Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: "Malicious"
- [*] MalScore: 10.0
- [*] File Name: "NanoCore_23bbbacf8c623db1b068e55993ae329f.exe"
- [*] File Size: 512512
- [*] File Type: "PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows"
- [*] SHA256: "3b6a0eaf0091139360a98bdc8c40753b4fd6d85fd28070918d2f01e34add1415"
- [*] MD5: "23bbbacf8c623db1b068e55993ae329f"
- [*] SHA1: "a3829070e7bf071da4f9df6cfffda3962923948f"
- [*] SHA512: "ccdd64277d0b230bb11974470af6ce93f7ee7371da2c148eccc30f1a77b946d738d171dee7619895fa675c18fc0e1c3009433e07938d2100728755ddae2d8f49"
- [*] CRC32: "FAD65474"
- [*] SSDEEP: "6144:DYr50WK823ewZWdEU0Fc9X/fPpCkD6wrHUKmCSPlBOzVaUITMsCCIduBFCM7:DO0WKTW0OX/pCkOwrH9cl8zV5rsXF9"
- [*] Process Execution: [
- "NanoCore_23bbbacf8c623db1b068e55993ae329f.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details": [
- {
- "section": "name: .rsrc, entropy: 7.43, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x0005be00, virtual_size: 0x0005bc58"
- }
- ]
- },
- {
- "Description": "Anomalous .NET characteristics",
- "Details": [
- {
- "anomalous_version": "Assembly version is set to 0"
- }
- ]
- },
- {
- "Description": "File has been identified by 39 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "MicroWorld-eScan": "Gen:Variant.Ursu.479545"
- },
- {
- "McAfee": "RDN/Generic BackDoor"
- },
- {
- "Cylance": "Unsafe"
- },
- {
- "BitDefender": "Gen:Variant.Ursu.479545"
- },
- {
- "Invincea": "heuristic"
- },
- {
- "Symantec": "ML.Attribute.HighConfidence"
- },
- {
- "APEX": "Malicious"
- },
- {
- "Paloalto": "generic.ml"
- },
- {
- "Kaspersky": "HEUR:Trojan.MSIL.Crypt.gen"
- },
- {
- "Alibaba": "Trojan:MSIL/GenKryptik.bfdae5a1"
- },
- {
- "Avast": "Win32:Malware-gen"
- },
- {
- "Ad-Aware": "Gen:Variant.Ursu.479545"
- },
- {
- "Emsisoft": "Gen:Variant.Ursu.479545 (B)"
- },
- {
- "Comodo": "Backdoor.MSIL.Bladabindi.ABC@6b1idd"
- },
- {
- "F-Secure": "Trojan.TR/AD.Nanocore.nbrdv"
- },
- {
- "DrWeb": "Trojan.KillProc.64796"
- },
- {
- "TrendMicro": "BKDR_HPXORSIL.SM"
- },
- {
- "McAfee-GW-Edition": "BehavesLike.Win32.Generic.hh"
- },
- {
- "FireEye": "Generic.mg.23bbbacf8c623db1"
- },
- {
- "Sophos": "Mal/Generic-S"
- },
- {
- "SentinelOne": "DFI - Malicious PE"
- },
- {
- "Cyren": "W32/Trojan.LXAO-5615"
- },
- {
- "Endgame": "malicious (high confidence)"
- },
- {
- "Avira": "TR/AD.Nanocore.nbrdv"
- },
- {
- "Fortinet": "MSIL/GenKryptik.DGKT!tr"
- },
- {
- "Arcabit": "Trojan.Ursu.D75139"
- },
- {
- "AegisLab": "Trojan.Multi.Generic.4!c"
- },
- {
- "ZoneAlarm": "HEUR:Trojan.MSIL.Crypt.gen"
- },
- {
- "ESET-NOD32": "a variant of MSIL/GenKryptik.DGKT"
- },
- {
- "Acronis": "suspicious"
- },
- {
- "VBA32": "TScope.Trojan.MSIL"
- },
- {
- "TrendMicro-HouseCall": "BKDR_HPXORSIL.SM"
- },
- {
- "Rising": "Trojan.GenKryptik!8.AA55 (CLOUD)"
- },
- {
- "Ikarus": "Trojan.Inject"
- },
- {
- "GData": "MSIL.Backdoor.Nancat.I55ETV"
- },
- {
- "AVG": "Win32:Malware-gen"
- },
- {
- "Cybereason": "malicious.0e7bf0"
- },
- {
- "CrowdStrike": "win/malicious_confidence_100% (W)"
- },
- {
- "Qihoo-360": "HEUR/QVM03.0.C789.Malware.Gen"
- }
- ]
- },
- {
- "Description": "Anomalous binary characteristics",
- "Details": [
- {
- "anomaly": "Actual checksum does not match that reported in PE header"
- }
- ]
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: []
- [*] Mutexes: []
- [*] Modified Files: []
- [*] Deleted Files: []
- [*] Modified Registry Keys: []
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "dotnet": {
- "customattrs": [],
- "assemblyinfo": {
- "version": "0.0.0.0",
- "name": "pqRZuKxmOlcSJLDyma"
- },
- "assemblyrefs": [
- {
- "version": "4.0.0.0",
- "name": "mscorlib"
- },
- {
- "version": "4.0.0.0",
- "name": "System"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Web"
- },
- {
- "version": "2.0.0.0",
- "name": "Serilog"
- }
- ],
- "typerefs": [
- {
- "typename": "Serilog.Core.ILogEventSink",
- "assembly": "Serilog"
- },
- {
- "typename": "Serilog.Debugging.SelfLog",
- "assembly": "Serilog"
- },
- {
- "typename": "Serilog.Events.LogEvent",
- "assembly": "Serilog"
- },
- {
- "typename": "System.Collections.Generic.Queue`1",
- "assembly": "System"
- },
- {
- "typename": "System.Net.Cookie",
- "assembly": "System"
- },
- {
- "typename": "System.Web.HttpServerUtility",
- "assembly": "System.Web"
- },
- {
- "typename": "System.ArgumentNullException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ArgumentOutOfRangeException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Concurrent.ConcurrentQueue`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.IEnumerable`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggableAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggableAttribute/DebuggingModes",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggerHiddenAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Exception",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IDisposable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Math",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Object",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ObjectDisposedException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.OperationCanceledException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Assembly",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MethodBase",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MethodInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.AsyncStateMachineAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.AsyncTaskMethodBuilder",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.AsyncVoidMethodBuilder",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilationRelaxationsAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilerGeneratedAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.IAsyncStateMachine",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.RuntimeCompatibilityAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.TaskAwaiter",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.CancellationToken",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.CancellationTokenSource",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Interlocked",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Monitor",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.SynchronizationContext",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Tasks.Task",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Timeout",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Timer",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.TimerCallback",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.TimeSpan",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Type",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ValueType",
- "assembly": "mscorlib"
- }
- ]
- },
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "_CorExeMain",
- "address": "0x402000"
- }
- ],
- "dll": "mscoree.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00082fb7",
- "overlay": {
- "size": "0x00019000",
- "offset": "0x00064200"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x0006d6ee",
- "icon_hash": null,
- "entrypoint": "0x00409e8e",
- "timestamp": "2019-05-04 16:27:36",
- "osversion": "4.0",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00002000",
- "size_of_data": "0x00008000",
- "entropy": "4.67",
- "raw_address": "0x00000200",
- "virtual_size": "0x00007e94",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0000a000",
- "size_of_data": "0x0005be00",
- "entropy": "7.43",
- "raw_address": "0x00008200",
- "virtual_size": "0x0005bc58",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00066000",
- "size_of_data": "0x00000200",
- "entropy": "0.08",
- "raw_address": "0x00064000",
- "virtual_size": "0x0000000c",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00009e3c",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000004f"
- },
- {
- "virtual_address": "0x0000a000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x0005bc58"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00066000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x0000000c"
- },
- {
- "virtual_address": "0x00009db8",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000008"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002008",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000048"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "f34d5f2d4577ed6d9ceec516c1f5a744",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "C:\\xampp\\htdocs\\Aspire\\files\\fantazyx_pqRZuKxmOlcSJLDy\\pqRZuKxmOlcSJLDyma.pdb",
- "imported_dll_count": 1,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegQueryInfoKeyW",
- "advapi32.dll.RegEnumKeyExW",
- "advapi32.dll.RegEnumValueW",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.RegQueryValueExW",
- "kernel32.dll.QueryActCtxW",
- "shlwapi.dll.UrlIsW"
- ]
- [*] Static Analysis: {
- "dotnet": {
- "customattrs": [],
- "assemblyinfo": {
- "version": "0.0.0.0",
- "name": "pqRZuKxmOlcSJLDyma"
- },
- "assemblyrefs": [
- {
- "version": "4.0.0.0",
- "name": "mscorlib"
- },
- {
- "version": "4.0.0.0",
- "name": "System"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Web"
- },
- {
- "version": "2.0.0.0",
- "name": "Serilog"
- }
- ],
- "typerefs": [
- {
- "typename": "Serilog.Core.ILogEventSink",
- "assembly": "Serilog"
- },
- {
- "typename": "Serilog.Debugging.SelfLog",
- "assembly": "Serilog"
- },
- {
- "typename": "Serilog.Events.LogEvent",
- "assembly": "Serilog"
- },
- {
- "typename": "System.Collections.Generic.Queue`1",
- "assembly": "System"
- },
- {
- "typename": "System.Net.Cookie",
- "assembly": "System"
- },
- {
- "typename": "System.Web.HttpServerUtility",
- "assembly": "System.Web"
- },
- {
- "typename": "System.ArgumentNullException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ArgumentOutOfRangeException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Concurrent.ConcurrentQueue`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.IEnumerable`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggableAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggableAttribute/DebuggingModes",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggerHiddenAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Exception",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IDisposable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Math",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Object",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ObjectDisposedException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.OperationCanceledException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Assembly",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MethodBase",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MethodInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.AsyncStateMachineAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.AsyncTaskMethodBuilder",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.AsyncVoidMethodBuilder",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilationRelaxationsAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilerGeneratedAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.IAsyncStateMachine",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.RuntimeCompatibilityAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.TaskAwaiter",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.CancellationToken",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.CancellationTokenSource",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Interlocked",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Monitor",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.SynchronizationContext",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Tasks.Task",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Timeout",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Timer",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.TimerCallback",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.TimeSpan",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Type",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ValueType",
- "assembly": "mscorlib"
- }
- ]
- },
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "_CorExeMain",
- "address": "0x402000"
- }
- ],
- "dll": "mscoree.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00082fb7",
- "overlay": {
- "size": "0x00019000",
- "offset": "0x00064200"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x0006d6ee",
- "icon_hash": null,
- "entrypoint": "0x00409e8e",
- "timestamp": "2019-05-04 16:27:36",
- "osversion": "4.0",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00002000",
- "size_of_data": "0x00008000",
- "entropy": "4.67",
- "raw_address": "0x00000200",
- "virtual_size": "0x00007e94",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0000a000",
- "size_of_data": "0x0005be00",
- "entropy": "7.43",
- "raw_address": "0x00008200",
- "virtual_size": "0x0005bc58",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00066000",
- "size_of_data": "0x00000200",
- "entropy": "0.08",
- "raw_address": "0x00064000",
- "virtual_size": "0x0000000c",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00009e3c",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000004f"
- },
- {
- "virtual_address": "0x0000a000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x0005bc58"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00066000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x0000000c"
- },
- {
- "virtual_address": "0x00009db8",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000008"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002008",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000048"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "f34d5f2d4577ed6d9ceec516c1f5a744",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "C:\\xampp\\htdocs\\Aspire\\files\\fantazyx_pqRZuKxmOlcSJLDy\\pqRZuKxmOlcSJLDyma.pdb",
- "imported_dll_count": 1,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement