Malicious
Classifications
Ransomware
Threat Names
-
Dynamic Analysis Report
Created on 2022-05-23T14:42:54+00:00
3bae281a122628561deb145beffcb3b2c1b8ab51e0c96818ef7a1203738af5d4.exe
Windows Exe (x86-32)
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "49 days, 17 hours, 7 minutes, 57 seconds" to "10 seconds" to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\RDhJ0CNFevzX\Desktop\3bae281a122628561deb145beffcb3b2c1b8ab51e0c96818ef7a1203738af5d4.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x0047E61E |
Size Of Code | 0x0009D000 |
Size Of Initialized Data | 0x00035000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_CUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2022-04-10 09:23 (UTC+2) |
Version Information (6)
»
FileVersion | 1.0.0.0 |
FileDescription | 易语言程序 |
ProductName | 易语言程序 |
ProductVersion | 1.0.0.0 |
LegalCopyright | 作者版权所有 请尊重并使用正版 |
Comments | 本程序使用易语言编写(http://www.eyuyan.com) |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0009CF66 | 0x0009D000 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x0049E000 | 0x000155F4 | 0x00016000 | 0x0009E000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.61 |
.data | 0x004B4000 | 0x00045D48 | 0x00019000 | 0x000B4000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.0 |
.rsrc | 0x004FA000 | 0x00005958 | 0x00006000 | 0x000CD000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.82 |
Imports (12)
»
KERNEL32.dll (145)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GlobalLock | - | 0x0049E174 | 0x000B1418 | 0x000B1418 | 0x0000018C |
GlobalAlloc | - | 0x0049E178 | 0x000B141C | 0x000B141C | 0x00000181 |
SuspendThread | - | 0x0049E17C | 0x000B1420 | 0x000B1420 | 0x00000298 |
TerminateThread | - | 0x0049E180 | 0x000B1424 | 0x000B1424 | 0x0000029F |
ReleaseMutex | - | 0x0049E184 | 0x000B1428 | 0x000B1428 | 0x00000225 |
CreateMutexA | - | 0x0049E188 | 0x000B142C | 0x000B142C | 0x0000003F |
GetCurrentProcess | - | 0x0049E18C | 0x000B1430 | 0x000B1430 | 0x000000F7 |
GetWindowsDirectoryA | - | 0x0049E190 | 0x000B1434 | 0x000B1434 | 0x0000017D |
GetSystemDirectoryA | - | 0x0049E194 | 0x000B1438 | 0x000B1438 | 0x00000159 |
SetConsoleTextAttribute | - | 0x0049E198 | 0x000B143C | 0x000B143C | 0x00000258 |
GetConsoleScreenBufferInfo | - | 0x0049E19C | 0x000B1440 | 0x000B1440 | 0x000000EE |
SetStdHandle | - | 0x0049E1A0 | 0x000B1444 | 0x000B1444 | 0x0000027C |
IsBadCodePtr | - | 0x0049E1A4 | 0x000B1448 | 0x000B1448 | 0x000001B2 |
IsBadReadPtr | - | 0x0049E1A8 | 0x000B144C | 0x000B144C | 0x000001B5 |
CompareStringW | - | 0x0049E1AC | 0x000B1450 | 0x000B1450 | 0x00000022 |
GlobalUnlock | - | 0x0049E1B0 | 0x000B1454 | 0x000B1454 | 0x00000193 |
SetUnhandledExceptionFilter | - | 0x0049E1B4 | 0x000B1458 | 0x000B1458 | 0x0000028B |
GetStringTypeW | - | 0x0049E1B8 | 0x000B145C | 0x000B145C | 0x00000156 |
GetStringTypeA | - | 0x0049E1BC | 0x000B1460 | 0x000B1460 | 0x00000153 |
IsBadWritePtr | - | 0x0049E1C0 | 0x000B1464 | 0x000B1464 | 0x000001B8 |
VirtualAlloc | - | 0x0049E1C4 | 0x000B1468 | 0x000B1468 | 0x000002BB |
LCMapStringW | - | 0x0049E1C8 | 0x000B146C | 0x000B146C | 0x000001C0 |
LCMapStringA | - | 0x0049E1CC | 0x000B1470 | 0x000B1470 | 0x000001BF |
SetEnvironmentVariableA | - | 0x0049E1D0 | 0x000B1474 | 0x000B1474 | 0x00000262 |
VirtualFree | - | 0x0049E1D4 | 0x000B1478 | 0x000B1478 | 0x000002BF |
HeapCreate | - | 0x0049E1D8 | 0x000B147C | 0x000B147C | 0x0000019B |
HeapDestroy | - | 0x0049E1DC | 0x000B1480 | 0x000B1480 | 0x0000019D |
GetEnvironmentVariableA | - | 0x0049E1E0 | 0x000B1484 | 0x000B1484 | 0x00000109 |
GetFileType | - | 0x0049E1E4 | 0x000B1488 | 0x000B1488 | 0x00000115 |
SetHandleCount | - | 0x0049E1E8 | 0x000B148C | 0x000B148C | 0x0000026D |
GetEnvironmentStringsW | - | 0x0049E1EC | 0x000B1490 | 0x000B1490 | 0x00000108 |
GetEnvironmentStrings | - | 0x0049E1F0 | 0x000B1494 | 0x000B1494 | 0x00000106 |
FreeEnvironmentStringsW | - | 0x0049E1F4 | 0x000B1498 | 0x000B1498 | 0x000000B3 |
FreeEnvironmentStringsA | - | 0x0049E1F8 | 0x000B149C | 0x000B149C | 0x000000B2 |
UnhandledExceptionFilter | - | 0x0049E1FC | 0x000B14A0 | 0x000B14A0 | 0x000002AD |
GetACP | - | 0x0049E200 | 0x000B14A4 | 0x000B14A4 | 0x000000B9 |
HeapSize | - | 0x0049E204 | 0x000B14A8 | 0x000B14A8 | 0x000001A3 |
TerminateProcess | - | 0x0049E208 | 0x000B14AC | 0x000B14AC | 0x0000029E |
RaiseException | - | 0x0049E20C | 0x000B14B0 | 0x000B14B0 | 0x0000020B |
GetConsoleMode | - | 0x0049E210 | 0x000B14B4 | 0x000B14B4 | 0x000000EB |
SetConsoleMode | - | 0x0049E214 | 0x000B14B8 | 0x000B14B8 | 0x00000250 |
ReadConsoleInputA | - | 0x0049E218 | 0x000B14BC | 0x000B14BC | 0x0000020D |
GetLocalTime | - | 0x0049E21C | 0x000B14C0 | 0x000B14C0 | 0x0000011B |
GetSystemTime | - | 0x0049E220 | 0x000B14C4 | 0x000B14C4 | 0x0000015D |
GetTimeZoneInformation | - | 0x0049E224 | 0x000B14C8 | 0x000B14C8 | 0x00000170 |
RtlUnwind | - | 0x0049E228 | 0x000B14CC | 0x000B14CC | 0x0000022F |
GetStartupInfoA | - | 0x0049E22C | 0x000B14D0 | 0x000B14D0 | 0x00000150 |
GetOEMCP | - | 0x0049E230 | 0x000B14D4 | 0x000B14D4 | 0x00000131 |
GetCPInfo | - | 0x0049E234 | 0x000B14D8 | 0x000B14D8 | 0x000000BF |
GetProcessVersion | - | 0x0049E238 | 0x000B14DC | 0x000B14DC | 0x00000145 |
SetErrorMode | - | 0x0049E23C | 0x000B14E0 | 0x000B14E0 | 0x00000264 |
GlobalFlags | - | 0x0049E240 | 0x000B14E4 | 0x000B14E4 | 0x00000187 |
GetCurrentThread | - | 0x0049E244 | 0x000B14E8 | 0x000B14E8 | 0x000000F9 |
GetFileTime | - | 0x0049E248 | 0x000B14EC | 0x000B14EC | 0x00000114 |
GetFileSize | - | 0x0049E24C | 0x000B14F0 | 0x000B14F0 | 0x00000112 |
TlsGetValue | - | 0x0049E250 | 0x000B14F4 | 0x000B14F4 | 0x000002A4 |
LocalReAlloc | - | 0x0049E254 | 0x000B14F8 | 0x000B14F8 | 0x000001CF |
SetConsoleCursorPosition | - | 0x0049E258 | 0x000B14FC | 0x000B14FC | 0x00000245 |
GetStdHandle | - | 0x0049E25C | 0x000B1500 | 0x000B1500 | 0x00000152 |
CreateSemaphoreA | - | 0x0049E260 | 0x000B1504 | 0x000B1504 | 0x00000047 |
ResumeThread | - | 0x0049E264 | 0x000B1508 | 0x000B1508 | 0x0000022C |
ReleaseSemaphore | - | 0x0049E268 | 0x000B150C | 0x000B150C | 0x00000226 |
EnterCriticalSection | - | 0x0049E26C | 0x000B1510 | 0x000B1510 | 0x00000066 |
LeaveCriticalSection | - | 0x0049E270 | 0x000B1514 | 0x000B1514 | 0x000001C1 |
GetProfileStringA | - | 0x0049E274 | 0x000B1518 | 0x000B1518 | 0x0000014B |
WriteFile | - | 0x0049E278 | 0x000B151C | 0x000B151C | 0x000002DF |
WaitForMultipleObjects | - | 0x0049E27C | 0x000B1520 | 0x000B1520 | 0x000002CC |
CreateFileA | - | 0x0049E280 | 0x000B1524 | 0x000B1524 | 0x00000034 |
SetEvent | - | 0x0049E284 | 0x000B1528 | 0x000B1528 | 0x00000265 |
FindResourceA | - | 0x0049E288 | 0x000B152C | 0x000B152C | 0x000000A3 |
LoadResource | - | 0x0049E28C | 0x000B1530 | 0x000B1530 | 0x000001C7 |
LockResource | - | 0x0049E290 | 0x000B1534 | 0x000B1534 | 0x000001D5 |
ReadFile | - | 0x0049E294 | 0x000B1538 | 0x000B1538 | 0x00000218 |
lstrlenW | - | 0x0049E298 | 0x000B153C | 0x000B153C | 0x00000309 |
GetModuleFileNameA | - | 0x0049E29C | 0x000B1540 | 0x000B1540 | 0x00000124 |
WideCharToMultiByte | - | 0x0049E2A0 | 0x000B1544 | 0x000B1544 | 0x000002D2 |
MultiByteToWideChar | - | 0x0049E2A4 | 0x000B1548 | 0x000B1548 | 0x000001E4 |
GetCurrentThreadId | - | 0x0049E2A8 | 0x000B154C | 0x000B154C | 0x000000FA |
ExitProcess | - | 0x0049E2AC | 0x000B1550 | 0x000B1550 | 0x0000007D |
GlobalSize | - | 0x0049E2B0 | 0x000B1554 | 0x000B1554 | 0x00000190 |
GlobalFree | - | 0x0049E2B4 | 0x000B1558 | 0x000B1558 | 0x00000188 |
DeleteCriticalSection | - | 0x0049E2B8 | 0x000B155C | 0x000B155C | 0x00000055 |
InitializeCriticalSection | - | 0x0049E2BC | 0x000B1560 | 0x000B1560 | 0x000001AA |
lstrcatA | - | 0x0049E2C0 | 0x000B1564 | 0x000B1564 | 0x000002F9 |
lstrlenA | - | 0x0049E2C4 | 0x000B1568 | 0x000B1568 | 0x00000308 |
WinExec | - | 0x0049E2C8 | 0x000B156C | 0x000B156C | 0x000002D3 |
lstrcpyA | - | 0x0049E2CC | 0x000B1570 | 0x000B1570 | 0x00000302 |
FindNextFileA | - | 0x0049E2D0 | 0x000B1574 | 0x000B1574 | 0x0000009D |
GlobalReAlloc | - | 0x0049E2D4 | 0x000B1578 | 0x000B1578 | 0x0000018F |
HeapFree | - | 0x0049E2D8 | 0x000B157C | 0x000B157C | 0x0000019F |
HeapReAlloc | - | 0x0049E2DC | 0x000B1580 | 0x000B1580 | 0x000001A2 |
GetProcessHeap | - | 0x0049E2E0 | 0x000B1584 | 0x000B1584 | 0x00000140 |
HeapAlloc | - | 0x0049E2E4 | 0x000B1588 | 0x000B1588 | 0x00000199 |
GetFullPathNameA | - | 0x0049E2E8 | 0x000B158C | 0x000B158C | 0x00000116 |
FreeLibrary | - | 0x0049E2EC | 0x000B1590 | 0x000B1590 | 0x000000B4 |
LoadLibraryA | - | 0x0049E2F0 | 0x000B1594 | 0x000B1594 | 0x000001C2 |
GetLastError | - | 0x0049E2F4 | 0x000B1598 | 0x000B1598 | 0x0000011A |
GetVersionExA | - | 0x0049E2F8 | 0x000B159C | 0x000B159C | 0x00000175 |
WritePrivateProfileStringA | - | 0x0049E2FC | 0x000B15A0 | 0x000B15A0 | 0x000002E5 |
CreateThread | - | 0x0049E300 | 0x000B15A4 | 0x000B15A4 | 0x0000004A |
CreateEventA | - | 0x0049E304 | 0x000B15A8 | 0x000B15A8 | 0x00000031 |
Sleep | - | 0x0049E308 | 0x000B15AC | 0x000B15AC | 0x00000296 |
TlsSetValue | - | 0x0049E30C | 0x000B15B0 | 0x000B15B0 | 0x000002A5 |
TlsFree | - | 0x0049E310 | 0x000B15B4 | 0x000B15B4 | 0x000002A3 |
GlobalHandle | - | 0x0049E314 | 0x000B15B8 | 0x000B15B8 | 0x0000018B |
TlsAlloc | - | 0x0049E318 | 0x000B15BC | 0x000B15BC | 0x000002A2 |
LocalAlloc | - | 0x0049E31C | 0x000B15C0 | 0x000B15C0 | 0x000001C8 |
lstrcmpA | - | 0x0049E320 | 0x000B15C4 | 0x000B15C4 | 0x000002FC |
GetVersion | - | 0x0049E324 | 0x000B15C8 | 0x000B15C8 | 0x00000174 |
GlobalGetAtomNameA | - | 0x0049E328 | 0x000B15CC | 0x000B15CC | 0x00000189 |
GlobalAddAtomA | - | 0x0049E32C | 0x000B15D0 | 0x000B15D0 | 0x0000017F |
GlobalFindAtomA | - | 0x0049E330 | 0x000B15D4 | 0x000B15D4 | 0x00000184 |
GlobalDeleteAtom | - | 0x0049E334 | 0x000B15D8 | 0x000B15D8 | 0x00000183 |
lstrcmpiA | - | 0x0049E338 | 0x000B15DC | 0x000B15DC | 0x000002FF |
SetEndOfFile | - | 0x0049E33C | 0x000B15E0 | 0x000B15E0 | 0x00000261 |
UnlockFile | - | 0x0049E340 | 0x000B15E4 | 0x000B15E4 | 0x000002AE |
LockFile | - | 0x0049E344 | 0x000B15E8 | 0x000B15E8 | 0x000001D3 |
FlushFileBuffers | - | 0x0049E348 | 0x000B15EC | 0x000B15EC | 0x000000AA |
SetFilePointer | - | 0x0049E34C | 0x000B15F0 | 0x000B15F0 | 0x0000026A |
DuplicateHandle | - | 0x0049E350 | 0x000B15F4 | 0x000B15F4 | 0x00000063 |
lstrcpynA | - | 0x0049E354 | 0x000B15F8 | 0x000B15F8 | 0x00000305 |
SetLastError | - | 0x0049E358 | 0x000B15FC | 0x000B15FC | 0x00000271 |
FileTimeToLocalFileTime | - | 0x0049E35C | 0x000B1600 | 0x000B1600 | 0x00000089 |
FileTimeToSystemTime | - | 0x0049E360 | 0x000B1604 | 0x000B1604 | 0x0000008A |
LocalFree | - | 0x0049E364 | 0x000B1608 | 0x000B1608 | 0x000001CC |
InterlockedDecrement | - | 0x0049E368 | 0x000B160C | 0x000B160C | 0x000001AD |
InterlockedIncrement | - | 0x0049E36C | 0x000B1610 | 0x000B1610 | 0x000001B0 |
GetTempPathA | - | 0x0049E370 | 0x000B1614 | 0x000B1614 | 0x00000165 |
FindFirstFileA | - | 0x0049E374 | 0x000B1618 | 0x000B1618 | 0x00000094 |
FindClose | - | 0x0049E378 | 0x000B161C | 0x000B161C | 0x00000090 |
SetFileAttributesA | - | 0x0049E37C | 0x000B1620 | 0x000B1620 | 0x00000268 |
GetFileAttributesA | - | 0x0049E380 | 0x000B1624 | 0x000B1624 | 0x0000010D |
MoveFileA | - | 0x0049E384 | 0x000B1628 | 0x000B1628 | 0x000001DD |
DeleteFileA | - | 0x0049E388 | 0x000B162C | 0x000B162C | 0x00000057 |
CopyFileA | - | 0x0049E38C | 0x000B1630 | 0x000B1630 | 0x00000028 |
SetCurrentDirectoryA | - | 0x0049E390 | 0x000B1634 | 0x000B1634 | 0x0000025D |
GetVolumeInformationA | - | 0x0049E394 | 0x000B1638 | 0x000B1638 | 0x00000177 |
CloseHandle | - | 0x0049E398 | 0x000B163C | 0x000B163C | 0x0000001B |
GetModuleHandleA | - | 0x0049E39C | 0x000B1640 | 0x000B1640 | 0x00000126 |
GetProcAddress | - | 0x0049E3A0 | 0x000B1644 | 0x000B1644 | 0x0000013E |
MulDiv | - | 0x0049E3A4 | 0x000B1648 | 0x000B1648 | 0x000001E3 |
GetCommandLineA | - | 0x0049E3A8 | 0x000B164C | 0x000B164C | 0x000000CA |
GetTickCount | - | 0x0049E3AC | 0x000B1650 | 0x000B1650 | 0x0000016D |
WaitForSingleObject | - | 0x0049E3B0 | 0x000B1654 | 0x000B1654 | 0x000002CE |
CompareStringA | - | 0x0049E3B4 | 0x000B1658 | 0x000B1658 | 0x00000021 |
USER32.dll (152)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetWindowDC | - | 0x0049E408 | 0x000B16AC | 0x000B16AC | 0x00000154 |
wsprintfA | - | 0x0049E40C | 0x000B16B0 | 0x000B16B0 | 0x000002AC |
CloseClipboard | - | 0x0049E410 | 0x000B16B4 | 0x000B16B4 | 0x0000003C |
GetClipboardData | - | 0x0049E414 | 0x000B16B8 | 0x000B16B8 | 0x000000F2 |
OpenClipboard | - | 0x0049E418 | 0x000B16BC | 0x000B16BC | 0x000001D3 |
SetClipboardData | - | 0x0049E41C | 0x000B16C0 | 0x000B16C0 | 0x00000223 |
EmptyClipboard | - | 0x0049E420 | 0x000B16C4 | 0x000B16C4 | 0x000000B4 |
GetSystemMetrics | - | 0x0049E424 | 0x000B16C8 | 0x000B16C8 | 0x00000146 |
GetCursorPos | - | 0x0049E428 | 0x000B16CC | 0x000B16CC | 0x000000FC |
MessageBoxA | - | 0x0049E42C | 0x000B16D0 | 0x000B16D0 | 0x000001BE |
SetWindowPos | - | 0x0049E430 | 0x000B16D4 | 0x000B16D4 | 0x0000025B |
SendMessageA | - | 0x0049E434 | 0x000B16D8 | 0x000B16D8 | 0x00000214 |
DestroyCursor | - | 0x0049E438 | 0x000B16DC | 0x000B16DC | 0x0000008B |
SetParent | - | 0x0049E43C | 0x000B16E0 | 0x000B16E0 | 0x0000023E |
IsWindow | - | 0x0049E440 | 0x000B16E4 | 0x000B16E4 | 0x0000018F |
PostMessageA | - | 0x0049E444 | 0x000B16E8 | 0x000B16E8 | 0x000001DE |
GetTopWindow | - | 0x0049E448 | 0x000B16EC | 0x000B16EC | 0x0000014C |
GetParent | - | 0x0049E44C | 0x000B16F0 | 0x000B16F0 | 0x00000135 |
GetFocus | - | 0x0049E450 | 0x000B16F4 | 0x000B16F4 | 0x00000107 |
GetClientRect | - | 0x0049E454 | 0x000B16F8 | 0x000B16F8 | 0x000000F0 |
InvalidateRect | - | 0x0049E458 | 0x000B16FC | 0x000B16FC | 0x0000017A |
ValidateRect | - | 0x0049E45C | 0x000B1700 | 0x000B1700 | 0x0000029A |
UpdateWindow | - | 0x0049E460 | 0x000B1704 | 0x000B1704 | 0x00000291 |
EqualRect | - | 0x0049E464 | 0x000B1708 | 0x000B1708 | 0x000000D1 |
GetWindowRect | - | 0x0049E468 | 0x000B170C | 0x000B170C | 0x0000015C |
SetForegroundWindow | - | 0x0049E46C | 0x000B1710 | 0x000B1710 | 0x00000230 |
DestroyMenu | - | 0x0049E470 | 0x000B1714 | 0x000B1714 | 0x0000008D |
IsChild | - | 0x0049E474 | 0x000B1718 | 0x000B1718 | 0x00000185 |
ReleaseDC | - | 0x0049E478 | 0x000B171C | 0x000B171C | 0x00000203 |
IsRectEmpty | - | 0x0049E47C | 0x000B1720 | 0x000B1720 | 0x0000018E |
FillRect | - | 0x0049E480 | 0x000B1724 | 0x000B1724 | 0x000000D4 |
GetDC | - | 0x0049E484 | 0x000B1728 | 0x000B1728 | 0x000000FD |
SetCursor | - | 0x0049E488 | 0x000B172C | 0x000B172C | 0x00000226 |
LoadCursorA | - | 0x0049E48C | 0x000B1730 | 0x000B1730 | 0x0000019A |
SetCursorPos | - | 0x0049E490 | 0x000B1734 | 0x000B1734 | 0x00000228 |
SetActiveWindow | - | 0x0049E494 | 0x000B1738 | 0x000B1738 | 0x0000021C |
GetSysColor | - | 0x0049E498 | 0x000B173C | 0x000B173C | 0x00000143 |
GetForegroundWindow | - | 0x0049E49C | 0x000B1740 | 0x000B1740 | 0x00000108 |
LoadIconA | - | 0x0049E4A0 | 0x000B1744 | 0x000B1744 | 0x0000019E |
TranslateMessage | - | 0x0049E4A4 | 0x000B1748 | 0x000B1748 | 0x00000282 |
DrawFrameControl | - | 0x0049E4A8 | 0x000B174C | 0x000B174C | 0x000000A8 |
DrawEdge | - | 0x0049E4AC | 0x000B1750 | 0x000B1750 | 0x000000A5 |
DrawFocusRect | - | 0x0049E4B0 | 0x000B1754 | 0x000B1754 | 0x000000A6 |
WindowFromPoint | - | 0x0049E4B4 | 0x000B1758 | 0x000B1758 | 0x000002A9 |
GetMessageA | - | 0x0049E4B8 | 0x000B175C | 0x000B175C | 0x0000012A |
DispatchMessageA | - | 0x0049E4BC | 0x000B1760 | 0x000B1760 | 0x00000095 |
SetRectEmpty | - | 0x0049E4C0 | 0x000B1764 | 0x000B1764 | 0x00000245 |
RegisterClipboardFormatA | - | 0x0049E4C4 | 0x000B1768 | 0x000B1768 | 0x000001F6 |
CreateIconFromResourceEx | - | 0x0049E4C8 | 0x000B176C | 0x000B176C | 0x00000053 |
CreateIconFromResource | - | 0x0049E4CC | 0x000B1770 | 0x000B1770 | 0x00000052 |
DrawIconEx | - | 0x0049E4D0 | 0x000B1774 | 0x000B1774 | 0x000000AA |
CreatePopupMenu | - | 0x0049E4D4 | 0x000B1778 | 0x000B1778 | 0x00000058 |
AppendMenuA | - | 0x0049E4D8 | 0x000B177C | 0x000B177C | 0x00000007 |
ModifyMenuA | - | 0x0049E4DC | 0x000B1780 | 0x000B1780 | 0x000001C4 |
CreateMenu | - | 0x0049E4E0 | 0x000B1784 | 0x000B1784 | 0x00000057 |
CreateAcceleratorTableA | - | 0x0049E4E4 | 0x000B1788 | 0x000B1788 | 0x00000046 |
GetDlgCtrlID | - | 0x0049E4E8 | 0x000B178C | 0x000B178C | 0x00000101 |
GetSubMenu | - | 0x0049E4EC | 0x000B1790 | 0x000B1790 | 0x00000142 |
EnableMenuItem | - | 0x0049E4F0 | 0x000B1794 | 0x000B1794 | 0x000000B5 |
ClientToScreen | - | 0x0049E4F4 | 0x000B1798 | 0x000B1798 | 0x0000003A |
EnumDisplaySettingsA | - | 0x0049E4F8 | 0x000B179C | 0x000B179C | 0x000000C5 |
LoadImageA | - | 0x0049E4FC | 0x000B17A0 | 0x000B17A0 | 0x000001A0 |
SystemParametersInfoA | - | 0x0049E500 | 0x000B17A4 | 0x000B17A4 | 0x00000271 |
ShowWindow | - | 0x0049E504 | 0x000B17A8 | 0x000B17A8 | 0x0000026A |
IsWindowEnabled | - | 0x0049E508 | 0x000B17AC | 0x000B17AC | 0x00000190 |
TranslateAcceleratorA | - | 0x0049E50C | 0x000B17B0 | 0x000B17B0 | 0x0000027F |
GetKeyState | - | 0x0049E510 | 0x000B17B4 | 0x000B17B4 | 0x00000112 |
CopyAcceleratorTableA | - | 0x0049E514 | 0x000B17B8 | 0x000B17B8 | 0x00000040 |
PostQuitMessage | - | 0x0049E518 | 0x000B17BC | 0x000B17BC | 0x000001E0 |
IsZoomed | - | 0x0049E51C | 0x000B17C0 | 0x000B17C0 | 0x00000193 |
GetClassInfoA | - | 0x0049E520 | 0x000B17C4 | 0x000B17C4 | 0x000000E7 |
DefWindowProcA | - | 0x0049E524 | 0x000B17C8 | 0x000B17C8 | 0x00000084 |
GetMenu | - | 0x0049E528 | 0x000B17CC | 0x000B17CC | 0x0000011C |
SetMenu | - | 0x0049E52C | 0x000B17D0 | 0x000B17D0 | 0x00000235 |
PeekMessageA | - | 0x0049E530 | 0x000B17D4 | 0x000B17D4 | 0x000001DC |
IsIconic | - | 0x0049E534 | 0x000B17D8 | 0x000B17D8 | 0x0000018C |
SetFocus | - | 0x0049E538 | 0x000B17DC | 0x000B17DC | 0x0000022F |
GetActiveWindow | - | 0x0049E53C | 0x000B17E0 | 0x000B17E0 | 0x000000DD |
GetWindow | - | 0x0049E540 | 0x000B17E4 | 0x000B17E4 | 0x00000152 |
DestroyAcceleratorTable | - | 0x0049E544 | 0x000B17E8 | 0x000B17E8 | 0x00000089 |
SetWindowRgn | - | 0x0049E548 | 0x000B17EC | 0x000B17EC | 0x0000025C |
GetMessagePos | - | 0x0049E54C | 0x000B17F0 | 0x000B17F0 | 0x0000012C |
ScreenToClient | - | 0x0049E550 | 0x000B17F4 | 0x000B17F4 | 0x0000020A |
ChildWindowFromPointEx | - | 0x0049E554 | 0x000B17F8 | 0x000B17F8 | 0x00000038 |
CopyRect | - | 0x0049E558 | 0x000B17FC | 0x000B17FC | 0x00000044 |
LoadBitmapA | - | 0x0049E55C | 0x000B1800 | 0x000B1800 | 0x00000198 |
WinHelpA | - | 0x0049E560 | 0x000B1804 | 0x000B1804 | 0x000002A6 |
KillTimer | - | 0x0049E564 | 0x000B1808 | 0x000B1808 | 0x00000195 |
SetTimer | - | 0x0049E568 | 0x000B180C | 0x000B180C | 0x00000252 |
ReleaseCapture | - | 0x0049E56C | 0x000B1810 | 0x000B1810 | 0x00000202 |
GetCapture | - | 0x0049E570 | 0x000B1814 | 0x000B1814 | 0x000000E4 |
SetCapture | - | 0x0049E574 | 0x000B1818 | 0x000B1818 | 0x0000021D |
GetScrollRange | - | 0x0049E578 | 0x000B181C | 0x000B181C | 0x00000140 |
SetScrollRange | - | 0x0049E57C | 0x000B1820 | 0x000B1820 | 0x00000248 |
SetScrollPos | - | 0x0049E580 | 0x000B1824 | 0x000B1824 | 0x00000247 |
GetWindowTextA | - | 0x0049E584 | 0x000B1828 | 0x000B1828 | 0x0000015E |
GetWindowTextLengthA | - | 0x0049E588 | 0x000B182C | 0x000B182C | 0x0000015F |
CharUpperA | - | 0x0049E58C | 0x000B1830 | 0x000B1830 | 0x0000002F |
UnregisterClassA | - | 0x0049E590 | 0x000B1834 | 0x000B1834 | 0x0000028B |
BeginPaint | - | 0x0049E594 | 0x000B1838 | 0x000B1838 | 0x0000000C |
EndPaint | - | 0x0049E598 | 0x000B183C | 0x000B183C | 0x000000BB |
TabbedTextOutA | - | 0x0049E59C | 0x000B1840 | 0x000B1840 | 0x00000273 |
DrawTextA | - | 0x0049E5A0 | 0x000B1844 | 0x000B1844 | 0x000000AF |
GrayStringA | - | 0x0049E5A4 | 0x000B1848 | 0x000B1848 | 0x00000164 |
GetDlgItem | - | 0x0049E5A8 | 0x000B184C | 0x000B184C | 0x00000102 |
DestroyWindow | - | 0x0049E5AC | 0x000B1850 | 0x000B1850 | 0x0000008E |
CreateDialogIndirectParamA | - | 0x0049E5B0 | 0x000B1854 | 0x000B1854 | 0x0000004C |
EndDialog | - | 0x0049E5B4 | 0x000B1858 | 0x000B1858 | 0x000000B9 |
GetNextDlgTabItem | - | 0x0049E5B8 | 0x000B185C | 0x000B185C | 0x00000133 |
GetWindowPlacement | - | 0x0049E5BC | 0x000B1860 | 0x000B1860 | 0x0000015B |
RegisterWindowMessageA | - | 0x0049E5C0 | 0x000B1864 | 0x000B1864 | 0x00000200 |
GetLastActivePopup | - | 0x0049E5C4 | 0x000B1868 | 0x000B1868 | 0x00000119 |
GetMessageTime | - | 0x0049E5C8 | 0x000B186C | 0x000B186C | 0x0000012D |
RemovePropA | - | 0x0049E5CC | 0x000B1870 | 0x000B1870 | 0x00000205 |
CallWindowProcA | - | 0x0049E5D0 | 0x000B1874 | 0x000B1874 | 0x00000016 |
GetPropA | - | 0x0049E5D4 | 0x000B1878 | 0x000B1878 | 0x0000013A |
UnhookWindowsHookEx | - | 0x0049E5D8 | 0x000B187C | 0x000B187C | 0x00000286 |
SetPropA | - | 0x0049E5DC | 0x000B1880 | 0x000B1880 | 0x00000242 |
GetClassLongA | - | 0x0049E5E0 | 0x000B1884 | 0x000B1884 | 0x000000EB |
CallNextHookEx | - | 0x0049E5E4 | 0x000B1888 | 0x000B1888 | 0x00000015 |
SetWindowsHookExA | - | 0x0049E5E8 | 0x000B188C | 0x000B188C | 0x00000262 |
CreateWindowExA | - | 0x0049E5EC | 0x000B1890 | 0x000B1890 | 0x00000059 |
GetMenuItemID | - | 0x0049E5F0 | 0x000B1894 | 0x000B1894 | 0x00000123 |
GetMenuItemCount | - | 0x0049E5F4 | 0x000B1898 | 0x000B1898 | 0x00000122 |
RegisterClassA | - | 0x0049E5F8 | 0x000B189C | 0x000B189C | 0x000001F2 |
GetScrollPos | - | 0x0049E5FC | 0x000B18A0 | 0x000B18A0 | 0x0000013F |
AdjustWindowRectEx | - | 0x0049E600 | 0x000B18A4 | 0x000B18A4 | 0x00000002 |
MapWindowPoints | - | 0x0049E604 | 0x000B18A8 | 0x000B18A8 | 0x000001B9 |
SendDlgItemMessageA | - | 0x0049E608 | 0x000B18AC | 0x000B18AC | 0x0000020F |
ScrollWindowEx | - | 0x0049E60C | 0x000B18B0 | 0x000B18B0 | 0x0000020E |
IsDialogMessageA | - | 0x0049E610 | 0x000B18B4 | 0x000B18B4 | 0x00000188 |
SetWindowTextA | - | 0x0049E614 | 0x000B18B8 | 0x000B18B8 | 0x0000025E |
MoveWindow | - | 0x0049E618 | 0x000B18BC | 0x000B18BC | 0x000001C9 |
CheckMenuItem | - | 0x0049E61C | 0x000B18C0 | 0x000B18C0 | 0x00000034 |
SetMenuItemBitmaps | - | 0x0049E620 | 0x000B18C4 | 0x000B18C4 | 0x00000239 |
GetMenuState | - | 0x0049E624 | 0x000B18C8 | 0x000B18C8 | 0x00000127 |
GetMenuCheckMarkDimensions | - | 0x0049E628 | 0x000B18CC | 0x000B18CC | 0x0000011E |
GetClassNameA | - | 0x0049E62C | 0x000B18D0 | 0x000B18D0 | 0x000000ED |
GetDesktopWindow | - | 0x0049E630 | 0x000B18D4 | 0x000B18D4 | 0x000000FF |
LoadStringA | - | 0x0049E634 | 0x000B18D8 | 0x000B18D8 | 0x000001AB |
GetSysColorBrush | - | 0x0049E638 | 0x000B18DC | 0x000B18DC | 0x00000144 |
SetRect | - | 0x0049E63C | 0x000B18E0 | 0x000B18E0 | 0x00000244 |
InflateRect | - | 0x0049E640 | 0x000B18E4 | 0x000B18E4 | 0x00000171 |
IntersectRect | - | 0x0049E644 | 0x000B18E8 | 0x000B18E8 | 0x00000179 |
DestroyIcon | - | 0x0049E648 | 0x000B18EC | 0x000B18EC | 0x0000008C |
PtInRect | - | 0x0049E64C | 0x000B18F0 | 0x000B18F0 | 0x000001EA |
OffsetRect | - | 0x0049E650 | 0x000B18F4 | 0x000B18F4 | 0x000001D2 |
IsWindowVisible | - | 0x0049E654 | 0x000B18F8 | 0x000B18F8 | 0x00000192 |
EnableWindow | - | 0x0049E658 | 0x000B18FC | 0x000B18FC | 0x000000B7 |
RedrawWindow | - | 0x0049E65C | 0x000B1900 | 0x000B1900 | 0x000001F1 |
GetWindowLongA | - | 0x0049E660 | 0x000B1904 | 0x000B1904 | 0x00000156 |
SetWindowLongA | - | 0x0049E664 | 0x000B1908 | 0x000B1908 | 0x00000258 |
GDI32.dll (82)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetPolyFillMode | - | 0x0049E028 | 0x000B12CC | 0x000B12CC | 0x000001EB |
SetBkColor | - | 0x0049E02C | 0x000B12D0 | 0x000B12D0 | 0x000001CD |
CreateRectRgnIndirect | - | 0x0049E030 | 0x000B12D4 | 0x000B12D4 | 0x00000049 |
SetStretchBltMode | - | 0x0049E034 | 0x000B12D8 | 0x000B12D8 | 0x000001EF |
GetClipRgn | - | 0x0049E038 | 0x000B12DC | 0x000B12DC | 0x0000011B |
CreatePolygonRgn | - | 0x0049E03C | 0x000B12E0 | 0x000B12E0 | 0x00000047 |
SelectClipRgn | - | 0x0049E040 | 0x000B12E4 | 0x000B12E4 | 0x000001C5 |
DeleteObject | - | 0x0049E044 | 0x000B12E8 | 0x000B12E8 | 0x00000053 |
CreateDIBitmap | - | 0x0049E048 | 0x000B12EC | 0x000B12EC | 0x00000030 |
GetSystemPaletteEntries | - | 0x0049E04C | 0x000B12F0 | 0x000B12F0 | 0x00000163 |
CreatePalette | - | 0x0049E050 | 0x000B12F4 | 0x000B12F4 | 0x00000042 |
StretchBlt | - | 0x0049E054 | 0x000B12F8 | 0x000B12F8 | 0x00000200 |
SelectPalette | - | 0x0049E058 | 0x000B12FC | 0x000B12FC | 0x000001C8 |
RealizePalette | - | 0x0049E05C | 0x000B1300 | 0x000B1300 | 0x000001AC |
GetDIBits | - | 0x0049E060 | 0x000B1304 | 0x000B1304 | 0x00000124 |
GetWindowExtEx | - | 0x0049E064 | 0x000B1308 | 0x000B1308 | 0x0000017B |
GetViewportOrgEx | - | 0x0049E068 | 0x000B130C | 0x000B130C | 0x00000179 |
GetWindowOrgEx | - | 0x0049E06C | 0x000B1310 | 0x000B1310 | 0x0000017C |
BeginPath | - | 0x0049E070 | 0x000B1314 | 0x000B1314 | 0x00000010 |
EndPath | - | 0x0049E074 | 0x000B1318 | 0x000B1318 | 0x0000005D |
PathToRegion | - | 0x0049E078 | 0x000B131C | 0x000B131C | 0x00000195 |
CreateEllipticRgn | - | 0x0049E07C | 0x000B1320 | 0x000B1320 | 0x00000032 |
CreateRoundRectRgn | - | 0x0049E080 | 0x000B1324 | 0x000B1324 | 0x0000004A |
GetTextColor | - | 0x0049E084 | 0x000B1328 | 0x000B1328 | 0x00000169 |
GetBkMode | - | 0x0049E088 | 0x000B132C | 0x000B132C | 0x00000108 |
GetBkColor | - | 0x0049E08C | 0x000B1330 | 0x000B1330 | 0x00000107 |
GetROP2 | - | 0x0049E090 | 0x000B1334 | 0x000B1334 | 0x00000159 |
GetStretchBltMode | - | 0x0049E094 | 0x000B1338 | 0x000B1338 | 0x00000160 |
GetPolyFillMode | - | 0x0049E098 | 0x000B133C | 0x000B133C | 0x00000158 |
CreateCompatibleBitmap | - | 0x0049E09C | 0x000B1340 | 0x000B1340 | 0x00000029 |
CreateDCA | - | 0x0049E0A0 | 0x000B1344 | 0x000B1344 | 0x0000002B |
CreateBitmap | - | 0x0049E0A4 | 0x000B1348 | 0x000B1348 | 0x00000024 |
SelectObject | - | 0x0049E0A8 | 0x000B134C | 0x000B134C | 0x000001C7 |
GetObjectA | - | 0x0049E0AC | 0x000B1350 | 0x000B1350 | 0x0000014F |
CreatePen | - | 0x0049E0B0 | 0x000B1354 | 0x000B1354 | 0x00000044 |
PatBlt | - | 0x0049E0B4 | 0x000B1358 | 0x000B1358 | 0x00000194 |
CombineRgn | - | 0x0049E0B8 | 0x000B135C | 0x000B135C | 0x0000001E |
CreateRectRgn | - | 0x0049E0BC | 0x000B1360 | 0x000B1360 | 0x00000048 |
FillRgn | - | 0x0049E0C0 | 0x000B1364 | 0x000B1364 | 0x000000A8 |
CreateSolidBrush | - | 0x0049E0C4 | 0x000B1368 | 0x000B1368 | 0x0000004D |
GetStockObject | - | 0x0049E0C8 | 0x000B136C | 0x000B136C | 0x0000015F |
CreateFontIndirectA | - | 0x0049E0CC | 0x000B1370 | 0x000B1370 | 0x00000037 |
EndPage | - | 0x0049E0D0 | 0x000B1374 | 0x000B1374 | 0x0000005C |
EndDoc | - | 0x0049E0D4 | 0x000B1378 | 0x000B1378 | 0x0000005A |
DeleteDC | - | 0x0049E0D8 | 0x000B137C | 0x000B137C | 0x00000050 |
StartDocA | - | 0x0049E0DC | 0x000B1380 | 0x000B1380 | 0x000001FC |
StartPage | - | 0x0049E0E0 | 0x000B1384 | 0x000B1384 | 0x000001FF |
BitBlt | - | 0x0049E0E4 | 0x000B1388 | 0x000B1388 | 0x00000011 |
CreateCompatibleDC | - | 0x0049E0E8 | 0x000B138C | 0x000B138C | 0x0000002A |
Ellipse | - | 0x0049E0EC | 0x000B1390 | 0x000B1390 | 0x00000058 |
Rectangle | - | 0x0049E0F0 | 0x000B1394 | 0x000B1394 | 0x000001AF |
LPtoDP | - | 0x0049E0F4 | 0x000B1398 | 0x000B1398 | 0x00000182 |
DPtoLP | - | 0x0049E0F8 | 0x000B139C | 0x000B139C | 0x0000004E |
GetCurrentObject | - | 0x0049E0FC | 0x000B13A0 | 0x000B13A0 | 0x0000011E |
RoundRect | - | 0x0049E100 | 0x000B13A4 | 0x000B13A4 | 0x000001BA |
GetTextExtentPoint32A | - | 0x0049E104 | 0x000B13A8 | 0x000B13A8 | 0x0000016E |
GetDeviceCaps | - | 0x0049E108 | 0x000B13AC | 0x000B13AC | 0x00000125 |
SaveDC | - | 0x0049E10C | 0x000B13B0 | 0x000B13B0 | 0x000001C0 |
RestoreDC | - | 0x0049E110 | 0x000B13B4 | 0x000B13B4 | 0x000001B9 |
SetBkMode | - | 0x0049E114 | 0x000B13B8 | 0x000B13B8 | 0x000001CE |
SetROP2 | - | 0x0049E118 | 0x000B13BC | 0x000B13BC | 0x000001EC |
SetTextColor | - | 0x0049E11C | 0x000B13C0 | 0x000B13C0 | 0x000001F3 |
SetMapMode | - | 0x0049E120 | 0x000B13C4 | 0x000B13C4 | 0x000001E2 |
SetViewportOrgEx | - | 0x0049E124 | 0x000B13C8 | 0x000B13C8 | 0x000001F6 |
OffsetViewportOrgEx | - | 0x0049E128 | 0x000B13CC | 0x000B13CC | 0x0000018C |
SetViewportExtEx | - | 0x0049E12C | 0x000B13D0 | 0x000B13D0 | 0x000001F5 |
ScaleViewportExtEx | - | 0x0049E130 | 0x000B13D4 | 0x000B13D4 | 0x000001C1 |
SetWindowOrgEx | - | 0x0049E134 | 0x000B13D8 | 0x000B13D8 | 0x000001FA |
SetWindowExtEx | - | 0x0049E138 | 0x000B13DC | 0x000B13DC | 0x000001F9 |
ScaleWindowExtEx | - | 0x0049E13C | 0x000B13E0 | 0x000B13E0 | 0x000001C2 |
GetClipBox | - | 0x0049E140 | 0x000B13E4 | 0x000B13E4 | 0x0000011A |
ExcludeClipRect | - | 0x0049E144 | 0x000B13E8 | 0x000B13E8 | 0x00000098 |
MoveToEx | - | 0x0049E148 | 0x000B13EC | 0x000B13EC | 0x00000188 |
GetTextMetricsA | - | 0x0049E14C | 0x000B13F0 | 0x000B13F0 | 0x00000175 |
Escape | - | 0x0049E150 | 0x000B13F4 | 0x000B13F4 | 0x00000095 |
ExtTextOutA | - | 0x0049E154 | 0x000B13F8 | 0x000B13F8 | 0x0000009E |
TextOutA | - | 0x0049E158 | 0x000B13FC | 0x000B13FC | 0x00000205 |
RectVisible | - | 0x0049E15C | 0x000B1400 | 0x000B1400 | 0x000001AE |
PtVisible | - | 0x0049E160 | 0x000B1404 | 0x000B1404 | 0x000001AA |
GetViewportExtEx | - | 0x0049E164 | 0x000B1408 | 0x000B1408 | 0x00000178 |
ExtSelectClipRgn | - | 0x0049E168 | 0x000B140C | 0x000B140C | 0x0000009D |
LineTo | - | 0x0049E16C | 0x000B1410 | 0x000B1410 | 0x00000184 |
WINMM.dll (18)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
midiStreamRestart | - | 0x0049E66C | 0x000B1910 | 0x000B1910 | 0x00000063 |
midiStreamClose | - | 0x0049E670 | 0x000B1914 | 0x000B1914 | 0x0000005D |
midiOutReset | - | 0x0049E674 | 0x000B1918 | 0x000B1918 | 0x00000059 |
midiStreamStop | - | 0x0049E678 | 0x000B191C | 0x000B191C | 0x00000064 |
midiStreamOut | - | 0x0049E67C | 0x000B1920 | 0x000B1920 | 0x0000005F |
midiOutPrepareHeader | - | 0x0049E680 | 0x000B1924 | 0x000B1924 | 0x00000058 |
midiStreamProperty | - | 0x0049E684 | 0x000B1928 | 0x000B1928 | 0x00000062 |
midiStreamOpen | - | 0x0049E688 | 0x000B192C | 0x000B192C | 0x0000005E |
midiOutUnprepareHeader | - | 0x0049E68C | 0x000B1930 | 0x000B1930 | 0x0000005C |
waveOutOpen | - | 0x0049E690 | 0x000B1934 | 0x000B1934 | 0x000000B8 |
waveOutGetNumDevs | - | 0x0049E694 | 0x000B1938 | 0x000B1938 | 0x000000B2 |
waveOutClose | - | 0x0049E698 | 0x000B193C | 0x000B193C | 0x000000AC |
waveOutReset | - | 0x0049E69C | 0x000B1940 | 0x000B1940 | 0x000000BB |
waveOutPause | - | 0x0049E6A0 | 0x000B1944 | 0x000B1944 | 0x000000B9 |
waveOutWrite | - | 0x0049E6A4 | 0x000B1948 | 0x000B1948 | 0x000000C1 |
waveOutPrepareHeader | - | 0x0049E6A8 | 0x000B194C | 0x000B194C | 0x000000BA |
waveOutUnprepareHeader | - | 0x0049E6AC | 0x000B1950 | 0x000B1950 | 0x000000C0 |
waveOutRestart | - | 0x0049E6B0 | 0x000B1954 | 0x000B1954 | 0x000000BC |
WINSPOOL.DRV (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ClosePrinter | - | 0x0049E6B8 | 0x000B195C | 0x000B195C | 0x0000001C |
DocumentPropertiesA | - | 0x0049E6BC | 0x000B1960 | 0x000B1960 | 0x00000047 |
OpenPrinterA | - | 0x0049E6C0 | 0x000B1964 | 0x000B1964 | 0x0000007C |
ADVAPI32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCloseKey | - | 0x0049E000 | 0x000B12A4 | 0x000B12A4 | 0x0000015B |
RegOpenKeyExA | - | 0x0049E004 | 0x000B12A8 | 0x000B12A8 | 0x00000172 |
RegSetValueExA | - | 0x0049E008 | 0x000B12AC | 0x000B12AC | 0x00000186 |
RegCreateKeyA | - | 0x0049E00C | 0x000B12B0 | 0x000B12B0 | 0x0000015E |
RegQueryValueA | - | 0x0049E010 | 0x000B12B4 | 0x000B12B4 | 0x0000017A |
RegCreateKeyExA | - | 0x0049E014 | 0x000B12B8 | 0x000B12B8 | 0x0000015F |
SHELL32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Shell_NotifyIconA | - | 0x0049E3F8 | 0x000B169C | 0x000B169C | 0x00000079 |
SHGetSpecialFolderPathA | - | 0x0049E3FC | 0x000B16A0 | 0x000B16A0 | 0x00000054 |
ShellExecuteA | - | 0x0049E400 | 0x000B16A4 | 0x000B16A4 | 0x00000072 |
ole32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OleInitialize | - | 0x0049E708 | 0x000B19AC | 0x000B19AC | 0x000000C9 |
OleUninitialize | - | 0x0049E70C | 0x000B19B0 | 0x000B19B0 | 0x000000E0 |
CLSIDFromString | - | 0x0049E710 | 0x000B19B4 | 0x000B19B4 | 0x00000006 |
OLEAUT32.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantCopy | 0x0000000A | 0x0049E3BC | 0x000B1660 | 0x000B1660 | - |
VariantClear | 0x00000009 | 0x0049E3C0 | 0x000B1664 | 0x000B1664 | - |
VariantChangeType | 0x0000000C | 0x0049E3C4 | 0x000B1668 | 0x000B1668 | - |
SafeArrayGetUBound | 0x00000013 | 0x0049E3C8 | 0x000B166C | 0x000B166C | - |
SafeArrayGetLBound | 0x00000014 | 0x0049E3CC | 0x000B1670 | 0x000B1670 | - |
SafeArrayGetDim | 0x00000011 | 0x0049E3D0 | 0x000B1674 | 0x000B1674 | - |
SafeArrayUnaccessData | 0x00000018 | 0x0049E3D4 | 0x000B1678 | 0x000B1678 | - |
SafeArrayAccessData | 0x00000017 | 0x0049E3D8 | 0x000B167C | 0x000B167C | - |
SafeArrayGetElement | 0x00000019 | 0x0049E3DC | 0x000B1680 | 0x000B1680 | - |
VariantCopyInd | 0x0000000B | 0x0049E3E0 | 0x000B1684 | 0x000B1684 | - |
VariantInit | 0x00000008 | 0x0049E3E4 | 0x000B1688 | 0x000B1688 | - |
UnRegisterTypeLib | 0x000000BA | 0x0049E3E8 | 0x000B168C | 0x000B168C | - |
RegisterTypeLib | 0x000000A3 | 0x0049E3EC | 0x000B1690 | 0x000B1690 | - |
LoadTypeLib | 0x000000A1 | 0x0049E3F0 | 0x000B1694 | 0x000B1694 | - |
COMCTL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_Destroy | - | 0x0049E01C | 0x000B12C0 | 0x000B12C0 | 0x00000022 |
None | 0x00000011 | 0x0049E020 | 0x000B12C4 | 0x000B12C4 | - |
WS2_32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
getpeername | 0x00000005 | 0x0049E6C8 | 0x000B196C | 0x000B196C | - |
recv | 0x00000010 | 0x0049E6CC | 0x000B1970 | 0x000B1970 | - |
ioctlsocket | 0x0000000A | 0x0049E6D0 | 0x000B1974 | 0x000B1974 | - |
recvfrom | 0x00000011 | 0x0049E6D4 | 0x000B1978 | 0x000B1978 | - |
closesocket | 0x00000003 | 0x0049E6D8 | 0x000B197C | 0x000B197C | - |
WSACleanup | 0x00000074 | 0x0049E6DC | 0x000B1980 | 0x000B1980 | - |
inet_ntoa | 0x0000000C | 0x0049E6E0 | 0x000B1984 | 0x000B1984 | - |
ntohl | 0x0000000E | 0x0049E6E4 | 0x000B1988 | 0x000B1988 | - |
accept | 0x00000001 | 0x0049E6E8 | 0x000B198C | 0x000B198C | - |
WSAAsyncSelect | 0x00000065 | 0x0049E6EC | 0x000B1990 | 0x000B1990 | - |
comdlg32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ChooseColorA | - | 0x0049E6F4 | 0x000B1998 | 0x000B1998 | 0x00000000 |
GetOpenFileNameA | - | 0x0049E6F8 | 0x000B199C | 0x000B199C | 0x00000009 |
GetSaveFileNameA | - | 0x0049E6FC | 0x000B19A0 | 0x000B19A0 | 0x0000000B |
GetFileTitleA | - | 0x0049E700 | 0x000B19A4 | 0x000B19A4 | 0x00000007 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
3bae281a122628561deb145beffcb3b2c1b8ab51e0c96818ef7a1203738af5d4.exe | 1 | 0x00400000 | 0x004FFFFF | Relevant Image |
![]() |
32-bit | 0x00483A40 |
![]() |
...
|
C:\Users\RDhJ0CNFevzX\Desktop\3bae281a122628561deb145beffcb3b2c1b8ab51e0c96818ef7a1203738af5d4.exe.WsIR | Sample File | Empty |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\3zR9K4.mp4.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\3zR9K4.mp4.WsIR | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\we628slryqfcn.mp3.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\we628slryqfcn.mp3.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\k_oqupeew0f6q.m4a.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\k_oqupeew0f6q.m4a.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\rkek9t3rdv\bb7ilcqwymxeiup.xlsx.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\rkek9t3rdv\bb7ilcqwymxeiup.xlsx.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\12zna3pivem1wor.m4a.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\12zna3pivem1wor.m4a.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\-z4rq8r9ukr1.jpg.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\-z4rq8r9ukr1.jpg.wsir | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\s1hsdGQT_lQqo9A_5D_H.pps.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\s1hsdGQT_lQqo9A_5D_H.pps.WsIR | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\aju7snug.mp4.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\aju7snug.mp4.wsir | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\fIZIjrAeWDHx\Rkek9t3Rdv\WpL3Kq1Gh.m4a.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\fIZIjrAeWDHx\Rkek9t3Rdv\WpL3Kq1Gh.m4a.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\bUROA-.jpg.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\bUROA-.jpg.WsIR | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\ah-aj-xw2l9.pps.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\ah-aj-xw2l9.pps.wsir | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\IZYh4yd5GmG9gUQxF.m4a.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\IZYh4yd5GmG9gUQxF.m4a.WsIR | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\ldwzx9czy0viyiaugjtg.wav.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\ldwzx9czy0viyiaugjtg.wav.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\pv g_1cump.bmp.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\pv g_1cump.bmp.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\4fjcz48nwkc.mp4.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\4fjcz48nwkc.mp4.wsir | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\CPi5XIB.swf.WsIR | Dropped File | Compressed |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\CPi5XIB.swf.WsIR | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\9aseh.swf.wsir | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\fIZIjrAeWDHx\Rkek9t3Rdv\RbArjN3ZSZrBNDWJ1be.wav.WsIR | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\9aseh.swf.wsir | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\fIZIjrAeWDHx\Rkek9t3Rdv\RbArjN3ZSZrBNDWJ1be.wav.WsIR | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\b8oqnzm.mp4.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\b8oqnzm.mp4.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\95o-aud3nhe9qs4eevn.mp3.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\95o-aud3nhe9qs4eevn.mp3.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\9cfuw_e 1dao.odt.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\9cfuw_e 1dao.odt.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\rd18vxrba4wvaixb9.doc.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\rd18vxrba4wvaixb9.doc.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\giv1lznke-dybxmcbir3.mp3.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\giv1lznke-dybxmcbir3.mp3.wsir | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\0EEYc EDyqT.flv.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\0EEYc EDyqT.flv.WsIR | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\rkek9t3rdv\ke4ecubbut2.m4a.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\rkek9t3rdv\ke4ecubbut2.m4a.wsir | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\GiRIi3vyk91ALiSqq9.mkv.WsIR | Dropped File | Binary |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\GiRIi3vyk91ALiSqq9.mkv.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\fIZIjrAeWDHx\Rkek9t3Rdv\65OLmi32HgseAx.bmp.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\fIZIjrAeWDHx\Rkek9t3Rdv\65OLmi32HgseAx.bmp.WsIR | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\vj4l1avobz6t5xyoq.flv.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\vj4l1avobz6t5xyoq.flv.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\gxyvohpaxjzlat.pptx.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\gxyvohpaxjzlat.pptx.wsir | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\fIZIjrAeWDHx\Rkek9t3Rdv\faYc088QK.doc.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\fIZIjrAeWDHx\Rkek9t3Rdv\faYc088QK.doc.WsIR | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\rkek9t3rdv\h csagnwcw60j2xdsh.wav.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\rkek9t3rdv\h csagnwcw60j2xdsh.wav.wsir | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\oWU-E0n.avi.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\oWU-E0n.avi.WsIR | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\4ut8p0tdn5vkztsh.gif.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\4ut8p0tdn5vkztsh.gif.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\vmbov2jwdpztudyp.flv.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\vmbov2jwdpztudyp.flv.wsir | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\fIZIjrAeWDHx\Rkek9t3Rdv\xlhKZ08bI-i8DrHWTeNL.avi.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\fIZIjrAeWDHx\Rkek9t3Rdv\xlhKZ08bI-i8DrHWTeNL.avi.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\uD8bDL.xlsx.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\uD8bDL.xlsx.WsIR | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\jnsbv273_xuna9wdfumt.swf.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\jnsbv273_xuna9wdfumt.swf.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\jpnfqkpt0lf7c.avi.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\jpnfqkpt0lf7c.avi.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\8ksw42jkoolb1lix.jpg.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\8ksw42jkoolb1lix.jpg.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\rkek9t3rdv\kfprms4.mp3.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\rkek9t3rdv\kfprms4.mp3.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\g6-ktjjzl.png.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\g6-ktjjzl.png.wsir | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\EBL1pJQrCMBq.docx.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\EBL1pJQrCMBq.docx.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\4TbtoSVhWGA.jpg.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\4TbtoSVhWGA.jpg.WsIR | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\qhtez_bgydaj-l.png.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\qhtez_bgydaj-l.png.wsir | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\KYao8Y.ots.WsIR | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Desktop\KYao8Y.ots.WsIR | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\rkek9t3rdv\amb8c8tyuzftkxddd6vn.mp3.wsir | Dropped File | Stream |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\fizijraewdhx\rkek9t3rdv\amb8c8tyuzftkxddd6vn.mp3.wsir | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\Documents\½âÃÜÎļþ.key | Dropped File | Text |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\desktop.ini.wsir.wsir | Dropped File | Text |
Clean
|
...
|
»
c:\output | Dropped File | Empty |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\desktop\desktop.ini.wsir | Dropped File | Empty |
Clean
|
...
|
»