Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: ""
- [*] MalScore: 10.0
- [*] File Name: "Exes_e7951257.exe"
- [*] File Size: 501760
- [*] File Type: "PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows"
- [*] SHA256: "be9940c6090d4b0d30f98fd46c555e9c905a72d653015cd37847acaea31cd4e9"
- [*] MD5: "d997ce6a8c9166225f43dbc990136011"
- [*] SHA1: "178cb1974c75aed9d31aefd9d8db4a7b536e2abf"
- [*] SHA512: "527b57050e42ac7805eb00f23e0b6f4a6184e0a7cf6e1f461ba35c80a16f4b1465f20ea9a7b4667eec40772c8a4c89c795551f4cb4a6114390a9f1cd0998fe8f"
- [*] CRC32: "E7951257"
- [*] SSDEEP: "12288:lmeHu196U0eCmytWEJH2sSLF9tQG0fYQtWuotPq:TM96U0eCXoEJH2sSLFDQGSYlty"
- [*] Process Execution: [
- "Exes_e7951257.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details": [
- {
- "section": "name: .rsrc, entropy: 7.45, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x00053600, virtual_size: 0x00053434"
- }
- ]
- },
- {
- "Description": "Anomalous .NET characteristics",
- "Details": [
- {
- "anomalous_version": "Assembly version is set to 0"
- }
- ]
- },
- {
- "Description": "File has been identified by 37 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "MicroWorld-eScan": "Trojan.GenericKD.32055675"
- },
- {
- "McAfee": "RDN/Generic BackDoor"
- },
- {
- "Cylance": "Unsafe"
- },
- {
- "AegisLab": "Trojan.MSIL.NanoBot.4!c"
- },
- {
- "Alibaba": "Trojan:MSIL/Kryptik.c2064829"
- },
- {
- "K7GW": "Trojan ( 0054ef891 )"
- },
- {
- "Symantec": "ML.Attribute.HighConfidence"
- },
- {
- "ESET-NOD32": "a variant of MSIL/Kryptik.RUC"
- },
- {
- "APEX": "Malicious"
- },
- {
- "Paloalto": "generic.ml"
- },
- {
- "GData": "Win32.Trojan-Stealer.FormBook.8EYNBH"
- },
- {
- "Kaspersky": "HEUR:Backdoor.MSIL.NanoBot.gen"
- },
- {
- "BitDefender": "Trojan.GenericKD.32055675"
- },
- {
- "Avast": "FileRepMalware"
- },
- {
- "Ad-Aware": "Trojan.GenericKD.32055675"
- },
- {
- "Sophos": "Mal/Generic-S"
- },
- {
- "F-Secure": "Trojan.TR/Kryptik.jjbaj"
- },
- {
- "DrWeb": "Trojan.PWS.Spy.21275"
- },
- {
- "Invincea": "heuristic"
- },
- {
- "McAfee-GW-Edition": "BehavesLike.Win32.Generic.gh"
- },
- {
- "FireEye": "Generic.mg.d997ce6a8c916622"
- },
- {
- "Emsisoft": "Trojan.Crypt (A)"
- },
- {
- "Cyren": "W32/Trojan.QVHM-1523"
- },
- {
- "Endgame": "malicious (high confidence)"
- },
- {
- "Avira": "TR/Kryptik.jjbaj"
- },
- {
- "Microsoft": "Trojan:Win32/Tiggre!plock"
- },
- {
- "ZoneAlarm": "HEUR:Backdoor.MSIL.NanoBot.gen"
- },
- {
- "Acronis": "suspicious"
- },
- {
- "ALYac": "Backdoor.Agent.NanoBot.Gen"
- },
- {
- "TrendMicro-HouseCall": "TROJ_GEN.R002H0DFD19"
- },
- {
- "Rising": "Backdoor.NanoBot!8.28C (CLOUD)"
- },
- {
- "Ikarus": "Trojan.Inject"
- },
- {
- "Fortinet": "MSIL/Kryptik.RUC!tr"
- },
- {
- "AVG": "FileRepMalware"
- },
- {
- "Cybereason": "malicious.74c75a"
- },
- {
- "CrowdStrike": "win/malicious_confidence_100% (W)"
- },
- {
- "Qihoo-360": "Win32/Backdoor.BO.5c9"
- }
- ]
- }
- ]
- [*] Started Service: []
- [*] Executed Commands: []
- [*] Mutexes: []
- [*] Modified Files: []
- [*] Deleted Files: []
- [*] Modified Registry Keys: []
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "dotnet": {
- "customattrs": [
- {
- "type": "TypeDef",
- "name": "[mscorlib]System.Reflection.DefaultMemberAttribute",
- "value": "It"
- },
- {
- "type": "TypeDef",
- "name": "[mscorlib]System.Reflection.DefaultMemberAttribute",
- "value": "It"
- }
- ],
- "assemblyinfo": {
- "version": "0.0.0.0",
- "name": "gmVyOXfzhWMQdivjma"
- },
- "assemblyrefs": [
- {
- "version": "4.0.0.0",
- "name": "mscorlib"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Web"
- },
- {
- "version": "4.0.0.0",
- "name": "System"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Core"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Configuration"
- }
- ],
- "typerefs": [
- {
- "typename": "System.CodeDom.Compiler.CodeDomProvider",
- "assembly": "System"
- },
- {
- "typename": "System.Collections.Specialized.NameObjectCollectionBase",
- "assembly": "System"
- },
- {
- "typename": "System.Collections.Specialized.NameValueCollection",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.EditorBrowsableAttribute",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.EditorBrowsableState",
- "assembly": "System"
- },
- {
- "typename": "System.Net.Cookie",
- "assembly": "System"
- },
- {
- "typename": "System.Uri",
- "assembly": "System"
- },
- {
- "typename": "System.Configuration.ConfigurationElementCollection",
- "assembly": "System.Configuration"
- },
- {
- "typename": "System.Linq.Enumerable",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.Expressions.BinaryExpression",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.Expressions.Expression",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.Expressions.Expression`1",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.Expressions.MemberExpression",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.Expressions.MethodCallExpression",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.Expressions.ParameterExpression",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.Expressions.UnaryExpression",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Web.ApplicationShutdownReason",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.Compilation.BuildManager",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.Configuration.HttpModuleAction",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.Configuration.HttpModuleActionCollection",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.Configuration.HttpModulesSection",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.HttpApplication",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.HttpContext",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.HttpModuleCollection",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.HttpRequest",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.HttpRuntime",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.HttpServerUtility",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.IHttpModule",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.Util.RequestValidationSource",
- "assembly": "System.Web"
- },
- {
- "typename": "Microsoft.Win32.Registry",
- "assembly": "mscorlib"
- },
- {
- "typename": "Microsoft.Win32.RegistryKey",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Action",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Action`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Action`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Action`3",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.AppDomain",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ArgumentException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ArgumentNullException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Array",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.AsyncCallback",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Boolean",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.ArrayList",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.DictionaryEntry",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.IEnumerable`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.List`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.List`1/Enumerator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Hashtable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.ICollection",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IDictionary",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IDictionaryEnumerator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IEnumerable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IEnumerator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IEqualityComparer",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IList",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Converter`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Delegate",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggableAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggableAttribute/DebuggingModes",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Enum",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`3",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.CultureInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Guid",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IAsyncResult",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IDisposable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IFormatProvider",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Int32",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IntPtr",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.InvalidOperationException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.MulticastDelegate",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Nullable`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Object",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.PlatformNotSupportedException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Assembly",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyFileVersionAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Binder",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.BindingFlags",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.ConstructorInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.DefaultMemberAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Emit.DynamicMethod",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Emit.ILGenerator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Emit.OpCode",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Emit.OpCodes",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.FieldInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MemberInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MethodBase",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MethodInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.ParameterInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.ParameterModifier",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilationRelaxationsAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilerGeneratedAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.RuntimeCompatibilityAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.RuntimeTypeHandle",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Security.CodeAccessPermission",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Security.Permissions.RegistryPermission",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Security.Permissions.RegistryPermissionAccess",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Security.SecurityCriticalAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Security.SecuritySafeCriticalAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.String",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.StringComparer",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.StringComparison",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Text.StringBuilder",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Interlocked",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Monitor",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Type",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ValueType",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Version",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Void",
- "assembly": "mscorlib"
- }
- ]
- },
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "_CorExeMain",
- "address": "0x402000"
- }
- ],
- "dll": "mscoree.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00089639",
- "overlay": {
- "size": "0x00019000",
- "offset": "0x00061800"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x00089639",
- "icon_hash": null,
- "entrypoint": "0x0040fcae",
- "timestamp": "2019-05-06 19:37:27",
- "osversion": "4.0",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00002000",
- "size_of_data": "0x0000de00",
- "entropy": "5.39",
- "raw_address": "0x00000200",
- "virtual_size": "0x0000dcb4",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00010000",
- "size_of_data": "0x00053600",
- "entropy": "7.45",
- "raw_address": "0x0000e000",
- "virtual_size": "0x00053434",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00064000",
- "size_of_data": "0x00000200",
- "entropy": "0.08",
- "raw_address": "0x00061600",
- "virtual_size": "0x0000000c",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0000fc58",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000053"
- },
- {
- "virtual_address": "0x00010000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00053434"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00064000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x0000000c"
- },
- {
- "virtual_address": "0x0000fbd8",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000008"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002008",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000048"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "f34d5f2d4577ed6d9ceec516c1f5a744",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "C:\\xampp\\htdocs\\Aspire\\files\\root_gmVyOXfzhWMQdivj\\gmVyOXfzhWMQdivjma.pdb",
- "imported_dll_count": 1,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegQueryInfoKeyW",
- "advapi32.dll.RegEnumKeyExW",
- "advapi32.dll.RegEnumValueW",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.RegQueryValueExW",
- "kernel32.dll.QueryActCtxW",
- "shlwapi.dll.UrlIsW"
- ]
- [*] Static Analysis: {
- "dotnet": {
- "customattrs": [
- {
- "type": "TypeDef",
- "name": "[mscorlib]System.Reflection.DefaultMemberAttribute",
- "value": "It"
- },
- {
- "type": "TypeDef",
- "name": "[mscorlib]System.Reflection.DefaultMemberAttribute",
- "value": "It"
- }
- ],
- "assemblyinfo": {
- "version": "0.0.0.0",
- "name": "gmVyOXfzhWMQdivjma"
- },
- "assemblyrefs": [
- {
- "version": "4.0.0.0",
- "name": "mscorlib"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Web"
- },
- {
- "version": "4.0.0.0",
- "name": "System"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Core"
- },
- {
- "version": "4.0.0.0",
- "name": "System.Configuration"
- }
- ],
- "typerefs": [
- {
- "typename": "System.CodeDom.Compiler.CodeDomProvider",
- "assembly": "System"
- },
- {
- "typename": "System.Collections.Specialized.NameObjectCollectionBase",
- "assembly": "System"
- },
- {
- "typename": "System.Collections.Specialized.NameValueCollection",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.EditorBrowsableAttribute",
- "assembly": "System"
- },
- {
- "typename": "System.ComponentModel.EditorBrowsableState",
- "assembly": "System"
- },
- {
- "typename": "System.Net.Cookie",
- "assembly": "System"
- },
- {
- "typename": "System.Uri",
- "assembly": "System"
- },
- {
- "typename": "System.Configuration.ConfigurationElementCollection",
- "assembly": "System.Configuration"
- },
- {
- "typename": "System.Linq.Enumerable",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.Expressions.BinaryExpression",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.Expressions.Expression",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.Expressions.Expression`1",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.Expressions.MemberExpression",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.Expressions.MethodCallExpression",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.Expressions.ParameterExpression",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Linq.Expressions.UnaryExpression",
- "assembly": "System.Core"
- },
- {
- "typename": "System.Web.ApplicationShutdownReason",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.Compilation.BuildManager",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.Configuration.HttpModuleAction",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.Configuration.HttpModuleActionCollection",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.Configuration.HttpModulesSection",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.HttpApplication",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.HttpContext",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.HttpModuleCollection",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.HttpRequest",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.HttpRuntime",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.HttpServerUtility",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.IHttpModule",
- "assembly": "System.Web"
- },
- {
- "typename": "System.Web.Util.RequestValidationSource",
- "assembly": "System.Web"
- },
- {
- "typename": "Microsoft.Win32.Registry",
- "assembly": "mscorlib"
- },
- {
- "typename": "Microsoft.Win32.RegistryKey",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Action",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Action`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Action`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Action`3",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.AppDomain",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ArgumentException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ArgumentNullException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Array",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.AsyncCallback",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Boolean",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.ArrayList",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.DictionaryEntry",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.IEnumerable`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.List`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Generic.List`1/Enumerator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.Hashtable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.ICollection",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IDictionary",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IDictionaryEnumerator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IEnumerable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IEnumerator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IEqualityComparer",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Collections.IList",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Converter`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Delegate",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggableAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Diagnostics.DebuggableAttribute/DebuggingModes",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Enum",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`2",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Func`3",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Globalization.CultureInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Guid",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IAsyncResult",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IDisposable",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IFormatProvider",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Int32",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.IntPtr",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.InvalidOperationException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.MulticastDelegate",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Nullable`1",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Object",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.PlatformNotSupportedException",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Assembly",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.AssemblyFileVersionAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Binder",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.BindingFlags",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.ConstructorInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.DefaultMemberAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Emit.DynamicMethod",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Emit.ILGenerator",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Emit.OpCode",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.Emit.OpCodes",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.FieldInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MemberInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MethodBase",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.MethodInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.ParameterInfo",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Reflection.ParameterModifier",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilationRelaxationsAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.CompilerGeneratedAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Runtime.CompilerServices.RuntimeCompatibilityAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.RuntimeTypeHandle",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Security.CodeAccessPermission",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Security.Permissions.RegistryPermission",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Security.Permissions.RegistryPermissionAccess",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Security.SecurityCriticalAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Security.SecuritySafeCriticalAttribute",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.String",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.StringComparer",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.StringComparison",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Text.StringBuilder",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Interlocked",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Threading.Monitor",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Type",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.ValueType",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Version",
- "assembly": "mscorlib"
- },
- {
- "typename": "System.Void",
- "assembly": "mscorlib"
- }
- ]
- },
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "_CorExeMain",
- "address": "0x402000"
- }
- ],
- "dll": "mscoree.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00089639",
- "overlay": {
- "size": "0x00019000",
- "offset": "0x00061800"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x00089639",
- "icon_hash": null,
- "entrypoint": "0x0040fcae",
- "timestamp": "2019-05-06 19:37:27",
- "osversion": "4.0",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00002000",
- "size_of_data": "0x0000de00",
- "entropy": "5.39",
- "raw_address": "0x00000200",
- "virtual_size": "0x0000dcb4",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00010000",
- "size_of_data": "0x00053600",
- "entropy": "7.45",
- "raw_address": "0x0000e000",
- "virtual_size": "0x00053434",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00064000",
- "size_of_data": "0x00000200",
- "entropy": "0.08",
- "raw_address": "0x00061600",
- "virtual_size": "0x0000000c",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0000fc58",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000053"
- },
- {
- "virtual_address": "0x00010000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00053434"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00064000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x0000000c"
- },
- {
- "virtual_address": "0x0000fbd8",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000008"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00002008",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000048"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "f34d5f2d4577ed6d9ceec516c1f5a744",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "C:\\xampp\\htdocs\\Aspire\\files\\root_gmVyOXfzhWMQdivj\\gmVyOXfzhWMQdivjma.pdb",
- "imported_dll_count": 1,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement