Advertisement
paladin316

986107_2019-06-25_06_30.json

Jun 25th, 2019
1,356
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 136.76 KB | None | 0 0
  1.  
  2. [*] MalFamily: ""
  3.  
  4. [*] MalScore: 10.0
  5.  
  6. [*] File Name: "986107"
  7. [*] File Size: 1426376
  8. [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. [*] SHA256: "d14b33b60ae3037c3059fbe807e0bf7b50927f90ad1aaf59646139ef8dd95ab2"
  10. [*] MD5: "72356d0f96620067d52f5ae8bfb75288"
  11. [*] SHA1: "398d28f2132543f29cfbb61981f313cf62abc00a"
  12. [*] SHA512: "2928b2d5ff4ee78cb4fd17a458579ea126c876a1b382180e4e1b015ab70867eb7e6ce0acf01881f399de76095d2f15b15913d8ee4a24fb19d808ccebd11571d3"
  13. [*] CRC32: "339596BE"
  14. [*] SSDEEP: "24576:Rw6Basswrd5/BCQ8GZIFqkmf6eeeZMI/8E18iHWYBRV17ADa:RwOa0rP8GZHky6LMz/8K8iHPBfB"
  15.  
  16. [*] Process Execution: []
  17.  
  18. [*] Signatures Detected: [
  19. {
  20. "Description": "File has been identified by 35 Antiviruses on VirusTotal as malicious",
  21. "Details": [
  22. {
  23. "MicroWorld-eScan": "Trojan.Agent.DZAA"
  24. },
  25. {
  26. "FireEye": "Generic.mg.72356d0f96620067"
  27. },
  28. {
  29. "Qihoo-360": "Win32/Virus.Adware.b51"
  30. },
  31. {
  32. "McAfee": "Artemis!72356D0F9662"
  33. },
  34. {
  35. "Cylance": "Unsafe"
  36. },
  37. {
  38. "Alibaba": "AdWare:Win32/Generic.ae6d06b3"
  39. },
  40. {
  41. "Symantec": "ML.Attribute.HighConfidence"
  42. },
  43. {
  44. "ESET-NOD32": "a variant of Win32/Injector.EGEZ"
  45. },
  46. {
  47. "APEX": "Malicious"
  48. },
  49. {
  50. "Paloalto": "generic.ml"
  51. },
  52. {
  53. "GData": "Trojan.Agent.DZAA"
  54. },
  55. {
  56. "Kaspersky": "HEUR:Trojan-PSW.Win32.Agent.gen"
  57. },
  58. {
  59. "BitDefender": "Trojan.Agent.DZAA"
  60. },
  61. {
  62. "Endgame": "malicious (high confidence)"
  63. },
  64. {
  65. "Sophos": "Mal/Generic-S"
  66. },
  67. {
  68. "F-Secure": "Trojan.TR/AD.LokiBot.yecpp"
  69. },
  70. {
  71. "DrWeb": "Trojan.Inject3.17998"
  72. },
  73. {
  74. "Invincea": "heuristic"
  75. },
  76. {
  77. "McAfee-GW-Edition": "BehavesLike.Win32.Generic.th"
  78. },
  79. {
  80. "Emsisoft": "Trojan.Agent.DZAA (B)"
  81. },
  82. {
  83. "Ikarus": "Win32.Outbreak"
  84. },
  85. {
  86. "Jiangmin": "Trojan.BypassUAC.o"
  87. },
  88. {
  89. "Avira": "TR/AD.LokiBot.yecpp"
  90. },
  91. {
  92. "Microsoft": "Trojan:Win32/Conteban.B!ml"
  93. },
  94. {
  95. "Arcabit": "Trojan.Agent.DZAA"
  96. },
  97. {
  98. "ZoneAlarm": "HEUR:Trojan-PSW.Win32.Agent.gen"
  99. },
  100. {
  101. "VBA32": "BScope.Trojan.Inject"
  102. },
  103. {
  104. "Ad-Aware": "Trojan.Agent.DZAA"
  105. },
  106. {
  107. "Panda": "Trj/GdSda.A"
  108. },
  109. {
  110. "SentinelOne": "DFI - Malicious PE"
  111. },
  112. {
  113. "Fortinet": "Adware/Generic"
  114. },
  115. {
  116. "AVG": "Win32:PWSX-gen [Trj]"
  117. },
  118. {
  119. "Cybereason": "malicious.213254"
  120. },
  121. {
  122. "Avast": "Win32:PWSX-gen [Trj]"
  123. },
  124. {
  125. "CrowdStrike": "win/malicious_confidence_90% (W)"
  126. }
  127. ]
  128. },
  129. {
  130. "Description": "Anomalous binary characteristics",
  131. "Details": [
  132. {
  133. "anomaly": "Timestamp on binary predates the release date of the OS version it requires by at least a year"
  134. },
  135. {
  136. "anomaly": "Actual checksum does not match that reported in PE header"
  137. }
  138. ]
  139. }
  140. ]
  141.  
  142. [*] Started Service: []
  143.  
  144. [*] Executed Commands: []
  145.  
  146. [*] Mutexes: []
  147.  
  148. [*] Modified Files: []
  149.  
  150. [*] Deleted Files: []
  151.  
  152. [*] Modified Registry Keys: []
  153.  
  154. [*] Deleted Registry Keys: []
  155.  
  156. [*] DNS Communications: []
  157.  
  158. [*] Domains: []
  159.  
  160. [*] Network Communication - ICMP: []
  161.  
  162. [*] Network Communication - HTTP: []
  163.  
  164. [*] Network Communication - SMTP: []
  165.  
  166. [*] Network Communication - Hosts: []
  167.  
  168. [*] Network Communication - IRC: []
  169.  
  170. [*] Static Analysis: {
  171. "pe": {
  172. "peid_signatures": null,
  173. "imports": [
  174. {
  175. "imports": [
  176. {
  177. "name": "DeleteCriticalSection",
  178. "address": "0x46e140"
  179. },
  180. {
  181. "name": "LeaveCriticalSection",
  182. "address": "0x46e144"
  183. },
  184. {
  185. "name": "EnterCriticalSection",
  186. "address": "0x46e148"
  187. },
  188. {
  189. "name": "InitializeCriticalSection",
  190. "address": "0x46e14c"
  191. },
  192. {
  193. "name": "VirtualFree",
  194. "address": "0x46e150"
  195. },
  196. {
  197. "name": "VirtualAlloc",
  198. "address": "0x46e154"
  199. },
  200. {
  201. "name": "LocalFree",
  202. "address": "0x46e158"
  203. },
  204. {
  205. "name": "LocalAlloc",
  206. "address": "0x46e15c"
  207. },
  208. {
  209. "name": "GetVersion",
  210. "address": "0x46e160"
  211. },
  212. {
  213. "name": "GetCurrentThreadId",
  214. "address": "0x46e164"
  215. },
  216. {
  217. "name": "InterlockedDecrement",
  218. "address": "0x46e168"
  219. },
  220. {
  221. "name": "InterlockedIncrement",
  222. "address": "0x46e16c"
  223. },
  224. {
  225. "name": "VirtualQuery",
  226. "address": "0x46e170"
  227. },
  228. {
  229. "name": "WideCharToMultiByte",
  230. "address": "0x46e174"
  231. },
  232. {
  233. "name": "MultiByteToWideChar",
  234. "address": "0x46e178"
  235. },
  236. {
  237. "name": "lstrlenA",
  238. "address": "0x46e17c"
  239. },
  240. {
  241. "name": "lstrcpynA",
  242. "address": "0x46e180"
  243. },
  244. {
  245. "name": "LoadLibraryExA",
  246. "address": "0x46e184"
  247. },
  248. {
  249. "name": "GetThreadLocale",
  250. "address": "0x46e188"
  251. },
  252. {
  253. "name": "GetStartupInfoA",
  254. "address": "0x46e18c"
  255. },
  256. {
  257. "name": "GetProcAddress",
  258. "address": "0x46e190"
  259. },
  260. {
  261. "name": "GetModuleHandleA",
  262. "address": "0x46e194"
  263. },
  264. {
  265. "name": "GetModuleFileNameA",
  266. "address": "0x46e198"
  267. },
  268. {
  269. "name": "GetLocaleInfoA",
  270. "address": "0x46e19c"
  271. },
  272. {
  273. "name": "GetLastError",
  274. "address": "0x46e1a0"
  275. },
  276. {
  277. "name": "GetCommandLineA",
  278. "address": "0x46e1a4"
  279. },
  280. {
  281. "name": "FreeLibrary",
  282. "address": "0x46e1a8"
  283. },
  284. {
  285. "name": "FindFirstFileA",
  286. "address": "0x46e1ac"
  287. },
  288. {
  289. "name": "FindClose",
  290. "address": "0x46e1b0"
  291. },
  292. {
  293. "name": "ExitProcess",
  294. "address": "0x46e1b4"
  295. },
  296. {
  297. "name": "ExitThread",
  298. "address": "0x46e1b8"
  299. },
  300. {
  301. "name": "CreateThread",
  302. "address": "0x46e1bc"
  303. },
  304. {
  305. "name": "WriteFile",
  306. "address": "0x46e1c0"
  307. },
  308. {
  309. "name": "UnhandledExceptionFilter",
  310. "address": "0x46e1c4"
  311. },
  312. {
  313. "name": "SetFilePointer",
  314. "address": "0x46e1c8"
  315. },
  316. {
  317. "name": "SetEndOfFile",
  318. "address": "0x46e1cc"
  319. },
  320. {
  321. "name": "RtlUnwind",
  322. "address": "0x46e1d0"
  323. },
  324. {
  325. "name": "ReadFile",
  326. "address": "0x46e1d4"
  327. },
  328. {
  329. "name": "RaiseException",
  330. "address": "0x46e1d8"
  331. },
  332. {
  333. "name": "GetStdHandle",
  334. "address": "0x46e1dc"
  335. },
  336. {
  337. "name": "GetFileSize",
  338. "address": "0x46e1e0"
  339. },
  340. {
  341. "name": "GetFileType",
  342. "address": "0x46e1e4"
  343. },
  344. {
  345. "name": "CreateFileA",
  346. "address": "0x46e1e8"
  347. },
  348. {
  349. "name": "CloseHandle",
  350. "address": "0x46e1ec"
  351. }
  352. ],
  353. "dll": "kernel32.dll"
  354. },
  355. {
  356. "imports": [
  357. {
  358. "name": "GetKeyboardType",
  359. "address": "0x46e1f4"
  360. },
  361. {
  362. "name": "LoadStringA",
  363. "address": "0x46e1f8"
  364. },
  365. {
  366. "name": "MessageBoxA",
  367. "address": "0x46e1fc"
  368. },
  369. {
  370. "name": "CharNextA",
  371. "address": "0x46e200"
  372. }
  373. ],
  374. "dll": "user32.dll"
  375. },
  376. {
  377. "imports": [
  378. {
  379. "name": "RegQueryValueExA",
  380. "address": "0x46e208"
  381. },
  382. {
  383. "name": "RegOpenKeyExA",
  384. "address": "0x46e20c"
  385. },
  386. {
  387. "name": "RegCloseKey",
  388. "address": "0x46e210"
  389. }
  390. ],
  391. "dll": "advapi32.dll"
  392. },
  393. {
  394. "imports": [
  395. {
  396. "name": "SysFreeString",
  397. "address": "0x46e218"
  398. },
  399. {
  400. "name": "SysReAllocStringLen",
  401. "address": "0x46e21c"
  402. },
  403. {
  404. "name": "SysAllocStringLen",
  405. "address": "0x46e220"
  406. }
  407. ],
  408. "dll": "oleaut32.dll"
  409. },
  410. {
  411. "imports": [
  412. {
  413. "name": "TlsSetValue",
  414. "address": "0x46e228"
  415. },
  416. {
  417. "name": "TlsGetValue",
  418. "address": "0x46e22c"
  419. },
  420. {
  421. "name": "LocalAlloc",
  422. "address": "0x46e230"
  423. },
  424. {
  425. "name": "GetModuleHandleA",
  426. "address": "0x46e234"
  427. }
  428. ],
  429. "dll": "kernel32.dll"
  430. },
  431. {
  432. "imports": [
  433. {
  434. "name": "RegQueryValueExA",
  435. "address": "0x46e23c"
  436. },
  437. {
  438. "name": "RegOpenKeyExA",
  439. "address": "0x46e240"
  440. },
  441. {
  442. "name": "RegCloseKey",
  443. "address": "0x46e244"
  444. }
  445. ],
  446. "dll": "advapi32.dll"
  447. },
  448. {
  449. "imports": [
  450. {
  451. "name": "lstrcpyA",
  452. "address": "0x46e24c"
  453. },
  454. {
  455. "name": "WriteFile",
  456. "address": "0x46e250"
  457. },
  458. {
  459. "name": "WaitForSingleObject",
  460. "address": "0x46e254"
  461. },
  462. {
  463. "name": "VirtualQuery",
  464. "address": "0x46e258"
  465. },
  466. {
  467. "name": "VirtualAlloc",
  468. "address": "0x46e25c"
  469. },
  470. {
  471. "name": "Sleep",
  472. "address": "0x46e260"
  473. },
  474. {
  475. "name": "SizeofResource",
  476. "address": "0x46e264"
  477. },
  478. {
  479. "name": "SetThreadLocale",
  480. "address": "0x46e268"
  481. },
  482. {
  483. "name": "SetFilePointer",
  484. "address": "0x46e26c"
  485. },
  486. {
  487. "name": "SetEvent",
  488. "address": "0x46e270"
  489. },
  490. {
  491. "name": "SetErrorMode",
  492. "address": "0x46e274"
  493. },
  494. {
  495. "name": "SetEndOfFile",
  496. "address": "0x46e278"
  497. },
  498. {
  499. "name": "ResumeThread",
  500. "address": "0x46e27c"
  501. },
  502. {
  503. "name": "ResetEvent",
  504. "address": "0x46e280"
  505. },
  506. {
  507. "name": "ReadFile",
  508. "address": "0x46e284"
  509. },
  510. {
  511. "name": "MulDiv",
  512. "address": "0x46e288"
  513. },
  514. {
  515. "name": "LockResource",
  516. "address": "0x46e28c"
  517. },
  518. {
  519. "name": "LoadResource",
  520. "address": "0x46e290"
  521. },
  522. {
  523. "name": "LoadLibraryA",
  524. "address": "0x46e294"
  525. },
  526. {
  527. "name": "LeaveCriticalSection",
  528. "address": "0x46e298"
  529. },
  530. {
  531. "name": "IsBadWritePtr",
  532. "address": "0x46e29c"
  533. },
  534. {
  535. "name": "IsBadReadPtr",
  536. "address": "0x46e2a0"
  537. },
  538. {
  539. "name": "InitializeCriticalSection",
  540. "address": "0x46e2a4"
  541. },
  542. {
  543. "name": "GlobalUnlock",
  544. "address": "0x46e2a8"
  545. },
  546. {
  547. "name": "GlobalReAlloc",
  548. "address": "0x46e2ac"
  549. },
  550. {
  551. "name": "GlobalMemoryStatus",
  552. "address": "0x46e2b0"
  553. },
  554. {
  555. "name": "GlobalHandle",
  556. "address": "0x46e2b4"
  557. },
  558. {
  559. "name": "GlobalLock",
  560. "address": "0x46e2b8"
  561. },
  562. {
  563. "name": "GlobalFree",
  564. "address": "0x46e2bc"
  565. },
  566. {
  567. "name": "GlobalFindAtomA",
  568. "address": "0x46e2c0"
  569. },
  570. {
  571. "name": "GlobalDeleteAtom",
  572. "address": "0x46e2c4"
  573. },
  574. {
  575. "name": "GlobalAlloc",
  576. "address": "0x46e2c8"
  577. },
  578. {
  579. "name": "GlobalAddAtomA",
  580. "address": "0x46e2cc"
  581. },
  582. {
  583. "name": "GetVersionExA",
  584. "address": "0x46e2d0"
  585. },
  586. {
  587. "name": "GetVersion",
  588. "address": "0x46e2d4"
  589. },
  590. {
  591. "name": "GetTickCount",
  592. "address": "0x46e2d8"
  593. },
  594. {
  595. "name": "GetThreadLocale",
  596. "address": "0x46e2dc"
  597. },
  598. {
  599. "name": "GetTempPathA",
  600. "address": "0x46e2e0"
  601. },
  602. {
  603. "name": "GetTempFileNameA",
  604. "address": "0x46e2e4"
  605. },
  606. {
  607. "name": "GetSystemInfo",
  608. "address": "0x46e2e8"
  609. },
  610. {
  611. "name": "GetStringTypeExA",
  612. "address": "0x46e2ec"
  613. },
  614. {
  615. "name": "GetStdHandle",
  616. "address": "0x46e2f0"
  617. },
  618. {
  619. "name": "GetProcAddress",
  620. "address": "0x46e2f4"
  621. },
  622. {
  623. "name": "GetModuleHandleA",
  624. "address": "0x46e2f8"
  625. },
  626. {
  627. "name": "GetModuleFileNameA",
  628. "address": "0x46e2fc"
  629. },
  630. {
  631. "name": "GetLocaleInfoA",
  632. "address": "0x46e300"
  633. },
  634. {
  635. "name": "GetLocalTime",
  636. "address": "0x46e304"
  637. },
  638. {
  639. "name": "GetLastError",
  640. "address": "0x46e308"
  641. },
  642. {
  643. "name": "GetFullPathNameA",
  644. "address": "0x46e30c"
  645. },
  646. {
  647. "name": "GetExitCodeThread",
  648. "address": "0x46e310"
  649. },
  650. {
  651. "name": "GetDiskFreeSpaceA",
  652. "address": "0x46e314"
  653. },
  654. {
  655. "name": "GetDateFormatA",
  656. "address": "0x46e318"
  657. },
  658. {
  659. "name": "GetCurrentThreadId",
  660. "address": "0x46e31c"
  661. },
  662. {
  663. "name": "GetCurrentProcessId",
  664. "address": "0x46e320"
  665. },
  666. {
  667. "name": "GetCPInfo",
  668. "address": "0x46e324"
  669. },
  670. {
  671. "name": "GetACP",
  672. "address": "0x46e328"
  673. },
  674. {
  675. "name": "FreeResource",
  676. "address": "0x46e32c"
  677. },
  678. {
  679. "name": "InterlockedIncrement",
  680. "address": "0x46e330"
  681. },
  682. {
  683. "name": "InterlockedExchange",
  684. "address": "0x46e334"
  685. },
  686. {
  687. "name": "InterlockedDecrement",
  688. "address": "0x46e338"
  689. },
  690. {
  691. "name": "FreeLibrary",
  692. "address": "0x46e33c"
  693. },
  694. {
  695. "name": "FormatMessageA",
  696. "address": "0x46e340"
  697. },
  698. {
  699. "name": "FindResourceA",
  700. "address": "0x46e344"
  701. },
  702. {
  703. "name": "ExitProcess",
  704. "address": "0x46e348"
  705. },
  706. {
  707. "name": "EnumCalendarInfoA",
  708. "address": "0x46e34c"
  709. },
  710. {
  711. "name": "EnterCriticalSection",
  712. "address": "0x46e350"
  713. },
  714. {
  715. "name": "DeleteFileA",
  716. "address": "0x46e354"
  717. },
  718. {
  719. "name": "DeleteCriticalSection",
  720. "address": "0x46e358"
  721. },
  722. {
  723. "name": "CreateThread",
  724. "address": "0x46e35c"
  725. },
  726. {
  727. "name": "CreateProcessA",
  728. "address": "0x46e360"
  729. },
  730. {
  731. "name": "CreateFileA",
  732. "address": "0x46e364"
  733. },
  734. {
  735. "name": "CreateEventA",
  736. "address": "0x46e368"
  737. },
  738. {
  739. "name": "CompareStringA",
  740. "address": "0x46e36c"
  741. },
  742. {
  743. "name": "CloseHandle",
  744. "address": "0x46e370"
  745. }
  746. ],
  747. "dll": "kernel32.dll"
  748. },
  749. {
  750. "imports": [
  751. {
  752. "name": "VerQueryValueA",
  753. "address": "0x46e378"
  754. },
  755. {
  756. "name": "GetFileVersionInfoSizeA",
  757. "address": "0x46e37c"
  758. },
  759. {
  760. "name": "GetFileVersionInfoA",
  761. "address": "0x46e380"
  762. }
  763. ],
  764. "dll": "version.dll"
  765. },
  766. {
  767. "imports": [
  768. {
  769. "name": "UnrealizeObject",
  770. "address": "0x46e388"
  771. },
  772. {
  773. "name": "StretchBlt",
  774. "address": "0x46e38c"
  775. },
  776. {
  777. "name": "SetWindowOrgEx",
  778. "address": "0x46e390"
  779. },
  780. {
  781. "name": "SetWinMetaFileBits",
  782. "address": "0x46e394"
  783. },
  784. {
  785. "name": "SetViewportOrgEx",
  786. "address": "0x46e398"
  787. },
  788. {
  789. "name": "SetTextColor",
  790. "address": "0x46e39c"
  791. },
  792. {
  793. "name": "SetStretchBltMode",
  794. "address": "0x46e3a0"
  795. },
  796. {
  797. "name": "SetROP2",
  798. "address": "0x46e3a4"
  799. },
  800. {
  801. "name": "SetPixel",
  802. "address": "0x46e3a8"
  803. },
  804. {
  805. "name": "SetEnhMetaFileBits",
  806. "address": "0x46e3ac"
  807. },
  808. {
  809. "name": "SetDIBColorTable",
  810. "address": "0x46e3b0"
  811. },
  812. {
  813. "name": "SetBrushOrgEx",
  814. "address": "0x46e3b4"
  815. },
  816. {
  817. "name": "SetBkMode",
  818. "address": "0x46e3b8"
  819. },
  820. {
  821. "name": "SetBkColor",
  822. "address": "0x46e3bc"
  823. },
  824. {
  825. "name": "SelectPalette",
  826. "address": "0x46e3c0"
  827. },
  828. {
  829. "name": "SelectObject",
  830. "address": "0x46e3c4"
  831. },
  832. {
  833. "name": "SaveDC",
  834. "address": "0x46e3c8"
  835. },
  836. {
  837. "name": "RestoreDC",
  838. "address": "0x46e3cc"
  839. },
  840. {
  841. "name": "Rectangle",
  842. "address": "0x46e3d0"
  843. },
  844. {
  845. "name": "RectVisible",
  846. "address": "0x46e3d4"
  847. },
  848. {
  849. "name": "RealizePalette",
  850. "address": "0x46e3d8"
  851. },
  852. {
  853. "name": "PlayEnhMetaFile",
  854. "address": "0x46e3dc"
  855. },
  856. {
  857. "name": "PatBlt",
  858. "address": "0x46e3e0"
  859. },
  860. {
  861. "name": "MoveToEx",
  862. "address": "0x46e3e4"
  863. },
  864. {
  865. "name": "MaskBlt",
  866. "address": "0x46e3e8"
  867. },
  868. {
  869. "name": "LineTo",
  870. "address": "0x46e3ec"
  871. },
  872. {
  873. "name": "IntersectClipRect",
  874. "address": "0x46e3f0"
  875. },
  876. {
  877. "name": "GetWindowOrgEx",
  878. "address": "0x46e3f4"
  879. },
  880. {
  881. "name": "GetWinMetaFileBits",
  882. "address": "0x46e3f8"
  883. },
  884. {
  885. "name": "GetTextMetricsA",
  886. "address": "0x46e3fc"
  887. },
  888. {
  889. "name": "GetTextExtentPointA",
  890. "address": "0x46e400"
  891. },
  892. {
  893. "name": "GetTextExtentPoint32A",
  894. "address": "0x46e404"
  895. },
  896. {
  897. "name": "GetSystemPaletteEntries",
  898. "address": "0x46e408"
  899. },
  900. {
  901. "name": "GetStockObject",
  902. "address": "0x46e40c"
  903. },
  904. {
  905. "name": "GetPixelFormat",
  906. "address": "0x46e410"
  907. },
  908. {
  909. "name": "GetPixel",
  910. "address": "0x46e414"
  911. },
  912. {
  913. "name": "GetPaletteEntries",
  914. "address": "0x46e418"
  915. },
  916. {
  917. "name": "GetObjectA",
  918. "address": "0x46e41c"
  919. },
  920. {
  921. "name": "GetMapMode",
  922. "address": "0x46e420"
  923. },
  924. {
  925. "name": "GetEnhMetaFilePaletteEntries",
  926. "address": "0x46e424"
  927. },
  928. {
  929. "name": "GetEnhMetaFileHeader",
  930. "address": "0x46e428"
  931. },
  932. {
  933. "name": "GetEnhMetaFileBits",
  934. "address": "0x46e42c"
  935. },
  936. {
  937. "name": "GetDeviceCaps",
  938. "address": "0x46e430"
  939. },
  940. {
  941. "name": "GetDIBits",
  942. "address": "0x46e434"
  943. },
  944. {
  945. "name": "GetDIBColorTable",
  946. "address": "0x46e438"
  947. },
  948. {
  949. "name": "GetDCOrgEx",
  950. "address": "0x46e43c"
  951. },
  952. {
  953. "name": "GetCurrentPositionEx",
  954. "address": "0x46e440"
  955. },
  956. {
  957. "name": "GetClipBox",
  958. "address": "0x46e444"
  959. },
  960. {
  961. "name": "GetBrushOrgEx",
  962. "address": "0x46e448"
  963. },
  964. {
  965. "name": "GetBkColor",
  966. "address": "0x46e44c"
  967. },
  968. {
  969. "name": "GetBitmapBits",
  970. "address": "0x46e450"
  971. },
  972. {
  973. "name": "ExcludeClipRect",
  974. "address": "0x46e454"
  975. },
  976. {
  977. "name": "DeleteObject",
  978. "address": "0x46e458"
  979. },
  980. {
  981. "name": "DeleteEnhMetaFile",
  982. "address": "0x46e45c"
  983. },
  984. {
  985. "name": "DeleteDC",
  986. "address": "0x46e460"
  987. },
  988. {
  989. "name": "CreateSolidBrush",
  990. "address": "0x46e464"
  991. },
  992. {
  993. "name": "CreatePenIndirect",
  994. "address": "0x46e468"
  995. },
  996. {
  997. "name": "CreatePalette",
  998. "address": "0x46e46c"
  999. },
  1000. {
  1001. "name": "CreateHalftonePalette",
  1002. "address": "0x46e470"
  1003. },
  1004. {
  1005. "name": "CreateFontIndirectA",
  1006. "address": "0x46e474"
  1007. },
  1008. {
  1009. "name": "CreateDIBitmap",
  1010. "address": "0x46e478"
  1011. },
  1012. {
  1013. "name": "CreateDIBSection",
  1014. "address": "0x46e47c"
  1015. },
  1016. {
  1017. "name": "CreateCompatibleDC",
  1018. "address": "0x46e480"
  1019. },
  1020. {
  1021. "name": "CreateCompatibleBitmap",
  1022. "address": "0x46e484"
  1023. },
  1024. {
  1025. "name": "CreateBrushIndirect",
  1026. "address": "0x46e488"
  1027. },
  1028. {
  1029. "name": "CreateBitmap",
  1030. "address": "0x46e48c"
  1031. },
  1032. {
  1033. "name": "CopyEnhMetaFileA",
  1034. "address": "0x46e490"
  1035. },
  1036. {
  1037. "name": "BitBlt",
  1038. "address": "0x46e494"
  1039. }
  1040. ],
  1041. "dll": "gdi32.dll"
  1042. },
  1043. {
  1044. "imports": [
  1045. {
  1046. "name": "CreateWindowExA",
  1047. "address": "0x46e49c"
  1048. },
  1049. {
  1050. "name": "WindowFromPoint",
  1051. "address": "0x46e4a0"
  1052. },
  1053. {
  1054. "name": "WinHelpA",
  1055. "address": "0x46e4a4"
  1056. },
  1057. {
  1058. "name": "WaitMessage",
  1059. "address": "0x46e4a8"
  1060. },
  1061. {
  1062. "name": "UpdateWindow",
  1063. "address": "0x46e4ac"
  1064. },
  1065. {
  1066. "name": "UnregisterClassA",
  1067. "address": "0x46e4b0"
  1068. },
  1069. {
  1070. "name": "UnhookWindowsHookEx",
  1071. "address": "0x46e4b4"
  1072. },
  1073. {
  1074. "name": "TranslateMessage",
  1075. "address": "0x46e4b8"
  1076. },
  1077. {
  1078. "name": "TranslateMDISysAccel",
  1079. "address": "0x46e4bc"
  1080. },
  1081. {
  1082. "name": "TrackPopupMenu",
  1083. "address": "0x46e4c0"
  1084. },
  1085. {
  1086. "name": "SystemParametersInfoA",
  1087. "address": "0x46e4c4"
  1088. },
  1089. {
  1090. "name": "ShowWindow",
  1091. "address": "0x46e4c8"
  1092. },
  1093. {
  1094. "name": "ShowScrollBar",
  1095. "address": "0x46e4cc"
  1096. },
  1097. {
  1098. "name": "ShowOwnedPopups",
  1099. "address": "0x46e4d0"
  1100. },
  1101. {
  1102. "name": "ShowCursor",
  1103. "address": "0x46e4d4"
  1104. },
  1105. {
  1106. "name": "SetWindowsHookExA",
  1107. "address": "0x46e4d8"
  1108. },
  1109. {
  1110. "name": "SetWindowTextA",
  1111. "address": "0x46e4dc"
  1112. },
  1113. {
  1114. "name": "SetWindowPos",
  1115. "address": "0x46e4e0"
  1116. },
  1117. {
  1118. "name": "SetWindowPlacement",
  1119. "address": "0x46e4e4"
  1120. },
  1121. {
  1122. "name": "SetWindowLongA",
  1123. "address": "0x46e4e8"
  1124. },
  1125. {
  1126. "name": "SetTimer",
  1127. "address": "0x46e4ec"
  1128. },
  1129. {
  1130. "name": "SetScrollRange",
  1131. "address": "0x46e4f0"
  1132. },
  1133. {
  1134. "name": "SetScrollPos",
  1135. "address": "0x46e4f4"
  1136. },
  1137. {
  1138. "name": "SetScrollInfo",
  1139. "address": "0x46e4f8"
  1140. },
  1141. {
  1142. "name": "SetRect",
  1143. "address": "0x46e4fc"
  1144. },
  1145. {
  1146. "name": "SetPropA",
  1147. "address": "0x46e500"
  1148. },
  1149. {
  1150. "name": "SetParent",
  1151. "address": "0x46e504"
  1152. },
  1153. {
  1154. "name": "SetMenuItemInfoA",
  1155. "address": "0x46e508"
  1156. },
  1157. {
  1158. "name": "SetMenu",
  1159. "address": "0x46e50c"
  1160. },
  1161. {
  1162. "name": "SetForegroundWindow",
  1163. "address": "0x46e510"
  1164. },
  1165. {
  1166. "name": "SetFocus",
  1167. "address": "0x46e514"
  1168. },
  1169. {
  1170. "name": "SetCursor",
  1171. "address": "0x46e518"
  1172. },
  1173. {
  1174. "name": "SetClipboardData",
  1175. "address": "0x46e51c"
  1176. },
  1177. {
  1178. "name": "SetClassLongA",
  1179. "address": "0x46e520"
  1180. },
  1181. {
  1182. "name": "SetCapture",
  1183. "address": "0x46e524"
  1184. },
  1185. {
  1186. "name": "SetActiveWindow",
  1187. "address": "0x46e528"
  1188. },
  1189. {
  1190. "name": "SendMessageA",
  1191. "address": "0x46e52c"
  1192. },
  1193. {
  1194. "name": "ScrollWindow",
  1195. "address": "0x46e530"
  1196. },
  1197. {
  1198. "name": "ScreenToClient",
  1199. "address": "0x46e534"
  1200. },
  1201. {
  1202. "name": "RemovePropA",
  1203. "address": "0x46e538"
  1204. },
  1205. {
  1206. "name": "RemoveMenu",
  1207. "address": "0x46e53c"
  1208. },
  1209. {
  1210. "name": "ReleaseDC",
  1211. "address": "0x46e540"
  1212. },
  1213. {
  1214. "name": "ReleaseCapture",
  1215. "address": "0x46e544"
  1216. },
  1217. {
  1218. "name": "RegisterWindowMessageA",
  1219. "address": "0x46e548"
  1220. },
  1221. {
  1222. "name": "RegisterClipboardFormatA",
  1223. "address": "0x46e54c"
  1224. },
  1225. {
  1226. "name": "RegisterClassA",
  1227. "address": "0x46e550"
  1228. },
  1229. {
  1230. "name": "RedrawWindow",
  1231. "address": "0x46e554"
  1232. },
  1233. {
  1234. "name": "PtInRect",
  1235. "address": "0x46e558"
  1236. },
  1237. {
  1238. "name": "PostQuitMessage",
  1239. "address": "0x46e55c"
  1240. },
  1241. {
  1242. "name": "PostMessageA",
  1243. "address": "0x46e560"
  1244. },
  1245. {
  1246. "name": "PeekMessageA",
  1247. "address": "0x46e564"
  1248. },
  1249. {
  1250. "name": "OpenClipboard",
  1251. "address": "0x46e568"
  1252. },
  1253. {
  1254. "name": "OffsetRect",
  1255. "address": "0x46e56c"
  1256. },
  1257. {
  1258. "name": "OemToCharA",
  1259. "address": "0x46e570"
  1260. },
  1261. {
  1262. "name": "MsgWaitForMultipleObjects",
  1263. "address": "0x46e574"
  1264. },
  1265. {
  1266. "name": "MessageBoxA",
  1267. "address": "0x46e578"
  1268. },
  1269. {
  1270. "name": "MessageBeep",
  1271. "address": "0x46e57c"
  1272. },
  1273. {
  1274. "name": "MapWindowPoints",
  1275. "address": "0x46e580"
  1276. },
  1277. {
  1278. "name": "MapVirtualKeyA",
  1279. "address": "0x46e584"
  1280. },
  1281. {
  1282. "name": "LoadStringA",
  1283. "address": "0x46e588"
  1284. },
  1285. {
  1286. "name": "LoadKeyboardLayoutA",
  1287. "address": "0x46e58c"
  1288. },
  1289. {
  1290. "name": "LoadIconA",
  1291. "address": "0x46e590"
  1292. },
  1293. {
  1294. "name": "LoadCursorA",
  1295. "address": "0x46e594"
  1296. },
  1297. {
  1298. "name": "LoadBitmapA",
  1299. "address": "0x46e598"
  1300. },
  1301. {
  1302. "name": "KillTimer",
  1303. "address": "0x46e59c"
  1304. },
  1305. {
  1306. "name": "IsZoomed",
  1307. "address": "0x46e5a0"
  1308. },
  1309. {
  1310. "name": "IsWindowVisible",
  1311. "address": "0x46e5a4"
  1312. },
  1313. {
  1314. "name": "IsWindowEnabled",
  1315. "address": "0x46e5a8"
  1316. },
  1317. {
  1318. "name": "IsWindow",
  1319. "address": "0x46e5ac"
  1320. },
  1321. {
  1322. "name": "IsRectEmpty",
  1323. "address": "0x46e5b0"
  1324. },
  1325. {
  1326. "name": "IsIconic",
  1327. "address": "0x46e5b4"
  1328. },
  1329. {
  1330. "name": "IsDialogMessageA",
  1331. "address": "0x46e5b8"
  1332. },
  1333. {
  1334. "name": "IsChild",
  1335. "address": "0x46e5bc"
  1336. },
  1337. {
  1338. "name": "InvalidateRect",
  1339. "address": "0x46e5c0"
  1340. },
  1341. {
  1342. "name": "IntersectRect",
  1343. "address": "0x46e5c4"
  1344. },
  1345. {
  1346. "name": "InsertMenuItemA",
  1347. "address": "0x46e5c8"
  1348. },
  1349. {
  1350. "name": "InsertMenuA",
  1351. "address": "0x46e5cc"
  1352. },
  1353. {
  1354. "name": "InflateRect",
  1355. "address": "0x46e5d0"
  1356. },
  1357. {
  1358. "name": "GetWindowThreadProcessId",
  1359. "address": "0x46e5d4"
  1360. },
  1361. {
  1362. "name": "GetWindowTextA",
  1363. "address": "0x46e5d8"
  1364. },
  1365. {
  1366. "name": "GetWindowRect",
  1367. "address": "0x46e5dc"
  1368. },
  1369. {
  1370. "name": "GetWindowPlacement",
  1371. "address": "0x46e5e0"
  1372. },
  1373. {
  1374. "name": "GetWindowLongA",
  1375. "address": "0x46e5e4"
  1376. },
  1377. {
  1378. "name": "GetWindowDC",
  1379. "address": "0x46e5e8"
  1380. },
  1381. {
  1382. "name": "GetTopWindow",
  1383. "address": "0x46e5ec"
  1384. },
  1385. {
  1386. "name": "GetSystemMetrics",
  1387. "address": "0x46e5f0"
  1388. },
  1389. {
  1390. "name": "GetSystemMenu",
  1391. "address": "0x46e5f4"
  1392. },
  1393. {
  1394. "name": "GetSysColorBrush",
  1395. "address": "0x46e5f8"
  1396. },
  1397. {
  1398. "name": "GetSysColor",
  1399. "address": "0x46e5fc"
  1400. },
  1401. {
  1402. "name": "GetSubMenu",
  1403. "address": "0x46e600"
  1404. },
  1405. {
  1406. "name": "GetScrollRange",
  1407. "address": "0x46e604"
  1408. },
  1409. {
  1410. "name": "GetScrollPos",
  1411. "address": "0x46e608"
  1412. },
  1413. {
  1414. "name": "GetScrollInfo",
  1415. "address": "0x46e60c"
  1416. },
  1417. {
  1418. "name": "GetPropA",
  1419. "address": "0x46e610"
  1420. },
  1421. {
  1422. "name": "GetParent",
  1423. "address": "0x46e614"
  1424. },
  1425. {
  1426. "name": "GetWindow",
  1427. "address": "0x46e618"
  1428. },
  1429. {
  1430. "name": "GetMenuStringA",
  1431. "address": "0x46e61c"
  1432. },
  1433. {
  1434. "name": "GetMenuState",
  1435. "address": "0x46e620"
  1436. },
  1437. {
  1438. "name": "GetMenuItemInfoA",
  1439. "address": "0x46e624"
  1440. },
  1441. {
  1442. "name": "GetMenuItemID",
  1443. "address": "0x46e628"
  1444. },
  1445. {
  1446. "name": "GetMenuItemCount",
  1447. "address": "0x46e62c"
  1448. },
  1449. {
  1450. "name": "GetMenu",
  1451. "address": "0x46e630"
  1452. },
  1453. {
  1454. "name": "GetLastActivePopup",
  1455. "address": "0x46e634"
  1456. },
  1457. {
  1458. "name": "GetKeyboardState",
  1459. "address": "0x46e638"
  1460. },
  1461. {
  1462. "name": "GetKeyboardLayoutList",
  1463. "address": "0x46e63c"
  1464. },
  1465. {
  1466. "name": "GetKeyboardLayout",
  1467. "address": "0x46e640"
  1468. },
  1469. {
  1470. "name": "GetKeyState",
  1471. "address": "0x46e644"
  1472. },
  1473. {
  1474. "name": "GetKeyNameTextA",
  1475. "address": "0x46e648"
  1476. },
  1477. {
  1478. "name": "GetIconInfo",
  1479. "address": "0x46e64c"
  1480. },
  1481. {
  1482. "name": "GetForegroundWindow",
  1483. "address": "0x46e650"
  1484. },
  1485. {
  1486. "name": "GetFocus",
  1487. "address": "0x46e654"
  1488. },
  1489. {
  1490. "name": "GetDlgItem",
  1491. "address": "0x46e658"
  1492. },
  1493. {
  1494. "name": "GetDesktopWindow",
  1495. "address": "0x46e65c"
  1496. },
  1497. {
  1498. "name": "GetDCEx",
  1499. "address": "0x46e660"
  1500. },
  1501. {
  1502. "name": "GetDC",
  1503. "address": "0x46e664"
  1504. },
  1505. {
  1506. "name": "GetCursorPos",
  1507. "address": "0x46e668"
  1508. },
  1509. {
  1510. "name": "GetCursor",
  1511. "address": "0x46e66c"
  1512. },
  1513. {
  1514. "name": "GetClipboardData",
  1515. "address": "0x46e670"
  1516. },
  1517. {
  1518. "name": "GetClientRect",
  1519. "address": "0x46e674"
  1520. },
  1521. {
  1522. "name": "GetClassNameA",
  1523. "address": "0x46e678"
  1524. },
  1525. {
  1526. "name": "GetClassInfoA",
  1527. "address": "0x46e67c"
  1528. },
  1529. {
  1530. "name": "GetCapture",
  1531. "address": "0x46e680"
  1532. },
  1533. {
  1534. "name": "GetActiveWindow",
  1535. "address": "0x46e684"
  1536. },
  1537. {
  1538. "name": "FrameRect",
  1539. "address": "0x46e688"
  1540. },
  1541. {
  1542. "name": "FindWindowA",
  1543. "address": "0x46e68c"
  1544. },
  1545. {
  1546. "name": "FillRect",
  1547. "address": "0x46e690"
  1548. },
  1549. {
  1550. "name": "EqualRect",
  1551. "address": "0x46e694"
  1552. },
  1553. {
  1554. "name": "EnumWindows",
  1555. "address": "0x46e698"
  1556. },
  1557. {
  1558. "name": "EnumThreadWindows",
  1559. "address": "0x46e69c"
  1560. },
  1561. {
  1562. "name": "EndPaint",
  1563. "address": "0x46e6a0"
  1564. },
  1565. {
  1566. "name": "EnableWindow",
  1567. "address": "0x46e6a4"
  1568. },
  1569. {
  1570. "name": "EnableScrollBar",
  1571. "address": "0x46e6a8"
  1572. },
  1573. {
  1574. "name": "EnableMenuItem",
  1575. "address": "0x46e6ac"
  1576. },
  1577. {
  1578. "name": "EmptyClipboard",
  1579. "address": "0x46e6b0"
  1580. },
  1581. {
  1582. "name": "DrawTextA",
  1583. "address": "0x46e6b4"
  1584. },
  1585. {
  1586. "name": "DrawMenuBar",
  1587. "address": "0x46e6b8"
  1588. },
  1589. {
  1590. "name": "DrawIconEx",
  1591. "address": "0x46e6bc"
  1592. },
  1593. {
  1594. "name": "DrawIcon",
  1595. "address": "0x46e6c0"
  1596. },
  1597. {
  1598. "name": "DrawFrameControl",
  1599. "address": "0x46e6c4"
  1600. },
  1601. {
  1602. "name": "DrawFocusRect",
  1603. "address": "0x46e6c8"
  1604. },
  1605. {
  1606. "name": "DrawEdge",
  1607. "address": "0x46e6cc"
  1608. },
  1609. {
  1610. "name": "DispatchMessageA",
  1611. "address": "0x46e6d0"
  1612. },
  1613. {
  1614. "name": "DestroyWindow",
  1615. "address": "0x46e6d4"
  1616. },
  1617. {
  1618. "name": "DestroyMenu",
  1619. "address": "0x46e6d8"
  1620. },
  1621. {
  1622. "name": "DestroyIcon",
  1623. "address": "0x46e6dc"
  1624. },
  1625. {
  1626. "name": "DestroyCursor",
  1627. "address": "0x46e6e0"
  1628. },
  1629. {
  1630. "name": "DeleteMenu",
  1631. "address": "0x46e6e4"
  1632. },
  1633. {
  1634. "name": "DefWindowProcA",
  1635. "address": "0x46e6e8"
  1636. },
  1637. {
  1638. "name": "DefMDIChildProcA",
  1639. "address": "0x46e6ec"
  1640. },
  1641. {
  1642. "name": "DefFrameProcA",
  1643. "address": "0x46e6f0"
  1644. },
  1645. {
  1646. "name": "CreatePopupMenu",
  1647. "address": "0x46e6f4"
  1648. },
  1649. {
  1650. "name": "CreateMenu",
  1651. "address": "0x46e6f8"
  1652. },
  1653. {
  1654. "name": "CreateIcon",
  1655. "address": "0x46e6fc"
  1656. },
  1657. {
  1658. "name": "CloseClipboard",
  1659. "address": "0x46e700"
  1660. },
  1661. {
  1662. "name": "ClientToScreen",
  1663. "address": "0x46e704"
  1664. },
  1665. {
  1666. "name": "CheckMenuItem",
  1667. "address": "0x46e708"
  1668. },
  1669. {
  1670. "name": "CallWindowProcA",
  1671. "address": "0x46e70c"
  1672. },
  1673. {
  1674. "name": "CallNextHookEx",
  1675. "address": "0x46e710"
  1676. },
  1677. {
  1678. "name": "BeginPaint",
  1679. "address": "0x46e714"
  1680. },
  1681. {
  1682. "name": "CharNextA",
  1683. "address": "0x46e718"
  1684. },
  1685. {
  1686. "name": "CharLowerBuffA",
  1687. "address": "0x46e71c"
  1688. },
  1689. {
  1690. "name": "CharLowerA",
  1691. "address": "0x46e720"
  1692. },
  1693. {
  1694. "name": "CharUpperBuffA",
  1695. "address": "0x46e724"
  1696. },
  1697. {
  1698. "name": "CharToOemA",
  1699. "address": "0x46e728"
  1700. },
  1701. {
  1702. "name": "AdjustWindowRectEx",
  1703. "address": "0x46e72c"
  1704. },
  1705. {
  1706. "name": "ActivateKeyboardLayout",
  1707. "address": "0x46e730"
  1708. }
  1709. ],
  1710. "dll": "user32.dll"
  1711. },
  1712. {
  1713. "imports": [
  1714. {
  1715. "name": "Sleep",
  1716. "address": "0x46e738"
  1717. }
  1718. ],
  1719. "dll": "kernel32.dll"
  1720. },
  1721. {
  1722. "imports": [
  1723. {
  1724. "name": "SafeArrayPtrOfIndex",
  1725. "address": "0x46e740"
  1726. },
  1727. {
  1728. "name": "SafeArrayGetUBound",
  1729. "address": "0x46e744"
  1730. },
  1731. {
  1732. "name": "SafeArrayGetLBound",
  1733. "address": "0x46e748"
  1734. },
  1735. {
  1736. "name": "SafeArrayCreate",
  1737. "address": "0x46e74c"
  1738. },
  1739. {
  1740. "name": "VariantChangeType",
  1741. "address": "0x46e750"
  1742. },
  1743. {
  1744. "name": "VariantCopy",
  1745. "address": "0x46e754"
  1746. },
  1747. {
  1748. "name": "VariantClear",
  1749. "address": "0x46e758"
  1750. },
  1751. {
  1752. "name": "VariantInit",
  1753. "address": "0x46e75c"
  1754. }
  1755. ],
  1756. "dll": "oleaut32.dll"
  1757. },
  1758. {
  1759. "imports": [
  1760. {
  1761. "name": "ImageList_SetIconSize",
  1762. "address": "0x46e764"
  1763. },
  1764. {
  1765. "name": "ImageList_GetIconSize",
  1766. "address": "0x46e768"
  1767. },
  1768. {
  1769. "name": "ImageList_Write",
  1770. "address": "0x46e76c"
  1771. },
  1772. {
  1773. "name": "ImageList_Read",
  1774. "address": "0x46e770"
  1775. },
  1776. {
  1777. "name": "ImageList_GetDragImage",
  1778. "address": "0x46e774"
  1779. },
  1780. {
  1781. "name": "ImageList_DragShowNolock",
  1782. "address": "0x46e778"
  1783. },
  1784. {
  1785. "name": "ImageList_SetDragCursorImage",
  1786. "address": "0x46e77c"
  1787. },
  1788. {
  1789. "name": "ImageList_DragMove",
  1790. "address": "0x46e780"
  1791. },
  1792. {
  1793. "name": "ImageList_DragLeave",
  1794. "address": "0x46e784"
  1795. },
  1796. {
  1797. "name": "ImageList_DragEnter",
  1798. "address": "0x46e788"
  1799. },
  1800. {
  1801. "name": "ImageList_EndDrag",
  1802. "address": "0x46e78c"
  1803. },
  1804. {
  1805. "name": "ImageList_BeginDrag",
  1806. "address": "0x46e790"
  1807. },
  1808. {
  1809. "name": "ImageList_Remove",
  1810. "address": "0x46e794"
  1811. },
  1812. {
  1813. "name": "ImageList_DrawEx",
  1814. "address": "0x46e798"
  1815. },
  1816. {
  1817. "name": "ImageList_Replace",
  1818. "address": "0x46e79c"
  1819. },
  1820. {
  1821. "name": "ImageList_Draw",
  1822. "address": "0x46e7a0"
  1823. },
  1824. {
  1825. "name": "ImageList_GetBkColor",
  1826. "address": "0x46e7a4"
  1827. },
  1828. {
  1829. "name": "ImageList_SetBkColor",
  1830. "address": "0x46e7a8"
  1831. },
  1832. {
  1833. "name": "ImageList_ReplaceIcon",
  1834. "address": "0x46e7ac"
  1835. },
  1836. {
  1837. "name": "ImageList_Add",
  1838. "address": "0x46e7b0"
  1839. },
  1840. {
  1841. "name": "ImageList_SetImageCount",
  1842. "address": "0x46e7b4"
  1843. },
  1844. {
  1845. "name": "ImageList_GetImageCount",
  1846. "address": "0x46e7b8"
  1847. },
  1848. {
  1849. "name": "ImageList_Destroy",
  1850. "address": "0x46e7bc"
  1851. },
  1852. {
  1853. "name": "ImageList_Create",
  1854. "address": "0x46e7c0"
  1855. }
  1856. ],
  1857. "dll": "comctl32.dll"
  1858. },
  1859. {
  1860. "imports": [
  1861. {
  1862. "name": "GetOpenFileNameA",
  1863. "address": "0x46e7c8"
  1864. }
  1865. ],
  1866. "dll": "comdlg32.dll"
  1867. },
  1868. {
  1869. "imports": [
  1870. {
  1871. "name": "WSACleanup",
  1872. "address": "0x46e7d0"
  1873. },
  1874. {
  1875. "name": "WSAStartup",
  1876. "address": "0x46e7d4"
  1877. },
  1878. {
  1879. "name": "WSAGetLastError",
  1880. "address": "0x46e7d8"
  1881. },
  1882. {
  1883. "name": "WSAAsyncGetHostByName",
  1884. "address": "0x46e7dc"
  1885. },
  1886. {
  1887. "name": "WSAAsyncSelect",
  1888. "address": "0x46e7e0"
  1889. },
  1890. {
  1891. "name": "socket",
  1892. "address": "0x46e7e4"
  1893. },
  1894. {
  1895. "name": "setsockopt",
  1896. "address": "0x46e7e8"
  1897. },
  1898. {
  1899. "name": "send",
  1900. "address": "0x46e7ec"
  1901. },
  1902. {
  1903. "name": "recv",
  1904. "address": "0x46e7f0"
  1905. },
  1906. {
  1907. "name": "inet_addr",
  1908. "address": "0x46e7f4"
  1909. },
  1910. {
  1911. "name": "htons",
  1912. "address": "0x46e7f8"
  1913. },
  1914. {
  1915. "name": "connect",
  1916. "address": "0x46e7fc"
  1917. },
  1918. {
  1919. "name": "closesocket",
  1920. "address": "0x46e800"
  1921. },
  1922. {
  1923. "name": "accept",
  1924. "address": "0x46e804"
  1925. }
  1926. ],
  1927. "dll": "wsock32.dll"
  1928. }
  1929. ],
  1930. "digital_signers": null,
  1931. "exported_dll_name": null,
  1932. "actual_checksum": "0x0015ecfd",
  1933. "overlay": {
  1934. "size": "0x0009b7c8",
  1935. "offset": "0x000c0c00"
  1936. },
  1937. "imagebase": "0x00400000",
  1938. "reported_checksum": "0x000d0b4d",
  1939. "icon_hash": null,
  1940. "entrypoint": "0x00469844",
  1941. "timestamp": "1992-06-19 22:22:17",
  1942. "osversion": "4.0",
  1943. "sections": [
  1944. {
  1945. "name": "CODE",
  1946. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
  1947. "virtual_address": "0x00001000",
  1948. "size_of_data": "0x00068a00",
  1949. "entropy": "6.51",
  1950. "raw_address": "0x00000400",
  1951. "virtual_size": "0x000688b8",
  1952. "characteristics_raw": "0x60000020"
  1953. },
  1954. {
  1955. "name": "DATA",
  1956. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  1957. "virtual_address": "0x0006a000",
  1958. "size_of_data": "0x00002000",
  1959. "entropy": "4.12",
  1960. "raw_address": "0x00068e00",
  1961. "virtual_size": "0x00001f0c",
  1962. "characteristics_raw": "0xc0000040"
  1963. },
  1964. {
  1965. "name": "BSS",
  1966. "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  1967. "virtual_address": "0x0006c000",
  1968. "size_of_data": "0x00000000",
  1969. "entropy": "0.00",
  1970. "raw_address": "0x0006ae00",
  1971. "virtual_size": "0x000010b9",
  1972. "characteristics_raw": "0xc0000000"
  1973. },
  1974. {
  1975. "name": ".idata",
  1976. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  1977. "virtual_address": "0x0006e000",
  1978. "size_of_data": "0x00002600",
  1979. "entropy": "4.97",
  1980. "raw_address": "0x0006ae00",
  1981. "virtual_size": "0x000024d4",
  1982. "characteristics_raw": "0xc0000040"
  1983. },
  1984. {
  1985. "name": ".tls",
  1986. "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  1987. "virtual_address": "0x00071000",
  1988. "size_of_data": "0x00000000",
  1989. "entropy": "0.00",
  1990. "raw_address": "0x0006d400",
  1991. "virtual_size": "0x00000010",
  1992. "characteristics_raw": "0xc0000000"
  1993. },
  1994. {
  1995. "name": ".rdata",
  1996. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
  1997. "virtual_address": "0x00072000",
  1998. "size_of_data": "0x00000200",
  1999. "entropy": "0.20",
  2000. "raw_address": "0x0006d400",
  2001. "virtual_size": "0x00000018",
  2002. "characteristics_raw": "0x50000040"
  2003. },
  2004. {
  2005. "name": ".reloc",
  2006. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
  2007. "virtual_address": "0x00073000",
  2008. "size_of_data": "0x00007c00",
  2009. "entropy": "6.65",
  2010. "raw_address": "0x0006d600",
  2011. "virtual_size": "0x00007adc",
  2012. "characteristics_raw": "0x50000040"
  2013. },
  2014. {
  2015. "name": ".rsrc",
  2016. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
  2017. "virtual_address": "0x0007b000",
  2018. "size_of_data": "0x0004ba00",
  2019. "entropy": "5.80",
  2020. "raw_address": "0x00075200",
  2021. "virtual_size": "0x0004b9ac",
  2022. "characteristics_raw": "0x50000040"
  2023. }
  2024. ],
  2025. "resources": [],
  2026. "dirents": [
  2027. {
  2028. "virtual_address": "0x00000000",
  2029. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  2030. "size": "0x00000000"
  2031. },
  2032. {
  2033. "virtual_address": "0x0006e000",
  2034. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  2035. "size": "0x000024d4"
  2036. },
  2037. {
  2038. "virtual_address": "0x0007b000",
  2039. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  2040. "size": "0x0004b9ac"
  2041. },
  2042. {
  2043. "virtual_address": "0x00000000",
  2044. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  2045. "size": "0x00000000"
  2046. },
  2047. {
  2048. "virtual_address": "0x00000000",
  2049. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  2050. "size": "0x00000000"
  2051. },
  2052. {
  2053. "virtual_address": "0x00073000",
  2054. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  2055. "size": "0x00007adc"
  2056. },
  2057. {
  2058. "virtual_address": "0x00000000",
  2059. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  2060. "size": "0x00000000"
  2061. },
  2062. {
  2063. "virtual_address": "0x00000000",
  2064. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  2065. "size": "0x00000000"
  2066. },
  2067. {
  2068. "virtual_address": "0x00000000",
  2069. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  2070. "size": "0x00000000"
  2071. },
  2072. {
  2073. "virtual_address": "0x00072000",
  2074. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  2075. "size": "0x00000018"
  2076. },
  2077. {
  2078. "virtual_address": "0x00000000",
  2079. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  2080. "size": "0x00000000"
  2081. },
  2082. {
  2083. "virtual_address": "0x00000000",
  2084. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  2085. "size": "0x00000000"
  2086. },
  2087. {
  2088. "virtual_address": "0x00000000",
  2089. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  2090. "size": "0x00000000"
  2091. },
  2092. {
  2093. "virtual_address": "0x00000000",
  2094. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  2095. "size": "0x00000000"
  2096. },
  2097. {
  2098. "virtual_address": "0x00000000",
  2099. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  2100. "size": "0x00000000"
  2101. },
  2102. {
  2103. "virtual_address": "0x00000000",
  2104. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  2105. "size": "0x00000000"
  2106. }
  2107. ],
  2108. "exports": [],
  2109. "guest_signers": {},
  2110. "imphash": "5ae4cca98b2f15124dd50272f7881db7",
  2111. "icon_fuzzy": null,
  2112. "icon": null,
  2113. "pdbpath": null,
  2114. "imported_dll_count": 15,
  2115. "versioninfo": []
  2116. }
  2117. }
  2118.  
  2119. [*] Resolved APIs: []
  2120.  
  2121. [*] Static Analysis: {
  2122. "pe": {
  2123. "peid_signatures": null,
  2124. "imports": [
  2125. {
  2126. "imports": [
  2127. {
  2128. "name": "DeleteCriticalSection",
  2129. "address": "0x46e140"
  2130. },
  2131. {
  2132. "name": "LeaveCriticalSection",
  2133. "address": "0x46e144"
  2134. },
  2135. {
  2136. "name": "EnterCriticalSection",
  2137. "address": "0x46e148"
  2138. },
  2139. {
  2140. "name": "InitializeCriticalSection",
  2141. "address": "0x46e14c"
  2142. },
  2143. {
  2144. "name": "VirtualFree",
  2145. "address": "0x46e150"
  2146. },
  2147. {
  2148. "name": "VirtualAlloc",
  2149. "address": "0x46e154"
  2150. },
  2151. {
  2152. "name": "LocalFree",
  2153. "address": "0x46e158"
  2154. },
  2155. {
  2156. "name": "LocalAlloc",
  2157. "address": "0x46e15c"
  2158. },
  2159. {
  2160. "name": "GetVersion",
  2161. "address": "0x46e160"
  2162. },
  2163. {
  2164. "name": "GetCurrentThreadId",
  2165. "address": "0x46e164"
  2166. },
  2167. {
  2168. "name": "InterlockedDecrement",
  2169. "address": "0x46e168"
  2170. },
  2171. {
  2172. "name": "InterlockedIncrement",
  2173. "address": "0x46e16c"
  2174. },
  2175. {
  2176. "name": "VirtualQuery",
  2177. "address": "0x46e170"
  2178. },
  2179. {
  2180. "name": "WideCharToMultiByte",
  2181. "address": "0x46e174"
  2182. },
  2183. {
  2184. "name": "MultiByteToWideChar",
  2185. "address": "0x46e178"
  2186. },
  2187. {
  2188. "name": "lstrlenA",
  2189. "address": "0x46e17c"
  2190. },
  2191. {
  2192. "name": "lstrcpynA",
  2193. "address": "0x46e180"
  2194. },
  2195. {
  2196. "name": "LoadLibraryExA",
  2197. "address": "0x46e184"
  2198. },
  2199. {
  2200. "name": "GetThreadLocale",
  2201. "address": "0x46e188"
  2202. },
  2203. {
  2204. "name": "GetStartupInfoA",
  2205. "address": "0x46e18c"
  2206. },
  2207. {
  2208. "name": "GetProcAddress",
  2209. "address": "0x46e190"
  2210. },
  2211. {
  2212. "name": "GetModuleHandleA",
  2213. "address": "0x46e194"
  2214. },
  2215. {
  2216. "name": "GetModuleFileNameA",
  2217. "address": "0x46e198"
  2218. },
  2219. {
  2220. "name": "GetLocaleInfoA",
  2221. "address": "0x46e19c"
  2222. },
  2223. {
  2224. "name": "GetLastError",
  2225. "address": "0x46e1a0"
  2226. },
  2227. {
  2228. "name": "GetCommandLineA",
  2229. "address": "0x46e1a4"
  2230. },
  2231. {
  2232. "name": "FreeLibrary",
  2233. "address": "0x46e1a8"
  2234. },
  2235. {
  2236. "name": "FindFirstFileA",
  2237. "address": "0x46e1ac"
  2238. },
  2239. {
  2240. "name": "FindClose",
  2241. "address": "0x46e1b0"
  2242. },
  2243. {
  2244. "name": "ExitProcess",
  2245. "address": "0x46e1b4"
  2246. },
  2247. {
  2248. "name": "ExitThread",
  2249. "address": "0x46e1b8"
  2250. },
  2251. {
  2252. "name": "CreateThread",
  2253. "address": "0x46e1bc"
  2254. },
  2255. {
  2256. "name": "WriteFile",
  2257. "address": "0x46e1c0"
  2258. },
  2259. {
  2260. "name": "UnhandledExceptionFilter",
  2261. "address": "0x46e1c4"
  2262. },
  2263. {
  2264. "name": "SetFilePointer",
  2265. "address": "0x46e1c8"
  2266. },
  2267. {
  2268. "name": "SetEndOfFile",
  2269. "address": "0x46e1cc"
  2270. },
  2271. {
  2272. "name": "RtlUnwind",
  2273. "address": "0x46e1d0"
  2274. },
  2275. {
  2276. "name": "ReadFile",
  2277. "address": "0x46e1d4"
  2278. },
  2279. {
  2280. "name": "RaiseException",
  2281. "address": "0x46e1d8"
  2282. },
  2283. {
  2284. "name": "GetStdHandle",
  2285. "address": "0x46e1dc"
  2286. },
  2287. {
  2288. "name": "GetFileSize",
  2289. "address": "0x46e1e0"
  2290. },
  2291. {
  2292. "name": "GetFileType",
  2293. "address": "0x46e1e4"
  2294. },
  2295. {
  2296. "name": "CreateFileA",
  2297. "address": "0x46e1e8"
  2298. },
  2299. {
  2300. "name": "CloseHandle",
  2301. "address": "0x46e1ec"
  2302. }
  2303. ],
  2304. "dll": "kernel32.dll"
  2305. },
  2306. {
  2307. "imports": [
  2308. {
  2309. "name": "GetKeyboardType",
  2310. "address": "0x46e1f4"
  2311. },
  2312. {
  2313. "name": "LoadStringA",
  2314. "address": "0x46e1f8"
  2315. },
  2316. {
  2317. "name": "MessageBoxA",
  2318. "address": "0x46e1fc"
  2319. },
  2320. {
  2321. "name": "CharNextA",
  2322. "address": "0x46e200"
  2323. }
  2324. ],
  2325. "dll": "user32.dll"
  2326. },
  2327. {
  2328. "imports": [
  2329. {
  2330. "name": "RegQueryValueExA",
  2331. "address": "0x46e208"
  2332. },
  2333. {
  2334. "name": "RegOpenKeyExA",
  2335. "address": "0x46e20c"
  2336. },
  2337. {
  2338. "name": "RegCloseKey",
  2339. "address": "0x46e210"
  2340. }
  2341. ],
  2342. "dll": "advapi32.dll"
  2343. },
  2344. {
  2345. "imports": [
  2346. {
  2347. "name": "SysFreeString",
  2348. "address": "0x46e218"
  2349. },
  2350. {
  2351. "name": "SysReAllocStringLen",
  2352. "address": "0x46e21c"
  2353. },
  2354. {
  2355. "name": "SysAllocStringLen",
  2356. "address": "0x46e220"
  2357. }
  2358. ],
  2359. "dll": "oleaut32.dll"
  2360. },
  2361. {
  2362. "imports": [
  2363. {
  2364. "name": "TlsSetValue",
  2365. "address": "0x46e228"
  2366. },
  2367. {
  2368. "name": "TlsGetValue",
  2369. "address": "0x46e22c"
  2370. },
  2371. {
  2372. "name": "LocalAlloc",
  2373. "address": "0x46e230"
  2374. },
  2375. {
  2376. "name": "GetModuleHandleA",
  2377. "address": "0x46e234"
  2378. }
  2379. ],
  2380. "dll": "kernel32.dll"
  2381. },
  2382. {
  2383. "imports": [
  2384. {
  2385. "name": "RegQueryValueExA",
  2386. "address": "0x46e23c"
  2387. },
  2388. {
  2389. "name": "RegOpenKeyExA",
  2390. "address": "0x46e240"
  2391. },
  2392. {
  2393. "name": "RegCloseKey",
  2394. "address": "0x46e244"
  2395. }
  2396. ],
  2397. "dll": "advapi32.dll"
  2398. },
  2399. {
  2400. "imports": [
  2401. {
  2402. "name": "lstrcpyA",
  2403. "address": "0x46e24c"
  2404. },
  2405. {
  2406. "name": "WriteFile",
  2407. "address": "0x46e250"
  2408. },
  2409. {
  2410. "name": "WaitForSingleObject",
  2411. "address": "0x46e254"
  2412. },
  2413. {
  2414. "name": "VirtualQuery",
  2415. "address": "0x46e258"
  2416. },
  2417. {
  2418. "name": "VirtualAlloc",
  2419. "address": "0x46e25c"
  2420. },
  2421. {
  2422. "name": "Sleep",
  2423. "address": "0x46e260"
  2424. },
  2425. {
  2426. "name": "SizeofResource",
  2427. "address": "0x46e264"
  2428. },
  2429. {
  2430. "name": "SetThreadLocale",
  2431. "address": "0x46e268"
  2432. },
  2433. {
  2434. "name": "SetFilePointer",
  2435. "address": "0x46e26c"
  2436. },
  2437. {
  2438. "name": "SetEvent",
  2439. "address": "0x46e270"
  2440. },
  2441. {
  2442. "name": "SetErrorMode",
  2443. "address": "0x46e274"
  2444. },
  2445. {
  2446. "name": "SetEndOfFile",
  2447. "address": "0x46e278"
  2448. },
  2449. {
  2450. "name": "ResumeThread",
  2451. "address": "0x46e27c"
  2452. },
  2453. {
  2454. "name": "ResetEvent",
  2455. "address": "0x46e280"
  2456. },
  2457. {
  2458. "name": "ReadFile",
  2459. "address": "0x46e284"
  2460. },
  2461. {
  2462. "name": "MulDiv",
  2463. "address": "0x46e288"
  2464. },
  2465. {
  2466. "name": "LockResource",
  2467. "address": "0x46e28c"
  2468. },
  2469. {
  2470. "name": "LoadResource",
  2471. "address": "0x46e290"
  2472. },
  2473. {
  2474. "name": "LoadLibraryA",
  2475. "address": "0x46e294"
  2476. },
  2477. {
  2478. "name": "LeaveCriticalSection",
  2479. "address": "0x46e298"
  2480. },
  2481. {
  2482. "name": "IsBadWritePtr",
  2483. "address": "0x46e29c"
  2484. },
  2485. {
  2486. "name": "IsBadReadPtr",
  2487. "address": "0x46e2a0"
  2488. },
  2489. {
  2490. "name": "InitializeCriticalSection",
  2491. "address": "0x46e2a4"
  2492. },
  2493. {
  2494. "name": "GlobalUnlock",
  2495. "address": "0x46e2a8"
  2496. },
  2497. {
  2498. "name": "GlobalReAlloc",
  2499. "address": "0x46e2ac"
  2500. },
  2501. {
  2502. "name": "GlobalMemoryStatus",
  2503. "address": "0x46e2b0"
  2504. },
  2505. {
  2506. "name": "GlobalHandle",
  2507. "address": "0x46e2b4"
  2508. },
  2509. {
  2510. "name": "GlobalLock",
  2511. "address": "0x46e2b8"
  2512. },
  2513. {
  2514. "name": "GlobalFree",
  2515. "address": "0x46e2bc"
  2516. },
  2517. {
  2518. "name": "GlobalFindAtomA",
  2519. "address": "0x46e2c0"
  2520. },
  2521. {
  2522. "name": "GlobalDeleteAtom",
  2523. "address": "0x46e2c4"
  2524. },
  2525. {
  2526. "name": "GlobalAlloc",
  2527. "address": "0x46e2c8"
  2528. },
  2529. {
  2530. "name": "GlobalAddAtomA",
  2531. "address": "0x46e2cc"
  2532. },
  2533. {
  2534. "name": "GetVersionExA",
  2535. "address": "0x46e2d0"
  2536. },
  2537. {
  2538. "name": "GetVersion",
  2539. "address": "0x46e2d4"
  2540. },
  2541. {
  2542. "name": "GetTickCount",
  2543. "address": "0x46e2d8"
  2544. },
  2545. {
  2546. "name": "GetThreadLocale",
  2547. "address": "0x46e2dc"
  2548. },
  2549. {
  2550. "name": "GetTempPathA",
  2551. "address": "0x46e2e0"
  2552. },
  2553. {
  2554. "name": "GetTempFileNameA",
  2555. "address": "0x46e2e4"
  2556. },
  2557. {
  2558. "name": "GetSystemInfo",
  2559. "address": "0x46e2e8"
  2560. },
  2561. {
  2562. "name": "GetStringTypeExA",
  2563. "address": "0x46e2ec"
  2564. },
  2565. {
  2566. "name": "GetStdHandle",
  2567. "address": "0x46e2f0"
  2568. },
  2569. {
  2570. "name": "GetProcAddress",
  2571. "address": "0x46e2f4"
  2572. },
  2573. {
  2574. "name": "GetModuleHandleA",
  2575. "address": "0x46e2f8"
  2576. },
  2577. {
  2578. "name": "GetModuleFileNameA",
  2579. "address": "0x46e2fc"
  2580. },
  2581. {
  2582. "name": "GetLocaleInfoA",
  2583. "address": "0x46e300"
  2584. },
  2585. {
  2586. "name": "GetLocalTime",
  2587. "address": "0x46e304"
  2588. },
  2589. {
  2590. "name": "GetLastError",
  2591. "address": "0x46e308"
  2592. },
  2593. {
  2594. "name": "GetFullPathNameA",
  2595. "address": "0x46e30c"
  2596. },
  2597. {
  2598. "name": "GetExitCodeThread",
  2599. "address": "0x46e310"
  2600. },
  2601. {
  2602. "name": "GetDiskFreeSpaceA",
  2603. "address": "0x46e314"
  2604. },
  2605. {
  2606. "name": "GetDateFormatA",
  2607. "address": "0x46e318"
  2608. },
  2609. {
  2610. "name": "GetCurrentThreadId",
  2611. "address": "0x46e31c"
  2612. },
  2613. {
  2614. "name": "GetCurrentProcessId",
  2615. "address": "0x46e320"
  2616. },
  2617. {
  2618. "name": "GetCPInfo",
  2619. "address": "0x46e324"
  2620. },
  2621. {
  2622. "name": "GetACP",
  2623. "address": "0x46e328"
  2624. },
  2625. {
  2626. "name": "FreeResource",
  2627. "address": "0x46e32c"
  2628. },
  2629. {
  2630. "name": "InterlockedIncrement",
  2631. "address": "0x46e330"
  2632. },
  2633. {
  2634. "name": "InterlockedExchange",
  2635. "address": "0x46e334"
  2636. },
  2637. {
  2638. "name": "InterlockedDecrement",
  2639. "address": "0x46e338"
  2640. },
  2641. {
  2642. "name": "FreeLibrary",
  2643. "address": "0x46e33c"
  2644. },
  2645. {
  2646. "name": "FormatMessageA",
  2647. "address": "0x46e340"
  2648. },
  2649. {
  2650. "name": "FindResourceA",
  2651. "address": "0x46e344"
  2652. },
  2653. {
  2654. "name": "ExitProcess",
  2655. "address": "0x46e348"
  2656. },
  2657. {
  2658. "name": "EnumCalendarInfoA",
  2659. "address": "0x46e34c"
  2660. },
  2661. {
  2662. "name": "EnterCriticalSection",
  2663. "address": "0x46e350"
  2664. },
  2665. {
  2666. "name": "DeleteFileA",
  2667. "address": "0x46e354"
  2668. },
  2669. {
  2670. "name": "DeleteCriticalSection",
  2671. "address": "0x46e358"
  2672. },
  2673. {
  2674. "name": "CreateThread",
  2675. "address": "0x46e35c"
  2676. },
  2677. {
  2678. "name": "CreateProcessA",
  2679. "address": "0x46e360"
  2680. },
  2681. {
  2682. "name": "CreateFileA",
  2683. "address": "0x46e364"
  2684. },
  2685. {
  2686. "name": "CreateEventA",
  2687. "address": "0x46e368"
  2688. },
  2689. {
  2690. "name": "CompareStringA",
  2691. "address": "0x46e36c"
  2692. },
  2693. {
  2694. "name": "CloseHandle",
  2695. "address": "0x46e370"
  2696. }
  2697. ],
  2698. "dll": "kernel32.dll"
  2699. },
  2700. {
  2701. "imports": [
  2702. {
  2703. "name": "VerQueryValueA",
  2704. "address": "0x46e378"
  2705. },
  2706. {
  2707. "name": "GetFileVersionInfoSizeA",
  2708. "address": "0x46e37c"
  2709. },
  2710. {
  2711. "name": "GetFileVersionInfoA",
  2712. "address": "0x46e380"
  2713. }
  2714. ],
  2715. "dll": "version.dll"
  2716. },
  2717. {
  2718. "imports": [
  2719. {
  2720. "name": "UnrealizeObject",
  2721. "address": "0x46e388"
  2722. },
  2723. {
  2724. "name": "StretchBlt",
  2725. "address": "0x46e38c"
  2726. },
  2727. {
  2728. "name": "SetWindowOrgEx",
  2729. "address": "0x46e390"
  2730. },
  2731. {
  2732. "name": "SetWinMetaFileBits",
  2733. "address": "0x46e394"
  2734. },
  2735. {
  2736. "name": "SetViewportOrgEx",
  2737. "address": "0x46e398"
  2738. },
  2739. {
  2740. "name": "SetTextColor",
  2741. "address": "0x46e39c"
  2742. },
  2743. {
  2744. "name": "SetStretchBltMode",
  2745. "address": "0x46e3a0"
  2746. },
  2747. {
  2748. "name": "SetROP2",
  2749. "address": "0x46e3a4"
  2750. },
  2751. {
  2752. "name": "SetPixel",
  2753. "address": "0x46e3a8"
  2754. },
  2755. {
  2756. "name": "SetEnhMetaFileBits",
  2757. "address": "0x46e3ac"
  2758. },
  2759. {
  2760. "name": "SetDIBColorTable",
  2761. "address": "0x46e3b0"
  2762. },
  2763. {
  2764. "name": "SetBrushOrgEx",
  2765. "address": "0x46e3b4"
  2766. },
  2767. {
  2768. "name": "SetBkMode",
  2769. "address": "0x46e3b8"
  2770. },
  2771. {
  2772. "name": "SetBkColor",
  2773. "address": "0x46e3bc"
  2774. },
  2775. {
  2776. "name": "SelectPalette",
  2777. "address": "0x46e3c0"
  2778. },
  2779. {
  2780. "name": "SelectObject",
  2781. "address": "0x46e3c4"
  2782. },
  2783. {
  2784. "name": "SaveDC",
  2785. "address": "0x46e3c8"
  2786. },
  2787. {
  2788. "name": "RestoreDC",
  2789. "address": "0x46e3cc"
  2790. },
  2791. {
  2792. "name": "Rectangle",
  2793. "address": "0x46e3d0"
  2794. },
  2795. {
  2796. "name": "RectVisible",
  2797. "address": "0x46e3d4"
  2798. },
  2799. {
  2800. "name": "RealizePalette",
  2801. "address": "0x46e3d8"
  2802. },
  2803. {
  2804. "name": "PlayEnhMetaFile",
  2805. "address": "0x46e3dc"
  2806. },
  2807. {
  2808. "name": "PatBlt",
  2809. "address": "0x46e3e0"
  2810. },
  2811. {
  2812. "name": "MoveToEx",
  2813. "address": "0x46e3e4"
  2814. },
  2815. {
  2816. "name": "MaskBlt",
  2817. "address": "0x46e3e8"
  2818. },
  2819. {
  2820. "name": "LineTo",
  2821. "address": "0x46e3ec"
  2822. },
  2823. {
  2824. "name": "IntersectClipRect",
  2825. "address": "0x46e3f0"
  2826. },
  2827. {
  2828. "name": "GetWindowOrgEx",
  2829. "address": "0x46e3f4"
  2830. },
  2831. {
  2832. "name": "GetWinMetaFileBits",
  2833. "address": "0x46e3f8"
  2834. },
  2835. {
  2836. "name": "GetTextMetricsA",
  2837. "address": "0x46e3fc"
  2838. },
  2839. {
  2840. "name": "GetTextExtentPointA",
  2841. "address": "0x46e400"
  2842. },
  2843. {
  2844. "name": "GetTextExtentPoint32A",
  2845. "address": "0x46e404"
  2846. },
  2847. {
  2848. "name": "GetSystemPaletteEntries",
  2849. "address": "0x46e408"
  2850. },
  2851. {
  2852. "name": "GetStockObject",
  2853. "address": "0x46e40c"
  2854. },
  2855. {
  2856. "name": "GetPixelFormat",
  2857. "address": "0x46e410"
  2858. },
  2859. {
  2860. "name": "GetPixel",
  2861. "address": "0x46e414"
  2862. },
  2863. {
  2864. "name": "GetPaletteEntries",
  2865. "address": "0x46e418"
  2866. },
  2867. {
  2868. "name": "GetObjectA",
  2869. "address": "0x46e41c"
  2870. },
  2871. {
  2872. "name": "GetMapMode",
  2873. "address": "0x46e420"
  2874. },
  2875. {
  2876. "name": "GetEnhMetaFilePaletteEntries",
  2877. "address": "0x46e424"
  2878. },
  2879. {
  2880. "name": "GetEnhMetaFileHeader",
  2881. "address": "0x46e428"
  2882. },
  2883. {
  2884. "name": "GetEnhMetaFileBits",
  2885. "address": "0x46e42c"
  2886. },
  2887. {
  2888. "name": "GetDeviceCaps",
  2889. "address": "0x46e430"
  2890. },
  2891. {
  2892. "name": "GetDIBits",
  2893. "address": "0x46e434"
  2894. },
  2895. {
  2896. "name": "GetDIBColorTable",
  2897. "address": "0x46e438"
  2898. },
  2899. {
  2900. "name": "GetDCOrgEx",
  2901. "address": "0x46e43c"
  2902. },
  2903. {
  2904. "name": "GetCurrentPositionEx",
  2905. "address": "0x46e440"
  2906. },
  2907. {
  2908. "name": "GetClipBox",
  2909. "address": "0x46e444"
  2910. },
  2911. {
  2912. "name": "GetBrushOrgEx",
  2913. "address": "0x46e448"
  2914. },
  2915. {
  2916. "name": "GetBkColor",
  2917. "address": "0x46e44c"
  2918. },
  2919. {
  2920. "name": "GetBitmapBits",
  2921. "address": "0x46e450"
  2922. },
  2923. {
  2924. "name": "ExcludeClipRect",
  2925. "address": "0x46e454"
  2926. },
  2927. {
  2928. "name": "DeleteObject",
  2929. "address": "0x46e458"
  2930. },
  2931. {
  2932. "name": "DeleteEnhMetaFile",
  2933. "address": "0x46e45c"
  2934. },
  2935. {
  2936. "name": "DeleteDC",
  2937. "address": "0x46e460"
  2938. },
  2939. {
  2940. "name": "CreateSolidBrush",
  2941. "address": "0x46e464"
  2942. },
  2943. {
  2944. "name": "CreatePenIndirect",
  2945. "address": "0x46e468"
  2946. },
  2947. {
  2948. "name": "CreatePalette",
  2949. "address": "0x46e46c"
  2950. },
  2951. {
  2952. "name": "CreateHalftonePalette",
  2953. "address": "0x46e470"
  2954. },
  2955. {
  2956. "name": "CreateFontIndirectA",
  2957. "address": "0x46e474"
  2958. },
  2959. {
  2960. "name": "CreateDIBitmap",
  2961. "address": "0x46e478"
  2962. },
  2963. {
  2964. "name": "CreateDIBSection",
  2965. "address": "0x46e47c"
  2966. },
  2967. {
  2968. "name": "CreateCompatibleDC",
  2969. "address": "0x46e480"
  2970. },
  2971. {
  2972. "name": "CreateCompatibleBitmap",
  2973. "address": "0x46e484"
  2974. },
  2975. {
  2976. "name": "CreateBrushIndirect",
  2977. "address": "0x46e488"
  2978. },
  2979. {
  2980. "name": "CreateBitmap",
  2981. "address": "0x46e48c"
  2982. },
  2983. {
  2984. "name": "CopyEnhMetaFileA",
  2985. "address": "0x46e490"
  2986. },
  2987. {
  2988. "name": "BitBlt",
  2989. "address": "0x46e494"
  2990. }
  2991. ],
  2992. "dll": "gdi32.dll"
  2993. },
  2994. {
  2995. "imports": [
  2996. {
  2997. "name": "CreateWindowExA",
  2998. "address": "0x46e49c"
  2999. },
  3000. {
  3001. "name": "WindowFromPoint",
  3002. "address": "0x46e4a0"
  3003. },
  3004. {
  3005. "name": "WinHelpA",
  3006. "address": "0x46e4a4"
  3007. },
  3008. {
  3009. "name": "WaitMessage",
  3010. "address": "0x46e4a8"
  3011. },
  3012. {
  3013. "name": "UpdateWindow",
  3014. "address": "0x46e4ac"
  3015. },
  3016. {
  3017. "name": "UnregisterClassA",
  3018. "address": "0x46e4b0"
  3019. },
  3020. {
  3021. "name": "UnhookWindowsHookEx",
  3022. "address": "0x46e4b4"
  3023. },
  3024. {
  3025. "name": "TranslateMessage",
  3026. "address": "0x46e4b8"
  3027. },
  3028. {
  3029. "name": "TranslateMDISysAccel",
  3030. "address": "0x46e4bc"
  3031. },
  3032. {
  3033. "name": "TrackPopupMenu",
  3034. "address": "0x46e4c0"
  3035. },
  3036. {
  3037. "name": "SystemParametersInfoA",
  3038. "address": "0x46e4c4"
  3039. },
  3040. {
  3041. "name": "ShowWindow",
  3042. "address": "0x46e4c8"
  3043. },
  3044. {
  3045. "name": "ShowScrollBar",
  3046. "address": "0x46e4cc"
  3047. },
  3048. {
  3049. "name": "ShowOwnedPopups",
  3050. "address": "0x46e4d0"
  3051. },
  3052. {
  3053. "name": "ShowCursor",
  3054. "address": "0x46e4d4"
  3055. },
  3056. {
  3057. "name": "SetWindowsHookExA",
  3058. "address": "0x46e4d8"
  3059. },
  3060. {
  3061. "name": "SetWindowTextA",
  3062. "address": "0x46e4dc"
  3063. },
  3064. {
  3065. "name": "SetWindowPos",
  3066. "address": "0x46e4e0"
  3067. },
  3068. {
  3069. "name": "SetWindowPlacement",
  3070. "address": "0x46e4e4"
  3071. },
  3072. {
  3073. "name": "SetWindowLongA",
  3074. "address": "0x46e4e8"
  3075. },
  3076. {
  3077. "name": "SetTimer",
  3078. "address": "0x46e4ec"
  3079. },
  3080. {
  3081. "name": "SetScrollRange",
  3082. "address": "0x46e4f0"
  3083. },
  3084. {
  3085. "name": "SetScrollPos",
  3086. "address": "0x46e4f4"
  3087. },
  3088. {
  3089. "name": "SetScrollInfo",
  3090. "address": "0x46e4f8"
  3091. },
  3092. {
  3093. "name": "SetRect",
  3094. "address": "0x46e4fc"
  3095. },
  3096. {
  3097. "name": "SetPropA",
  3098. "address": "0x46e500"
  3099. },
  3100. {
  3101. "name": "SetParent",
  3102. "address": "0x46e504"
  3103. },
  3104. {
  3105. "name": "SetMenuItemInfoA",
  3106. "address": "0x46e508"
  3107. },
  3108. {
  3109. "name": "SetMenu",
  3110. "address": "0x46e50c"
  3111. },
  3112. {
  3113. "name": "SetForegroundWindow",
  3114. "address": "0x46e510"
  3115. },
  3116. {
  3117. "name": "SetFocus",
  3118. "address": "0x46e514"
  3119. },
  3120. {
  3121. "name": "SetCursor",
  3122. "address": "0x46e518"
  3123. },
  3124. {
  3125. "name": "SetClipboardData",
  3126. "address": "0x46e51c"
  3127. },
  3128. {
  3129. "name": "SetClassLongA",
  3130. "address": "0x46e520"
  3131. },
  3132. {
  3133. "name": "SetCapture",
  3134. "address": "0x46e524"
  3135. },
  3136. {
  3137. "name": "SetActiveWindow",
  3138. "address": "0x46e528"
  3139. },
  3140. {
  3141. "name": "SendMessageA",
  3142. "address": "0x46e52c"
  3143. },
  3144. {
  3145. "name": "ScrollWindow",
  3146. "address": "0x46e530"
  3147. },
  3148. {
  3149. "name": "ScreenToClient",
  3150. "address": "0x46e534"
  3151. },
  3152. {
  3153. "name": "RemovePropA",
  3154. "address": "0x46e538"
  3155. },
  3156. {
  3157. "name": "RemoveMenu",
  3158. "address": "0x46e53c"
  3159. },
  3160. {
  3161. "name": "ReleaseDC",
  3162. "address": "0x46e540"
  3163. },
  3164. {
  3165. "name": "ReleaseCapture",
  3166. "address": "0x46e544"
  3167. },
  3168. {
  3169. "name": "RegisterWindowMessageA",
  3170. "address": "0x46e548"
  3171. },
  3172. {
  3173. "name": "RegisterClipboardFormatA",
  3174. "address": "0x46e54c"
  3175. },
  3176. {
  3177. "name": "RegisterClassA",
  3178. "address": "0x46e550"
  3179. },
  3180. {
  3181. "name": "RedrawWindow",
  3182. "address": "0x46e554"
  3183. },
  3184. {
  3185. "name": "PtInRect",
  3186. "address": "0x46e558"
  3187. },
  3188. {
  3189. "name": "PostQuitMessage",
  3190. "address": "0x46e55c"
  3191. },
  3192. {
  3193. "name": "PostMessageA",
  3194. "address": "0x46e560"
  3195. },
  3196. {
  3197. "name": "PeekMessageA",
  3198. "address": "0x46e564"
  3199. },
  3200. {
  3201. "name": "OpenClipboard",
  3202. "address": "0x46e568"
  3203. },
  3204. {
  3205. "name": "OffsetRect",
  3206. "address": "0x46e56c"
  3207. },
  3208. {
  3209. "name": "OemToCharA",
  3210. "address": "0x46e570"
  3211. },
  3212. {
  3213. "name": "MsgWaitForMultipleObjects",
  3214. "address": "0x46e574"
  3215. },
  3216. {
  3217. "name": "MessageBoxA",
  3218. "address": "0x46e578"
  3219. },
  3220. {
  3221. "name": "MessageBeep",
  3222. "address": "0x46e57c"
  3223. },
  3224. {
  3225. "name": "MapWindowPoints",
  3226. "address": "0x46e580"
  3227. },
  3228. {
  3229. "name": "MapVirtualKeyA",
  3230. "address": "0x46e584"
  3231. },
  3232. {
  3233. "name": "LoadStringA",
  3234. "address": "0x46e588"
  3235. },
  3236. {
  3237. "name": "LoadKeyboardLayoutA",
  3238. "address": "0x46e58c"
  3239. },
  3240. {
  3241. "name": "LoadIconA",
  3242. "address": "0x46e590"
  3243. },
  3244. {
  3245. "name": "LoadCursorA",
  3246. "address": "0x46e594"
  3247. },
  3248. {
  3249. "name": "LoadBitmapA",
  3250. "address": "0x46e598"
  3251. },
  3252. {
  3253. "name": "KillTimer",
  3254. "address": "0x46e59c"
  3255. },
  3256. {
  3257. "name": "IsZoomed",
  3258. "address": "0x46e5a0"
  3259. },
  3260. {
  3261. "name": "IsWindowVisible",
  3262. "address": "0x46e5a4"
  3263. },
  3264. {
  3265. "name": "IsWindowEnabled",
  3266. "address": "0x46e5a8"
  3267. },
  3268. {
  3269. "name": "IsWindow",
  3270. "address": "0x46e5ac"
  3271. },
  3272. {
  3273. "name": "IsRectEmpty",
  3274. "address": "0x46e5b0"
  3275. },
  3276. {
  3277. "name": "IsIconic",
  3278. "address": "0x46e5b4"
  3279. },
  3280. {
  3281. "name": "IsDialogMessageA",
  3282. "address": "0x46e5b8"
  3283. },
  3284. {
  3285. "name": "IsChild",
  3286. "address": "0x46e5bc"
  3287. },
  3288. {
  3289. "name": "InvalidateRect",
  3290. "address": "0x46e5c0"
  3291. },
  3292. {
  3293. "name": "IntersectRect",
  3294. "address": "0x46e5c4"
  3295. },
  3296. {
  3297. "name": "InsertMenuItemA",
  3298. "address": "0x46e5c8"
  3299. },
  3300. {
  3301. "name": "InsertMenuA",
  3302. "address": "0x46e5cc"
  3303. },
  3304. {
  3305. "name": "InflateRect",
  3306. "address": "0x46e5d0"
  3307. },
  3308. {
  3309. "name": "GetWindowThreadProcessId",
  3310. "address": "0x46e5d4"
  3311. },
  3312. {
  3313. "name": "GetWindowTextA",
  3314. "address": "0x46e5d8"
  3315. },
  3316. {
  3317. "name": "GetWindowRect",
  3318. "address": "0x46e5dc"
  3319. },
  3320. {
  3321. "name": "GetWindowPlacement",
  3322. "address": "0x46e5e0"
  3323. },
  3324. {
  3325. "name": "GetWindowLongA",
  3326. "address": "0x46e5e4"
  3327. },
  3328. {
  3329. "name": "GetWindowDC",
  3330. "address": "0x46e5e8"
  3331. },
  3332. {
  3333. "name": "GetTopWindow",
  3334. "address": "0x46e5ec"
  3335. },
  3336. {
  3337. "name": "GetSystemMetrics",
  3338. "address": "0x46e5f0"
  3339. },
  3340. {
  3341. "name": "GetSystemMenu",
  3342. "address": "0x46e5f4"
  3343. },
  3344. {
  3345. "name": "GetSysColorBrush",
  3346. "address": "0x46e5f8"
  3347. },
  3348. {
  3349. "name": "GetSysColor",
  3350. "address": "0x46e5fc"
  3351. },
  3352. {
  3353. "name": "GetSubMenu",
  3354. "address": "0x46e600"
  3355. },
  3356. {
  3357. "name": "GetScrollRange",
  3358. "address": "0x46e604"
  3359. },
  3360. {
  3361. "name": "GetScrollPos",
  3362. "address": "0x46e608"
  3363. },
  3364. {
  3365. "name": "GetScrollInfo",
  3366. "address": "0x46e60c"
  3367. },
  3368. {
  3369. "name": "GetPropA",
  3370. "address": "0x46e610"
  3371. },
  3372. {
  3373. "name": "GetParent",
  3374. "address": "0x46e614"
  3375. },
  3376. {
  3377. "name": "GetWindow",
  3378. "address": "0x46e618"
  3379. },
  3380. {
  3381. "name": "GetMenuStringA",
  3382. "address": "0x46e61c"
  3383. },
  3384. {
  3385. "name": "GetMenuState",
  3386. "address": "0x46e620"
  3387. },
  3388. {
  3389. "name": "GetMenuItemInfoA",
  3390. "address": "0x46e624"
  3391. },
  3392. {
  3393. "name": "GetMenuItemID",
  3394. "address": "0x46e628"
  3395. },
  3396. {
  3397. "name": "GetMenuItemCount",
  3398. "address": "0x46e62c"
  3399. },
  3400. {
  3401. "name": "GetMenu",
  3402. "address": "0x46e630"
  3403. },
  3404. {
  3405. "name": "GetLastActivePopup",
  3406. "address": "0x46e634"
  3407. },
  3408. {
  3409. "name": "GetKeyboardState",
  3410. "address": "0x46e638"
  3411. },
  3412. {
  3413. "name": "GetKeyboardLayoutList",
  3414. "address": "0x46e63c"
  3415. },
  3416. {
  3417. "name": "GetKeyboardLayout",
  3418. "address": "0x46e640"
  3419. },
  3420. {
  3421. "name": "GetKeyState",
  3422. "address": "0x46e644"
  3423. },
  3424. {
  3425. "name": "GetKeyNameTextA",
  3426. "address": "0x46e648"
  3427. },
  3428. {
  3429. "name": "GetIconInfo",
  3430. "address": "0x46e64c"
  3431. },
  3432. {
  3433. "name": "GetForegroundWindow",
  3434. "address": "0x46e650"
  3435. },
  3436. {
  3437. "name": "GetFocus",
  3438. "address": "0x46e654"
  3439. },
  3440. {
  3441. "name": "GetDlgItem",
  3442. "address": "0x46e658"
  3443. },
  3444. {
  3445. "name": "GetDesktopWindow",
  3446. "address": "0x46e65c"
  3447. },
  3448. {
  3449. "name": "GetDCEx",
  3450. "address": "0x46e660"
  3451. },
  3452. {
  3453. "name": "GetDC",
  3454. "address": "0x46e664"
  3455. },
  3456. {
  3457. "name": "GetCursorPos",
  3458. "address": "0x46e668"
  3459. },
  3460. {
  3461. "name": "GetCursor",
  3462. "address": "0x46e66c"
  3463. },
  3464. {
  3465. "name": "GetClipboardData",
  3466. "address": "0x46e670"
  3467. },
  3468. {
  3469. "name": "GetClientRect",
  3470. "address": "0x46e674"
  3471. },
  3472. {
  3473. "name": "GetClassNameA",
  3474. "address": "0x46e678"
  3475. },
  3476. {
  3477. "name": "GetClassInfoA",
  3478. "address": "0x46e67c"
  3479. },
  3480. {
  3481. "name": "GetCapture",
  3482. "address": "0x46e680"
  3483. },
  3484. {
  3485. "name": "GetActiveWindow",
  3486. "address": "0x46e684"
  3487. },
  3488. {
  3489. "name": "FrameRect",
  3490. "address": "0x46e688"
  3491. },
  3492. {
  3493. "name": "FindWindowA",
  3494. "address": "0x46e68c"
  3495. },
  3496. {
  3497. "name": "FillRect",
  3498. "address": "0x46e690"
  3499. },
  3500. {
  3501. "name": "EqualRect",
  3502. "address": "0x46e694"
  3503. },
  3504. {
  3505. "name": "EnumWindows",
  3506. "address": "0x46e698"
  3507. },
  3508. {
  3509. "name": "EnumThreadWindows",
  3510. "address": "0x46e69c"
  3511. },
  3512. {
  3513. "name": "EndPaint",
  3514. "address": "0x46e6a0"
  3515. },
  3516. {
  3517. "name": "EnableWindow",
  3518. "address": "0x46e6a4"
  3519. },
  3520. {
  3521. "name": "EnableScrollBar",
  3522. "address": "0x46e6a8"
  3523. },
  3524. {
  3525. "name": "EnableMenuItem",
  3526. "address": "0x46e6ac"
  3527. },
  3528. {
  3529. "name": "EmptyClipboard",
  3530. "address": "0x46e6b0"
  3531. },
  3532. {
  3533. "name": "DrawTextA",
  3534. "address": "0x46e6b4"
  3535. },
  3536. {
  3537. "name": "DrawMenuBar",
  3538. "address": "0x46e6b8"
  3539. },
  3540. {
  3541. "name": "DrawIconEx",
  3542. "address": "0x46e6bc"
  3543. },
  3544. {
  3545. "name": "DrawIcon",
  3546. "address": "0x46e6c0"
  3547. },
  3548. {
  3549. "name": "DrawFrameControl",
  3550. "address": "0x46e6c4"
  3551. },
  3552. {
  3553. "name": "DrawFocusRect",
  3554. "address": "0x46e6c8"
  3555. },
  3556. {
  3557. "name": "DrawEdge",
  3558. "address": "0x46e6cc"
  3559. },
  3560. {
  3561. "name": "DispatchMessageA",
  3562. "address": "0x46e6d0"
  3563. },
  3564. {
  3565. "name": "DestroyWindow",
  3566. "address": "0x46e6d4"
  3567. },
  3568. {
  3569. "name": "DestroyMenu",
  3570. "address": "0x46e6d8"
  3571. },
  3572. {
  3573. "name": "DestroyIcon",
  3574. "address": "0x46e6dc"
  3575. },
  3576. {
  3577. "name": "DestroyCursor",
  3578. "address": "0x46e6e0"
  3579. },
  3580. {
  3581. "name": "DeleteMenu",
  3582. "address": "0x46e6e4"
  3583. },
  3584. {
  3585. "name": "DefWindowProcA",
  3586. "address": "0x46e6e8"
  3587. },
  3588. {
  3589. "name": "DefMDIChildProcA",
  3590. "address": "0x46e6ec"
  3591. },
  3592. {
  3593. "name": "DefFrameProcA",
  3594. "address": "0x46e6f0"
  3595. },
  3596. {
  3597. "name": "CreatePopupMenu",
  3598. "address": "0x46e6f4"
  3599. },
  3600. {
  3601. "name": "CreateMenu",
  3602. "address": "0x46e6f8"
  3603. },
  3604. {
  3605. "name": "CreateIcon",
  3606. "address": "0x46e6fc"
  3607. },
  3608. {
  3609. "name": "CloseClipboard",
  3610. "address": "0x46e700"
  3611. },
  3612. {
  3613. "name": "ClientToScreen",
  3614. "address": "0x46e704"
  3615. },
  3616. {
  3617. "name": "CheckMenuItem",
  3618. "address": "0x46e708"
  3619. },
  3620. {
  3621. "name": "CallWindowProcA",
  3622. "address": "0x46e70c"
  3623. },
  3624. {
  3625. "name": "CallNextHookEx",
  3626. "address": "0x46e710"
  3627. },
  3628. {
  3629. "name": "BeginPaint",
  3630. "address": "0x46e714"
  3631. },
  3632. {
  3633. "name": "CharNextA",
  3634. "address": "0x46e718"
  3635. },
  3636. {
  3637. "name": "CharLowerBuffA",
  3638. "address": "0x46e71c"
  3639. },
  3640. {
  3641. "name": "CharLowerA",
  3642. "address": "0x46e720"
  3643. },
  3644. {
  3645. "name": "CharUpperBuffA",
  3646. "address": "0x46e724"
  3647. },
  3648. {
  3649. "name": "CharToOemA",
  3650. "address": "0x46e728"
  3651. },
  3652. {
  3653. "name": "AdjustWindowRectEx",
  3654. "address": "0x46e72c"
  3655. },
  3656. {
  3657. "name": "ActivateKeyboardLayout",
  3658. "address": "0x46e730"
  3659. }
  3660. ],
  3661. "dll": "user32.dll"
  3662. },
  3663. {
  3664. "imports": [
  3665. {
  3666. "name": "Sleep",
  3667. "address": "0x46e738"
  3668. }
  3669. ],
  3670. "dll": "kernel32.dll"
  3671. },
  3672. {
  3673. "imports": [
  3674. {
  3675. "name": "SafeArrayPtrOfIndex",
  3676. "address": "0x46e740"
  3677. },
  3678. {
  3679. "name": "SafeArrayGetUBound",
  3680. "address": "0x46e744"
  3681. },
  3682. {
  3683. "name": "SafeArrayGetLBound",
  3684. "address": "0x46e748"
  3685. },
  3686. {
  3687. "name": "SafeArrayCreate",
  3688. "address": "0x46e74c"
  3689. },
  3690. {
  3691. "name": "VariantChangeType",
  3692. "address": "0x46e750"
  3693. },
  3694. {
  3695. "name": "VariantCopy",
  3696. "address": "0x46e754"
  3697. },
  3698. {
  3699. "name": "VariantClear",
  3700. "address": "0x46e758"
  3701. },
  3702. {
  3703. "name": "VariantInit",
  3704. "address": "0x46e75c"
  3705. }
  3706. ],
  3707. "dll": "oleaut32.dll"
  3708. },
  3709. {
  3710. "imports": [
  3711. {
  3712. "name": "ImageList_SetIconSize",
  3713. "address": "0x46e764"
  3714. },
  3715. {
  3716. "name": "ImageList_GetIconSize",
  3717. "address": "0x46e768"
  3718. },
  3719. {
  3720. "name": "ImageList_Write",
  3721. "address": "0x46e76c"
  3722. },
  3723. {
  3724. "name": "ImageList_Read",
  3725. "address": "0x46e770"
  3726. },
  3727. {
  3728. "name": "ImageList_GetDragImage",
  3729. "address": "0x46e774"
  3730. },
  3731. {
  3732. "name": "ImageList_DragShowNolock",
  3733. "address": "0x46e778"
  3734. },
  3735. {
  3736. "name": "ImageList_SetDragCursorImage",
  3737. "address": "0x46e77c"
  3738. },
  3739. {
  3740. "name": "ImageList_DragMove",
  3741. "address": "0x46e780"
  3742. },
  3743. {
  3744. "name": "ImageList_DragLeave",
  3745. "address": "0x46e784"
  3746. },
  3747. {
  3748. "name": "ImageList_DragEnter",
  3749. "address": "0x46e788"
  3750. },
  3751. {
  3752. "name": "ImageList_EndDrag",
  3753. "address": "0x46e78c"
  3754. },
  3755. {
  3756. "name": "ImageList_BeginDrag",
  3757. "address": "0x46e790"
  3758. },
  3759. {
  3760. "name": "ImageList_Remove",
  3761. "address": "0x46e794"
  3762. },
  3763. {
  3764. "name": "ImageList_DrawEx",
  3765. "address": "0x46e798"
  3766. },
  3767. {
  3768. "name": "ImageList_Replace",
  3769. "address": "0x46e79c"
  3770. },
  3771. {
  3772. "name": "ImageList_Draw",
  3773. "address": "0x46e7a0"
  3774. },
  3775. {
  3776. "name": "ImageList_GetBkColor",
  3777. "address": "0x46e7a4"
  3778. },
  3779. {
  3780. "name": "ImageList_SetBkColor",
  3781. "address": "0x46e7a8"
  3782. },
  3783. {
  3784. "name": "ImageList_ReplaceIcon",
  3785. "address": "0x46e7ac"
  3786. },
  3787. {
  3788. "name": "ImageList_Add",
  3789. "address": "0x46e7b0"
  3790. },
  3791. {
  3792. "name": "ImageList_SetImageCount",
  3793. "address": "0x46e7b4"
  3794. },
  3795. {
  3796. "name": "ImageList_GetImageCount",
  3797. "address": "0x46e7b8"
  3798. },
  3799. {
  3800. "name": "ImageList_Destroy",
  3801. "address": "0x46e7bc"
  3802. },
  3803. {
  3804. "name": "ImageList_Create",
  3805. "address": "0x46e7c0"
  3806. }
  3807. ],
  3808. "dll": "comctl32.dll"
  3809. },
  3810. {
  3811. "imports": [
  3812. {
  3813. "name": "GetOpenFileNameA",
  3814. "address": "0x46e7c8"
  3815. }
  3816. ],
  3817. "dll": "comdlg32.dll"
  3818. },
  3819. {
  3820. "imports": [
  3821. {
  3822. "name": "WSACleanup",
  3823. "address": "0x46e7d0"
  3824. },
  3825. {
  3826. "name": "WSAStartup",
  3827. "address": "0x46e7d4"
  3828. },
  3829. {
  3830. "name": "WSAGetLastError",
  3831. "address": "0x46e7d8"
  3832. },
  3833. {
  3834. "name": "WSAAsyncGetHostByName",
  3835. "address": "0x46e7dc"
  3836. },
  3837. {
  3838. "name": "WSAAsyncSelect",
  3839. "address": "0x46e7e0"
  3840. },
  3841. {
  3842. "name": "socket",
  3843. "address": "0x46e7e4"
  3844. },
  3845. {
  3846. "name": "setsockopt",
  3847. "address": "0x46e7e8"
  3848. },
  3849. {
  3850. "name": "send",
  3851. "address": "0x46e7ec"
  3852. },
  3853. {
  3854. "name": "recv",
  3855. "address": "0x46e7f0"
  3856. },
  3857. {
  3858. "name": "inet_addr",
  3859. "address": "0x46e7f4"
  3860. },
  3861. {
  3862. "name": "htons",
  3863. "address": "0x46e7f8"
  3864. },
  3865. {
  3866. "name": "connect",
  3867. "address": "0x46e7fc"
  3868. },
  3869. {
  3870. "name": "closesocket",
  3871. "address": "0x46e800"
  3872. },
  3873. {
  3874. "name": "accept",
  3875. "address": "0x46e804"
  3876. }
  3877. ],
  3878. "dll": "wsock32.dll"
  3879. }
  3880. ],
  3881. "digital_signers": null,
  3882. "exported_dll_name": null,
  3883. "actual_checksum": "0x0015ecfd",
  3884. "overlay": {
  3885. "size": "0x0009b7c8",
  3886. "offset": "0x000c0c00"
  3887. },
  3888. "imagebase": "0x00400000",
  3889. "reported_checksum": "0x000d0b4d",
  3890. "icon_hash": null,
  3891. "entrypoint": "0x00469844",
  3892. "timestamp": "1992-06-19 22:22:17",
  3893. "osversion": "4.0",
  3894. "sections": [
  3895. {
  3896. "name": "CODE",
  3897. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
  3898. "virtual_address": "0x00001000",
  3899. "size_of_data": "0x00068a00",
  3900. "entropy": "6.51",
  3901. "raw_address": "0x00000400",
  3902. "virtual_size": "0x000688b8",
  3903. "characteristics_raw": "0x60000020"
  3904. },
  3905. {
  3906. "name": "DATA",
  3907. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  3908. "virtual_address": "0x0006a000",
  3909. "size_of_data": "0x00002000",
  3910. "entropy": "4.12",
  3911. "raw_address": "0x00068e00",
  3912. "virtual_size": "0x00001f0c",
  3913. "characteristics_raw": "0xc0000040"
  3914. },
  3915. {
  3916. "name": "BSS",
  3917. "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  3918. "virtual_address": "0x0006c000",
  3919. "size_of_data": "0x00000000",
  3920. "entropy": "0.00",
  3921. "raw_address": "0x0006ae00",
  3922. "virtual_size": "0x000010b9",
  3923. "characteristics_raw": "0xc0000000"
  3924. },
  3925. {
  3926. "name": ".idata",
  3927. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  3928. "virtual_address": "0x0006e000",
  3929. "size_of_data": "0x00002600",
  3930. "entropy": "4.97",
  3931. "raw_address": "0x0006ae00",
  3932. "virtual_size": "0x000024d4",
  3933. "characteristics_raw": "0xc0000040"
  3934. },
  3935. {
  3936. "name": ".tls",
  3937. "characteristics": "IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  3938. "virtual_address": "0x00071000",
  3939. "size_of_data": "0x00000000",
  3940. "entropy": "0.00",
  3941. "raw_address": "0x0006d400",
  3942. "virtual_size": "0x00000010",
  3943. "characteristics_raw": "0xc0000000"
  3944. },
  3945. {
  3946. "name": ".rdata",
  3947. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
  3948. "virtual_address": "0x00072000",
  3949. "size_of_data": "0x00000200",
  3950. "entropy": "0.20",
  3951. "raw_address": "0x0006d400",
  3952. "virtual_size": "0x00000018",
  3953. "characteristics_raw": "0x50000040"
  3954. },
  3955. {
  3956. "name": ".reloc",
  3957. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
  3958. "virtual_address": "0x00073000",
  3959. "size_of_data": "0x00007c00",
  3960. "entropy": "6.65",
  3961. "raw_address": "0x0006d600",
  3962. "virtual_size": "0x00007adc",
  3963. "characteristics_raw": "0x50000040"
  3964. },
  3965. {
  3966. "name": ".rsrc",
  3967. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ",
  3968. "virtual_address": "0x0007b000",
  3969. "size_of_data": "0x0004ba00",
  3970. "entropy": "5.80",
  3971. "raw_address": "0x00075200",
  3972. "virtual_size": "0x0004b9ac",
  3973. "characteristics_raw": "0x50000040"
  3974. }
  3975. ],
  3976. "resources": [],
  3977. "dirents": [
  3978. {
  3979. "virtual_address": "0x00000000",
  3980. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  3981. "size": "0x00000000"
  3982. },
  3983. {
  3984. "virtual_address": "0x0006e000",
  3985. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  3986. "size": "0x000024d4"
  3987. },
  3988. {
  3989. "virtual_address": "0x0007b000",
  3990. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  3991. "size": "0x0004b9ac"
  3992. },
  3993. {
  3994. "virtual_address": "0x00000000",
  3995. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  3996. "size": "0x00000000"
  3997. },
  3998. {
  3999. "virtual_address": "0x00000000",
  4000. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  4001. "size": "0x00000000"
  4002. },
  4003. {
  4004. "virtual_address": "0x00073000",
  4005. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  4006. "size": "0x00007adc"
  4007. },
  4008. {
  4009. "virtual_address": "0x00000000",
  4010. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  4011. "size": "0x00000000"
  4012. },
  4013. {
  4014. "virtual_address": "0x00000000",
  4015. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  4016. "size": "0x00000000"
  4017. },
  4018. {
  4019. "virtual_address": "0x00000000",
  4020. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  4021. "size": "0x00000000"
  4022. },
  4023. {
  4024. "virtual_address": "0x00072000",
  4025. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  4026. "size": "0x00000018"
  4027. },
  4028. {
  4029. "virtual_address": "0x00000000",
  4030. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  4031. "size": "0x00000000"
  4032. },
  4033. {
  4034. "virtual_address": "0x00000000",
  4035. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  4036. "size": "0x00000000"
  4037. },
  4038. {
  4039. "virtual_address": "0x00000000",
  4040. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  4041. "size": "0x00000000"
  4042. },
  4043. {
  4044. "virtual_address": "0x00000000",
  4045. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  4046. "size": "0x00000000"
  4047. },
  4048. {
  4049. "virtual_address": "0x00000000",
  4050. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  4051. "size": "0x00000000"
  4052. },
  4053. {
  4054. "virtual_address": "0x00000000",
  4055. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  4056. "size": "0x00000000"
  4057. }
  4058. ],
  4059. "exports": [],
  4060. "guest_signers": {},
  4061. "imphash": "5ae4cca98b2f15124dd50272f7881db7",
  4062. "icon_fuzzy": null,
  4063. "icon": null,
  4064. "pdbpath": null,
  4065. "imported_dll_count": 15,
  4066. "versioninfo": []
  4067. }
  4068. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement