[*] MalFamily: "Malicious" [*] MalScore: 10.0 [*] File Name: "Exes_cfe5a7469deb3aff3d6630614833afda.jpg" [*] File Size: 695808 [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows" [*] SHA256: "5230f18b804d1117f09f2ec7d7b45977c154bc80bfbfbb3c1f32997a28583087" [*] MD5: "cfe5a7469deb3aff3d6630614833afda" [*] SHA1: "8d99a9c94bfced8df8f50395e990465d0721e815" [*] SHA512: "89fa84f2f5395d5b5a6d263140c7a118d97c8e7d11283f41148dd786f6d16bc583292cec30dbd6e8d9ef3743633fb9adde63e3624a36c9ec89281dfb7603e8ff" [*] CRC32: "2A788C9E" [*] SSDEEP: "12288:ZHVfUkANPz6aWw+a1WpCYuA7OtqgiWRLjEeUpnFEkGmqDUezf7K76:ZmkANP3+a6ClAGwk6A54E7KO" [*] Process Execution: [ "Exes_cfe5a7469deb3aff3d6630614833afda.jpg", "Exes_cfe5a7469deb3aff3d6630614833afda.jpg" ] [*] Signatures Detected: [ { "Description": "Creates RWX memory", "Details": [] }, { "Description": "A process created a hidden window", "Details": [ { "Process": "Exes_cfe5a7469deb3aff3d6630614833afda.jpg -> C:\\Users\\user\\AppData\\Local\\Temp\\Exes_cfe5a7469deb3aff3d6630614833afda.jpg" } ] }, { "Description": "Executed a process and injected code into it, probably while unpacking", "Details": [ { "Injection": "Exes_cfe5a7469deb3aff3d6630614833afda.jpg(1204) -> Exes_cfe5a7469deb3aff3d6630614833afda.jpg(848)" } ] }, { "Description": "Installs itself for autorun at Windows startup", "Details": [ { "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\MSFEEditor" }, { "data": "\"C:\\Users\\user\\AppData\\Local\\Temp\\Exes_cfe5a7469deb3aff3d6630614833afda.jpg\" e" } ] }, { "Description": "Writes a potential ransom message to disk", "Details": [ { "ransom_file": "@@_TAKE_A_LOOK_@@.txt" } ] }, { "Description": "File has been identified by 28 Antiviruses on VirusTotal as malicious", "Details": [ { "FireEye": "Generic.mg.cfe5a7469deb3aff" }, { "McAfee": "Artemis!CFE5A7469DEB" }, { "AegisLab": "Trojan.Multi.Generic.4!c" }, { "Alibaba": "Trojan:Win32/GenKryptik.d9750615" }, { "Symantec": "ML.Attribute.HighConfidence" }, { "APEX": "Malicious" }, { "Paloalto": "generic.ml" }, { "Kaspersky": "Trojan-Ransom.Win32.Gen.rrx" }, { "Avast": "Win32:Malware-gen" }, { "Endgame": "malicious (high confidence)" }, { "Sophos": "Mal/Generic-S" }, { "Comodo": "TrojWare.Win32.Fakecsrss.AV@88nqyj" }, { "Invincea": "heuristic" }, { "McAfee-GW-Edition": "BehavesLike.Win32.MultiPlug.jh" }, { "Avira": "TR/AD.MalwareCrypter.jwj" }, { "Microsoft": "Ransom:Win32/Genasom" }, { "ZoneAlarm": "Trojan-Ransom.Win32.Gen.rrx" }, { "AhnLab-V3": "Win-Trojan/MalPe14.Suspicious" }, { "Acronis": "suspicious" }, { "VBA32": "BScope.Trojan.Chapak" }, { "MAX": "malware (ai score=99)" }, { "ESET-NOD32": "a variant of Win32/GenKryptik.DMFE" }, { "Rising": "Ransom.Gen!8.DE83 (CLOUD)" }, { "SentinelOne": "DFI - Suspicious PE" }, { "Fortinet": "W32/GenKryptik.DLJK!tr" }, { "AVG": "Win32:Malware-gen" }, { "CrowdStrike": "win/malicious_confidence_100% (W)" }, { "Qihoo-360": "Trojan.Generic" } ] } ] [*] Started Service: [] [*] Executed Commands: [ "\"C:\\Users\\user\\AppData\\Local\\Temp\\Exes_cfe5a7469deb3aff3d6630614833afda.jpg\"" ] [*] Mutexes: [] [*] Modified Files: [ "C:\\Users\\user\\AppData\\Roaming\\000000000.key", "C:\\@@_READ_ME_@@.txt", "C:\\@@_TAKE_A_LOOK_@@.txt", "C:\\@@_HELPER_@@.txt", "C:\\$Recycle.Bin\\@@_READ_ME_@@.txt", "C:\\$Recycle.Bin\\@@_TAKE_A_LOOK_@@.txt", "C:\\$Recycle.Bin\\@@_HELPER_@@.txt", "C:\\$Recycle.Bin\\S-1-5-21-0000000000-0000000000-0000000000-1000\\@@_READ_ME_@@.txt", "C:\\$Recycle.Bin\\S-1-5-21-0000000000-0000000000-0000000000-1000\\@@_TAKE_A_LOOK_@@.txt", "C:\\$Recycle.Bin\\S-1-5-21-0000000000-0000000000-0000000000-1000\\@@_HELPER_@@.txt", "C:\\$Recycle.Bin\\S-1-5-21-0000000000-0000000000-0000000000-1000\\$IFF23GH.xlsx", "C:\\$Recycle.Bin\\S-1-5-21-0000000000-0000000000-0000000000-1000\\$IFF23GH.xlsx.peekaboo", "C:\\$Recycle.Bin\\S-1-5-21-0000000000-0000000000-0000000000-1000\\$IRVJH6O.zip", "C:\\$Recycle.Bin\\S-1-5-21-0000000000-0000000000-0000000000-1000\\$IRVJH6O.zip.peekaboo", "C:\\.doc" ] [*] Deleted Files: [ "C:\\$Recycle.Bin\\S-1-5-21-0000000000-0000000000-0000000000-1000\\$IFF23GH.xlsx", "C:\\$Recycle.Bin\\S-1-5-21-0000000000-0000000000-0000000000-1000\\$IRVJH6O.zip" ] [*] Modified Registry Keys: [ "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\MSFEEditor" ] [*] Deleted Registry Keys: [] [*] DNS Communications: [] [*] Domains: [] [*] Network Communication - ICMP: [] [*] Network Communication - HTTP: [] [*] Network Communication - SMTP: [] [*] Network Communication - Hosts: [] [*] Network Communication - IRC: [] [*] Static Analysis: { "pe": { "peid_signatures": null, "imports": [ { "imports": [ { "name": "SetPriorityClass", "address": "0x49e000" }, { "name": "GetDriveTypeW", "address": "0x49e004" }, { "name": "WaitNamedPipeA", "address": "0x49e008" }, { "name": "ZombifyActCtx", "address": "0x49e00c" }, { "name": "SetEnvironmentVariableW", "address": "0x49e010" }, { "name": "WaitForSingleObject", "address": "0x49e014" }, { "name": "GetModuleHandleW", "address": "0x49e018" }, { "name": "ExpandEnvironmentStringsA", "address": "0x49e01c" }, { "name": "EnumTimeFormatsA", "address": "0x49e020" }, { "name": "EnumTimeFormatsW", "address": "0x49e024" }, { "name": "GetCommandLineA", "address": "0x49e028" }, { "name": "InitializeCriticalSection", "address": "0x49e02c" }, { "name": "GlobalAlloc", "address": "0x49e030" }, { "name": "Sleep", "address": "0x49e034" }, { "name": "FormatMessageW", "address": "0x49e038" }, { "name": "SetConsoleCP", "address": "0x49e03c" }, { "name": "IsProcessorFeaturePresent", "address": "0x49e040" }, { "name": "ReplaceFileW", "address": "0x49e044" }, { "name": "GetSystemDirectoryA", "address": "0x49e048" }, { "name": "GetStringTypeExA", "address": "0x49e04c" }, { "name": "GetLastError", "address": "0x49e050" }, { "name": "DefineDosDeviceW", "address": "0x49e054" }, { "name": "HeapUnlock", "address": "0x49e058" }, { "name": "GetFirmwareEnvironmentVariableW", "address": "0x49e05c" }, { "name": "CreateMemoryResourceNotification", "address": "0x49e060" }, { "name": "LoadLibraryA", "address": "0x49e064" }, { "name": "GetVolumePathNamesForVolumeNameA", "address": "0x49e068" }, { "name": "GetDefaultCommConfigA", "address": "0x49e06c" }, { "name": "FindFirstVolumeMountPointA", "address": "0x49e070" }, { "name": "_lread", "address": "0x49e074" }, { "name": "VirtualProtect", "address": "0x49e078" }, { "name": "DeleteCriticalSection", "address": "0x49e07c" }, { "name": "MoveFileWithProgressW", "address": "0x49e080" }, { "name": "EnumSystemLocalesA", "address": "0x49e084" }, { "name": "GetLocaleInfoA", "address": "0x49e088" }, { "name": "GetUserDefaultLCID", "address": "0x49e08c" }, { "name": "GetStringTypeW", "address": "0x49e090" }, { "name": "MultiByteToWideChar", "address": "0x49e094" }, { "name": "LCMapStringW", "address": "0x49e098" }, { "name": "HeapAlloc", "address": "0x49e09c" }, { "name": "GetProcAddress", "address": "0x49e0a0" }, { "name": "ExitProcess", "address": "0x49e0a4" }, { "name": "DecodePointer", "address": "0x49e0a8" }, { "name": "GetCommandLineW", "address": "0x49e0ac" }, { "name": "HeapSetInformation", "address": "0x49e0b0" }, { "name": "GetStartupInfoW", "address": "0x49e0b4" }, { "name": "WriteFile", "address": "0x49e0b8" }, { "name": "GetStdHandle", "address": "0x49e0bc" }, { "name": "GetModuleFileNameW", "address": "0x49e0c0" }, { "name": "HeapCreate", "address": "0x49e0c4" }, { "name": "HeapDestroy", "address": "0x49e0c8" }, { "name": "EncodePointer", "address": "0x49e0cc" }, { "name": "InitializeCriticalSectionAndSpinCount", "address": "0x49e0d0" }, { "name": "LeaveCriticalSection", "address": "0x49e0d4" }, { "name": "FatalAppExitA", "address": "0x49e0d8" }, { "name": "EnterCriticalSection", "address": "0x49e0dc" }, { "name": "SetConsoleCtrlHandler", "address": "0x49e0e0" }, { "name": "FreeLibrary", "address": "0x49e0e4" }, { "name": "InterlockedExchange", "address": "0x49e0e8" }, { "name": "LoadLibraryW", "address": "0x49e0ec" }, { "name": "GetLocaleInfoW", "address": "0x49e0f0" }, { "name": "UnhandledExceptionFilter", "address": "0x49e0f4" }, { "name": "SetUnhandledExceptionFilter", "address": "0x49e0f8" }, { "name": "IsDebuggerPresent", "address": "0x49e0fc" }, { "name": "TerminateProcess", "address": "0x49e100" }, { "name": "GetCurrentProcess", "address": "0x49e104" }, { "name": "TlsAlloc", "address": "0x49e108" }, { "name": "TlsGetValue", "address": "0x49e10c" }, { "name": "TlsSetValue", "address": "0x49e110" }, { "name": "TlsFree", "address": "0x49e114" }, { "name": "InterlockedIncrement", "address": "0x49e118" }, { "name": "SetLastError", "address": "0x49e11c" }, { "name": "GetCurrentThreadId", "address": "0x49e120" }, { "name": "InterlockedDecrement", "address": "0x49e124" }, { "name": "GetCurrentThread", "address": "0x49e128" }, { "name": "FreeEnvironmentStringsW", "address": "0x49e12c" }, { "name": "GetEnvironmentStringsW", "address": "0x49e130" }, { "name": "SetHandleCount", "address": "0x49e134" }, { "name": "GetFileType", "address": "0x49e138" }, { "name": "QueryPerformanceCounter", "address": "0x49e13c" }, { "name": "GetTickCount", "address": "0x49e140" }, { "name": "GetCurrentProcessId", "address": "0x49e144" }, { "name": "GetSystemTimeAsFileTime", "address": "0x49e148" }, { "name": "HeapFree", "address": "0x49e14c" }, { "name": "WideCharToMultiByte", "address": "0x49e150" }, { "name": "GetCPInfo", "address": "0x49e154" }, { "name": "GetACP", "address": "0x49e158" }, { "name": "GetOEMCP", "address": "0x49e15c" }, { "name": "IsValidCodePage", "address": "0x49e160" }, { "name": "HeapSize", "address": "0x49e164" }, { "name": "RtlUnwind", "address": "0x49e168" }, { "name": "RaiseException", "address": "0x49e16c" }, { "name": "HeapReAlloc", "address": "0x49e170" }, { "name": "IsValidLocale", "address": "0x49e174" } ], "dll": "KERNEL32.dll" }, { "imports": [ { "name": "GetMessageTime", "address": "0x49e184" }, { "name": "GetOpenClipboardWindow", "address": "0x49e188" }, { "name": "GetMenuBarInfo", "address": "0x49e18c" } ], "dll": "USER32.dll" }, { "imports": [ { "name": "AlphaBlend", "address": "0x49e17c" } ], "dll": "MSIMG32.dll" } ], "digital_signers": null, "exported_dll_name": null, "actual_checksum": "0x000b118e", "overlay": null, "imagebase": "0x00400000", "reported_checksum": "0x000b118e", "icon_hash": null, "entrypoint": "0x00403de3", "timestamp": "2018-08-05 15:09:05", "osversion": "5.1", "sections": [ { "name": ".text", "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ", "virtual_address": "0x00001000", "size_of_data": "0x0009ca00", "entropy": "6.48", "raw_address": "0x00000400", "virtual_size": "0x0009c9ac", "characteristics_raw": "0x60000020" }, { "name": ".rdata", "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ", "virtual_address": "0x0009e000", "size_of_data": "0x00004e00", "entropy": "6.15", "raw_address": "0x0009ce00", "virtual_size": "0x00004ce0", "characteristics_raw": "0x40000040" }, { "name": ".data", "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE", "virtual_address": "0x000a3000", "size_of_data": "0x00001e00", "entropy": "2.32", "raw_address": "0x000a1c00", "virtual_size": "0x000136e4", "characteristics_raw": "0xc0000040" }, { "name": ".rsrc", "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ", "virtual_address": "0x000b7000", "size_of_data": "0x00004e00", "entropy": "5.14", "raw_address": "0x000a3a00", "virtual_size": "0x00004c50", "characteristics_raw": "0x40000040" }, { "name": ".reloc", "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ", "virtual_address": "0x000bc000", "size_of_data": "0x00001600", "entropy": "4.98", "raw_address": "0x000a8800", "virtual_size": "0x00001466", "characteristics_raw": "0x42000040" } ], "resources": [], "dirents": [ { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_EXPORT", "size": "0x00000000" }, { "virtual_address": "0x000a2364", "name": "IMAGE_DIRECTORY_ENTRY_IMPORT", "size": "0x00000050" }, { "virtual_address": "0x000b7000", "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE", "size": "0x00004c50" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION", "size": "0x00000000" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_SECURITY", "size": "0x00000000" }, { "virtual_address": "0x000bc000", "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC", "size": "0x00000e08" }, { "virtual_address": "0x0009e1d0", "name": "IMAGE_DIRECTORY_ENTRY_DEBUG", "size": "0x0000001c" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT", "size": "0x00000000" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR", "size": "0x00000000" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_TLS", "size": "0x00000000" }, { "virtual_address": "0x000a1fe8", "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG", "size": "0x00000040" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT", "size": "0x00000000" }, { "virtual_address": "0x0009e000", "name": "IMAGE_DIRECTORY_ENTRY_IAT", "size": "0x00000194" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT", "size": "0x00000000" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR", "size": "0x00000000" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_RESERVED", "size": "0x00000000" } ], "exports": [], "guest_signers": {}, "imphash": "15fa16f95b1a04b163a5d62e7ef7d180", "icon_fuzzy": null, "icon": null, "pdbpath": "C:\\popic fupabenemutavepiv_bide80.pdb\\x00\\tmp_680866860\\bin\\kigoge.pdb\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x000\\x87\\x00\\x00\\x10\\xbc", "imported_dll_count": 3, "versioninfo": [] } } [*] Resolved APIs: [ "kernel32.dll.FlsAlloc", "kernel32.dll.FlsGetValue", "kernel32.dll.FlsSetValue", "kernel32.dll.FlsFree", "user32.dll.MessageBoxA", "user32.dll.GetMessageExtraInfo", "kernel32.dll.WinExec", "kernel32.dll.CreateFileA", "kernel32.dll.WriteFile", "kernel32.dll.CloseHandle", "kernel32.dll.CreateProcessA", "kernel32.dll.GetThreadContext", "kernel32.dll.VirtualAlloc", "kernel32.dll.VirtualAllocEx", "kernel32.dll.VirtualFree", "kernel32.dll.ReadProcessMemory", "kernel32.dll.WriteProcessMemory", "kernel32.dll.SetThreadContext", "kernel32.dll.ResumeThread", "kernel32.dll.WaitForSingleObject", "kernel32.dll.GetModuleFileNameA", "kernel32.dll.GetCommandLineA", "ntdll.dll.NtUnmapViewOfSection", "ntdll.dll.NtWriteVirtualMemory", "user32.dll.RegisterClassExA", "user32.dll.CreateWindowExA", "user32.dll.PostMessageA", "user32.dll.GetMessageA", "user32.dll.DefWindowProcA", "kernel32.dll.GetFileAttributesA", "kernel32.dll.GetStartupInfoA", "kernel32.dll.VirtualProtectEx", "kernel32.dll.ExitProcess", "uxtheme.dll.ThemeInitApiHook", "user32.dll.IsProcessDPIAware", "dwmapi.dll.DwmIsCompositionEnabled", "kernel32.dll.InitializeCriticalSectionEx", "kernel32.dll.LCMapStringEx", "kernel32.dll.InitOnceExecuteOnce", "kernel32.dll.CreateEventExW", "kernel32.dll.CreateSemaphoreW", "kernel32.dll.CreateSemaphoreExW", "kernel32.dll.CreateThreadpoolTimer", "kernel32.dll.SetThreadpoolTimer", "kernel32.dll.WaitForThreadpoolTimerCallbacks", "kernel32.dll.CloseThreadpoolTimer", "kernel32.dll.CreateThreadpoolWait", "kernel32.dll.SetThreadpoolWait", "kernel32.dll.CloseThreadpoolWait", "kernel32.dll.FlushProcessWriteBuffers", "kernel32.dll.FreeLibraryWhenCallbackReturns", "kernel32.dll.GetCurrentProcessorNumber", "kernel32.dll.CreateSymbolicLinkW", "kernel32.dll.GetTickCount64", "kernel32.dll.GetFileInformationByHandleEx", "kernel32.dll.SetFileInformationByHandle", "kernel32.dll.InitializeConditionVariable", "kernel32.dll.WakeConditionVariable", "kernel32.dll.WakeAllConditionVariable", "kernel32.dll.SleepConditionVariableCS", "kernel32.dll.InitializeSRWLock", "kernel32.dll.AcquireSRWLockExclusive", "kernel32.dll.TryAcquireSRWLockExclusive", "kernel32.dll.ReleaseSRWLockExclusive", "kernel32.dll.SleepConditionVariableSRW", "kernel32.dll.CreateThreadpoolWork", "kernel32.dll.SubmitThreadpoolWork", "kernel32.dll.CloseThreadpoolWork", "kernel32.dll.CompareStringEx", "kernel32.dll.GetLocaleInfoEx", "kernel32.dll.AreFileApisANSI", "kernel32.dll.EnumSystemLocalesEx", "kernel32.dll.GetDateFormatEx", "kernel32.dll.GetTimeFormatEx", "kernel32.dll.GetUserDefaultLocaleName", "kernel32.dll.IsValidLocaleName", "kernel32.dll.LCIDToLocaleName", "kernel32.dll.LocaleNameToLCID", "advapi32.dll.SystemFunction036", "cryptbase.dll.SystemFunction001", "cryptbase.dll.SystemFunction002", "cryptbase.dll.SystemFunction003", "cryptbase.dll.SystemFunction004", "cryptbase.dll.SystemFunction005", "cryptbase.dll.SystemFunction028", "cryptbase.dll.SystemFunction029", "cryptbase.dll.SystemFunction034", "cryptbase.dll.SystemFunction036", "cryptbase.dll.SystemFunction040", "cryptbase.dll.SystemFunction041" ] [*] Static Analysis: { "pe": { "peid_signatures": null, "imports": [ { "imports": [ { "name": "SetPriorityClass", "address": "0x49e000" }, { "name": "GetDriveTypeW", "address": "0x49e004" }, { "name": "WaitNamedPipeA", "address": "0x49e008" }, { "name": "ZombifyActCtx", "address": "0x49e00c" }, { "name": "SetEnvironmentVariableW", "address": "0x49e010" }, { "name": "WaitForSingleObject", "address": "0x49e014" }, { "name": "GetModuleHandleW", "address": "0x49e018" }, { "name": "ExpandEnvironmentStringsA", "address": "0x49e01c" }, { "name": "EnumTimeFormatsA", "address": "0x49e020" }, { "name": "EnumTimeFormatsW", "address": "0x49e024" }, { "name": "GetCommandLineA", "address": "0x49e028" }, { "name": "InitializeCriticalSection", "address": "0x49e02c" }, { "name": "GlobalAlloc", "address": "0x49e030" }, { "name": "Sleep", "address": "0x49e034" }, { "name": "FormatMessageW", "address": "0x49e038" }, { "name": "SetConsoleCP", "address": "0x49e03c" }, { "name": "IsProcessorFeaturePresent", "address": "0x49e040" }, { "name": "ReplaceFileW", "address": "0x49e044" }, { "name": "GetSystemDirectoryA", "address": "0x49e048" }, { "name": "GetStringTypeExA", "address": "0x49e04c" }, { "name": "GetLastError", "address": "0x49e050" }, { "name": "DefineDosDeviceW", "address": "0x49e054" }, { "name": "HeapUnlock", "address": "0x49e058" }, { "name": "GetFirmwareEnvironmentVariableW", "address": "0x49e05c" }, { "name": "CreateMemoryResourceNotification", "address": "0x49e060" }, { "name": "LoadLibraryA", "address": "0x49e064" }, { "name": "GetVolumePathNamesForVolumeNameA", "address": "0x49e068" }, { "name": "GetDefaultCommConfigA", "address": "0x49e06c" }, { "name": "FindFirstVolumeMountPointA", "address": "0x49e070" }, { "name": "_lread", "address": "0x49e074" }, { "name": "VirtualProtect", "address": "0x49e078" }, { "name": "DeleteCriticalSection", "address": "0x49e07c" }, { "name": "MoveFileWithProgressW", "address": "0x49e080" }, { "name": "EnumSystemLocalesA", "address": "0x49e084" }, { "name": "GetLocaleInfoA", "address": "0x49e088" }, { "name": "GetUserDefaultLCID", "address": "0x49e08c" }, { "name": "GetStringTypeW", "address": "0x49e090" }, { "name": "MultiByteToWideChar", "address": "0x49e094" }, { "name": "LCMapStringW", "address": "0x49e098" }, { "name": "HeapAlloc", "address": "0x49e09c" }, { "name": "GetProcAddress", "address": "0x49e0a0" }, { "name": "ExitProcess", "address": "0x49e0a4" }, { "name": "DecodePointer", "address": "0x49e0a8" }, { "name": "GetCommandLineW", "address": "0x49e0ac" }, { "name": "HeapSetInformation", "address": "0x49e0b0" }, { "name": "GetStartupInfoW", "address": "0x49e0b4" }, { "name": "WriteFile", "address": "0x49e0b8" }, { "name": "GetStdHandle", "address": "0x49e0bc" }, { "name": "GetModuleFileNameW", "address": "0x49e0c0" }, { "name": "HeapCreate", "address": "0x49e0c4" }, { "name": "HeapDestroy", "address": "0x49e0c8" }, { "name": "EncodePointer", "address": "0x49e0cc" }, { "name": "InitializeCriticalSectionAndSpinCount", "address": "0x49e0d0" }, { "name": "LeaveCriticalSection", "address": "0x49e0d4" }, { "name": "FatalAppExitA", "address": "0x49e0d8" }, { "name": "EnterCriticalSection", "address": "0x49e0dc" }, { "name": "SetConsoleCtrlHandler", "address": "0x49e0e0" }, { "name": "FreeLibrary", "address": "0x49e0e4" }, { "name": "InterlockedExchange", "address": "0x49e0e8" }, { "name": "LoadLibraryW", "address": "0x49e0ec" }, { "name": "GetLocaleInfoW", "address": "0x49e0f0" }, { "name": "UnhandledExceptionFilter", "address": "0x49e0f4" }, { "name": "SetUnhandledExceptionFilter", "address": "0x49e0f8" }, { "name": "IsDebuggerPresent", "address": "0x49e0fc" }, { "name": "TerminateProcess", "address": "0x49e100" }, { "name": "GetCurrentProcess", "address": "0x49e104" }, { "name": "TlsAlloc", "address": "0x49e108" }, { "name": "TlsGetValue", "address": "0x49e10c" }, { "name": "TlsSetValue", "address": "0x49e110" }, { "name": "TlsFree", "address": "0x49e114" }, { "name": "InterlockedIncrement", "address": "0x49e118" }, { "name": "SetLastError", "address": "0x49e11c" }, { "name": "GetCurrentThreadId", "address": "0x49e120" }, { "name": "InterlockedDecrement", "address": "0x49e124" }, { "name": "GetCurrentThread", "address": "0x49e128" }, { "name": "FreeEnvironmentStringsW", "address": "0x49e12c" }, { "name": "GetEnvironmentStringsW", "address": "0x49e130" }, { "name": "SetHandleCount", "address": "0x49e134" }, { "name": "GetFileType", "address": "0x49e138" }, { "name": "QueryPerformanceCounter", "address": "0x49e13c" }, { "name": "GetTickCount", "address": "0x49e140" }, { "name": "GetCurrentProcessId", "address": "0x49e144" }, { "name": "GetSystemTimeAsFileTime", "address": "0x49e148" }, { "name": "HeapFree", "address": "0x49e14c" }, { "name": "WideCharToMultiByte", "address": "0x49e150" }, { "name": "GetCPInfo", "address": "0x49e154" }, { "name": "GetACP", "address": "0x49e158" }, { "name": "GetOEMCP", "address": "0x49e15c" }, { "name": "IsValidCodePage", "address": "0x49e160" }, { "name": "HeapSize", "address": "0x49e164" }, { "name": "RtlUnwind", "address": "0x49e168" }, { "name": "RaiseException", "address": "0x49e16c" }, { "name": "HeapReAlloc", "address": "0x49e170" }, { "name": "IsValidLocale", "address": "0x49e174" } ], "dll": "KERNEL32.dll" }, { "imports": [ { "name": "GetMessageTime", "address": "0x49e184" }, { "name": "GetOpenClipboardWindow", "address": "0x49e188" }, { "name": "GetMenuBarInfo", "address": "0x49e18c" } ], "dll": "USER32.dll" }, { "imports": [ { "name": "AlphaBlend", "address": "0x49e17c" } ], "dll": "MSIMG32.dll" } ], "digital_signers": null, "exported_dll_name": null, "actual_checksum": "0x000b118e", "overlay": null, "imagebase": "0x00400000", "reported_checksum": "0x000b118e", "icon_hash": null, "entrypoint": "0x00403de3", "timestamp": "2018-08-05 15:09:05", "osversion": "5.1", "sections": [ { "name": ".text", "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ", "virtual_address": "0x00001000", "size_of_data": "0x0009ca00", "entropy": "6.48", "raw_address": "0x00000400", "virtual_size": "0x0009c9ac", "characteristics_raw": "0x60000020" }, { "name": ".rdata", "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ", "virtual_address": "0x0009e000", "size_of_data": "0x00004e00", "entropy": "6.15", "raw_address": "0x0009ce00", "virtual_size": "0x00004ce0", "characteristics_raw": "0x40000040" }, { "name": ".data", "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE", "virtual_address": "0x000a3000", "size_of_data": "0x00001e00", "entropy": "2.32", "raw_address": "0x000a1c00", "virtual_size": "0x000136e4", "characteristics_raw": "0xc0000040" }, { "name": ".rsrc", "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ", "virtual_address": "0x000b7000", "size_of_data": "0x00004e00", "entropy": "5.14", "raw_address": "0x000a3a00", "virtual_size": "0x00004c50", "characteristics_raw": "0x40000040" }, { "name": ".reloc", "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ", "virtual_address": "0x000bc000", "size_of_data": "0x00001600", "entropy": "4.98", "raw_address": "0x000a8800", "virtual_size": "0x00001466", "characteristics_raw": "0x42000040" } ], "resources": [], "dirents": [ { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_EXPORT", "size": "0x00000000" }, { "virtual_address": "0x000a2364", "name": "IMAGE_DIRECTORY_ENTRY_IMPORT", "size": "0x00000050" }, { "virtual_address": "0x000b7000", "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE", "size": "0x00004c50" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION", "size": "0x00000000" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_SECURITY", "size": "0x00000000" }, { "virtual_address": "0x000bc000", "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC", "size": "0x00000e08" }, { "virtual_address": "0x0009e1d0", "name": "IMAGE_DIRECTORY_ENTRY_DEBUG", "size": "0x0000001c" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT", "size": "0x00000000" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR", "size": "0x00000000" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_TLS", "size": "0x00000000" }, { "virtual_address": "0x000a1fe8", "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG", "size": "0x00000040" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT", "size": "0x00000000" }, { "virtual_address": "0x0009e000", "name": "IMAGE_DIRECTORY_ENTRY_IAT", "size": "0x00000194" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT", "size": "0x00000000" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR", "size": "0x00000000" }, { "virtual_address": "0x00000000", "name": "IMAGE_DIRECTORY_ENTRY_RESERVED", "size": "0x00000000" } ], "exports": [], "guest_signers": {}, "imphash": "15fa16f95b1a04b163a5d62e7ef7d180", "icon_fuzzy": null, "icon": null, "pdbpath": "C:\\popic fupabenemutavepiv_bide80.pdb\\x00\\tmp_680866860\\bin\\kigoge.pdb\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00Z\\x00\\x000\\x87\\x00\\x00\\x10\\xbc", "imported_dll_count": 3, "versioninfo": [] } }