VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Dropper, Trojan, Pua |
b.exe
Windows Exe (x86-32)
Created at 2019-07-04T15:36:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\b.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x427f4a |
Size Of Code | 0x8de00 |
Size Of Initialized Data | 0x220600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-07-04 13:48:23+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x8dd2e | 0x8de00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.68 |
.rdata | 0x48f000 | 0x2e10e | 0x2e200 | 0x8e200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.76 |
.data | 0x4be000 | 0x8f74 | 0x5200 | 0xbc400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.2 |
.rsrc | 0x4c7000 | 0x1e5fdc | 0x1e6000 | 0xc1600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.99 |
.reloc | 0x6ad000 | 0x7130 | 0x7200 | 0x2a7600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.78 |
Imports (18)
»
WSOCK32.dll (23)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSACleanup | 0x74 | 0x48f7c8 | 0xbad90 | 0xb9f90 | - |
socket | 0x17 | 0x48f7cc | 0xbad94 | 0xb9f94 | - |
inet_ntoa | 0xc | 0x48f7d0 | 0xbad98 | 0xb9f98 | - |
setsockopt | 0x15 | 0x48f7d4 | 0xbad9c | 0xb9f9c | - |
ntohs | 0xf | 0x48f7d8 | 0xbada0 | 0xb9fa0 | - |
recvfrom | 0x11 | 0x48f7dc | 0xbada4 | 0xb9fa4 | - |
ioctlsocket | 0xa | 0x48f7e0 | 0xbada8 | 0xb9fa8 | - |
htons | 0x9 | 0x48f7e4 | 0xbadac | 0xb9fac | - |
WSAStartup | 0x73 | 0x48f7e8 | 0xbadb0 | 0xb9fb0 | - |
__WSAFDIsSet | 0x97 | 0x48f7ec | 0xbadb4 | 0xb9fb4 | - |
select | 0x12 | 0x48f7f0 | 0xbadb8 | 0xb9fb8 | - |
accept | 0x1 | 0x48f7f4 | 0xbadbc | 0xb9fbc | - |
listen | 0xd | 0x48f7f8 | 0xbadc0 | 0xb9fc0 | - |
bind | 0x2 | 0x48f7fc | 0xbadc4 | 0xb9fc4 | - |
closesocket | 0x3 | 0x48f800 | 0xbadc8 | 0xb9fc8 | - |
WSAGetLastError | 0x6f | 0x48f804 | 0xbadcc | 0xb9fcc | - |
recv | 0x10 | 0x48f808 | 0xbadd0 | 0xb9fd0 | - |
sendto | 0x14 | 0x48f80c | 0xbadd4 | 0xb9fd4 | - |
send | 0x13 | 0x48f810 | 0xbadd8 | 0xb9fd8 | - |
inet_addr | 0xb | 0x48f814 | 0xbaddc | 0xb9fdc | - |
gethostbyname | 0x34 | 0x48f818 | 0xbade0 | 0xb9fe0 | - |
gethostname | 0x39 | 0x48f81c | 0xbade4 | 0xb9fe4 | - |
connect | 0x4 | 0x48f820 | 0xbade8 | 0xb9fe8 | - |
VERSION.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFileVersionInfoW | 0x0 | 0x48f76c | 0xbad34 | 0xb9f34 | 0x6 |
GetFileVersionInfoSizeW | 0x0 | 0x48f770 | 0xbad38 | 0xb9f38 | 0x5 |
VerQueryValueW | 0x0 | 0x48f774 | 0xbad3c | 0xb9f3c | 0xe |
WINMM.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
timeGetTime | 0x0 | 0x48f7b8 | 0xbad80 | 0xb9f80 | 0x94 |
waveOutSetVolume | 0x0 | 0x48f7bc | 0xbad84 | 0xb9f84 | 0xbb |
mciSendStringW | 0x0 | 0x48f7c0 | 0xbad88 | 0xb9f88 | 0x32 |
COMCTL32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_ReplaceIcon | 0x0 | 0x48f088 | 0xba650 | 0xb9850 | 0x6f |
ImageList_Destroy | 0x0 | 0x48f08c | 0xba654 | 0xb9854 | 0x54 |
ImageList_Remove | 0x0 | 0x48f090 | 0xba658 | 0xb9858 | 0x6d |
ImageList_SetDragCursorImage | 0x0 | 0x48f094 | 0xba65c | 0xb985c | 0x72 |
ImageList_BeginDrag | 0x0 | 0x48f098 | 0xba660 | 0xb9860 | 0x50 |
ImageList_DragEnter | 0x0 | 0x48f09c | 0xba664 | 0xb9864 | 0x56 |
ImageList_DragLeave | 0x0 | 0x48f0a0 | 0xba668 | 0xb9868 | 0x57 |
ImageList_EndDrag | 0x0 | 0x48f0a4 | 0xba66c | 0xb986c | 0x5e |
ImageList_DragMove | 0x0 | 0x48f0a8 | 0xba670 | 0xb9870 | 0x58 |
InitCommonControlsEx | 0x0 | 0x48f0ac | 0xba674 | 0xb9874 | 0x7b |
ImageList_Create | 0x0 | 0x48f0b0 | 0xba678 | 0xb9878 | 0x53 |
MPR.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetUseConnectionW | 0x0 | 0x48f3f8 | 0xba9c0 | 0xb9bc0 | 0x49 |
WNetCancelConnection2W | 0x0 | 0x48f3fc | 0xba9c4 | 0xb9bc4 | 0xc |
WNetGetConnectionW | 0x0 | 0x48f400 | 0xba9c8 | 0xb9bc8 | 0x24 |
WNetAddConnection2W | 0x0 | 0x48f404 | 0xba9cc | 0xb9bcc | 0x6 |
WININET.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InternetQueryDataAvailable | 0x0 | 0x48f77c | 0xbad44 | 0xb9f44 | 0x9b |
InternetCloseHandle | 0x0 | 0x48f780 | 0xbad48 | 0xb9f48 | 0x6b |
InternetOpenW | 0x0 | 0x48f784 | 0xbad4c | 0xb9f4c | 0x9a |
InternetSetOptionW | 0x0 | 0x48f788 | 0xbad50 | 0xb9f50 | 0xaf |
InternetCrackUrlW | 0x0 | 0x48f78c | 0xbad54 | 0xb9f54 | 0x74 |
HttpQueryInfoW | 0x0 | 0x48f790 | 0xbad58 | 0xb9f58 | 0x5a |
InternetQueryOptionW | 0x0 | 0x48f794 | 0xbad5c | 0xb9f5c | 0x9e |
HttpOpenRequestW | 0x0 | 0x48f798 | 0xbad60 | 0xb9f60 | 0x58 |
HttpSendRequestW | 0x0 | 0x48f79c | 0xbad64 | 0xb9f64 | 0x5e |
FtpOpenFileW | 0x0 | 0x48f7a0 | 0xbad68 | 0xb9f68 | 0x35 |
FtpGetFileSize | 0x0 | 0x48f7a4 | 0xbad6c | 0xb9f6c | 0x32 |
InternetOpenUrlW | 0x0 | 0x48f7a8 | 0xbad70 | 0xb9f70 | 0x99 |
InternetReadFile | 0x0 | 0x48f7ac | 0xbad74 | 0xb9f74 | 0x9f |
InternetConnectW | 0x0 | 0x48f7b0 | 0xbad78 | 0xb9f78 | 0x72 |
PSAPI.DLL (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetProcessMemoryInfo | 0x0 | 0x48f484 | 0xbaa4c | 0xb9c4c | 0x15 |
IPHLPAPI.DLL (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IcmpCreateFile | 0x0 | 0x48f154 | 0xba71c | 0xb991c | 0x85 |
IcmpCloseHandle | 0x0 | 0x48f158 | 0xba720 | 0xb9920 | 0x84 |
IcmpSendEcho | 0x0 | 0x48f15c | 0xba724 | 0xb9924 | 0x87 |
USERENV.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DestroyEnvironmentBlock | 0x0 | 0x48f750 | 0xbad18 | 0xb9f18 | 0x4 |
UnloadUserProfile | 0x0 | 0x48f754 | 0xbad1c | 0xb9f1c | 0x2c |
CreateEnvironmentBlock | 0x0 | 0x48f758 | 0xbad20 | 0xb9f20 | 0x0 |
LoadUserProfileW | 0x0 | 0x48f75c | 0xbad24 | 0xb9f24 | 0x21 |
UxTheme.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IsThemeActive | 0x0 | 0x48f764 | 0xbad2c | 0xb9f2c | 0x3f |
KERNEL32.dll (164)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DuplicateHandle | 0x0 | 0x48f164 | 0xba72c | 0xb992c | 0xe8 |
CreateThread | 0x0 | 0x48f168 | 0xba730 | 0xb9930 | 0xb5 |
WaitForSingleObject | 0x0 | 0x48f16c | 0xba734 | 0xb9934 | 0x4f9 |
HeapAlloc | 0x0 | 0x48f170 | 0xba738 | 0xb9938 | 0x2cb |
GetProcessHeap | 0x0 | 0x48f174 | 0xba73c | 0xb993c | 0x24a |
HeapFree | 0x0 | 0x48f178 | 0xba740 | 0xb9940 | 0x2cf |
Sleep | 0x0 | 0x48f17c | 0xba744 | 0xb9944 | 0x4b2 |
GetCurrentThreadId | 0x0 | 0x48f180 | 0xba748 | 0xb9948 | 0x1c5 |
MultiByteToWideChar | 0x0 | 0x48f184 | 0xba74c | 0xb994c | 0x367 |
MulDiv | 0x0 | 0x48f188 | 0xba750 | 0xb9950 | 0x366 |
GetVersionExW | 0x0 | 0x48f18c | 0xba754 | 0xb9954 | 0x2a4 |
IsWow64Process | 0x0 | 0x48f190 | 0xba758 | 0xb9958 | 0x30e |
GetSystemInfo | 0x0 | 0x48f194 | 0xba75c | 0xb995c | 0x273 |
FreeLibrary | 0x0 | 0x48f198 | 0xba760 | 0xb9960 | 0x162 |
LoadLibraryA | 0x0 | 0x48f19c | 0xba764 | 0xb9964 | 0x33c |
GetProcAddress | 0x0 | 0x48f1a0 | 0xba768 | 0xb9968 | 0x245 |
SetErrorMode | 0x0 | 0x48f1a4 | 0xba76c | 0xb996c | 0x458 |
GetModuleFileNameW | 0x0 | 0x48f1a8 | 0xba770 | 0xb9970 | 0x214 |
WideCharToMultiByte | 0x0 | 0x48f1ac | 0xba774 | 0xb9974 | 0x511 |
lstrcpyW | 0x0 | 0x48f1b0 | 0xba778 | 0xb9978 | 0x548 |
lstrlenW | 0x0 | 0x48f1b4 | 0xba77c | 0xb997c | 0x54e |
GetModuleHandleW | 0x0 | 0x48f1b8 | 0xba780 | 0xb9980 | 0x218 |
QueryPerformanceCounter | 0x0 | 0x48f1bc | 0xba784 | 0xb9984 | 0x3a7 |
VirtualFreeEx | 0x0 | 0x48f1c0 | 0xba788 | 0xb9988 | 0x4ed |
OpenProcess | 0x0 | 0x48f1c4 | 0xba78c | 0xb998c | 0x380 |
VirtualAllocEx | 0x0 | 0x48f1c8 | 0xba790 | 0xb9990 | 0x4ea |
WriteProcessMemory | 0x0 | 0x48f1cc | 0xba794 | 0xb9994 | 0x52e |
ReadProcessMemory | 0x0 | 0x48f1d0 | 0xba798 | 0xb9998 | 0x3c3 |
CreateFileW | 0x0 | 0x48f1d4 | 0xba79c | 0xb999c | 0x8f |
SetFilePointerEx | 0x0 | 0x48f1d8 | 0xba7a0 | 0xb99a0 | 0x467 |
SetEndOfFile | 0x0 | 0x48f1dc | 0xba7a4 | 0xb99a4 | 0x453 |
ReadFile | 0x0 | 0x48f1e0 | 0xba7a8 | 0xb99a8 | 0x3c0 |
WriteFile | 0x0 | 0x48f1e4 | 0xba7ac | 0xb99ac | 0x525 |
FlushFileBuffers | 0x0 | 0x48f1e8 | 0xba7b0 | 0xb99b0 | 0x157 |
TerminateProcess | 0x0 | 0x48f1ec | 0xba7b4 | 0xb99b4 | 0x4c0 |
CreateToolhelp32Snapshot | 0x0 | 0x48f1f0 | 0xba7b8 | 0xb99b8 | 0xbe |
Process32FirstW | 0x0 | 0x48f1f4 | 0xba7bc | 0xb99bc | 0x396 |
Process32NextW | 0x0 | 0x48f1f8 | 0xba7c0 | 0xb99c0 | 0x398 |
SetFileTime | 0x0 | 0x48f1fc | 0xba7c4 | 0xb99c4 | 0x46a |
GetFileAttributesW | 0x0 | 0x48f200 | 0xba7c8 | 0xb99c8 | 0x1ea |
FindFirstFileW | 0x0 | 0x48f204 | 0xba7cc | 0xb99cc | 0x139 |
SetCurrentDirectoryW | 0x0 | 0x48f208 | 0xba7d0 | 0xb99d0 | 0x44d |
GetLongPathNameW | 0x0 | 0x48f20c | 0xba7d4 | 0xb99d4 | 0x20f |
GetShortPathNameW | 0x0 | 0x48f210 | 0xba7d8 | 0xb99d8 | 0x261 |
DeleteFileW | 0x0 | 0x48f214 | 0xba7dc | 0xb99dc | 0xd6 |
FindNextFileW | 0x0 | 0x48f218 | 0xba7e0 | 0xb99e0 | 0x145 |
CopyFileExW | 0x0 | 0x48f21c | 0xba7e4 | 0xb99e4 | 0x72 |
MoveFileW | 0x0 | 0x48f220 | 0xba7e8 | 0xb99e8 | 0x363 |
CreateDirectoryW | 0x0 | 0x48f224 | 0xba7ec | 0xb99ec | 0x81 |
RemoveDirectoryW | 0x0 | 0x48f228 | 0xba7f0 | 0xb99f0 | 0x403 |
SetSystemPowerState | 0x0 | 0x48f22c | 0xba7f4 | 0xb99f4 | 0x48a |
QueryPerformanceFrequency | 0x0 | 0x48f230 | 0xba7f8 | 0xb99f8 | 0x3a8 |
FindResourceW | 0x0 | 0x48f234 | 0xba7fc | 0xb99fc | 0x14e |
LoadResource | 0x0 | 0x48f238 | 0xba800 | 0xb9a00 | 0x341 |
LockResource | 0x0 | 0x48f23c | 0xba804 | 0xb9a04 | 0x354 |
SizeofResource | 0x0 | 0x48f240 | 0xba808 | 0xb9a08 | 0x4b1 |
EnumResourceNamesW | 0x0 | 0x48f244 | 0xba80c | 0xb9a0c | 0x102 |
OutputDebugStringW | 0x0 | 0x48f248 | 0xba810 | 0xb9a10 | 0x38a |
GetTempPathW | 0x0 | 0x48f24c | 0xba814 | 0xb9a14 | 0x285 |
GetTempFileNameW | 0x0 | 0x48f250 | 0xba818 | 0xb9a18 | 0x283 |
DeviceIoControl | 0x0 | 0x48f254 | 0xba81c | 0xb9a1c | 0xdd |
GetLocalTime | 0x0 | 0x48f258 | 0xba820 | 0xb9a20 | 0x203 |
CompareStringW | 0x0 | 0x48f25c | 0xba824 | 0xb9a24 | 0x64 |
GetCurrentProcess | 0x0 | 0x48f260 | 0xba828 | 0xb9a28 | 0x1c0 |
EnterCriticalSection | 0x0 | 0x48f264 | 0xba82c | 0xb9a2c | 0xee |
LeaveCriticalSection | 0x0 | 0x48f268 | 0xba830 | 0xb9a30 | 0x339 |
GetStdHandle | 0x0 | 0x48f26c | 0xba834 | 0xb9a34 | 0x264 |
CreatePipe | 0x0 | 0x48f270 | 0xba838 | 0xb9a38 | 0xa1 |
InterlockedExchange | 0x0 | 0x48f274 | 0xba83c | 0xb9a3c | 0x2ec |
TerminateThread | 0x0 | 0x48f278 | 0xba840 | 0xb9a40 | 0x4c1 |
LoadLibraryExW | 0x0 | 0x48f27c | 0xba844 | 0xb9a44 | 0x33e |
FindResourceExW | 0x0 | 0x48f280 | 0xba848 | 0xb9a48 | 0x14d |
CopyFileW | 0x0 | 0x48f284 | 0xba84c | 0xb9a4c | 0x75 |
VirtualFree | 0x0 | 0x48f288 | 0xba850 | 0xb9a50 | 0x4ec |
FormatMessageW | 0x0 | 0x48f28c | 0xba854 | 0xb9a54 | 0x15e |
GetExitCodeProcess | 0x0 | 0x48f290 | 0xba858 | 0xb9a58 | 0x1df |
GetPrivateProfileStringW | 0x0 | 0x48f294 | 0xba85c | 0xb9a5c | 0x242 |
WritePrivateProfileStringW | 0x0 | 0x48f298 | 0xba860 | 0xb9a60 | 0x52b |
GetPrivateProfileSectionW | 0x0 | 0x48f29c | 0xba864 | 0xb9a64 | 0x240 |
WritePrivateProfileSectionW | 0x0 | 0x48f2a0 | 0xba868 | 0xb9a68 | 0x529 |
GetPrivateProfileSectionNamesW | 0x0 | 0x48f2a4 | 0xba86c | 0xb9a6c | 0x23f |
FileTimeToLocalFileTime | 0x0 | 0x48f2a8 | 0xba870 | 0xb9a70 | 0x124 |
FileTimeToSystemTime | 0x0 | 0x48f2ac | 0xba874 | 0xb9a74 | 0x125 |
SystemTimeToFileTime | 0x0 | 0x48f2b0 | 0xba878 | 0xb9a78 | 0x4bd |
LocalFileTimeToFileTime | 0x0 | 0x48f2b4 | 0xba87c | 0xb9a7c | 0x346 |
GetDriveTypeW | 0x0 | 0x48f2b8 | 0xba880 | 0xb9a80 | 0x1d3 |
GetDiskFreeSpaceExW | 0x0 | 0x48f2bc | 0xba884 | 0xb9a84 | 0x1ce |
GetDiskFreeSpaceW | 0x0 | 0x48f2c0 | 0xba888 | 0xb9a88 | 0x1cf |
GetVolumeInformationW | 0x0 | 0x48f2c4 | 0xba88c | 0xb9a8c | 0x2a7 |
SetVolumeLabelW | 0x0 | 0x48f2c8 | 0xba890 | 0xb9a90 | 0x4a9 |
CreateHardLinkW | 0x0 | 0x48f2cc | 0xba894 | 0xb9a94 | 0x93 |
SetFileAttributesW | 0x0 | 0x48f2d0 | 0xba898 | 0xb9a98 | 0x461 |
CreateEventW | 0x0 | 0x48f2d4 | 0xba89c | 0xb9a9c | 0x85 |
SetEvent | 0x0 | 0x48f2d8 | 0xba8a0 | 0xb9aa0 | 0x459 |
GetEnvironmentVariableW | 0x0 | 0x48f2dc | 0xba8a4 | 0xb9aa4 | 0x1dc |
SetEnvironmentVariableW | 0x0 | 0x48f2e0 | 0xba8a8 | 0xb9aa8 | 0x457 |
GlobalLock | 0x0 | 0x48f2e4 | 0xba8ac | 0xb9aac | 0x2be |
GlobalUnlock | 0x0 | 0x48f2e8 | 0xba8b0 | 0xb9ab0 | 0x2c5 |
GlobalAlloc | 0x0 | 0x48f2ec | 0xba8b4 | 0xb9ab4 | 0x2b3 |
GetFileSize | 0x0 | 0x48f2f0 | 0xba8b8 | 0xb9ab8 | 0x1f0 |
GlobalFree | 0x0 | 0x48f2f4 | 0xba8bc | 0xb9abc | 0x2ba |
GlobalMemoryStatusEx | 0x0 | 0x48f2f8 | 0xba8c0 | 0xb9ac0 | 0x2c0 |
Beep | 0x0 | 0x48f2fc | 0xba8c4 | 0xb9ac4 | 0x36 |
GetSystemDirectoryW | 0x0 | 0x48f300 | 0xba8c8 | 0xb9ac8 | 0x270 |
HeapReAlloc | 0x0 | 0x48f304 | 0xba8cc | 0xb9acc | 0x2d2 |
HeapSize | 0x0 | 0x48f308 | 0xba8d0 | 0xb9ad0 | 0x2d4 |
GetComputerNameW | 0x0 | 0x48f30c | 0xba8d4 | 0xb9ad4 | 0x18f |
GetWindowsDirectoryW | 0x0 | 0x48f310 | 0xba8d8 | 0xb9ad8 | 0x2af |
GetCurrentProcessId | 0x0 | 0x48f314 | 0xba8dc | 0xb9adc | 0x1c1 |
GetProcessIoCounters | 0x0 | 0x48f318 | 0xba8e0 | 0xb9ae0 | 0x24e |
CreateProcessW | 0x0 | 0x48f31c | 0xba8e4 | 0xb9ae4 | 0xa8 |
GetProcessId | 0x0 | 0x48f320 | 0xba8e8 | 0xb9ae8 | 0x24c |
SetPriorityClass | 0x0 | 0x48f324 | 0xba8ec | 0xb9aec | 0x47d |
LoadLibraryW | 0x0 | 0x48f328 | 0xba8f0 | 0xb9af0 | 0x33f |
VirtualAlloc | 0x0 | 0x48f32c | 0xba8f4 | 0xb9af4 | 0x4e9 |
IsDebuggerPresent | 0x0 | 0x48f330 | 0xba8f8 | 0xb9af8 | 0x300 |
GetCurrentDirectoryW | 0x0 | 0x48f334 | 0xba8fc | 0xb9afc | 0x1bf |
lstrcmpiW | 0x0 | 0x48f338 | 0xba900 | 0xb9b00 | 0x545 |
DecodePointer | 0x0 | 0x48f33c | 0xba904 | 0xb9b04 | 0xca |
GetLastError | 0x0 | 0x48f340 | 0xba908 | 0xb9b08 | 0x202 |
RaiseException | 0x0 | 0x48f344 | 0xba90c | 0xb9b0c | 0x3b1 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x48f348 | 0xba910 | 0xb9b10 | 0x2e3 |
DeleteCriticalSection | 0x0 | 0x48f34c | 0xba914 | 0xb9b14 | 0xd1 |
InterlockedDecrement | 0x0 | 0x48f350 | 0xba918 | 0xb9b18 | 0x2eb |
InterlockedIncrement | 0x0 | 0x48f354 | 0xba91c | 0xb9b1c | 0x2ef |
GetCurrentThread | 0x0 | 0x48f358 | 0xba920 | 0xb9b20 | 0x1c4 |
CloseHandle | 0x0 | 0x48f35c | 0xba924 | 0xb9b24 | 0x52 |
GetFullPathNameW | 0x0 | 0x48f360 | 0xba928 | 0xb9b28 | 0x1fb |
EncodePointer | 0x0 | 0x48f364 | 0xba92c | 0xb9b2c | 0xea |
ExitProcess | 0x0 | 0x48f368 | 0xba930 | 0xb9b30 | 0x119 |
GetModuleHandleExW | 0x0 | 0x48f36c | 0xba934 | 0xb9b34 | 0x217 |
ExitThread | 0x0 | 0x48f370 | 0xba938 | 0xb9b38 | 0x11a |
GetSystemTimeAsFileTime | 0x0 | 0x48f374 | 0xba93c | 0xb9b3c | 0x279 |
ResumeThread | 0x0 | 0x48f378 | 0xba940 | 0xb9b40 | 0x413 |
GetCommandLineW | 0x0 | 0x48f37c | 0xba944 | 0xb9b44 | 0x187 |
IsProcessorFeaturePresent | 0x0 | 0x48f380 | 0xba948 | 0xb9b48 | 0x304 |
IsValidCodePage | 0x0 | 0x48f384 | 0xba94c | 0xb9b4c | 0x30a |
GetACP | 0x0 | 0x48f388 | 0xba950 | 0xb9b50 | 0x168 |
GetOEMCP | 0x0 | 0x48f38c | 0xba954 | 0xb9b54 | 0x237 |
GetCPInfo | 0x0 | 0x48f390 | 0xba958 | 0xb9b58 | 0x172 |
SetLastError | 0x0 | 0x48f394 | 0xba95c | 0xb9b5c | 0x473 |
UnhandledExceptionFilter | 0x0 | 0x48f398 | 0xba960 | 0xb9b60 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x48f39c | 0xba964 | 0xb9b64 | 0x4a5 |
TlsAlloc | 0x0 | 0x48f3a0 | 0xba968 | 0xb9b68 | 0x4c5 |
TlsGetValue | 0x0 | 0x48f3a4 | 0xba96c | 0xb9b6c | 0x4c7 |
TlsSetValue | 0x0 | 0x48f3a8 | 0xba970 | 0xb9b70 | 0x4c8 |
TlsFree | 0x0 | 0x48f3ac | 0xba974 | 0xb9b74 | 0x4c6 |
GetStartupInfoW | 0x0 | 0x48f3b0 | 0xba978 | 0xb9b78 | 0x263 |
GetStringTypeW | 0x0 | 0x48f3b4 | 0xba97c | 0xb9b7c | 0x269 |
SetStdHandle | 0x0 | 0x48f3b8 | 0xba980 | 0xb9b80 | 0x487 |
GetFileType | 0x0 | 0x48f3bc | 0xba984 | 0xb9b84 | 0x1f3 |
GetConsoleCP | 0x0 | 0x48f3c0 | 0xba988 | 0xb9b88 | 0x19a |
GetConsoleMode | 0x0 | 0x48f3c4 | 0xba98c | 0xb9b8c | 0x1ac |
RtlUnwind | 0x0 | 0x48f3c8 | 0xba990 | 0xb9b90 | 0x418 |
ReadConsoleW | 0x0 | 0x48f3cc | 0xba994 | 0xb9b94 | 0x3be |
GetTimeZoneInformation | 0x0 | 0x48f3d0 | 0xba998 | 0xb9b98 | 0x298 |
GetDateFormatW | 0x0 | 0x48f3d4 | 0xba99c | 0xb9b9c | 0x1c8 |
GetTimeFormatW | 0x0 | 0x48f3d8 | 0xba9a0 | 0xb9ba0 | 0x297 |
LCMapStringW | 0x0 | 0x48f3dc | 0xba9a4 | 0xb9ba4 | 0x32d |
GetEnvironmentStringsW | 0x0 | 0x48f3e0 | 0xba9a8 | 0xb9ba8 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x48f3e4 | 0xba9ac | 0xb9bac | 0x161 |
WriteConsoleW | 0x0 | 0x48f3e8 | 0xba9b0 | 0xb9bb0 | 0x524 |
FindClose | 0x0 | 0x48f3ec | 0xba9b4 | 0xb9bb4 | 0x12e |
SetEnvironmentVariableA | 0x0 | 0x48f3f0 | 0xba9b8 | 0xb9bb8 | 0x456 |
USER32.dll (160)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AdjustWindowRectEx | 0x0 | 0x48f4cc | 0xbaa94 | 0xb9c94 | 0x3 |
CopyImage | 0x0 | 0x48f4d0 | 0xbaa98 | 0xb9c98 | 0x54 |
SetWindowPos | 0x0 | 0x48f4d4 | 0xbaa9c | 0xb9c9c | 0x2c6 |
GetCursorInfo | 0x0 | 0x48f4d8 | 0xbaaa0 | 0xb9ca0 | 0x11f |
RegisterHotKey | 0x0 | 0x48f4dc | 0xbaaa4 | 0xb9ca4 | 0x256 |
ClientToScreen | 0x0 | 0x48f4e0 | 0xbaaa8 | 0xb9ca8 | 0x47 |
GetKeyboardLayoutNameW | 0x0 | 0x48f4e4 | 0xbaaac | 0xb9cac | 0x141 |
IsCharAlphaW | 0x0 | 0x48f4e8 | 0xbaab0 | 0xb9cb0 | 0x1c4 |
IsCharAlphaNumericW | 0x0 | 0x48f4ec | 0xbaab4 | 0xb9cb4 | 0x1c3 |
IsCharLowerW | 0x0 | 0x48f4f0 | 0xbaab8 | 0xb9cb8 | 0x1c6 |
IsCharUpperW | 0x0 | 0x48f4f4 | 0xbaabc | 0xb9cbc | 0x1c8 |
GetMenuStringW | 0x0 | 0x48f4f8 | 0xbaac0 | 0xb9cc0 | 0x158 |
GetSubMenu | 0x0 | 0x48f4fc | 0xbaac4 | 0xb9cc4 | 0x17a |
GetCaretPos | 0x0 | 0x48f500 | 0xbaac8 | 0xb9cc8 | 0x10a |
IsZoomed | 0x0 | 0x48f504 | 0xbaacc | 0xb9ccc | 0x1e2 |
MonitorFromPoint | 0x0 | 0x48f508 | 0xbaad0 | 0xb9cd0 | 0x218 |
GetMonitorInfoW | 0x0 | 0x48f50c | 0xbaad4 | 0xb9cd4 | 0x15f |
SetWindowLongW | 0x0 | 0x48f510 | 0xbaad8 | 0xb9cd8 | 0x2c4 |
SetLayeredWindowAttributes | 0x0 | 0x48f514 | 0xbaadc | 0xb9cdc | 0x298 |
FlashWindow | 0x0 | 0x48f518 | 0xbaae0 | 0xb9ce0 | 0xfb |
GetClassLongW | 0x0 | 0x48f51c | 0xbaae4 | 0xb9ce4 | 0x110 |
TranslateAcceleratorW | 0x0 | 0x48f520 | 0xbaae8 | 0xb9ce8 | 0x2fa |
IsDialogMessageW | 0x0 | 0x48f524 | 0xbaaec | 0xb9cec | 0x1cd |
GetSysColor | 0x0 | 0x48f528 | 0xbaaf0 | 0xb9cf0 | 0x17b |
InflateRect | 0x0 | 0x48f52c | 0xbaaf4 | 0xb9cf4 | 0x1b5 |
DrawFocusRect | 0x0 | 0x48f530 | 0xbaaf8 | 0xb9cf8 | 0xc4 |
DrawTextW | 0x0 | 0x48f534 | 0xbaafc | 0xb9cfc | 0xd0 |
FrameRect | 0x0 | 0x48f538 | 0xbab00 | 0xb9d00 | 0xfd |
DrawFrameControl | 0x0 | 0x48f53c | 0xbab04 | 0xb9d04 | 0xc6 |
FillRect | 0x0 | 0x48f540 | 0xbab08 | 0xb9d08 | 0xf6 |
PtInRect | 0x0 | 0x48f544 | 0xbab0c | 0xb9d0c | 0x240 |
DestroyAcceleratorTable | 0x0 | 0x48f548 | 0xbab10 | 0xb9d10 | 0xa0 |
CreateAcceleratorTableW | 0x0 | 0x48f54c | 0xbab14 | 0xb9d14 | 0x58 |
SetCursor | 0x0 | 0x48f550 | 0xbab18 | 0xb9d18 | 0x288 |
GetWindowDC | 0x0 | 0x48f554 | 0xbab1c | 0xb9d1c | 0x192 |
GetSystemMetrics | 0x0 | 0x48f558 | 0xbab20 | 0xb9d20 | 0x17e |
GetActiveWindow | 0x0 | 0x48f55c | 0xbab24 | 0xb9d24 | 0x100 |
CharNextW | 0x0 | 0x48f560 | 0xbab28 | 0xb9d28 | 0x31 |
wsprintfW | 0x0 | 0x48f564 | 0xbab2c | 0xb9d2c | 0x333 |
RedrawWindow | 0x0 | 0x48f568 | 0xbab30 | 0xb9d30 | 0x24a |
DrawMenuBar | 0x0 | 0x48f56c | 0xbab34 | 0xb9d34 | 0xc9 |
DestroyMenu | 0x0 | 0x48f570 | 0xbab38 | 0xb9d38 | 0xa4 |
SetMenu | 0x0 | 0x48f574 | 0xbab3c | 0xb9d3c | 0x29c |
GetWindowTextLengthW | 0x0 | 0x48f578 | 0xbab40 | 0xb9d40 | 0x1a2 |
CreateMenu | 0x0 | 0x48f57c | 0xbab44 | 0xb9d44 | 0x6a |
IsDlgButtonChecked | 0x0 | 0x48f580 | 0xbab48 | 0xb9d48 | 0x1ce |
DefDlgProcW | 0x0 | 0x48f584 | 0xbab4c | 0xb9d4c | 0x95 |
CallWindowProcW | 0x0 | 0x48f588 | 0xbab50 | 0xb9d50 | 0x1e |
ReleaseCapture | 0x0 | 0x48f58c | 0xbab54 | 0xb9d54 | 0x264 |
SetCapture | 0x0 | 0x48f590 | 0xbab58 | 0xb9d58 | 0x280 |
CreateIconFromResourceEx | 0x0 | 0x48f594 | 0xbab5c | 0xb9d5c | 0x66 |
mouse_event | 0x0 | 0x48f598 | 0xbab60 | 0xb9d60 | 0x331 |
ExitWindowsEx | 0x0 | 0x48f59c | 0xbab64 | 0xb9d64 | 0xf5 |
SetActiveWindow | 0x0 | 0x48f5a0 | 0xbab68 | 0xb9d68 | 0x27f |
FindWindowExW | 0x0 | 0x48f5a4 | 0xbab6c | 0xb9d6c | 0xf9 |
EnumThreadWindows | 0x0 | 0x48f5a8 | 0xbab70 | 0xb9d70 | 0xef |
SetMenuDefaultItem | 0x0 | 0x48f5ac | 0xbab74 | 0xb9d74 | 0x29e |
InsertMenuItemW | 0x0 | 0x48f5b0 | 0xbab78 | 0xb9d78 | 0x1b9 |
IsMenu | 0x0 | 0x48f5b4 | 0xbab7c | 0xb9d7c | 0x1d2 |
TrackPopupMenuEx | 0x0 | 0x48f5b8 | 0xbab80 | 0xb9d80 | 0x2f7 |
GetCursorPos | 0x0 | 0x48f5bc | 0xbab84 | 0xb9d84 | 0x120 |
DeleteMenu | 0x0 | 0x48f5c0 | 0xbab88 | 0xb9d88 | 0x9e |
SetRect | 0x0 | 0x48f5c4 | 0xbab8c | 0xb9d8c | 0x2ae |
GetMenuItemID | 0x0 | 0x48f5c8 | 0xbab90 | 0xb9d90 | 0x152 |
GetMenuItemCount | 0x0 | 0x48f5cc | 0xbab94 | 0xb9d94 | 0x151 |
SetMenuItemInfoW | 0x0 | 0x48f5d0 | 0xbab98 | 0xb9d98 | 0x2a2 |
GetMenuItemInfoW | 0x0 | 0x48f5d4 | 0xbab9c | 0xb9d9c | 0x154 |
SetForegroundWindow | 0x0 | 0x48f5d8 | 0xbaba0 | 0xb9da0 | 0x293 |
IsIconic | 0x0 | 0x48f5dc | 0xbaba4 | 0xb9da4 | 0x1d1 |
FindWindowW | 0x0 | 0x48f5e0 | 0xbaba8 | 0xb9da8 | 0xfa |
MonitorFromRect | 0x0 | 0x48f5e4 | 0xbabac | 0xb9dac | 0x219 |
keybd_event | 0x0 | 0x48f5e8 | 0xbabb0 | 0xb9db0 | 0x330 |
SendInput | 0x0 | 0x48f5ec | 0xbabb4 | 0xb9db4 | 0x276 |
GetAsyncKeyState | 0x0 | 0x48f5f0 | 0xbabb8 | 0xb9db8 | 0x107 |
SetKeyboardState | 0x0 | 0x48f5f4 | 0xbabbc | 0xb9dbc | 0x296 |
GetKeyboardState | 0x0 | 0x48f5f8 | 0xbabc0 | 0xb9dc0 | 0x142 |
GetKeyState | 0x0 | 0x48f5fc | 0xbabc4 | 0xb9dc4 | 0x13d |
VkKeyScanW | 0x0 | 0x48f600 | 0xbabc8 | 0xb9dc8 | 0x321 |
LoadStringW | 0x0 | 0x48f604 | 0xbabcc | 0xb9dcc | 0x1fa |
DialogBoxParamW | 0x0 | 0x48f608 | 0xbabd0 | 0xb9dd0 | 0xac |
MessageBeep | 0x0 | 0x48f60c | 0xbabd4 | 0xb9dd4 | 0x20d |
EndDialog | 0x0 | 0x48f610 | 0xbabd8 | 0xb9dd8 | 0xda |
SendDlgItemMessageW | 0x0 | 0x48f614 | 0xbabdc | 0xb9ddc | 0x273 |
GetDlgItem | 0x0 | 0x48f618 | 0xbabe0 | 0xb9de0 | 0x127 |
SetWindowTextW | 0x0 | 0x48f61c | 0xbabe4 | 0xb9de4 | 0x2cb |
CopyRect | 0x0 | 0x48f620 | 0xbabe8 | 0xb9de8 | 0x55 |
ReleaseDC | 0x0 | 0x48f624 | 0xbabec | 0xb9dec | 0x265 |
GetDC | 0x0 | 0x48f628 | 0xbabf0 | 0xb9df0 | 0x121 |
EndPaint | 0x0 | 0x48f62c | 0xbabf4 | 0xb9df4 | 0xdc |
BeginPaint | 0x0 | 0x48f630 | 0xbabf8 | 0xb9df8 | 0xe |
GetClientRect | 0x0 | 0x48f634 | 0xbabfc | 0xb9dfc | 0x114 |
GetMenu | 0x0 | 0x48f638 | 0xbac00 | 0xb9e00 | 0x14b |
DestroyWindow | 0x0 | 0x48f63c | 0xbac04 | 0xb9e04 | 0xa6 |
EnumWindows | 0x0 | 0x48f640 | 0xbac08 | 0xb9e08 | 0xf2 |
GetDesktopWindow | 0x0 | 0x48f644 | 0xbac0c | 0xb9e0c | 0x123 |
IsWindow | 0x0 | 0x48f648 | 0xbac10 | 0xb9e10 | 0x1db |
IsWindowEnabled | 0x0 | 0x48f64c | 0xbac14 | 0xb9e14 | 0x1dc |
IsWindowVisible | 0x0 | 0x48f650 | 0xbac18 | 0xb9e18 | 0x1e0 |
EnableWindow | 0x0 | 0x48f654 | 0xbac1c | 0xb9e1c | 0xd8 |
InvalidateRect | 0x0 | 0x48f658 | 0xbac20 | 0xb9e20 | 0x1be |
GetWindowLongW | 0x0 | 0x48f65c | 0xbac24 | 0xb9e24 | 0x196 |
GetWindowThreadProcessId | 0x0 | 0x48f660 | 0xbac28 | 0xb9e28 | 0x1a4 |
AttachThreadInput | 0x0 | 0x48f664 | 0xbac2c | 0xb9e2c | 0xc |
GetFocus | 0x0 | 0x48f668 | 0xbac30 | 0xb9e30 | 0x12c |
GetWindowTextW | 0x0 | 0x48f66c | 0xbac34 | 0xb9e34 | 0x1a3 |
ScreenToClient | 0x0 | 0x48f670 | 0xbac38 | 0xb9e38 | 0x26d |
SendMessageTimeoutW | 0x0 | 0x48f674 | 0xbac3c | 0xb9e3c | 0x27b |
EnumChildWindows | 0x0 | 0x48f678 | 0xbac40 | 0xb9e40 | 0xdf |
CharUpperBuffW | 0x0 | 0x48f67c | 0xbac44 | 0xb9e44 | 0x3b |
GetParent | 0x0 | 0x48f680 | 0xbac48 | 0xb9e48 | 0x164 |
GetDlgCtrlID | 0x0 | 0x48f684 | 0xbac4c | 0xb9e4c | 0x126 |
SendMessageW | 0x0 | 0x48f688 | 0xbac50 | 0xb9e50 | 0x27c |
MapVirtualKeyW | 0x0 | 0x48f68c | 0xbac54 | 0xb9e54 | 0x208 |
PostMessageW | 0x0 | 0x48f690 | 0xbac58 | 0xb9e58 | 0x236 |
GetWindowRect | 0x0 | 0x48f694 | 0xbac5c | 0xb9e5c | 0x19c |
SetUserObjectSecurity | 0x0 | 0x48f698 | 0xbac60 | 0xb9e60 | 0x2be |
CloseDesktop | 0x0 | 0x48f69c | 0xbac64 | 0xb9e64 | 0x4a |
CloseWindowStation | 0x0 | 0x48f6a0 | 0xbac68 | 0xb9e68 | 0x4e |
OpenDesktopW | 0x0 | 0x48f6a4 | 0xbac6c | 0xb9e6c | 0x228 |
SetProcessWindowStation | 0x0 | 0x48f6a8 | 0xbac70 | 0xb9e70 | 0x2aa |
GetProcessWindowStation | 0x0 | 0x48f6ac | 0xbac74 | 0xb9e74 | 0x168 |
OpenWindowStationW | 0x0 | 0x48f6b0 | 0xbac78 | 0xb9e78 | 0x22d |
GetUserObjectSecurity | 0x0 | 0x48f6b4 | 0xbac7c | 0xb9e7c | 0x18c |
MessageBoxW | 0x0 | 0x48f6b8 | 0xbac80 | 0xb9e80 | 0x215 |
DefWindowProcW | 0x0 | 0x48f6bc | 0xbac84 | 0xb9e84 | 0x9c |
SetClipboardData | 0x0 | 0x48f6c0 | 0xbac88 | 0xb9e88 | 0x286 |
EmptyClipboard | 0x0 | 0x48f6c4 | 0xbac8c | 0xb9e8c | 0xd5 |
CountClipboardFormats | 0x0 | 0x48f6c8 | 0xbac90 | 0xb9e90 | 0x56 |
CloseClipboard | 0x0 | 0x48f6cc | 0xbac94 | 0xb9e94 | 0x49 |
GetClipboardData | 0x0 | 0x48f6d0 | 0xbac98 | 0xb9e98 | 0x116 |
IsClipboardFormatAvailable | 0x0 | 0x48f6d4 | 0xbac9c | 0xb9e9c | 0x1ca |
OpenClipboard | 0x0 | 0x48f6d8 | 0xbaca0 | 0xb9ea0 | 0x226 |
BlockInput | 0x0 | 0x48f6dc | 0xbaca4 | 0xb9ea4 | 0xf |
GetMessageW | 0x0 | 0x48f6e0 | 0xbaca8 | 0xb9ea8 | 0x15d |
LockWindowUpdate | 0x0 | 0x48f6e4 | 0xbacac | 0xb9eac | 0x1fd |
DispatchMessageW | 0x0 | 0x48f6e8 | 0xbacb0 | 0xb9eb0 | 0xaf |
TranslateMessage | 0x0 | 0x48f6ec | 0xbacb4 | 0xb9eb4 | 0x2fc |
PeekMessageW | 0x0 | 0x48f6f0 | 0xbacb8 | 0xb9eb8 | 0x233 |
UnregisterHotKey | 0x0 | 0x48f6f4 | 0xbacbc | 0xb9ebc | 0x308 |
CheckMenuRadioItem | 0x0 | 0x48f6f8 | 0xbacc0 | 0xb9ec0 | 0x40 |
CharLowerBuffW | 0x0 | 0x48f6fc | 0xbacc4 | 0xb9ec4 | 0x2d |
MoveWindow | 0x0 | 0x48f700 | 0xbacc8 | 0xb9ec8 | 0x21b |
SetFocus | 0x0 | 0x48f704 | 0xbaccc | 0xb9ecc | 0x292 |
PostQuitMessage | 0x0 | 0x48f708 | 0xbacd0 | 0xb9ed0 | 0x237 |
KillTimer | 0x0 | 0x48f70c | 0xbacd4 | 0xb9ed4 | 0x1e3 |
CreatePopupMenu | 0x0 | 0x48f710 | 0xbacd8 | 0xb9ed8 | 0x6b |
RegisterWindowMessageW | 0x0 | 0x48f714 | 0xbacdc | 0xb9edc | 0x263 |
SetTimer | 0x0 | 0x48f718 | 0xbace0 | 0xb9ee0 | 0x2bb |
ShowWindow | 0x0 | 0x48f71c | 0xbace4 | 0xb9ee4 | 0x2df |
CreateWindowExW | 0x0 | 0x48f720 | 0xbace8 | 0xb9ee8 | 0x6e |
RegisterClassExW | 0x0 | 0x48f724 | 0xbacec | 0xb9eec | 0x24d |
LoadIconW | 0x0 | 0x48f728 | 0xbacf0 | 0xb9ef0 | 0x1ed |
LoadCursorW | 0x0 | 0x48f72c | 0xbacf4 | 0xb9ef4 | 0x1eb |
GetSysColorBrush | 0x0 | 0x48f730 | 0xbacf8 | 0xb9ef8 | 0x17c |
GetForegroundWindow | 0x0 | 0x48f734 | 0xbacfc | 0xb9efc | 0x12d |
MessageBoxA | 0x0 | 0x48f738 | 0xbad00 | 0xb9f00 | 0x20e |
DestroyIcon | 0x0 | 0x48f73c | 0xbad04 | 0xb9f04 | 0xa3 |
SystemParametersInfoW | 0x0 | 0x48f740 | 0xbad08 | 0xb9f08 | 0x2ec |
LoadImageW | 0x0 | 0x48f744 | 0xbad0c | 0xb9f0c | 0x1ef |
GetClassNameW | 0x0 | 0x48f748 | 0xbad10 | 0xb9f10 | 0x112 |
GDI32.dll (35)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StrokePath | 0x0 | 0x48f0c4 | 0xba68c | 0xb988c | 0x2b6 |
DeleteObject | 0x0 | 0x48f0c8 | 0xba690 | 0xb9890 | 0xe6 |
GetTextExtentPoint32W | 0x0 | 0x48f0cc | 0xba694 | 0xb9894 | 0x21e |
ExtCreatePen | 0x0 | 0x48f0d0 | 0xba698 | 0xb9898 | 0x132 |
GetDeviceCaps | 0x0 | 0x48f0d4 | 0xba69c | 0xb989c | 0x1cb |
EndPath | 0x0 | 0x48f0d8 | 0xba6a0 | 0xb98a0 | 0xf3 |
SetPixel | 0x0 | 0x48f0dc | 0xba6a4 | 0xb98a4 | 0x29b |
CloseFigure | 0x0 | 0x48f0e0 | 0xba6a8 | 0xb98a8 | 0x1e |
CreateCompatibleBitmap | 0x0 | 0x48f0e4 | 0xba6ac | 0xb98ac | 0x2f |
CreateCompatibleDC | 0x0 | 0x48f0e8 | 0xba6b0 | 0xb98b0 | 0x30 |
SelectObject | 0x0 | 0x48f0ec | 0xba6b4 | 0xb98b4 | 0x277 |
StretchBlt | 0x0 | 0x48f0f0 | 0xba6b8 | 0xb98b8 | 0x2b3 |
GetDIBits | 0x0 | 0x48f0f4 | 0xba6bc | 0xb98bc | 0x1ca |
LineTo | 0x0 | 0x48f0f8 | 0xba6c0 | 0xb98c0 | 0x236 |
AngleArc | 0x0 | 0x48f0fc | 0xba6c4 | 0xb98c4 | 0x8 |
MoveToEx | 0x0 | 0x48f100 | 0xba6c8 | 0xb98c8 | 0x23a |
Ellipse | 0x0 | 0x48f104 | 0xba6cc | 0xb98cc | 0xed |
DeleteDC | 0x0 | 0x48f108 | 0xba6d0 | 0xb98d0 | 0xe3 |
GetPixel | 0x0 | 0x48f10c | 0xba6d4 | 0xb98d4 | 0x204 |
CreateDCW | 0x0 | 0x48f110 | 0xba6d8 | 0xb98d8 | 0x32 |
GetStockObject | 0x0 | 0x48f114 | 0xba6dc | 0xb98dc | 0x20d |
GetTextFaceW | 0x0 | 0x48f118 | 0xba6e0 | 0xb98e0 | 0x224 |
CreateFontW | 0x0 | 0x48f11c | 0xba6e4 | 0xb98e4 | 0x41 |
SetTextColor | 0x0 | 0x48f120 | 0xba6e8 | 0xb98e8 | 0x2a6 |
PolyDraw | 0x0 | 0x48f124 | 0xba6ec | 0xb98ec | 0x250 |
BeginPath | 0x0 | 0x48f128 | 0xba6f0 | 0xb98f0 | 0x12 |
Rectangle | 0x0 | 0x48f12c | 0xba6f4 | 0xb98f4 | 0x25f |
SetViewportOrgEx | 0x0 | 0x48f130 | 0xba6f8 | 0xb98f8 | 0x2a9 |
GetObjectW | 0x0 | 0x48f134 | 0xba6fc | 0xb98fc | 0x1fd |
SetBkMode | 0x0 | 0x48f138 | 0xba700 | 0xb9900 | 0x27f |
RoundRect | 0x0 | 0x48f13c | 0xba704 | 0xb9904 | 0x26a |
SetBkColor | 0x0 | 0x48f140 | 0xba708 | 0xb9908 | 0x27e |
CreatePen | 0x0 | 0x48f144 | 0xba70c | 0xb990c | 0x4b |
CreateSolidBrush | 0x0 | 0x48f148 | 0xba710 | 0xb9910 | 0x54 |
StrokeAndFillPath | 0x0 | 0x48f14c | 0xba714 | 0xb9914 | 0x2b5 |
COMDLG32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetOpenFileNameW | 0x0 | 0x48f0b8 | 0xba680 | 0xb9880 | 0xc |
GetSaveFileNameW | 0x0 | 0x48f0bc | 0xba684 | 0xb9884 | 0xe |
ADVAPI32.dll (33)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetAce | 0x0 | 0x48f000 | 0xba5c8 | 0xb97c8 | 0x123 |
RegEnumValueW | 0x0 | 0x48f004 | 0xba5cc | 0xb97cc | 0x252 |
RegDeleteValueW | 0x0 | 0x48f008 | 0xba5d0 | 0xb97d0 | 0x248 |
RegDeleteKeyW | 0x0 | 0x48f00c | 0xba5d4 | 0xb97d4 | 0x244 |
RegEnumKeyExW | 0x0 | 0x48f010 | 0xba5d8 | 0xb97d8 | 0x24f |
RegSetValueExW | 0x0 | 0x48f014 | 0xba5dc | 0xb97dc | 0x27e |
RegOpenKeyExW | 0x0 | 0x48f018 | 0xba5e0 | 0xb97e0 | 0x261 |
RegCloseKey | 0x0 | 0x48f01c | 0xba5e4 | 0xb97e4 | 0x230 |
RegQueryValueExW | 0x0 | 0x48f020 | 0xba5e8 | 0xb97e8 | 0x26e |
RegConnectRegistryW | 0x0 | 0x48f024 | 0xba5ec | 0xb97ec | 0x234 |
InitializeSecurityDescriptor | 0x0 | 0x48f028 | 0xba5f0 | 0xb97f0 | 0x177 |
InitializeAcl | 0x0 | 0x48f02c | 0xba5f4 | 0xb97f4 | 0x176 |
AdjustTokenPrivileges | 0x0 | 0x48f030 | 0xba5f8 | 0xb97f8 | 0x1f |
OpenThreadToken | 0x0 | 0x48f034 | 0xba5fc | 0xb97fc | 0x1fc |
OpenProcessToken | 0x0 | 0x48f038 | 0xba600 | 0xb9800 | 0x1f7 |
LookupPrivilegeValueW | 0x0 | 0x48f03c | 0xba604 | 0xb9804 | 0x197 |
DuplicateTokenEx | 0x0 | 0x48f040 | 0xba608 | 0xb9808 | 0xdf |
CreateProcessAsUserW | 0x0 | 0x48f044 | 0xba60c | 0xb980c | 0x7c |
CreateProcessWithLogonW | 0x0 | 0x48f048 | 0xba610 | 0xb9810 | 0x7d |
GetLengthSid | 0x0 | 0x48f04c | 0xba614 | 0xb9814 | 0x136 |
CopySid | 0x0 | 0x48f050 | 0xba618 | 0xb9818 | 0x76 |
LogonUserW | 0x0 | 0x48f054 | 0xba61c | 0xb981c | 0x18d |
AllocateAndInitializeSid | 0x0 | 0x48f058 | 0xba620 | 0xb9820 | 0x20 |
CheckTokenMembership | 0x0 | 0x48f05c | 0xba624 | 0xb9824 | 0x51 |
RegCreateKeyExW | 0x0 | 0x48f060 | 0xba628 | 0xb9828 | 0x239 |
FreeSid | 0x0 | 0x48f064 | 0xba62c | 0xb982c | 0x120 |
GetTokenInformation | 0x0 | 0x48f068 | 0xba630 | 0xb9830 | 0x15a |
GetSecurityDescriptorDacl | 0x0 | 0x48f06c | 0xba634 | 0xb9834 | 0x148 |
GetAclInformation | 0x0 | 0x48f070 | 0xba638 | 0xb9838 | 0x124 |
AddAce | 0x0 | 0x48f074 | 0xba63c | 0xb983c | 0x16 |
SetSecurityDescriptorDacl | 0x0 | 0x48f078 | 0xba640 | 0xb9840 | 0x2b6 |
GetUserNameW | 0x0 | 0x48f07c | 0xba644 | 0xb9844 | 0x165 |
InitiateSystemShutdownExW | 0x0 | 0x48f080 | 0xba648 | 0xb9848 | 0x17d |
SHELL32.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DragQueryPoint | 0x0 | 0x48f48c | 0xbaa54 | 0xb9c54 | 0x20 |
ShellExecuteExW | 0x0 | 0x48f490 | 0xbaa58 | 0xb9c58 | 0x121 |
DragQueryFileW | 0x0 | 0x48f494 | 0xbaa5c | 0xb9c5c | 0x1f |
SHEmptyRecycleBinW | 0x0 | 0x48f498 | 0xbaa60 | 0xb9c60 | 0xa5 |
SHGetPathFromIDListW | 0x0 | 0x48f49c | 0xbaa64 | 0xb9c64 | 0xd7 |
SHBrowseForFolderW | 0x0 | 0x48f4a0 | 0xbaa68 | 0xb9c68 | 0x7b |
SHCreateShellItem | 0x0 | 0x48f4a4 | 0xbaa6c | 0xb9c6c | 0x9a |
SHGetDesktopFolder | 0x0 | 0x48f4a8 | 0xbaa70 | 0xb9c70 | 0xb6 |
SHGetSpecialFolderLocation | 0x0 | 0x48f4ac | 0xbaa74 | 0xb9c74 | 0xdf |
SHGetFolderPathW | 0x0 | 0x48f4b0 | 0xbaa78 | 0xb9c78 | 0xc3 |
SHFileOperationW | 0x0 | 0x48f4b4 | 0xbaa7c | 0xb9c7c | 0xac |
ExtractIconExW | 0x0 | 0x48f4b8 | 0xbaa80 | 0xb9c80 | 0x2a |
Shell_NotifyIconW | 0x0 | 0x48f4bc | 0xbaa84 | 0xb9c84 | 0x12e |
ShellExecuteW | 0x0 | 0x48f4c0 | 0xbaa88 | 0xb9c88 | 0x122 |
DragFinish | 0x0 | 0x48f4c4 | 0xbaa8c | 0xb9c8c | 0x1b |
ole32.dll (22)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoTaskMemAlloc | 0x0 | 0x48f828 | 0xbadf0 | 0xb9ff0 | 0x67 |
CoTaskMemFree | 0x0 | 0x48f82c | 0xbadf4 | 0xb9ff4 | 0x68 |
CLSIDFromString | 0x0 | 0x48f830 | 0xbadf8 | 0xb9ff8 | 0x8 |
ProgIDFromCLSID | 0x0 | 0x48f834 | 0xbadfc | 0xb9ffc | 0x14b |
CLSIDFromProgID | 0x0 | 0x48f838 | 0xbae00 | 0xba000 | 0x6 |
OleSetMenuDescriptor | 0x0 | 0x48f83c | 0xbae04 | 0xba004 | 0x147 |
MkParseDisplayName | 0x0 | 0x48f840 | 0xbae08 | 0xba008 | 0xd4 |
OleSetContainedObject | 0x0 | 0x48f844 | 0xbae0c | 0xba00c | 0x146 |
CoCreateInstance | 0x0 | 0x48f848 | 0xbae10 | 0xba010 | 0x10 |
IIDFromString | 0x0 | 0x48f84c | 0xbae14 | 0xba014 | 0xcd |
StringFromGUID2 | 0x0 | 0x48f850 | 0xbae18 | 0xba018 | 0x179 |
CreateStreamOnHGlobal | 0x0 | 0x48f854 | 0xbae1c | 0xba01c | 0x86 |
OleInitialize | 0x0 | 0x48f858 | 0xbae20 | 0xba020 | 0x132 |
OleUninitialize | 0x0 | 0x48f85c | 0xbae24 | 0xba024 | 0x149 |
CoInitialize | 0x0 | 0x48f860 | 0xbae28 | 0xba028 | 0x3e |
CoUninitialize | 0x0 | 0x48f864 | 0xbae2c | 0xba02c | 0x6c |
GetRunningObjectTable | 0x0 | 0x48f868 | 0xbae30 | 0xba030 | 0x97 |
CoGetInstanceFromFile | 0x0 | 0x48f86c | 0xbae34 | 0xba034 | 0x2d |
CoGetObject | 0x0 | 0x48f870 | 0xbae38 | 0xba038 | 0x35 |
CoSetProxyBlanket | 0x0 | 0x48f874 | 0xbae3c | 0xba03c | 0x63 |
CoCreateInstanceEx | 0x0 | 0x48f878 | 0xbae40 | 0xba040 | 0x11 |
CoInitializeSecurity | 0x0 | 0x48f87c | 0xbae44 | 0xba044 | 0x40 |
OLEAUT32.dll (29)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadTypeLibEx | 0xb7 | 0x48f40c | 0xba9d4 | 0xb9bd4 | - |
VariantCopyInd | 0xb | 0x48f410 | 0xba9d8 | 0xb9bd8 | - |
SysReAllocString | 0x3 | 0x48f414 | 0xba9dc | 0xb9bdc | - |
SysFreeString | 0x6 | 0x48f418 | 0xba9e0 | 0xb9be0 | - |
SafeArrayDestroyDescriptor | 0x26 | 0x48f41c | 0xba9e4 | 0xb9be4 | - |
SafeArrayDestroyData | 0x27 | 0x48f420 | 0xba9e8 | 0xb9be8 | - |
SafeArrayUnaccessData | 0x18 | 0x48f424 | 0xba9ec | 0xb9bec | - |
SafeArrayAccessData | 0x17 | 0x48f428 | 0xba9f0 | 0xb9bf0 | - |
SafeArrayAllocData | 0x25 | 0x48f42c | 0xba9f4 | 0xb9bf4 | - |
SafeArrayAllocDescriptorEx | 0x29 | 0x48f430 | 0xba9f8 | 0xb9bf8 | - |
SafeArrayCreateVector | 0x19b | 0x48f434 | 0xba9fc | 0xb9bfc | - |
RegisterTypeLib | 0xa3 | 0x48f438 | 0xbaa00 | 0xb9c00 | - |
CreateStdDispatch | 0x20 | 0x48f43c | 0xbaa04 | 0xb9c04 | - |
DispCallFunc | 0x92 | 0x48f440 | 0xbaa08 | 0xb9c08 | - |
VariantChangeType | 0xc | 0x48f444 | 0xbaa0c | 0xb9c0c | - |
SysStringLen | 0x7 | 0x48f448 | 0xbaa10 | 0xb9c10 | - |
VariantTimeToSystemTime | 0xb9 | 0x48f44c | 0xbaa14 | 0xb9c14 | - |
VarR8FromDec | 0xdc | 0x48f450 | 0xbaa18 | 0xb9c18 | - |
SafeArrayGetVartype | 0x4d | 0x48f454 | 0xbaa1c | 0xb9c1c | - |
VariantCopy | 0xa | 0x48f458 | 0xbaa20 | 0xb9c20 | - |
VariantClear | 0x9 | 0x48f45c | 0xbaa24 | 0xb9c24 | - |
OleLoadPicture | 0x1a2 | 0x48f460 | 0xbaa28 | 0xb9c28 | - |
QueryPathOfRegTypeLib | 0xa4 | 0x48f464 | 0xbaa2c | 0xb9c2c | - |
RegisterTypeLibForUser | 0x1ba | 0x48f468 | 0xbaa30 | 0xb9c30 | - |
UnRegisterTypeLibForUser | 0x1bb | 0x48f46c | 0xbaa34 | 0xb9c34 | - |
UnRegisterTypeLib | 0xba | 0x48f470 | 0xbaa38 | 0xb9c38 | - |
CreateDispTypeInfo | 0x1f | 0x48f474 | 0xbaa3c | 0xb9c3c | - |
SysAllocString | 0x2 | 0x48f478 | 0xbaa40 | 0xb9c40 | - |
VariantInit | 0x8 | 0x48f47c | 0xbaa44 | 0xb9c44 | - |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
b.exe | 1 | 0x01320000 | 0x015D4FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
b.exe | 1 | 0x01320000 | 0x015D4FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
AIT:Trojan.Nymeria.640 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\b.exe | Modified File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x427f4a |
Size Of Code | 0x8de00 |
Size Of Initialized Data | 0x220600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-07-04 13:48:23+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x8dd2e | 0x8de00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.68 |
.rdata | 0x48f000 | 0x2e10e | 0x2e200 | 0x8e200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.76 |
.data | 0x4be000 | 0x8f74 | 0x5200 | 0xbc400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.2 |
.rsrc | 0x4c7000 | 0x1e5fdc | 0x1e6000 | 0xc1600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.99 |
.reloc | 0x6ad000 | 0x7130 | 0x7200 | 0x2a7600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.78 |
Imports (18)
»
WSOCK32.dll (23)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSACleanup | 0x74 | 0x48f7c8 | 0xbad90 | 0xb9f90 | - |
socket | 0x17 | 0x48f7cc | 0xbad94 | 0xb9f94 | - |
inet_ntoa | 0xc | 0x48f7d0 | 0xbad98 | 0xb9f98 | - |
setsockopt | 0x15 | 0x48f7d4 | 0xbad9c | 0xb9f9c | - |
ntohs | 0xf | 0x48f7d8 | 0xbada0 | 0xb9fa0 | - |
recvfrom | 0x11 | 0x48f7dc | 0xbada4 | 0xb9fa4 | - |
ioctlsocket | 0xa | 0x48f7e0 | 0xbada8 | 0xb9fa8 | - |
htons | 0x9 | 0x48f7e4 | 0xbadac | 0xb9fac | - |
WSAStartup | 0x73 | 0x48f7e8 | 0xbadb0 | 0xb9fb0 | - |
__WSAFDIsSet | 0x97 | 0x48f7ec | 0xbadb4 | 0xb9fb4 | - |
select | 0x12 | 0x48f7f0 | 0xbadb8 | 0xb9fb8 | - |
accept | 0x1 | 0x48f7f4 | 0xbadbc | 0xb9fbc | - |
listen | 0xd | 0x48f7f8 | 0xbadc0 | 0xb9fc0 | - |
bind | 0x2 | 0x48f7fc | 0xbadc4 | 0xb9fc4 | - |
closesocket | 0x3 | 0x48f800 | 0xbadc8 | 0xb9fc8 | - |
WSAGetLastError | 0x6f | 0x48f804 | 0xbadcc | 0xb9fcc | - |
recv | 0x10 | 0x48f808 | 0xbadd0 | 0xb9fd0 | - |
sendto | 0x14 | 0x48f80c | 0xbadd4 | 0xb9fd4 | - |
send | 0x13 | 0x48f810 | 0xbadd8 | 0xb9fd8 | - |
inet_addr | 0xb | 0x48f814 | 0xbaddc | 0xb9fdc | - |
gethostbyname | 0x34 | 0x48f818 | 0xbade0 | 0xb9fe0 | - |
gethostname | 0x39 | 0x48f81c | 0xbade4 | 0xb9fe4 | - |
connect | 0x4 | 0x48f820 | 0xbade8 | 0xb9fe8 | - |
VERSION.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFileVersionInfoW | 0x0 | 0x48f76c | 0xbad34 | 0xb9f34 | 0x6 |
GetFileVersionInfoSizeW | 0x0 | 0x48f770 | 0xbad38 | 0xb9f38 | 0x5 |
VerQueryValueW | 0x0 | 0x48f774 | 0xbad3c | 0xb9f3c | 0xe |
WINMM.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
timeGetTime | 0x0 | 0x48f7b8 | 0xbad80 | 0xb9f80 | 0x94 |
waveOutSetVolume | 0x0 | 0x48f7bc | 0xbad84 | 0xb9f84 | 0xbb |
mciSendStringW | 0x0 | 0x48f7c0 | 0xbad88 | 0xb9f88 | 0x32 |
COMCTL32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_ReplaceIcon | 0x0 | 0x48f088 | 0xba650 | 0xb9850 | 0x6f |
ImageList_Destroy | 0x0 | 0x48f08c | 0xba654 | 0xb9854 | 0x54 |
ImageList_Remove | 0x0 | 0x48f090 | 0xba658 | 0xb9858 | 0x6d |
ImageList_SetDragCursorImage | 0x0 | 0x48f094 | 0xba65c | 0xb985c | 0x72 |
ImageList_BeginDrag | 0x0 | 0x48f098 | 0xba660 | 0xb9860 | 0x50 |
ImageList_DragEnter | 0x0 | 0x48f09c | 0xba664 | 0xb9864 | 0x56 |
ImageList_DragLeave | 0x0 | 0x48f0a0 | 0xba668 | 0xb9868 | 0x57 |
ImageList_EndDrag | 0x0 | 0x48f0a4 | 0xba66c | 0xb986c | 0x5e |
ImageList_DragMove | 0x0 | 0x48f0a8 | 0xba670 | 0xb9870 | 0x58 |
InitCommonControlsEx | 0x0 | 0x48f0ac | 0xba674 | 0xb9874 | 0x7b |
ImageList_Create | 0x0 | 0x48f0b0 | 0xba678 | 0xb9878 | 0x53 |
MPR.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetUseConnectionW | 0x0 | 0x48f3f8 | 0xba9c0 | 0xb9bc0 | 0x49 |
WNetCancelConnection2W | 0x0 | 0x48f3fc | 0xba9c4 | 0xb9bc4 | 0xc |
WNetGetConnectionW | 0x0 | 0x48f400 | 0xba9c8 | 0xb9bc8 | 0x24 |
WNetAddConnection2W | 0x0 | 0x48f404 | 0xba9cc | 0xb9bcc | 0x6 |
WININET.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InternetQueryDataAvailable | 0x0 | 0x48f77c | 0xbad44 | 0xb9f44 | 0x9b |
InternetCloseHandle | 0x0 | 0x48f780 | 0xbad48 | 0xb9f48 | 0x6b |
InternetOpenW | 0x0 | 0x48f784 | 0xbad4c | 0xb9f4c | 0x9a |
InternetSetOptionW | 0x0 | 0x48f788 | 0xbad50 | 0xb9f50 | 0xaf |
InternetCrackUrlW | 0x0 | 0x48f78c | 0xbad54 | 0xb9f54 | 0x74 |
HttpQueryInfoW | 0x0 | 0x48f790 | 0xbad58 | 0xb9f58 | 0x5a |
InternetQueryOptionW | 0x0 | 0x48f794 | 0xbad5c | 0xb9f5c | 0x9e |
HttpOpenRequestW | 0x0 | 0x48f798 | 0xbad60 | 0xb9f60 | 0x58 |
HttpSendRequestW | 0x0 | 0x48f79c | 0xbad64 | 0xb9f64 | 0x5e |
FtpOpenFileW | 0x0 | 0x48f7a0 | 0xbad68 | 0xb9f68 | 0x35 |
FtpGetFileSize | 0x0 | 0x48f7a4 | 0xbad6c | 0xb9f6c | 0x32 |
InternetOpenUrlW | 0x0 | 0x48f7a8 | 0xbad70 | 0xb9f70 | 0x99 |
InternetReadFile | 0x0 | 0x48f7ac | 0xbad74 | 0xb9f74 | 0x9f |
InternetConnectW | 0x0 | 0x48f7b0 | 0xbad78 | 0xb9f78 | 0x72 |
PSAPI.DLL (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetProcessMemoryInfo | 0x0 | 0x48f484 | 0xbaa4c | 0xb9c4c | 0x15 |
IPHLPAPI.DLL (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IcmpCreateFile | 0x0 | 0x48f154 | 0xba71c | 0xb991c | 0x85 |
IcmpCloseHandle | 0x0 | 0x48f158 | 0xba720 | 0xb9920 | 0x84 |
IcmpSendEcho | 0x0 | 0x48f15c | 0xba724 | 0xb9924 | 0x87 |
USERENV.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DestroyEnvironmentBlock | 0x0 | 0x48f750 | 0xbad18 | 0xb9f18 | 0x4 |
UnloadUserProfile | 0x0 | 0x48f754 | 0xbad1c | 0xb9f1c | 0x2c |
CreateEnvironmentBlock | 0x0 | 0x48f758 | 0xbad20 | 0xb9f20 | 0x0 |
LoadUserProfileW | 0x0 | 0x48f75c | 0xbad24 | 0xb9f24 | 0x21 |
UxTheme.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IsThemeActive | 0x0 | 0x48f764 | 0xbad2c | 0xb9f2c | 0x3f |
KERNEL32.dll (164)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DuplicateHandle | 0x0 | 0x48f164 | 0xba72c | 0xb992c | 0xe8 |
CreateThread | 0x0 | 0x48f168 | 0xba730 | 0xb9930 | 0xb5 |
WaitForSingleObject | 0x0 | 0x48f16c | 0xba734 | 0xb9934 | 0x4f9 |
HeapAlloc | 0x0 | 0x48f170 | 0xba738 | 0xb9938 | 0x2cb |
GetProcessHeap | 0x0 | 0x48f174 | 0xba73c | 0xb993c | 0x24a |
HeapFree | 0x0 | 0x48f178 | 0xba740 | 0xb9940 | 0x2cf |
Sleep | 0x0 | 0x48f17c | 0xba744 | 0xb9944 | 0x4b2 |
GetCurrentThreadId | 0x0 | 0x48f180 | 0xba748 | 0xb9948 | 0x1c5 |
MultiByteToWideChar | 0x0 | 0x48f184 | 0xba74c | 0xb994c | 0x367 |
MulDiv | 0x0 | 0x48f188 | 0xba750 | 0xb9950 | 0x366 |
GetVersionExW | 0x0 | 0x48f18c | 0xba754 | 0xb9954 | 0x2a4 |
IsWow64Process | 0x0 | 0x48f190 | 0xba758 | 0xb9958 | 0x30e |
GetSystemInfo | 0x0 | 0x48f194 | 0xba75c | 0xb995c | 0x273 |
FreeLibrary | 0x0 | 0x48f198 | 0xba760 | 0xb9960 | 0x162 |
LoadLibraryA | 0x0 | 0x48f19c | 0xba764 | 0xb9964 | 0x33c |
GetProcAddress | 0x0 | 0x48f1a0 | 0xba768 | 0xb9968 | 0x245 |
SetErrorMode | 0x0 | 0x48f1a4 | 0xba76c | 0xb996c | 0x458 |
GetModuleFileNameW | 0x0 | 0x48f1a8 | 0xba770 | 0xb9970 | 0x214 |
WideCharToMultiByte | 0x0 | 0x48f1ac | 0xba774 | 0xb9974 | 0x511 |
lstrcpyW | 0x0 | 0x48f1b0 | 0xba778 | 0xb9978 | 0x548 |
lstrlenW | 0x0 | 0x48f1b4 | 0xba77c | 0xb997c | 0x54e |
GetModuleHandleW | 0x0 | 0x48f1b8 | 0xba780 | 0xb9980 | 0x218 |
QueryPerformanceCounter | 0x0 | 0x48f1bc | 0xba784 | 0xb9984 | 0x3a7 |
VirtualFreeEx | 0x0 | 0x48f1c0 | 0xba788 | 0xb9988 | 0x4ed |
OpenProcess | 0x0 | 0x48f1c4 | 0xba78c | 0xb998c | 0x380 |
VirtualAllocEx | 0x0 | 0x48f1c8 | 0xba790 | 0xb9990 | 0x4ea |
WriteProcessMemory | 0x0 | 0x48f1cc | 0xba794 | 0xb9994 | 0x52e |
ReadProcessMemory | 0x0 | 0x48f1d0 | 0xba798 | 0xb9998 | 0x3c3 |
CreateFileW | 0x0 | 0x48f1d4 | 0xba79c | 0xb999c | 0x8f |
SetFilePointerEx | 0x0 | 0x48f1d8 | 0xba7a0 | 0xb99a0 | 0x467 |
SetEndOfFile | 0x0 | 0x48f1dc | 0xba7a4 | 0xb99a4 | 0x453 |
ReadFile | 0x0 | 0x48f1e0 | 0xba7a8 | 0xb99a8 | 0x3c0 |
WriteFile | 0x0 | 0x48f1e4 | 0xba7ac | 0xb99ac | 0x525 |
FlushFileBuffers | 0x0 | 0x48f1e8 | 0xba7b0 | 0xb99b0 | 0x157 |
TerminateProcess | 0x0 | 0x48f1ec | 0xba7b4 | 0xb99b4 | 0x4c0 |
CreateToolhelp32Snapshot | 0x0 | 0x48f1f0 | 0xba7b8 | 0xb99b8 | 0xbe |
Process32FirstW | 0x0 | 0x48f1f4 | 0xba7bc | 0xb99bc | 0x396 |
Process32NextW | 0x0 | 0x48f1f8 | 0xba7c0 | 0xb99c0 | 0x398 |
SetFileTime | 0x0 | 0x48f1fc | 0xba7c4 | 0xb99c4 | 0x46a |
GetFileAttributesW | 0x0 | 0x48f200 | 0xba7c8 | 0xb99c8 | 0x1ea |
FindFirstFileW | 0x0 | 0x48f204 | 0xba7cc | 0xb99cc | 0x139 |
SetCurrentDirectoryW | 0x0 | 0x48f208 | 0xba7d0 | 0xb99d0 | 0x44d |
GetLongPathNameW | 0x0 | 0x48f20c | 0xba7d4 | 0xb99d4 | 0x20f |
GetShortPathNameW | 0x0 | 0x48f210 | 0xba7d8 | 0xb99d8 | 0x261 |
DeleteFileW | 0x0 | 0x48f214 | 0xba7dc | 0xb99dc | 0xd6 |
FindNextFileW | 0x0 | 0x48f218 | 0xba7e0 | 0xb99e0 | 0x145 |
CopyFileExW | 0x0 | 0x48f21c | 0xba7e4 | 0xb99e4 | 0x72 |
MoveFileW | 0x0 | 0x48f220 | 0xba7e8 | 0xb99e8 | 0x363 |
CreateDirectoryW | 0x0 | 0x48f224 | 0xba7ec | 0xb99ec | 0x81 |
RemoveDirectoryW | 0x0 | 0x48f228 | 0xba7f0 | 0xb99f0 | 0x403 |
SetSystemPowerState | 0x0 | 0x48f22c | 0xba7f4 | 0xb99f4 | 0x48a |
QueryPerformanceFrequency | 0x0 | 0x48f230 | 0xba7f8 | 0xb99f8 | 0x3a8 |
FindResourceW | 0x0 | 0x48f234 | 0xba7fc | 0xb99fc | 0x14e |
LoadResource | 0x0 | 0x48f238 | 0xba800 | 0xb9a00 | 0x341 |
LockResource | 0x0 | 0x48f23c | 0xba804 | 0xb9a04 | 0x354 |
SizeofResource | 0x0 | 0x48f240 | 0xba808 | 0xb9a08 | 0x4b1 |
EnumResourceNamesW | 0x0 | 0x48f244 | 0xba80c | 0xb9a0c | 0x102 |
OutputDebugStringW | 0x0 | 0x48f248 | 0xba810 | 0xb9a10 | 0x38a |
GetTempPathW | 0x0 | 0x48f24c | 0xba814 | 0xb9a14 | 0x285 |
GetTempFileNameW | 0x0 | 0x48f250 | 0xba818 | 0xb9a18 | 0x283 |
DeviceIoControl | 0x0 | 0x48f254 | 0xba81c | 0xb9a1c | 0xdd |
GetLocalTime | 0x0 | 0x48f258 | 0xba820 | 0xb9a20 | 0x203 |
CompareStringW | 0x0 | 0x48f25c | 0xba824 | 0xb9a24 | 0x64 |
GetCurrentProcess | 0x0 | 0x48f260 | 0xba828 | 0xb9a28 | 0x1c0 |
EnterCriticalSection | 0x0 | 0x48f264 | 0xba82c | 0xb9a2c | 0xee |
LeaveCriticalSection | 0x0 | 0x48f268 | 0xba830 | 0xb9a30 | 0x339 |
GetStdHandle | 0x0 | 0x48f26c | 0xba834 | 0xb9a34 | 0x264 |
CreatePipe | 0x0 | 0x48f270 | 0xba838 | 0xb9a38 | 0xa1 |
InterlockedExchange | 0x0 | 0x48f274 | 0xba83c | 0xb9a3c | 0x2ec |
TerminateThread | 0x0 | 0x48f278 | 0xba840 | 0xb9a40 | 0x4c1 |
LoadLibraryExW | 0x0 | 0x48f27c | 0xba844 | 0xb9a44 | 0x33e |
FindResourceExW | 0x0 | 0x48f280 | 0xba848 | 0xb9a48 | 0x14d |
CopyFileW | 0x0 | 0x48f284 | 0xba84c | 0xb9a4c | 0x75 |
VirtualFree | 0x0 | 0x48f288 | 0xba850 | 0xb9a50 | 0x4ec |
FormatMessageW | 0x0 | 0x48f28c | 0xba854 | 0xb9a54 | 0x15e |
GetExitCodeProcess | 0x0 | 0x48f290 | 0xba858 | 0xb9a58 | 0x1df |
GetPrivateProfileStringW | 0x0 | 0x48f294 | 0xba85c | 0xb9a5c | 0x242 |
WritePrivateProfileStringW | 0x0 | 0x48f298 | 0xba860 | 0xb9a60 | 0x52b |
GetPrivateProfileSectionW | 0x0 | 0x48f29c | 0xba864 | 0xb9a64 | 0x240 |
WritePrivateProfileSectionW | 0x0 | 0x48f2a0 | 0xba868 | 0xb9a68 | 0x529 |
GetPrivateProfileSectionNamesW | 0x0 | 0x48f2a4 | 0xba86c | 0xb9a6c | 0x23f |
FileTimeToLocalFileTime | 0x0 | 0x48f2a8 | 0xba870 | 0xb9a70 | 0x124 |
FileTimeToSystemTime | 0x0 | 0x48f2ac | 0xba874 | 0xb9a74 | 0x125 |
SystemTimeToFileTime | 0x0 | 0x48f2b0 | 0xba878 | 0xb9a78 | 0x4bd |
LocalFileTimeToFileTime | 0x0 | 0x48f2b4 | 0xba87c | 0xb9a7c | 0x346 |
GetDriveTypeW | 0x0 | 0x48f2b8 | 0xba880 | 0xb9a80 | 0x1d3 |
GetDiskFreeSpaceExW | 0x0 | 0x48f2bc | 0xba884 | 0xb9a84 | 0x1ce |
GetDiskFreeSpaceW | 0x0 | 0x48f2c0 | 0xba888 | 0xb9a88 | 0x1cf |
GetVolumeInformationW | 0x0 | 0x48f2c4 | 0xba88c | 0xb9a8c | 0x2a7 |
SetVolumeLabelW | 0x0 | 0x48f2c8 | 0xba890 | 0xb9a90 | 0x4a9 |
CreateHardLinkW | 0x0 | 0x48f2cc | 0xba894 | 0xb9a94 | 0x93 |
SetFileAttributesW | 0x0 | 0x48f2d0 | 0xba898 | 0xb9a98 | 0x461 |
CreateEventW | 0x0 | 0x48f2d4 | 0xba89c | 0xb9a9c | 0x85 |
SetEvent | 0x0 | 0x48f2d8 | 0xba8a0 | 0xb9aa0 | 0x459 |
GetEnvironmentVariableW | 0x0 | 0x48f2dc | 0xba8a4 | 0xb9aa4 | 0x1dc |
SetEnvironmentVariableW | 0x0 | 0x48f2e0 | 0xba8a8 | 0xb9aa8 | 0x457 |
GlobalLock | 0x0 | 0x48f2e4 | 0xba8ac | 0xb9aac | 0x2be |
GlobalUnlock | 0x0 | 0x48f2e8 | 0xba8b0 | 0xb9ab0 | 0x2c5 |
GlobalAlloc | 0x0 | 0x48f2ec | 0xba8b4 | 0xb9ab4 | 0x2b3 |
GetFileSize | 0x0 | 0x48f2f0 | 0xba8b8 | 0xb9ab8 | 0x1f0 |
GlobalFree | 0x0 | 0x48f2f4 | 0xba8bc | 0xb9abc | 0x2ba |
GlobalMemoryStatusEx | 0x0 | 0x48f2f8 | 0xba8c0 | 0xb9ac0 | 0x2c0 |
Beep | 0x0 | 0x48f2fc | 0xba8c4 | 0xb9ac4 | 0x36 |
GetSystemDirectoryW | 0x0 | 0x48f300 | 0xba8c8 | 0xb9ac8 | 0x270 |
HeapReAlloc | 0x0 | 0x48f304 | 0xba8cc | 0xb9acc | 0x2d2 |
HeapSize | 0x0 | 0x48f308 | 0xba8d0 | 0xb9ad0 | 0x2d4 |
GetComputerNameW | 0x0 | 0x48f30c | 0xba8d4 | 0xb9ad4 | 0x18f |
GetWindowsDirectoryW | 0x0 | 0x48f310 | 0xba8d8 | 0xb9ad8 | 0x2af |
GetCurrentProcessId | 0x0 | 0x48f314 | 0xba8dc | 0xb9adc | 0x1c1 |
GetProcessIoCounters | 0x0 | 0x48f318 | 0xba8e0 | 0xb9ae0 | 0x24e |
CreateProcessW | 0x0 | 0x48f31c | 0xba8e4 | 0xb9ae4 | 0xa8 |
GetProcessId | 0x0 | 0x48f320 | 0xba8e8 | 0xb9ae8 | 0x24c |
SetPriorityClass | 0x0 | 0x48f324 | 0xba8ec | 0xb9aec | 0x47d |
LoadLibraryW | 0x0 | 0x48f328 | 0xba8f0 | 0xb9af0 | 0x33f |
VirtualAlloc | 0x0 | 0x48f32c | 0xba8f4 | 0xb9af4 | 0x4e9 |
IsDebuggerPresent | 0x0 | 0x48f330 | 0xba8f8 | 0xb9af8 | 0x300 |
GetCurrentDirectoryW | 0x0 | 0x48f334 | 0xba8fc | 0xb9afc | 0x1bf |
lstrcmpiW | 0x0 | 0x48f338 | 0xba900 | 0xb9b00 | 0x545 |
DecodePointer | 0x0 | 0x48f33c | 0xba904 | 0xb9b04 | 0xca |
GetLastError | 0x0 | 0x48f340 | 0xba908 | 0xb9b08 | 0x202 |
RaiseException | 0x0 | 0x48f344 | 0xba90c | 0xb9b0c | 0x3b1 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x48f348 | 0xba910 | 0xb9b10 | 0x2e3 |
DeleteCriticalSection | 0x0 | 0x48f34c | 0xba914 | 0xb9b14 | 0xd1 |
InterlockedDecrement | 0x0 | 0x48f350 | 0xba918 | 0xb9b18 | 0x2eb |
InterlockedIncrement | 0x0 | 0x48f354 | 0xba91c | 0xb9b1c | 0x2ef |
GetCurrentThread | 0x0 | 0x48f358 | 0xba920 | 0xb9b20 | 0x1c4 |
CloseHandle | 0x0 | 0x48f35c | 0xba924 | 0xb9b24 | 0x52 |
GetFullPathNameW | 0x0 | 0x48f360 | 0xba928 | 0xb9b28 | 0x1fb |
EncodePointer | 0x0 | 0x48f364 | 0xba92c | 0xb9b2c | 0xea |
ExitProcess | 0x0 | 0x48f368 | 0xba930 | 0xb9b30 | 0x119 |
GetModuleHandleExW | 0x0 | 0x48f36c | 0xba934 | 0xb9b34 | 0x217 |
ExitThread | 0x0 | 0x48f370 | 0xba938 | 0xb9b38 | 0x11a |
GetSystemTimeAsFileTime | 0x0 | 0x48f374 | 0xba93c | 0xb9b3c | 0x279 |
ResumeThread | 0x0 | 0x48f378 | 0xba940 | 0xb9b40 | 0x413 |
GetCommandLineW | 0x0 | 0x48f37c | 0xba944 | 0xb9b44 | 0x187 |
IsProcessorFeaturePresent | 0x0 | 0x48f380 | 0xba948 | 0xb9b48 | 0x304 |
IsValidCodePage | 0x0 | 0x48f384 | 0xba94c | 0xb9b4c | 0x30a |
GetACP | 0x0 | 0x48f388 | 0xba950 | 0xb9b50 | 0x168 |
GetOEMCP | 0x0 | 0x48f38c | 0xba954 | 0xb9b54 | 0x237 |
GetCPInfo | 0x0 | 0x48f390 | 0xba958 | 0xb9b58 | 0x172 |
SetLastError | 0x0 | 0x48f394 | 0xba95c | 0xb9b5c | 0x473 |
UnhandledExceptionFilter | 0x0 | 0x48f398 | 0xba960 | 0xb9b60 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x48f39c | 0xba964 | 0xb9b64 | 0x4a5 |
TlsAlloc | 0x0 | 0x48f3a0 | 0xba968 | 0xb9b68 | 0x4c5 |
TlsGetValue | 0x0 | 0x48f3a4 | 0xba96c | 0xb9b6c | 0x4c7 |
TlsSetValue | 0x0 | 0x48f3a8 | 0xba970 | 0xb9b70 | 0x4c8 |
TlsFree | 0x0 | 0x48f3ac | 0xba974 | 0xb9b74 | 0x4c6 |
GetStartupInfoW | 0x0 | 0x48f3b0 | 0xba978 | 0xb9b78 | 0x263 |
GetStringTypeW | 0x0 | 0x48f3b4 | 0xba97c | 0xb9b7c | 0x269 |
SetStdHandle | 0x0 | 0x48f3b8 | 0xba980 | 0xb9b80 | 0x487 |
GetFileType | 0x0 | 0x48f3bc | 0xba984 | 0xb9b84 | 0x1f3 |
GetConsoleCP | 0x0 | 0x48f3c0 | 0xba988 | 0xb9b88 | 0x19a |
GetConsoleMode | 0x0 | 0x48f3c4 | 0xba98c | 0xb9b8c | 0x1ac |
RtlUnwind | 0x0 | 0x48f3c8 | 0xba990 | 0xb9b90 | 0x418 |
ReadConsoleW | 0x0 | 0x48f3cc | 0xba994 | 0xb9b94 | 0x3be |
GetTimeZoneInformation | 0x0 | 0x48f3d0 | 0xba998 | 0xb9b98 | 0x298 |
GetDateFormatW | 0x0 | 0x48f3d4 | 0xba99c | 0xb9b9c | 0x1c8 |
GetTimeFormatW | 0x0 | 0x48f3d8 | 0xba9a0 | 0xb9ba0 | 0x297 |
LCMapStringW | 0x0 | 0x48f3dc | 0xba9a4 | 0xb9ba4 | 0x32d |
GetEnvironmentStringsW | 0x0 | 0x48f3e0 | 0xba9a8 | 0xb9ba8 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x48f3e4 | 0xba9ac | 0xb9bac | 0x161 |
WriteConsoleW | 0x0 | 0x48f3e8 | 0xba9b0 | 0xb9bb0 | 0x524 |
FindClose | 0x0 | 0x48f3ec | 0xba9b4 | 0xb9bb4 | 0x12e |
SetEnvironmentVariableA | 0x0 | 0x48f3f0 | 0xba9b8 | 0xb9bb8 | 0x456 |
USER32.dll (160)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AdjustWindowRectEx | 0x0 | 0x48f4cc | 0xbaa94 | 0xb9c94 | 0x3 |
CopyImage | 0x0 | 0x48f4d0 | 0xbaa98 | 0xb9c98 | 0x54 |
SetWindowPos | 0x0 | 0x48f4d4 | 0xbaa9c | 0xb9c9c | 0x2c6 |
GetCursorInfo | 0x0 | 0x48f4d8 | 0xbaaa0 | 0xb9ca0 | 0x11f |
RegisterHotKey | 0x0 | 0x48f4dc | 0xbaaa4 | 0xb9ca4 | 0x256 |
ClientToScreen | 0x0 | 0x48f4e0 | 0xbaaa8 | 0xb9ca8 | 0x47 |
GetKeyboardLayoutNameW | 0x0 | 0x48f4e4 | 0xbaaac | 0xb9cac | 0x141 |
IsCharAlphaW | 0x0 | 0x48f4e8 | 0xbaab0 | 0xb9cb0 | 0x1c4 |
IsCharAlphaNumericW | 0x0 | 0x48f4ec | 0xbaab4 | 0xb9cb4 | 0x1c3 |
IsCharLowerW | 0x0 | 0x48f4f0 | 0xbaab8 | 0xb9cb8 | 0x1c6 |
IsCharUpperW | 0x0 | 0x48f4f4 | 0xbaabc | 0xb9cbc | 0x1c8 |
GetMenuStringW | 0x0 | 0x48f4f8 | 0xbaac0 | 0xb9cc0 | 0x158 |
GetSubMenu | 0x0 | 0x48f4fc | 0xbaac4 | 0xb9cc4 | 0x17a |
GetCaretPos | 0x0 | 0x48f500 | 0xbaac8 | 0xb9cc8 | 0x10a |
IsZoomed | 0x0 | 0x48f504 | 0xbaacc | 0xb9ccc | 0x1e2 |
MonitorFromPoint | 0x0 | 0x48f508 | 0xbaad0 | 0xb9cd0 | 0x218 |
GetMonitorInfoW | 0x0 | 0x48f50c | 0xbaad4 | 0xb9cd4 | 0x15f |
SetWindowLongW | 0x0 | 0x48f510 | 0xbaad8 | 0xb9cd8 | 0x2c4 |
SetLayeredWindowAttributes | 0x0 | 0x48f514 | 0xbaadc | 0xb9cdc | 0x298 |
FlashWindow | 0x0 | 0x48f518 | 0xbaae0 | 0xb9ce0 | 0xfb |
GetClassLongW | 0x0 | 0x48f51c | 0xbaae4 | 0xb9ce4 | 0x110 |
TranslateAcceleratorW | 0x0 | 0x48f520 | 0xbaae8 | 0xb9ce8 | 0x2fa |
IsDialogMessageW | 0x0 | 0x48f524 | 0xbaaec | 0xb9cec | 0x1cd |
GetSysColor | 0x0 | 0x48f528 | 0xbaaf0 | 0xb9cf0 | 0x17b |
InflateRect | 0x0 | 0x48f52c | 0xbaaf4 | 0xb9cf4 | 0x1b5 |
DrawFocusRect | 0x0 | 0x48f530 | 0xbaaf8 | 0xb9cf8 | 0xc4 |
DrawTextW | 0x0 | 0x48f534 | 0xbaafc | 0xb9cfc | 0xd0 |
FrameRect | 0x0 | 0x48f538 | 0xbab00 | 0xb9d00 | 0xfd |
DrawFrameControl | 0x0 | 0x48f53c | 0xbab04 | 0xb9d04 | 0xc6 |
FillRect | 0x0 | 0x48f540 | 0xbab08 | 0xb9d08 | 0xf6 |
PtInRect | 0x0 | 0x48f544 | 0xbab0c | 0xb9d0c | 0x240 |
DestroyAcceleratorTable | 0x0 | 0x48f548 | 0xbab10 | 0xb9d10 | 0xa0 |
CreateAcceleratorTableW | 0x0 | 0x48f54c | 0xbab14 | 0xb9d14 | 0x58 |
SetCursor | 0x0 | 0x48f550 | 0xbab18 | 0xb9d18 | 0x288 |
GetWindowDC | 0x0 | 0x48f554 | 0xbab1c | 0xb9d1c | 0x192 |
GetSystemMetrics | 0x0 | 0x48f558 | 0xbab20 | 0xb9d20 | 0x17e |
GetActiveWindow | 0x0 | 0x48f55c | 0xbab24 | 0xb9d24 | 0x100 |
CharNextW | 0x0 | 0x48f560 | 0xbab28 | 0xb9d28 | 0x31 |
wsprintfW | 0x0 | 0x48f564 | 0xbab2c | 0xb9d2c | 0x333 |
RedrawWindow | 0x0 | 0x48f568 | 0xbab30 | 0xb9d30 | 0x24a |
DrawMenuBar | 0x0 | 0x48f56c | 0xbab34 | 0xb9d34 | 0xc9 |
DestroyMenu | 0x0 | 0x48f570 | 0xbab38 | 0xb9d38 | 0xa4 |
SetMenu | 0x0 | 0x48f574 | 0xbab3c | 0xb9d3c | 0x29c |
GetWindowTextLengthW | 0x0 | 0x48f578 | 0xbab40 | 0xb9d40 | 0x1a2 |
CreateMenu | 0x0 | 0x48f57c | 0xbab44 | 0xb9d44 | 0x6a |
IsDlgButtonChecked | 0x0 | 0x48f580 | 0xbab48 | 0xb9d48 | 0x1ce |
DefDlgProcW | 0x0 | 0x48f584 | 0xbab4c | 0xb9d4c | 0x95 |
CallWindowProcW | 0x0 | 0x48f588 | 0xbab50 | 0xb9d50 | 0x1e |
ReleaseCapture | 0x0 | 0x48f58c | 0xbab54 | 0xb9d54 | 0x264 |
SetCapture | 0x0 | 0x48f590 | 0xbab58 | 0xb9d58 | 0x280 |
CreateIconFromResourceEx | 0x0 | 0x48f594 | 0xbab5c | 0xb9d5c | 0x66 |
mouse_event | 0x0 | 0x48f598 | 0xbab60 | 0xb9d60 | 0x331 |
ExitWindowsEx | 0x0 | 0x48f59c | 0xbab64 | 0xb9d64 | 0xf5 |
SetActiveWindow | 0x0 | 0x48f5a0 | 0xbab68 | 0xb9d68 | 0x27f |
FindWindowExW | 0x0 | 0x48f5a4 | 0xbab6c | 0xb9d6c | 0xf9 |
EnumThreadWindows | 0x0 | 0x48f5a8 | 0xbab70 | 0xb9d70 | 0xef |
SetMenuDefaultItem | 0x0 | 0x48f5ac | 0xbab74 | 0xb9d74 | 0x29e |
InsertMenuItemW | 0x0 | 0x48f5b0 | 0xbab78 | 0xb9d78 | 0x1b9 |
IsMenu | 0x0 | 0x48f5b4 | 0xbab7c | 0xb9d7c | 0x1d2 |
TrackPopupMenuEx | 0x0 | 0x48f5b8 | 0xbab80 | 0xb9d80 | 0x2f7 |
GetCursorPos | 0x0 | 0x48f5bc | 0xbab84 | 0xb9d84 | 0x120 |
DeleteMenu | 0x0 | 0x48f5c0 | 0xbab88 | 0xb9d88 | 0x9e |
SetRect | 0x0 | 0x48f5c4 | 0xbab8c | 0xb9d8c | 0x2ae |
GetMenuItemID | 0x0 | 0x48f5c8 | 0xbab90 | 0xb9d90 | 0x152 |
GetMenuItemCount | 0x0 | 0x48f5cc | 0xbab94 | 0xb9d94 | 0x151 |
SetMenuItemInfoW | 0x0 | 0x48f5d0 | 0xbab98 | 0xb9d98 | 0x2a2 |
GetMenuItemInfoW | 0x0 | 0x48f5d4 | 0xbab9c | 0xb9d9c | 0x154 |
SetForegroundWindow | 0x0 | 0x48f5d8 | 0xbaba0 | 0xb9da0 | 0x293 |
IsIconic | 0x0 | 0x48f5dc | 0xbaba4 | 0xb9da4 | 0x1d1 |
FindWindowW | 0x0 | 0x48f5e0 | 0xbaba8 | 0xb9da8 | 0xfa |
MonitorFromRect | 0x0 | 0x48f5e4 | 0xbabac | 0xb9dac | 0x219 |
keybd_event | 0x0 | 0x48f5e8 | 0xbabb0 | 0xb9db0 | 0x330 |
SendInput | 0x0 | 0x48f5ec | 0xbabb4 | 0xb9db4 | 0x276 |
GetAsyncKeyState | 0x0 | 0x48f5f0 | 0xbabb8 | 0xb9db8 | 0x107 |
SetKeyboardState | 0x0 | 0x48f5f4 | 0xbabbc | 0xb9dbc | 0x296 |
GetKeyboardState | 0x0 | 0x48f5f8 | 0xbabc0 | 0xb9dc0 | 0x142 |
GetKeyState | 0x0 | 0x48f5fc | 0xbabc4 | 0xb9dc4 | 0x13d |
VkKeyScanW | 0x0 | 0x48f600 | 0xbabc8 | 0xb9dc8 | 0x321 |
LoadStringW | 0x0 | 0x48f604 | 0xbabcc | 0xb9dcc | 0x1fa |
DialogBoxParamW | 0x0 | 0x48f608 | 0xbabd0 | 0xb9dd0 | 0xac |
MessageBeep | 0x0 | 0x48f60c | 0xbabd4 | 0xb9dd4 | 0x20d |
EndDialog | 0x0 | 0x48f610 | 0xbabd8 | 0xb9dd8 | 0xda |
SendDlgItemMessageW | 0x0 | 0x48f614 | 0xbabdc | 0xb9ddc | 0x273 |
GetDlgItem | 0x0 | 0x48f618 | 0xbabe0 | 0xb9de0 | 0x127 |
SetWindowTextW | 0x0 | 0x48f61c | 0xbabe4 | 0xb9de4 | 0x2cb |
CopyRect | 0x0 | 0x48f620 | 0xbabe8 | 0xb9de8 | 0x55 |
ReleaseDC | 0x0 | 0x48f624 | 0xbabec | 0xb9dec | 0x265 |
GetDC | 0x0 | 0x48f628 | 0xbabf0 | 0xb9df0 | 0x121 |
EndPaint | 0x0 | 0x48f62c | 0xbabf4 | 0xb9df4 | 0xdc |
BeginPaint | 0x0 | 0x48f630 | 0xbabf8 | 0xb9df8 | 0xe |
GetClientRect | 0x0 | 0x48f634 | 0xbabfc | 0xb9dfc | 0x114 |
GetMenu | 0x0 | 0x48f638 | 0xbac00 | 0xb9e00 | 0x14b |
DestroyWindow | 0x0 | 0x48f63c | 0xbac04 | 0xb9e04 | 0xa6 |
EnumWindows | 0x0 | 0x48f640 | 0xbac08 | 0xb9e08 | 0xf2 |
GetDesktopWindow | 0x0 | 0x48f644 | 0xbac0c | 0xb9e0c | 0x123 |
IsWindow | 0x0 | 0x48f648 | 0xbac10 | 0xb9e10 | 0x1db |
IsWindowEnabled | 0x0 | 0x48f64c | 0xbac14 | 0xb9e14 | 0x1dc |
IsWindowVisible | 0x0 | 0x48f650 | 0xbac18 | 0xb9e18 | 0x1e0 |
EnableWindow | 0x0 | 0x48f654 | 0xbac1c | 0xb9e1c | 0xd8 |
InvalidateRect | 0x0 | 0x48f658 | 0xbac20 | 0xb9e20 | 0x1be |
GetWindowLongW | 0x0 | 0x48f65c | 0xbac24 | 0xb9e24 | 0x196 |
GetWindowThreadProcessId | 0x0 | 0x48f660 | 0xbac28 | 0xb9e28 | 0x1a4 |
AttachThreadInput | 0x0 | 0x48f664 | 0xbac2c | 0xb9e2c | 0xc |
GetFocus | 0x0 | 0x48f668 | 0xbac30 | 0xb9e30 | 0x12c |
GetWindowTextW | 0x0 | 0x48f66c | 0xbac34 | 0xb9e34 | 0x1a3 |
ScreenToClient | 0x0 | 0x48f670 | 0xbac38 | 0xb9e38 | 0x26d |
SendMessageTimeoutW | 0x0 | 0x48f674 | 0xbac3c | 0xb9e3c | 0x27b |
EnumChildWindows | 0x0 | 0x48f678 | 0xbac40 | 0xb9e40 | 0xdf |
CharUpperBuffW | 0x0 | 0x48f67c | 0xbac44 | 0xb9e44 | 0x3b |
GetParent | 0x0 | 0x48f680 | 0xbac48 | 0xb9e48 | 0x164 |
GetDlgCtrlID | 0x0 | 0x48f684 | 0xbac4c | 0xb9e4c | 0x126 |
SendMessageW | 0x0 | 0x48f688 | 0xbac50 | 0xb9e50 | 0x27c |
MapVirtualKeyW | 0x0 | 0x48f68c | 0xbac54 | 0xb9e54 | 0x208 |
PostMessageW | 0x0 | 0x48f690 | 0xbac58 | 0xb9e58 | 0x236 |
GetWindowRect | 0x0 | 0x48f694 | 0xbac5c | 0xb9e5c | 0x19c |
SetUserObjectSecurity | 0x0 | 0x48f698 | 0xbac60 | 0xb9e60 | 0x2be |
CloseDesktop | 0x0 | 0x48f69c | 0xbac64 | 0xb9e64 | 0x4a |
CloseWindowStation | 0x0 | 0x48f6a0 | 0xbac68 | 0xb9e68 | 0x4e |
OpenDesktopW | 0x0 | 0x48f6a4 | 0xbac6c | 0xb9e6c | 0x228 |
SetProcessWindowStation | 0x0 | 0x48f6a8 | 0xbac70 | 0xb9e70 | 0x2aa |
GetProcessWindowStation | 0x0 | 0x48f6ac | 0xbac74 | 0xb9e74 | 0x168 |
OpenWindowStationW | 0x0 | 0x48f6b0 | 0xbac78 | 0xb9e78 | 0x22d |
GetUserObjectSecurity | 0x0 | 0x48f6b4 | 0xbac7c | 0xb9e7c | 0x18c |
MessageBoxW | 0x0 | 0x48f6b8 | 0xbac80 | 0xb9e80 | 0x215 |
DefWindowProcW | 0x0 | 0x48f6bc | 0xbac84 | 0xb9e84 | 0x9c |
SetClipboardData | 0x0 | 0x48f6c0 | 0xbac88 | 0xb9e88 | 0x286 |
EmptyClipboard | 0x0 | 0x48f6c4 | 0xbac8c | 0xb9e8c | 0xd5 |
CountClipboardFormats | 0x0 | 0x48f6c8 | 0xbac90 | 0xb9e90 | 0x56 |
CloseClipboard | 0x0 | 0x48f6cc | 0xbac94 | 0xb9e94 | 0x49 |
GetClipboardData | 0x0 | 0x48f6d0 | 0xbac98 | 0xb9e98 | 0x116 |
IsClipboardFormatAvailable | 0x0 | 0x48f6d4 | 0xbac9c | 0xb9e9c | 0x1ca |
OpenClipboard | 0x0 | 0x48f6d8 | 0xbaca0 | 0xb9ea0 | 0x226 |
BlockInput | 0x0 | 0x48f6dc | 0xbaca4 | 0xb9ea4 | 0xf |
GetMessageW | 0x0 | 0x48f6e0 | 0xbaca8 | 0xb9ea8 | 0x15d |
LockWindowUpdate | 0x0 | 0x48f6e4 | 0xbacac | 0xb9eac | 0x1fd |
DispatchMessageW | 0x0 | 0x48f6e8 | 0xbacb0 | 0xb9eb0 | 0xaf |
TranslateMessage | 0x0 | 0x48f6ec | 0xbacb4 | 0xb9eb4 | 0x2fc |
PeekMessageW | 0x0 | 0x48f6f0 | 0xbacb8 | 0xb9eb8 | 0x233 |
UnregisterHotKey | 0x0 | 0x48f6f4 | 0xbacbc | 0xb9ebc | 0x308 |
CheckMenuRadioItem | 0x0 | 0x48f6f8 | 0xbacc0 | 0xb9ec0 | 0x40 |
CharLowerBuffW | 0x0 | 0x48f6fc | 0xbacc4 | 0xb9ec4 | 0x2d |
MoveWindow | 0x0 | 0x48f700 | 0xbacc8 | 0xb9ec8 | 0x21b |
SetFocus | 0x0 | 0x48f704 | 0xbaccc | 0xb9ecc | 0x292 |
PostQuitMessage | 0x0 | 0x48f708 | 0xbacd0 | 0xb9ed0 | 0x237 |
KillTimer | 0x0 | 0x48f70c | 0xbacd4 | 0xb9ed4 | 0x1e3 |
CreatePopupMenu | 0x0 | 0x48f710 | 0xbacd8 | 0xb9ed8 | 0x6b |
RegisterWindowMessageW | 0x0 | 0x48f714 | 0xbacdc | 0xb9edc | 0x263 |
SetTimer | 0x0 | 0x48f718 | 0xbace0 | 0xb9ee0 | 0x2bb |
ShowWindow | 0x0 | 0x48f71c | 0xbace4 | 0xb9ee4 | 0x2df |
CreateWindowExW | 0x0 | 0x48f720 | 0xbace8 | 0xb9ee8 | 0x6e |
RegisterClassExW | 0x0 | 0x48f724 | 0xbacec | 0xb9eec | 0x24d |
LoadIconW | 0x0 | 0x48f728 | 0xbacf0 | 0xb9ef0 | 0x1ed |
LoadCursorW | 0x0 | 0x48f72c | 0xbacf4 | 0xb9ef4 | 0x1eb |
GetSysColorBrush | 0x0 | 0x48f730 | 0xbacf8 | 0xb9ef8 | 0x17c |
GetForegroundWindow | 0x0 | 0x48f734 | 0xbacfc | 0xb9efc | 0x12d |
MessageBoxA | 0x0 | 0x48f738 | 0xbad00 | 0xb9f00 | 0x20e |
DestroyIcon | 0x0 | 0x48f73c | 0xbad04 | 0xb9f04 | 0xa3 |
SystemParametersInfoW | 0x0 | 0x48f740 | 0xbad08 | 0xb9f08 | 0x2ec |
LoadImageW | 0x0 | 0x48f744 | 0xbad0c | 0xb9f0c | 0x1ef |
GetClassNameW | 0x0 | 0x48f748 | 0xbad10 | 0xb9f10 | 0x112 |
GDI32.dll (35)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StrokePath | 0x0 | 0x48f0c4 | 0xba68c | 0xb988c | 0x2b6 |
DeleteObject | 0x0 | 0x48f0c8 | 0xba690 | 0xb9890 | 0xe6 |
GetTextExtentPoint32W | 0x0 | 0x48f0cc | 0xba694 | 0xb9894 | 0x21e |
ExtCreatePen | 0x0 | 0x48f0d0 | 0xba698 | 0xb9898 | 0x132 |
GetDeviceCaps | 0x0 | 0x48f0d4 | 0xba69c | 0xb989c | 0x1cb |
EndPath | 0x0 | 0x48f0d8 | 0xba6a0 | 0xb98a0 | 0xf3 |
SetPixel | 0x0 | 0x48f0dc | 0xba6a4 | 0xb98a4 | 0x29b |
CloseFigure | 0x0 | 0x48f0e0 | 0xba6a8 | 0xb98a8 | 0x1e |
CreateCompatibleBitmap | 0x0 | 0x48f0e4 | 0xba6ac | 0xb98ac | 0x2f |
CreateCompatibleDC | 0x0 | 0x48f0e8 | 0xba6b0 | 0xb98b0 | 0x30 |
SelectObject | 0x0 | 0x48f0ec | 0xba6b4 | 0xb98b4 | 0x277 |
StretchBlt | 0x0 | 0x48f0f0 | 0xba6b8 | 0xb98b8 | 0x2b3 |
GetDIBits | 0x0 | 0x48f0f4 | 0xba6bc | 0xb98bc | 0x1ca |
LineTo | 0x0 | 0x48f0f8 | 0xba6c0 | 0xb98c0 | 0x236 |
AngleArc | 0x0 | 0x48f0fc | 0xba6c4 | 0xb98c4 | 0x8 |
MoveToEx | 0x0 | 0x48f100 | 0xba6c8 | 0xb98c8 | 0x23a |
Ellipse | 0x0 | 0x48f104 | 0xba6cc | 0xb98cc | 0xed |
DeleteDC | 0x0 | 0x48f108 | 0xba6d0 | 0xb98d0 | 0xe3 |
GetPixel | 0x0 | 0x48f10c | 0xba6d4 | 0xb98d4 | 0x204 |
CreateDCW | 0x0 | 0x48f110 | 0xba6d8 | 0xb98d8 | 0x32 |
GetStockObject | 0x0 | 0x48f114 | 0xba6dc | 0xb98dc | 0x20d |
GetTextFaceW | 0x0 | 0x48f118 | 0xba6e0 | 0xb98e0 | 0x224 |
CreateFontW | 0x0 | 0x48f11c | 0xba6e4 | 0xb98e4 | 0x41 |
SetTextColor | 0x0 | 0x48f120 | 0xba6e8 | 0xb98e8 | 0x2a6 |
PolyDraw | 0x0 | 0x48f124 | 0xba6ec | 0xb98ec | 0x250 |
BeginPath | 0x0 | 0x48f128 | 0xba6f0 | 0xb98f0 | 0x12 |
Rectangle | 0x0 | 0x48f12c | 0xba6f4 | 0xb98f4 | 0x25f |
SetViewportOrgEx | 0x0 | 0x48f130 | 0xba6f8 | 0xb98f8 | 0x2a9 |
GetObjectW | 0x0 | 0x48f134 | 0xba6fc | 0xb98fc | 0x1fd |
SetBkMode | 0x0 | 0x48f138 | 0xba700 | 0xb9900 | 0x27f |
RoundRect | 0x0 | 0x48f13c | 0xba704 | 0xb9904 | 0x26a |
SetBkColor | 0x0 | 0x48f140 | 0xba708 | 0xb9908 | 0x27e |
CreatePen | 0x0 | 0x48f144 | 0xba70c | 0xb990c | 0x4b |
CreateSolidBrush | 0x0 | 0x48f148 | 0xba710 | 0xb9910 | 0x54 |
StrokeAndFillPath | 0x0 | 0x48f14c | 0xba714 | 0xb9914 | 0x2b5 |
COMDLG32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetOpenFileNameW | 0x0 | 0x48f0b8 | 0xba680 | 0xb9880 | 0xc |
GetSaveFileNameW | 0x0 | 0x48f0bc | 0xba684 | 0xb9884 | 0xe |
ADVAPI32.dll (33)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetAce | 0x0 | 0x48f000 | 0xba5c8 | 0xb97c8 | 0x123 |
RegEnumValueW | 0x0 | 0x48f004 | 0xba5cc | 0xb97cc | 0x252 |
RegDeleteValueW | 0x0 | 0x48f008 | 0xba5d0 | 0xb97d0 | 0x248 |
RegDeleteKeyW | 0x0 | 0x48f00c | 0xba5d4 | 0xb97d4 | 0x244 |
RegEnumKeyExW | 0x0 | 0x48f010 | 0xba5d8 | 0xb97d8 | 0x24f |
RegSetValueExW | 0x0 | 0x48f014 | 0xba5dc | 0xb97dc | 0x27e |
RegOpenKeyExW | 0x0 | 0x48f018 | 0xba5e0 | 0xb97e0 | 0x261 |
RegCloseKey | 0x0 | 0x48f01c | 0xba5e4 | 0xb97e4 | 0x230 |
RegQueryValueExW | 0x0 | 0x48f020 | 0xba5e8 | 0xb97e8 | 0x26e |
RegConnectRegistryW | 0x0 | 0x48f024 | 0xba5ec | 0xb97ec | 0x234 |
InitializeSecurityDescriptor | 0x0 | 0x48f028 | 0xba5f0 | 0xb97f0 | 0x177 |
InitializeAcl | 0x0 | 0x48f02c | 0xba5f4 | 0xb97f4 | 0x176 |
AdjustTokenPrivileges | 0x0 | 0x48f030 | 0xba5f8 | 0xb97f8 | 0x1f |
OpenThreadToken | 0x0 | 0x48f034 | 0xba5fc | 0xb97fc | 0x1fc |
OpenProcessToken | 0x0 | 0x48f038 | 0xba600 | 0xb9800 | 0x1f7 |
LookupPrivilegeValueW | 0x0 | 0x48f03c | 0xba604 | 0xb9804 | 0x197 |
DuplicateTokenEx | 0x0 | 0x48f040 | 0xba608 | 0xb9808 | 0xdf |
CreateProcessAsUserW | 0x0 | 0x48f044 | 0xba60c | 0xb980c | 0x7c |
CreateProcessWithLogonW | 0x0 | 0x48f048 | 0xba610 | 0xb9810 | 0x7d |
GetLengthSid | 0x0 | 0x48f04c | 0xba614 | 0xb9814 | 0x136 |
CopySid | 0x0 | 0x48f050 | 0xba618 | 0xb9818 | 0x76 |
LogonUserW | 0x0 | 0x48f054 | 0xba61c | 0xb981c | 0x18d |
AllocateAndInitializeSid | 0x0 | 0x48f058 | 0xba620 | 0xb9820 | 0x20 |
CheckTokenMembership | 0x0 | 0x48f05c | 0xba624 | 0xb9824 | 0x51 |
RegCreateKeyExW | 0x0 | 0x48f060 | 0xba628 | 0xb9828 | 0x239 |
FreeSid | 0x0 | 0x48f064 | 0xba62c | 0xb982c | 0x120 |
GetTokenInformation | 0x0 | 0x48f068 | 0xba630 | 0xb9830 | 0x15a |
GetSecurityDescriptorDacl | 0x0 | 0x48f06c | 0xba634 | 0xb9834 | 0x148 |
GetAclInformation | 0x0 | 0x48f070 | 0xba638 | 0xb9838 | 0x124 |
AddAce | 0x0 | 0x48f074 | 0xba63c | 0xb983c | 0x16 |
SetSecurityDescriptorDacl | 0x0 | 0x48f078 | 0xba640 | 0xb9840 | 0x2b6 |
GetUserNameW | 0x0 | 0x48f07c | 0xba644 | 0xb9844 | 0x165 |
InitiateSystemShutdownExW | 0x0 | 0x48f080 | 0xba648 | 0xb9848 | 0x17d |
SHELL32.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DragQueryPoint | 0x0 | 0x48f48c | 0xbaa54 | 0xb9c54 | 0x20 |
ShellExecuteExW | 0x0 | 0x48f490 | 0xbaa58 | 0xb9c58 | 0x121 |
DragQueryFileW | 0x0 | 0x48f494 | 0xbaa5c | 0xb9c5c | 0x1f |
SHEmptyRecycleBinW | 0x0 | 0x48f498 | 0xbaa60 | 0xb9c60 | 0xa5 |
SHGetPathFromIDListW | 0x0 | 0x48f49c | 0xbaa64 | 0xb9c64 | 0xd7 |
SHBrowseForFolderW | 0x0 | 0x48f4a0 | 0xbaa68 | 0xb9c68 | 0x7b |
SHCreateShellItem | 0x0 | 0x48f4a4 | 0xbaa6c | 0xb9c6c | 0x9a |
SHGetDesktopFolder | 0x0 | 0x48f4a8 | 0xbaa70 | 0xb9c70 | 0xb6 |
SHGetSpecialFolderLocation | 0x0 | 0x48f4ac | 0xbaa74 | 0xb9c74 | 0xdf |
SHGetFolderPathW | 0x0 | 0x48f4b0 | 0xbaa78 | 0xb9c78 | 0xc3 |
SHFileOperationW | 0x0 | 0x48f4b4 | 0xbaa7c | 0xb9c7c | 0xac |
ExtractIconExW | 0x0 | 0x48f4b8 | 0xbaa80 | 0xb9c80 | 0x2a |
Shell_NotifyIconW | 0x0 | 0x48f4bc | 0xbaa84 | 0xb9c84 | 0x12e |
ShellExecuteW | 0x0 | 0x48f4c0 | 0xbaa88 | 0xb9c88 | 0x122 |
DragFinish | 0x0 | 0x48f4c4 | 0xbaa8c | 0xb9c8c | 0x1b |
ole32.dll (22)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoTaskMemAlloc | 0x0 | 0x48f828 | 0xbadf0 | 0xb9ff0 | 0x67 |
CoTaskMemFree | 0x0 | 0x48f82c | 0xbadf4 | 0xb9ff4 | 0x68 |
CLSIDFromString | 0x0 | 0x48f830 | 0xbadf8 | 0xb9ff8 | 0x8 |
ProgIDFromCLSID | 0x0 | 0x48f834 | 0xbadfc | 0xb9ffc | 0x14b |
CLSIDFromProgID | 0x0 | 0x48f838 | 0xbae00 | 0xba000 | 0x6 |
OleSetMenuDescriptor | 0x0 | 0x48f83c | 0xbae04 | 0xba004 | 0x147 |
MkParseDisplayName | 0x0 | 0x48f840 | 0xbae08 | 0xba008 | 0xd4 |
OleSetContainedObject | 0x0 | 0x48f844 | 0xbae0c | 0xba00c | 0x146 |
CoCreateInstance | 0x0 | 0x48f848 | 0xbae10 | 0xba010 | 0x10 |
IIDFromString | 0x0 | 0x48f84c | 0xbae14 | 0xba014 | 0xcd |
StringFromGUID2 | 0x0 | 0x48f850 | 0xbae18 | 0xba018 | 0x179 |
CreateStreamOnHGlobal | 0x0 | 0x48f854 | 0xbae1c | 0xba01c | 0x86 |
OleInitialize | 0x0 | 0x48f858 | 0xbae20 | 0xba020 | 0x132 |
OleUninitialize | 0x0 | 0x48f85c | 0xbae24 | 0xba024 | 0x149 |
CoInitialize | 0x0 | 0x48f860 | 0xbae28 | 0xba028 | 0x3e |
CoUninitialize | 0x0 | 0x48f864 | 0xbae2c | 0xba02c | 0x6c |
GetRunningObjectTable | 0x0 | 0x48f868 | 0xbae30 | 0xba030 | 0x97 |
CoGetInstanceFromFile | 0x0 | 0x48f86c | 0xbae34 | 0xba034 | 0x2d |
CoGetObject | 0x0 | 0x48f870 | 0xbae38 | 0xba038 | 0x35 |
CoSetProxyBlanket | 0x0 | 0x48f874 | 0xbae3c | 0xba03c | 0x63 |
CoCreateInstanceEx | 0x0 | 0x48f878 | 0xbae40 | 0xba040 | 0x11 |
CoInitializeSecurity | 0x0 | 0x48f87c | 0xbae44 | 0xba044 | 0x40 |
OLEAUT32.dll (29)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadTypeLibEx | 0xb7 | 0x48f40c | 0xba9d4 | 0xb9bd4 | - |
VariantCopyInd | 0xb | 0x48f410 | 0xba9d8 | 0xb9bd8 | - |
SysReAllocString | 0x3 | 0x48f414 | 0xba9dc | 0xb9bdc | - |
SysFreeString | 0x6 | 0x48f418 | 0xba9e0 | 0xb9be0 | - |
SafeArrayDestroyDescriptor | 0x26 | 0x48f41c | 0xba9e4 | 0xb9be4 | - |
SafeArrayDestroyData | 0x27 | 0x48f420 | 0xba9e8 | 0xb9be8 | - |
SafeArrayUnaccessData | 0x18 | 0x48f424 | 0xba9ec | 0xb9bec | - |
SafeArrayAccessData | 0x17 | 0x48f428 | 0xba9f0 | 0xb9bf0 | - |
SafeArrayAllocData | 0x25 | 0x48f42c | 0xba9f4 | 0xb9bf4 | - |
SafeArrayAllocDescriptorEx | 0x29 | 0x48f430 | 0xba9f8 | 0xb9bf8 | - |
SafeArrayCreateVector | 0x19b | 0x48f434 | 0xba9fc | 0xb9bfc | - |
RegisterTypeLib | 0xa3 | 0x48f438 | 0xbaa00 | 0xb9c00 | - |
CreateStdDispatch | 0x20 | 0x48f43c | 0xbaa04 | 0xb9c04 | - |
DispCallFunc | 0x92 | 0x48f440 | 0xbaa08 | 0xb9c08 | - |
VariantChangeType | 0xc | 0x48f444 | 0xbaa0c | 0xb9c0c | - |
SysStringLen | 0x7 | 0x48f448 | 0xbaa10 | 0xb9c10 | - |
VariantTimeToSystemTime | 0xb9 | 0x48f44c | 0xbaa14 | 0xb9c14 | - |
VarR8FromDec | 0xdc | 0x48f450 | 0xbaa18 | 0xb9c18 | - |
SafeArrayGetVartype | 0x4d | 0x48f454 | 0xbaa1c | 0xb9c1c | - |
VariantCopy | 0xa | 0x48f458 | 0xbaa20 | 0xb9c20 | - |
VariantClear | 0x9 | 0x48f45c | 0xbaa24 | 0xb9c24 | - |
OleLoadPicture | 0x1a2 | 0x48f460 | 0xbaa28 | 0xb9c28 | - |
QueryPathOfRegTypeLib | 0xa4 | 0x48f464 | 0xbaa2c | 0xb9c2c | - |
RegisterTypeLibForUser | 0x1ba | 0x48f468 | 0xbaa30 | 0xb9c30 | - |
UnRegisterTypeLibForUser | 0x1bb | 0x48f46c | 0xbaa34 | 0xb9c34 | - |
UnRegisterTypeLib | 0xba | 0x48f470 | 0xbaa38 | 0xb9c38 | - |
CreateDispTypeInfo | 0x1f | 0x48f474 | 0xbaa3c | 0xb9c3c | - |
SysAllocString | 0x2 | 0x48f478 | 0xbaa40 | 0xb9c40 | - |
VariantInit | 0x8 | 0x48f47c | 0xbaa44 | 0xb9c44 | - |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
b.exe | 1 | 0x01320000 | 0x015D4FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
b.exe | 1 | 0x01320000 | 0x015D4FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
AIT:Trojan.Nymeria.640 |
Malicious
|
C:\Users\5P5NRG~1\AppData\Local\Temp\PreCrack-Ableton.exe | Dropped File | Binary |
Blacklisted
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2018-02-07 22:04 (UTC+1) |
Last Seen | 2019-06-26 05:54 (UTC+2) |
Names | Win32.Trojan.Keygen |
Families | Keygen |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4032bf |
Size Of Code | 0x6000 |
Size Of Initialized Data | 0x1d000 |
Size Of Uninitialized Data | 0x400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2016-12-11 21:50:45+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x5e59 | 0x6000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.42 |
.rdata | 0x407000 | 0x1246 | 0x1400 | 0x6400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.0 |
.data | 0x409000 | 0x1a818 | 0x400 | 0x7800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.21 |
.ndata | 0x424000 | 0x8000 | 0x0 | 0x0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x42c000 | 0x22910 | 0x22a00 | 0x7c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.06 |
Imports (7)
»
KERNEL32.dll (61)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CopyFileA | 0x0 | 0x407070 | 0x7538 | 0x6938 | 0x43 |
Sleep | 0x0 | 0x407074 | 0x753c | 0x693c | 0x356 |
GetTickCount | 0x0 | 0x407078 | 0x7540 | 0x6940 | 0x1df |
CreateFileA | 0x0 | 0x40707c | 0x7544 | 0x6944 | 0x53 |
GetFileSize | 0x0 | 0x407080 | 0x7548 | 0x6948 | 0x163 |
GetModuleFileNameA | 0x0 | 0x407084 | 0x754c | 0x694c | 0x17d |
ReadFile | 0x0 | 0x407088 | 0x7550 | 0x6950 | 0x2b5 |
GetFileAttributesA | 0x0 | 0x40708c | 0x7554 | 0x6954 | 0x15e |
SetFileAttributesA | 0x0 | 0x407090 | 0x7558 | 0x6958 | 0x319 |
ExitProcess | 0x0 | 0x407094 | 0x755c | 0x695c | 0xb9 |
SetEnvironmentVariableA | 0x0 | 0x407098 | 0x7560 | 0x6960 | 0x313 |
GetWindowsDirectoryA | 0x0 | 0x40709c | 0x7564 | 0x6964 | 0x1f3 |
GetTempPathA | 0x0 | 0x4070a0 | 0x7568 | 0x6968 | 0x1d5 |
GetCommandLineA | 0x0 | 0x4070a4 | 0x756c | 0x696c | 0x110 |
lstrlenA | 0x0 | 0x4070a8 | 0x7570 | 0x6970 | 0x3cc |
GetVersion | 0x0 | 0x4070ac | 0x7574 | 0x6974 | 0x1e8 |
GetCurrentProcess | 0x0 | 0x4070b0 | 0x7578 | 0x6978 | 0x142 |
GetFullPathNameA | 0x0 | 0x4070b4 | 0x757c | 0x697c | 0x169 |
GetDiskFreeSpaceA | 0x0 | 0x4070b8 | 0x7580 | 0x6980 | 0x14d |
GlobalUnlock | 0x0 | 0x4070bc | 0x7584 | 0x6984 | 0x20a |
GlobalLock | 0x0 | 0x4070c0 | 0x7588 | 0x6988 | 0x203 |
CreateThread | 0x0 | 0x4070c4 | 0x758c | 0x698c | 0x6f |
GetLastError | 0x0 | 0x4070c8 | 0x7590 | 0x6990 | 0x171 |
CreateDirectoryA | 0x0 | 0x4070cc | 0x7594 | 0x6994 | 0x4b |
CreateProcessA | 0x0 | 0x4070d0 | 0x7598 | 0x6998 | 0x66 |
RemoveDirectoryA | 0x0 | 0x4070d4 | 0x759c | 0x699c | 0x2c4 |
GetTempFileNameA | 0x0 | 0x4070d8 | 0x75a0 | 0x69a0 | 0x1d3 |
WriteFile | 0x0 | 0x4070dc | 0x75a4 | 0x69a4 | 0x3a4 |
lstrcpyA | 0x0 | 0x4070e0 | 0x75a8 | 0x69a8 | 0x3c6 |
MoveFileExA | 0x0 | 0x4070e4 | 0x75ac | 0x69ac | 0x26f |
lstrcatA | 0x0 | 0x4070e8 | 0x75b0 | 0x69b0 | 0x3bd |
GetSystemDirectoryA | 0x0 | 0x4070ec | 0x75b4 | 0x69b4 | 0x1c1 |
GetProcAddress | 0x0 | 0x4070f0 | 0x75b8 | 0x69b8 | 0x1a0 |
CloseHandle | 0x0 | 0x4070f4 | 0x75bc | 0x69bc | 0x34 |
SetCurrentDirectoryA | 0x0 | 0x4070f8 | 0x75c0 | 0x69c0 | 0x30a |
MoveFileA | 0x0 | 0x4070fc | 0x75c4 | 0x69c4 | 0x26e |
CompareFileTime | 0x0 | 0x407100 | 0x75c8 | 0x69c8 | 0x39 |
GetShortPathNameA | 0x0 | 0x407104 | 0x75cc | 0x69cc | 0x1b5 |
SearchPathA | 0x0 | 0x407108 | 0x75d0 | 0x69d0 | 0x2db |
lstrcmpiA | 0x0 | 0x40710c | 0x75d4 | 0x69d4 | 0x3c3 |
SetFileTime | 0x0 | 0x407110 | 0x75d8 | 0x69d8 | 0x31f |
lstrcmpA | 0x0 | 0x407114 | 0x75dc | 0x69dc | 0x3c0 |
ExpandEnvironmentStringsA | 0x0 | 0x407118 | 0x75e0 | 0x69e0 | 0xbc |
lstrcpynA | 0x0 | 0x40711c | 0x75e4 | 0x69e4 | 0x3c9 |
SetErrorMode | 0x0 | 0x407120 | 0x75e8 | 0x69e8 | 0x315 |
GlobalFree | 0x0 | 0x407124 | 0x75ec | 0x69ec | 0x1ff |
FindFirstFileA | 0x0 | 0x407128 | 0x75f0 | 0x69f0 | 0xd2 |
FindNextFileA | 0x0 | 0x40712c | 0x75f4 | 0x69f4 | 0xdc |
DeleteFileA | 0x0 | 0x407130 | 0x75f8 | 0x69f8 | 0x83 |
SetFilePointer | 0x0 | 0x407134 | 0x75fc | 0x69fc | 0x31b |
GetPrivateProfileStringA | 0x0 | 0x407138 | 0x7600 | 0x6a00 | 0x19c |
FindClose | 0x0 | 0x40713c | 0x7604 | 0x6a04 | 0xce |
MultiByteToWideChar | 0x0 | 0x407140 | 0x7608 | 0x6a08 | 0x275 |
FreeLibrary | 0x0 | 0x407144 | 0x760c | 0x6a0c | 0xf8 |
MulDiv | 0x0 | 0x407148 | 0x7610 | 0x6a10 | 0x274 |
WritePrivateProfileStringA | 0x0 | 0x40714c | 0x7614 | 0x6a14 | 0x3a9 |
LoadLibraryExA | 0x0 | 0x407150 | 0x7618 | 0x6a18 | 0x253 |
GetModuleHandleA | 0x0 | 0x407154 | 0x761c | 0x6a1c | 0x17f |
GetExitCodeProcess | 0x0 | 0x407158 | 0x7620 | 0x6a20 | 0x15a |
WaitForSingleObject | 0x0 | 0x40715c | 0x7624 | 0x6a24 | 0x390 |
GlobalAlloc | 0x0 | 0x407160 | 0x7628 | 0x6a28 | 0x1f8 |
USER32.dll (63)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ScreenToClient | 0x0 | 0x407184 | 0x764c | 0x6a4c | 0x231 |
GetSystemMenu | 0x0 | 0x407188 | 0x7650 | 0x6a50 | 0x15c |
SetClassLongA | 0x0 | 0x40718c | 0x7654 | 0x6a54 | 0x247 |
IsWindowEnabled | 0x0 | 0x407190 | 0x7658 | 0x6a58 | 0x1ae |
SetWindowPos | 0x0 | 0x407194 | 0x765c | 0x6a5c | 0x283 |
GetSysColor | 0x0 | 0x407198 | 0x7660 | 0x6a60 | 0x15a |
GetWindowLongA | 0x0 | 0x40719c | 0x7664 | 0x6a64 | 0x16e |
SetCursor | 0x0 | 0x4071a0 | 0x7668 | 0x6a68 | 0x24d |
LoadCursorA | 0x0 | 0x4071a4 | 0x766c | 0x6a6c | 0x1ba |
CheckDlgButton | 0x0 | 0x4071a8 | 0x7670 | 0x6a70 | 0x38 |
GetMessagePos | 0x0 | 0x4071ac | 0x7674 | 0x6a74 | 0x13c |
LoadBitmapA | 0x0 | 0x4071b0 | 0x7678 | 0x6a78 | 0x1b8 |
CallWindowProcA | 0x0 | 0x4071b4 | 0x767c | 0x6a7c | 0x1b |
IsWindowVisible | 0x0 | 0x4071b8 | 0x7680 | 0x6a80 | 0x1b1 |
CloseClipboard | 0x0 | 0x4071bc | 0x7684 | 0x6a84 | 0x42 |
SetClipboardData | 0x0 | 0x4071c0 | 0x7688 | 0x6a88 | 0x24a |
EmptyClipboard | 0x0 | 0x4071c4 | 0x768c | 0x6a8c | 0xc1 |
PostQuitMessage | 0x0 | 0x4071c8 | 0x7690 | 0x6a90 | 0x204 |
GetWindowRect | 0x0 | 0x4071cc | 0x7694 | 0x6a94 | 0x174 |
EnableMenuItem | 0x0 | 0x4071d0 | 0x7698 | 0x6a98 | 0xc2 |
CreatePopupMenu | 0x0 | 0x4071d4 | 0x769c | 0x6a9c | 0x5e |
GetSystemMetrics | 0x0 | 0x4071d8 | 0x76a0 | 0x6aa0 | 0x15d |
SetDlgItemTextA | 0x0 | 0x4071dc | 0x76a4 | 0x6aa4 | 0x253 |
GetDlgItemTextA | 0x0 | 0x4071e0 | 0x76a8 | 0x6aa8 | 0x113 |
MessageBoxIndirectA | 0x0 | 0x4071e4 | 0x76ac | 0x6aac | 0x1e2 |
CharPrevA | 0x0 | 0x4071e8 | 0x76b0 | 0x6ab0 | 0x2d |
DispatchMessageA | 0x0 | 0x4071ec | 0x76b4 | 0x6ab4 | 0xa1 |
PeekMessageA | 0x0 | 0x4071f0 | 0x76b8 | 0x6ab8 | 0x200 |
ReleaseDC | 0x0 | 0x4071f4 | 0x76bc | 0x6abc | 0x22a |
EnableWindow | 0x0 | 0x4071f8 | 0x76c0 | 0x6ac0 | 0xc4 |
InvalidateRect | 0x0 | 0x4071fc | 0x76c4 | 0x6ac4 | 0x193 |
SendMessageA | 0x0 | 0x407200 | 0x76c8 | 0x6ac8 | 0x23b |
DefWindowProcA | 0x0 | 0x407204 | 0x76cc | 0x6acc | 0x8e |
BeginPaint | 0x0 | 0x407208 | 0x76d0 | 0x6ad0 | 0xd |
GetClientRect | 0x0 | 0x40720c | 0x76d4 | 0x6ad4 | 0xff |
FillRect | 0x0 | 0x407210 | 0x76d8 | 0x6ad8 | 0xe2 |
DrawTextA | 0x0 | 0x407214 | 0x76dc | 0x6adc | 0xbc |
EndDialog | 0x0 | 0x407218 | 0x76e0 | 0x6ae0 | 0xc6 |
RegisterClassA | 0x0 | 0x40721c | 0x76e4 | 0x6ae4 | 0x216 |
SystemParametersInfoA | 0x0 | 0x407220 | 0x76e8 | 0x6ae8 | 0x299 |
CreateWindowExA | 0x0 | 0x407224 | 0x76ec | 0x6aec | 0x60 |
GetClassInfoA | 0x0 | 0x407228 | 0x76f0 | 0x6af0 | 0xf6 |
DialogBoxParamA | 0x0 | 0x40722c | 0x76f4 | 0x6af4 | 0x9e |
CharNextA | 0x0 | 0x407230 | 0x76f8 | 0x6af8 | 0x2a |
ExitWindowsEx | 0x0 | 0x407234 | 0x76fc | 0x6afc | 0xe1 |
GetDC | 0x0 | 0x407238 | 0x7700 | 0x6b00 | 0x10c |
CreateDialogParamA | 0x0 | 0x40723c | 0x7704 | 0x6b04 | 0x55 |
SetTimer | 0x0 | 0x407240 | 0x7708 | 0x6b08 | 0x27a |
GetDlgItem | 0x0 | 0x407244 | 0x770c | 0x6b0c | 0x111 |
SetWindowLongA | 0x0 | 0x407248 | 0x7710 | 0x6b10 | 0x280 |
SetForegroundWindow | 0x0 | 0x40724c | 0x7714 | 0x6b14 | 0x257 |
LoadImageA | 0x0 | 0x407250 | 0x7718 | 0x6b18 | 0x1c0 |
IsWindow | 0x0 | 0x407254 | 0x771c | 0x6b1c | 0x1ad |
SendMessageTimeoutA | 0x0 | 0x407258 | 0x7720 | 0x6b20 | 0x23e |
FindWindowExA | 0x0 | 0x40725c | 0x7724 | 0x6b24 | 0xe4 |
OpenClipboard | 0x0 | 0x407260 | 0x7728 | 0x6b28 | 0x1f6 |
TrackPopupMenu | 0x0 | 0x407264 | 0x772c | 0x6b2c | 0x2a4 |
AppendMenuA | 0x0 | 0x407268 | 0x7730 | 0x6b30 | 0x8 |
EndPaint | 0x0 | 0x40726c | 0x7734 | 0x6b34 | 0xc8 |
DestroyWindow | 0x0 | 0x407270 | 0x7738 | 0x6b38 | 0x99 |
wsprintfA | 0x0 | 0x407274 | 0x773c | 0x6b3c | 0x2d7 |
ShowWindow | 0x0 | 0x407278 | 0x7740 | 0x6b40 | 0x292 |
SetWindowTextA | 0x0 | 0x40727c | 0x7744 | 0x6b44 | 0x286 |
GDI32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SelectObject | 0x0 | 0x40704c | 0x7514 | 0x6914 | 0x20e |
SetBkMode | 0x0 | 0x407050 | 0x7518 | 0x6918 | 0x216 |
CreateFontIndirectA | 0x0 | 0x407054 | 0x751c | 0x691c | 0x3a |
SetTextColor | 0x0 | 0x407058 | 0x7520 | 0x6920 | 0x23c |
DeleteObject | 0x0 | 0x40705c | 0x7524 | 0x6924 | 0x8f |
GetDeviceCaps | 0x0 | 0x407060 | 0x7528 | 0x6928 | 0x16b |
CreateBrushIndirect | 0x0 | 0x407064 | 0x752c | 0x692c | 0x29 |
SetBkColor | 0x0 | 0x407068 | 0x7530 | 0x6930 | 0x215 |
SHELL32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderLocation | 0x0 | 0x407168 | 0x7630 | 0x6a30 | 0xc3 |
SHGetPathFromIDListA | 0x0 | 0x40716c | 0x7634 | 0x6a34 | 0xbc |
SHBrowseForFolderA | 0x0 | 0x407170 | 0x7638 | 0x6a38 | 0x79 |
SHGetFileInfoA | 0x0 | 0x407174 | 0x763c | 0x6a3c | 0xac |
ShellExecuteA | 0x0 | 0x407178 | 0x7640 | 0x6a40 | 0x107 |
SHFileOperationA | 0x0 | 0x40717c | 0x7644 | 0x6a44 | 0x9a |
ADVAPI32.dll (13)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegDeleteKeyA | 0x0 | 0x407000 | 0x74c8 | 0x68c8 | 0x1d4 |
SetFileSecurityA | 0x0 | 0x407004 | 0x74cc | 0x68cc | 0x22e |
OpenProcessToken | 0x0 | 0x407008 | 0x74d0 | 0x68d0 | 0x1ac |
LookupPrivilegeValueA | 0x0 | 0x40700c | 0x74d4 | 0x68d4 | 0x14f |
AdjustTokenPrivileges | 0x0 | 0x407010 | 0x74d8 | 0x68d8 | 0x1c |
RegOpenKeyExA | 0x0 | 0x407014 | 0x74dc | 0x68dc | 0x1ec |
RegEnumValueA | 0x0 | 0x407018 | 0x74e0 | 0x68e0 | 0x1e1 |
RegDeleteValueA | 0x0 | 0x40701c | 0x74e4 | 0x68e4 | 0x1d8 |
RegCloseKey | 0x0 | 0x407020 | 0x74e8 | 0x68e8 | 0x1cb |
RegCreateKeyExA | 0x0 | 0x407024 | 0x74ec | 0x68ec | 0x1d1 |
RegSetValueExA | 0x0 | 0x407028 | 0x74f0 | 0x68f0 | 0x204 |
RegQueryValueExA | 0x0 | 0x40702c | 0x74f4 | 0x68f4 | 0x1f7 |
RegEnumKeyA | 0x0 | 0x407030 | 0x74f8 | 0x68f8 | 0x1dd |
COMCTL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_Create | 0x0 | 0x407038 | 0x7500 | 0x6900 | 0x37 |
ImageList_AddMasked | 0x0 | 0x40703c | 0x7504 | 0x6904 | 0x34 |
ImageList_Destroy | 0x0 | 0x407040 | 0x7508 | 0x6908 | 0x38 |
(by ordinal) | 0x11 | 0x407044 | 0x750c | 0x690c | - |
ole32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OleUninitialize | 0x0 | 0x407284 | 0x774c | 0x6b4c | 0x105 |
OleInitialize | 0x0 | 0x407288 | 0x7750 | 0x6b50 | 0xee |
CoTaskMemFree | 0x0 | 0x40728c | 0x7754 | 0x6b54 | 0x65 |
CoCreateInstance | 0x0 | 0x407290 | 0x7758 | 0x6b58 | 0x10 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
precrack-ableton.exe | 2 | 0x00400000 | 0x0044EFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
C:\Users\5P5NRG~1\AppData\Local\Temp\R2RLIVE.dll | Dropped File | Binary |
Blacklisted
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2018-02-09 01:31 (UTC+1) |
Last Seen | 2019-03-09 00:22 (UTC+1) |
Names | Win32.Trojan.Grp |
Families | Grp |
Classification | Trojan |
PE Information
»
Image Base | 0x10000000 |
Entry Point | 0x100b4004 |
Size Of Code | 0x2d8 |
Size Of Initialized Data | 0x4e200 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-02-06 14:45:17+00:00 |
Sections (2)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
- | 0x10001000 | 0xb3000 | 0x4e200 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.98 |
petite | 0x100b4000 | 0x2d8 | 0x2d8 | 0x4e600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.98 |
Imports (3)
»
user32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | 0x0 | 0x100b41ec | 0xb41ec | 0x4e7ec | 0x0 |
wsprintfA | 0x0 | 0x100b41f0 | 0xb41f0 | 0x4e7f0 | 0x0 |
kernel32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitProcess | 0x0 | 0x100b41f8 | 0xb41f8 | 0x4e7f8 | 0x0 |
GetModuleHandleA | 0x0 | 0x100b41fc | 0xb41fc | 0x4e7fc | 0x0 |
GetProcAddress | 0x0 | 0x100b4200 | 0xb4200 | 0x4e800 | 0x0 |
VirtualProtect | 0x0 | 0x100b4204 | 0xb4204 | 0x4e804 | 0x0 |
VirtualAlloc | 0x0 | 0x100b4208 | 0xb4208 | 0x4e808 | 0x0 |
VirtualFree | 0x0 | 0x100b420c | 0xb420c | 0x4e80c | 0x0 |
LoadLibraryA | 0x0 | 0x100b4210 | 0xb4210 | 0x4e810 | 0x0 |
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ReportEventA | 0x0 | 0x100b4218 | 0xb4218 | 0x4e818 | 0x0 |
Exports (1)
»
Api name | EAT Address | Ordinal |
---|---|---|
GenerateLicense | 0x1000 | 0x1 |
C:\Users\5P5NRG~1\AppData\Local\Temp\buran.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x422314 |
Size Of Code | 0x21c00 |
Size Of Initialized Data | 0x5000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-07-03 16:57:59+00:00 |
Sections (9)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x20cc4 | 0x20e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.67 |
.itext | 0x422000 | 0xccc | 0xe00 | 0x21200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.11 |
.data | 0x423000 | 0x16b0 | 0x1800 | 0x22000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.93 |
.bss | 0x425000 | 0x5234 | 0x0 | 0x23800 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x42b000 | 0x11ea | 0x1200 | 0x23800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.01 |
.tls | 0x42d000 | 0xc | 0x0 | 0x24a00 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rdata | 0x42e000 | 0x18 | 0x200 | 0x24a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.2 |
.reloc | 0x42f000 | 0x20c0 | 0x2200 | 0x24c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.58 |
.rsrc | 0x432000 | 0x0 | 0x200 | 0x26e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.0 |
Imports (15)
»
oleaut32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysFreeString | 0x0 | 0x42b3e0 | 0x2b140 | 0x23940 | 0x0 |
SysReAllocStringLen | 0x0 | 0x42b3e4 | 0x2b144 | 0x23944 | 0x0 |
SysAllocStringLen | 0x0 | 0x42b3e8 | 0x2b148 | 0x23948 | 0x0 |
advapi32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExA | 0x0 | 0x42b3f0 | 0x2b150 | 0x23950 | 0x0 |
RegOpenKeyExA | 0x0 | 0x42b3f4 | 0x2b154 | 0x23954 | 0x0 |
RegCloseKey | 0x0 | 0x42b3f8 | 0x2b158 | 0x23958 | 0x0 |
user32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetKeyboardType | 0x0 | 0x42b400 | 0x2b160 | 0x23960 | 0x0 |
DestroyWindow | 0x0 | 0x42b404 | 0x2b164 | 0x23964 | 0x0 |
LoadStringA | 0x0 | 0x42b408 | 0x2b168 | 0x23968 | 0x0 |
MessageBoxA | 0x0 | 0x42b40c | 0x2b16c | 0x2396c | 0x0 |
CharNextA | 0x0 | 0x42b410 | 0x2b170 | 0x23970 | 0x0 |
kernel32.dll (33)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetACP | 0x0 | 0x42b418 | 0x2b178 | 0x23978 | 0x0 |
Sleep | 0x0 | 0x42b41c | 0x2b17c | 0x2397c | 0x0 |
VirtualFree | 0x0 | 0x42b420 | 0x2b180 | 0x23980 | 0x0 |
VirtualAlloc | 0x0 | 0x42b424 | 0x2b184 | 0x23984 | 0x0 |
GetTickCount | 0x0 | 0x42b428 | 0x2b188 | 0x23988 | 0x0 |
QueryPerformanceCounter | 0x0 | 0x42b42c | 0x2b18c | 0x2398c | 0x0 |
GetCurrentThreadId | 0x0 | 0x42b430 | 0x2b190 | 0x23990 | 0x0 |
InterlockedDecrement | 0x0 | 0x42b434 | 0x2b194 | 0x23994 | 0x0 |
InterlockedIncrement | 0x0 | 0x42b438 | 0x2b198 | 0x23998 | 0x0 |
VirtualQuery | 0x0 | 0x42b43c | 0x2b19c | 0x2399c | 0x0 |
WideCharToMultiByte | 0x0 | 0x42b440 | 0x2b1a0 | 0x239a0 | 0x0 |
MultiByteToWideChar | 0x0 | 0x42b444 | 0x2b1a4 | 0x239a4 | 0x0 |
lstrlenA | 0x0 | 0x42b448 | 0x2b1a8 | 0x239a8 | 0x0 |
lstrcpynA | 0x0 | 0x42b44c | 0x2b1ac | 0x239ac | 0x0 |
LoadLibraryExA | 0x0 | 0x42b450 | 0x2b1b0 | 0x239b0 | 0x0 |
GetThreadLocale | 0x0 | 0x42b454 | 0x2b1b4 | 0x239b4 | 0x0 |
GetStartupInfoA | 0x0 | 0x42b458 | 0x2b1b8 | 0x239b8 | 0x0 |
GetProcAddress | 0x0 | 0x42b45c | 0x2b1bc | 0x239bc | 0x0 |
GetModuleHandleA | 0x0 | 0x42b460 | 0x2b1c0 | 0x239c0 | 0x0 |
GetModuleFileNameA | 0x0 | 0x42b464 | 0x2b1c4 | 0x239c4 | 0x0 |
GetLocaleInfoA | 0x0 | 0x42b468 | 0x2b1c8 | 0x239c8 | 0x0 |
GetCommandLineA | 0x0 | 0x42b46c | 0x2b1cc | 0x239cc | 0x0 |
FreeLibrary | 0x0 | 0x42b470 | 0x2b1d0 | 0x239d0 | 0x0 |
FindFirstFileA | 0x0 | 0x42b474 | 0x2b1d4 | 0x239d4 | 0x0 |
FindClose | 0x0 | 0x42b478 | 0x2b1d8 | 0x239d8 | 0x0 |
ExitProcess | 0x0 | 0x42b47c | 0x2b1dc | 0x239dc | 0x0 |
ExitThread | 0x0 | 0x42b480 | 0x2b1e0 | 0x239e0 | 0x0 |
CreateThread | 0x0 | 0x42b484 | 0x2b1e4 | 0x239e4 | 0x0 |
WriteFile | 0x0 | 0x42b488 | 0x2b1e8 | 0x239e8 | 0x0 |
UnhandledExceptionFilter | 0x0 | 0x42b48c | 0x2b1ec | 0x239ec | 0x0 |
RtlUnwind | 0x0 | 0x42b490 | 0x2b1f0 | 0x239f0 | 0x0 |
RaiseException | 0x0 | 0x42b494 | 0x2b1f4 | 0x239f4 | 0x0 |
GetStdHandle | 0x0 | 0x42b498 | 0x2b1f8 | 0x239f8 | 0x0 |
kernel32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TlsSetValue | 0x0 | 0x42b4a0 | 0x2b200 | 0x23a00 | 0x0 |
TlsGetValue | 0x0 | 0x42b4a4 | 0x2b204 | 0x23a04 | 0x0 |
LocalAlloc | 0x0 | 0x42b4a8 | 0x2b208 | 0x23a08 | 0x0 |
GetModuleHandleA | 0x0 | 0x42b4ac | 0x2b20c | 0x23a0c | 0x0 |
user32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TranslateMessage | 0x0 | 0x42b4b4 | 0x2b214 | 0x23a14 | 0x0 |
PeekMessageA | 0x0 | 0x42b4b8 | 0x2b218 | 0x23a18 | 0x0 |
MsgWaitForMultipleObjects | 0x0 | 0x42b4bc | 0x2b21c | 0x23a1c | 0x0 |
MessageBoxA | 0x0 | 0x42b4c0 | 0x2b220 | 0x23a20 | 0x0 |
LoadStringA | 0x0 | 0x42b4c4 | 0x2b224 | 0x23a24 | 0x0 |
GetSystemMetrics | 0x0 | 0x42b4c8 | 0x2b228 | 0x23a28 | 0x0 |
DispatchMessageA | 0x0 | 0x42b4cc | 0x2b22c | 0x23a2c | 0x0 |
CharNextW | 0x0 | 0x42b4d0 | 0x2b230 | 0x23a30 | 0x0 |
CharLowerBuffW | 0x0 | 0x42b4d4 | 0x2b234 | 0x23a34 | 0x0 |
CharNextA | 0x0 | 0x42b4d8 | 0x2b238 | 0x23a38 | 0x0 |
CharLowerBuffA | 0x0 | 0x42b4dc | 0x2b23c | 0x23a3c | 0x0 |
CharToOemA | 0x0 | 0x42b4e0 | 0x2b240 | 0x23a40 | 0x0 |
mpr.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetOpenEnumA | 0x0 | 0x42b4e8 | 0x2b248 | 0x23a48 | 0x0 |
WNetEnumResourceA | 0x0 | 0x42b4ec | 0x2b24c | 0x23a4c | 0x0 |
WNetCloseEnum | 0x0 | 0x42b4f0 | 0x2b250 | 0x23a50 | 0x0 |
kernel32.dll (61)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WriteFile | 0x0 | 0x42b4f8 | 0x2b258 | 0x23a58 | 0x0 |
WaitForSingleObject | 0x0 | 0x42b4fc | 0x2b25c | 0x23a5c | 0x0 |
VirtualQuery | 0x0 | 0x42b500 | 0x2b260 | 0x23a60 | 0x0 |
SetFilePointer | 0x0 | 0x42b504 | 0x2b264 | 0x23a64 | 0x0 |
SetFileAttributesW | 0x0 | 0x42b508 | 0x2b268 | 0x23a68 | 0x0 |
SetEvent | 0x0 | 0x42b50c | 0x2b26c | 0x23a6c | 0x0 |
SetEndOfFile | 0x0 | 0x42b510 | 0x2b270 | 0x23a70 | 0x0 |
ResumeThread | 0x0 | 0x42b514 | 0x2b274 | 0x23a74 | 0x0 |
ResetEvent | 0x0 | 0x42b518 | 0x2b278 | 0x23a78 | 0x0 |
ReadFile | 0x0 | 0x42b51c | 0x2b27c | 0x23a7c | 0x0 |
MoveFileW | 0x0 | 0x42b520 | 0x2b280 | 0x23a80 | 0x0 |
LeaveCriticalSection | 0x0 | 0x42b524 | 0x2b284 | 0x23a84 | 0x0 |
InitializeCriticalSection | 0x0 | 0x42b528 | 0x2b288 | 0x23a88 | 0x0 |
GlobalUnlock | 0x0 | 0x42b52c | 0x2b28c | 0x23a8c | 0x0 |
GlobalReAlloc | 0x0 | 0x42b530 | 0x2b290 | 0x23a90 | 0x0 |
GlobalHandle | 0x0 | 0x42b534 | 0x2b294 | 0x23a94 | 0x0 |
GlobalLock | 0x0 | 0x42b538 | 0x2b298 | 0x23a98 | 0x0 |
GlobalFree | 0x0 | 0x42b53c | 0x2b29c | 0x23a9c | 0x0 |
GlobalAlloc | 0x0 | 0x42b540 | 0x2b2a0 | 0x23aa0 | 0x0 |
GetVersionExA | 0x0 | 0x42b544 | 0x2b2a4 | 0x23aa4 | 0x0 |
GetThreadLocale | 0x0 | 0x42b548 | 0x2b2a8 | 0x23aa8 | 0x0 |
GetStdHandle | 0x0 | 0x42b54c | 0x2b2ac | 0x23aac | 0x0 |
GetProcAddress | 0x0 | 0x42b550 | 0x2b2b0 | 0x23ab0 | 0x0 |
GetModuleHandleA | 0x0 | 0x42b554 | 0x2b2b4 | 0x23ab4 | 0x0 |
GetModuleFileNameW | 0x0 | 0x42b558 | 0x2b2b8 | 0x23ab8 | 0x0 |
GetModuleFileNameA | 0x0 | 0x42b55c | 0x2b2bc | 0x23abc | 0x0 |
GetLocaleInfoA | 0x0 | 0x42b560 | 0x2b2c0 | 0x23ac0 | 0x0 |
GetLocalTime | 0x0 | 0x42b564 | 0x2b2c4 | 0x23ac4 | 0x0 |
GetLastError | 0x0 | 0x42b568 | 0x2b2c8 | 0x23ac8 | 0x0 |
GetFullPathNameA | 0x0 | 0x42b56c | 0x2b2cc | 0x23acc | 0x0 |
GetExitCodeThread | 0x0 | 0x42b570 | 0x2b2d0 | 0x23ad0 | 0x0 |
GetEnvironmentVariableW | 0x0 | 0x42b574 | 0x2b2d4 | 0x23ad4 | 0x0 |
GetEnvironmentVariableA | 0x0 | 0x42b578 | 0x2b2d8 | 0x23ad8 | 0x0 |
GetDriveTypeA | 0x0 | 0x42b57c | 0x2b2dc | 0x23adc | 0x0 |
GetDiskFreeSpaceA | 0x0 | 0x42b580 | 0x2b2e0 | 0x23ae0 | 0x0 |
GetDateFormatA | 0x0 | 0x42b584 | 0x2b2e4 | 0x23ae4 | 0x0 |
GetCurrentThreadId | 0x0 | 0x42b588 | 0x2b2e8 | 0x23ae8 | 0x0 |
GetCurrentProcess | 0x0 | 0x42b58c | 0x2b2ec | 0x23aec | 0x0 |
GetCommandLineW | 0x0 | 0x42b590 | 0x2b2f0 | 0x23af0 | 0x0 |
GetCPInfo | 0x0 | 0x42b594 | 0x2b2f4 | 0x23af4 | 0x0 |
InterlockedIncrement | 0x0 | 0x42b598 | 0x2b2f8 | 0x23af8 | 0x0 |
InterlockedExchange | 0x0 | 0x42b59c | 0x2b2fc | 0x23afc | 0x0 |
InterlockedDecrement | 0x0 | 0x42b5a0 | 0x2b300 | 0x23b00 | 0x0 |
FreeLibrary | 0x0 | 0x42b5a4 | 0x2b304 | 0x23b04 | 0x0 |
FormatMessageA | 0x0 | 0x42b5a8 | 0x2b308 | 0x23b08 | 0x0 |
FindNextFileW | 0x0 | 0x42b5ac | 0x2b30c | 0x23b0c | 0x0 |
FindFirstFileW | 0x0 | 0x42b5b0 | 0x2b310 | 0x23b10 | 0x0 |
FindClose | 0x0 | 0x42b5b4 | 0x2b314 | 0x23b14 | 0x0 |
FileTimeToLocalFileTime | 0x0 | 0x42b5b8 | 0x2b318 | 0x23b18 | 0x0 |
FileTimeToDosDateTime | 0x0 | 0x42b5bc | 0x2b31c | 0x23b1c | 0x0 |
ExitProcess | 0x0 | 0x42b5c0 | 0x2b320 | 0x23b20 | 0x0 |
EnumCalendarInfoA | 0x0 | 0x42b5c4 | 0x2b324 | 0x23b24 | 0x0 |
EnterCriticalSection | 0x0 | 0x42b5c8 | 0x2b328 | 0x23b28 | 0x0 |
DeleteFileW | 0x0 | 0x42b5cc | 0x2b32c | 0x23b2c | 0x0 |
DeleteCriticalSection | 0x0 | 0x42b5d0 | 0x2b330 | 0x23b30 | 0x0 |
CreateProcessW | 0x0 | 0x42b5d4 | 0x2b334 | 0x23b34 | 0x0 |
CreateFileW | 0x0 | 0x42b5d8 | 0x2b338 | 0x23b38 | 0x0 |
CreateFileA | 0x0 | 0x42b5dc | 0x2b33c | 0x23b3c | 0x0 |
CreateEventA | 0x0 | 0x42b5e0 | 0x2b340 | 0x23b40 | 0x0 |
CompareStringA | 0x0 | 0x42b5e4 | 0x2b344 | 0x23b44 | 0x0 |
CloseHandle | 0x0 | 0x42b5e8 | 0x2b348 | 0x23b48 | 0x0 |
advapi32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegSetValueExA | 0x0 | 0x42b5f0 | 0x2b350 | 0x23b50 | 0x0 |
RegQueryValueExA | 0x0 | 0x42b5f4 | 0x2b354 | 0x23b54 | 0x0 |
RegOpenKeyExA | 0x0 | 0x42b5f8 | 0x2b358 | 0x23b58 | 0x0 |
RegCreateKeyExA | 0x0 | 0x42b5fc | 0x2b35c | 0x23b5c | 0x0 |
RegCloseKey | 0x0 | 0x42b600 | 0x2b360 | 0x23b60 | 0x0 |
OpenProcessToken | 0x0 | 0x42b604 | 0x2b364 | 0x23b64 | 0x0 |
LookupPrivilegeValueA | 0x0 | 0x42b608 | 0x2b368 | 0x23b68 | 0x0 |
AdjustTokenPrivileges | 0x0 | 0x42b60c | 0x2b36c | 0x23b6c | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x42b614 | 0x2b374 | 0x23b74 | 0x0 |
kernel32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Sleep | 0x0 | 0x42b61c | 0x2b37c | 0x23b7c | 0x0 |
oleaut32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SafeArrayPtrOfIndex | 0x0 | 0x42b624 | 0x2b384 | 0x23b84 | 0x0 |
SafeArrayGetUBound | 0x0 | 0x42b628 | 0x2b388 | 0x23b88 | 0x0 |
SafeArrayGetLBound | 0x0 | 0x42b62c | 0x2b38c | 0x23b8c | 0x0 |
SafeArrayCreate | 0x0 | 0x42b630 | 0x2b390 | 0x23b90 | 0x0 |
VariantChangeType | 0x0 | 0x42b634 | 0x2b394 | 0x23b94 | 0x0 |
VariantCopy | 0x0 | 0x42b638 | 0x2b398 | 0x23b98 | 0x0 |
VariantClear | 0x0 | 0x42b63c | 0x2b39c | 0x23b9c | 0x0 |
VariantInit | 0x0 | 0x42b640 | 0x2b3a0 | 0x23ba0 | 0x0 |
wininet.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InternetReadFile | 0x0 | 0x42b648 | 0x2b3a8 | 0x23ba8 | 0x0 |
InternetOpenUrlA | 0x0 | 0x42b64c | 0x2b3ac | 0x23bac | 0x0 |
InternetOpenA | 0x0 | 0x42b650 | 0x2b3b0 | 0x23bb0 | 0x0 |
InternetConnectA | 0x0 | 0x42b654 | 0x2b3b4 | 0x23bb4 | 0x0 |
InternetCloseHandle | 0x0 | 0x42b658 | 0x2b3b8 | 0x23bb8 | 0x0 |
HttpSendRequestA | 0x0 | 0x42b65c | 0x2b3bc | 0x23bbc | 0x0 |
HttpOpenRequestA | 0x0 | 0x42b660 | 0x2b3c0 | 0x23bc0 | 0x0 |
HttpAddRequestHeadersA | 0x0 | 0x42b664 | 0x2b3c4 | 0x23bc4 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderLocation | 0x0 | 0x42b66c | 0x2b3cc | 0x23bcc | 0x0 |
shell32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetPathFromIDListW | 0x0 | 0x42b674 | 0x2b3d4 | 0x23bd4 | 0x0 |
SHGetMalloc | 0x0 | 0x42b678 | 0x2b3d8 | 0x23bd8 | 0x0 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buran.exe | 3 | 0x00930000 | 0x00962FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buran.exe | 3 | 0x00930000 | 0x00962FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Win32.Malware.jKW@aONj6oc |
Malicious
|
C:\Users\5P5NRG~1\AppData\Local\Temp\keygen.exe | Dropped File | Binary |
Suspicious
|
...
|
»
File Reputation Information
»
Severity |
Suspicious
|
First Seen | 2018-02-09 01:58 (UTC+1) |
Last Seen | 2019-06-23 08:47 (UTC+2) |
Names | Win32.PUA.Keygen |
Families | Keygen |
Classification | Pua |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x422f8e |
Size Of Code | 0x2d000 |
Size Of Initialized Data | 0xd000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2016-07-25 14:35:47+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x2c96a | 0x2d000 | 0x1000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.63 |
.rdata | 0x42e000 | 0x774a | 0x8000 | 0x2e000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.95 |
.data | 0x436000 | 0x3438 | 0x2000 | 0x36000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.78 |
.rsrc | 0x43a000 | 0x290 | 0x1000 | 0x38000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.34 |
Imports (11)
»
COMCTL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_TrackMouseEvent | 0x0 | 0x42e008 | 0x34690 | 0x34690 | 0x6b |
(by ordinal) | 0x11 | 0x42e00c | 0x34694 | 0x34694 | - |
MSIMG32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GradientFill | 0x0 | 0x42e1dc | 0x34864 | 0x34864 | 0x2 |
KERNEL32.dll (85)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VirtualProtect | 0x0 | 0x42e084 | 0x3470c | 0x3470c | 0x379 |
GetCPInfo | 0x0 | 0x42e088 | 0x34710 | 0x34710 | 0xfc |
GetOEMCP | 0x0 | 0x42e08c | 0x34714 | 0x34714 | 0x18b |
GetACP | 0x0 | 0x42e090 | 0x34718 | 0x34718 | 0xf5 |
HeapSize | 0x0 | 0x42e094 | 0x3471c | 0x3471c | 0x212 |
SetUnhandledExceptionFilter | 0x0 | 0x42e098 | 0x34720 | 0x34720 | 0x33b |
WriteFile | 0x0 | 0x42e09c | 0x34724 | 0x34724 | 0x394 |
GetFileType | 0x0 | 0x42e0a0 | 0x34728 | 0x34728 | 0x15e |
GetStdHandle | 0x0 | 0x42e0a4 | 0x3472c | 0x3472c | 0x1b1 |
SetHandleCount | 0x0 | 0x42e0a8 | 0x34730 | 0x34730 | 0x317 |
IsBadWritePtr | 0x0 | 0x42e0ac | 0x34734 | 0x34734 | 0x22c |
VirtualAlloc | 0x0 | 0x42e0b0 | 0x34738 | 0x34738 | 0x373 |
VirtualFree | 0x0 | 0x42e0b4 | 0x3473c | 0x3473c | 0x376 |
HeapCreate | 0x0 | 0x42e0b8 | 0x34740 | 0x34740 | 0x208 |
HeapDestroy | 0x0 | 0x42e0bc | 0x34744 | 0x34744 | 0x20a |
ReadFile | 0x0 | 0x42e0c0 | 0x34748 | 0x34748 | 0x2a9 |
CloseHandle | 0x0 | 0x42e0c4 | 0x3474c | 0x3474c | 0x2e |
LCMapStringW | 0x0 | 0x42e0c8 | 0x34750 | 0x34750 | 0x23b |
LCMapStringA | 0x0 | 0x42e0cc | 0x34754 | 0x34754 | 0x23a |
SetFilePointer | 0x0 | 0x42e0d0 | 0x34758 | 0x34758 | 0x30e |
GetCurrentProcess | 0x0 | 0x42e0d4 | 0x3475c | 0x3475c | 0x13a |
TerminateProcess | 0x0 | 0x42e0d8 | 0x34760 | 0x34760 | 0x34f |
ExitProcess | 0x0 | 0x42e0dc | 0x34764 | 0x34764 | 0xaf |
GetVersionExA | 0x0 | 0x42e0e0 | 0x34768 | 0x34768 | 0x1df |
GetStartupInfoA | 0x0 | 0x42e0e4 | 0x3476c | 0x3476c | 0x1af |
GetModuleHandleA | 0x0 | 0x42e0e8 | 0x34770 | 0x34770 | 0x177 |
SetCurrentDirectoryA | 0x0 | 0x42e0ec | 0x34774 | 0x34774 | 0x2fd |
SetEnvironmentVariableA | 0x0 | 0x42e0f0 | 0x34778 | 0x34778 | 0x306 |
CreateDirectoryA | 0x0 | 0x42e0f4 | 0x3477c | 0x3477c | 0x45 |
GetLastError | 0x0 | 0x42e0f8 | 0x34780 | 0x34780 | 0x169 |
GetFullPathNameA | 0x0 | 0x42e0fc | 0x34784 | 0x34784 | 0x161 |
GetCurrentDirectoryA | 0x0 | 0x42e100 | 0x34788 | 0x34788 | 0x138 |
GetDriveTypeA | 0x0 | 0x42e104 | 0x3478c | 0x3478c | 0x14b |
HeapReAlloc | 0x0 | 0x42e108 | 0x34790 | 0x34790 | 0x210 |
RtlUnwind | 0x0 | 0x42e10c | 0x34794 | 0x34794 | 0x2ca |
RaiseException | 0x0 | 0x42e110 | 0x34798 | 0x34798 | 0x29b |
HeapFree | 0x0 | 0x42e114 | 0x3479c | 0x3479c | 0x20c |
HeapAlloc | 0x0 | 0x42e118 | 0x347a0 | 0x347a0 | 0x206 |
UnhandledExceptionFilter | 0x0 | 0x42e11c | 0x347a4 | 0x347a4 | 0x360 |
FreeEnvironmentStringsA | 0x0 | 0x42e120 | 0x347a8 | 0x347a8 | 0xed |
GetEnvironmentStrings | 0x0 | 0x42e124 | 0x347ac | 0x347ac | 0x14d |
FreeEnvironmentStringsW | 0x0 | 0x42e128 | 0x347b0 | 0x347b0 | 0xee |
GetEnvironmentStringsW | 0x0 | 0x42e12c | 0x347b4 | 0x347b4 | 0x14f |
SetStdHandle | 0x0 | 0x42e130 | 0x347b8 | 0x347b8 | 0x32a |
FlushFileBuffers | 0x0 | 0x42e134 | 0x347bc | 0x347bc | 0xe5 |
CreateFileA | 0x0 | 0x42e138 | 0x347c0 | 0x347c0 | 0x4d |
GetLocaleInfoA | 0x0 | 0x42e13c | 0x347c4 | 0x347c4 | 0x16c |
GetStringTypeA | 0x0 | 0x42e140 | 0x347c8 | 0x347c8 | 0x1b2 |
GetStringTypeW | 0x0 | 0x42e144 | 0x347cc | 0x347cc | 0x1b5 |
IsBadReadPtr | 0x0 | 0x42e148 | 0x347d0 | 0x347d0 | 0x229 |
IsBadCodePtr | 0x0 | 0x42e14c | 0x347d4 | 0x347d4 | 0x226 |
QueryPerformanceCounter | 0x0 | 0x42e150 | 0x347d8 | 0x347d8 | 0x297 |
GetCurrentThreadId | 0x0 | 0x42e154 | 0x347dc | 0x347dc | 0x13e |
GetCurrentProcessId | 0x0 | 0x42e158 | 0x347e0 | 0x347e0 | 0x13b |
GetSystemTimeAsFileTime | 0x0 | 0x42e15c | 0x347e4 | 0x347e4 | 0x1c0 |
InterlockedExchange | 0x0 | 0x42e160 | 0x347e8 | 0x347e8 | 0x21f |
GetLocalTime | 0x0 | 0x42e164 | 0x347ec | 0x347ec | 0x16b |
FindFirstFileA | 0x0 | 0x42e168 | 0x347f0 | 0x347f0 | 0xc9 |
FindNextFileA | 0x0 | 0x42e16c | 0x347f4 | 0x347f4 | 0xd3 |
FindClose | 0x0 | 0x42e170 | 0x347f8 | 0x347f8 | 0xc5 |
DeleteFileA | 0x0 | 0x42e174 | 0x347fc | 0x347fc | 0x7c |
GetShortPathNameA | 0x0 | 0x42e178 | 0x34800 | 0x34800 | 0x1ad |
GlobalLock | 0x0 | 0x42e17c | 0x34804 | 0x34804 | 0x1f9 |
GlobalUnlock | 0x0 | 0x42e180 | 0x34808 | 0x34808 | 0x200 |
MulDiv | 0x0 | 0x42e184 | 0x3480c | 0x3480c | 0x26a |
GlobalAlloc | 0x0 | 0x42e188 | 0x34810 | 0x34810 | 0x1ee |
GlobalFree | 0x0 | 0x42e18c | 0x34814 | 0x34814 | 0x1f5 |
GetCommandLineA | 0x0 | 0x42e190 | 0x34818 | 0x34818 | 0x108 |
GetSystemInfo | 0x0 | 0x42e194 | 0x3481c | 0x3481c | 0x1bb |
GlobalMemoryStatus | 0x0 | 0x42e198 | 0x34820 | 0x34820 | 0x1fa |
GetVersion | 0x0 | 0x42e19c | 0x34824 | 0x34824 | 0x1de |
GetComputerNameA | 0x0 | 0x42e1a0 | 0x34828 | 0x34828 | 0x10c |
GetWindowsDirectoryA | 0x0 | 0x42e1a4 | 0x3482c | 0x3482c | 0x1e9 |
GetSystemDirectoryA | 0x0 | 0x42e1a8 | 0x34830 | 0x34830 | 0x1b9 |
WinExec | 0x0 | 0x42e1ac | 0x34834 | 0x34834 | 0x388 |
FreeLibrary | 0x0 | 0x42e1b0 | 0x34838 | 0x34838 | 0xef |
WideCharToMultiByte | 0x0 | 0x42e1b4 | 0x3483c | 0x3483c | 0x387 |
MultiByteToWideChar | 0x0 | 0x42e1b8 | 0x34840 | 0x34840 | 0x26b |
LoadLibraryA | 0x0 | 0x42e1bc | 0x34844 | 0x34844 | 0x248 |
GetProcAddress | 0x0 | 0x42e1c0 | 0x34848 | 0x34848 | 0x198 |
Sleep | 0x0 | 0x42e1c4 | 0x3484c | 0x3484c | 0x347 |
GetTickCount | 0x0 | 0x42e1c8 | 0x34850 | 0x34850 | 0x1d5 |
GetModuleFileNameA | 0x0 | 0x42e1cc | 0x34854 | 0x34854 | 0x175 |
SetEndOfFile | 0x0 | 0x42e1d0 | 0x34858 | 0x34858 | 0x303 |
VirtualQuery | 0x0 | 0x42e1d4 | 0x3485c | 0x3485c | 0x37b |
USER32.dll (56)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PostQuitMessage | 0x0 | 0x42e244 | 0x348cc | 0x348cc | 0x203 |
LoadIconA | 0x0 | 0x42e248 | 0x348d0 | 0x348d0 | 0x1bd |
ReleaseDC | 0x0 | 0x42e24c | 0x348d4 | 0x348d4 | 0x22a |
InvalidateRect | 0x0 | 0x42e250 | 0x348d8 | 0x348d8 | 0x193 |
DefWindowProcA | 0x0 | 0x42e254 | 0x348dc | 0x348dc | 0x8e |
BeginPaint | 0x0 | 0x42e258 | 0x348e0 | 0x348e0 | 0xd |
LoadCursorA | 0x0 | 0x42e25c | 0x348e4 | 0x348e4 | 0x1b9 |
RegisterClassA | 0x0 | 0x42e260 | 0x348e8 | 0x348e8 | 0x216 |
UnregisterClassA | 0x0 | 0x42e264 | 0x348ec | 0x348ec | 0x2b3 |
AdjustWindowRectEx | 0x0 | 0x42e268 | 0x348f0 | 0x348f0 | 0x2 |
EndPaint | 0x0 | 0x42e26c | 0x348f4 | 0x348f4 | 0xc8 |
FillRect | 0x0 | 0x42e270 | 0x348f8 | 0x348f8 | 0xe2 |
TabbedTextOutA | 0x0 | 0x42e274 | 0x348fc | 0x348fc | 0x29b |
GetSysColor | 0x0 | 0x42e278 | 0x34900 | 0x34900 | 0x15a |
MoveWindow | 0x0 | 0x42e27c | 0x34904 | 0x34904 | 0x1eb |
GetActiveWindow | 0x0 | 0x42e280 | 0x34908 | 0x34908 | 0xeb |
GetClassLongA | 0x0 | 0x42e284 | 0x3490c | 0x3490c | 0xfa |
SetClassLongA | 0x0 | 0x42e288 | 0x34910 | 0x34910 | 0x247 |
SetWindowLongA | 0x0 | 0x42e28c | 0x34914 | 0x34914 | 0x280 |
IsWindowEnabled | 0x0 | 0x42e290 | 0x34918 | 0x34918 | 0x1ae |
EnableWindow | 0x0 | 0x42e294 | 0x3491c | 0x3491c | 0xc4 |
SetFocus | 0x0 | 0x42e298 | 0x34920 | 0x34920 | 0x256 |
GetFocus | 0x0 | 0x42e29c | 0x34924 | 0x34924 | 0x116 |
GetWindowLongA | 0x0 | 0x42e2a0 | 0x34928 | 0x34928 | 0x16e |
GetClientRect | 0x0 | 0x42e2a4 | 0x3492c | 0x3492c | 0xff |
InflateRect | 0x0 | 0x42e2a8 | 0x34930 | 0x34930 | 0x18a |
DrawFocusRect | 0x0 | 0x42e2ac | 0x34934 | 0x34934 | 0xb3 |
DrawTextA | 0x0 | 0x42e2b0 | 0x34938 | 0x34938 | 0xbc |
PostMessageA | 0x0 | 0x42e2b4 | 0x3493c | 0x3493c | 0x201 |
SetWindowTextA | 0x0 | 0x42e2b8 | 0x34940 | 0x34940 | 0x286 |
GetDlgItemTextA | 0x0 | 0x42e2bc | 0x34944 | 0x34944 | 0x113 |
GetDlgCtrlID | 0x0 | 0x42e2c0 | 0x34948 | 0x34948 | 0x110 |
IsDlgButtonChecked | 0x0 | 0x42e2c4 | 0x3494c | 0x3494c | 0x1a3 |
CallWindowProcA | 0x0 | 0x42e2c8 | 0x34950 | 0x34950 | 0x1b |
MsgWaitForMultipleObjects | 0x0 | 0x42e2cc | 0x34954 | 0x34954 | 0x1ec |
PeekMessageA | 0x0 | 0x42e2d0 | 0x34958 | 0x34958 | 0x1ff |
GetMessageA | 0x0 | 0x42e2d4 | 0x3495c | 0x3495c | 0x13a |
TranslateMessage | 0x0 | 0x42e2d8 | 0x34960 | 0x34960 | 0x2aa |
DispatchMessageA | 0x0 | 0x42e2dc | 0x34964 | 0x34964 | 0xa1 |
MapVirtualKeyA | 0x0 | 0x42e2e0 | 0x34968 | 0x34968 | 0x1d5 |
GetWindowRect | 0x0 | 0x42e2e4 | 0x3496c | 0x3496c | 0x174 |
SetActiveWindow | 0x0 | 0x42e2e8 | 0x34970 | 0x34970 | 0x243 |
SetWindowPos | 0x0 | 0x42e2ec | 0x34974 | 0x34974 | 0x283 |
GetAsyncKeyState | 0x0 | 0x42e2f0 | 0x34978 | 0x34978 | 0xf2 |
GetCursorPos | 0x0 | 0x42e2f4 | 0x3497c | 0x3497c | 0x10b |
SetCursorPos | 0x0 | 0x42e2f8 | 0x34980 | 0x34980 | 0x24f |
ShowCursor | 0x0 | 0x42e2fc | 0x34984 | 0x34984 | 0x28e |
MessageBoxA | 0x0 | 0x42e300 | 0x34988 | 0x34988 | 0x1de |
EnumDisplaySettingsA | 0x0 | 0x42e304 | 0x3498c | 0x3498c | 0xd3 |
ChangeDisplaySettingsA | 0x0 | 0x42e308 | 0x34990 | 0x34990 | 0x20 |
CreateWindowExA | 0x0 | 0x42e30c | 0x34994 | 0x34994 | 0x60 |
ShowWindow | 0x0 | 0x42e310 | 0x34998 | 0x34998 | 0x292 |
SendMessageA | 0x0 | 0x42e314 | 0x3499c | 0x3499c | 0x23b |
DestroyWindow | 0x0 | 0x42e318 | 0x349a0 | 0x349a0 | 0x99 |
GetDC | 0x0 | 0x42e31c | 0x349a4 | 0x349a4 | 0x10c |
GetSystemMetrics | 0x0 | 0x42e320 | 0x349a8 | 0x349a8 | 0x15d |
GDI32.dll (27)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateDIBSection | 0x0 | 0x42e014 | 0x3469c | 0x3469c | 0x32 |
CreateCompatibleDC | 0x0 | 0x42e018 | 0x346a0 | 0x346a0 | 0x2d |
Rectangle | 0x0 | 0x42e01c | 0x346a4 | 0x346a4 | 0x1f6 |
DeleteDC | 0x0 | 0x42e020 | 0x346a8 | 0x346a8 | 0x8c |
SetStretchBltMode | 0x0 | 0x42e024 | 0x346ac | 0x346ac | 0x238 |
StretchBlt | 0x0 | 0x42e028 | 0x346b0 | 0x346b0 | 0x249 |
Ellipse | 0x0 | 0x42e02c | 0x346b4 | 0x346b4 | 0x94 |
MoveToEx | 0x0 | 0x42e030 | 0x346b8 | 0x346b8 | 0x1d1 |
LineTo | 0x0 | 0x42e034 | 0x346bc | 0x346bc | 0x1cd |
SetPixel | 0x0 | 0x42e038 | 0x346c0 | 0x346c0 | 0x231 |
GetPixel | 0x0 | 0x42e03c | 0x346c4 | 0x346c4 | 0x19c |
GetTextExtentPoint32A | 0x0 | 0x42e040 | 0x346c8 | 0x346c8 | 0x1b4 |
SetDIBColorTable | 0x0 | 0x42e044 | 0x346cc | 0x346cc | 0x21e |
CreatePalette | 0x0 | 0x42e048 | 0x346d0 | 0x346d0 | 0x45 |
CreateSolidBrush | 0x0 | 0x42e04c | 0x346d4 | 0x346d4 | 0x50 |
CreatePen | 0x0 | 0x42e050 | 0x346d8 | 0x346d8 | 0x47 |
GetTextMetricsA | 0x0 | 0x42e054 | 0x346dc | 0x346dc | 0x1bc |
SelectPalette | 0x0 | 0x42e058 | 0x346e0 | 0x346e0 | 0x20f |
RealizePalette | 0x0 | 0x42e05c | 0x346e4 | 0x346e4 | 0x1f3 |
BitBlt | 0x0 | 0x42e060 | 0x346e8 | 0x346e8 | 0x12 |
SelectObject | 0x0 | 0x42e064 | 0x346ec | 0x346ec | 0x20e |
SetBkMode | 0x0 | 0x42e068 | 0x346f0 | 0x346f0 | 0x216 |
SetTextColor | 0x0 | 0x42e06c | 0x346f4 | 0x346f4 | 0x23c |
GetStockObject | 0x0 | 0x42e070 | 0x346f8 | 0x346f8 | 0x1a5 |
CreateFontIndirectA | 0x0 | 0x42e074 | 0x346fc | 0x346fc | 0x3a |
DeleteObject | 0x0 | 0x42e078 | 0x34700 | 0x34700 | 0x8f |
GetDeviceCaps | 0x0 | 0x42e07c | 0x34704 | 0x34704 | 0x16b |
comdlg32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetSaveFileNameA | 0x0 | 0x42e344 | 0x349cc | 0x349cc | 0xb |
ChooseColorA | 0x0 | 0x42e348 | 0x349d0 | 0x349d0 | 0x0 |
GetOpenFileNameA | 0x0 | 0x42e34c | 0x349d4 | 0x349d4 | 0x9 |
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetUserNameA | 0x0 | 0x42e000 | 0x34688 | 0x34688 | 0x123 |
SHELL32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteExA | 0x0 | 0x42e234 | 0x348bc | 0x348bc | 0x108 |
SHGetSpecialFolderPathA | 0x0 | 0x42e238 | 0x348c0 | 0x348c0 | 0xc3 |
ShellExecuteA | 0x0 | 0x42e23c | 0x348c4 | 0x348c4 | 0x106 |
ole32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OleInitialize | 0x0 | 0x42e354 | 0x349dc | 0x349dc | 0xed |
CoCreateInstance | 0x0 | 0x42e358 | 0x349e0 | 0x349e0 | 0x10 |
IIDFromString | 0x0 | 0x42e35c | 0x349e4 | 0x349e4 | 0xc5 |
CoUninitialize | 0x0 | 0x42e360 | 0x349e8 | 0x349e8 | 0x68 |
CreateStreamOnHGlobal | 0x0 | 0x42e364 | 0x349ec | 0x349ec | 0x82 |
OleUninitialize | 0x0 | 0x42e368 | 0x349f0 | 0x349f0 | 0x104 |
CoInitializeEx | 0x0 | 0x42e36c | 0x349f4 | 0x349f4 | 0x3b |
CLSIDFromProgID | 0x0 | 0x42e370 | 0x349f8 | 0x349f8 | 0x6 |
OLEAUT32.dll (19)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SafeArrayGetElement | 0x19 | 0x42e1e4 | 0x3486c | 0x3486c | - |
OleLoadPicture | 0x1a2 | 0x42e1e8 | 0x34870 | 0x34870 | - |
SafeArrayPutElement | 0x1a | 0x42e1ec | 0x34874 | 0x34874 | - |
SafeArrayCopy | 0x1b | 0x42e1f0 | 0x34878 | 0x34878 | - |
SafeArrayGetVartype | 0x4d | 0x42e1f4 | 0x3487c | 0x3487c | - |
SafeArrayGetLBound | 0x14 | 0x42e1f8 | 0x34880 | 0x34880 | - |
SafeArrayGetUBound | 0x13 | 0x42e1fc | 0x34884 | 0x34884 | - |
SysAllocString | 0x2 | 0x42e200 | 0x34888 | 0x34888 | - |
VariantCopy | 0xa | 0x42e204 | 0x3488c | 0x3488c | - |
VariantCopyInd | 0xb | 0x42e208 | 0x34890 | 0x34890 | - |
VariantChangeType | 0xc | 0x42e20c | 0x34894 | 0x34894 | - |
SysAllocStringByteLen | 0x96 | 0x42e210 | 0x34898 | 0x34898 | - |
SysFreeString | 0x6 | 0x42e214 | 0x3489c | 0x3489c | - |
SafeArrayCreate | 0xf | 0x42e218 | 0x348a0 | 0x348a0 | - |
SafeArrayUnaccessData | 0x18 | 0x42e21c | 0x348a4 | 0x348a4 | - |
VariantClear | 0x9 | 0x42e220 | 0x348a8 | 0x348a8 | - |
VariantInit | 0x8 | 0x42e224 | 0x348ac | 0x348ac | - |
SafeArrayAccessData | 0x17 | 0x42e228 | 0x348b0 | 0x348b0 | - |
SafeArrayGetDim | 0x11 | 0x42e22c | 0x348b4 | 0x348b4 | - |
WINMM.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
sndPlaySoundA | 0x0 | 0x42e328 | 0x349b0 | 0x349b0 | 0x9c |
mciSendStringA | 0x0 | 0x42e32c | 0x349b4 | 0x349b4 | 0x40 |
timeEndPeriod | 0x0 | 0x42e330 | 0x349b8 | 0x349b8 | 0xa0 |
timeGetDevCaps | 0x0 | 0x42e334 | 0x349bc | 0x349bc | 0xa1 |
timeBeginPeriod | 0x0 | 0x42e338 | 0x349c0 | 0x349c0 | 0x9f |
timeGetTime | 0x0 | 0x42e33c | 0x349c4 | 0x349c4 | 0xa3 |
Memory Dumps (18)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
keygen.exe | 4 | 0x00400000 | 0x0043AFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
bassmod.dll | 4 | 0x10000000 | 0x10012FFF | Content Changed | - | 32-bit | 0x10012043 |
![]() |
![]() |
...
|
bassmod.dll | 4 | 0x10000000 | 0x10012FFF | Content Changed | - | 32-bit | 0x1000D8F5 |
![]() |
![]() |
...
|
bassmod.dll | 4 | 0x10000000 | 0x10012FFF | Content Changed | - | 32-bit | 0x1000CC7A |
![]() |
![]() |
...
|
bassmod.dll | 4 | 0x10000000 | 0x10012FFF | Content Changed | - | 32-bit | 0x10001000 |
![]() |
![]() |
...
|
buffer | 4 | 0x00270000 | 0x002A8FFF | First Execution | - | 32-bit | 0x00270000 |
![]() |
![]() |
...
|
bassmod.dll | 4 | 0x10000000 | 0x10012FFF | Content Changed | - | 32-bit | 0x10009B2F |
![]() |
![]() |
...
|
bassmod.dll | 4 | 0x10000000 | 0x10012FFF | Content Changed | - | 32-bit | 0x1000A06D |
![]() |
![]() |
...
|
bassmod.dll | 4 | 0x10000000 | 0x10012FFF | Content Changed | - | 32-bit | 0x100022D2 |
![]() |
![]() |
...
|
bassmod.dll | 4 | 0x10000000 | 0x10012FFF | Content Changed | - | 32-bit | 0x10006DC0 |
![]() |
![]() |
...
|
bassmod.dll | 4 | 0x10000000 | 0x10012FFF | Content Changed | - | 32-bit | 0x100051A6, 0x100040CC, ... |
![]() |
![]() |
...
|
bassmod.dll | 4 | 0x10000000 | 0x10012FFF | Content Changed | - | 32-bit | 0x1001204D |
![]() |
![]() |
...
|
bassmod.dll | 4 | 0x10000000 | 0x10012FFF | Content Changed | - | 32-bit | 0x1000CB70 |
![]() |
![]() |
...
|
bassmod.dll | 4 | 0x10000000 | 0x10012FFF | Content Changed | - | 32-bit | 0x10001775 |
![]() |
![]() |
...
|
bassmod.dll | 4 | 0x10000000 | 0x10012FFF | Content Changed | - | 32-bit | 0x10008A6F |
![]() |
![]() |
...
|
bassmod.dll | 4 | 0x10000000 | 0x10012FFF | Content Changed | - | 32-bit | 0x10006980 |
![]() |
![]() |
...
|
bassmod.dll | 4 | 0x10000000 | 0x10012FFF | Content Changed | - | 32-bit | 0x10002355 |
![]() |
![]() |
...
|
bassmod.dll | 4 | 0x10000000 | 0x10012FFF | Content Changed | - | 32-bit | 0x10005A4E, 0x1000493A, ... |
![]() |
![]() |
...
|
C:\Users\5P5NRG~1\AppData\Local\Temp\AE785005.buran | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2011-05-31 22:44 (UTC+2) |
Last Seen | 2019-03-29 06:26 (UTC+1) |
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\-0WGp.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\-0WGp.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\7ipS.ods | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9ElWv1el4-AEdsTzk.wav | Modified File | Audio |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9ElWv1el4-AEdsTzk.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Cj5z8Sw9v7O.ods | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\c_qKiZxj_.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Et7K.png | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Et7K.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Fe3xoXvZ.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fjTg.doc | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fjTg.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\I4Iad0fPEqg6-9Mh.ppt | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\JbIp2jE99EF1.m4a | Modified File | Audio |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\JbIp2jE99EF1.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\LBZUp1SXtI.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NoWc.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\vf_ByTU VEqfO2gyl.avi | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\vf_ByTU VEqfO2gyl.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\VU7dAF.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\xiUKv.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\xiUKv.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZpFl53FhUZWvTmzGO.mkv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZpFl53FhUZWvTmzGO.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\_vjCvn7YEhbszd.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\_vjCvn7YEhbszd.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\cSnf.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ctSfaOF2nu_3Iug.avi | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ctSfaOF2nu_3Iug.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\GM24uvlDX4d23gnf.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\GM24uvlDX4d23gnf.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\0S0ya1lf.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\3aNP40yASecb0.wav | Modified File | Audio |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\cartridges\as90.xsl | Modified File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\cartridges\informix.xsl | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\D kR5epoSNcxyM_AME73.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\msjet.xsl.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\cartridges\sql2000.xsl | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\sql2000.xsl.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\NJ jir0c hBFN8.pdf | Modified File |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\NJ jir0c hBFN8.pdf | Modified File |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\cartridges\sql70.xsl | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\sql70.xsl.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\o4XOe7.xls | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\o4XOe7.xls | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\cartridges\sql90.xsl | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\Sybase.xsl.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\_onGBYzZ_yVXka.bmp | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\resources\1033\msmdsrv.rll | Modified File | Binary |
Unknown
|
...
|
»
PE Information
»
Image Base | 0x46410000 |
Size Of Initialized Data | 0xa1200 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 2009-03-29 18:20:10+00:00 |
Version Information (10)
»
CompanyName | Microsoft Corporation |
FileDescription | Microsoft SQL Server Analysis Services |
FileVersion | 2007.0100.2531.00 |
InternalName | Resource strings |
LegalCopyright | Microsoft Corp. All rights reserved. |
LegalTrademarks | Microsoft SQL Server is a registered trademark of Microsoft Corporation. |
OriginalFilename | msmdsrv.rll |
Platform | NT |
ProductName | Microsoft SQL Server Analysis Services |
ProductVersion | 10.0.2531.0 |
Sections (1)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.rsrc | 0x46411000 | 0xa10a8 | 0xa1200 | 0x200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.97 |
Digital Signatures (2)
»
Certificate: Microsoft Corporation
»
Issued by | Microsoft Corporation |
Parent Certificate | Microsoft Code Signing PCA |
Country Name | US |
Valid From | 2008-10-22 21:24:55+00:00 |
Valid Until | 2010-01-22 21:34:55+00:00 |
Algorithm | sha1_rsa |
Serial Number | 61 06 27 81 00 00 00 00 00 08 |
Thumbprint | 9E 95 C6 25 D8 1B 2B A9 C7 2F D7 02 75 C3 69 96 13 AF 61 E3 |
Certificate: Microsoft Code Signing PCA
»
Issued by | Microsoft Code Signing PCA |
Country Name | US |
Valid From | 2007-08-22 22:31:02+00:00 |
Valid Until | 2012-08-25 07:00:00+00:00 |
Algorithm | sha1_rsa |
Serial Number | 2E AB 11 DC 50 FF 5C 9D CB C0 |
Thumbprint | 30 36 E3 B2 5B 88 A5 5B 86 FC 90 E6 E9 EA AD 50 81 44 51 66 |
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\V7c X\- t6YX67FJjNzE.jpg | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\resources\1033\msolui100.rll | Modified File | Binary |
Unknown
|
...
|
»
PE Information
»
Image Base | 0x429f0000 |
Size Of Initialized Data | 0x1400 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 2008-07-09 21:50:46+00:00 |
Version Information (10)
»
CompanyName | Microsoft Corporation |
FileDescription | Microsoft OLE DB Provider for Analysis Services Connection Dialog 10.0 Strings |
FileVersion | 2007.0100.1600.022 |
InternalName | OLE DB Provider Connection Dialog Resource Strings |
LegalCopyright | Microsoft Corp. All rights reserved. |
LegalTrademarks | Microsoft SQL Server is a registered trademark of Microsoft Corporation. |
OriginalFilename | msolui100.rll |
Platform | NT |
ProductName | Microsoft SQL Server Analysis Services |
ProductVersion | 10.0.1600.22 |
Sections (1)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.rsrc | 0x429f1000 | 0x13c0 | 0x1400 | 0x200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.43 |
Digital Signatures (3)
»
Certificate: Microsoft Corporation
»
Issued by | Microsoft Corporation |
Parent Certificate | Microsoft Code Signing PCA |
Country Name | US |
Valid From | 2007-08-23 00:23:13+00:00 |
Valid Until | 2009-02-23 00:33:13+00:00 |
Algorithm | sha1_rsa |
Serial Number | 61 0F 78 4D 00 00 00 00 00 03 |
Thumbprint | D5 7F AC 60 F1 A8 D3 48 77 AE B3 50 E8 3F 46 F6 EF C9 E5 F1 |
Certificate: Microsoft Code Signing PCA
»
Issued by | Microsoft Code Signing PCA |
Parent Certificate | Microsoft Root Authority |
Country Name | US |
Valid From | 2007-08-22 22:31:02+00:00 |
Valid Until | 2012-08-25 07:00:00+00:00 |
Algorithm | sha1_rsa |
Serial Number | 2E AB 11 DC 50 FF 5C 9D CB C0 |
Thumbprint | 30 36 E3 B2 5B 88 A5 5B 86 FC 90 E6 E9 EA AD 50 81 44 51 66 |
Certificate: Microsoft Root Authority
»
Issued by | Microsoft Root Authority |
Country Name | - |
Valid From | 1997-01-10 07:00:00+00:00 |
Valid Until | 2020-12-31 07:00:00+00:00 |
Algorithm | md5_rsa |
Serial Number | C1 00 8B 3C 3C 88 11 D1 3E F6 63 EC DF 40 |
Thumbprint | A4 34 89 15 9A 52 0F 0D 93 D0 32 CC AF 37 E7 FE 20 A8 B4 19 |
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\V7c X\D3fZ-WqBjG.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\V7c X\d3sOR gctCdkgmAa.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\V7c X\d3sOR gctCdkgmAa.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\V7c X\msHrJviis.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00037_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\V7c X\VeyN3H.png | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00038_.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00038_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\V7c X\ZHkOWx.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00040_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00057_.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00057_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00090_.gif | Modified File | Image |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00092_.gif | Modified File | Image |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00103_.gif | Modified File | Image |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00120_.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00120_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00126_.gif | Modified File | Image |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00129_.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00139_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00142_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00154_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00157_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00158_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00160_.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00160_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00161_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00164_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00165_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00167_.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00167_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00170_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00172_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00175_.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00175_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00176_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN00010_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an00015_.wmf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN00790_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an00853_.wmf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN00853_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an00932_.wmf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN00932_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an01039_.wmf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01039_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01044_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01060_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an01084_.wmf | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an01173_.wmf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01184_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an01216_.wmf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01216_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01251_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01545_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN02122_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an02724_.wmf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN03500_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an04108_.wmf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04108_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an04117_.wmf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04117_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04134_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04195_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04196_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an04235_.wmf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04235_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04269_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04332_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an04355_.wmf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04369_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04384_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04385_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\bd00141_.wmf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD00141_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD06102_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD07761_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD08758_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD08808_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD19563_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD19582_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD19695_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD19988_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BL00008_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BL00045_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BL00098_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BL00105_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BL00122_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BL00194_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BL00195_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BL00234_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\history\history.ie5\index.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp\BASSMOD.dll | Dropped File | Binary |
Unknown
|
...
|
»
PE Information
»
Image Base | 0x10000000 |
Entry Point | 0x10012043 |
Size Of Code | 0x11688 |
Size Of Initialized Data | 0x11688 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2004-06-20 12:54:13+00:00 |
Packer | Petite v1.4 |
Sections (2)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
- | 0x10001000 | 0x11000 | 0x7c04 | 0xa00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.98 |
- | 0x10012000 | 0x688 | 0x800 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.01 |
Imports (4)
»
KERNEL32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitProcess | 0x0 | 0x10012234 | 0x12234 | 0x434 | 0x0 |
LoadLibraryA | 0x0 | 0x10012238 | 0x12238 | 0x438 | 0x0 |
GetProcAddress | 0x0 | 0x1001223c | 0x1223c | 0x43c | 0x0 |
VirtualProtect | 0x0 | 0x10012240 | 0x12240 | 0x440 | 0x0 |
GlobalAlloc | 0x0 | 0x10012244 | 0x12244 | 0x444 | 0x0 |
GlobalFree | 0x0 | 0x10012248 | 0x12248 | 0x448 | 0x0 |
WINMM.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
timeGetTime | 0x0 | 0x10012250 | 0x12250 | 0x450 | 0x0 |
MSVCRT.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x1 | 0x10012258 | 0x12258 | 0x458 | - |
user32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | 0x0 | 0x10012228 | 0x12228 | 0x428 | 0x0 |
wsprintfA | 0x0 | 0x1001222c | 0x1222c | 0x42c | 0x0 |
Exports (27)
»
Api name | EAT Address | Ordinal |
---|---|---|
BASSMOD_ErrorGetCode | 0xcb3c | 0x1 |
BASSMOD_Free | 0x8baa | 0x2 |
BASSMOD_GetCPU | 0x1086 | 0x3 |
BASSMOD_GetDeviceDescription | 0xcae1 | 0x4 |
BASSMOD_GetVersion | 0xcb31 | 0x5 |
BASSMOD_GetVolume | 0x10f8 | 0x6 |
BASSMOD_Init | 0x1267 | 0x7 |
BASSMOD_MusicDecode | 0xca58 | 0x8 |
BASSMOD_MusicFree | 0xc34e | 0x9 |
BASSMOD_MusicGetLength | 0xc392 | 0xa |
BASSMOD_MusicGetName | 0xc374 | 0xb |
BASSMOD_MusicGetPosition | 0xc797 | 0xc |
BASSMOD_MusicGetVolume | 0xc73f | 0xd |
BASSMOD_MusicIsActive | 0x1223 | 0xe |
BASSMOD_MusicLoad | 0x8f34 | 0xf |
BASSMOD_MusicPause | 0x11d8 | 0x10 |
BASSMOD_MusicPlay | 0xc3dd | 0x11 |
BASSMOD_MusicPlayEx | 0xc508 | 0x12 |
BASSMOD_MusicRemoveSync | 0x8ec5 | 0x13 |
BASSMOD_MusicSetAmplify | 0xc5f9 | 0x14 |
BASSMOD_MusicSetPanSep | 0xc63d | 0x15 |
BASSMOD_MusicSetPosition | 0xc84f | 0x16 |
BASSMOD_MusicSetPositionScaler | 0xc681 | 0x17 |
BASSMOD_MusicSetSync | 0x8d65 | 0x18 |
BASSMOD_MusicSetVolume | 0xc6d3 | 0x19 |
BASSMOD_MusicStop | 0x1144 | 0x1a |
BASSMOD_SetVolume | 0x1094 | 0x1b |
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1rk85P.mp4 | Modified File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1rk85P.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\7ipS.ods | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\b.exe | Modified File | Stream |
Not Queried
|
...
|
»
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
b.exe | 1 | 0x01320000 | 0x015D4FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
b.exe | 1 | 0x01320000 | 0x015D4FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Cj5z8Sw9v7O.ods | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\c_qKiZxj_.avi | Modified File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\dY0yl5mK9vD.bmp | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\dY0yl5mK9vD.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ejaysz9GSkSB.png | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ejaysz9GSkSB.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Fe3xoXvZ.m4a | Modified File | Audio |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\H4aSLRpC.jpg | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\H4aSLRpC.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\I4Iad0fPEqg6-9Mh.ppt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\KfAMOG30Jk_h.mkv | Modified File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\KfAMOG30Jk_h.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\LBZUp1SXtI.mp4 | Modified File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NoWc.png | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\rTuCnu4wqEdHxm7AJY.xlsx | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\rTuCnu4wqEdHxm7AJY.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Vo6kTwdLO.bmp | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Vo6kTwdLO.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\VU7dAF.avi | Modified File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\VYZTfBZ-0.m4a | Modified File | Audio |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\VYZTfBZ-0.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\-yeC580iAmxs.jpg | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\-yeC580iAmxs.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\cSnf.docx | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\XeKZ1lckwCS6l.mp4 | Modified File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\XeKZ1lckwCS6l.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\cartridges\as80.xsl | Modified File | Text |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\as80.xsl.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\0S0ya1lf.avi | Modified File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\3aNP40yASecb0.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\as90.xsl.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\80 K90vK.mkv | Modified File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\80 K90vK.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\Informix.xsl.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\D kR5epoSNcxyM_AME73.wav | Modified File | Audio |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\cartridges\msjet.xsl | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\E6fI.xls | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\E6fI.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\sql90.xsl.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\RjQLaKs8b3A4.m4a | Modified File | Audio |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\RjQLaKs8b3A4.m4a | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\cartridges\sybase.xsl | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\_onGBYzZ_yVXka.bmp | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Resources\1033\msmdsrv.rll.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\V7c X\- t6YX67FJjNzE.jpg | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Resources\1033\msolui100.rll.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\V7c X\D3fZ-WqBjG.flv | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00004_.gif | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00004_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\V7c X\J1J_05qqT.mkv | Modified File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\V7c X\J1J_05qqT.mkv | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00011_.gif | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00011_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\V7c X\msHrJviis.png | Modified File | Image |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00021_.gif | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00021_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\V7c X\UMuPxsNP6UswBKnIxz.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\V7c X\UMuPxsNP6UswBKnIxz.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00037_.gif | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\V7c X\VeyN3H.png | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wC JYi\ey6ais\V7c X\ZHkOWx.gif | Modified File | Image |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00040_.gif | Modified File | Image |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00052_.gif | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00052_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00090_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00092_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00103_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00126_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00129_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00130_.gif | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00130_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00135_.gif | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00135_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00139_.gif | Modified File | Image |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00142_.gif | Modified File | Image |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00154_.gif | Modified File | Image |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00157_.gif | Modified File | Image |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00158_.gif | Modified File | Image |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00161_.gif | Modified File | Image |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00163_.gif | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00163_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00164_.gif | Modified File | Image |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00165_.gif | Modified File | Image |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00169_.gif | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00169_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00170_.gif | Modified File | Image |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00171_.gif | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00171_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00172_.gif | Modified File | Image |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00174_.gif | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00174_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\ag00176_.gif | Modified File | Image |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an00010_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN00015_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an00790_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an00914_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN00914_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an00965_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN00965_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an01044_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an01060_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01084_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01173_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an01174_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01174_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an01184_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an01218_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN01218_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an01251_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an01545_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an02122_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an02559_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN02559_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN02724_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an03500_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an04134_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an04174_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04174_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an04191_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04191_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an04195_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an04196_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an04206_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04206_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an04225_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04225_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an04267_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04267_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an04269_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an04323_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04323_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an04326_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04326_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an04332_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AN04355_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft office\clipart\pub60cor\an04369_.wmf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BABY_01.MID.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Audio |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD00116_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD00146_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD00155_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD00160_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD00173_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD05119_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD06200_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD07804_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD07831_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD08773_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD08868_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD09031_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD09194_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD09662_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD09664_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD10890_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD10972_.GIF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD19827_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD19828_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD19986_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD20013_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BL00012_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BL00130_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BL00148_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BL00152_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BL00242_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BL00247_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BL00248_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BL00252_.WMF.-20D3E156-A287-60BB-BBEE-4579C665442A | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\index.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp\bgm.xm | Dropped File | Audio |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\!!! YOUR FILES ARE ENCRYPTED !!!.TXT | Dropped File | Text |
Not Queried
|
...
|
»