VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Dropper
Downloader
Ransomware
|
Threat Names: |
Satana
Trojan.GenericKD.33533697
Trojan.GenericKD.33533023
...
|
WSHSetup.exe
Windows Exe (x86-32)
Created at 2020-03-12T14:44:00
Remarks (2/2)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "10 seconds" to "10 seconds" to reveal dormant functionality.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
0 | 512 Bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x48845e |
Size Of Code | 0x99200 |
Size Of Initialized Data | 0x47200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-03-08 09:21:22+00:00 |
Version Information (11)
»
Comments | Weizs Cost Pagers Bootmgr |
CompanyName | Crawler.com |
FileDescription | Weizs Cost Pagers Bootmgr |
FileVersion | 7.3.98.196 |
InternalName | ComparevalidatorIgamerefreshable |
Languages | English |
LegalCopyright | Copyright © 2000 - 2014 KG and its Licensors Crawler.com |
LegalTrademarks | Copyright © 2000 - 2014 KG and its Licensors Crawler.com |
OriginalFilename | ComparevalidatorIgamerefreshable.exe |
ProductName | ComparevalidatorIgamerefreshable |
ProductVersion | 7.3.98.196 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x99100 | 0x99200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.23 |
.rdata | 0x49b000 | 0x1c33e | 0x1c400 | 0x99600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.75 |
.data | 0x4b8000 | 0x7804 | 0x3e00 | 0xb5a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.07 |
.rsrc | 0x4c0000 | 0x1e800 | 0x1e800 | 0xb9800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.22 |
.reloc | 0x4df000 | 0x8632 | 0x8800 | 0xd8000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.87 |
Imports (20)
»
KERNEL32.dll (108)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FreeEnvironmentStringsW | 0x0 | 0x49b130 | 0xb56b4 | 0xb3cb4 | 0x161 |
LoadLibraryW | 0x0 | 0x49b134 | 0xb56b8 | 0xb3cb8 | 0x33f |
GetStringTypeW | 0x0 | 0x49b138 | 0xb56bc | 0xb3cbc | 0x269 |
HeapCreate | 0x0 | 0x49b13c | 0xb56c0 | 0xb3cc0 | 0x2cd |
HeapSize | 0x0 | 0x49b140 | 0xb56c4 | 0xb3cc4 | 0x2d4 |
SetHandleCount | 0x0 | 0x49b144 | 0xb56c8 | 0xb3cc8 | 0x46f |
FlushFileBuffers | 0x0 | 0x49b148 | 0xb56cc | 0xb3ccc | 0x157 |
GetConsoleCP | 0x0 | 0x49b14c | 0xb56d0 | 0xb3cd0 | 0x19a |
LCMapStringW | 0x0 | 0x49b150 | 0xb56d4 | 0xb3cd4 | 0x32d |
IsValidCodePage | 0x0 | 0x49b154 | 0xb56d8 | 0xb3cd8 | 0x30a |
GetOEMCP | 0x0 | 0x49b158 | 0xb56dc | 0xb3cdc | 0x237 |
GetCPInfo | 0x0 | 0x49b15c | 0xb56e0 | 0xb3ce0 | 0x172 |
IsProcessorFeaturePresent | 0x0 | 0x49b160 | 0xb56e4 | 0xb3ce4 | 0x304 |
TerminateProcess | 0x0 | 0x49b164 | 0xb56e8 | 0xb3ce8 | 0x4c0 |
IsDebuggerPresent | 0x0 | 0x49b168 | 0xb56ec | 0xb3cec | 0x300 |
SetUnhandledExceptionFilter | 0x0 | 0x49b16c | 0xb56f0 | 0xb3cf0 | 0x4a5 |
UnhandledExceptionFilter | 0x0 | 0x49b170 | 0xb56f4 | 0xb3cf4 | 0x4d3 |
GetEnvironmentStringsW | 0x0 | 0x49b174 | 0xb56f8 | 0xb3cf8 | 0x1da |
TlsFree | 0x0 | 0x49b178 | 0xb56fc | 0xb3cfc | 0x4c6 |
GetCurrentProcessId | 0x0 | 0x49b17c | 0xb5700 | 0xb3d00 | 0x1c1 |
TlsGetValue | 0x0 | 0x49b180 | 0xb5704 | 0xb3d04 | 0x4c7 |
TlsAlloc | 0x0 | 0x49b184 | 0xb5708 | 0xb3d08 | 0x4c5 |
GetStartupInfoW | 0x0 | 0x49b188 | 0xb570c | 0xb3d0c | 0x263 |
HeapSetInformation | 0x0 | 0x49b18c | 0xb5710 | 0xb3d10 | 0x2d3 |
GetCommandLineA | 0x0 | 0x49b190 | 0xb5714 | 0xb3d14 | 0x186 |
VirtualQuery | 0x0 | 0x49b194 | 0xb5718 | 0xb3d18 | 0x4f1 |
GetSystemInfo | 0x0 | 0x49b198 | 0xb571c | 0xb3d1c | 0x273 |
GetModuleHandleW | 0x0 | 0x49b19c | 0xb5720 | 0xb3d20 | 0x218 |
VirtualAlloc | 0x0 | 0x49b1a0 | 0xb5724 | 0xb3d24 | 0x4e9 |
VirtualProtect | 0x0 | 0x49b1a4 | 0xb5728 | 0xb3d28 | 0x4ef |
GetModuleFileNameW | 0x0 | 0x49b1a8 | 0xb572c | 0xb3d2c | 0x214 |
GetStdHandle | 0x0 | 0x49b1ac | 0xb5730 | 0xb3d30 | 0x264 |
WriteConsoleW | 0x0 | 0x49b1b0 | 0xb5734 | 0xb3d34 | 0x524 |
HeapReAlloc | 0x0 | 0x49b1b4 | 0xb5738 | 0xb3d38 | 0x2d2 |
HeapFree | 0x0 | 0x49b1b8 | 0xb573c | 0xb3d3c | 0x2cf |
HeapAlloc | 0x0 | 0x49b1bc | 0xb5740 | 0xb3d40 | 0x2cb |
EncodePointer | 0x0 | 0x49b1c0 | 0xb5744 | 0xb3d44 | 0xea |
DecodePointer | 0x0 | 0x49b1c4 | 0xb5748 | 0xb3d48 | 0xca |
RtlUnwind | 0x0 | 0x49b1c8 | 0xb574c | 0xb3d4c | 0x418 |
SetStdHandle | 0x0 | 0x49b1cc | 0xb5750 | 0xb3d50 | 0x487 |
LocalFree | 0x0 | 0x49b1d0 | 0xb5754 | 0xb3d54 | 0x348 |
SetLastError | 0x0 | 0x49b1d4 | 0xb5758 | 0xb3d58 | 0x473 |
QueryPerformanceCounter | 0x0 | 0x49b1d8 | 0xb575c | 0xb3d5c | 0x3a7 |
FileTimeToSystemTime | 0x0 | 0x49b1dc | 0xb5760 | 0xb3d60 | 0x125 |
SystemTimeToTzSpecificLocalTime | 0x0 | 0x49b1e0 | 0xb5764 | 0xb3d64 | 0x4be |
GetSystemTimeAsFileTime | 0x0 | 0x49b1e4 | 0xb5768 | 0xb3d68 | 0x279 |
TlsSetValue | 0x0 | 0x49b1e8 | 0xb576c | 0xb3d6c | 0x4c8 |
CreateFileW | 0x0 | 0x49b1ec | 0xb5770 | 0xb3d70 | 0x8f |
GetCommState | 0x0 | 0x49b1f0 | 0xb5774 | 0xb3d74 | 0x184 |
SetErrorMode | 0x0 | 0x49b1f4 | 0xb5778 | 0xb3d78 | 0x458 |
GetLogicalDrives | 0x0 | 0x49b1f8 | 0xb577c | 0xb3d7c | 0x209 |
GetVolumePathNameW | 0x0 | 0x49b1fc | 0xb5780 | 0xb3d80 | 0x2ab |
GetVolumeNameForVolumeMountPointW | 0x0 | 0x49b200 | 0xb5784 | 0xb3d84 | 0x2a9 |
GetComputerNameExW | 0x0 | 0x49b204 | 0xb5788 | 0xb3d88 | 0x18e |
GetConsoleMode | 0x0 | 0x49b208 | 0xb578c | 0xb3d8c | 0x1ac |
CreateEventA | 0x0 | 0x49b20c | 0xb5790 | 0xb3d90 | 0x82 |
WaitForSingleObject | 0x0 | 0x49b210 | 0xb5794 | 0xb3d94 | 0x4f9 |
IsDBCSLeadByte | 0x0 | 0x49b214 | 0xb5798 | 0xb3d98 | 0x2fe |
lstrcmpiA | 0x0 | 0x49b218 | 0xb579c | 0xb3d9c | 0x544 |
LoadLibraryExA | 0x0 | 0x49b21c | 0xb57a0 | 0xb3da0 | 0x33d |
lstrlenA | 0x0 | 0x49b220 | 0xb57a4 | 0xb3da4 | 0x54d |
lstrlenW | 0x0 | 0x49b224 | 0xb57a8 | 0xb3da8 | 0x54e |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x49b228 | 0xb57ac | 0xb3dac | 0x2e3 |
RaiseException | 0x0 | 0x49b22c | 0xb57b0 | 0xb3db0 | 0x3b1 |
FreeLibrary | 0x0 | 0x49b230 | 0xb57b4 | 0xb3db4 | 0x162 |
WriteFile | 0x0 | 0x49b234 | 0xb57b8 | 0xb3db8 | 0x525 |
SetFileTime | 0x0 | 0x49b238 | 0xb57bc | 0xb3dbc | 0x46a |
CreateDirectoryA | 0x0 | 0x49b23c | 0xb57c0 | 0xb3dc0 | 0x7c |
DosDateTimeToFileTime | 0x0 | 0x49b240 | 0xb57c4 | 0xb3dc4 | 0xe4 |
SystemTimeToFileTime | 0x0 | 0x49b244 | 0xb57c8 | 0xb3dc8 | 0x4bd |
GetCurrentProcess | 0x0 | 0x49b248 | 0xb57cc | 0xb3dcc | 0x1c0 |
DuplicateHandle | 0x0 | 0x49b24c | 0xb57d0 | 0xb3dd0 | 0xe8 |
GetFileType | 0x0 | 0x49b250 | 0xb57d4 | 0xb3dd4 | 0x1f3 |
SetFilePointer | 0x0 | 0x49b254 | 0xb57d8 | 0xb3dd8 | 0x466 |
ExitProcess | 0x0 | 0x49b258 | 0xb57dc | 0xb3ddc | 0x119 |
GetCurrentDirectoryA | 0x0 | 0x49b25c | 0xb57e0 | 0xb3de0 | 0x1be |
GetModuleFileNameA | 0x0 | 0x49b260 | 0xb57e4 | 0xb3de4 | 0x213 |
FindResourceA | 0x0 | 0x49b264 | 0xb57e8 | 0xb3de8 | 0x14b |
LoadResource | 0x0 | 0x49b268 | 0xb57ec | 0xb3dec | 0x341 |
FreeResource | 0x0 | 0x49b26c | 0xb57f0 | 0xb3df0 | 0x165 |
SizeofResource | 0x0 | 0x49b270 | 0xb57f4 | 0xb3df4 | 0x4b1 |
LockResource | 0x0 | 0x49b274 | 0xb57f8 | 0xb3df8 | 0x354 |
GetLastError | 0x0 | 0x49b278 | 0xb57fc | 0xb3dfc | 0x202 |
GetModuleHandleA | 0x0 | 0x49b27c | 0xb5800 | 0xb3e00 | 0x215 |
WideCharToMultiByte | 0x0 | 0x49b280 | 0xb5804 | 0xb3e04 | 0x511 |
GlobalAlloc | 0x0 | 0x49b284 | 0xb5808 | 0xb3e08 | 0x2b3 |
GlobalLock | 0x0 | 0x49b288 | 0xb580c | 0xb3e0c | 0x2be |
GlobalUnlock | 0x0 | 0x49b28c | 0xb5810 | 0xb3e10 | 0x2c5 |
CreateFileA | 0x0 | 0x49b290 | 0xb5814 | 0xb3e14 | 0x88 |
GetFileSize | 0x0 | 0x49b294 | 0xb5818 | 0xb3e18 | 0x1f0 |
CloseHandle | 0x0 | 0x49b298 | 0xb581c | 0xb3e1c | 0x52 |
ReadFile | 0x0 | 0x49b29c | 0xb5820 | 0xb3e20 | 0x3c0 |
InterlockedIncrement | 0x0 | 0x49b2a0 | 0xb5824 | 0xb3e24 | 0x2ef |
InterlockedDecrement | 0x0 | 0x49b2a4 | 0xb5828 | 0xb3e28 | 0x2eb |
LoadLibraryA | 0x0 | 0x49b2a8 | 0xb582c | 0xb3e2c | 0x33c |
GetProcAddress | 0x0 | 0x49b2ac | 0xb5830 | 0xb3e30 | 0x245 |
GetACP | 0x0 | 0x49b2b0 | 0xb5834 | 0xb3e34 | 0x168 |
MultiByteToWideChar | 0x0 | 0x49b2b4 | 0xb5838 | 0xb3e38 | 0x367 |
MulDiv | 0x0 | 0x49b2b8 | 0xb583c | 0xb3e3c | 0x366 |
GetTickCount | 0x0 | 0x49b2bc | 0xb5840 | 0xb3e40 | 0x293 |
GetLocalTime | 0x0 | 0x49b2c0 | 0xb5844 | 0xb3e44 | 0x203 |
LeaveCriticalSection | 0x0 | 0x49b2c4 | 0xb5848 | 0xb3e48 | 0x339 |
EnterCriticalSection | 0x0 | 0x49b2c8 | 0xb584c | 0xb3e4c | 0xee |
DeleteCriticalSection | 0x0 | 0x49b2cc | 0xb5850 | 0xb3e50 | 0xd1 |
GetVersionExA | 0x0 | 0x49b2d0 | 0xb5854 | 0xb3e54 | 0x2a3 |
InitializeCriticalSection | 0x0 | 0x49b2d4 | 0xb5858 | 0xb3e58 | 0x2e2 |
Sleep | 0x0 | 0x49b2d8 | 0xb585c | 0xb3e5c | 0x4b2 |
GetCurrentThreadId | 0x0 | 0x49b2dc | 0xb5860 | 0xb3e60 | 0x1c5 |
USER32.dll (94)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | 0x0 | 0x49b31c | 0xb58a0 | 0xb3ea0 | 0x20e |
SetWindowRgn | 0x0 | 0x49b320 | 0xb58a4 | 0xb3ea4 | 0x2c7 |
wvsprintfA | 0x0 | 0x49b324 | 0xb58a8 | 0xb3ea8 | 0x334 |
OffsetRect | 0x0 | 0x49b328 | 0xb58ac | 0xb3eac | 0x225 |
SystemParametersInfoA | 0x0 | 0x49b32c | 0xb58b0 | 0xb3eb0 | 0x2eb |
CharPrevA | 0x0 | 0x49b330 | 0xb58b4 | 0xb3eb4 | 0x32 |
DrawTextA | 0x0 | 0x49b334 | 0xb58b8 | 0xb3eb8 | 0xcd |
UnionRect | 0x0 | 0x49b338 | 0xb58bc | 0xb3ebc | 0x301 |
GetActiveWindow | 0x0 | 0x49b33c | 0xb58c0 | 0xb3ec0 | 0x100 |
GetUpdateRect | 0x0 | 0x49b340 | 0xb58c4 | 0xb3ec4 | 0x187 |
IsWindowVisible | 0x0 | 0x49b344 | 0xb58c8 | 0xb3ec8 | 0x1e0 |
SetRect | 0x0 | 0x49b348 | 0xb58cc | 0xb3ecc | 0x2ae |
MessageBoxW | 0x0 | 0x49b34c | 0xb58d0 | 0xb3ed0 | 0x215 |
GetDlgItem | 0x0 | 0x49b350 | 0xb58d4 | 0xb3ed4 | 0x127 |
CheckMenuRadioItem | 0x0 | 0x49b354 | 0xb58d8 | 0xb3ed8 | 0x40 |
GetDCEx | 0x0 | 0x49b358 | 0xb58dc | 0xb3edc | 0x122 |
IsZoomed | 0x0 | 0x49b35c | 0xb58e0 | 0xb3ee0 | 0x1e2 |
GetWindowRect | 0x0 | 0x49b360 | 0xb58e4 | 0xb3ee4 | 0x19c |
UpdateWindow | 0x0 | 0x49b364 | 0xb58e8 | 0xb3ee8 | 0x311 |
MoveWindow | 0x0 | 0x49b368 | 0xb58ec | 0xb3eec | 0x21b |
DestroyWindow | 0x0 | 0x49b36c | 0xb58f0 | 0xb3ef0 | 0xa6 |
ReleaseDC | 0x0 | 0x49b370 | 0xb58f4 | 0xb3ef4 | 0x265 |
GetDC | 0x0 | 0x49b374 | 0xb58f8 | 0xb3ef8 | 0x121 |
ReleaseCapture | 0x0 | 0x49b378 | 0xb58fc | 0xb3efc | 0x264 |
SetCapture | 0x0 | 0x49b37c | 0xb5900 | 0xb3f00 | 0x280 |
FillRect | 0x0 | 0x49b380 | 0xb5904 | 0xb3f04 | 0xf6 |
LockWindowUpdate | 0x0 | 0x49b384 | 0xb5908 | 0xb3f08 | 0x1fd |
SetClassLongA | 0x0 | 0x49b388 | 0xb590c | 0xb3f0c | 0x283 |
GetClassLongA | 0x0 | 0x49b38c | 0xb5910 | 0xb3f10 | 0x10f |
AttachThreadInput | 0x0 | 0x49b390 | 0xb5914 | 0xb3f14 | 0xc |
CopyImage | 0x0 | 0x49b394 | 0xb5918 | 0xb3f18 | 0x54 |
SetScrollPos | 0x0 | 0x49b398 | 0xb591c | 0xb3f1c | 0x2b1 |
AppendMenuW | 0x0 | 0x49b39c | 0xb5920 | 0xb3f20 | 0xa |
TrackPopupMenu | 0x0 | 0x49b3a0 | 0xb5924 | 0xb3f24 | 0x2f6 |
InvalidateRect | 0x0 | 0x49b3a4 | 0xb5928 | 0xb3f28 | 0x1be |
InvalidateRgn | 0x0 | 0x49b3a8 | 0xb592c | 0xb3f2c | 0x1bf |
DefWindowProcA | 0x0 | 0x49b3ac | 0xb5930 | 0xb3f30 | 0x9b |
GetMenuCheckMarkDimensions | 0x0 | 0x49b3b0 | 0xb5934 | 0xb3f34 | 0x14d |
GetClientRect | 0x0 | 0x49b3b4 | 0xb5938 | 0xb3f38 | 0x114 |
SetTimer | 0x0 | 0x49b3b8 | 0xb593c | 0xb3f3c | 0x2bb |
EndPaint | 0x0 | 0x49b3bc | 0xb5940 | 0xb3f40 | 0xdc |
BeginPaint | 0x0 | 0x49b3c0 | 0xb5944 | 0xb3f44 | 0xe |
PtInRect | 0x0 | 0x49b3c4 | 0xb5948 | 0xb3f48 | 0x240 |
ScreenToClient | 0x0 | 0x49b3c8 | 0xb594c | 0xb3f4c | 0x26d |
ClientToScreen | 0x0 | 0x49b3cc | 0xb5950 | 0xb3f50 | 0x47 |
GetGUIThreadInfo | 0x0 | 0x49b3d0 | 0xb5954 | 0xb3f54 | 0x12e |
ShowWindow | 0x0 | 0x49b3d4 | 0xb5958 | 0xb3f58 | 0x2df |
SetFocus | 0x0 | 0x49b3d8 | 0xb595c | 0xb3f5c | 0x292 |
SetCursor | 0x0 | 0x49b3dc | 0xb5960 | 0xb3f60 | 0x288 |
LoadCursorA | 0x0 | 0x49b3e0 | 0xb5964 | 0xb3f64 | 0x1e8 |
CharNextA | 0x0 | 0x49b3e4 | 0xb5968 | 0xb3f68 | 0x2f |
IntersectRect | 0x0 | 0x49b3e8 | 0xb596c | 0xb3f6c | 0x1bd |
GetParent | 0x0 | 0x49b3ec | 0xb5970 | 0xb3f70 | 0x164 |
GetMonitorInfoA | 0x0 | 0x49b3f0 | 0xb5974 | 0xb3f74 | 0x15e |
MonitorFromWindow | 0x0 | 0x49b3f4 | 0xb5978 | 0xb3f78 | 0x21a |
MapWindowPoints | 0x0 | 0x49b3f8 | 0xb597c | 0xb3f7c | 0x209 |
GetFocus | 0x0 | 0x49b3fc | 0xb5980 | 0xb3f80 | 0x12c |
GetCursorPos | 0x0 | 0x49b400 | 0xb5984 | 0xb3f84 | 0x120 |
SendMessageA | 0x0 | 0x49b404 | 0xb5988 | 0xb3f88 | 0x277 |
SetWindowPos | 0x0 | 0x49b408 | 0xb598c | 0xb3f8c | 0x2c6 |
IsRectEmpty | 0x0 | 0x49b40c | 0xb5990 | 0xb3f90 | 0x1d4 |
GetWindowTextLengthA | 0x0 | 0x49b410 | 0xb5994 | 0xb3f94 | 0x1a1 |
EnableWindow | 0x0 | 0x49b414 | 0xb5998 | 0xb3f98 | 0xd8 |
SetWindowTextA | 0x0 | 0x49b418 | 0xb599c | 0xb3f9c | 0x2ca |
GetCaretPos | 0x0 | 0x49b41c | 0xb59a0 | 0xb3fa0 | 0x10a |
GetCaretBlinkTime | 0x0 | 0x49b420 | 0xb59a4 | 0xb3fa4 | 0x109 |
GetWindowTextA | 0x0 | 0x49b424 | 0xb59a8 | 0xb3fa8 | 0x1a0 |
CreateCaret | 0x0 | 0x49b428 | 0xb59ac | 0xb3fac | 0x59 |
HideCaret | 0x0 | 0x49b42c | 0xb59b0 | 0xb3fb0 | 0x1a9 |
ShowCaret | 0x0 | 0x49b430 | 0xb59b4 | 0xb3fb4 | 0x2d9 |
SetCaretPos | 0x0 | 0x49b434 | 0xb59b8 | 0xb3fb8 | 0x282 |
GetSysColor | 0x0 | 0x49b438 | 0xb59bc | 0xb3fbc | 0x17b |
GetKeyState | 0x0 | 0x49b43c | 0xb59c0 | 0xb3fc0 | 0x13d |
GetWindowLongA | 0x0 | 0x49b440 | 0xb59c4 | 0xb3fc4 | 0x195 |
KillTimer | 0x0 | 0x49b444 | 0xb59c8 | 0xb3fc8 | 0x1e3 |
PostMessageA | 0x0 | 0x49b448 | 0xb59cc | 0xb3fcc | 0x235 |
SetPropA | 0x0 | 0x49b44c | 0xb59d0 | 0xb3fd0 | 0x2ac |
GetPropA | 0x0 | 0x49b450 | 0xb59d4 | 0xb3fd4 | 0x16a |
CallWindowProcA | 0x0 | 0x49b454 | 0xb59d8 | 0xb3fd8 | 0x1d |
GetClassInfoExA | 0x0 | 0x49b458 | 0xb59dc | 0xb3fdc | 0x10c |
CreateWindowExA | 0x0 | 0x49b45c | 0xb59e0 | 0xb3fe0 | 0x6d |
SetWindowLongA | 0x0 | 0x49b460 | 0xb59e4 | 0xb3fe4 | 0x2c3 |
IsWindow | 0x0 | 0x49b464 | 0xb59e8 | 0xb3fe8 | 0x1db |
DispatchMessageA | 0x0 | 0x49b468 | 0xb59ec | 0xb3fec | 0xae |
TranslateMessage | 0x0 | 0x49b46c | 0xb59f0 | 0xb3ff0 | 0x2fc |
GetMessageA | 0x0 | 0x49b470 | 0xb59f4 | 0xb3ff4 | 0x159 |
DialogBoxIndirectParamA | 0x0 | 0x49b474 | 0xb59f8 | 0xb3ff8 | 0xa8 |
EnableMenuItem | 0x0 | 0x49b478 | 0xb59fc | 0xb3ffc | 0xd6 |
GetSystemMenu | 0x0 | 0x49b47c | 0xb5a00 | 0xb4000 | 0x17d |
CreateAcceleratorTableA | 0x0 | 0x49b480 | 0xb5a04 | 0xb4004 | 0x57 |
RegisterClassExA | 0x0 | 0x49b484 | 0xb5a08 | 0xb4008 | 0x24c |
RegisterClassA | 0x0 | 0x49b488 | 0xb5a0c | 0xb400c | 0x24b |
GetWindow | 0x0 | 0x49b48c | 0xb5a10 | 0xb4010 | 0x18e |
IsIconic | 0x0 | 0x49b490 | 0xb5a14 | 0xb4014 | 0x1d1 |
GDI32.dll (45)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetStockObject | 0x0 | 0x49b05c | 0xb55e0 | 0xb3be0 | 0x20d |
CreateFontIndirectA | 0x0 | 0x49b060 | 0xb55e4 | 0xb3be4 | 0x3d |
GetObjectA | 0x0 | 0x49b064 | 0xb55e8 | 0xb3be8 | 0x1fb |
SetBkMode | 0x0 | 0x49b068 | 0xb55ec | 0xb3bec | 0x27f |
SetTextColor | 0x0 | 0x49b06c | 0xb55f0 | 0xb3bf0 | 0x2a6 |
CreatePatternBrush | 0x0 | 0x49b070 | 0xb55f4 | 0xb3bf4 | 0x4a |
CreateSolidBrush | 0x0 | 0x49b074 | 0xb55f8 | 0xb3bf8 | 0x54 |
DeleteObject | 0x0 | 0x49b078 | 0xb55fc | 0xb3bfc | 0xe6 |
GetDeviceCaps | 0x0 | 0x49b07c | 0xb5600 | 0xb3c00 | 0x1cb |
RoundRect | 0x0 | 0x49b080 | 0xb5604 | 0xb3c04 | 0x26a |
TextOutA | 0x0 | 0x49b084 | 0xb5608 | 0xb3c08 | 0x2b8 |
CreatePen | 0x0 | 0x49b088 | 0xb560c | 0xb3c0c | 0x4b |
GetCharABCWidthsA | 0x0 | 0x49b08c | 0xb5610 | 0xb3c10 | 0x1b1 |
ExtSelectClipRgn | 0x0 | 0x49b090 | 0xb5614 | 0xb3c14 | 0x136 |
GdiFlush | 0x0 | 0x49b094 | 0xb5618 | 0xb3c18 | 0x175 |
CreateFontA | 0x0 | 0x49b098 | 0xb561c | 0xb3c1c | 0x3c |
Escape | 0x0 | 0x49b09c | 0xb5620 | 0xb3c20 | 0x12e |
ExtEscape | 0x0 | 0x49b0a0 | 0xb5624 | 0xb3c24 | 0x134 |
EnumObjects | 0x0 | 0x49b0a4 | 0xb5628 | 0xb3c28 | 0x12c |
CreateDCA | 0x0 | 0x49b0a8 | 0xb562c | 0xb3c2c | 0x31 |
SetDCPenColor | 0x0 | 0x49b0ac | 0xb5630 | 0xb3c30 | 0x286 |
DeleteDC | 0x0 | 0x49b0b0 | 0xb5634 | 0xb3c34 | 0xe3 |
SetWindowOrgEx | 0x0 | 0x49b0b4 | 0xb5638 | 0xb3c38 | 0x2ad |
Rectangle | 0x0 | 0x49b0b8 | 0xb563c | 0xb3c3c | 0x25f |
RestoreDC | 0x0 | 0x49b0bc | 0xb5640 | 0xb3c40 | 0x269 |
BitBlt | 0x0 | 0x49b0c0 | 0xb5644 | 0xb3c44 | 0x13 |
SaveDC | 0x0 | 0x49b0c4 | 0xb5648 | 0xb3c48 | 0x270 |
SelectObject | 0x0 | 0x49b0c8 | 0xb564c | 0xb3c4c | 0x277 |
CreateCompatibleBitmap | 0x0 | 0x49b0cc | 0xb5650 | 0xb3c50 | 0x2f |
CreateCompatibleDC | 0x0 | 0x49b0d0 | 0xb5654 | 0xb3c54 | 0x30 |
GetTextMetricsA | 0x0 | 0x49b0d4 | 0xb5658 | 0xb3c58 | 0x225 |
SelectClipRgn | 0x0 | 0x49b0d8 | 0xb565c | 0xb3c5c | 0x275 |
CombineRgn | 0x0 | 0x49b0dc | 0xb5660 | 0xb3c60 | 0x22 |
CreateRectRgnIndirect | 0x0 | 0x49b0e0 | 0xb5664 | 0xb3c64 | 0x50 |
GetClipBox | 0x0 | 0x49b0e4 | 0xb5668 | 0xb3c68 | 0x1c0 |
CreateRoundRectRgn | 0x0 | 0x49b0e8 | 0xb566c | 0xb3c6c | 0x51 |
StretchBlt | 0x0 | 0x49b0ec | 0xb5670 | 0xb3c70 | 0x2b3 |
SetStretchBltMode | 0x0 | 0x49b0f0 | 0xb5674 | 0xb3c74 | 0x2a2 |
ExtTextOutA | 0x0 | 0x49b0f4 | 0xb5678 | 0xb3c78 | 0x137 |
SetBkColor | 0x0 | 0x49b0f8 | 0xb567c | 0xb3c7c | 0x27e |
LineTo | 0x0 | 0x49b0fc | 0xb5680 | 0xb3c80 | 0x236 |
MoveToEx | 0x0 | 0x49b100 | 0xb5684 | 0xb3c84 | 0x23a |
GetTextExtentPoint32A | 0x0 | 0x49b104 | 0xb5688 | 0xb3c88 | 0x21d |
CreateDIBSection | 0x0 | 0x49b108 | 0xb568c | 0xb3c8c | 0x35 |
CreatePenIndirect | 0x0 | 0x49b10c | 0xb5690 | 0xb3c90 | 0x4c |
COMDLG32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetOpenFileNameA | 0x0 | 0x49b04c | 0xb55d0 | 0xb3bd0 | 0xb |
ADVAPI32.dll (13)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MakeAbsoluteSD2 | 0x0 | 0x49b000 | 0xb5584 | 0xb3b84 | 0x1e1 |
RegCloseKey | 0x0 | 0x49b004 | 0xb5588 | 0xb3b88 | 0x230 |
RegDeleteKeyA | 0x0 | 0x49b008 | 0xb558c | 0xb3b8c | 0x23d |
RegCreateKeyExA | 0x0 | 0x49b00c | 0xb5590 | 0xb3b90 | 0x238 |
RegOpenKeyExA | 0x0 | 0x49b010 | 0xb5594 | 0xb3b94 | 0x260 |
RegEnumKeyExA | 0x0 | 0x49b014 | 0xb5598 | 0xb3b98 | 0x24e |
IsValidSecurityDescriptor | 0x0 | 0x49b018 | 0xb559c | 0xb3b9c | 0x185 |
LookupPrivilegeValueW | 0x0 | 0x49b01c | 0xb55a0 | 0xb3ba0 | 0x197 |
LsaAddAccountRights | 0x0 | 0x49b020 | 0xb55a4 | 0xb3ba4 | 0x19a |
LookupPrivilegeNameA | 0x0 | 0x49b024 | 0xb55a8 | 0xb3ba8 | 0x194 |
RegSetValueExA | 0x0 | 0x49b028 | 0xb55ac | 0xb3bac | 0x27d |
RegQueryInfoKeyW | 0x0 | 0x49b02c | 0xb55b0 | 0xb3bb0 | 0x268 |
RegDeleteValueA | 0x0 | 0x49b030 | 0xb55b4 | 0xb3bb4 | 0x247 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteA | 0x0 | 0x49b314 | 0xb5898 | 0xb3e98 | 0x11e |
ole32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OleLockRunning | 0x0 | 0x49b55c | 0xb5ae0 | 0xb40e0 | 0x138 |
CoInitialize | 0x0 | 0x49b560 | 0xb5ae4 | 0xb40e4 | 0x3e |
CoUninitialize | 0x0 | 0x49b564 | 0xb5ae8 | 0xb40e8 | 0x6c |
CoTaskMemRealloc | 0x0 | 0x49b568 | 0xb5aec | 0xb40ec | 0x69 |
CoTaskMemAlloc | 0x0 | 0x49b56c | 0xb5af0 | 0xb40f0 | 0x67 |
CoTaskMemFree | 0x0 | 0x49b570 | 0xb5af4 | 0xb40f4 | 0x68 |
OleInitialize | 0x0 | 0x49b574 | 0xb5af8 | 0xb40f8 | 0x132 |
OleUninitialize | 0x0 | 0x49b578 | 0xb5afc | 0xb40fc | 0x149 |
CreateStreamOnHGlobal | 0x0 | 0x49b57c | 0xb5b00 | 0xb4100 | 0x86 |
CoCreateInstance | 0x0 | 0x49b580 | 0xb5b04 | 0xb4104 | 0x10 |
CLSIDFromString | 0x0 | 0x49b584 | 0xb5b08 | 0xb4108 | 0x8 |
CLSIDFromProgID | 0x0 | 0x49b588 | 0xb5b0c | 0xb410c | 0x6 |
OLEAUT32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
BSTR_UserSize | 0x11b | 0x49b2f4 | 0xb5878 | 0xb3e78 | - |
VarUI4FromStr | 0x115 | 0x49b2f8 | 0xb587c | 0xb3e7c | - |
SysAllocStringLen | 0x4 | 0x49b2fc | 0xb5880 | 0xb3e80 | - |
VariantInit | 0x8 | 0x49b300 | 0xb5884 | 0xb3e84 | - |
VariantClear | 0x9 | 0x49b304 | 0xb5888 | 0xb3e88 | - |
SysFreeString | 0x6 | 0x49b308 | 0xb588c | 0xb3e8c | - |
SysAllocString | 0x2 | 0x49b30c | 0xb5890 | 0xb3e90 | - |
gdiplus.dll (41)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GdipGetImageWidth | 0x0 | 0x49b4b4 | 0xb5a38 | 0xb4038 | 0x12c |
GdipGetImageHeight | 0x0 | 0x49b4b8 | 0xb5a3c | 0xb403c | 0x122 |
GdipGetPropertyItemSize | 0x0 | 0x49b4bc | 0xb5a40 | 0xb4040 | 0x177 |
GdipGetPropertyItem | 0x0 | 0x49b4c0 | 0xb5a44 | 0xb4044 | 0x176 |
GdipGetFamily | 0x0 | 0x49b4c4 | 0xb5a48 | 0xb4048 | 0x109 |
GdipCreateFontFromDC | 0x0 | 0x49b4c8 | 0xb5a4c | 0xb404c | 0x58 |
GdipCloneBrush | 0x0 | 0x49b4cc | 0xb5a50 | 0xb4050 | 0x32 |
GdipSetTextRenderingHint | 0x0 | 0x49b4d0 | 0xb5a54 | 0xb4054 | 0x254 |
GdipCreateStringFormat | 0x0 | 0x49b4d4 | 0xb5a58 | 0xb4058 | 0x84 |
GdipSetStringFormatLineAlign | 0x0 | 0x49b4d8 | 0xb5a5c | 0xb405c | 0x24f |
GdipSetStringFormatAlign | 0x0 | 0x49b4dc | 0xb5a60 | 0xb4060 | 0x24b |
GdipCreateLineBrushI | 0x0 | 0x49b4e0 | 0xb5a64 | 0xb4064 | 0x69 |
GdipCreateBitmapFromScan0 | 0x0 | 0x49b4e4 | 0xb5a68 | 0xb4068 | 0x50 |
GdipGetImageGraphicsContext | 0x0 | 0x49b4e8 | 0xb5a6c | 0xb406c | 0x121 |
GdipSetSmoothingMode | 0x0 | 0x49b4ec | 0xb5a70 | 0xb4070 | 0x249 |
GdipSetCompositingQuality | 0x0 | 0x49b4f0 | 0xb5a74 | 0xb4074 | 0x203 |
GdipSetInterpolationMode | 0x0 | 0x49b4f4 | 0xb5a78 | 0xb4078 | 0x218 |
GdipSetPixelOffsetMode | 0x0 | 0x49b4f8 | 0xb5a7c | 0xb407c | 0x246 |
GdipDrawString | 0x0 | 0x49b4fc | 0xb5a80 | 0xb4080 | 0xc8 |
GdipGraphicsClear | 0x0 | 0x49b500 | 0xb5a84 | 0xb4084 | 0x195 |
GdipDrawImage | 0x0 | 0x49b504 | 0xb5a88 | 0xb4088 | 0xae |
GdipDeleteFontFamily | 0x0 | 0x49b508 | 0xb5a8c | 0xb408c | 0x8f |
GdipDeleteBrush | 0x0 | 0x49b50c | 0xb5a90 | 0xb4090 | 0x8a |
GdipDeleteStringFormat | 0x0 | 0x49b510 | 0xb5a94 | 0xb4094 | 0x97 |
GdipDeleteFont | 0x0 | 0x49b514 | 0xb5a98 | 0xb4098 | 0x8e |
GdiplusShutdown | 0x0 | 0x49b518 | 0xb5a9c | 0xb409c | 0x274 |
GdiplusStartup | 0x0 | 0x49b51c | 0xb5aa0 | 0xb40a0 | 0x275 |
GdipCloneImage | 0x0 | 0x49b520 | 0xb5aa4 | 0xb40a4 | 0x36 |
GdipDisposeImage | 0x0 | 0x49b524 | 0xb5aa8 | 0xb40a8 | 0x98 |
GdipFree | 0x0 | 0x49b528 | 0xb5aac | 0xb40ac | 0xed |
GdipAlloc | 0x0 | 0x49b52c | 0xb5ab0 | 0xb40b0 | 0x21 |
GdipLoadImageFromStreamICM | 0x0 | 0x49b530 | 0xb5ab4 | 0xb40b4 | 0x1b8 |
GdipLoadImageFromStream | 0x0 | 0x49b534 | 0xb5ab8 | 0xb40b8 | 0x1b7 |
GdipCreateFromHDC | 0x0 | 0x49b538 | 0xb5abc | 0xb40bc | 0x5b |
GdipDrawImageRectI | 0x0 | 0x49b53c | 0xb5ac0 | 0xb40c0 | 0xb8 |
GdipImageSelectActiveFrame | 0x0 | 0x49b540 | 0xb5ac4 | 0xb40c4 | 0x19c |
GdipDeleteGraphics | 0x0 | 0x49b544 | 0xb5ac8 | 0xb40c8 | 0x90 |
GdipImageGetFrameDimensionsCount | 0x0 | 0x49b548 | 0xb5acc | 0xb40cc | 0x199 |
GdipImageGetFrameDimensionsList | 0x0 | 0x49b54c | 0xb5ad0 | 0xb40d0 | 0x19a |
GdipImageGetFrameCount | 0x0 | 0x49b550 | 0xb5ad4 | 0xb40d4 | 0x198 |
GdipCreateFontFromLogfontA | 0x0 | 0x49b554 | 0xb5ad8 | 0xb40d8 | 0x59 |
IMM32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImmSetCompositionFontA | 0x0 | 0x49b114 | 0xb5698 | 0xb3c98 | 0x70 |
ImmSetCompositionWindow | 0x0 | 0x49b118 | 0xb569c | 0xb3c9c | 0x74 |
ImmGetContext | 0x0 | 0x49b11c | 0xb56a0 | 0xb3ca0 | 0x38 |
ImmReleaseContext | 0x0 | 0x49b120 | 0xb56a4 | 0xb3ca4 | 0x68 |
COMCTL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_TrackMouseEvent | 0x0 | 0x49b040 | 0xb55c4 | 0xb3bc4 | 0x92 |
(by ordinal) | 0x11 | 0x49b044 | 0xb55c8 | 0xb3bc8 | - |
WINMM.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
mmioWrite | 0x0 | 0x49b498 | 0xb5a1c | 0xb401c | 0x89 |
mmioCreateChunk | 0x0 | 0x49b49c | 0xb5a20 | 0xb4020 | 0x78 |
mmioOpenW | 0x0 | 0x49b4a0 | 0xb5a24 | 0xb4024 | 0x7f |
mmioAscend | 0x0 | 0x49b4a4 | 0xb5a28 | 0xb4028 | 0x76 |
urlmon.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateAsyncBindCtx | 0x0 | 0x49b590 | 0xb5b14 | 0xb4114 | 0x1f |
MSACM32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
acmDriverOpen | 0x0 | 0x49b2e4 | 0xb5868 | 0xb3e68 | 0x9 |
NETAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetWkstaUserGetInfo | 0x0 | 0x49b2ec | 0xb5870 | 0xb3e70 | 0x10e |
IPHLPAPI.DLL (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetIpNetTable | 0x0 | 0x49b128 | 0xb56ac | 0xb3cac | 0x5c |
AVIFIL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AVIMakeCompressedStream | 0x0 | 0x49b038 | 0xb55bc | 0xb3bbc | 0x16 |
wsnmp32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x1f5 | 0x49b598 | 0xb5b1c | 0xb411c | - |
d2d1.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x1 | 0x49b4ac | 0xb5a30 | 0xb4030 | - |
DWrite.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DWriteCreateFactory | 0x0 | 0x49b054 | 0xb55d8 | 0xb3bd8 | 0x0 |
Memory Dumps (6)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
wshsetup.exe | 1 | 0x00A60000 | 0x00B47FFF | Relevant Image |
![]() |
32-bit | 0x00AE9448 |
![]() |
![]() |
...
|
buffer | 1 | 0x02BF0000 | 0x02C22FFF | First Execution |
![]() |
32-bit | 0x02BF0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02BF0000 | 0x02C22FFF | Content Changed |
![]() |
32-bit | 0x02BF2B0E |
![]() |
![]() |
...
|
wshsetup.exe | 1 | 0x00A60000 | 0x00B47FFF | Content Changed |
![]() |
32-bit | 0x00A6192B |
![]() |
![]() |
...
|
wshsetup.exe | 1 | 0x00A60000 | 0x00B47FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
wshsetup.exe | 1 | 0x00A60000 | 0x00B47FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.33533697 |
Malicious
|
C:\Users\FD1HVy\AppData\Roaming\52E8.tmp.exe | Downloaded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x44a7be |
Size Of Code | 0x5a800 |
Size Of Initialized Data | 0x58e00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-03-08 10:51:10+00:00 |
Version Information (9)
»
Comments | Focusing Arcane Mullis Hba Subexpressions |
CompanyName | DocuSign |
FileDescription | Focusing Arcane Mullis Hba Subexpressions |
FileVersion | 7.4.3.7 |
LegalCopyright | ©DocuSign. All rights reserved. |
OriginalFilename | GelcatinNetware |
PrivateBuild | 7.4.3.7 |
ProductName | GelcatinNetware |
ProductVersion | 7.4.3.7 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x5a6c0 | 0x5a800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x45c000 | 0x17bba | 0x17c00 | 0x5ac00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.63 |
.data | 0x474000 | 0x68e4 | 0x3000 | 0x72800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.01 |
.rsrc | 0x47b000 | 0x3624c | 0x36400 | 0x75800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.38 |
.reloc | 0x4b2000 | 0x7cfa | 0x7e00 | 0xabc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.81 |
Imports (23)
»
KERNEL32.dll (107)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCurrentProcessId | 0x0 | 0x45c110 | 0x71c08 | 0x70808 | 0x1c1 |
GetEnvironmentStringsW | 0x0 | 0x45c114 | 0x71c0c | 0x7080c | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x45c118 | 0x71c10 | 0x70810 | 0x161 |
LoadLibraryW | 0x0 | 0x45c11c | 0x71c14 | 0x70814 | 0x33f |
GetStringTypeW | 0x0 | 0x45c120 | 0x71c18 | 0x70818 | 0x269 |
HeapCreate | 0x0 | 0x45c124 | 0x71c1c | 0x7081c | 0x2cd |
HeapSize | 0x0 | 0x45c128 | 0x71c20 | 0x70820 | 0x2d4 |
SetHandleCount | 0x0 | 0x45c12c | 0x71c24 | 0x70824 | 0x46f |
FlushFileBuffers | 0x0 | 0x45c130 | 0x71c28 | 0x70828 | 0x157 |
GetConsoleMode | 0x0 | 0x45c134 | 0x71c2c | 0x7082c | 0x1ac |
GetConsoleCP | 0x0 | 0x45c138 | 0x71c30 | 0x70830 | 0x19a |
IsProcessorFeaturePresent | 0x0 | 0x45c13c | 0x71c34 | 0x70834 | 0x304 |
TerminateProcess | 0x0 | 0x45c140 | 0x71c38 | 0x70838 | 0x4c0 |
IsDebuggerPresent | 0x0 | 0x45c144 | 0x71c3c | 0x7083c | 0x300 |
SetUnhandledExceptionFilter | 0x0 | 0x45c148 | 0x71c40 | 0x70840 | 0x4a5 |
UnhandledExceptionFilter | 0x0 | 0x45c14c | 0x71c44 | 0x70844 | 0x4d3 |
LCMapStringW | 0x0 | 0x45c150 | 0x71c48 | 0x70848 | 0x32d |
LocalFree | 0x0 | 0x45c154 | 0x71c4c | 0x7084c | 0x348 |
SetLastError | 0x0 | 0x45c158 | 0x71c50 | 0x70850 | 0x473 |
TlsFree | 0x0 | 0x45c15c | 0x71c54 | 0x70854 | 0x4c6 |
SetStdHandle | 0x0 | 0x45c160 | 0x71c58 | 0x70858 | 0x487 |
TlsGetValue | 0x0 | 0x45c164 | 0x71c5c | 0x7085c | 0x4c7 |
TlsAlloc | 0x0 | 0x45c168 | 0x71c60 | 0x70860 | 0x4c5 |
IsValidCodePage | 0x0 | 0x45c16c | 0x71c64 | 0x70864 | 0x30a |
GetOEMCP | 0x0 | 0x45c170 | 0x71c68 | 0x70868 | 0x237 |
GetCPInfo | 0x0 | 0x45c174 | 0x71c6c | 0x7086c | 0x172 |
GetStartupInfoW | 0x0 | 0x45c178 | 0x71c70 | 0x70870 | 0x263 |
HeapSetInformation | 0x0 | 0x45c17c | 0x71c74 | 0x70874 | 0x2d3 |
GetCommandLineA | 0x0 | 0x45c180 | 0x71c78 | 0x70878 | 0x186 |
GetSystemTimeAsFileTime | 0x0 | 0x45c184 | 0x71c7c | 0x7087c | 0x279 |
VirtualQuery | 0x0 | 0x45c188 | 0x71c80 | 0x70880 | 0x4f1 |
GetSystemInfo | 0x0 | 0x45c18c | 0x71c84 | 0x70884 | 0x273 |
GetModuleHandleW | 0x0 | 0x45c190 | 0x71c88 | 0x70888 | 0x218 |
VirtualAlloc | 0x0 | 0x45c194 | 0x71c8c | 0x7088c | 0x4e9 |
VirtualProtect | 0x0 | 0x45c198 | 0x71c90 | 0x70890 | 0x4ef |
GetModuleFileNameW | 0x0 | 0x45c19c | 0x71c94 | 0x70894 | 0x214 |
GetStdHandle | 0x0 | 0x45c1a0 | 0x71c98 | 0x70898 | 0x264 |
WriteConsoleW | 0x0 | 0x45c1a4 | 0x71c9c | 0x7089c | 0x524 |
HeapReAlloc | 0x0 | 0x45c1a8 | 0x71ca0 | 0x708a0 | 0x2d2 |
HeapAlloc | 0x0 | 0x45c1ac | 0x71ca4 | 0x708a4 | 0x2cb |
HeapFree | 0x0 | 0x45c1b0 | 0x71ca8 | 0x708a8 | 0x2cf |
RtlUnwind | 0x0 | 0x45c1b4 | 0x71cac | 0x708ac | 0x418 |
EncodePointer | 0x0 | 0x45c1b8 | 0x71cb0 | 0x708b0 | 0xea |
DecodePointer | 0x0 | 0x45c1bc | 0x71cb4 | 0x708b4 | 0xca |
CreateEventA | 0x0 | 0x45c1c0 | 0x71cb8 | 0x708b8 | 0x82 |
GlobalFree | 0x0 | 0x45c1c4 | 0x71cbc | 0x708bc | 0x2ba |
CreateMutexA | 0x0 | 0x45c1c8 | 0x71cc0 | 0x708c0 | 0x9b |
WaitForSingleObject | 0x0 | 0x45c1cc | 0x71cc4 | 0x708c4 | 0x4f9 |
ReleaseMutex | 0x0 | 0x45c1d0 | 0x71cc8 | 0x708c8 | 0x3fa |
SetPriorityClass | 0x0 | 0x45c1d4 | 0x71ccc | 0x708cc | 0x47d |
CreateFileW | 0x0 | 0x45c1d8 | 0x71cd0 | 0x708d0 | 0x8f |
TlsSetValue | 0x0 | 0x45c1dc | 0x71cd4 | 0x708d4 | 0x4c8 |
QueryPerformanceFrequency | 0x0 | 0x45c1e0 | 0x71cd8 | 0x708d8 | 0x3a8 |
QueryPerformanceCounter | 0x0 | 0x45c1e4 | 0x71cdc | 0x708dc | 0x3a7 |
OutputDebugStringW | 0x0 | 0x45c1e8 | 0x71ce0 | 0x708e0 | 0x38a |
CreateThread | 0x0 | 0x45c1ec | 0x71ce4 | 0x708e4 | 0xb5 |
LoadLibraryExA | 0x0 | 0x45c1f0 | 0x71ce8 | 0x708e8 | 0x33d |
IsDBCSLeadByte | 0x0 | 0x45c1f4 | 0x71cec | 0x708ec | 0x2fe |
lstrcmpiA | 0x0 | 0x45c1f8 | 0x71cf0 | 0x708f0 | 0x544 |
lstrlenA | 0x0 | 0x45c1fc | 0x71cf4 | 0x708f4 | 0x54d |
lstrlenW | 0x0 | 0x45c200 | 0x71cf8 | 0x708f8 | 0x54e |
FreeLibrary | 0x0 | 0x45c204 | 0x71cfc | 0x708fc | 0x162 |
GetLocalTime | 0x0 | 0x45c208 | 0x71d00 | 0x70900 | 0x203 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x45c20c | 0x71d04 | 0x70904 | 0x2e3 |
RaiseException | 0x0 | 0x45c210 | 0x71d08 | 0x70908 | 0x3b1 |
WriteFile | 0x0 | 0x45c214 | 0x71d0c | 0x7090c | 0x525 |
SetFileTime | 0x0 | 0x45c218 | 0x71d10 | 0x70910 | 0x46a |
CreateDirectoryA | 0x0 | 0x45c21c | 0x71d14 | 0x70914 | 0x7c |
DosDateTimeToFileTime | 0x0 | 0x45c220 | 0x71d18 | 0x70918 | 0xe4 |
SystemTimeToFileTime | 0x0 | 0x45c224 | 0x71d1c | 0x7091c | 0x4bd |
GetCurrentProcess | 0x0 | 0x45c228 | 0x71d20 | 0x70920 | 0x1c0 |
DuplicateHandle | 0x0 | 0x45c22c | 0x71d24 | 0x70924 | 0xe8 |
GetFileType | 0x0 | 0x45c230 | 0x71d28 | 0x70928 | 0x1f3 |
SetFilePointer | 0x0 | 0x45c234 | 0x71d2c | 0x7092c | 0x466 |
ExitProcess | 0x0 | 0x45c238 | 0x71d30 | 0x70930 | 0x119 |
GetCurrentDirectoryA | 0x0 | 0x45c23c | 0x71d34 | 0x70934 | 0x1be |
GetModuleFileNameA | 0x0 | 0x45c240 | 0x71d38 | 0x70938 | 0x213 |
FindResourceA | 0x0 | 0x45c244 | 0x71d3c | 0x7093c | 0x14b |
LoadResource | 0x0 | 0x45c248 | 0x71d40 | 0x70940 | 0x341 |
FreeResource | 0x0 | 0x45c24c | 0x71d44 | 0x70944 | 0x165 |
SizeofResource | 0x0 | 0x45c250 | 0x71d48 | 0x70948 | 0x4b1 |
LockResource | 0x0 | 0x45c254 | 0x71d4c | 0x7094c | 0x354 |
GetLastError | 0x0 | 0x45c258 | 0x71d50 | 0x70950 | 0x202 |
GetModuleHandleA | 0x0 | 0x45c25c | 0x71d54 | 0x70954 | 0x215 |
WideCharToMultiByte | 0x0 | 0x45c260 | 0x71d58 | 0x70958 | 0x511 |
CreateFileA | 0x0 | 0x45c264 | 0x71d5c | 0x7095c | 0x88 |
GetFileSize | 0x0 | 0x45c268 | 0x71d60 | 0x70960 | 0x1f0 |
CloseHandle | 0x0 | 0x45c26c | 0x71d64 | 0x70964 | 0x52 |
ReadFile | 0x0 | 0x45c270 | 0x71d68 | 0x70968 | 0x3c0 |
GlobalAlloc | 0x0 | 0x45c274 | 0x71d6c | 0x7096c | 0x2b3 |
GlobalLock | 0x0 | 0x45c278 | 0x71d70 | 0x70970 | 0x2be |
GlobalUnlock | 0x0 | 0x45c27c | 0x71d74 | 0x70974 | 0x2c5 |
InterlockedDecrement | 0x0 | 0x45c280 | 0x71d78 | 0x70978 | 0x2eb |
InterlockedIncrement | 0x0 | 0x45c284 | 0x71d7c | 0x7097c | 0x2ef |
LoadLibraryA | 0x0 | 0x45c288 | 0x71d80 | 0x70980 | 0x33c |
GetProcAddress | 0x0 | 0x45c28c | 0x71d84 | 0x70984 | 0x245 |
GetACP | 0x0 | 0x45c290 | 0x71d88 | 0x70988 | 0x168 |
MultiByteToWideChar | 0x0 | 0x45c294 | 0x71d8c | 0x7098c | 0x367 |
MulDiv | 0x0 | 0x45c298 | 0x71d90 | 0x70990 | 0x366 |
GetTickCount | 0x0 | 0x45c29c | 0x71d94 | 0x70994 | 0x293 |
LeaveCriticalSection | 0x0 | 0x45c2a0 | 0x71d98 | 0x70998 | 0x339 |
EnterCriticalSection | 0x0 | 0x45c2a4 | 0x71d9c | 0x7099c | 0xee |
DeleteCriticalSection | 0x0 | 0x45c2a8 | 0x71da0 | 0x709a0 | 0xd1 |
GetVersionExA | 0x0 | 0x45c2ac | 0x71da4 | 0x709a4 | 0x2a3 |
InitializeCriticalSection | 0x0 | 0x45c2b0 | 0x71da8 | 0x709a8 | 0x2e2 |
Sleep | 0x0 | 0x45c2b4 | 0x71dac | 0x709ac | 0x4b2 |
GetCurrentThreadId | 0x0 | 0x45c2b8 | 0x71db0 | 0x709b0 | 0x1c5 |
USER32.dll (99)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
UnionRect | 0x0 | 0x45c334 | 0x71e2c | 0x70a2c | 0x301 |
KillTimer | 0x0 | 0x45c338 | 0x71e30 | 0x70a30 | 0x1e3 |
IsWindowVisible | 0x0 | 0x45c33c | 0x71e34 | 0x70a34 | 0x1e0 |
GetUpdateRect | 0x0 | 0x45c340 | 0x71e38 | 0x70a38 | 0x187 |
GetActiveWindow | 0x0 | 0x45c344 | 0x71e3c | 0x70a3c | 0x100 |
DrawTextA | 0x0 | 0x45c348 | 0x71e40 | 0x70a40 | 0xcd |
CharPrevA | 0x0 | 0x45c34c | 0x71e44 | 0x70a44 | 0x32 |
SetRect | 0x0 | 0x45c350 | 0x71e48 | 0x70a48 | 0x2ae |
OffsetRect | 0x0 | 0x45c354 | 0x71e4c | 0x70a4c | 0x225 |
SetMenu | 0x0 | 0x45c358 | 0x71e50 | 0x70a50 | 0x29c |
InsertMenuItemA | 0x0 | 0x45c35c | 0x71e54 | 0x70a54 | 0x1b8 |
GetMenuCheckMarkDimensions | 0x0 | 0x45c360 | 0x71e58 | 0x70a58 | 0x14d |
IsZoomed | 0x0 | 0x45c364 | 0x71e5c | 0x70a5c | 0x1e2 |
GetWindowRect | 0x0 | 0x45c368 | 0x71e60 | 0x70a60 | 0x19c |
UpdateWindow | 0x0 | 0x45c36c | 0x71e64 | 0x70a64 | 0x311 |
MoveWindow | 0x0 | 0x45c370 | 0x71e68 | 0x70a68 | 0x21b |
DestroyWindow | 0x0 | 0x45c374 | 0x71e6c | 0x70a6c | 0xa6 |
ReleaseDC | 0x0 | 0x45c378 | 0x71e70 | 0x70a70 | 0x265 |
GetDC | 0x0 | 0x45c37c | 0x71e74 | 0x70a74 | 0x121 |
ReleaseCapture | 0x0 | 0x45c380 | 0x71e78 | 0x70a78 | 0x264 |
SetCapture | 0x0 | 0x45c384 | 0x71e7c | 0x70a7c | 0x280 |
FillRect | 0x0 | 0x45c388 | 0x71e80 | 0x70a80 | 0xf6 |
InvalidateRect | 0x0 | 0x45c38c | 0x71e84 | 0x70a84 | 0x1be |
InvalidateRgn | 0x0 | 0x45c390 | 0x71e88 | 0x70a88 | 0x1bf |
DefWindowProcA | 0x0 | 0x45c394 | 0x71e8c | 0x70a8c | 0x9b |
MessageBoxA | 0x0 | 0x45c398 | 0x71e90 | 0x70a90 | 0x20e |
CreatePopupMenu | 0x0 | 0x45c39c | 0x71e94 | 0x70a94 | 0x6b |
CreateMenu | 0x0 | 0x45c3a0 | 0x71e98 | 0x70a98 | 0x6a |
LoadIconA | 0x0 | 0x45c3a4 | 0x71e9c | 0x70a9c | 0x1ec |
GetDlgItem | 0x0 | 0x45c3a8 | 0x71ea0 | 0x70aa0 | 0x127 |
PeekMessageA | 0x0 | 0x45c3ac | 0x71ea4 | 0x70aa4 | 0x232 |
LoadAcceleratorsA | 0x0 | 0x45c3b0 | 0x71ea8 | 0x70aa8 | 0x1e4 |
LoadStringW | 0x0 | 0x45c3b4 | 0x71eac | 0x70aac | 0x1fa |
SetScrollPos | 0x0 | 0x45c3b8 | 0x71eb0 | 0x70ab0 | 0x2b1 |
SetTimer | 0x0 | 0x45c3bc | 0x71eb4 | 0x70ab4 | 0x2bb |
EndPaint | 0x0 | 0x45c3c0 | 0x71eb8 | 0x70ab8 | 0xdc |
BeginPaint | 0x0 | 0x45c3c4 | 0x71ebc | 0x70abc | 0xe |
PtInRect | 0x0 | 0x45c3c8 | 0x71ec0 | 0x70ac0 | 0x240 |
ScreenToClient | 0x0 | 0x45c3cc | 0x71ec4 | 0x70ac4 | 0x26d |
ClientToScreen | 0x0 | 0x45c3d0 | 0x71ec8 | 0x70ac8 | 0x47 |
GetGUIThreadInfo | 0x0 | 0x45c3d4 | 0x71ecc | 0x70acc | 0x12e |
GetClientRect | 0x0 | 0x45c3d8 | 0x71ed0 | 0x70ad0 | 0x114 |
ShowWindow | 0x0 | 0x45c3dc | 0x71ed4 | 0x70ad4 | 0x2df |
SetFocus | 0x0 | 0x45c3e0 | 0x71ed8 | 0x70ad8 | 0x292 |
CreateAcceleratorTableA | 0x0 | 0x45c3e4 | 0x71edc | 0x70adc | 0x57 |
SetCursor | 0x0 | 0x45c3e8 | 0x71ee0 | 0x70ae0 | 0x288 |
LoadCursorA | 0x0 | 0x45c3ec | 0x71ee4 | 0x70ae4 | 0x1e8 |
IntersectRect | 0x0 | 0x45c3f0 | 0x71ee8 | 0x70ae8 | 0x1bd |
GetParent | 0x0 | 0x45c3f4 | 0x71eec | 0x70aec | 0x164 |
GetMonitorInfoA | 0x0 | 0x45c3f8 | 0x71ef0 | 0x70af0 | 0x15e |
MonitorFromWindow | 0x0 | 0x45c3fc | 0x71ef4 | 0x70af4 | 0x21a |
MapWindowPoints | 0x0 | 0x45c400 | 0x71ef8 | 0x70af8 | 0x209 |
GetFocus | 0x0 | 0x45c404 | 0x71efc | 0x70afc | 0x12c |
GetCursorPos | 0x0 | 0x45c408 | 0x71f00 | 0x70b00 | 0x120 |
SetWindowPos | 0x0 | 0x45c40c | 0x71f04 | 0x70b04 | 0x2c6 |
IsRectEmpty | 0x0 | 0x45c410 | 0x71f08 | 0x70b08 | 0x1d4 |
SendMessageA | 0x0 | 0x45c414 | 0x71f0c | 0x70b0c | 0x277 |
GetWindowTextA | 0x0 | 0x45c418 | 0x71f10 | 0x70b10 | 0x1a0 |
GetWindowTextLengthA | 0x0 | 0x45c41c | 0x71f14 | 0x70b14 | 0x1a1 |
SetWindowTextA | 0x0 | 0x45c420 | 0x71f18 | 0x70b18 | 0x2ca |
EnableWindow | 0x0 | 0x45c424 | 0x71f1c | 0x70b1c | 0xd8 |
GetCaretPos | 0x0 | 0x45c428 | 0x71f20 | 0x70b20 | 0x10a |
GetCaretBlinkTime | 0x0 | 0x45c42c | 0x71f24 | 0x70b24 | 0x109 |
CreateCaret | 0x0 | 0x45c430 | 0x71f28 | 0x70b28 | 0x59 |
HideCaret | 0x0 | 0x45c434 | 0x71f2c | 0x70b2c | 0x1a9 |
ShowCaret | 0x0 | 0x45c438 | 0x71f30 | 0x70b30 | 0x2d9 |
SetCaretPos | 0x0 | 0x45c43c | 0x71f34 | 0x70b34 | 0x282 |
GetSysColor | 0x0 | 0x45c440 | 0x71f38 | 0x70b38 | 0x17b |
GetKeyState | 0x0 | 0x45c444 | 0x71f3c | 0x70b3c | 0x13d |
GetWindowLongA | 0x0 | 0x45c448 | 0x71f40 | 0x70b40 | 0x195 |
wsprintfA | 0x0 | 0x45c44c | 0x71f44 | 0x70b44 | 0x332 |
SetWindowLongA | 0x0 | 0x45c450 | 0x71f48 | 0x70b48 | 0x2c3 |
IsWindow | 0x0 | 0x45c454 | 0x71f4c | 0x70b4c | 0x1db |
PostQuitMessage | 0x0 | 0x45c458 | 0x71f50 | 0x70b50 | 0x237 |
DispatchMessageA | 0x0 | 0x45c45c | 0x71f54 | 0x70b54 | 0xae |
TranslateMessage | 0x0 | 0x45c460 | 0x71f58 | 0x70b58 | 0x2fc |
GetMessageA | 0x0 | 0x45c464 | 0x71f5c | 0x70b5c | 0x159 |
CreateWindowExA | 0x0 | 0x45c468 | 0x71f60 | 0x70b60 | 0x6d |
GetClassInfoExA | 0x0 | 0x45c46c | 0x71f64 | 0x70b64 | 0x10c |
RegisterClassExA | 0x0 | 0x45c470 | 0x71f68 | 0x70b68 | 0x24c |
RegisterClassA | 0x0 | 0x45c474 | 0x71f6c | 0x70b6c | 0x24b |
RemovePropA | 0x0 | 0x45c478 | 0x71f70 | 0x70b70 | 0x268 |
DrawFrameControl | 0x0 | 0x45c47c | 0x71f74 | 0x70b74 | 0xc6 |
AppendMenuA | 0x0 | 0x45c480 | 0x71f78 | 0x70b78 | 0x9 |
PostMessageA | 0x0 | 0x45c484 | 0x71f7c | 0x70b7c | 0x235 |
SetPropA | 0x0 | 0x45c488 | 0x71f80 | 0x70b80 | 0x2ac |
GetWindow | 0x0 | 0x45c48c | 0x71f84 | 0x70b84 | 0x18e |
IsIconic | 0x0 | 0x45c490 | 0x71f88 | 0x70b88 | 0x1d1 |
LoadImageA | 0x0 | 0x45c494 | 0x71f8c | 0x70b8c | 0x1ee |
CallWindowProcA | 0x0 | 0x45c498 | 0x71f90 | 0x70b90 | 0x1d |
GetPropA | 0x0 | 0x45c49c | 0x71f94 | 0x70b94 | 0x16a |
TrackMouseEvent | 0x0 | 0x45c4a0 | 0x71f98 | 0x70b98 | 0x2f5 |
MessageBoxW | 0x0 | 0x45c4a4 | 0x71f9c | 0x70b9c | 0x215 |
DrawFocusRect | 0x0 | 0x45c4a8 | 0x71fa0 | 0x70ba0 | 0xc4 |
BeginDeferWindowPos | 0x0 | 0x45c4ac | 0x71fa4 | 0x70ba4 | 0xd |
GetSystemMenu | 0x0 | 0x45c4b0 | 0x71fa8 | 0x70ba8 | 0x17d |
wvsprintfA | 0x0 | 0x45c4b4 | 0x71fac | 0x70bac | 0x334 |
CharNextA | 0x0 | 0x45c4b8 | 0x71fb0 | 0x70bb0 | 0x2f |
SetWindowRgn | 0x0 | 0x45c4bc | 0x71fb4 | 0x70bb4 | 0x2c7 |
GDI32.dll (43)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetTextColor | 0x0 | 0x45c04c | 0x71b44 | 0x70744 | 0x2a6 |
CreatePatternBrush | 0x0 | 0x45c050 | 0x71b48 | 0x70748 | 0x4a |
CreateSolidBrush | 0x0 | 0x45c054 | 0x71b4c | 0x7074c | 0x54 |
DeleteObject | 0x0 | 0x45c058 | 0x71b50 | 0x70750 | 0xe6 |
GetDeviceCaps | 0x0 | 0x45c05c | 0x71b54 | 0x70754 | 0x1cb |
CreateRoundRectRgn | 0x0 | 0x45c060 | 0x71b58 | 0x70758 | 0x51 |
StretchBlt | 0x0 | 0x45c064 | 0x71b5c | 0x7075c | 0x2b3 |
CreateDIBSection | 0x0 | 0x45c068 | 0x71b60 | 0x70760 | 0x35 |
SetStretchBltMode | 0x0 | 0x45c06c | 0x71b64 | 0x70764 | 0x2a2 |
ExtTextOutA | 0x0 | 0x45c070 | 0x71b68 | 0x70768 | 0x137 |
SetBkColor | 0x0 | 0x45c074 | 0x71b6c | 0x7076c | 0x27e |
LineTo | 0x0 | 0x45c078 | 0x71b70 | 0x70770 | 0x236 |
MoveToEx | 0x0 | 0x45c07c | 0x71b74 | 0x70774 | 0x23a |
SetBkMode | 0x0 | 0x45c080 | 0x71b78 | 0x70778 | 0x27f |
RoundRect | 0x0 | 0x45c084 | 0x71b7c | 0x7077c | 0x26a |
TextOutA | 0x0 | 0x45c088 | 0x71b80 | 0x70780 | 0x2b8 |
GetTextExtentPoint32A | 0x0 | 0x45c08c | 0x71b84 | 0x70784 | 0x21d |
GetCharABCWidthsA | 0x0 | 0x45c090 | 0x71b88 | 0x70788 | 0x1b1 |
ExtSelectClipRgn | 0x0 | 0x45c094 | 0x71b8c | 0x7078c | 0x136 |
GdiFlush | 0x0 | 0x45c098 | 0x71b90 | 0x70790 | 0x175 |
DescribePixelFormat | 0x0 | 0x45c09c | 0x71b94 | 0x70794 | 0xe7 |
SetTextJustification | 0x0 | 0x45c0a0 | 0x71b98 | 0x70798 | 0x2a7 |
GetWindowOrgEx | 0x0 | 0x45c0a4 | 0x71b9c | 0x7079c | 0x22c |
EnumFontFamiliesExA | 0x0 | 0x45c0a8 | 0x71ba0 | 0x707a0 | 0x124 |
GetObjectA | 0x0 | 0x45c0ac | 0x71ba4 | 0x707a4 | 0x1fb |
CreateFontIndirectA | 0x0 | 0x45c0b0 | 0x71ba8 | 0x707a8 | 0x3d |
GetStockObject | 0x0 | 0x45c0b4 | 0x71bac | 0x707ac | 0x20d |
GetTextMetricsA | 0x0 | 0x45c0b8 | 0x71bb0 | 0x707b0 | 0x225 |
SelectObject | 0x0 | 0x45c0bc | 0x71bb4 | 0x707b4 | 0x277 |
CreatePen | 0x0 | 0x45c0c0 | 0x71bb8 | 0x707b8 | 0x4b |
DeleteDC | 0x0 | 0x45c0c4 | 0x71bbc | 0x707bc | 0xe3 |
SetWindowOrgEx | 0x0 | 0x45c0c8 | 0x71bc0 | 0x707c0 | 0x2ad |
Rectangle | 0x0 | 0x45c0cc | 0x71bc4 | 0x707c4 | 0x25f |
RestoreDC | 0x0 | 0x45c0d0 | 0x71bc8 | 0x707c8 | 0x269 |
BitBlt | 0x0 | 0x45c0d4 | 0x71bcc | 0x707cc | 0x13 |
SaveDC | 0x0 | 0x45c0d8 | 0x71bd0 | 0x707d0 | 0x270 |
CreateCompatibleBitmap | 0x0 | 0x45c0dc | 0x71bd4 | 0x707d4 | 0x2f |
CreateCompatibleDC | 0x0 | 0x45c0e0 | 0x71bd8 | 0x707d8 | 0x30 |
SelectClipRgn | 0x0 | 0x45c0e4 | 0x71bdc | 0x707dc | 0x275 |
CombineRgn | 0x0 | 0x45c0e8 | 0x71be0 | 0x707e0 | 0x22 |
CreateRectRgnIndirect | 0x0 | 0x45c0ec | 0x71be4 | 0x707e4 | 0x50 |
CreatePenIndirect | 0x0 | 0x45c0f0 | 0x71be8 | 0x707e8 | 0x4c |
GetClipBox | 0x0 | 0x45c0f4 | 0x71bec | 0x707ec | 0x1c0 |
ADVAPI32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCreateKeyExA | 0x0 | 0x45c000 | 0x71af8 | 0x706f8 | 0x238 |
RegDeleteKeyA | 0x0 | 0x45c004 | 0x71afc | 0x706fc | 0x23d |
RegDeleteValueA | 0x0 | 0x45c008 | 0x71b00 | 0x70700 | 0x247 |
RegCloseKey | 0x0 | 0x45c00c | 0x71b04 | 0x70704 | 0x230 |
RegSetValueExA | 0x0 | 0x45c010 | 0x71b08 | 0x70708 | 0x27d |
RegQueryInfoKeyW | 0x0 | 0x45c014 | 0x71b0c | 0x7070c | 0x268 |
RegEnumKeyExA | 0x0 | 0x45c018 | 0x71b10 | 0x70710 | 0x24e |
RegisterEventSourceA | 0x0 | 0x45c01c | 0x71b14 | 0x70714 | 0x282 |
LogonUserA | 0x0 | 0x45c020 | 0x71b18 | 0x70718 | 0x189 |
ImpersonateLoggedOnUser | 0x0 | 0x45c024 | 0x71b1c | 0x7071c | 0x173 |
RegOpenKeyExA | 0x0 | 0x45c028 | 0x71b20 | 0x70720 | 0x260 |
SHELL32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetFolderPathW | 0x0 | 0x45c308 | 0x71e00 | 0x70a00 | 0xc3 |
SHFileOperationA | 0x0 | 0x45c30c | 0x71e04 | 0x70a04 | 0xab |
SHGetDesktopFolder | 0x0 | 0x45c310 | 0x71e08 | 0x70a08 | 0xb6 |
SHBrowseForFolderA | 0x0 | 0x45c314 | 0x71e0c | 0x70a0c | 0x7a |
SHChangeNotify | 0x0 | 0x45c318 | 0x71e10 | 0x70a10 | 0x7f |
ShellExecuteA | 0x0 | 0x45c31c | 0x71e14 | 0x70a14 | 0x11e |
SHGetMalloc | 0x0 | 0x45c320 | 0x71e18 | 0x70a18 | 0xcf |
ole32.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StgCreateDocfile | 0x0 | 0x45c618 | 0x72110 | 0x70d10 | 0x167 |
RevokeDragDrop | 0x0 | 0x45c61c | 0x72114 | 0x70d14 | 0x159 |
GetHGlobalFromStream | 0x0 | 0x45c620 | 0x72118 | 0x70d18 | 0x95 |
CoTaskMemFree | 0x0 | 0x45c624 | 0x7211c | 0x70d1c | 0x68 |
CoTaskMemRealloc | 0x0 | 0x45c628 | 0x72120 | 0x70d20 | 0x69 |
CoTaskMemAlloc | 0x0 | 0x45c62c | 0x72124 | 0x70d24 | 0x67 |
OleUninitialize | 0x0 | 0x45c630 | 0x72128 | 0x70d28 | 0x149 |
CreateStreamOnHGlobal | 0x0 | 0x45c634 | 0x7212c | 0x70d2c | 0x86 |
CoCreateInstance | 0x0 | 0x45c638 | 0x72130 | 0x70d30 | 0x10 |
OleLockRunning | 0x0 | 0x45c63c | 0x72134 | 0x70d34 | 0x138 |
CLSIDFromString | 0x0 | 0x45c640 | 0x72138 | 0x70d38 | 0x8 |
CLSIDFromProgID | 0x0 | 0x45c644 | 0x7213c | 0x70d3c | 0x6 |
CoUninitialize | 0x0 | 0x45c648 | 0x72140 | 0x70d40 | 0x6c |
CoInitialize | 0x0 | 0x45c64c | 0x72144 | 0x70d44 | 0x3e |
OleInitialize | 0x0 | 0x45c650 | 0x72148 | 0x70d48 | 0x132 |
OLEAUT32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysFreeString | 0x6 | 0x45c2dc | 0x71dd4 | 0x709d4 | - |
VariantInit | 0x8 | 0x45c2e0 | 0x71dd8 | 0x709d8 | - |
SysAllocString | 0x2 | 0x45c2e4 | 0x71ddc | 0x709dc | - |
SystemTimeToVariantTime | 0xb8 | 0x45c2e8 | 0x71de0 | 0x709e0 | - |
VarUI4FromStr | 0x115 | 0x45c2ec | 0x71de4 | 0x709e4 | - |
SysAllocStringLen | 0x4 | 0x45c2f0 | 0x71de8 | 0x709e8 | - |
VariantClear | 0x9 | 0x45c2f4 | 0x71dec | 0x709ec | - |
ODBC32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x9 | 0x45c2d4 | 0x71dcc | 0x709cc | - |
gdiplus.dll (43)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GdipCreateFromHDC | 0x0 | 0x45c558 | 0x72050 | 0x70c50 | 0x5b |
GdipFree | 0x0 | 0x45c55c | 0x72054 | 0x70c54 | 0xed |
GdipAlloc | 0x0 | 0x45c560 | 0x72058 | 0x70c58 | 0x21 |
GdipGetImageEncoders | 0x0 | 0x45c564 | 0x7205c | 0x70c5c | 0x11e |
GdipGetImageEncodersSize | 0x0 | 0x45c568 | 0x72060 | 0x70c60 | 0x11f |
GdipCloneBrush | 0x0 | 0x45c56c | 0x72064 | 0x70c64 | 0x32 |
GdipGetFamily | 0x0 | 0x45c570 | 0x72068 | 0x70c68 | 0x109 |
GdipCreateFontFromLogfontA | 0x0 | 0x45c574 | 0x7206c | 0x70c6c | 0x59 |
GdipCreateFontFromDC | 0x0 | 0x45c578 | 0x72070 | 0x70c70 | 0x58 |
GdipDrawImage | 0x0 | 0x45c57c | 0x72074 | 0x70c74 | 0xae |
GdipDrawString | 0x0 | 0x45c580 | 0x72078 | 0x70c78 | 0xc8 |
GdipGraphicsClear | 0x0 | 0x45c584 | 0x7207c | 0x70c7c | 0x195 |
GdipDeleteGraphics | 0x0 | 0x45c588 | 0x72080 | 0x70c80 | 0x90 |
GdipSetSmoothingMode | 0x0 | 0x45c58c | 0x72084 | 0x70c84 | 0x249 |
GdipSetInterpolationMode | 0x0 | 0x45c590 | 0x72088 | 0x70c88 | 0x218 |
GdipSetTextRenderingHint | 0x0 | 0x45c594 | 0x7208c | 0x70c8c | 0x254 |
GdipSetCompositingQuality | 0x0 | 0x45c598 | 0x72090 | 0x70c90 | 0x203 |
GdipGetImageGraphicsContext | 0x0 | 0x45c59c | 0x72094 | 0x70c94 | 0x121 |
GdipSetStringFormatLineAlign | 0x0 | 0x45c5a0 | 0x72098 | 0x70c98 | 0x24f |
GdipSetStringFormatAlign | 0x0 | 0x45c5a4 | 0x7209c | 0x70c9c | 0x24b |
GdipCreateLineBrushI | 0x0 | 0x45c5a8 | 0x720a0 | 0x70ca0 | 0x69 |
GdiplusShutdown | 0x0 | 0x45c5ac | 0x720a4 | 0x70ca4 | 0x274 |
GdiplusStartup | 0x0 | 0x45c5b0 | 0x720a8 | 0x70ca8 | 0x275 |
GdipCreateBitmapFromScan0 | 0x0 | 0x45c5b4 | 0x720ac | 0x70cac | 0x50 |
GdipDeleteFont | 0x0 | 0x45c5b8 | 0x720b0 | 0x70cb0 | 0x8e |
GdipDeleteFontFamily | 0x0 | 0x45c5bc | 0x720b4 | 0x70cb4 | 0x8f |
GdipDeleteStringFormat | 0x0 | 0x45c5c0 | 0x720b8 | 0x70cb8 | 0x97 |
GdipCreateStringFormat | 0x0 | 0x45c5c4 | 0x720bc | 0x70cbc | 0x84 |
GdipDeleteBrush | 0x0 | 0x45c5c8 | 0x720c0 | 0x70cc0 | 0x8a |
GdipCloneImage | 0x0 | 0x45c5cc | 0x720c4 | 0x70cc4 | 0x36 |
GdipDrawImageRectI | 0x0 | 0x45c5d0 | 0x720c8 | 0x70cc8 | 0xb8 |
GdipSetPixelOffsetMode | 0x0 | 0x45c5d4 | 0x720cc | 0x70ccc | 0x246 |
GdipGetPropertyItem | 0x0 | 0x45c5d8 | 0x720d0 | 0x70cd0 | 0x176 |
GdipGetPropertyItemSize | 0x0 | 0x45c5dc | 0x720d4 | 0x70cd4 | 0x177 |
GdipImageSelectActiveFrame | 0x0 | 0x45c5e0 | 0x720d8 | 0x70cd8 | 0x19c |
GdipImageGetFrameCount | 0x0 | 0x45c5e4 | 0x720dc | 0x70cdc | 0x198 |
GdipImageGetFrameDimensionsList | 0x0 | 0x45c5e8 | 0x720e0 | 0x70ce0 | 0x19a |
GdipImageGetFrameDimensionsCount | 0x0 | 0x45c5ec | 0x720e4 | 0x70ce4 | 0x199 |
GdipGetImageHeight | 0x0 | 0x45c5f0 | 0x720e8 | 0x70ce8 | 0x122 |
GdipGetImageWidth | 0x0 | 0x45c5f4 | 0x720ec | 0x70cec | 0x12c |
GdipDisposeImage | 0x0 | 0x45c5f8 | 0x720f0 | 0x70cf0 | 0x98 |
GdipLoadImageFromStreamICM | 0x0 | 0x45c5fc | 0x720f4 | 0x70cf4 | 0x1b8 |
GdipLoadImageFromStream | 0x0 | 0x45c600 | 0x720f8 | 0x70cf8 | 0x1b7 |
IMM32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImmReleaseContext | 0x0 | 0x45c0fc | 0x71bf4 | 0x707f4 | 0x68 |
ImmSetCompositionWindow | 0x0 | 0x45c100 | 0x71bf8 | 0x707f8 | 0x74 |
ImmGetContext | 0x0 | 0x45c104 | 0x71bfc | 0x707fc | 0x38 |
ImmSetCompositionFontA | 0x0 | 0x45c108 | 0x71c00 | 0x70800 | 0x70 |
PSAPI.DLL (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EnumPageFilesA | 0x0 | 0x45c2fc | 0x71df4 | 0x709f4 | 0x2 |
GetProcessMemoryInfo | 0x0 | 0x45c300 | 0x71df8 | 0x709f8 | 0x15 |
COMCTL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_TrackMouseEvent | 0x0 | 0x45c030 | 0x71b28 | 0x70728 | 0x92 |
(by ordinal) | 0x11 | 0x45c034 | 0x71b2c | 0x7072c | - |
WINMM.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
timeSetEvent | 0x0 | 0x45c4f0 | 0x71fe8 | 0x70be8 | 0x96 |
timeGetTime | 0x0 | 0x45c4f4 | 0x71fec | 0x70bec | 0x94 |
waveOutClose | 0x0 | 0x45c4f8 | 0x71ff0 | 0x70bf0 | 0xa8 |
waveOutRestart | 0x0 | 0x45c4fc | 0x71ff4 | 0x70bf4 | 0xb8 |
waveOutWrite | 0x0 | 0x45c500 | 0x71ff8 | 0x70bf8 | 0xbd |
timeBeginPeriod | 0x0 | 0x45c504 | 0x71ffc | 0x70bfc | 0x90 |
waveOutUnprepareHeader | 0x0 | 0x45c508 | 0x72000 | 0x70c00 | 0xbc |
waveOutOpen | 0x0 | 0x45c50c | 0x72004 | 0x70c04 | 0xb4 |
waveOutPrepareHeader | 0x0 | 0x45c510 | 0x72008 | 0x70c08 | 0xb6 |
waveOutReset | 0x0 | 0x45c514 | 0x7200c | 0x70c0c | 0xb7 |
WS2_32.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
__WSAFDIsSet | 0x97 | 0x45c51c | 0x72014 | 0x70c14 | - |
select | 0x12 | 0x45c520 | 0x72018 | 0x70c18 | - |
accept | 0x1 | 0x45c524 | 0x7201c | 0x70c1c | - |
WSAStartup | 0x73 | 0x45c528 | 0x72020 | 0x70c20 | - |
WSASocketA | 0x0 | 0x45c52c | 0x72024 | 0x70c24 | 0x52 |
getsockopt | 0x7 | 0x45c530 | 0x72028 | 0x70c28 | - |
closesocket | 0x3 | 0x45c534 | 0x7202c | 0x70c2c | - |
listen | 0xd | 0x45c538 | 0x72030 | 0x70c30 | - |
WSAGetLastError | 0x6f | 0x45c53c | 0x72034 | 0x70c34 | - |
WSACleanup | 0x74 | 0x45c540 | 0x72038 | 0x70c38 | - |
socket | 0x17 | 0x45c544 | 0x7203c | 0x70c3c | - |
htons | 0x9 | 0x45c548 | 0x72040 | 0x70c40 | - |
bind | 0x2 | 0x45c54c | 0x72044 | 0x70c44 | - |
recv | 0x10 | 0x45c550 | 0x72048 | 0x70c48 | - |
SHLWAPI.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathMatchSpecW | 0x0 | 0x45c328 | 0x71e20 | 0x70a20 | 0x7b |
StrRetToBufA | 0x0 | 0x45c32c | 0x71e24 | 0x70a24 | 0x13d |
UxTheme.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DrawThemeText | 0x0 | 0x45c4cc | 0x71fc4 | 0x70bc4 | 0x10 |
GetThemeInt | 0x0 | 0x45c4d0 | 0x71fc8 | 0x70bc8 | 0x27 |
MSACM32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
acmDriverClose | 0x0 | 0x45c2c0 | 0x71db8 | 0x709b8 | 0x3 |
acmFormatTagDetailsA | 0x0 | 0x45c2c4 | 0x71dbc | 0x709bc | 0x1d |
NETAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetShareGetInfo | 0x0 | 0x45c2cc | 0x71dc4 | 0x709c4 | 0xf1 |
WININET.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InternetHangUp | 0x0 | 0x45c4d8 | 0x71fd0 | 0x70bd0 | 0x94 |
InternetGetCookieW | 0x0 | 0x45c4dc | 0x71fd4 | 0x70bd4 | 0x89 |
InternetGoOnlineW | 0x0 | 0x45c4e0 | 0x71fd8 | 0x70bd8 | 0x93 |
InternetGetPerSiteCookieDecisionW | 0x0 | 0x45c4e4 | 0x71fdc | 0x70bdc | 0x8d |
InternetInitializeAutoProxyDll | 0x0 | 0x45c4e8 | 0x71fe0 | 0x70be0 | 0x95 |
USERENV.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExpandEnvironmentStringsForUserA | 0x0 | 0x45c4c4 | 0x71fbc | 0x70bbc | 0xb |
msi.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x8 | 0x45c608 | 0x72100 | 0x70d00 | - |
(by ordinal) | 0x11 | 0x45c60c | 0x72104 | 0x70d04 | - |
(by ordinal) | 0x40 | 0x45c610 | 0x72108 | 0x70d08 | - |
CRYPTUI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptUIWizFreeDigitalSignContext | 0x0 | 0x45c03c | 0x71b34 | 0x70734 | 0x29 |
ESENT.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
JetTruncateLogInstance | 0x0 | 0x45c044 | 0x71b3c | 0x7073c | 0x149 |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.33533023 |
Malicious
|
C:\Users\FD1HVy\AppData\Local\Temp\qjpg.exe | Downloaded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4052c0 |
Size Of Code | 0x5000 |
Size Of Initialized Data | 0x14600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-03-10 13:02:39+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x4f30 | 0x5000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.44 |
.rdata | 0x406000 | 0x283e | 0x2a00 | 0x5400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.27 |
.data | 0x409000 | 0x10b8c | 0x1e00 | 0x7e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.9 |
.CRT | 0x41a000 | 0x8 | 0x200 | 0x9c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.0 |
.tls | 0x41b000 | 0xc | 0x200 | 0x9e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.reloc | 0x41c000 | 0xaba | 0xc00 | 0xa000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.67 |
Imports (2)
»
ntdll.dll (27)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RtlInitializeCriticalSection | 0x0 | 0x406110 | 0x816c | 0x756c | 0x273 |
wcstombs | 0x0 | 0x406114 | 0x8170 | 0x7570 | 0x580 |
wcsncmp | 0x0 | 0x406118 | 0x8174 | 0x7574 | 0x579 |
NtOpenProcess | 0x0 | 0x40611c | 0x8178 | 0x7578 | 0xc7 |
strrchr | 0x0 | 0x406120 | 0x817c | 0x757c | 0x564 |
RtlGetNtVersionNumbers | 0x0 | 0x406124 | 0x8180 | 0x7580 | 0x259 |
CsrGetProcessId | 0x0 | 0x406128 | 0x8184 | 0x7584 | 0x9 |
NtDelayExecution | 0x0 | 0x40612c | 0x8188 | 0x7588 | 0x87 |
wcsstr | 0x0 | 0x406130 | 0x818c | 0x758c | 0x57e |
wcsrchr | 0x0 | 0x406134 | 0x8190 | 0x7590 | 0x57c |
NtSetInformationThread | 0x0 | 0x406138 | 0x8194 | 0x7594 | 0x134 |
_wcslwr | 0x0 | 0x40613c | 0x8198 | 0x7598 | 0x52c |
NtQueryInformationProcess | 0x0 | 0x406140 | 0x819c | 0x759c | 0xe7 |
RtlGetCurrentPeb | 0x0 | 0x406144 | 0x81a0 | 0x75a0 | 0x248 |
swprintf | 0x0 | 0x406148 | 0x81a4 | 0x75a4 | 0x569 |
wcsncpy | 0x0 | 0x40614c | 0x81a8 | 0x75a8 | 0x57a |
NtYieldExecution | 0x0 | 0x406150 | 0x81ac | 0x75ac | 0x166 |
NtTerminateProcess | 0x0 | 0x406154 | 0x81b0 | 0x75b0 | 0x150 |
RtlCreateHeap | 0x0 | 0x406158 | 0x81b4 | 0x75b4 | 0x1cc |
mbstowcs | 0x0 | 0x40615c | 0x81b8 | 0x75b8 | 0x54e |
sprintf | 0x0 | 0x406160 | 0x81bc | 0x75bc | 0x557 |
_stricmp | 0x0 | 0x406164 | 0x81c0 | 0x75c0 | 0x51f |
memset | 0x0 | 0x406168 | 0x81c4 | 0x75c4 | 0x553 |
_chkstk | 0x0 | 0x40616c | 0x81c8 | 0x75c8 | 0x50f |
memcpy | 0x0 | 0x406170 | 0x81cc | 0x75cc | 0x551 |
_allrem | 0x0 | 0x406174 | 0x81d0 | 0x75d0 | 0x507 |
RtlUnwind | 0x0 | 0x406178 | 0x81d4 | 0x75d4 | 0x341 |
KERNEL32.dll (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExpandEnvironmentStringsW | 0x0 | 0x406000 | 0x805c | 0x745c | 0x11d |
CreateThread | 0x0 | 0x406004 | 0x8060 | 0x7460 | 0xb5 |
DeleteFileA | 0x0 | 0x406008 | 0x8064 | 0x7464 | 0xd3 |
SetFileAttributesW | 0x0 | 0x40600c | 0x8068 | 0x7468 | 0x461 |
ResumeThread | 0x0 | 0x406010 | 0x806c | 0x746c | 0x413 |
DeleteFileW | 0x0 | 0x406014 | 0x8070 | 0x7470 | 0xd6 |
GetWindowsDirectoryW | 0x0 | 0x406018 | 0x8074 | 0x7474 | 0x2af |
CloseHandle | 0x0 | 0x40601c | 0x8078 | 0x7478 | 0x52 |
OutputDebugStringA | 0x0 | 0x406020 | 0x807c | 0x747c | 0x389 |
GetCurrentThreadId | 0x0 | 0x406024 | 0x8080 | 0x7480 | 0x1c5 |
GetShortPathNameW | 0x0 | 0x406028 | 0x8084 | 0x7484 | 0x261 |
FindNextFileW | 0x0 | 0x40602c | 0x8088 | 0x7488 | 0x145 |
GetModuleHandleA | 0x0 | 0x406030 | 0x808c | 0x748c | 0x215 |
GetModuleFileNameA | 0x0 | 0x406034 | 0x8090 | 0x7490 | 0x213 |
WaitForMultipleObjects | 0x0 | 0x406038 | 0x8094 | 0x7494 | 0x4f7 |
DeviceIoControl | 0x0 | 0x40603c | 0x8098 | 0x7498 | 0xdd |
CreateFileMappingA | 0x0 | 0x406040 | 0x809c | 0x749c | 0x89 |
LoadLibraryA | 0x0 | 0x406044 | 0x80a0 | 0x74a0 | 0x33c |
GetFullPathNameW | 0x0 | 0x406048 | 0x80a4 | 0x74a4 | 0x1fb |
ExitProcess | 0x0 | 0x40604c | 0x80a8 | 0x74a8 | 0x119 |
GetCommandLineW | 0x0 | 0x406050 | 0x80ac | 0x74ac | 0x187 |
GetComputerNameA | 0x0 | 0x406054 | 0x80b0 | 0x74b0 | 0x18c |
CreateFileA | 0x0 | 0x406058 | 0x80b4 | 0x74b4 | 0x88 |
GetFileSize | 0x0 | 0x40605c | 0x80b8 | 0x74b8 | 0x1f0 |
FindFirstFileW | 0x0 | 0x406060 | 0x80bc | 0x74bc | 0x139 |
SetFilePointer | 0x0 | 0x406064 | 0x80c0 | 0x74c0 | 0x466 |
GetLocaleInfoA | 0x0 | 0x406068 | 0x80c4 | 0x74c4 | 0x204 |
MapViewOfFile | 0x0 | 0x40606c | 0x80c8 | 0x74c8 | 0x357 |
UnmapViewOfFile | 0x0 | 0x406070 | 0x80cc | 0x74cc | 0x4d6 |
GetDriveTypeW | 0x0 | 0x406074 | 0x80d0 | 0x74d0 | 0x1d3 |
FreeLibrary | 0x0 | 0x406078 | 0x80d4 | 0x74d4 | 0x162 |
HeapAlloc | 0x0 | 0x40607c | 0x80d8 | 0x74d8 | 0x2cb |
InterlockedIncrement | 0x0 | 0x406080 | 0x80dc | 0x74dc | 0x2ef |
MoveFileExW | 0x0 | 0x406084 | 0x80e0 | 0x74e0 | 0x360 |
InterlockedDecrement | 0x0 | 0x406088 | 0x80e4 | 0x74e4 | 0x2eb |
GetCurrentProcess | 0x0 | 0x40608c | 0x80e8 | 0x74e8 | 0x1c0 |
GetLogicalDriveStringsW | 0x0 | 0x406090 | 0x80ec | 0x74ec | 0x208 |
HeapFree | 0x0 | 0x406094 | 0x80f0 | 0x74f0 | 0x2cf |
WaitForSingleObject | 0x0 | 0x406098 | 0x80f4 | 0x74f4 | 0x4f9 |
GetSystemDefaultLCID | 0x0 | 0x40609c | 0x80f8 | 0x74f8 | 0x26b |
OutputDebugStringW | 0x0 | 0x4060a0 | 0x80fc | 0x74fc | 0x38a |
GetTickCount | 0x0 | 0x4060a4 | 0x8100 | 0x7500 | 0x293 |
GetProcessHeap | 0x0 | 0x4060a8 | 0x8104 | 0x7504 | 0x24a |
GetLocalTime | 0x0 | 0x4060ac | 0x8108 | 0x7508 | 0x203 |
GlobalAlloc | 0x0 | 0x4060b0 | 0x810c | 0x750c | 0x2b3 |
GetSystemDirectoryW | 0x0 | 0x4060b4 | 0x8110 | 0x7510 | 0x270 |
TerminateThread | 0x0 | 0x4060b8 | 0x8114 | 0x7514 | 0x4c1 |
Sleep | 0x0 | 0x4060bc | 0x8118 | 0x7518 | 0x4b2 |
CopyFileW | 0x0 | 0x4060c0 | 0x811c | 0x751c | 0x75 |
LeaveCriticalSection | 0x0 | 0x4060c4 | 0x8120 | 0x7520 | 0x339 |
GetFileAttributesW | 0x0 | 0x4060c8 | 0x8124 | 0x7524 | 0x1ea |
CreateProcessA | 0x0 | 0x4060cc | 0x8128 | 0x7528 | 0xa4 |
ReadFile | 0x0 | 0x4060d0 | 0x812c | 0x752c | 0x3c0 |
CreateFileW | 0x0 | 0x4060d4 | 0x8130 | 0x7530 | 0x8f |
ExitThread | 0x0 | 0x4060d8 | 0x8134 | 0x7534 | 0x11a |
SetThreadPriority | 0x0 | 0x4060dc | 0x8138 | 0x7538 | 0x499 |
FlushFileBuffers | 0x0 | 0x4060e0 | 0x813c | 0x753c | 0x157 |
GetTempPathW | 0x0 | 0x4060e4 | 0x8140 | 0x7540 | 0x285 |
GetFileSizeEx | 0x0 | 0x4060e8 | 0x8144 | 0x7544 | 0x1f1 |
GetLastError | 0x0 | 0x4060ec | 0x8148 | 0x7548 | 0x202 |
GetProcAddress | 0x0 | 0x4060f0 | 0x814c | 0x754c | 0x245 |
SetVolumeLabelW | 0x0 | 0x4060f4 | 0x8150 | 0x7550 | 0x4a9 |
MoveFileW | 0x0 | 0x4060f8 | 0x8154 | 0x7554 | 0x363 |
EnterCriticalSection | 0x0 | 0x4060fc | 0x8158 | 0x7558 | 0xee |
GlobalFree | 0x0 | 0x406100 | 0x815c | 0x755c | 0x2ba |
FindClose | 0x0 | 0x406104 | 0x8160 | 0x7560 | 0x12e |
WriteFile | 0x0 | 0x406108 | 0x8164 | 0x7564 | 0x525 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
7120.tmp.exe | 4 | 0x00400000 | 0x0041CFFF | Relevant Image |
![]() |
32-bit | 0x00401810 |
![]() |
![]() |
...
|
qjpg.exe | 7 | 0x00400000 | 0x0041CFFF | Relevant Image |
![]() |
32-bit | 0x00401810 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.42839733 |
Malicious
|
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Satana | Satana ransomware | Ransomware |
5/5
|
...
|
Satana | Satana ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1025\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\coronaVi2022@protonmail.ch___Parameterinfo.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\coronaVi2022@protonmail.ch___eula.rtf | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\coronaVi2022@protonmail.ch___UiInfo.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\coronaVi2022@protonmail.ch___LocalizedData.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\coronaVi2022@protonmail.ch___Parameterinfo.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\coronaVi2022@protonmail.ch___UiInfo.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\coronaVi2022@protonmail.ch___SplashScreen.bmp | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\coronaVi2022@protonmail.ch___watermark.bmp | Dropped File | Stream |
Unknown
|
...
|
»
C:\coronaVi2022@protonmail.ch___BOOTSECT.bak | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\coronaVi2022@protonmail.ch___OfficeUpdateSchedule.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\coronaVi2022@protonmail.ch___splash.gif | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\coronaVi2022@protonmail.ch___splash@2x.gif | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\coronaVi2022@protonmail.ch___splash_11-lic.gif | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\coronaVi2022@protonmail.ch___win32_CopyDrop32x32.gif | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\coronaVi2022@protonmail.ch___jvm.hprof.txt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\README.txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\AppXManifest.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office16\coronaVi2022@protonmail.ch___SLERROR.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\coronaVi2022@protonmail.ch___THIRDPARTYLICENSEREADME-JAVAFX.txt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\Office16\coronaVi2022@protonmail.ch___OSPP.vbs | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AuthoredExtensions.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\lis.exe | Dropped File | Binary |
Unknown
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4010af |
Size Of Code | 0x200 |
Size Of Initialized Data | 0x600 |
File Type | FileType.executable |
Subsystem | Subsystem.native |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-03-10 13:02:36+00:00 |
Sections (2)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x102 | 0x200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 3.49 |
.rdata | 0x402000 | 0x4cc | 0x600 | 0x600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.16 |
Imports (1)
»
ntdll.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NtDeviceIoControlFile | 0x0 | 0x402000 | 0x2400 | 0xa00 | 0x8e |
NtTerminateProcess | 0x0 | 0x402004 | 0x2404 | 0xa04 | 0x150 |
RtlInitUnicodeString | 0x0 | 0x402008 | 0x2408 | 0xa08 | 0x26e |
RtlFreeUnicodeString | 0x0 | 0x40200c | 0x240c | 0xa0c | 0x23e |
NtDisplayString | 0x0 | 0x402010 | 0x2410 | 0xa10 | 0x8f |
NtCreateFile | 0x0 | 0x402014 | 0x2414 | 0xa14 | 0x6f |
NtClose | 0x0 | 0x402018 | 0x2418 | 0xa18 | 0x63 |
NtDelayExecution | 0x0 | 0x40201c | 0x241c | 0xa1c | 0x87 |
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AuthoredExtensions.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\coronaVi2022@protonmail.ch___ParameterInfo.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\coronaVi2022@protonmail.ch___FileSystemMetadata.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\coronaVi2022@protonmail.ch___coronaVi2022@protonmail.ch___AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml | Dropped File | Stream |
Not Queried
|
...
|
»