Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: ""
- [*] MalScore: 0.0
- [*] File Name: "ADExplorer.exe"
- [*] File Size: 479832
- [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- [*] SHA256: "bb45d8ffe245c361c04cca44d0df6e6bd7596cabd70070ffe0d9f519e3b620ea"
- [*] MD5: "5d70cf91907165a1425e4ecb4ffa03aa"
- [*] SHA1: "bc1d7c9968ee92431f8ad9b4f8063b5b56f32ad5"
- [*] SHA512: "fa92e37a6cf5b5eb1f107dc3153fca20f2f041160a61033bac5b6edde68f759ef97967dfdba734e11f20a429df53f9cd1e0a24aa5541f69749f403387aa70c7f"
- [*] CRC32: "AFDD017F"
- [*] SSDEEP: "12288:QJB9/HQLmTMga6JzQdrAVzDtpzO9LZvYC:QCLmwgza2VzSLZvB"
- [*] Process Execution: [
- "ADExplorer.exe"
- ]
- [*] Signatures Detected: []
- [*] Started Service: []
- [*] Executed Commands: []
- [*] Mutexes: [
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1"
- ]
- [*] Modified Files: [
- "\\??\\UNC\\Host*\\MAILSLOT\\NET\\NETLOGON"
- ]
- [*] Deleted Files: []
- [*] Modified Registry Keys: [
- "HKEY_CURRENT_USER\\Software\\MSDART\\Active Directory Explorer",
- "HKEY_CURRENT_USER\\Software\\Sysinternals\\Active Directory Explorer",
- "HKEY_CURRENT_USER\\Software\\Sysinternals\\Active Directory Explorer\\EulaAccepted"
- ]
- [*] Deleted Registry Keys: []
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "NetUserGetGroups",
- "address": "0x4502e0"
- },
- {
- "name": "NetUserGetLocalGroups",
- "address": "0x4502e4"
- }
- ],
- "dll": "NETAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "UuidFromStringW",
- "address": "0x450328"
- }
- ],
- "dll": "RPCRT4.dll"
- },
- {
- "imports": [
- {
- "name": "GetFileVersionInfoSizeW",
- "address": "0x4504d0"
- },
- {
- "name": "GetFileVersionInfoW",
- "address": "0x4504d4"
- },
- {
- "name": "VerQueryValueW",
- "address": "0x4504d8"
- }
- ],
- "dll": "VERSION.dll"
- },
- {
- "imports": [
- {
- "name": "LCMapStringA",
- "address": "0x450118"
- },
- {
- "name": "GetConsoleMode",
- "address": "0x45011c"
- },
- {
- "name": "GetConsoleCP",
- "address": "0x450120"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x450124"
- },
- {
- "name": "DebugBreak",
- "address": "0x450128"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x45012c"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x450130"
- },
- {
- "name": "GetEnvironmentStringsW",
- "address": "0x450134"
- },
- {
- "name": "FreeEnvironmentStringsW",
- "address": "0x450138"
- },
- {
- "name": "GetEnvironmentStrings",
- "address": "0x45013c"
- },
- {
- "name": "FreeEnvironmentStringsA",
- "address": "0x450140"
- },
- {
- "name": "GetFileType",
- "address": "0x450144"
- },
- {
- "name": "SetHandleCount",
- "address": "0x450148"
- },
- {
- "name": "LCMapStringW",
- "address": "0x45014c"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x450150"
- },
- {
- "name": "GetStdHandle",
- "address": "0x450154"
- },
- {
- "name": "ExitProcess",
- "address": "0x450158"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x45015c"
- },
- {
- "name": "VirtualFree",
- "address": "0x450160"
- },
- {
- "name": "HeapCreate",
- "address": "0x450164"
- },
- {
- "name": "GetStringTypeA",
- "address": "0x450168"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x45016c"
- },
- {
- "name": "SetLastError",
- "address": "0x450170"
- },
- {
- "name": "TlsFree",
- "address": "0x450174"
- },
- {
- "name": "IsValidCodePage",
- "address": "0x450178"
- },
- {
- "name": "GetOEMCP",
- "address": "0x45017c"
- },
- {
- "name": "GetACP",
- "address": "0x450180"
- },
- {
- "name": "GetCPInfo",
- "address": "0x450184"
- },
- {
- "name": "RaiseException",
- "address": "0x450188"
- },
- {
- "name": "RtlUnwind",
- "address": "0x45018c"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x450190"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x450194"
- },
- {
- "name": "HeapReAlloc",
- "address": "0x450198"
- },
- {
- "name": "IsDebuggerPresent",
- "address": "0x45019c"
- },
- {
- "name": "SetUnhandledExceptionFilter",
- "address": "0x4501a0"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x4501a4"
- },
- {
- "name": "TerminateProcess",
- "address": "0x4501a8"
- },
- {
- "name": "CreateThread",
- "address": "0x4501ac"
- },
- {
- "name": "ResumeThread",
- "address": "0x4501b0"
- },
- {
- "name": "ExitThread",
- "address": "0x4501b4"
- },
- {
- "name": "HeapSize",
- "address": "0x4501b8"
- },
- {
- "name": "HeapAlloc",
- "address": "0x4501bc"
- },
- {
- "name": "GetStringTypeW",
- "address": "0x4501c0"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x4501c4"
- },
- {
- "name": "InitializeCriticalSectionAndSpinCount",
- "address": "0x4501c8"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x4501cc"
- },
- {
- "name": "ExpandEnvironmentStringsA",
- "address": "0x4501d0"
- },
- {
- "name": "GetProcessHeap",
- "address": "0x4501d4"
- },
- {
- "name": "HeapFree",
- "address": "0x4501d8"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x4501dc"
- },
- {
- "name": "lstrlenA",
- "address": "0x4501e0"
- },
- {
- "name": "WriteFile",
- "address": "0x4501e4"
- },
- {
- "name": "FileTimeToLocalFileTime",
- "address": "0x4501e8"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x4501ec"
- },
- {
- "name": "FreeLibrary",
- "address": "0x4501f0"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x4501f4"
- },
- {
- "name": "GetLastError",
- "address": "0x4501f8"
- },
- {
- "name": "Sleep",
- "address": "0x4501fc"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x450200"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x450204"
- },
- {
- "name": "CreateFileW",
- "address": "0x450208"
- },
- {
- "name": "ReadFile",
- "address": "0x45020c"
- },
- {
- "name": "GetSystemDirectoryW",
- "address": "0x450210"
- },
- {
- "name": "OutputDebugStringW",
- "address": "0x450214"
- },
- {
- "name": "GetFileSize",
- "address": "0x450218"
- },
- {
- "name": "TlsAlloc",
- "address": "0x45021c"
- },
- {
- "name": "FormatMessageW",
- "address": "0x450220"
- },
- {
- "name": "TlsSetValue",
- "address": "0x450224"
- },
- {
- "name": "GetUserDefaultLangID",
- "address": "0x450228"
- },
- {
- "name": "TlsGetValue",
- "address": "0x45022c"
- },
- {
- "name": "GetSystemDefaultLangID",
- "address": "0x450230"
- },
- {
- "name": "LocalAlloc",
- "address": "0x450234"
- },
- {
- "name": "LocalFree",
- "address": "0x450238"
- },
- {
- "name": "GetTimeZoneInformation",
- "address": "0x45023c"
- },
- {
- "name": "FileTimeToSystemTime",
- "address": "0x450240"
- },
- {
- "name": "GetTimeFormatW",
- "address": "0x450244"
- },
- {
- "name": "CompareFileTime",
- "address": "0x450248"
- },
- {
- "name": "SystemTimeToFileTime",
- "address": "0x45024c"
- },
- {
- "name": "SystemTimeToTzSpecificLocalTime",
- "address": "0x450250"
- },
- {
- "name": "GetDateFormatW",
- "address": "0x450254"
- },
- {
- "name": "DeleteFileW",
- "address": "0x450258"
- },
- {
- "name": "CloseHandle",
- "address": "0x45025c"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x450260"
- },
- {
- "name": "CreateFileMappingW",
- "address": "0x450264"
- },
- {
- "name": "GlobalFree",
- "address": "0x450268"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x45026c"
- },
- {
- "name": "GetProcAddress",
- "address": "0x450270"
- },
- {
- "name": "GlobalUnlock",
- "address": "0x450274"
- },
- {
- "name": "CompareStringW",
- "address": "0x450278"
- },
- {
- "name": "GetModuleFileNameW",
- "address": "0x45027c"
- },
- {
- "name": "GetFileAttributesW",
- "address": "0x450280"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x450284"
- },
- {
- "name": "GetVersionExW",
- "address": "0x450288"
- },
- {
- "name": "LoadLibraryW",
- "address": "0x45028c"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x450290"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x450294"
- },
- {
- "name": "GetTickCount",
- "address": "0x450298"
- },
- {
- "name": "GetModuleHandleW",
- "address": "0x45029c"
- },
- {
- "name": "GlobalLock",
- "address": "0x4502a0"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x4502a4"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x4502a8"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x4502ac"
- },
- {
- "name": "UnmapViewOfFile",
- "address": "0x4502b0"
- },
- {
- "name": "MapViewOfFile",
- "address": "0x4502b4"
- },
- {
- "name": "SetFilePointer",
- "address": "0x4502b8"
- },
- {
- "name": "GetCommandLineW",
- "address": "0x4502bc"
- },
- {
- "name": "SetStdHandle",
- "address": "0x4502c0"
- },
- {
- "name": "FlushFileBuffers",
- "address": "0x4502c4"
- },
- {
- "name": "VirtualQuery",
- "address": "0x4502c8"
- },
- {
- "name": "WriteConsoleA",
- "address": "0x4502cc"
- },
- {
- "name": "GetConsoleOutputCP",
- "address": "0x4502d0"
- },
- {
- "name": "WriteConsoleW",
- "address": "0x4502d4"
- },
- {
- "name": "CreateFileA",
- "address": "0x4502d8"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "DispatchMessageW",
- "address": "0x45033c"
- },
- {
- "name": "MoveWindow",
- "address": "0x450340"
- },
- {
- "name": "CheckMenuItem",
- "address": "0x450344"
- },
- {
- "name": "MsgWaitForMultipleObjects",
- "address": "0x450348"
- },
- {
- "name": "DrawTextW",
- "address": "0x45034c"
- },
- {
- "name": "PostMessageW",
- "address": "0x450350"
- },
- {
- "name": "SetCapture",
- "address": "0x450354"
- },
- {
- "name": "LoadImageW",
- "address": "0x450358"
- },
- {
- "name": "TrackPopupMenu",
- "address": "0x45035c"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x450360"
- },
- {
- "name": "GetMessageW",
- "address": "0x450364"
- },
- {
- "name": "GetWindowRect",
- "address": "0x450368"
- },
- {
- "name": "ScreenToClient",
- "address": "0x45036c"
- },
- {
- "name": "GetDlgItemInt",
- "address": "0x450370"
- },
- {
- "name": "TranslateAcceleratorW",
- "address": "0x450374"
- },
- {
- "name": "CloseClipboard",
- "address": "0x450378"
- },
- {
- "name": "GetWindowTextLengthW",
- "address": "0x45037c"
- },
- {
- "name": "SetCursor",
- "address": "0x450380"
- },
- {
- "name": "SetWindowPlacement",
- "address": "0x450384"
- },
- {
- "name": "DestroyWindow",
- "address": "0x450388"
- },
- {
- "name": "ClientToScreen",
- "address": "0x45038c"
- },
- {
- "name": "EndPaint",
- "address": "0x450390"
- },
- {
- "name": "DialogBoxIndirectParamW",
- "address": "0x450394"
- },
- {
- "name": "CopyIcon",
- "address": "0x450398"
- },
- {
- "name": "IsZoomed",
- "address": "0x45039c"
- },
- {
- "name": "GetSubMenu",
- "address": "0x4503a0"
- },
- {
- "name": "DeleteMenu",
- "address": "0x4503a4"
- },
- {
- "name": "GetFocus",
- "address": "0x4503a8"
- },
- {
- "name": "DialogBoxParamW",
- "address": "0x4503ac"
- },
- {
- "name": "GetParent",
- "address": "0x4503b0"
- },
- {
- "name": "LoadCursorW",
- "address": "0x4503b4"
- },
- {
- "name": "MessageBeep",
- "address": "0x4503b8"
- },
- {
- "name": "MenuItemFromPoint",
- "address": "0x4503bc"
- },
- {
- "name": "GetClientRect",
- "address": "0x4503c0"
- },
- {
- "name": "SetFocus",
- "address": "0x4503c4"
- },
- {
- "name": "GetMenuItemInfoW",
- "address": "0x4503c8"
- },
- {
- "name": "BeginPaint",
- "address": "0x4503cc"
- },
- {
- "name": "PtInRect",
- "address": "0x4503d0"
- },
- {
- "name": "SetPropW",
- "address": "0x4503d4"
- },
- {
- "name": "InsertMenuItemW",
- "address": "0x4503d8"
- },
- {
- "name": "TranslateMessage",
- "address": "0x4503dc"
- },
- {
- "name": "LoadAcceleratorsW",
- "address": "0x4503e0"
- },
- {
- "name": "InflateRect",
- "address": "0x4503e4"
- },
- {
- "name": "ChildWindowFromPoint",
- "address": "0x4503e8"
- },
- {
- "name": "SetDlgItemInt",
- "address": "0x4503ec"
- },
- {
- "name": "GetMenu",
- "address": "0x4503f0"
- },
- {
- "name": "IsDialogMessageW",
- "address": "0x4503f4"
- },
- {
- "name": "DefWindowProcW",
- "address": "0x4503f8"
- },
- {
- "name": "CallWindowProcW",
- "address": "0x4503fc"
- },
- {
- "name": "GetPropW",
- "address": "0x450400"
- },
- {
- "name": "DrawFrameControl",
- "address": "0x450404"
- },
- {
- "name": "EndDeferWindowPos",
- "address": "0x450408"
- },
- {
- "name": "DestroyIcon",
- "address": "0x45040c"
- },
- {
- "name": "SetWindowTextW",
- "address": "0x450410"
- },
- {
- "name": "DestroyMenu",
- "address": "0x450414"
- },
- {
- "name": "SetClipboardData",
- "address": "0x450418"
- },
- {
- "name": "RegisterClassExW",
- "address": "0x45041c"
- },
- {
- "name": "LoadIconW",
- "address": "0x450420"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x450424"
- },
- {
- "name": "OffsetRect",
- "address": "0x450428"
- },
- {
- "name": "InvalidateRect",
- "address": "0x45042c"
- },
- {
- "name": "LoadMenuW",
- "address": "0x450430"
- },
- {
- "name": "GetWindowLongW",
- "address": "0x450434"
- },
- {
- "name": "AppendMenuW",
- "address": "0x450438"
- },
- {
- "name": "GetWindowTextW",
- "address": "0x45043c"
- },
- {
- "name": "PeekMessageW",
- "address": "0x450440"
- },
- {
- "name": "GetClassNameW",
- "address": "0x450444"
- },
- {
- "name": "EnableMenuItem",
- "address": "0x450448"
- },
- {
- "name": "EmptyClipboard",
- "address": "0x45044c"
- },
- {
- "name": "GetDlgItem",
- "address": "0x450450"
- },
- {
- "name": "SetWindowLongW",
- "address": "0x450454"
- },
- {
- "name": "EndDialog",
- "address": "0x450458"
- },
- {
- "name": "SendDlgItemMessageW",
- "address": "0x45045c"
- },
- {
- "name": "GetSysColor",
- "address": "0x450460"
- },
- {
- "name": "SetWindowPos",
- "address": "0x450464"
- },
- {
- "name": "CheckDlgButton",
- "address": "0x450468"
- },
- {
- "name": "EnumChildWindows",
- "address": "0x45046c"
- },
- {
- "name": "ShowWindow",
- "address": "0x450470"
- },
- {
- "name": "CreatePopupMenu",
- "address": "0x450474"
- },
- {
- "name": "GetSysColorBrush",
- "address": "0x450478"
- },
- {
- "name": "IsDlgButtonChecked",
- "address": "0x45047c"
- },
- {
- "name": "CreateDialogParamW",
- "address": "0x450480"
- },
- {
- "name": "DrawMenuBar",
- "address": "0x450484"
- },
- {
- "name": "GetActiveWindow",
- "address": "0x450488"
- },
- {
- "name": "GetMenuItemCount",
- "address": "0x45048c"
- },
- {
- "name": "CreateWindowExW",
- "address": "0x450490"
- },
- {
- "name": "SetMenuDefaultItem",
- "address": "0x450494"
- },
- {
- "name": "OpenClipboard",
- "address": "0x450498"
- },
- {
- "name": "DeferWindowPos",
- "address": "0x45049c"
- },
- {
- "name": "MessageBoxW",
- "address": "0x4504a0"
- },
- {
- "name": "ReleaseCapture",
- "address": "0x4504a4"
- },
- {
- "name": "BeginDeferWindowPos",
- "address": "0x4504a8"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x4504ac"
- },
- {
- "name": "IsWindowVisible",
- "address": "0x4504b0"
- },
- {
- "name": "GetDlgItemTextW",
- "address": "0x4504b4"
- },
- {
- "name": "SetDlgItemTextW",
- "address": "0x4504b8"
- },
- {
- "name": "SendMessageW",
- "address": "0x4504bc"
- },
- {
- "name": "MapWindowPoints",
- "address": "0x4504c0"
- },
- {
- "name": "UpdateWindow",
- "address": "0x4504c4"
- },
- {
- "name": "EnableWindow",
- "address": "0x4504c8"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "SetBkColor",
- "address": "0x4500dc"
- },
- {
- "name": "ExtTextOutW",
- "address": "0x4500e0"
- },
- {
- "name": "EndPage",
- "address": "0x4500e4"
- },
- {
- "name": "StartPage",
- "address": "0x4500e8"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x4500ec"
- },
- {
- "name": "SetMapMode",
- "address": "0x4500f0"
- },
- {
- "name": "SetTextColor",
- "address": "0x4500f4"
- },
- {
- "name": "CreateFontIndirectW",
- "address": "0x4500f8"
- },
- {
- "name": "SetBkMode",
- "address": "0x4500fc"
- },
- {
- "name": "SelectObject",
- "address": "0x450100"
- },
- {
- "name": "GetObjectW",
- "address": "0x450104"
- },
- {
- "name": "EndDoc",
- "address": "0x450108"
- },
- {
- "name": "GetStockObject",
- "address": "0x45010c"
- },
- {
- "name": "StartDocW",
- "address": "0x450110"
- }
- ],
- "dll": "GDI32.dll"
- },
- {
- "imports": [
- {
- "name": "GetSaveFileNameW",
- "address": "0x4500cc"
- },
- {
- "name": "GetOpenFileNameW",
- "address": "0x4500d0"
- },
- {
- "name": "PrintDlgW",
- "address": "0x4500d4"
- }
- ],
- "dll": "COMDLG32.dll"
- },
- {
- "imports": [
- {
- "name": "GetSecurityDescriptorLength",
- "address": "0x45001c"
- },
- {
- "name": "RegDeleteValueW",
- "address": "0x450020"
- },
- {
- "name": "RegCreateKeyW",
- "address": "0x450024"
- },
- {
- "name": "RegEnumValueW",
- "address": "0x450028"
- },
- {
- "name": "RegSetValueExW",
- "address": "0x45002c"
- },
- {
- "name": "ConvertStringSidToSidW",
- "address": "0x450030"
- },
- {
- "name": "ConvertStringSecurityDescriptorToSecurityDescriptorW",
- "address": "0x450034"
- },
- {
- "name": "GetLengthSid",
- "address": "0x450038"
- },
- {
- "name": "ConvertSidToStringSidW",
- "address": "0x45003c"
- },
- {
- "name": "ConvertSecurityDescriptorToStringSecurityDescriptorW",
- "address": "0x450040"
- },
- {
- "name": "RegQueryValueExW",
- "address": "0x450044"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x450048"
- },
- {
- "name": "RegQueryValueExA",
- "address": "0x45004c"
- },
- {
- "name": "AdjustTokenPrivileges",
- "address": "0x450050"
- },
- {
- "name": "LookupPrivilegeValueW",
- "address": "0x450054"
- },
- {
- "name": "OpenProcessToken",
- "address": "0x450058"
- },
- {
- "name": "GetSecurityDescriptorDacl",
- "address": "0x45005c"
- },
- {
- "name": "GetSecurityDescriptorGroup",
- "address": "0x450060"
- },
- {
- "name": "IsValidSid",
- "address": "0x450064"
- },
- {
- "name": "GetSecurityDescriptorOwner",
- "address": "0x450068"
- },
- {
- "name": "GetSidIdentifierAuthority",
- "address": "0x45006c"
- },
- {
- "name": "GetSidSubAuthority",
- "address": "0x450070"
- },
- {
- "name": "MapGenericMask",
- "address": "0x450074"
- },
- {
- "name": "GetSidSubAuthorityCount",
- "address": "0x450078"
- },
- {
- "name": "EqualSid",
- "address": "0x45007c"
- },
- {
- "name": "GetAce",
- "address": "0x450080"
- },
- {
- "name": "LookupAccountSidW",
- "address": "0x450084"
- },
- {
- "name": "AllocateAndInitializeSid",
- "address": "0x450088"
- },
- {
- "name": "RegCloseKey",
- "address": "0x45008c"
- }
- ],
- "dll": "ADVAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "CommandLineToArgvW",
- "address": "0x450330"
- },
- {
- "name": "ShellExecuteW",
- "address": "0x450334"
- }
- ],
- "dll": "SHELL32.dll"
- },
- {
- "imports": [
- {
- "name": "CoInitialize",
- "address": "0x450504"
- },
- {
- "name": "CreateBindCtx",
- "address": "0x450508"
- },
- {
- "name": "CoUninitialize",
- "address": "0x45050c"
- },
- {
- "name": "CoCreateInstance",
- "address": "0x450510"
- },
- {
- "name": "IIDFromString",
- "address": "0x450514"
- },
- {
- "name": "StringFromGUID2",
- "address": "0x450518"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "SafeArrayAccessData",
- "address": "0x4502ec"
- },
- {
- "name": "SystemTimeToVariantTime",
- "address": "0x4502f0"
- },
- {
- "name": "VariantTimeToSystemTime",
- "address": "0x4502f4"
- },
- {
- "name": "SafeArrayGetUBound",
- "address": "0x4502f8"
- },
- {
- "name": "SysFreeString",
- "address": "0x4502fc"
- },
- {
- "name": "SafeArrayGetElement",
- "address": "0x450300"
- },
- {
- "name": "VarDateFromStr",
- "address": "0x450304"
- },
- {
- "name": "VariantChangeType",
- "address": "0x450308"
- },
- {
- "name": "VariantInit",
- "address": "0x45030c"
- },
- {
- "name": "SysAllocStringByteLen",
- "address": "0x450310"
- },
- {
- "name": "VariantClear",
- "address": "0x450314"
- },
- {
- "name": "SafeArrayGetLBound",
- "address": "0x450318"
- },
- {
- "name": "SysStringLen",
- "address": "0x45031c"
- },
- {
- "name": "SysAllocString",
- "address": "0x450320"
- }
- ],
- "dll": "OLEAUT32.dll"
- },
- {
- "imports": [
- {
- "name": "ImageList_Draw",
- "address": "0x450094"
- },
- {
- "name": "CreateToolbarEx",
- "address": "0x450098"
- },
- {
- "name": "CreatePropertySheetPageW",
- "address": "0x45009c"
- },
- {
- "name": "ImageList_Create",
- "address": "0x4500a0"
- },
- {
- "name": "ImageList_ReplaceIcon",
- "address": "0x4500a4"
- },
- {
- "name": "ImageList_EndDrag",
- "address": "0x4500a8"
- },
- {
- "name": "ImageList_DragMove",
- "address": "0x4500ac"
- },
- {
- "name": "ImageList_BeginDrag",
- "address": "0x4500b0"
- },
- {
- "name": "ImageList_DragLeave",
- "address": "0x4500b4"
- },
- {
- "name": "ImageList_DragEnter",
- "address": "0x4500b8"
- },
- {
- "name": null,
- "address": "0x4500bc"
- },
- {
- "name": "CreateStatusWindowW",
- "address": "0x4500c0"
- },
- {
- "name": "PropertySheetW",
- "address": "0x4500c4"
- }
- ],
- "dll": "COMCTL32.dll"
- },
- {
- "imports": [
- {
- "name": null,
- "address": "0x450000"
- },
- {
- "name": null,
- "address": "0x450004"
- },
- {
- "name": null,
- "address": "0x450008"
- },
- {
- "name": null,
- "address": "0x45000c"
- },
- {
- "name": null,
- "address": "0x450010"
- },
- {
- "name": null,
- "address": "0x450014"
- }
- ],
- "dll": "ACTIVEDS.dll"
- },
- {
- "imports": [
- {
- "name": null,
- "address": "0x4504e0"
- },
- {
- "name": null,
- "address": "0x4504e4"
- },
- {
- "name": null,
- "address": "0x4504e8"
- },
- {
- "name": null,
- "address": "0x4504ec"
- },
- {
- "name": null,
- "address": "0x4504f0"
- },
- {
- "name": null,
- "address": "0x4504f4"
- },
- {
- "name": null,
- "address": "0x4504f8"
- },
- {
- "name": null,
- "address": "0x4504fc"
- }
- ],
- "dll": "WLDAP32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00081405",
- "overlay": {
- "size": "0x00001a58",
- "offset": "0x00073800"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x00081405",
- "icon_hash": null,
- "entrypoint": "0x004149ec",
- "timestamp": "2012-06-30 09:47:15",
- "osversion": "5.0",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x0004f000",
- "entropy": "6.28",
- "raw_address": "0x00000400",
- "virtual_size": "0x0004eecc",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00050000",
- "size_of_data": "0x0000fc00",
- "entropy": "4.68",
- "raw_address": "0x0004f400",
- "virtual_size": "0x0000fc00",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00060000",
- "size_of_data": "0x0000a400",
- "entropy": "2.63",
- "raw_address": "0x0005f000",
- "virtual_size": "0x0000c5c0",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0006d000",
- "size_of_data": "0x0000a400",
- "entropy": "4.30",
- "raw_address": "0x00069400",
- "virtual_size": "0x0000a318",
- "characteristics_raw": "0x40000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0005e090",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000012c"
- },
- {
- "virtual_address": "0x0006d000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x0000a318"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00073800",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00001a58"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00050570",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0005af98",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000040"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00050000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000520"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "fc22a526c18358f987f144e2ac31d338",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "c:\\src\\ADExplorer\\Release\\ADExplorer.pdb",
- "imported_dll_count": 14,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "kernel32.dll.FlsAlloc",
- "kernel32.dll.FlsGetValue",
- "kernel32.dll.FlsSetValue",
- "kernel32.dll.FlsFree",
- "kernel32.dll.IsProcessorFeaturePresent",
- "cryptbase.dll.SystemFunction036",
- "uxtheme.dll.ThemeInitApiHook",
- "user32.dll.IsProcessDPIAware",
- "dwmapi.dll.DwmIsCompositionEnabled",
- "comctl32.dll.RegisterClassNameW",
- "uxtheme.dll.EnableThemeDialogTexture",
- "uxtheme.dll.OpenThemeData",
- "uxtheme.dll.GetThemeBool",
- "comctl32.dll.HIMAGELIST_QueryInterface",
- "comctl32.dll.DrawShadowText",
- "comctl32.dll.DrawSizeBox",
- "comctl32.dll.DrawScrollBar",
- "comctl32.dll.SizeBoxHwnd",
- "comctl32.dll.ScrollBar_MouseMove",
- "comctl32.dll.ScrollBar_Menu",
- "comctl32.dll.HandleScrollCmd",
- "comctl32.dll.DetachScrollBars",
- "comctl32.dll.AttachScrollBars",
- "comctl32.dll.CCSetScrollInfo",
- "comctl32.dll.CCGetScrollInfo",
- "comctl32.dll.CCEnableScrollBar",
- "comctl32.dll.QuerySystemGestureStatus",
- "uxtheme.dll.#49",
- "uxtheme.dll.CloseThemeData",
- "gdi32.dll.GetLayout",
- "gdi32.dll.GdiRealizationInfo",
- "gdi32.dll.FontIsLinked",
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegQueryInfoKeyW",
- "gdi32.dll.GetTextFaceAliasW",
- "advapi32.dll.RegEnumValueW",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.RegQueryValueExW",
- "gdi32.dll.GetFontAssocStatus",
- "advapi32.dll.RegQueryValueExA",
- "advapi32.dll.RegEnumKeyExW",
- "gdi32.dll.GdiIsMetaPrintDC",
- "ole32.dll.CoInitializeEx",
- "ole32.dll.CoUninitialize",
- "ole32.dll.CoRegisterInitializeSpy",
- "ole32.dll.CoRevokeInitializeSpy",
- "uxtheme.dll.BufferedPaintInit",
- "uxtheme.dll.BufferedPaintRenderAnimation",
- "uxtheme.dll.GetThemeTransitionDuration",
- "uxtheme.dll.BeginBufferedAnimation",
- "uxtheme.dll.IsThemeBackgroundPartiallyTransparent",
- "uxtheme.dll.DrawThemeParentBackground",
- "uxtheme.dll.DrawThemeBackground",
- "uxtheme.dll.GetThemeBackgroundContentRect",
- "uxtheme.dll.DrawThemeText",
- "uxtheme.dll.EndBufferedAnimation",
- "uxtheme.dll.GetThemePartSize",
- "uxtheme.dll.BufferedPaintStopAllAnimations",
- "uxtheme.dll.BufferedPaintUnInit",
- "uxtheme.dll.GetThemeColor",
- "uxtheme.dll.IsThemePartDefined",
- "uxtheme.dll.GetThemeFont",
- "uxtheme.dll.GetThemeMargins",
- "imm32.dll.ImmIsIME",
- "uxtheme.dll.GetThemeTextExtent",
- "imm32.dll.ImmGetContext",
- "imm32.dll.ImmReleaseContext",
- "imm32.dll.ImmAssociateContext",
- "uxtheme.dll.GetThemeTextMetrics",
- "uxtheme.dll.GetThemeBackgroundExtent",
- "uxtheme.dll.GetThemeInt",
- "uxtheme.dll.DrawThemeTextEx",
- "uxtheme.dll.DrawThemeParentBackgroundEx",
- "uxtheme.dll.BeginBufferedPaint",
- "uxtheme.dll.EndBufferedPaint",
- "ole32.dll.CLSIDFromProgID",
- "ole32.dll.CoCreateInstance",
- "secur32.dll.LsaConnectUntrusted",
- "secur32.dll.LsaCallAuthenticationPackage",
- "secur32.dll.LsaFreeReturnBuffer",
- "advapi32.dll.CreateWellKnownSid",
- "advapi32.dll.LookupAccountSidW",
- "sechost.dll.LookupAccountSidLocalW",
- "advapi32.dll.OpenThreadToken",
- "advapi32.dll.OpenProcessToken",
- "advapi32.dll.GetTokenInformation",
- "advapi32.dll.GetSidSubAuthority",
- "netapi32.dll.DsGetDcNameW",
- "advapi32.dll.LsaOpenPolicy",
- "advapi32.dll.LsaQueryInformationPolicy",
- "netutils.dll.NetApiBufferAllocate",
- "advapi32.dll.LsaFreeMemory",
- "advapi32.dll.LsaClose",
- "ws2_32.dll.#115",
- "dnsapi.dll.DnsValidateName_W",
- "netutils.dll.NetpIsDomainNameValid",
- "wldap32.dll.#119",
- "netutils.dll.NetApiBufferFree",
- "ws2_32.dll.#116",
- "oleaut32.dll.#9",
- "oleaut32.dll.#6",
- "oleaut32.dll.#201",
- "oleaut32.dll.#202"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "NetUserGetGroups",
- "address": "0x4502e0"
- },
- {
- "name": "NetUserGetLocalGroups",
- "address": "0x4502e4"
- }
- ],
- "dll": "NETAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "UuidFromStringW",
- "address": "0x450328"
- }
- ],
- "dll": "RPCRT4.dll"
- },
- {
- "imports": [
- {
- "name": "GetFileVersionInfoSizeW",
- "address": "0x4504d0"
- },
- {
- "name": "GetFileVersionInfoW",
- "address": "0x4504d4"
- },
- {
- "name": "VerQueryValueW",
- "address": "0x4504d8"
- }
- ],
- "dll": "VERSION.dll"
- },
- {
- "imports": [
- {
- "name": "LCMapStringA",
- "address": "0x450118"
- },
- {
- "name": "GetConsoleMode",
- "address": "0x45011c"
- },
- {
- "name": "GetConsoleCP",
- "address": "0x450120"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x450124"
- },
- {
- "name": "DebugBreak",
- "address": "0x450128"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x45012c"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x450130"
- },
- {
- "name": "GetEnvironmentStringsW",
- "address": "0x450134"
- },
- {
- "name": "FreeEnvironmentStringsW",
- "address": "0x450138"
- },
- {
- "name": "GetEnvironmentStrings",
- "address": "0x45013c"
- },
- {
- "name": "FreeEnvironmentStringsA",
- "address": "0x450140"
- },
- {
- "name": "GetFileType",
- "address": "0x450144"
- },
- {
- "name": "SetHandleCount",
- "address": "0x450148"
- },
- {
- "name": "LCMapStringW",
- "address": "0x45014c"
- },
- {
- "name": "GetModuleFileNameA",
- "address": "0x450150"
- },
- {
- "name": "GetStdHandle",
- "address": "0x450154"
- },
- {
- "name": "ExitProcess",
- "address": "0x450158"
- },
- {
- "name": "VirtualAlloc",
- "address": "0x45015c"
- },
- {
- "name": "VirtualFree",
- "address": "0x450160"
- },
- {
- "name": "HeapCreate",
- "address": "0x450164"
- },
- {
- "name": "GetStringTypeA",
- "address": "0x450168"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x45016c"
- },
- {
- "name": "SetLastError",
- "address": "0x450170"
- },
- {
- "name": "TlsFree",
- "address": "0x450174"
- },
- {
- "name": "IsValidCodePage",
- "address": "0x450178"
- },
- {
- "name": "GetOEMCP",
- "address": "0x45017c"
- },
- {
- "name": "GetACP",
- "address": "0x450180"
- },
- {
- "name": "GetCPInfo",
- "address": "0x450184"
- },
- {
- "name": "RaiseException",
- "address": "0x450188"
- },
- {
- "name": "RtlUnwind",
- "address": "0x45018c"
- },
- {
- "name": "GetStartupInfoA",
- "address": "0x450190"
- },
- {
- "name": "GetCommandLineA",
- "address": "0x450194"
- },
- {
- "name": "HeapReAlloc",
- "address": "0x450198"
- },
- {
- "name": "IsDebuggerPresent",
- "address": "0x45019c"
- },
- {
- "name": "SetUnhandledExceptionFilter",
- "address": "0x4501a0"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x4501a4"
- },
- {
- "name": "TerminateProcess",
- "address": "0x4501a8"
- },
- {
- "name": "CreateThread",
- "address": "0x4501ac"
- },
- {
- "name": "ResumeThread",
- "address": "0x4501b0"
- },
- {
- "name": "ExitThread",
- "address": "0x4501b4"
- },
- {
- "name": "HeapSize",
- "address": "0x4501b8"
- },
- {
- "name": "HeapAlloc",
- "address": "0x4501bc"
- },
- {
- "name": "GetStringTypeW",
- "address": "0x4501c0"
- },
- {
- "name": "GetLocaleInfoA",
- "address": "0x4501c4"
- },
- {
- "name": "InitializeCriticalSectionAndSpinCount",
- "address": "0x4501c8"
- },
- {
- "name": "LoadLibraryA",
- "address": "0x4501cc"
- },
- {
- "name": "ExpandEnvironmentStringsA",
- "address": "0x4501d0"
- },
- {
- "name": "GetProcessHeap",
- "address": "0x4501d4"
- },
- {
- "name": "HeapFree",
- "address": "0x4501d8"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x4501dc"
- },
- {
- "name": "lstrlenA",
- "address": "0x4501e0"
- },
- {
- "name": "WriteFile",
- "address": "0x4501e4"
- },
- {
- "name": "FileTimeToLocalFileTime",
- "address": "0x4501e8"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x4501ec"
- },
- {
- "name": "FreeLibrary",
- "address": "0x4501f0"
- },
- {
- "name": "GetSystemInfo",
- "address": "0x4501f4"
- },
- {
- "name": "GetLastError",
- "address": "0x4501f8"
- },
- {
- "name": "Sleep",
- "address": "0x4501fc"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x450200"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x450204"
- },
- {
- "name": "CreateFileW",
- "address": "0x450208"
- },
- {
- "name": "ReadFile",
- "address": "0x45020c"
- },
- {
- "name": "GetSystemDirectoryW",
- "address": "0x450210"
- },
- {
- "name": "OutputDebugStringW",
- "address": "0x450214"
- },
- {
- "name": "GetFileSize",
- "address": "0x450218"
- },
- {
- "name": "TlsAlloc",
- "address": "0x45021c"
- },
- {
- "name": "FormatMessageW",
- "address": "0x450220"
- },
- {
- "name": "TlsSetValue",
- "address": "0x450224"
- },
- {
- "name": "GetUserDefaultLangID",
- "address": "0x450228"
- },
- {
- "name": "TlsGetValue",
- "address": "0x45022c"
- },
- {
- "name": "GetSystemDefaultLangID",
- "address": "0x450230"
- },
- {
- "name": "LocalAlloc",
- "address": "0x450234"
- },
- {
- "name": "LocalFree",
- "address": "0x450238"
- },
- {
- "name": "GetTimeZoneInformation",
- "address": "0x45023c"
- },
- {
- "name": "FileTimeToSystemTime",
- "address": "0x450240"
- },
- {
- "name": "GetTimeFormatW",
- "address": "0x450244"
- },
- {
- "name": "CompareFileTime",
- "address": "0x450248"
- },
- {
- "name": "SystemTimeToFileTime",
- "address": "0x45024c"
- },
- {
- "name": "SystemTimeToTzSpecificLocalTime",
- "address": "0x450250"
- },
- {
- "name": "GetDateFormatW",
- "address": "0x450254"
- },
- {
- "name": "DeleteFileW",
- "address": "0x450258"
- },
- {
- "name": "CloseHandle",
- "address": "0x45025c"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x450260"
- },
- {
- "name": "CreateFileMappingW",
- "address": "0x450264"
- },
- {
- "name": "GlobalFree",
- "address": "0x450268"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x45026c"
- },
- {
- "name": "GetProcAddress",
- "address": "0x450270"
- },
- {
- "name": "GlobalUnlock",
- "address": "0x450274"
- },
- {
- "name": "CompareStringW",
- "address": "0x450278"
- },
- {
- "name": "GetModuleFileNameW",
- "address": "0x45027c"
- },
- {
- "name": "GetFileAttributesW",
- "address": "0x450280"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x450284"
- },
- {
- "name": "GetVersionExW",
- "address": "0x450288"
- },
- {
- "name": "LoadLibraryW",
- "address": "0x45028c"
- },
- {
- "name": "GlobalAlloc",
- "address": "0x450290"
- },
- {
- "name": "InitializeCriticalSection",
- "address": "0x450294"
- },
- {
- "name": "GetTickCount",
- "address": "0x450298"
- },
- {
- "name": "GetModuleHandleW",
- "address": "0x45029c"
- },
- {
- "name": "GlobalLock",
- "address": "0x4502a0"
- },
- {
- "name": "InterlockedDecrement",
- "address": "0x4502a4"
- },
- {
- "name": "InterlockedIncrement",
- "address": "0x4502a8"
- },
- {
- "name": "SetEndOfFile",
- "address": "0x4502ac"
- },
- {
- "name": "UnmapViewOfFile",
- "address": "0x4502b0"
- },
- {
- "name": "MapViewOfFile",
- "address": "0x4502b4"
- },
- {
- "name": "SetFilePointer",
- "address": "0x4502b8"
- },
- {
- "name": "GetCommandLineW",
- "address": "0x4502bc"
- },
- {
- "name": "SetStdHandle",
- "address": "0x4502c0"
- },
- {
- "name": "FlushFileBuffers",
- "address": "0x4502c4"
- },
- {
- "name": "VirtualQuery",
- "address": "0x4502c8"
- },
- {
- "name": "WriteConsoleA",
- "address": "0x4502cc"
- },
- {
- "name": "GetConsoleOutputCP",
- "address": "0x4502d0"
- },
- {
- "name": "WriteConsoleW",
- "address": "0x4502d4"
- },
- {
- "name": "CreateFileA",
- "address": "0x4502d8"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "DispatchMessageW",
- "address": "0x45033c"
- },
- {
- "name": "MoveWindow",
- "address": "0x450340"
- },
- {
- "name": "CheckMenuItem",
- "address": "0x450344"
- },
- {
- "name": "MsgWaitForMultipleObjects",
- "address": "0x450348"
- },
- {
- "name": "DrawTextW",
- "address": "0x45034c"
- },
- {
- "name": "PostMessageW",
- "address": "0x450350"
- },
- {
- "name": "SetCapture",
- "address": "0x450354"
- },
- {
- "name": "LoadImageW",
- "address": "0x450358"
- },
- {
- "name": "TrackPopupMenu",
- "address": "0x45035c"
- },
- {
- "name": "PostQuitMessage",
- "address": "0x450360"
- },
- {
- "name": "GetMessageW",
- "address": "0x450364"
- },
- {
- "name": "GetWindowRect",
- "address": "0x450368"
- },
- {
- "name": "ScreenToClient",
- "address": "0x45036c"
- },
- {
- "name": "GetDlgItemInt",
- "address": "0x450370"
- },
- {
- "name": "TranslateAcceleratorW",
- "address": "0x450374"
- },
- {
- "name": "CloseClipboard",
- "address": "0x450378"
- },
- {
- "name": "GetWindowTextLengthW",
- "address": "0x45037c"
- },
- {
- "name": "SetCursor",
- "address": "0x450380"
- },
- {
- "name": "SetWindowPlacement",
- "address": "0x450384"
- },
- {
- "name": "DestroyWindow",
- "address": "0x450388"
- },
- {
- "name": "ClientToScreen",
- "address": "0x45038c"
- },
- {
- "name": "EndPaint",
- "address": "0x450390"
- },
- {
- "name": "DialogBoxIndirectParamW",
- "address": "0x450394"
- },
- {
- "name": "CopyIcon",
- "address": "0x450398"
- },
- {
- "name": "IsZoomed",
- "address": "0x45039c"
- },
- {
- "name": "GetSubMenu",
- "address": "0x4503a0"
- },
- {
- "name": "DeleteMenu",
- "address": "0x4503a4"
- },
- {
- "name": "GetFocus",
- "address": "0x4503a8"
- },
- {
- "name": "DialogBoxParamW",
- "address": "0x4503ac"
- },
- {
- "name": "GetParent",
- "address": "0x4503b0"
- },
- {
- "name": "LoadCursorW",
- "address": "0x4503b4"
- },
- {
- "name": "MessageBeep",
- "address": "0x4503b8"
- },
- {
- "name": "MenuItemFromPoint",
- "address": "0x4503bc"
- },
- {
- "name": "GetClientRect",
- "address": "0x4503c0"
- },
- {
- "name": "SetFocus",
- "address": "0x4503c4"
- },
- {
- "name": "GetMenuItemInfoW",
- "address": "0x4503c8"
- },
- {
- "name": "BeginPaint",
- "address": "0x4503cc"
- },
- {
- "name": "PtInRect",
- "address": "0x4503d0"
- },
- {
- "name": "SetPropW",
- "address": "0x4503d4"
- },
- {
- "name": "InsertMenuItemW",
- "address": "0x4503d8"
- },
- {
- "name": "TranslateMessage",
- "address": "0x4503dc"
- },
- {
- "name": "LoadAcceleratorsW",
- "address": "0x4503e0"
- },
- {
- "name": "InflateRect",
- "address": "0x4503e4"
- },
- {
- "name": "ChildWindowFromPoint",
- "address": "0x4503e8"
- },
- {
- "name": "SetDlgItemInt",
- "address": "0x4503ec"
- },
- {
- "name": "GetMenu",
- "address": "0x4503f0"
- },
- {
- "name": "IsDialogMessageW",
- "address": "0x4503f4"
- },
- {
- "name": "DefWindowProcW",
- "address": "0x4503f8"
- },
- {
- "name": "CallWindowProcW",
- "address": "0x4503fc"
- },
- {
- "name": "GetPropW",
- "address": "0x450400"
- },
- {
- "name": "DrawFrameControl",
- "address": "0x450404"
- },
- {
- "name": "EndDeferWindowPos",
- "address": "0x450408"
- },
- {
- "name": "DestroyIcon",
- "address": "0x45040c"
- },
- {
- "name": "SetWindowTextW",
- "address": "0x450410"
- },
- {
- "name": "DestroyMenu",
- "address": "0x450414"
- },
- {
- "name": "SetClipboardData",
- "address": "0x450418"
- },
- {
- "name": "RegisterClassExW",
- "address": "0x45041c"
- },
- {
- "name": "LoadIconW",
- "address": "0x450420"
- },
- {
- "name": "GetWindowPlacement",
- "address": "0x450424"
- },
- {
- "name": "OffsetRect",
- "address": "0x450428"
- },
- {
- "name": "InvalidateRect",
- "address": "0x45042c"
- },
- {
- "name": "LoadMenuW",
- "address": "0x450430"
- },
- {
- "name": "GetWindowLongW",
- "address": "0x450434"
- },
- {
- "name": "AppendMenuW",
- "address": "0x450438"
- },
- {
- "name": "GetWindowTextW",
- "address": "0x45043c"
- },
- {
- "name": "PeekMessageW",
- "address": "0x450440"
- },
- {
- "name": "GetClassNameW",
- "address": "0x450444"
- },
- {
- "name": "EnableMenuItem",
- "address": "0x450448"
- },
- {
- "name": "EmptyClipboard",
- "address": "0x45044c"
- },
- {
- "name": "GetDlgItem",
- "address": "0x450450"
- },
- {
- "name": "SetWindowLongW",
- "address": "0x450454"
- },
- {
- "name": "EndDialog",
- "address": "0x450458"
- },
- {
- "name": "SendDlgItemMessageW",
- "address": "0x45045c"
- },
- {
- "name": "GetSysColor",
- "address": "0x450460"
- },
- {
- "name": "SetWindowPos",
- "address": "0x450464"
- },
- {
- "name": "CheckDlgButton",
- "address": "0x450468"
- },
- {
- "name": "EnumChildWindows",
- "address": "0x45046c"
- },
- {
- "name": "ShowWindow",
- "address": "0x450470"
- },
- {
- "name": "CreatePopupMenu",
- "address": "0x450474"
- },
- {
- "name": "GetSysColorBrush",
- "address": "0x450478"
- },
- {
- "name": "IsDlgButtonChecked",
- "address": "0x45047c"
- },
- {
- "name": "CreateDialogParamW",
- "address": "0x450480"
- },
- {
- "name": "DrawMenuBar",
- "address": "0x450484"
- },
- {
- "name": "GetActiveWindow",
- "address": "0x450488"
- },
- {
- "name": "GetMenuItemCount",
- "address": "0x45048c"
- },
- {
- "name": "CreateWindowExW",
- "address": "0x450490"
- },
- {
- "name": "SetMenuDefaultItem",
- "address": "0x450494"
- },
- {
- "name": "OpenClipboard",
- "address": "0x450498"
- },
- {
- "name": "DeferWindowPos",
- "address": "0x45049c"
- },
- {
- "name": "MessageBoxW",
- "address": "0x4504a0"
- },
- {
- "name": "ReleaseCapture",
- "address": "0x4504a4"
- },
- {
- "name": "BeginDeferWindowPos",
- "address": "0x4504a8"
- },
- {
- "name": "GetSystemMetrics",
- "address": "0x4504ac"
- },
- {
- "name": "IsWindowVisible",
- "address": "0x4504b0"
- },
- {
- "name": "GetDlgItemTextW",
- "address": "0x4504b4"
- },
- {
- "name": "SetDlgItemTextW",
- "address": "0x4504b8"
- },
- {
- "name": "SendMessageW",
- "address": "0x4504bc"
- },
- {
- "name": "MapWindowPoints",
- "address": "0x4504c0"
- },
- {
- "name": "UpdateWindow",
- "address": "0x4504c4"
- },
- {
- "name": "EnableWindow",
- "address": "0x4504c8"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "SetBkColor",
- "address": "0x4500dc"
- },
- {
- "name": "ExtTextOutW",
- "address": "0x4500e0"
- },
- {
- "name": "EndPage",
- "address": "0x4500e4"
- },
- {
- "name": "StartPage",
- "address": "0x4500e8"
- },
- {
- "name": "GetDeviceCaps",
- "address": "0x4500ec"
- },
- {
- "name": "SetMapMode",
- "address": "0x4500f0"
- },
- {
- "name": "SetTextColor",
- "address": "0x4500f4"
- },
- {
- "name": "CreateFontIndirectW",
- "address": "0x4500f8"
- },
- {
- "name": "SetBkMode",
- "address": "0x4500fc"
- },
- {
- "name": "SelectObject",
- "address": "0x450100"
- },
- {
- "name": "GetObjectW",
- "address": "0x450104"
- },
- {
- "name": "EndDoc",
- "address": "0x450108"
- },
- {
- "name": "GetStockObject",
- "address": "0x45010c"
- },
- {
- "name": "StartDocW",
- "address": "0x450110"
- }
- ],
- "dll": "GDI32.dll"
- },
- {
- "imports": [
- {
- "name": "GetSaveFileNameW",
- "address": "0x4500cc"
- },
- {
- "name": "GetOpenFileNameW",
- "address": "0x4500d0"
- },
- {
- "name": "PrintDlgW",
- "address": "0x4500d4"
- }
- ],
- "dll": "COMDLG32.dll"
- },
- {
- "imports": [
- {
- "name": "GetSecurityDescriptorLength",
- "address": "0x45001c"
- },
- {
- "name": "RegDeleteValueW",
- "address": "0x450020"
- },
- {
- "name": "RegCreateKeyW",
- "address": "0x450024"
- },
- {
- "name": "RegEnumValueW",
- "address": "0x450028"
- },
- {
- "name": "RegSetValueExW",
- "address": "0x45002c"
- },
- {
- "name": "ConvertStringSidToSidW",
- "address": "0x450030"
- },
- {
- "name": "ConvertStringSecurityDescriptorToSecurityDescriptorW",
- "address": "0x450034"
- },
- {
- "name": "GetLengthSid",
- "address": "0x450038"
- },
- {
- "name": "ConvertSidToStringSidW",
- "address": "0x45003c"
- },
- {
- "name": "ConvertSecurityDescriptorToStringSecurityDescriptorW",
- "address": "0x450040"
- },
- {
- "name": "RegQueryValueExW",
- "address": "0x450044"
- },
- {
- "name": "RegOpenKeyExA",
- "address": "0x450048"
- },
- {
- "name": "RegQueryValueExA",
- "address": "0x45004c"
- },
- {
- "name": "AdjustTokenPrivileges",
- "address": "0x450050"
- },
- {
- "name": "LookupPrivilegeValueW",
- "address": "0x450054"
- },
- {
- "name": "OpenProcessToken",
- "address": "0x450058"
- },
- {
- "name": "GetSecurityDescriptorDacl",
- "address": "0x45005c"
- },
- {
- "name": "GetSecurityDescriptorGroup",
- "address": "0x450060"
- },
- {
- "name": "IsValidSid",
- "address": "0x450064"
- },
- {
- "name": "GetSecurityDescriptorOwner",
- "address": "0x450068"
- },
- {
- "name": "GetSidIdentifierAuthority",
- "address": "0x45006c"
- },
- {
- "name": "GetSidSubAuthority",
- "address": "0x450070"
- },
- {
- "name": "MapGenericMask",
- "address": "0x450074"
- },
- {
- "name": "GetSidSubAuthorityCount",
- "address": "0x450078"
- },
- {
- "name": "EqualSid",
- "address": "0x45007c"
- },
- {
- "name": "GetAce",
- "address": "0x450080"
- },
- {
- "name": "LookupAccountSidW",
- "address": "0x450084"
- },
- {
- "name": "AllocateAndInitializeSid",
- "address": "0x450088"
- },
- {
- "name": "RegCloseKey",
- "address": "0x45008c"
- }
- ],
- "dll": "ADVAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "CommandLineToArgvW",
- "address": "0x450330"
- },
- {
- "name": "ShellExecuteW",
- "address": "0x450334"
- }
- ],
- "dll": "SHELL32.dll"
- },
- {
- "imports": [
- {
- "name": "CoInitialize",
- "address": "0x450504"
- },
- {
- "name": "CreateBindCtx",
- "address": "0x450508"
- },
- {
- "name": "CoUninitialize",
- "address": "0x45050c"
- },
- {
- "name": "CoCreateInstance",
- "address": "0x450510"
- },
- {
- "name": "IIDFromString",
- "address": "0x450514"
- },
- {
- "name": "StringFromGUID2",
- "address": "0x450518"
- }
- ],
- "dll": "ole32.dll"
- },
- {
- "imports": [
- {
- "name": "SafeArrayAccessData",
- "address": "0x4502ec"
- },
- {
- "name": "SystemTimeToVariantTime",
- "address": "0x4502f0"
- },
- {
- "name": "VariantTimeToSystemTime",
- "address": "0x4502f4"
- },
- {
- "name": "SafeArrayGetUBound",
- "address": "0x4502f8"
- },
- {
- "name": "SysFreeString",
- "address": "0x4502fc"
- },
- {
- "name": "SafeArrayGetElement",
- "address": "0x450300"
- },
- {
- "name": "VarDateFromStr",
- "address": "0x450304"
- },
- {
- "name": "VariantChangeType",
- "address": "0x450308"
- },
- {
- "name": "VariantInit",
- "address": "0x45030c"
- },
- {
- "name": "SysAllocStringByteLen",
- "address": "0x450310"
- },
- {
- "name": "VariantClear",
- "address": "0x450314"
- },
- {
- "name": "SafeArrayGetLBound",
- "address": "0x450318"
- },
- {
- "name": "SysStringLen",
- "address": "0x45031c"
- },
- {
- "name": "SysAllocString",
- "address": "0x450320"
- }
- ],
- "dll": "OLEAUT32.dll"
- },
- {
- "imports": [
- {
- "name": "ImageList_Draw",
- "address": "0x450094"
- },
- {
- "name": "CreateToolbarEx",
- "address": "0x450098"
- },
- {
- "name": "CreatePropertySheetPageW",
- "address": "0x45009c"
- },
- {
- "name": "ImageList_Create",
- "address": "0x4500a0"
- },
- {
- "name": "ImageList_ReplaceIcon",
- "address": "0x4500a4"
- },
- {
- "name": "ImageList_EndDrag",
- "address": "0x4500a8"
- },
- {
- "name": "ImageList_DragMove",
- "address": "0x4500ac"
- },
- {
- "name": "ImageList_BeginDrag",
- "address": "0x4500b0"
- },
- {
- "name": "ImageList_DragLeave",
- "address": "0x4500b4"
- },
- {
- "name": "ImageList_DragEnter",
- "address": "0x4500b8"
- },
- {
- "name": null,
- "address": "0x4500bc"
- },
- {
- "name": "CreateStatusWindowW",
- "address": "0x4500c0"
- },
- {
- "name": "PropertySheetW",
- "address": "0x4500c4"
- }
- ],
- "dll": "COMCTL32.dll"
- },
- {
- "imports": [
- {
- "name": null,
- "address": "0x450000"
- },
- {
- "name": null,
- "address": "0x450004"
- },
- {
- "name": null,
- "address": "0x450008"
- },
- {
- "name": null,
- "address": "0x45000c"
- },
- {
- "name": null,
- "address": "0x450010"
- },
- {
- "name": null,
- "address": "0x450014"
- }
- ],
- "dll": "ACTIVEDS.dll"
- },
- {
- "imports": [
- {
- "name": null,
- "address": "0x4504e0"
- },
- {
- "name": null,
- "address": "0x4504e4"
- },
- {
- "name": null,
- "address": "0x4504e8"
- },
- {
- "name": null,
- "address": "0x4504ec"
- },
- {
- "name": null,
- "address": "0x4504f0"
- },
- {
- "name": null,
- "address": "0x4504f4"
- },
- {
- "name": null,
- "address": "0x4504f8"
- },
- {
- "name": null,
- "address": "0x4504fc"
- }
- ],
- "dll": "WLDAP32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00081405",
- "overlay": {
- "size": "0x00001a58",
- "offset": "0x00073800"
- },
- "imagebase": "0x00400000",
- "reported_checksum": "0x00081405",
- "icon_hash": null,
- "entrypoint": "0x004149ec",
- "timestamp": "2012-06-30 09:47:15",
- "osversion": "5.0",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x0004f000",
- "entropy": "6.28",
- "raw_address": "0x00000400",
- "virtual_size": "0x0004eecc",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00050000",
- "size_of_data": "0x0000fc00",
- "entropy": "4.68",
- "raw_address": "0x0004f400",
- "virtual_size": "0x0000fc00",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00060000",
- "size_of_data": "0x0000a400",
- "entropy": "2.63",
- "raw_address": "0x0005f000",
- "virtual_size": "0x0000c5c0",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0006d000",
- "size_of_data": "0x0000a400",
- "entropy": "4.30",
- "raw_address": "0x00069400",
- "virtual_size": "0x0000a318",
- "characteristics_raw": "0x40000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0005e090",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x0000012c"
- },
- {
- "virtual_address": "0x0006d000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x0000a318"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00073800",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00001a58"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00050570",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x0000001c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0005af98",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000040"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00050000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000520"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "fc22a526c18358f987f144e2ac31d338",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "c:\\src\\ADExplorer\\Release\\ADExplorer.pdb",
- "imported_dll_count": 14,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement