- {
- "name": "SetBrushOrgEx",
- "address": "0x46635c"
- },
- {
- "name": "SetBkMode",
- "address": "0x466360"
- },
- {
- "name": "SetBkColor",
- "address": "0x466364"
- },
- {
- "name": "SelectPalette",
- "address": "0x466368"
- },
- {
- "name": "SelectObject",
- "address": "0x46636c"
- },
- {
- "name": "ScaleWindowExtEx",
- "address": "0x466370"
- },
- {
- "name": "SaveDC",
- "address": "0x466374"
- },
- {
- "name": "RestoreDC",
- "address": "0x466378"
- },
- {
- "name": "Rectangle",
- "address": "0x46637c"
- },
- {
- "name": "RectVisible",
- "address": "0x466380"
- },
- {
- "name": "RealizePalette",
- "address": "0x466384"
- },
- {
- "name": "PatBlt",
- "address": "0x466388"
- },
- {
- "name": "MoveToEx",
- "address": "0x46638c"
- },
- {
- "name": "MaskBlt",
- "address": "0x466390"
- },
- {
- "name": "LineTo",
- "address": "0x466394"
- },
- {
- "name": "IntersectClipRect",
- "address": "0x466398"
- },
- {
- "name": "GetWindowOrgEx",
- "address": "0x46639c"
- },
- {
- "name": "GetTextMetricsA",
- "address": "0x4663a0"
- },
- {
- "name": "GetTextExtentPoint32A",
- "address": "0x4663a4"
- },
- {
- "name": "GetSystemPaletteEntries",
- "address": "0x4663a8"
- },
- {
- "name": "GetStockObject",
- "address": "0x4663ac"
- },
- {
- "name": "GetPixel",
- "address": "0x4663b0"
- },
- {
- "name": "GetPaletteEntries",
- "address": "0x4663b4"
- },
- {
- "name": "GetObjectA",
- "address": "0x4663b8"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x4663bc"
- },
- {
- "name": "GetDIBits",
- "address": "0x4663c0"
- },
- {
- "name": "GetDIBColorTable",
- "address": "0x4663c4"
- },
- {
- "name": "GetDCOrgEx",
- "address": "0x4663c8"
- },
- {
- "name": "GetCurrentPositionEx",
- "address": "0x4663cc"
- },
- {
- "name": "GetClipBox",
- "address": "0x4663d0"
- },
- {
- "name": "GetBrushOrgEx",
- "address": "0x4663d4"
- },
- {
- "name": "GetBitmapBits",
- "address": "0x4663d8"
- },
- {
- "name": "ExtTextOutA",
- "address": "0x4663dc"
- },
- {
- "name": "ExcludeClipRect",
- "address": "0x4663e0"
- },
- {
- "name": "EndPage",
- "address": "0x4663e4"
- },
- {
- "name": "EndDoc",
- "address": "0x4663e8"
- },
- {
- "name": "DeleteObject",
- "address": "0x4663ec"
- },
- {
- "name": "DeleteDC",
- "address": "0x4663f0"
- },
- {
- "name": "CreateSolidBrush",
- "address": "0x4663f4"
- },
- {
- "name": "CreatePenIndirect",
- "address": "0x4663f8"
- },
- {
- "name": "CreatePen",
- "address": "0x4663fc"
- },
- {
- "name": "CreatePalette",
- "address": "0x466400"
- },
- {
- "name": "CreateICA",
- "address": "0x466404"
- },
- {
- "name": "CreateHalftonePalette",
- "address": "0x466408"
- },
- {
- "name": "CreateFontIndirectA",
- "address": "0x46640c"
- },
- {
- "name": "CreateDIBitmap",
- "address": "0x466410"
- },
- {
- "name": "CreateDIBSection",
- "address": "0x466414"
- },
- {
- "name": "CreateDCA",
- "address": "0x466418"
- },
- {
- "name": "CreateCompatibleDC",
- "address": "0x46641c"
- },
- {
- "name": "CreateCompatibleBitmap",
- "address": "0x466420"
- },
- {
- "name": "CreateBrushIndirect",
- "address": "0x466424"
- },
- {
- "name": "CreateBitmap",
- "address": "0x466428"
- },
- {
- "name": "BitBlt",
- "address": "0x46642c"
- }
- ],
- "dll": "gdi32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateWindowExA",
- "address": "0x466434"
- },
- {
- "name": "WindowFromPoint",
- "address": "0x466438"
- },
- {
- "name": "WinHelpA",
- "address": "0x46643c"
- },
- {
- "name": "WaitMessage",
- "address": "0x466440"
- },
- {
- "name": "ValidateRect",
- "address": "0x466444"
- },
- {
- "name": "UpdateWindow",
- "address": "0x466448"
- },
- {
- "name": "UnregisterClassA",
- "address": "0x46644c"
- },
- {
- "name": "UnhookWindowsHookEx",
- "address": "0x466450"
- },
- {
- "name": "TranslateMessage",
- "address": "0x466454"
- },
- {
- "name": "TranslateMDISysAccel",
- "address": "0x466458"
- },
- {
- "name": "TrackPopupMenu",
- "address": "0x46645c"
- },
- {
- "name": "SystemParametersInfoA",
- "address": "0x466460"
- },
- {
- "name": "ShowWindow",
- "address": "0x466464"
- },
- {
- "name": "ShowScrollBar",
- "address": "0x466468"
- },
- {
- "name": "ShowOwnedPopups",
- "address": "0x46646c"
- },
- {
- "name": "ShowCursor",
- "address": "0x466470"
- },
- {
- "name": "SetWindowsHookExA",
- "address": "0x466474"
- },
- {
- "name": "SetWindowTextA",
- "address": "0x466478"
- },
- {
- "name": "SetWindowPos",
- "address": "0x46647c"
- },
- {
- "name": "SetWindowPlacement",
- "address": "0x466480"
- },
- {
- "name": "SetWindowLongA",
- "address": "0x466484"
- },
- {
- "name": "SetTimer",
- "address": "0x466488"
- },
- {
- "name": "SetScrollRange",
- "address": "0x46648c"
- },
- {
- "name": "SetScrollPos",
- "address": "0x466490"
- },
- {
- "name": "SetScrollInfo",
- "address": "0x466494"
- },
- {
- "name": "SetRect",
- "address": "0x466498"
- },
- {
- "name": "SetPropA",
- "address": "0x46649c"
- },
- {
- "name": "SetParent",
- "address": "0x4664a0"
- },
- {
- "name": "SetMenuItemInfoA",
- "address": "0x4664a4"
- },
- {
- "name": "SetMenu",
- "address": "0x4664a8"
- },
- {
- "name": "SetForegroundWindow",
- "address": "0x4664ac"
- },
- {
- "name": "SetFocus",
- "address": "0x4664b0"
- },
- {
- "name": "SetCursor",
- "address": "0x4664b4"
- },
- {
- "name": "SetClassLongA",
- "address": "0x4664b8"
- },
- {
- "name": "SetCapture",
- "address": "0x4664bc"
- },
- {
- "name": "SetActiveWindow",
- "address": "0x4664c0"
- },
- {
- "name": "SendMessageA",
- "address": "0x4664c4"
- },
- {
- "name": "ScrollWindow",
- "address": "0x4664c8"
- },
- {
- "name": "ScreenToClient",
- "address": "0x4664cc"
- },
- {
- "name": "RemovePropA",
- "address": "0x4664d0"
- },
- {
- "name": "RemoveMenu",
- "address": "0x4664d4"
- },
- {
- "name": "ReleaseDC",
- "address": "0x4664d8"
- },
- {
- "name": "ReleaseCapture",
- "address": "0x4664dc"
- },
- {
- "name": "RegisterWindowMessageA",
- "address": "0x4664e0"
- },
- {
- "name": "RegisterClipboardFormatA",
- "address": "0x4664e4"
- },
- {
- "name": "RegisterClassA",
- "address": "0x4664e8"
- },
- {
- "name": "RedrawWindow",
- "address": "0x4664ec"
- },
- {
- "name": "PtInRect",
- "address": "0x4664f0"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x4664f4"
- },
- {
- "name": "PostMessageA",
- "address": "0x4664f8"
- },
- {
- "name": "PeekMessageA",
- "address": "0x4664fc"
- },
- {
- "name": "OffsetRect",
- "address": "0x466500"
- },
- {
- "name": "OemToCharA",
- "address": "0x466504"
- },
- {
- "name": "MessageBoxA",
- "address": "0x466508"
- },
- {
- "name": "MapWindowPoints",
- "address": "0x46650c"
- },
- {
- "name": "MapVirtualKeyA",
- "address": "0x466510"
- },
- {
- "name": "LoadStringA",
- "address": "0x466514"
- },
- {
- "name": "LoadKeyboardLayoutA",
- "address": "0x466518"
- },
- {
- "name": "LoadIconA",
- "address": "0x46651c"
- },
- {
- "name": "LoadCursorA",
- "address": "0x466520"
- },
- {
- "name": "LoadBitmapA",
- "address": "0x466524"
- },
- {
- "name": "KillTimer",
- "address": "0x466528"
- },
- {
- "name": "IsZoomed",
- "address": "0x46652c"
- },
- {
- "name": "IsWindowVisible",
- "address": "0x466530"
- },
- {
- "name": "IsWindowEnabled",
- "address": "0x466534"
- },
- {
- "name": "IsWindow",
- "address": "0x466538"
- },
- {
- "name": "IsRectEmpty",
- "address": "0x46653c"
- },
- {
- "name": "IsIconic",
- "address": "0x466540"
- },
- {
- "name": "IsDialogMessageA",
- "address": "0x466544"
- },
- {
- "name": "IsChild",
- "address": "0x466548"
- },
- {
- "name": "InvalidateRect",
- "address": "0x46654c"
- },
- {
- "name": "IntersectRect",
- "address": "0x466550"
- },
- {
- "name": "InsertMenuItemA",
- "address": "0x466554"
- },
- {
- "name": "InsertMenuA",
- "address": "0x466558"
- },
- {
- "name": "InflateRect",
- "address": "0x46655c"
- },
- {
- "name": "GetWindowThreadProcessId",
- "address": "0x466560"
- },
- {
- "name": "GetWindowTextA",
- "address": "0x466564"
- },
- {
- "name": "GetWindowRect",
- "address": "0x466568"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x46656c"
- },
- {
- "name": "GetWindowLongA",
- "address": "0x466570"
- },
- {
- "name": "GetWindowDC",
- "address": "0x466574"
- },
- {
- "name": "GetTopWindow",
- "address": "0x466578"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x46657c"
- },
- {
- "name": "GetSystemMenu",
- "address": "0x466580"
- },
- {
- "name": "GetSysColorBrush",
- "address": "0x466584"
- },
- {
- "name": "GetSysColor",
- "address": "0x466588"
- },
- {
- "name": "GetSubMenu",
- "address": "0x46658c"
- },
- {
- "name": "GetScrollRange",
- "address": "0x466590"
- },
- {
- "name": "GetScrollPos",
- "address": "0x466594"
- },
- {
- "name": "GetScrollInfo",
- "address": "0x466598"
- },
- {
- "name": "GetPropA",
- "address": "0x46659c"
- },
- {
- "name": "GetParent",
- "address": "0x4665a0"
- },
- {
- "name": "GetWindow",
- "address": "0x4665a4"
- },
- {
- "name": "GetMenuStringA",
- "address": "0x4665a8"
- },
- {
- "name": "GetMenuState",
- "address": "0x4665ac"
- },
- {
- "name": "GetMenuItemInfoA",
- "address": "0x4665b0"
- },
- {
- "name": "GetMenuItemID",
- "address": "0x4665b4"
- },
- {
- "name": "GetMenuItemCount",
- "address": "0x4665b8"
- },
- {
- "name": "GetMenu",
- "address": "0x4665bc"
- },
- {
- "name": "GetLastActivePopup",
- "address": "0x4665c0"
- },
- {
- "name": "GetKeyboardState",
- "address": "0x4665c4"
- },
- {
- "name": "GetKeyboardLayoutList",
- "address": "0x4665c8"
- },
- {
- "name": "GetKeyboardLayout",
- "address": "0x4665cc"
- },
- {
- "name": "GetKeyState",
- "address": "0x4665d0"
- },
- {
- "name": "GetKeyNameTextA",
- "address": "0x4665d4"
- },
- {
- "name": "GetIconInfo",
- "address": "0x4665d8"
- },
- {
- "name": "GetForegroundWindow",
- "address": "0x4665dc"
- },
- {
- "name": "GetFocus",
- "address": "0x4665e0"
- },
- {
- "name": "GetDesktopWindow",
- "address": "0x4665e4"
- },
- {
- "name": "GetDCEx",
- "address": "0x4665e8"
- },
- {
- "name": "GetDC",
- "address": "0x4665ec"
- },
- {
- "name": "GetCursorPos",
- "address": "0x4665f0"
- },
- {
- "name": "GetCursor",
- "address": "0x4665f4"
- },
- {
- "name": "GetClientRect",
- "address": "0x4665f8"
- },
- {
- "name": "GetClassNameA",
- "address": "0x4665fc"
- },
- {
- "name": "GetClassInfoA",
- "address": "0x466600"
- },
- {
- "name": "GetCapture",
- "address": "0x466604"
- },
- {
- "name": "GetActiveWindow",
- "address": "0x466608"
- },
- {
- "name": "FrameRect",
- "address": "0x46660c"
- },
- {
- "name": "FindWindowA",
- "address": "0x466610"
- },
- {
- "name": "FillRect",
- "address": "0x466614"
- },
- {
- "name": "EqualRect",
- "address": "0x466618"
- },
- {
- "name": "EnumWindows",
- "address": "0x46661c"
- },
- {
- "name": "EnumThreadWindows",
- "address": "0x466620"
- },
- {
- "name": "EndPaint",
- "address": "0x466624"
- },
- {
- "name": "EnableWindow",
- "address": "0x466628"
- },
- {
- "name": "EnableScrollBar",
- "address": "0x46662c"
- },
- {
- "name": "EnableMenuItem",
- "address": "0x466630"
- },
- {
- "name": "DrawTextA",
- "address": "0x466634"
- },
- {
- "name": "DrawMenuBar",
- "address": "0x466638"
- },
- {
- "name": "DrawIconEx",
- "address": "0x46663c"
- },
- {
- "name": "DrawIcon",
- "address": "0x466640"
- },
- {
- "name": "DrawFrameControl",
- "address": "0x466644"
- },
- {
- "name": "DrawFocusRect",
- "address": "0x466648"
- },
- {
- "name": "DrawEdge",
- "address": "0x46664c"
- },
- {
- "name": "DispatchMessageA",
- "address": "0x466650"
- },
- {
- "name": "DestroyWindow",
- "address": "0x466654"
- },
- {
- "name": "DestroyMenu",
- "address": "0x466658"
- },
- {
- "name": "DestroyIcon",
- "address": "0x46665c"
- },
- {
- "name": "DestroyCursor",
- "address": "0x466660"
- },
- {
- "name": "DeleteMenu",
- "address": "0x466664"
- },
- {
- "name": "DefWindowProcA",
- "address": "0x466668"
- },
- {
- "name": "DefMDIChildProcA",
- "address": "0x46666c"
- },
- {
- "name": "DefFrameProcA",
- "address": "0x466670"
- },
- {
- "name": "CreatePopupMenu",
- "address": "0x466674"
- },
- {
- "name": "CreateMenu",
- "address": "0x466678"
- },
- {
- "name": "CreateIcon",
- "address": "0x46667c"
- },
- {
- "name": "ClientToScreen",
- "address": "0x466680"
- },
- {
- "name": "CheckMenuItem",
- "address": "0x466684"
- },
- {
- "name": "CallWindowProcA",
- "address": "0x466688"
- },
- {
- "name": "CallNextHookEx",
- "address": "0x46668c"
- },
- {
- "name": "BeginPaint",
- "address": "0x466690"
- },
- {
- "name": "CharNextA",
- "address": "0x466694"
- },
- {
- "name": "CharLowerA",
- "address": "0x466698"
- },
- {
- "name": "CharToOemA",
- "address": "0x46669c"
- },
- {
- "name": "AdjustWindowRectEx",
- "address": "0x4666a0"
- },
- {
- "name": "ActivateKeyboardLayout",
- "address": "0x4666a4"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "Sleep",
- "address": "0x4666ac"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "SafeArrayPtrOfIndex",
- "address": "0x4666b4"
- },
- {
- "name": "SafeArrayGetUBound",
- "address": "0x4666b8"
- },
- {
- "name": "SafeArrayGetLBound",
- "address": "0x4666bc"
- },
- {
- "name": "SafeArrayCreate",
- "address": "0x4666c0"
- },
- {
- "name": "VariantChangeType",
- "address": "0x4666c4"
- },
- {
- "name": "VariantCopy",
- "address": "0x4666c8"
- },
- {
- "name": "VariantClear",
- "address": "0x4666cc"
- },
- {
- "name": "VariantInit",
- "address": "0x4666d0"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "ImageList_SetIconSize",
- "address": "0x4666d8"
- },
- {
- "name": "ImageList_GetIconSize",
- "address": "0x4666dc"
- },
- {
- "name": "ImageList_Write",
- "address": "0x4666e0"
- },
- {
- "name": "ImageList_Read",
- "address": "0x4666e4"
- },
- {
- "name": "ImageList_GetDragImage",
- "address": "0x4666e8"
- },
- {
- "name": "ImageList_DragShowNolock",
- "address": "0x4666ec"
- },
- {
- "name": "ImageList_SetDragCursorImage",
- "address": "0x4666f0"
- },
- {
- "name": "ImageList_DragMove",
- "address": "0x4666f4"
- },
- {
- "name": "ImageList_DragLeave",
- "address": "0x4666f8"
- },
- {
- "name": "ImageList_DragEnter",
- "address": "0x4666fc"
- },
- {
- "name": "ImageList_EndDrag",
- "address": "0x466700"
- },
- {
- "name": "ImageList_BeginDrag",
- "address": "0x466704"
- },
- {
- "name": "ImageList_Remove",
- "address": "0x466708"
- },
- {
- "name": "ImageList_DrawEx",
- "address": "0x46670c"
- },
- {
- "name": "ImageList_Draw",
- "address": "0x466710"
- },
- {
- "name": "ImageList_GetBkColor",
- "address": "0x466714"
- },
- {
- "name": "ImageList_SetBkColor",
- "address": "0x466718"
- },
- {
- "name": "ImageList_ReplaceIcon",
- "address": "0x46671c"
- },
- {
- "name": "ImageList_Add",
- "address": "0x466720"
- },
- {
- "name": "ImageList_GetImageCount",
- "address": "0x466724"
- },
- {
- "name": "ImageList_Destroy",
- "address": "0x466728"
- },
- {
- "name": "ImageList_Create",
- "address": "0x46672c"
- },
- {
- "name": "InitCommonControls",
- "address": "0x466730"
- }
- ],
- "dll": "comctl32.dll"
- },
- {
- "imports": [
- {
- "name": "OpenPrinterA",
- "address": "0x466738"
- },
- {
- "name": "EnumPrintersA",
- "address": "0x46673c"
- },
- {
- "name": "DocumentPropertiesA",
- "address": "0x466740"
- },
- {
- "name": "ClosePrinter",
- "address": "0x466744"
- }
- ],
- "dll": "winspool.drv"
- },
- {
- "imports": [
- {
- "name": "PrintDlgA",
- "address": "0x46674c"
- }
- ],
- "dll": "comdlg32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x0009b687",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x0045a020",
- "timestamp": "1991-12-25 14:06:39",
- "osversion": "4.0",
- "sections": [
- {
- "name": "CODE",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00059200",
- "entropy": "6.51",
- "raw_address": "0x00000400",
- "virtual_size": "0x00059068",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": "DATA",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0005b000",
- "size_of_data": "0x00009400",
- "entropy": "4.95",
- "raw_address": "0x00059600",
- "virtual_size": "0x00009224",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": "BSS",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00065000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00062a00",
- "virtual_size": "0x00000cfd",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".idata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00066000",
- "size_of_data": "0x00002200",
- "entropy": "4.80",
- "raw_address": "0x00062a00",
- "virtual_size": "0x000020e4",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00069000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00064c00",
- "virtual_size": "0x00000010",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0006a000",
- "size_of_data": "0x00000200",
- "entropy": "0.21",
- "raw_address": "0x00064c00",
- "virtual_size": "0x00000018",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0006b000",
- "size_of_data": "0x00006a00",
- "entropy": "6.66",
- "raw_address": "0x00064e00",
- "virtual_size": "0x000069a8",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00072000",
- "size_of_data": "0x00026c00",
- "entropy": "7.22",
- "raw_address": "0x0006b800",
- "virtual_size": "0x00026ad4",
- "characteristics_raw": "0x50000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00066000",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x000020e4"
- },
- {
- "virtual_address": "0x00072000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00026ad4"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0006b000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x000069a8"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0006a000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "a4c69f0c0a976ff6c66b234a50f95a0c",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 15,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement