Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: "Dwud"
- [*] MalScore: 10.0
- [*] File Name: "f5.jpg"
- [*] File Size: 806912
- [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- [*] SHA256: "7c9e935e0cbf772fca2a93f51368cacc4440919ffbd1ba17106973346cc4ef64"
- [*] MD5: "bc481feb004a51adcc8a0188634c3bea"
- [*] SHA1: "27b21c06fb9ea9ec5e8cbeed31b343b94e9dfec4"
- [*] SHA512: "061c2f2050f9fb7758cd5b7d2e2b0cb2f42f3c2e6f3caa0d25aa43e9dfcf5595959b7718874cd5a66e7a9e840c99af899b17a3398e95091b6922b0ae500696d6"
- [*] CRC32: "6F78F9D8"
- [*] SSDEEP: "12288:cdqUJz8sEoMW54nHLZQBAz3U9Yo/1Azd+Y3je1fUf66LNtJOcmqFXYchuiT4:cU+FSW54nmK3UmjzlQfUS6PDTh"
- [*] Process Execution: [
- "f5.jpg",
- "f5.jpg"
- ]
- [*] Signatures Detected: [
- {
- "Description": "Creates RWX memory",
- "Details": []
- },
- {
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details": [
- {
- "section": "name: .rsrc, entropy: 7.18, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ, raw_size: 0x00038e00, virtual_size: 0x00038df4"
- }
- ]
- },
- {
- "Description": "Executed a process and injected code into it, probably while unpacking",
- "Details": [
- {
- "Injection": "f5.jpg(344) -> f5.jpg(1804)"
- }
- ]
- },
- {
- "Description": "File has been identified by 53 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "MicroWorld-eScan": "Trojan.Agent.DWUD"
- },
- {
- "CAT-QuickHeal": "Backdoor.NetWiredRC"
- },
- {
- "ALYac": "Trojan.Agent.DWUD"
- },
- {
- "AegisLab": "Trojan.Win32.NetWiredRC.4!c"
- },
- {
- "BitDefender": "Trojan.Agent.DWUD"
- },
- {
- "K7GW": "Trojan ( 0054dfbc1 )"
- },
- {
- "K7AntiVirus": "Trojan ( 0054dfbc1 )"
- },
- {
- "Invincea": "heuristic"
- },
- {
- "NANO-Antivirus": "Trojan.Win32.NetWiredRC.fqdoce"
- },
- {
- "Cyren": "W32/Trojan.CMD.gen!Eldorado"
- },
- {
- "Symantec": "Trojan.Gen.MBT"
- },
- {
- "Zoner": "Trojan.Win32.78120"
- },
- {
- "APEX": "Malicious"
- },
- {
- "ClamAV": "Win.Dropper.Genkryptik-6968862-0"
- },
- {
- "Kaspersky": "HEUR:Backdoor.Win32.NetWiredRC.gen"
- },
- {
- "Alibaba": "Backdoor:Win32/Skeeyah.6f927e0f"
- },
- {
- "ViRobot": "Trojan.Win32.Z.Injector.806912.FY"
- },
- {
- "Ad-Aware": "Trojan.Agent.DWUD"
- },
- {
- "Sophos": "Mal/Fareit-Q"
- },
- {
- "Comodo": "Malware@#2z32rnse1cak8"
- },
- {
- "F-Secure": "Trojan.TR/Injector.pabzb"
- },
- {
- "DrWeb": "Trojan.PWS.Stealer.26197"
- },
- {
- "TrendMicro": "TrojanSpy.Win32.LOKI.SMD1.hp"
- },
- {
- "McAfee-GW-Edition": "BehavesLike.Win32.Fareit.bh"
- },
- {
- "Trapmine": "malicious.moderate.ml.score"
- },
- {
- "FireEye": "Generic.mg.bc481feb004a51ad"
- },
- {
- "Emsisoft": "Trojan.Agent.DWUD (B)"
- },
- {
- "SentinelOne": "DFI - Malicious PE"
- },
- {
- "F-Prot": "W32/Trojan.CMD.gen!Eldorado"
- },
- {
- "Webroot": "W32.Trojan.Gen"
- },
- {
- "Avira": "TR/Injector.pabzb"
- },
- {
- "Fortinet": "W32/GenKryptik.DFRN!tr"
- },
- {
- "Antiy-AVL": "Trojan[Backdoor]/Win32.NetWiredRC"
- },
- {
- "Endgame": "malicious (high confidence)"
- },
- {
- "Microsoft": "Trojan:Win32/Skeeyah.A!bit"
- },
- {
- "ZoneAlarm": "HEUR:Backdoor.Win32.NetWiredRC.gen"
- },
- {
- "AhnLab-V3": "Win-Trojan/Delphiless.Exp"
- },
- {
- "Acronis": "suspicious"
- },
- {
- "McAfee": "Packed-FTB!BC481FEB004A"
- },
- {
- "MAX": "malware (ai score=100)"
- },
- {
- "VBA32": "Backdoor.NetWiredRC"
- },
- {
- "Panda": "Trj/CI.A"
- },
- {
- "Arcabit": "Trojan.Agent.DWUD"
- },
- {
- "ESET-NOD32": "a variant of Win32/Injector.EFJY"
- },
- {
- "TrendMicro-HouseCall": "TrojanSpy.Win32.LOKI.SMD1.hp"
- },
- {
- "Rising": "Malware.Heuristic.MLite(100%) (AI-LITE:7LxjClPPz6tN9mW9VR0UTQ)"
- },
- {
- "Ikarus": "Trojan-Spy.Keylogger.AgentTesla"
- },
- {
- "GData": "Trojan.Agent.DWUD"
- },
- {
- "AVG": "Win32:Malware-gen"
- },
- {
- "Cybereason": "malicious.6fb9ea"
- },
- {
- "Avast": "Win32:Malware-gen"
- },
- {
- "CrowdStrike": "win/malicious_confidence_100% (W)"
- },
- {
- "Qihoo-360": "Win32/Trojan.9ca"
- }
- ]
- },
- {
- "Description": "Anomalous binary characteristics",
- "Details": [
- {
- "anomaly": "Timestamp on binary predates the release date of the OS version it requires by at least a year"
- }
- ]
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: [
- "\"C:\\Users\\user\\AppData\\Local\\Temp\\f5.jpg\""
- ]
- [*] Mutexes: []
- [*] Modified Files: []
- [*] Deleted Files: []
- [*] Modified Registry Keys: []
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DeleteCriticalSection",
- "address": "0x483154"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x483158"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x48315c"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x483160"
- },
- {
- "name": "VirtualFree",
- "address": "0x483164"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x483168"
- },
- {
- "name": "LocalFree",
- "address": "0x48316c"
- },
- {
- "name": "LocalAlloc",
- "address": "0x483170"
- },
- {
- "name": "GetVersion",
- "address": "0x483174"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x483178"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x48317c"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x483180"
- },
- {
- "name": "VirtualQuery",
- "address": "0x483184"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x483188"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x48318c"
- },
- {
- "name": "lstrlenA",
- "address": "0x483190"
- },
- {
- "name": "lstrcpynA",
- "address": "0x483194"
- },
- {
- "name": "LoadLibraryExA",
- "address": "0x483198"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x48319c"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x4831a0"
- },
- {
- "name": "GetProcAddress",
- "address": "0x4831a4"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x4831a8"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x4831ac"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x4831b0"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x4831b4"
- },
- {
- "name": "FreeLibrary",
- "address": "0x4831b8"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x4831bc"
- },
- {
- "name": "FindClose",
- "address": "0x4831c0"
- },
- {
- "name": "ExitProcess",
- "address": "0x4831c4"
- },
- {
- "name": "WriteFile",
- "address": "0x4831c8"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x4831cc"
- },
- {
- "name": "RtlUnwind",
- "address": "0x4831d0"
- },
- {
- "name": "RaiseException",
- "address": "0x4831d4"
- },
- {
- "name": "GetStdHandle",
- "address": "0x4831d8"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "GetKeyboardType",
- "address": "0x4831e0"
- },
- {
- "name": "LoadStringA",
- "address": "0x4831e4"
- },
- {
- "name": "MessageBoxA",
- "address": "0x4831e8"
- },
- {
- "name": "CharNextA",
- "address": "0x4831ec"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x4831f4"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x4831f8"
- },
- {
- "name": "RegCloseKey",
- "address": "0x4831fc"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "SysFreeString",
- "address": "0x483204"
- },
- {
- "name": "SysReAllocStringLen",
- "address": "0x483208"
- },
- {
- "name": "SysAllocStringLen",
- "address": "0x48320c"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "TlsSetValue",
- "address": "0x483214"
- },
- {
- "name": "TlsGetValue",
- "address": "0x483218"
- },
- {
- "name": "LocalAlloc",
- "address": "0x48321c"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x483220"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x483228"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x48322c"
- },
- {
- "name": "RegCloseKey",
- "address": "0x483230"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "lstrcpyA",
- "address": "0x483238"
- },
- {
- "name": "WriteFile",
- "address": "0x48323c"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x483240"
- },
- {
- "name": "VirtualQuery",
- "address": "0x483244"
- },
- {
- "name": "VirtualProtectEx",
- "address": "0x483248"
- },
- {
- "name": "VirtualFree",
- "address": "0x48324c"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x483250"
- },
- {
- "name": "Sleep",
- "address": "0x483254"
- },
- {
- "name": "SizeofResource",
- "address": "0x483258"
- },
- {
- "name": "SetThreadLocale",
- "address": "0x48325c"
- },
- {
- "name": "SetFilePointer",
- "address": "0x483260"
- },
- {
- "name": "SetEvent",
- "address": "0x483264"
- },
- {
- "name": "SetErrorMode",
- "address": "0x483268"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x48326c"
- },
- {
- "name": "ResetEvent",
- "address": "0x483270"
- },
- {
- "name": "ReadFile",
- "address": "0x483274"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x483278"
- },
- {
- "name": "MulDiv",
- "address": "0x48327c"
- },
- {
- "name": "LockResource",
- "address": "0x483280"
- },
- {
- "name": "LoadResource",
- "address": "0x483284"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x483288"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x48328c"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x483290"
- },
- {
- "name": "GlobalUnlock",
- "address": "0x483294"
- },
- {
- "name": "GlobalReAlloc",
- "address": "0x483298"
- },
- {
- "name": "GlobalHandle",
- "address": "0x48329c"
- },
- {
- "name": "GlobalLock",
- "address": "0x4832a0"
- },
- {
- "name": "GlobalFree",
- "address": "0x4832a4"
- },
- {
- "name": "GlobalFindAtomA",
- "address": "0x4832a8"
- },
- {
- "name": "GlobalDeleteAtom",
- "address": "0x4832ac"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x4832b0"
- },
- {
- "name": "GlobalAddAtomA",
- "address": "0x4832b4"
- },
- {
- "name": "GetVersionExA",
- "address": "0x4832b8"
- },
- {
- "name": "GetVersion",
- "address": "0x4832bc"
- },
- {
- "name": "GetTickCount",
- "address": "0x4832c0"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x4832c4"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x4832c8"
- },
- {
- "name": "GetStringTypeExA",
- "address": "0x4832cc"
- },
- {
- "name": "GetStdHandle",
- "address": "0x4832d0"
- },
- {
- "name": "GetProcAddress",
- "address": "0x4832d4"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x4832d8"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x4832dc"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x4832e0"
- },
- {
- "name": "GetLocalTime",
- "address": "0x4832e4"
- },
- {
- "name": "GetLastError",
- "address": "0x4832e8"
- },
- {
- "name": "GetFullPathNameA",
- "address": "0x4832ec"
- },
- {
- "name": "GetDiskFreeSpaceA",
- "address": "0x4832f0"
- },
- {
- "name": "GetDateFormatA",
- "address": "0x4832f4"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x4832f8"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x4832fc"
- },
- {
- "name": "GetCPInfo",
- "address": "0x483300"
- },
- {
- "name": "GetACP",
- "address": "0x483304"
- },
- {
- "name": "FreeResource",
- "address": "0x483308"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x48330c"
- },
- {
- "name": "FreeLibrary",
- "address": "0x483310"
- },
- {
- "name": "FormatMessageA",
- "address": "0x483314"
- },
- {
- "name": "FindResourceA",
- "address": "0x483318"
- },
- {
- "name": "EnumCalendarInfoA",
- "address": "0x48331c"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x483320"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x483324"
- },
- {
- "name": "CreateThread",
- "address": "0x483328"
- },
- {
- "name": "CreateFileA",
- "address": "0x48332c"
- },
- {
- "name": "CreateEventA",
- "address": "0x483330"
- },
- {
- "name": "CompareStringA",
- "address": "0x483334"
- },
- {
- "name": "CloseHandle",
- "address": "0x483338"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "VerQueryValueA",
- "address": "0x483340"
- },
- {
- "name": "GetFileVersionInfoSizeA",
- "address": "0x483344"
- },
- {
- "name": "GetFileVersionInfoA",
- "address": "0x483348"
- }
- ],
- "dll": "version.dll"
- },
- {
- "imports": [
- {
- "name": "UnrealizeObject",
- "address": "0x483350"
- },
- {
- "name": "StretchBlt",
- "address": "0x483354"
- },
- {
- "name": "SetWindowOrgEx",
- "address": "0x483358"
- },
- {
- "name": "SetViewportOrgEx",
- "address": "0x48335c"
- },
- {
- "name": "SetTextColor",
- "address": "0x483360"
- },
- {
- "name": "SetStretchBltMode",
- "address": "0x483364"
- },
- {
- "name": "SetROP2",
- "address": "0x483368"
- },
- {
- "name": "SetPixel",
- "address": "0x48336c"
- },
- {
- "name": "SetDIBColorTable",
- "address": "0x483370"
- },
- {
- "name": "SetBrushOrgEx",
- "address": "0x483374"
- },
- {
- "name": "SetBkMode",
- "address": "0x483378"
- },
- {
- "name": "SetBkColor",
- "address": "0x48337c"
- },
- {
- "name": "SelectPalette",
- "address": "0x483380"
- },
- {
- "name": "SelectObject",
- "address": "0x483384"
- },
- {
- "name": "SaveDC",
- "address": "0x483388"
- },
- {
- "name": "RestoreDC",
- "address": "0x48338c"
- },
- {
- "name": "RectVisible",
- "address": "0x483390"
- },
- {
- "name": "RealizePalette",
- "address": "0x483394"
- },
- {
- "name": "PatBlt",
- "address": "0x483398"
- },
- {
- "name": "MoveToEx",
- "address": "0x48339c"
- },
- {
- "name": "MaskBlt",
- "address": "0x4833a0"
- },
- {
- "name": "LineTo",
- "address": "0x4833a4"
- },
- {
- "name": "IntersectClipRect",
- "address": "0x4833a8"
- },
- {
- "name": "GetWindowOrgEx",
- "address": "0x4833ac"
- },
- {
- "name": "GetTextMetricsA",
- "address": "0x4833b0"
- },
- {
- "name": "GetTextExtentPoint32A",
- "address": "0x4833b4"
- },
- {
- "name": "GetSystemPaletteEntries",
- "address": "0x4833b8"
- },
- {
- "name": "GetStockObject",
- "address": "0x4833bc"
- },
- {
- "name": "GetPixel",
- "address": "0x4833c0"
- },
- {
- "name": "GetPaletteEntries",
- "address": "0x4833c4"
- },
- {
- "name": "GetObjectA",
- "address": "0x4833c8"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x4833cc"
- },
- {
- "name": "GetDIBits",
- "address": "0x4833d0"
- },
- {
- "name": "GetDIBColorTable",
- "address": "0x4833d4"
- },
- {
- "name": "GetDCOrgEx",
- "address": "0x4833d8"
- },
- {
- "name": "GetCurrentPositionEx",
- "address": "0x4833dc"
- },
- {
- "name": "GetClipBox",
- "address": "0x4833e0"
- },
- {
- "name": "GetBrushOrgEx",
- "address": "0x4833e4"
- },
- {
- "name": "GetBitmapBits",
- "address": "0x4833e8"
- },
- {
- "name": "ExtTextOutA",
- "address": "0x4833ec"
- },
- {
- "name": "ExcludeClipRect",
- "address": "0x4833f0"
- },
- {
- "name": "DeleteObject",
- "address": "0x4833f4"
- },
- {
- "name": "DeleteDC",
- "address": "0x4833f8"
- },
- {
- "name": "CreateSolidBrush",
- "address": "0x4833fc"
- },
- {
- "name": "CreatePenIndirect",
- "address": "0x483400"
- },
- {
- "name": "CreatePalette",
- "address": "0x483404"
- },
- {
- "name": "CreateHalftonePalette",
- "address": "0x483408"
- },
- {
- "name": "CreateFontIndirectA",
- "address": "0x48340c"
- },
- {
- "name": "CreateDIBitmap",
- "address": "0x483410"
- },
- {
- "name": "CreateDIBSection",
- "address": "0x483414"
- },
- {
- "name": "CreateCompatibleDC",
- "address": "0x483418"
- },
- {
- "name": "CreateCompatibleBitmap",
- "address": "0x48341c"
- },
- {
- "name": "CreateBrushIndirect",
- "address": "0x483420"
- },
- {
- "name": "CreateBitmap",
- "address": "0x483424"
- },
- {
- "name": "BitBlt",
- "address": "0x483428"
- }
- ],
- "dll": "gdi32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateWindowExA",
- "address": "0x483430"
- },
- {
- "name": "WindowFromPoint",
- "address": "0x483434"
- },
- {
- "name": "WinHelpA",
- "address": "0x483438"
- },
- {
- "name": "WaitMessage",
- "address": "0x48343c"
- },
- {
- "name": "UpdateWindow",
- "address": "0x483440"
- },
- {
- "name": "UnregisterClassA",
- "address": "0x483444"
- },
- {
- "name": "UnhookWindowsHookEx",
- "address": "0x483448"
- },
- {
- "name": "TranslateMessage",
- "address": "0x48344c"
- },
- {
- "name": "TranslateMDISysAccel",
- "address": "0x483450"
- },
- {
- "name": "TrackPopupMenu",
- "address": "0x483454"
- },
- {
- "name": "SystemParametersInfoA",
- "address": "0x483458"
- },
- {
- "name": "ShowWindow",
- "address": "0x48345c"
- },
- {
- "name": "ShowScrollBar",
- "address": "0x483460"
- },
- {
- "name": "ShowOwnedPopups",
- "address": "0x483464"
- },
- {
- "name": "ShowCursor",
- "address": "0x483468"
- },
- {
- "name": "SetWindowsHookExA",
- "address": "0x48346c"
- },
- {
- "name": "SetWindowTextA",
- "address": "0x483470"
- },
- {
- "name": "SetWindowPos",
- "address": "0x483474"
- },
- {
- "name": "SetWindowPlacement",
- "address": "0x483478"
- },
- {
- "name": "SetWindowLongA",
- "address": "0x48347c"
- },
- {
- "name": "SetTimer",
- "address": "0x483480"
- },
- {
- "name": "SetScrollRange",
- "address": "0x483484"
- },
- {
- "name": "SetScrollPos",
- "address": "0x483488"
- },
- {
- "name": "SetScrollInfo",
- "address": "0x48348c"
- },
- {
- "name": "SetRect",
- "address": "0x483490"
- },
- {
- "name": "SetPropA",
- "address": "0x483494"
- },
- {
- "name": "SetParent",
- "address": "0x483498"
- },
- {
- "name": "SetMenuItemInfoA",
- "address": "0x48349c"
- },
- {
- "name": "SetMenu",
- "address": "0x4834a0"
- },
- {
- "name": "SetForegroundWindow",
- "address": "0x4834a4"
- },
- {
- "name": "SetFocus",
- "address": "0x4834a8"
- },
- {
- "name": "SetCursor",
- "address": "0x4834ac"
- },
- {
- "name": "SetClassLongA",
- "address": "0x4834b0"
- },
- {
- "name": "SetCapture",
- "address": "0x4834b4"
- },
- {
- "name": "SetActiveWindow",
- "address": "0x4834b8"
- },
- {
- "name": "SendMessageA",
- "address": "0x4834bc"
- },
- {
- "name": "ScrollWindow",
- "address": "0x4834c0"
- },
- {
- "name": "ScreenToClient",
- "address": "0x4834c4"
- },
- {
- "name": "RemovePropA",
- "address": "0x4834c8"
- },
- {
- "name": "RemoveMenu",
- "address": "0x4834cc"
- },
- {
- "name": "ReleaseDC",
- "address": "0x4834d0"
- },
- {
- "name": "ReleaseCapture",
- "address": "0x4834d4"
- },
- {
- "name": "RegisterWindowMessageA",
- "address": "0x4834d8"
- },
- {
- "name": "RegisterClipboardFormatA",
- "address": "0x4834dc"
- },
- {
- "name": "RegisterClassA",
- "address": "0x4834e0"
- },
- {
- "name": "RedrawWindow",
- "address": "0x4834e4"
- },
- {
- "name": "PtInRect",
- "address": "0x4834e8"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x4834ec"
- },
- {
- "name": "PostMessageA",
- "address": "0x4834f0"
- },
- {
- "name": "PeekMessageA",
- "address": "0x4834f4"
- },
- {
- "name": "OffsetRect",
- "address": "0x4834f8"
- },
- {
- "name": "OemToCharA",
- "address": "0x4834fc"
- },
- {
- "name": "MessageBoxA",
- "address": "0x483500"
- },
- {
- "name": "MapWindowPoints",
- "address": "0x483504"
- },
- {
- "name": "MapVirtualKeyA",
- "address": "0x483508"
- },
- {
- "name": "LoadStringA",
- "address": "0x48350c"
- },
- {
- "name": "LoadKeyboardLayoutA",
- "address": "0x483510"
- },
- {
- "name": "LoadIconA",
- "address": "0x483514"
- },
- {
- "name": "LoadCursorA",
- "address": "0x483518"
- },
- {
- "name": "LoadBitmapA",
- "address": "0x48351c"
- },
- {
- "name": "KillTimer",
- "address": "0x483520"
- },
- {
- "name": "IsZoomed",
- "address": "0x483524"
- },
- {
- "name": "IsWindowVisible",
- "address": "0x483528"
- },
- {
- "name": "IsWindowEnabled",
- "address": "0x48352c"
- },
- {
- "name": "IsWindow",
- "address": "0x483530"
- },
- {
- "name": "IsRectEmpty",
- "address": "0x483534"
- },
- {
- "name": "IsIconic",
- "address": "0x483538"
- },
- {
- "name": "IsDialogMessageA",
- "address": "0x48353c"
- },
- {
- "name": "IsChild",
- "address": "0x483540"
- },
- {
- "name": "InvalidateRect",
- "address": "0x483544"
- },
- {
- "name": "IntersectRect",
- "address": "0x483548"
- },
- {
- "name": "InsertMenuItemA",
- "address": "0x48354c"
- },
- {
- "name": "InsertMenuA",
- "address": "0x483550"
- },
- {
- "name": "InflateRect",
- "address": "0x483554"
- },
- {
- "name": "GetWindowThreadProcessId",
- "address": "0x483558"
- },
- {
- "name": "GetWindowTextA",
- "address": "0x48355c"
- },
- {
- "name": "GetWindowRect",
- "address": "0x483560"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x483564"
- },
- {
- "name": "GetWindowLongA",
- "address": "0x483568"
- },
- {
- "name": "GetWindowDC",
- "address": "0x48356c"
- },
- {
- "name": "GetTopWindow",
- "address": "0x483570"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x483574"
- },
- {
- "name": "GetSystemMenu",
- "address": "0x483578"
- },
- {
- "name": "GetSysColorBrush",
- "address": "0x48357c"
- },
- {
- "name": "GetSysColor",
- "address": "0x483580"
- },
- {
- "name": "GetSubMenu",
- "address": "0x483584"
- },
- {
- "name": "GetScrollRange",
- "address": "0x483588"
- },
- {
- "name": "GetScrollPos",
- "address": "0x48358c"
- },
- {
- "name": "GetScrollInfo",
- "address": "0x483590"
- },
- {
- "name": "GetPropA",
- "address": "0x483594"
- },
- {
- "name": "GetParent",
- "address": "0x483598"
- },
- {
- "name": "GetWindow",
- "address": "0x48359c"
- },
- {
- "name": "GetMenuStringA",
- "address": "0x4835a0"
- },
- {
- "name": "GetMenuState",
- "address": "0x4835a4"
- },
- {
- "name": "GetMenuItemInfoA",
- "address": "0x4835a8"
- },
- {
- "name": "GetMenuItemID",
- "address": "0x4835ac"
- },
- {
- "name": "GetMenuItemCount",
- "address": "0x4835b0"
- },
- {
- "name": "GetMenu",
- "address": "0x4835b4"
- },
- {
- "name": "GetLastInputInfo",
- "address": "0x4835b8"
- },
- {
- "name": "GetLastActivePopup",
- "address": "0x4835bc"
- },
- {
- "name": "GetKeyboardState",
- "address": "0x4835c0"
- },
- {
- "name": "GetKeyboardLayoutList",
- "address": "0x4835c4"
- },
- {
- "name": "GetKeyboardLayout",
- "address": "0x4835c8"
- },
- {
- "name": "GetKeyState",
- "address": "0x4835cc"
- },
- {
- "name": "GetKeyNameTextA",
- "address": "0x4835d0"
- },
- {
- "name": "GetIconInfo",
- "address": "0x4835d4"
- },
- {
- "name": "GetForegroundWindow",
- "address": "0x4835d8"
- },
- {
- "name": "GetFocus",
- "address": "0x4835dc"
- },
- {
- "name": "GetDlgItem",
- "address": "0x4835e0"
- },
- {
- "name": "GetDesktopWindow",
- "address": "0x4835e4"
- },
- {
- "name": "GetDCEx",
- "address": "0x4835e8"
- },
- {
- "name": "GetDC",
- "address": "0x4835ec"
- },
- {
- "name": "GetCursorPos",
- "address": "0x4835f0"
- },
- {
- "name": "GetCursor",
- "address": "0x4835f4"
- },
- {
- "name": "GetClipboardViewer",
- "address": "0x4835f8"
- },
- {
- "name": "GetClientRect",
- "address": "0x4835fc"
- },
- {
- "name": "GetClassNameA",
- "address": "0x483600"
- },
- {
- "name": "GetClassInfoA",
- "address": "0x483604"
- },
- {
- "name": "GetCapture",
- "address": "0x483608"
- },
- {
- "name": "GetActiveWindow",
- "address": "0x48360c"
- },
- {
- "name": "FrameRect",
- "address": "0x483610"
- },
- {
- "name": "FindWindowA",
- "address": "0x483614"
- },
- {
- "name": "FillRect",
- "address": "0x483618"
- },
- {
- "name": "EqualRect",
- "address": "0x48361c"
- },
- {
- "name": "EnumWindows",
- "address": "0x483620"
- },
- {
- "name": "EnumThreadWindows",
- "address": "0x483624"
- },
- {
- "name": "EndPaint",
- "address": "0x483628"
- },
- {
- "name": "EnableWindow",
- "address": "0x48362c"
- },
- {
- "name": "EnableScrollBar",
- "address": "0x483630"
- },
- {
- "name": "EnableMenuItem",
- "address": "0x483634"
- },
- {
- "name": "DrawTextA",
- "address": "0x483638"
- },
- {
- "name": "DrawMenuBar",
- "address": "0x48363c"
- },
- {
- "name": "DrawIconEx",
- "address": "0x483640"
- },
- {
- "name": "DrawIcon",
- "address": "0x483644"
- },
- {
- "name": "DrawFrameControl",
- "address": "0x483648"
- },
- {
- "name": "DrawFocusRect",
- "address": "0x48364c"
- },
- {
- "name": "DrawEdge",
- "address": "0x483650"
- },
- {
- "name": "DispatchMessageA",
- "address": "0x483654"
- },
- {
- "name": "DestroyWindow",
- "address": "0x483658"
- },
- {
- "name": "DestroyMenu",
- "address": "0x48365c"
- },
- {
- "name": "DestroyIcon",
- "address": "0x483660"
- },
- {
- "name": "DestroyCursor",
- "address": "0x483664"
- },
- {
- "name": "DeleteMenu",
- "address": "0x483668"
- },
- {
- "name": "DefWindowProcA",
- "address": "0x48366c"
- },
- {
- "name": "DefMDIChildProcA",
- "address": "0x483670"
- },
- {
- "name": "DefFrameProcA",
- "address": "0x483674"
- },
- {
- "name": "CreatePopupMenu",
- "address": "0x483678"
- },
- {
- "name": "CreateMenu",
- "address": "0x48367c"
- },
- {
- "name": "CreateIcon",
- "address": "0x483680"
- },
- {
- "name": "ClientToScreen",
- "address": "0x483684"
- },
- {
- "name": "CheckMenuItem",
- "address": "0x483688"
- },
- {
- "name": "CallWindowProcA",
- "address": "0x48368c"
- },
- {
- "name": "CallNextHookEx",
- "address": "0x483690"
- },
- {
- "name": "BeginPaint",
- "address": "0x483694"
- },
- {
- "name": "CharNextA",
- "address": "0x483698"
- },
- {
- "name": "CharLowerA",
- "address": "0x48369c"
- },
- {
- "name": "CharUpperBuffA",
- "address": "0x4836a0"
- },
- {
- "name": "CharToOemA",
- "address": "0x4836a4"
- },
- {
- "name": "AdjustWindowRectEx",
- "address": "0x4836a8"
- },
- {
- "name": "ActivateKeyboardLayout",
- "address": "0x4836ac"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "Sleep",
- "address": "0x4836b4"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "SafeArrayPtrOfIndex",
- "address": "0x4836bc"
- },
- {
- "name": "SafeArrayPutElement",
- "address": "0x4836c0"
- },
- {
- "name": "SafeArrayGetElement",
- "address": "0x4836c4"
- },
- {
- "name": "SafeArrayUnaccessData",
- "address": "0x4836c8"
- },
- {
- "name": "SafeArrayAccessData",
- "address": "0x4836cc"
- },
- {
- "name": "SafeArrayGetUBound",
- "address": "0x4836d0"
- },
- {
- "name": "SafeArrayGetLBound",
- "address": "0x4836d4"
- },
- {
- "name": "SafeArrayCreate",
- "address": "0x4836d8"
- },
- {
- "name": "VariantChangeType",
- "address": "0x4836dc"
- },
- {
- "name": "VariantCopyInd",
- "address": "0x4836e0"
- },
- {
- "name": "VariantCopy",
- "address": "0x4836e4"
- },
- {
- "name": "VariantClear",
- "address": "0x4836e8"
- },
- {
- "name": "VariantInit",
- "address": "0x4836ec"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "CoUninitialize",
- "address": "0x4836f4"
- },
- {
- "name": "CoInitialize",
- "address": "0x4836f8"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "GetErrorInfo",
- "address": "0x483700"
- },
- {
- "name": "SysFreeString",
- "address": "0x483704"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "ImageList_SetIconSize",
- "address": "0x48370c"
- },
- {
- "name": "ImageList_GetIconSize",
- "address": "0x483710"
- },
- {
- "name": "ImageList_Write",
- "address": "0x483714"
- },
- {
- "name": "ImageList_Read",
- "address": "0x483718"
- },
- {
- "name": "ImageList_GetDragImage",
- "address": "0x48371c"
- },
- {
- "name": "ImageList_DragShowNolock",
- "address": "0x483720"
- },
- {
- "name": "ImageList_SetDragCursorImage",
- "address": "0x483724"
- },
- {
- "name": "ImageList_DragMove",
- "address": "0x483728"
- },
- {
- "name": "ImageList_DragLeave",
- "address": "0x48372c"
- },
- {
- "name": "ImageList_DragEnter",
- "address": "0x483730"
- },
- {
- "name": "ImageList_EndDrag",
- "address": "0x483734"
- },
- {
- "name": "ImageList_BeginDrag",
- "address": "0x483738"
- },
- {
- "name": "ImageList_Remove",
- "address": "0x48373c"
- },
- {
- "name": "ImageList_DrawEx",
- "address": "0x483740"
- },
- {
- "name": "ImageList_Draw",
- "address": "0x483744"
- },
- {
- "name": "ImageList_GetBkColor",
- "address": "0x483748"
- },
- {
- "name": "ImageList_SetBkColor",
- "address": "0x48374c"
- },
- {
- "name": "ImageList_ReplaceIcon",
- "address": "0x483750"
- },
- {
- "name": "ImageList_Add",
- "address": "0x483754"
- },
- {
- "name": "ImageList_GetImageCount",
- "address": "0x483758"
- },
- {
- "name": "ImageList_Destroy",
- "address": "0x48375c"
- },
- {
- "name": "ImageList_Create",
- "address": "0x483760"
- }
- ],
- "dll": "comctl32.dll"
- },
- {
- "imports": [
- {
- "name": "GetSaveFileNameA",
- "address": "0x483768"
- },
- {
- "name": "GetOpenFileNameA",
- "address": "0x48376c"
- }
- ],
- "dll": "comdlg32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x000c9b64",
- "overlay": {
- "size": "0x00000200",
- "offset": "0x000c4e00"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x0047477c",
- "timestamp": "1992-05-07 20:59:57",
- "osversion": "4.0",
- "sections": [
- {
- "name": "CODE",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00073800",
- "entropy": "6.57",
- "raw_address": "0x00000400",
- "virtual_size": "0x000737c4",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": "DATA",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00075000",
- "size_of_data": "0x0000d000",
- "entropy": "3.93",
- "raw_address": "0x00073c00",
- "virtual_size": "0x0000cef0",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": "BSS",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00082000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00080c00",
- "virtual_size": "0x00000c45",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".idata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00083000",
- "size_of_data": "0x00002200",
- "entropy": "4.91",
- "raw_address": "0x00080c00",
- "virtual_size": "0x00002174",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00086000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00082e00",
- "virtual_size": "0x00000010",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00087000",
- "size_of_data": "0x00000200",
- "entropy": "0.21",
- "raw_address": "0x00082e00",
- "virtual_size": "0x00000018",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00088000",
- "size_of_data": "0x00009000",
- "entropy": "6.61",
- "raw_address": "0x00083000",
- "virtual_size": "0x00008e40",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00091000",
- "size_of_data": "0x00038e00",
- "entropy": "7.18",
- "raw_address": "0x0008c000",
- "virtual_size": "0x00038df4",
- "characteristics_raw": "0x50000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00083000",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00002174"
- },
- {
- "virtual_address": "0x00091000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00038df4"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00088000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00008e40"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00087000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "08d63d076187e00ae831c8357d868390",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 16,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "kernel32.dll.GetDiskFreeSpaceExA",
- "oleaut32.dll.VariantChangeTypeEx",
- "oleaut32.dll.VarNeg",
- "oleaut32.dll.VarNot",
- "oleaut32.dll.VarAdd",
- "oleaut32.dll.VarSub",
- "oleaut32.dll.VarMul",
- "oleaut32.dll.VarDiv",
- "oleaut32.dll.VarIdiv",
- "oleaut32.dll.VarMod",
- "oleaut32.dll.VarAnd",
- "oleaut32.dll.VarOr",
- "oleaut32.dll.VarXor",
- "oleaut32.dll.VarCmp",
- "oleaut32.dll.VarI4FromStr",
- "oleaut32.dll.VarR4FromStr",
- "oleaut32.dll.VarR8FromStr",
- "oleaut32.dll.VarDateFromStr",
- "oleaut32.dll.VarCyFromStr",
- "oleaut32.dll.VarBoolFromStr",
- "oleaut32.dll.VarBstrFromCy",
- "oleaut32.dll.VarBstrFromDate",
- "oleaut32.dll.VarBstrFromBool",
- "user32.dll.GetMonitorInfoA",
- "user32.dll.GetSystemMetrics",
- "user32.dll.EnumDisplayMonitors",
- "dwmapi.dll.DwmIsCompositionEnabled",
- "gdi32.dll.GetLayout",
- "gdi32.dll.GdiRealizationInfo",
- "gdi32.dll.FontIsLinked",
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegQueryInfoKeyW",
- "gdi32.dll.GetTextFaceAliasW",
- "advapi32.dll.RegEnumValueW",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.RegQueryValueExW",
- "gdi32.dll.GetFontAssocStatus",
- "advapi32.dll.RegQueryValueExA",
- "advapi32.dll.RegEnumKeyExW",
- "gdi32.dll.GdiIsMetaPrintDC",
- "user32.dll.AnimateWindow",
- "comctl32.dll.InitializeFlatSB",
- "comctl32.dll.UninitializeFlatSB",
- "comctl32.dll.FlatSB_GetScrollProp",
- "comctl32.dll.FlatSB_SetScrollProp",
- "comctl32.dll.FlatSB_EnableScrollBar",
- "comctl32.dll.FlatSB_ShowScrollBar",
- "comctl32.dll.FlatSB_GetScrollRange",
- "comctl32.dll.FlatSB_GetScrollInfo",
- "comctl32.dll.FlatSB_GetScrollPos",
- "comctl32.dll.FlatSB_SetScrollPos",
- "comctl32.dll.FlatSB_SetScrollInfo",
- "comctl32.dll.FlatSB_SetScrollRange",
- "user32.dll.SetLayeredWindowAttributes",
- "ole32.dll.CoCreateInstanceEx",
- "ole32.dll.CoInitializeEx",
- "ole32.dll.CoAddRefServerProcess",
- "ole32.dll.CoReleaseServerProcess",
- "ole32.dll.CoResumeClassObjects",
- "ole32.dll.CoSuspendClassObjects"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DeleteCriticalSection",
- "address": "0x483154"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x483158"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x48315c"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x483160"
- },
- {
- "name": "VirtualFree",
- "address": "0x483164"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x483168"
- },
- {
- "name": "LocalFree",
- "address": "0x48316c"
- },
- {
- "name": "LocalAlloc",
- "address": "0x483170"
- },
- {
- "name": "GetVersion",
- "address": "0x483174"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x483178"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x48317c"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x483180"
- },
- {
- "name": "VirtualQuery",
- "address": "0x483184"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x483188"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x48318c"
- },
- {
- "name": "lstrlenA",
- "address": "0x483190"
- },
- {
- "name": "lstrcpynA",
- "address": "0x483194"
- },
- {
- "name": "LoadLibraryExA",
- "address": "0x483198"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x48319c"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x4831a0"
- },
- {
- "name": "GetProcAddress",
- "address": "0x4831a4"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x4831a8"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x4831ac"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x4831b0"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x4831b4"
- },
- {
- "name": "FreeLibrary",
- "address": "0x4831b8"
- },
- {
- "name": "FindFirstFileA",
- "address": "0x4831bc"
- },
- {
- "name": "FindClose",
- "address": "0x4831c0"
- },
- {
- "name": "ExitProcess",
- "address": "0x4831c4"
- },
- {
- "name": "WriteFile",
- "address": "0x4831c8"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x4831cc"
- },
- {
- "name": "RtlUnwind",
- "address": "0x4831d0"
- },
- {
- "name": "RaiseException",
- "address": "0x4831d4"
- },
- {
- "name": "GetStdHandle",
- "address": "0x4831d8"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "GetKeyboardType",
- "address": "0x4831e0"
- },
- {
- "name": "LoadStringA",
- "address": "0x4831e4"
- },
- {
- "name": "MessageBoxA",
- "address": "0x4831e8"
- },
- {
- "name": "CharNextA",
- "address": "0x4831ec"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x4831f4"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x4831f8"
- },
- {
- "name": "RegCloseKey",
- "address": "0x4831fc"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "SysFreeString",
- "address": "0x483204"
- },
- {
- "name": "SysReAllocStringLen",
- "address": "0x483208"
- },
- {
- "name": "SysAllocStringLen",
- "address": "0x48320c"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "TlsSetValue",
- "address": "0x483214"
- },
- {
- "name": "TlsGetValue",
- "address": "0x483218"
- },
- {
- "name": "LocalAlloc",
- "address": "0x48321c"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x483220"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "RegQueryValueExA",
- "address": "0x483228"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x48322c"
- },
- {
- "name": "RegCloseKey",
- "address": "0x483230"
- }
- ],
- "dll": "advapi32.dll"
- },
- {
- "imports": [
- {
- "name": "lstrcpyA",
- "address": "0x483238"
- },
- {
- "name": "WriteFile",
- "address": "0x48323c"
- },
- {
- "name": "WaitForSingleObject",
- "address": "0x483240"
- },
- {
- "name": "VirtualQuery",
- "address": "0x483244"
- },
- {
- "name": "VirtualProtectEx",
- "address": "0x483248"
- },
- {
- "name": "VirtualFree",
- "address": "0x48324c"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x483250"
- },
- {
- "name": "Sleep",
- "address": "0x483254"
- },
- {
- "name": "SizeofResource",
- "address": "0x483258"
- },
- {
- "name": "SetThreadLocale",
- "address": "0x48325c"
- },
- {
- "name": "SetFilePointer",
- "address": "0x483260"
- },
- {
- "name": "SetEvent",
- "address": "0x483264"
- },
- {
- "name": "SetErrorMode",
- "address": "0x483268"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x48326c"
- },
- {
- "name": "ResetEvent",
- "address": "0x483270"
- },
- {
- "name": "ReadFile",
- "address": "0x483274"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x483278"
- },
- {
- "name": "MulDiv",
- "address": "0x48327c"
- },
- {
- "name": "LockResource",
- "address": "0x483280"
- },
- {
- "name": "LoadResource",
- "address": "0x483284"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x483288"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x48328c"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x483290"
- },
- {
- "name": "GlobalUnlock",
- "address": "0x483294"
- },
- {
- "name": "GlobalReAlloc",
- "address": "0x483298"
- },
- {
- "name": "GlobalHandle",
- "address": "0x48329c"
- },
- {
- "name": "GlobalLock",
- "address": "0x4832a0"
- },
- {
- "name": "GlobalFree",
- "address": "0x4832a4"
- },
- {
- "name": "GlobalFindAtomA",
- "address": "0x4832a8"
- },
- {
- "name": "GlobalDeleteAtom",
- "address": "0x4832ac"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x4832b0"
- },
- {
- "name": "GlobalAddAtomA",
- "address": "0x4832b4"
- },
- {
- "name": "GetVersionExA",
- "address": "0x4832b8"
- },
- {
- "name": "GetVersion",
- "address": "0x4832bc"
- },
- {
- "name": "GetTickCount",
- "address": "0x4832c0"
- },
- {
- "name": "GetThreadLocale",
- "address": "0x4832c4"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x4832c8"
- },
- {
- "name": "GetStringTypeExA",
- "address": "0x4832cc"
- },
- {
- "name": "GetStdHandle",
- "address": "0x4832d0"
- },
- {
- "name": "GetProcAddress",
- "address": "0x4832d4"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x4832d8"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x4832dc"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x4832e0"
- },
- {
- "name": "GetLocalTime",
- "address": "0x4832e4"
- },
- {
- "name": "GetLastError",
- "address": "0x4832e8"
- },
- {
- "name": "GetFullPathNameA",
- "address": "0x4832ec"
- },
- {
- "name": "GetDiskFreeSpaceA",
- "address": "0x4832f0"
- },
- {
- "name": "GetDateFormatA",
- "address": "0x4832f4"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x4832f8"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x4832fc"
- },
- {
- "name": "GetCPInfo",
- "address": "0x483300"
- },
- {
- "name": "GetACP",
- "address": "0x483304"
- },
- {
- "name": "FreeResource",
- "address": "0x483308"
- },
- {
- "name": "InterlockedExchange",
- "address": "0x48330c"
- },
- {
- "name": "FreeLibrary",
- "address": "0x483310"
- },
- {
- "name": "FormatMessageA",
- "address": "0x483314"
- },
- {
- "name": "FindResourceA",
- "address": "0x483318"
- },
- {
- "name": "EnumCalendarInfoA",
- "address": "0x48331c"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x483320"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x483324"
- },
- {
- "name": "CreateThread",
- "address": "0x483328"
- },
- {
- "name": "CreateFileA",
- "address": "0x48332c"
- },
- {
- "name": "CreateEventA",
- "address": "0x483330"
- },
- {
- "name": "CompareStringA",
- "address": "0x483334"
- },
- {
- "name": "CloseHandle",
- "address": "0x483338"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "VerQueryValueA",
- "address": "0x483340"
- },
- {
- "name": "GetFileVersionInfoSizeA",
- "address": "0x483344"
- },
- {
- "name": "GetFileVersionInfoA",
- "address": "0x483348"
- }
- ],
- "dll": "version.dll"
- },
- {
- "imports": [
- {
- "name": "UnrealizeObject",
- "address": "0x483350"
- },
- {
- "name": "StretchBlt",
- "address": "0x483354"
- },
- {
- "name": "SetWindowOrgEx",
- "address": "0x483358"
- },
- {
- "name": "SetViewportOrgEx",
- "address": "0x48335c"
- },
- {
- "name": "SetTextColor",
- "address": "0x483360"
- },
- {
- "name": "SetStretchBltMode",
- "address": "0x483364"
- },
- {
- "name": "SetROP2",
- "address": "0x483368"
- },
- {
- "name": "SetPixel",
- "address": "0x48336c"
- },
- {
- "name": "SetDIBColorTable",
- "address": "0x483370"
- },
- {
- "name": "SetBrushOrgEx",
- "address": "0x483374"
- },
- {
- "name": "SetBkMode",
- "address": "0x483378"
- },
- {
- "name": "SetBkColor",
- "address": "0x48337c"
- },
- {
- "name": "SelectPalette",
- "address": "0x483380"
- },
- {
- "name": "SelectObject",
- "address": "0x483384"
- },
- {
- "name": "SaveDC",
- "address": "0x483388"
- },
- {
- "name": "RestoreDC",
- "address": "0x48338c"
- },
- {
- "name": "RectVisible",
- "address": "0x483390"
- },
- {
- "name": "RealizePalette",
- "address": "0x483394"
- },
- {
- "name": "PatBlt",
- "address": "0x483398"
- },
- {
- "name": "MoveToEx",
- "address": "0x48339c"
- },
- {
- "name": "MaskBlt",
- "address": "0x4833a0"
- },
- {
- "name": "LineTo",
- "address": "0x4833a4"
- },
- {
- "name": "IntersectClipRect",
- "address": "0x4833a8"
- },
- {
- "name": "GetWindowOrgEx",
- "address": "0x4833ac"
- },
- {
- "name": "GetTextMetricsA",
- "address": "0x4833b0"
- },
- {
- "name": "GetTextExtentPoint32A",
- "address": "0x4833b4"
- },
- {
- "name": "GetSystemPaletteEntries",
- "address": "0x4833b8"
- },
- {
- "name": "GetStockObject",
- "address": "0x4833bc"
- },
- {
- "name": "GetPixel",
- "address": "0x4833c0"
- },
- {
- "name": "GetPaletteEntries",
- "address": "0x4833c4"
- },
- {
- "name": "GetObjectA",
- "address": "0x4833c8"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x4833cc"
- },
- {
- "name": "GetDIBits",
- "address": "0x4833d0"
- },
- {
- "name": "GetDIBColorTable",
- "address": "0x4833d4"
- },
- {
- "name": "GetDCOrgEx",
- "address": "0x4833d8"
- },
- {
- "name": "GetCurrentPositionEx",
- "address": "0x4833dc"
- },
- {
- "name": "GetClipBox",
- "address": "0x4833e0"
- },
- {
- "name": "GetBrushOrgEx",
- "address": "0x4833e4"
- },
- {
- "name": "GetBitmapBits",
- "address": "0x4833e8"
- },
- {
- "name": "ExtTextOutA",
- "address": "0x4833ec"
- },
- {
- "name": "ExcludeClipRect",
- "address": "0x4833f0"
- },
- {
- "name": "DeleteObject",
- "address": "0x4833f4"
- },
- {
- "name": "DeleteDC",
- "address": "0x4833f8"
- },
- {
- "name": "CreateSolidBrush",
- "address": "0x4833fc"
- },
- {
- "name": "CreatePenIndirect",
- "address": "0x483400"
- },
- {
- "name": "CreatePalette",
- "address": "0x483404"
- },
- {
- "name": "CreateHalftonePalette",
- "address": "0x483408"
- },
- {
- "name": "CreateFontIndirectA",
- "address": "0x48340c"
- },
- {
- "name": "CreateDIBitmap",
- "address": "0x483410"
- },
- {
- "name": "CreateDIBSection",
- "address": "0x483414"
- },
- {
- "name": "CreateCompatibleDC",
- "address": "0x483418"
- },
- {
- "name": "CreateCompatibleBitmap",
- "address": "0x48341c"
- },
- {
- "name": "CreateBrushIndirect",
- "address": "0x483420"
- },
- {
- "name": "CreateBitmap",
- "address": "0x483424"
- },
- {
- "name": "BitBlt",
- "address": "0x483428"
- }
- ],
- "dll": "gdi32.dll"
- },
- {
- "imports": [
- {
- "name": "CreateWindowExA",
- "address": "0x483430"
- },
- {
- "name": "WindowFromPoint",
- "address": "0x483434"
- },
- {
- "name": "WinHelpA",
- "address": "0x483438"
- },
- {
- "name": "WaitMessage",
- "address": "0x48343c"
- },
- {
- "name": "UpdateWindow",
- "address": "0x483440"
- },
- {
- "name": "UnregisterClassA",
- "address": "0x483444"
- },
- {
- "name": "UnhookWindowsHookEx",
- "address": "0x483448"
- },
- {
- "name": "TranslateMessage",
- "address": "0x48344c"
- },
- {
- "name": "TranslateMDISysAccel",
- "address": "0x483450"
- },
- {
- "name": "TrackPopupMenu",
- "address": "0x483454"
- },
- {
- "name": "SystemParametersInfoA",
- "address": "0x483458"
- },
- {
- "name": "ShowWindow",
- "address": "0x48345c"
- },
- {
- "name": "ShowScrollBar",
- "address": "0x483460"
- },
- {
- "name": "ShowOwnedPopups",
- "address": "0x483464"
- },
- {
- "name": "ShowCursor",
- "address": "0x483468"
- },
- {
- "name": "SetWindowsHookExA",
- "address": "0x48346c"
- },
- {
- "name": "SetWindowTextA",
- "address": "0x483470"
- },
- {
- "name": "SetWindowPos",
- "address": "0x483474"
- },
- {
- "name": "SetWindowPlacement",
- "address": "0x483478"
- },
- {
- "name": "SetWindowLongA",
- "address": "0x48347c"
- },
- {
- "name": "SetTimer",
- "address": "0x483480"
- },
- {
- "name": "SetScrollRange",
- "address": "0x483484"
- },
- {
- "name": "SetScrollPos",
- "address": "0x483488"
- },
- {
- "name": "SetScrollInfo",
- "address": "0x48348c"
- },
- {
- "name": "SetRect",
- "address": "0x483490"
- },
- {
- "name": "SetPropA",
- "address": "0x483494"
- },
- {
- "name": "SetParent",
- "address": "0x483498"
- },
- {
- "name": "SetMenuItemInfoA",
- "address": "0x48349c"
- },
- {
- "name": "SetMenu",
- "address": "0x4834a0"
- },
- {
- "name": "SetForegroundWindow",
- "address": "0x4834a4"
- },
- {
- "name": "SetFocus",
- "address": "0x4834a8"
- },
- {
- "name": "SetCursor",
- "address": "0x4834ac"
- },
- {
- "name": "SetClassLongA",
- "address": "0x4834b0"
- },
- {
- "name": "SetCapture",
- "address": "0x4834b4"
- },
- {
- "name": "SetActiveWindow",
- "address": "0x4834b8"
- },
- {
- "name": "SendMessageA",
- "address": "0x4834bc"
- },
- {
- "name": "ScrollWindow",
- "address": "0x4834c0"
- },
- {
- "name": "ScreenToClient",
- "address": "0x4834c4"
- },
- {
- "name": "RemovePropA",
- "address": "0x4834c8"
- },
- {
- "name": "RemoveMenu",
- "address": "0x4834cc"
- },
- {
- "name": "ReleaseDC",
- "address": "0x4834d0"
- },
- {
- "name": "ReleaseCapture",
- "address": "0x4834d4"
- },
- {
- "name": "RegisterWindowMessageA",
- "address": "0x4834d8"
- },
- {
- "name": "RegisterClipboardFormatA",
- "address": "0x4834dc"
- },
- {
- "name": "RegisterClassA",
- "address": "0x4834e0"
- },
- {
- "name": "RedrawWindow",
- "address": "0x4834e4"
- },
- {
- "name": "PtInRect",
- "address": "0x4834e8"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x4834ec"
- },
- {
- "name": "PostMessageA",
- "address": "0x4834f0"
- },
- {
- "name": "PeekMessageA",
- "address": "0x4834f4"
- },
- {
- "name": "OffsetRect",
- "address": "0x4834f8"
- },
- {
- "name": "OemToCharA",
- "address": "0x4834fc"
- },
- {
- "name": "MessageBoxA",
- "address": "0x483500"
- },
- {
- "name": "MapWindowPoints",
- "address": "0x483504"
- },
- {
- "name": "MapVirtualKeyA",
- "address": "0x483508"
- },
- {
- "name": "LoadStringA",
- "address": "0x48350c"
- },
- {
- "name": "LoadKeyboardLayoutA",
- "address": "0x483510"
- },
- {
- "name": "LoadIconA",
- "address": "0x483514"
- },
- {
- "name": "LoadCursorA",
- "address": "0x483518"
- },
- {
- "name": "LoadBitmapA",
- "address": "0x48351c"
- },
- {
- "name": "KillTimer",
- "address": "0x483520"
- },
- {
- "name": "IsZoomed",
- "address": "0x483524"
- },
- {
- "name": "IsWindowVisible",
- "address": "0x483528"
- },
- {
- "name": "IsWindowEnabled",
- "address": "0x48352c"
- },
- {
- "name": "IsWindow",
- "address": "0x483530"
- },
- {
- "name": "IsRectEmpty",
- "address": "0x483534"
- },
- {
- "name": "IsIconic",
- "address": "0x483538"
- },
- {
- "name": "IsDialogMessageA",
- "address": "0x48353c"
- },
- {
- "name": "IsChild",
- "address": "0x483540"
- },
- {
- "name": "InvalidateRect",
- "address": "0x483544"
- },
- {
- "name": "IntersectRect",
- "address": "0x483548"
- },
- {
- "name": "InsertMenuItemA",
- "address": "0x48354c"
- },
- {
- "name": "InsertMenuA",
- "address": "0x483550"
- },
- {
- "name": "InflateRect",
- "address": "0x483554"
- },
- {
- "name": "GetWindowThreadProcessId",
- "address": "0x483558"
- },
- {
- "name": "GetWindowTextA",
- "address": "0x48355c"
- },
- {
- "name": "GetWindowRect",
- "address": "0x483560"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x483564"
- },
- {
- "name": "GetWindowLongA",
- "address": "0x483568"
- },
- {
- "name": "GetWindowDC",
- "address": "0x48356c"
- },
- {
- "name": "GetTopWindow",
- "address": "0x483570"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x483574"
- },
- {
- "name": "GetSystemMenu",
- "address": "0x483578"
- },
- {
- "name": "GetSysColorBrush",
- "address": "0x48357c"
- },
- {
- "name": "GetSysColor",
- "address": "0x483580"
- },
- {
- "name": "GetSubMenu",
- "address": "0x483584"
- },
- {
- "name": "GetScrollRange",
- "address": "0x483588"
- },
- {
- "name": "GetScrollPos",
- "address": "0x48358c"
- },
- {
- "name": "GetScrollInfo",
- "address": "0x483590"
- },
- {
- "name": "GetPropA",
- "address": "0x483594"
- },
- {
- "name": "GetParent",
- "address": "0x483598"
- },
- {
- "name": "GetWindow",
- "address": "0x48359c"
- },
- {
- "name": "GetMenuStringA",
- "address": "0x4835a0"
- },
- {
- "name": "GetMenuState",
- "address": "0x4835a4"
- },
- {
- "name": "GetMenuItemInfoA",
- "address": "0x4835a8"
- },
- {
- "name": "GetMenuItemID",
- "address": "0x4835ac"
- },
- {
- "name": "GetMenuItemCount",
- "address": "0x4835b0"
- },
- {
- "name": "GetMenu",
- "address": "0x4835b4"
- },
- {
- "name": "GetLastInputInfo",
- "address": "0x4835b8"
- },
- {
- "name": "GetLastActivePopup",
- "address": "0x4835bc"
- },
- {
- "name": "GetKeyboardState",
- "address": "0x4835c0"
- },
- {
- "name": "GetKeyboardLayoutList",
- "address": "0x4835c4"
- },
- {
- "name": "GetKeyboardLayout",
- "address": "0x4835c8"
- },
- {
- "name": "GetKeyState",
- "address": "0x4835cc"
- },
- {
- "name": "GetKeyNameTextA",
- "address": "0x4835d0"
- },
- {
- "name": "GetIconInfo",
- "address": "0x4835d4"
- },
- {
- "name": "GetForegroundWindow",
- "address": "0x4835d8"
- },
- {
- "name": "GetFocus",
- "address": "0x4835dc"
- },
- {
- "name": "GetDlgItem",
- "address": "0x4835e0"
- },
- {
- "name": "GetDesktopWindow",
- "address": "0x4835e4"
- },
- {
- "name": "GetDCEx",
- "address": "0x4835e8"
- },
- {
- "name": "GetDC",
- "address": "0x4835ec"
- },
- {
- "name": "GetCursorPos",
- "address": "0x4835f0"
- },
- {
- "name": "GetCursor",
- "address": "0x4835f4"
- },
- {
- "name": "GetClipboardViewer",
- "address": "0x4835f8"
- },
- {
- "name": "GetClientRect",
- "address": "0x4835fc"
- },
- {
- "name": "GetClassNameA",
- "address": "0x483600"
- },
- {
- "name": "GetClassInfoA",
- "address": "0x483604"
- },
- {
- "name": "GetCapture",
- "address": "0x483608"
- },
- {
- "name": "GetActiveWindow",
- "address": "0x48360c"
- },
- {
- "name": "FrameRect",
- "address": "0x483610"
- },
- {
- "name": "FindWindowA",
- "address": "0x483614"
- },
- {
- "name": "FillRect",
- "address": "0x483618"
- },
- {
- "name": "EqualRect",
- "address": "0x48361c"
- },
- {
- "name": "EnumWindows",
- "address": "0x483620"
- },
- {
- "name": "EnumThreadWindows",
- "address": "0x483624"
- },
- {
- "name": "EndPaint",
- "address": "0x483628"
- },
- {
- "name": "EnableWindow",
- "address": "0x48362c"
- },
- {
- "name": "EnableScrollBar",
- "address": "0x483630"
- },
- {
- "name": "EnableMenuItem",
- "address": "0x483634"
- },
- {
- "name": "DrawTextA",
- "address": "0x483638"
- },
- {
- "name": "DrawMenuBar",
- "address": "0x48363c"
- },
- {
- "name": "DrawIconEx",
- "address": "0x483640"
- },
- {
- "name": "DrawIcon",
- "address": "0x483644"
- },
- {
- "name": "DrawFrameControl",
- "address": "0x483648"
- },
- {
- "name": "DrawFocusRect",
- "address": "0x48364c"
- },
- {
- "name": "DrawEdge",
- "address": "0x483650"
- },
- {
- "name": "DispatchMessageA",
- "address": "0x483654"
- },
- {
- "name": "DestroyWindow",
- "address": "0x483658"
- },
- {
- "name": "DestroyMenu",
- "address": "0x48365c"
- },
- {
- "name": "DestroyIcon",
- "address": "0x483660"
- },
- {
- "name": "DestroyCursor",
- "address": "0x483664"
- },
- {
- "name": "DeleteMenu",
- "address": "0x483668"
- },
- {
- "name": "DefWindowProcA",
- "address": "0x48366c"
- },
- {
- "name": "DefMDIChildProcA",
- "address": "0x483670"
- },
- {
- "name": "DefFrameProcA",
- "address": "0x483674"
- },
- {
- "name": "CreatePopupMenu",
- "address": "0x483678"
- },
- {
- "name": "CreateMenu",
- "address": "0x48367c"
- },
- {
- "name": "CreateIcon",
- "address": "0x483680"
- },
- {
- "name": "ClientToScreen",
- "address": "0x483684"
- },
- {
- "name": "CheckMenuItem",
- "address": "0x483688"
- },
- {
- "name": "CallWindowProcA",
- "address": "0x48368c"
- },
- {
- "name": "CallNextHookEx",
- "address": "0x483690"
- },
- {
- "name": "BeginPaint",
- "address": "0x483694"
- },
- {
- "name": "CharNextA",
- "address": "0x483698"
- },
- {
- "name": "CharLowerA",
- "address": "0x48369c"
- },
- {
- "name": "CharUpperBuffA",
- "address": "0x4836a0"
- },
- {
- "name": "CharToOemA",
- "address": "0x4836a4"
- },
- {
- "name": "AdjustWindowRectEx",
- "address": "0x4836a8"
- },
- {
- "name": "ActivateKeyboardLayout",
- "address": "0x4836ac"
- }
- ],
- "dll": "user32.dll"
- },
- {
- "imports": [
- {
- "name": "Sleep",
- "address": "0x4836b4"
- }
- ],
- "dll": "kernel32.dll"
- },
- {
- "imports": [
- {
- "name": "SafeArrayPtrOfIndex",
- "address": "0x4836bc"
- },
- {
- "name": "SafeArrayPutElement",
- "address": "0x4836c0"
- },
- {
- "name": "SafeArrayGetElement",
- "address": "0x4836c4"
- },
- {
- "name": "SafeArrayUnaccessData",
- "address": "0x4836c8"
- },
- {
- "name": "SafeArrayAccessData",
- "address": "0x4836cc"
- },
- {
- "name": "SafeArrayGetUBound",
- "address": "0x4836d0"
- },
- {
- "name": "SafeArrayGetLBound",
- "address": "0x4836d4"
- },
- {
- "name": "SafeArrayCreate",
- "address": "0x4836d8"
- },
- {
- "name": "VariantChangeType",
- "address": "0x4836dc"
- },
- {
- "name": "VariantCopyInd",
- "address": "0x4836e0"
- },
- {
- "name": "VariantCopy",
- "address": "0x4836e4"
- },
- {
- "name": "VariantClear",
- "address": "0x4836e8"
- },
- {
- "name": "VariantInit",
- "address": "0x4836ec"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "CoUninitialize",
- "address": "0x4836f4"
- },
- {
- "name": "CoInitialize",
- "address": "0x4836f8"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "GetErrorInfo",
- "address": "0x483700"
- },
- {
- "name": "SysFreeString",
- "address": "0x483704"
- }
- ],
- "dll": "oleaut32.dll"
- },
- {
- "imports": [
- {
- "name": "ImageList_SetIconSize",
- "address": "0x48370c"
- },
- {
- "name": "ImageList_GetIconSize",
- "address": "0x483710"
- },
- {
- "name": "ImageList_Write",
- "address": "0x483714"
- },
- {
- "name": "ImageList_Read",
- "address": "0x483718"
- },
- {
- "name": "ImageList_GetDragImage",
- "address": "0x48371c"
- },
- {
- "name": "ImageList_DragShowNolock",
- "address": "0x483720"
- },
- {
- "name": "ImageList_SetDragCursorImage",
- "address": "0x483724"
- },
- {
- "name": "ImageList_DragMove",
- "address": "0x483728"
- },
- {
- "name": "ImageList_DragLeave",
- "address": "0x48372c"
- },
- {
- "name": "ImageList_DragEnter",
- "address": "0x483730"
- },
- {
- "name": "ImageList_EndDrag",
- "address": "0x483734"
- },
- {
- "name": "ImageList_BeginDrag",
- "address": "0x483738"
- },
- {
- "name": "ImageList_Remove",
- "address": "0x48373c"
- },
- {
- "name": "ImageList_DrawEx",
- "address": "0x483740"
- },
- {
- "name": "ImageList_Draw",
- "address": "0x483744"
- },
- {
- "name": "ImageList_GetBkColor",
- "address": "0x483748"
- },
- {
- "name": "ImageList_SetBkColor",
- "address": "0x48374c"
- },
- {
- "name": "ImageList_ReplaceIcon",
- "address": "0x483750"
- },
- {
- "name": "ImageList_Add",
- "address": "0x483754"
- },
- {
- "name": "ImageList_GetImageCount",
- "address": "0x483758"
- },
- {
- "name": "ImageList_Destroy",
- "address": "0x48375c"
- },
- {
- "name": "ImageList_Create",
- "address": "0x483760"
- }
- ],
- "dll": "comctl32.dll"
- },
- {
- "imports": [
- {
- "name": "GetSaveFileNameA",
- "address": "0x483768"
- },
- {
- "name": "GetOpenFileNameA",
- "address": "0x48376c"
- }
- ],
- "dll": "comdlg32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x000c9b64",
- "overlay": {
- "size": "0x00000200",
- "offset": "0x000c4e00"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x0047477c",
- "timestamp": "1992-05-07 20:59:57",
- "osversion": "4.0",
- "sections": [
- {
- "name": "CODE",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00073800",
- "entropy": "6.57",
- "raw_address": "0x00000400",
- "virtual_size": "0x000737c4",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": "DATA",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00075000",
- "size_of_data": "0x0000d000",
- "entropy": "3.93",
- "raw_address": "0x00073c00",
- "virtual_size": "0x0000cef0",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": "BSS",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00082000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00080c00",
- "virtual_size": "0x00000c45",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".idata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00083000",
- "size_of_data": "0x00002200",
- "entropy": "4.91",
- "raw_address": "0x00080c00",
- "virtual_size": "0x00002174",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".tls",
- "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00086000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00082e00",
- "virtual_size": "0x00000010",
- "characteristics_raw": "0xc0000000"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00087000",
- "size_of_data": "0x00000200",
- "entropy": "0.21",
- "raw_address": "0x00082e00",
- "virtual_size": "0x00000018",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00088000",
- "size_of_data": "0x00009000",
- "entropy": "6.61",
- "raw_address": "0x00083000",
- "virtual_size": "0x00008e40",
- "characteristics_raw": "0x50000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00091000",
- "size_of_data": "0x00038e00",
- "entropy": "7.18",
- "raw_address": "0x0008c000",
- "virtual_size": "0x00038df4",
- "characteristics_raw": "0x50000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00083000",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00002174"
- },
- {
- "virtual_address": "0x00091000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00038df4"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00088000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00008e40"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00087000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "08d63d076187e00ae831c8357d868390",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 16,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement