Malicious
Classifications
Spyware
Threat Names
CryptOne Mal/HTMLGen-A
Dynamic Analysis Report
Created on 2022-03-23T03:44:00
b123.exe
Windows Exe (x86-32)
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "16 seconds" to "10 seconds" to reveal dormant functionality.
Remarks
(0x0200004A): 3 dumps were skipped because they exceeded the maximum dump size of 7 MB. The largest one was 100 MB.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
File Reputation Information
»
Verdict |
malicious
|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x42aa70 |
Size Of Code | 0x2c800 |
Size Of Initialized Data | 0xb600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 1984-09-16 09:55:41+00:00 |
Version Information (9)
»
CompanyName | Oracle Corporation |
FileDescription | Java ipdate Registration |
FileVersion | 2.8.121.13 |
Full Version | 2.8.121.13 |
InternalName | Java ipdate Registration |
LegalCopyright | Copyright © 2016 |
OriginalFilename | jaureg.exe |
ProductName | Java Platform SE Auto ipdater |
ProductVersion | 2.8.121.13 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x2c70e | 0x2c800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.52 |
.rdata | 0x42e000 | 0x3e8 | 0x400 | 0x2cc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.0 |
.data | 0x42f000 | 0x32fc | 0x3400 | 0x2d000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.64 |
.rsrc | 0x433000 | 0x8ce8 | 0x7e00 | 0x30400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.01 |
Imports (3)
»
KERNEL32.dll (177)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryW | - | 0x42f8d4 | 0x2f120 | 0x2d120 | 0x2f4 |
GetModuleHandleW | - | 0x42f8d8 | 0x2f124 | 0x2d124 | 0x1f9 |
FreeLibrary | - | 0x42f8dc | 0x2f128 | 0x2d128 | 0x14c |
GetProcAddress | - | 0x42f8e0 | 0x2f12c | 0x2d12c | 0x220 |
GetTickCount | - | 0x42f8e4 | 0x2f130 | 0x2d130 | 0x266 |
CreateEventW | - | 0x42f8e8 | 0x2f134 | 0x2d134 | 0x75 |
GetCurrentProcessId | - | 0x42f8ec | 0x2f138 | 0x2d138 | 0x1aa |
CloseHandle | - | 0x42f8f0 | 0x2f13c | 0x2d13c | 0x43 |
WaitForSingleObject | - | 0x42f8f4 | 0x2f140 | 0x2d140 | 0x464 |
GetThreadLocale | - | 0x42f8f8 | 0x2f144 | 0x2d144 | 0x25f |
CreateDirectoryW | - | 0x42f8fc | 0x2f148 | 0x2d148 | 0x71 |
GetSystemWindowsDirectoryW | - | 0x42f900 | 0x2f14c | 0x2d14c | 0x252 |
FindClose | - | 0x42f904 | 0x2f150 | 0x2d150 | 0x119 |
FindFirstFileW | - | 0x42f908 | 0x2f154 | 0x2d154 | 0x124 |
OpenProcess | - | 0x42f90c | 0x2f158 | 0x2d158 | 0x333 |
Process32NextW | - | 0x42f910 | 0x2f15c | 0x2d15c | 0x346 |
Process32FirstW | - | 0x42f914 | 0x2f160 | 0x2d160 | 0x344 |
CreateToolhelp32Snapshot | - | 0x42f918 | 0x2f164 | 0x2d164 | 0xac |
GetModuleFileNameW | - | 0x42f91c | 0x2f168 | 0x2d168 | 0x1f5 |
InterlockedIncrement | - | 0x42f920 | 0x2f16c | 0x2d16c | 0x2c0 |
GlobalMemoryStatusEx | - | 0x42f924 | 0x2f170 | 0x2d170 | 0x292 |
GetVersionExW | - | 0x42f928 | 0x2f174 | 0x2d174 | 0x276 |
VerifyVersionInfoW | - | 0x42f92c | 0x2f178 | 0x2d178 | 0x453 |
VerSetConditionMask | - | 0x42f930 | 0x2f17c | 0x2d17c | 0x44f |
GetCurrentProcess | - | 0x42f934 | 0x2f180 | 0x2d180 | 0x1a9 |
GetNativeSystemInfo | - | 0x42f938 | 0x2f184 | 0x2d184 | 0x206 |
GetLastError | - | 0x42f93c | 0x2f188 | 0x2d188 | 0x1e6 |
CreateFileW | - | 0x42f940 | 0x2f18c | 0x2d18c | 0x7f |
GetSystemDirectoryW | - | 0x42f944 | 0x2f190 | 0x2d190 | 0x246 |
CreateProcessW | - | 0x42f948 | 0x2f194 | 0x2d194 | 0x97 |
lstrlenW | - | 0x42f94c | 0x2f198 | 0x2d198 | 0x4b6 |
GetEnvironmentVariableW | - | 0x42f950 | 0x2f19c | 0x2d19c | 0x1c3 |
GetWindowsDirectoryW | - | 0x42f954 | 0x2f1a0 | 0x2d1a0 | 0x281 |
LocalFree | - | 0x42f958 | 0x2f1a4 | 0x2d1a4 | 0x2fd |
LocalAlloc | - | 0x42f95c | 0x2f1a8 | 0x2d1a8 | 0x2f9 |
FormatMessageW | - | 0x42f960 | 0x2f1ac | 0x2d1ac | 0x148 |
GetLongPathNameW | - | 0x42f964 | 0x2f1b0 | 0x2d1b0 | 0x1f2 |
GetShortPathNameW | - | 0x42f968 | 0x2f1b4 | 0x2d1b4 | 0x238 |
InterlockedDecrement | - | 0x42f96c | 0x2f1b8 | 0x2d1b8 | 0x2bc |
GetTempPathW | - | 0x42f970 | 0x2f1bc | 0x2d1bc | 0x25b |
GetLocalTime | - | 0x42f974 | 0x2f1c0 | 0x2d1c0 | 0x1e7 |
OutputDebugStringW | - | 0x42f978 | 0x2f1c4 | 0x2d1c4 | 0x33b |
GetCurrentThreadId | - | 0x42f97c | 0x2f1c8 | 0x2d1c8 | 0x1ad |
GetModuleHandleExW | - | 0x42f980 | 0x2f1cc | 0x2d1cc | 0x1f8 |
GetExitCodeProcess | - | 0x42f984 | 0x2f1d0 | 0x2d1d0 | 0x1c5 |
GetFileAttributesW | - | 0x42f988 | 0x2f1d4 | 0x2d1d4 | 0x1ce |
lstrlenA | - | 0x42f98c | 0x2f1d8 | 0x2d1d8 | 0x4b5 |
WriteConsoleW | - | 0x42f990 | 0x2f1dc | 0x2d1dc | 0x48c |
FlushFileBuffers | - | 0x42f994 | 0x2f1e0 | 0x2d1e0 | 0x141 |
HeapSize | - | 0x42f998 | 0x2f1e4 | 0x2d1e4 | 0x2a6 |
CompareStringW | - | 0x42f99c | 0x2f1e8 | 0x2d1e8 | 0x55 |
LCMapStringW | - | 0x42f9a0 | 0x2f1ec | 0x2d1ec | 0x2e3 |
QueryPerformanceCounter | - | 0x42f9a4 | 0x2f1f0 | 0x2d1f0 | 0x354 |
ReadFile | - | 0x42f9a8 | 0x2f1f4 | 0x2d1f4 | 0x368 |
GetProcessHeap | - | 0x42f9ac | 0x2f1f8 | 0x2d1f8 | 0x223 |
SetEndOfFile | - | 0x42f9b0 | 0x2f1fc | 0x2d1fc | 0x3cd |
SetFilePointer | - | 0x42f9b4 | 0x2f200 | 0x2d200 | 0x3df |
GetConsoleMode | - | 0x42f9b8 | 0x2f204 | 0x2d204 | 0x195 |
GetConsoleCP | - | 0x42f9bc | 0x2f208 | 0x2d208 | 0x183 |
SetStdHandle | - | 0x42f9c0 | 0x2f20c | 0x2d20c | 0x3fc |
SetHandleCount | - | 0x42f9c4 | 0x2f210 | 0x2d210 | 0x3e8 |
Sleep | - | 0x42f9c8 | 0x2f214 | 0x2d214 | 0x421 |
SetEnvironmentVariableW | - | 0x42f9cc | 0x2f218 | 0x2d218 | 0x3d1 |
SetEnvironmentVariableA | - | 0x42f9d0 | 0x2f21c | 0x2d21c | 0x3d0 |
DeleteCriticalSection | - | 0x42f9d4 | 0x2f220 | 0x2d220 | 0xbe |
InitializeCriticalSectionAndSpinCount | - | 0x42f9d8 | 0x2f224 | 0x2d224 | 0x2b5 |
GetEnvironmentStringsW | - | 0x42f9dc | 0x2f228 | 0x2d228 | 0x1c1 |
FreeEnvironmentStringsW | - | 0x42f9e0 | 0x2f22c | 0x2d22c | 0x14b |
GetStdHandle | - | 0x42f9e4 | 0x2f230 | 0x2d230 | 0x23b |
WriteFile | - | 0x42f9e8 | 0x2f234 | 0x2d234 | 0x48d |
HeapCreate | - | 0x42f9ec | 0x2f238 | 0x2d238 | 0x29f |
IsProcessorFeaturePresent | - | 0x42f9f0 | 0x2f23c | 0x2d23c | 0x2d5 |
InterlockedExchange | - | 0x42f9f4 | 0x2f240 | 0x2d240 | 0x2bd |
LoadLibraryA | - | 0x42f9f8 | 0x2f244 | 0x2d244 | 0x2f1 |
RaiseException | - | 0x42f9fc | 0x2f248 | 0x2d248 | 0x35a |
FileTimeToSystemTime | - | 0x42fa00 | 0x2f24c | 0x2d24c | 0x110 |
FileTimeToLocalFileTime | - | 0x42fa04 | 0x2f250 | 0x2d250 | 0x10f |
GetDriveTypeW | - | 0x42fa08 | 0x2f254 | 0x2d254 | 0x1bb |
FindFirstFileExW | - | 0x42fa0c | 0x2f258 | 0x2d258 | 0x11f |
WideCharToMultiByte | - | 0x42fa10 | 0x2f25c | 0x2d25c | 0x47a |
GetSystemTimeAsFileTime | - | 0x42fa14 | 0x2f260 | 0x2d260 | 0x24f |
HeapFree | - | 0x42fa18 | 0x2f264 | 0x2d264 | 0x2a1 |
HeapReAlloc | - | 0x42fa1c | 0x2f268 | 0x2d268 | 0x2a4 |
HeapAlloc | - | 0x42fa20 | 0x2f26c | 0x2d26c | 0x29d |
GetStringTypeW | - | 0x42fa24 | 0x2f270 | 0x2d270 | 0x240 |
ExitProcess | - | 0x42fa28 | 0x2f274 | 0x2d274 | 0x104 |
DecodePointer | - | 0x42fa2c | 0x2f278 | 0x2d278 | 0xb7 |
RtlUnwind | - | 0x42fa30 | 0x2f27c | 0x2d27c | 0x392 |
EnterCriticalSection | - | 0x42fa34 | 0x2f280 | 0x2d280 | 0xd9 |
LeaveCriticalSection | - | 0x42fa38 | 0x2f284 | 0x2d284 | 0x2ef |
DeleteFileW | - | 0x42fa3c | 0x2f288 | 0x2d288 | 0xc3 |
GetFileType | - | 0x42fa40 | 0x2f28c | 0x2d28c | 0x1d7 |
MultiByteToWideChar | - | 0x42fa44 | 0x2f290 | 0x2d290 | 0x31a |
GetTimeFormatW | - | 0x42fa48 | 0x2f294 | 0x2d294 | 0x26a |
GetDateFormatW | - | 0x42fa4c | 0x2f298 | 0x2d298 | 0x1b0 |
GetTimeZoneInformation | - | 0x42fa50 | 0x2f29c | 0x2d29c | 0x26b |
GetCommandLineW | - | 0x42fa54 | 0x2f2a0 | 0x2d2a0 | 0x170 |
HeapSetInformation | - | 0x42fa58 | 0x2f2a4 | 0x2d2a4 | 0x2a5 |
GetStartupInfoW | - | 0x42fa5c | 0x2f2a8 | 0x2d2a8 | 0x23a |
GetFullPathNameW | - | 0x42fa60 | 0x2f2ac | 0x2d2ac | 0x1df |
GetFileInformationByHandle | - | 0x42fa64 | 0x2f2b0 | 0x2d2b0 | 0x1d0 |
PeekNamedPipe | - | 0x42fa68 | 0x2f2b4 | 0x2d2b4 | 0x33e |
GetCurrentDirectoryW | - | 0x42fa6c | 0x2f2b8 | 0x2d2b8 | 0x1a8 |
UnhandledExceptionFilter | - | 0x42fa70 | 0x2f2bc | 0x2d2bc | 0x43e |
SetUnhandledExceptionFilter | - | 0x42fa74 | 0x2f2c0 | 0x2d2c0 | 0x415 |
IsDebuggerPresent | - | 0x42fa78 | 0x2f2c4 | 0x2d2c4 | 0x2d1 |
EncodePointer | - | 0x42fa7c | 0x2f2c8 | 0x2d2c8 | 0xd5 |
TerminateProcess | - | 0x42fa80 | 0x2f2cc | 0x2d2cc | 0x42d |
GetCPInfo | - | 0x42fa84 | 0x2f2d0 | 0x2d2d0 | 0x15b |
GetACP | - | 0x42fa88 | 0x2f2d4 | 0x2d2d4 | 0x152 |
GetOEMCP | - | 0x42fa8c | 0x2f2d8 | 0x2d2d8 | 0x213 |
IsValidCodePage | - | 0x42fa90 | 0x2f2dc | 0x2d2dc | 0x2db |
TlsAlloc | - | 0x42fa94 | 0x2f2e0 | 0x2d2e0 | 0x432 |
TlsGetValue | - | 0x42fa98 | 0x2f2e4 | 0x2d2e4 | 0x434 |
TlsSetValue | - | 0x42fa9c | 0x2f2e8 | 0x2d2e8 | 0x435 |
TlsFree | - | 0x42faa0 | 0x2f2ec | 0x2d2ec | 0x433 |
SetLastError | - | 0x42faa4 | 0x2f2f0 | 0x2d2f0 | 0x3ec |
GetVolumeInformationA | - | 0x42faa8 | 0x2f2f4 | 0x2d2f4 | 0x277 |
GetModuleFileNameA | - | 0x42faac | 0x2f2f8 | 0x2d2f8 | 0x1f4 |
GetOverlappedResult | - | 0x42fab0 | 0x2f2fc | 0x2d2fc | 0x214 |
CreateEventA | - | 0x42fab4 | 0x2f300 | 0x2d300 | 0x72 |
GlobalReAlloc | - | 0x42fab8 | 0x2f304 | 0x2d304 | 0x293 |
GetFileTime | - | 0x42fabc | 0x2f308 | 0x2d308 | 0x1d6 |
SetFileTime | - | 0x42fac0 | 0x2f30c | 0x2d30c | 0x3e3 |
SystemTimeToFileTime | - | 0x42fac4 | 0x2f310 | 0x2d310 | 0x42a |
GetCurrentThread | - | 0x42fac8 | 0x2f314 | 0x2d314 | 0x1ac |
GlobalMemoryStatus | - | 0x42facc | 0x2f318 | 0x2d318 | 0x291 |
GetSystemInfo | - | 0x42fad0 | 0x2f31c | 0x2d31c | 0x249 |
GetExitCodeThread | - | 0x42fad4 | 0x2f320 | 0x2d320 | 0x1c6 |
TerminateThread | - | 0x42fad8 | 0x2f324 | 0x2d324 | 0x42e |
CreateThread | - | 0x42fadc | 0x2f328 | 0x2d328 | 0xa3 |
GetDiskFreeSpaceA | - | 0x42fae0 | 0x2f32c | 0x2d32c | 0x1b4 |
GetCommandLineA | - | 0x42fae4 | 0x2f330 | 0x2d330 | 0x16f |
CreateMutexA | - | 0x42fae8 | 0x2f334 | 0x2d334 | 0x8b |
ReleaseMutex | - | 0x42faec | 0x2f338 | 0x2d338 | 0x377 |
OpenEventA | - | 0x42faf0 | 0x2f33c | 0x2d33c | 0x327 |
ResetEvent | - | 0x42faf4 | 0x2f340 | 0x2d340 | 0x38a |
GetFileAttributesA | - | 0x42faf8 | 0x2f344 | 0x2d344 | 0x1c9 |
lstrcatA | - | 0x42fafc | 0x2f348 | 0x2d348 | 0x4a6 |
GetVersionExA | - | 0x42fb00 | 0x2f34c | 0x2d34c | 0x275 |
GetModuleHandleA | - | 0x42fb04 | 0x2f350 | 0x2d350 | 0x1f6 |
GetComputerNameA | - | 0x42fb08 | 0x2f354 | 0x2d354 | 0x175 |
GetPrivateProfileIntA | - | 0x42fb0c | 0x2f358 | 0x2d358 | 0x216 |
GetUserDefaultLangID | - | 0x42fb10 | 0x2f35c | 0x2d35c | 0x26e |
GetPrivateProfileSectionA | - | 0x42fb14 | 0x2f360 | 0x2d360 | 0x218 |
GetSystemDirectoryA | - | 0x42fb18 | 0x2f364 | 0x2d364 | 0x245 |
VirtualAlloc | - | 0x42fb1c | 0x2f368 | 0x2d368 | 0x454 |
VirtualFree | - | 0x42fb20 | 0x2f36c | 0x2d36c | 0x457 |
FindFirstFileA | - | 0x42fb24 | 0x2f370 | 0x2d370 | 0x11d |
MoveFileExA | - | 0x42fb28 | 0x2f374 | 0x2d374 | 0x312 |
RemoveDirectoryA | - | 0x42fb2c | 0x2f378 | 0x2d378 | 0x37d |
FindNextFileA | - | 0x42fb30 | 0x2f37c | 0x2d37c | 0x12e |
GlobalAlloc | - | 0x42fb34 | 0x2f380 | 0x2d380 | 0x285 |
GlobalLock | - | 0x42fb38 | 0x2f384 | 0x2d384 | 0x290 |
GlobalUnlock | - | 0x42fb3c | 0x2f388 | 0x2d388 | 0x297 |
GlobalFree | - | 0x42fb40 | 0x2f38c | 0x2d38c | 0x28c |
GetFileSize | - | 0x42fb44 | 0x2f390 | 0x2d390 | 0x1d4 |
CopyFileA | - | 0x42fb48 | 0x2f394 | 0x2d394 | 0x60 |
GetPrivateProfileStringA | - | 0x42fb4c | 0x2f398 | 0x2d398 | 0x21c |
CreateFileA | - | 0x42fb50 | 0x2f39c | 0x2d39c | 0x78 |
DeviceIoControl | - | 0x42fb54 | 0x2f3a0 | 0x2d3a0 | 0xca |
InitializeCriticalSection | - | 0x42fb58 | 0x2f3a4 | 0x2d3a4 | 0x2b4 |
PulseEvent | - | 0x42fb5c | 0x2f3a8 | 0x2d3a8 | 0x348 |
GetWindowsDirectoryA | - | 0x42fb60 | 0x2f3ac | 0x2d3ac | 0x280 |
DeleteFileA | - | 0x42fb64 | 0x2f3b0 | 0x2d3b0 | 0xc0 |
GetCurrentDirectoryA | - | 0x42fb68 | 0x2f3b4 | 0x2d3b4 | 0x1a7 |
OpenFile | - | 0x42fb6c | 0x2f3b8 | 0x2d3b8 | 0x329 |
lstrcpyA | - | 0x42fb70 | 0x2f3bc | 0x2d3bc | 0x4af |
lstrcpynA | - | 0x42fb74 | 0x2f3c0 | 0x2d3c0 | 0x4b2 |
GetSystemTime | - | 0x42fb78 | 0x2f3c4 | 0x2d3c4 | 0x24d |
CreateProcessA | - | 0x42fb7c | 0x2f3c8 | 0x2d3c8 | 0x94 |
FormatMessageA | - | 0x42fb80 | 0x2f3cc | 0x2d3cc | 0x147 |
OutputDebugStringA | - | 0x42fb84 | 0x2f3d0 | 0x2d3d0 | 0x33a |
InterlockedCompareExchange | - | 0x42fb88 | 0x2f3d4 | 0x2d3d4 | 0x2ba |
GetStartupInfoA | - | 0x42fb8c | 0x2f3d8 | 0x2d3d8 | 0x239 |
SetFileAttributesA | - | 0x42fb90 | 0x2f3dc | 0x2d3dc | 0x3d7 |
SetErrorMode | - | 0x42fb94 | 0x2f3e0 | 0x2d3e0 | 0x3d2 |
USER32.dll (311)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetMenuBarInfo | - | 0x42fb9c | 0x2f3e8 | 0x2d3e8 | 0x13d |
ReuseDDElParam | - | 0x42fba0 | 0x2f3ec | 0x2d3ec | 0x253 |
UnpackDDElParam | - | 0x42fba4 | 0x2f3f0 | 0x2d3f0 | 0x2dd |
DefFrameProcA | - | 0x42fba8 | 0x2f3f4 | 0x2d3f4 | 0x90 |
DefMDIChildProcA | - | 0x42fbac | 0x2f3f8 | 0x2d3f8 | 0x92 |
TranslateMDISysAccel | - | 0x42fbb0 | 0x2f3fc | 0x2d3fc | 0x2d4 |
MsgWaitForMultipleObjectsEx | - | 0x42fbb4 | 0x2f400 | 0x2d400 | 0x207 |
GetNextDlgGroupItem | - | 0x42fbb8 | 0x2f404 | 0x2d404 | 0x152 |
DrawIconEx | - | 0x42fbbc | 0x2f408 | 0x2d408 | 0xc0 |
CopyImage | - | 0x42fbc0 | 0x2f40c | 0x2d40c | 0x4e |
GetIconInfo | - | 0x42fbc4 | 0x2f410 | 0x2d410 | 0x128 |
MonitorFromPoint | - | 0x42fbc8 | 0x2f414 | 0x2d414 | 0x202 |
RealChildWindowFromPoint | - | 0x42fbcc | 0x2f418 | 0x2d418 | 0x22b |
LoadAcceleratorsW | - | 0x42fbd0 | 0x2f41c | 0x2d41c | 0x1cf |
ShowOwnedPopups | - | 0x42fbd4 | 0x2f420 | 0x2d420 | 0x2b4 |
NotifyWinEvent | - | 0x42fbd8 | 0x2f424 | 0x2d424 | 0x208 |
CopyIcon | - | 0x42fbdc | 0x2f428 | 0x2d428 | 0x4d |
IsClipboardFormatAvailable | - | 0x42fbe0 | 0x2f42c | 0x2d42c | 0x1b6 |
SetWindowContextHelpId | - | 0x42fbe4 | 0x2f430 | 0x2d430 | 0x2a3 |
UpdateLayeredWindow | - | 0x42fbe8 | 0x2f434 | 0x2d434 | 0x2e6 |
EnumDisplayMonitors | - | 0x42fbec | 0x2f438 | 0x2d438 | 0xdf |
SetLayeredWindowAttributes | - | 0x42fbf0 | 0x2f43c | 0x2d43c | 0x27e |
InSendMessage | - | 0x42fbf4 | 0x2f440 | 0x2d440 | 0x19f |
CopyAcceleratorTableA | - | 0x42fbf8 | 0x2f444 | 0x2d444 | 0x4b |
InvalidateRgn | - | 0x42fbfc | 0x2f448 | 0x2d448 | 0x1ab |
LoadImageW | - | 0x42fc00 | 0x2f44c | 0x2d44c | 0x1d9 |
ToAsciiEx | - | 0x42fc04 | 0x2f450 | 0x2d450 | 0x2cb |
CreateAcceleratorTableA | - | 0x42fc08 | 0x2f454 | 0x2d454 | 0x51 |
SubtractRect | - | 0x42fc0c | 0x2f458 | 0x2d458 | 0x2bf |
GetWindowRgn | - | 0x42fc10 | 0x2f45c | 0x2d45c | 0x189 |
GetDCEx | - | 0x42fc14 | 0x2f460 | 0x2d460 | 0x11b |
CharUpperBuffA | - | 0x42fc18 | 0x2f464 | 0x2d464 | 0x38 |
SendNotifyMessageA | - | 0x42fc1c | 0x2f468 | 0x2d468 | 0x264 |
MapVirtualKeyExA | - | 0x42fc20 | 0x2f46c | 0x2d46c | 0x1f0 |
InvertRect | - | 0x42fc24 | 0x2f470 | 0x2d470 | 0x1ac |
SetPropA | - | 0x42fc28 | 0x2f474 | 0x2d474 | 0x28f |
GetPropA | - | 0x42fc2c | 0x2f478 | 0x2d478 | 0x15b |
GetClassInfoExA | - | 0x42fc30 | 0x2f47c | 0x2d47c | 0x105 |
RegisterClassExA | - | 0x42fc34 | 0x2f480 | 0x2d480 | 0x234 |
GetComboBoxInfo | - | 0x42fc38 | 0x2f484 | 0x2d484 | 0x115 |
SetDlgItemTextA | - | 0x42fc3c | 0x2f488 | 0x2d488 | 0x276 |
MessageBeep | - | 0x42fc40 | 0x2f48c | 0x2d48c | 0x1f7 |
EnumClipboardFormats | - | 0x42fc44 | 0x2f490 | 0x2d490 | 0xd9 |
CreateMenu | - | 0x42fc48 | 0x2f494 | 0x2d494 | 0x64 |
SetWindowTextW | - | 0x42fc4c | 0x2f498 | 0x2d498 | 0x2ac |
GetDlgItemTextA | - | 0x42fc50 | 0x2f49c | 0x2d49c | 0x121 |
GetSystemMenu | - | 0x42fc54 | 0x2f4a0 | 0x2d4a0 | 0x16e |
FindWindowExA | - | 0x42fc58 | 0x2f4a4 | 0x2d4a4 | 0xf1 |
TrackPopupMenuEx | - | 0x42fc5c | 0x2f4a8 | 0x2d4a8 | 0x2d0 |
MessageBoxW | - | 0x42fc60 | 0x2f4ac | 0x2d4ac | 0x1ff |
LoadIconA | - | 0x42fc64 | 0x2f4b0 | 0x2d4b0 | 0x1d6 |
DrawTextW | - | 0x42fc68 | 0x2f4b4 | 0x2d4b4 | 0xc8 |
GetTabbedTextExtentW | - | 0x42fc6c | 0x2f4b8 | 0x2d4b8 | 0x171 |
GetScrollPos | - | 0x42fc70 | 0x2f4bc | 0x2d4bc | 0x167 |
ShowScrollBar | - | 0x42fc74 | 0x2f4c0 | 0x2d4c0 | 0x2b5 |
EnableScrollBar | - | 0x42fc78 | 0x2f4c4 | 0x2d4c4 | 0xd0 |
SetWindowRgn | - | 0x42fc7c | 0x2f4c8 | 0x2d4c8 | 0x2a8 |
WindowFromDC | - | 0x42fc80 | 0x2f4cc | 0x2d4cc | 0x301 |
GetAsyncKeyState | - | 0x42fc84 | 0x2f4d0 | 0x2d4d0 | 0x100 |
LoadMenuW | - | 0x42fc88 | 0x2f4d4 | 0x2d4d4 | 0x1e1 |
CreateWindowExW | - | 0x42fc8c | 0x2f4d8 | 0x2d4d8 | 0x68 |
PostQuitMessage | - | 0x42fc90 | 0x2f4dc | 0x2d4dc | 0x220 |
TrackPopupMenu | - | 0x42fc94 | 0x2f4e0 | 0x2d4e0 | 0x2cf |
GetMenuStringA | - | 0x42fc98 | 0x2f4e4 | 0x2d4e4 | 0x148 |
SetKeyboardState | - | 0x42fc9c | 0x2f4e8 | 0x2d4e8 | 0x27c |
CheckMenuItem | - | 0x42fca0 | 0x2f4ec | 0x2d4ec | 0x3d |
SetWindowTextA | - | 0x42fca4 | 0x2f4f0 | 0x2d4f0 | 0x2ab |
DestroyAcceleratorTable | - | 0x42fca8 | 0x2f4f4 | 0x2d4f4 | 0x9a |
ModifyMenuW | - | 0x42fcac | 0x2f4f8 | 0x2d4f8 | 0x201 |
AppendMenuW | - | 0x42fcb0 | 0x2f4fc | 0x2d4fc | 0xa |
GetMenuStringW | - | 0x42fcb4 | 0x2f500 | 0x2d500 | 0x149 |
WinHelpA | - | 0x42fcb8 | 0x2f504 | 0x2d504 | 0x2ff |
GetAncestor | - | 0x42fcbc | 0x2f508 | 0x2d508 | 0xfd |
CallWindowProcA | - | 0x42fcc0 | 0x2f50c | 0x2d50c | 0x1c |
MapVirtualKeyA | - | 0x42fcc4 | 0x2f510 | 0x2d510 | 0x1ef |
keybd_event | - | 0x42fcc8 | 0x2f514 | 0x2d514 | 0x305 |
SetMenu | - | 0x42fccc | 0x2f518 | 0x2d518 | 0x27f |
AdjustWindowRectEx | - | 0x42fcd0 | 0x2f51c | 0x2d51c | 0x3 |
SystemParametersInfoA | - | 0x42fcd4 | 0x2f520 | 0x2d520 | 0x2c4 |
GetKeyboardState | - | 0x42fcd8 | 0x2f524 | 0x2d524 | 0x136 |
ToAscii | - | 0x42fcdc | 0x2f528 | 0x2d528 | 0x2ca |
GetTopWindow | - | 0x42fce0 | 0x2f52c | 0x2d52c | 0x175 |
ChildWindowFromPointEx | - | 0x42fce4 | 0x2f530 | 0x2d530 | 0x42 |
IsZoomed | - | 0x42fce8 | 0x2f534 | 0x2d534 | 0x1cc |
DrawMenuBar | - | 0x42fcec | 0x2f538 | 0x2d538 | 0xc1 |
SetMenuDefaultItem | - | 0x42fcf0 | 0x2f53c | 0x2d53c | 0x281 |
SendMessageW | - | 0x42fcf4 | 0x2f540 | 0x2d540 | 0x263 |
DrawStateA | - | 0x42fcf8 | 0x2f544 | 0x2d544 | 0xc3 |
FlashWindowEx | - | 0x42fcfc | 0x2f548 | 0x2d548 | 0xf5 |
CharUpperW | - | 0x42fd00 | 0x2f54c | 0x2d54c | 0x3a |
CharLowerW | - | 0x42fd04 | 0x2f550 | 0x2d550 | 0x2c |
IsCharLowerW | - | 0x42fd08 | 0x2f554 | 0x2d554 | 0x1b2 |
IsCharUpperW | - | 0x42fd0c | 0x2f558 | 0x2d558 | 0x1b4 |
CharUpperA | - | 0x42fd10 | 0x2f55c | 0x2d55c | 0x37 |
CharLowerA | - | 0x42fd14 | 0x2f560 | 0x2d560 | 0x29 |
IsCharLowerA | - | 0x42fd18 | 0x2f564 | 0x2d564 | 0x1b1 |
IsCharUpperA | - | 0x42fd1c | 0x2f568 | 0x2d568 | 0x1b3 |
RemoveMenu | - | 0x42fd20 | 0x2f56c | 0x2d56c | 0x24e |
GetMenuItemID | - | 0x42fd24 | 0x2f570 | 0x2d570 | 0x143 |
IsCharAlphaW | - | 0x42fd28 | 0x2f574 | 0x2d574 | 0x1b0 |
IsCharAlphaNumericW | - | 0x42fd2c | 0x2f578 | 0x2d578 | 0x1af |
IsCharAlphaA | - | 0x42fd30 | 0x2f57c | 0x2d57c | 0x1ad |
IsCharAlphaNumericA | - | 0x42fd34 | 0x2f580 | 0x2d580 | 0x1ae |
OemToCharBuffA | - | 0x42fd38 | 0x2f584 | 0x2d584 | 0x20b |
DefWindowProcW | - | 0x42fd3c | 0x2f588 | 0x2d588 | 0x96 |
GetUpdateRect | - | 0x42fd40 | 0x2f58c | 0x2d58c | 0x176 |
BeginPaint | - | 0x42fd44 | 0x2f590 | 0x2d590 | 0xe |
EndPaint | - | 0x42fd48 | 0x2f594 | 0x2d594 | 0xd5 |
GetKeyboardLayout | - | 0x42fd4c | 0x2f598 | 0x2d598 | 0x132 |
GetCursor | - | 0x42fd50 | 0x2f59c | 0x2d59c | 0x116 |
GetClipboardData | - | 0x42fd54 | 0x2f5a0 | 0x2d5a0 | 0x10f |
GetTabbedTextExtentA | - | 0x42fd58 | 0x2f5a4 | 0x2d5a4 | 0x170 |
CharToOemBuffA | - | 0x42fd5c | 0x2f5a8 | 0x2d5a8 | 0x34 |
GetScrollInfo | - | 0x42fd60 | 0x2f5ac | 0x2d5ac | 0x166 |
GetScrollRange | - | 0x42fd64 | 0x2f5b0 | 0x2d5b0 | 0x168 |
SetScrollPos | - | 0x42fd68 | 0x2f5b4 | 0x2d5b4 | 0x294 |
ScrollWindow | - | 0x42fd6c | 0x2f5b8 | 0x2d5b8 | 0x257 |
GetClassLongA | - | 0x42fd70 | 0x2f5bc | 0x2d5bc | 0x108 |
SetCaretPos | - | 0x42fd74 | 0x2f5c0 | 0x2d5c0 | 0x269 |
CreateCaret | - | 0x42fd78 | 0x2f5c4 | 0x2d5c4 | 0x53 |
ShowCaret | - | 0x42fd7c | 0x2f5c8 | 0x2d5c8 | 0x2b2 |
FrameRect | - | 0x42fd80 | 0x2f5cc | 0x2d5cc | 0xf6 |
DestroyCaret | - | 0x42fd84 | 0x2f5d0 | 0x2d5d0 | 0x9b |
HideCaret | - | 0x42fd88 | 0x2f5d4 | 0x2d5d4 | 0x195 |
GrayStringA | - | 0x42fd8c | 0x2f5d8 | 0x2d5d8 | 0x193 |
LoadCursorA | - | 0x42fd90 | 0x2f5dc | 0x2d5dc | 0x1d2 |
CharNextA | - | 0x42fd94 | 0x2f5e0 | 0x2d5e0 | 0x2d |
SetClassLongA | - | 0x42fd98 | 0x2f5e4 | 0x2d5e4 | 0x26a |
SetWindowLongW | - | 0x42fd9c | 0x2f5e8 | 0x2d5e8 | 0x2a5 |
GetWindowLongW | - | 0x42fda0 | 0x2f5ec | 0x2d5ec | 0x182 |
SetWindowsHookExA | - | 0x42fda4 | 0x2f5f0 | 0x2d5f0 | 0x2af |
RegisterClassA | - | 0x42fda8 | 0x2f5f4 | 0x2d5f4 | 0x233 |
UnregisterClassA | - | 0x42fdac | 0x2f5f8 | 0x2d5f8 | 0x2de |
FindWindowA | - | 0x42fdb0 | 0x2f5fc | 0x2d5fc | 0xf0 |
RegisterClipboardFormatA | - | 0x42fdb4 | 0x2f600 | 0x2d600 | 0x237 |
TileWindows | - | 0x42fdb8 | 0x2f604 | 0x2d604 | 0x2c9 |
GetDoubleClickTime | - | 0x42fdbc | 0x2f608 | 0x2d608 | 0x123 |
ShowWindow | - | 0x42fdc0 | 0x2f60c | 0x2d60c | 0x2b8 |
InsertMenuItemA | - | 0x42fdc4 | 0x2f610 | 0x2d610 | 0x1a4 |
DispatchMessageW | - | 0x42fdc8 | 0x2f614 | 0x2d614 | 0xa9 |
GetMessageW | - | 0x42fdcc | 0x2f618 | 0x2d618 | 0x14e |
GetForegroundWindow | - | 0x42fdd0 | 0x2f61c | 0x2d61c | 0x125 |
SetClipboardData | - | 0x42fdd4 | 0x2f620 | 0x2d620 | 0x26d |
GetActiveWindow | - | 0x42fdd8 | 0x2f624 | 0x2d624 | 0xf9 |
UnhookWindowsHookEx | - | 0x42fddc | 0x2f628 | 0x2d628 | 0x2d9 |
SetForegroundWindow | - | 0x42fde0 | 0x2f62c | 0x2d62c | 0x27a |
SetActiveWindow | - | 0x42fde4 | 0x2f630 | 0x2d630 | 0x266 |
LockWindowUpdate | - | 0x42fde8 | 0x2f634 | 0x2d634 | 0x1e7 |
ModifyMenuA | - | 0x42fdec | 0x2f638 | 0x2d638 | 0x200 |
GetMenuItemCount | - | 0x42fdf0 | 0x2f63c | 0x2d63c | 0x142 |
EnableMenuItem | - | 0x42fdf4 | 0x2f640 | 0x2d640 | 0xcf |
DeleteMenu | - | 0x42fdf8 | 0x2f644 | 0x2d644 | 0x98 |
GetWindowThreadProcessId | - | 0x42fdfc | 0x2f648 | 0x2d648 | 0x190 |
CallNextHookEx | - | 0x42fe00 | 0x2f64c | 0x2d64c | 0x1b |
IsRectEmpty | - | 0x42fe04 | 0x2f650 | 0x2d650 | 0x1c0 |
OffsetRect | - | 0x42fe08 | 0x2f654 | 0x2d654 | 0x20e |
BeginDeferWindowPos | - | 0x42fe0c | 0x2f658 | 0x2d658 | 0xd |
EndDeferWindowPos | - | 0x42fe10 | 0x2f65c | 0x2d65c | 0xd2 |
IsIconic | - | 0x42fe14 | 0x2f660 | 0x2d660 | 0x1bd |
DrawIcon | - | 0x42fe18 | 0x2f664 | 0x2d664 | 0xbf |
GetDlgCtrlID | - | 0x42fe1c | 0x2f668 | 0x2d668 | 0x11e |
GetSysColorBrush | - | 0x42fe20 | 0x2f66c | 0x2d66c | 0x16d |
IntersectRect | - | 0x42fe24 | 0x2f670 | 0x2d670 | 0x1a9 |
SetRect | - | 0x42fe28 | 0x2f674 | 0x2d674 | 0x291 |
SetRectEmpty | - | 0x42fe2c | 0x2f678 | 0x2d678 | 0x292 |
IsWindowEnabled | - | 0x42fe30 | 0x2f67c | 0x2d67c | 0x1c6 |
RegisterWindowMessageA | - | 0x42fe34 | 0x2f680 | 0x2d680 | 0x249 |
DestroyIcon | - | 0x42fe38 | 0x2f684 | 0x2d684 | 0x9d |
LoadImageA | - | 0x42fe3c | 0x2f688 | 0x2d688 | 0x1d8 |
GetSystemMetrics | - | 0x42fe40 | 0x2f68c | 0x2d68c | 0x16f |
DestroyMenu | - | 0x42fe44 | 0x2f690 | 0x2d690 | 0x9e |
SetMenuInfo | - | 0x42fe48 | 0x2f694 | 0x2d694 | 0x282 |
GetSubMenu | - | 0x42fe4c | 0x2f698 | 0x2d698 | 0x16b |
DefWindowProcA | - | 0x42fe50 | 0x2f69c | 0x2d69c | 0x95 |
ValidateRect | - | 0x42fe54 | 0x2f6a0 | 0x2d6a0 | 0x2f2 |
SetCursorPos | - | 0x42fe58 | 0x2f6a4 | 0x2d6a4 | 0x272 |
ReleaseCapture | - | 0x42fe5c | 0x2f6a8 | 0x2d6a8 | 0x24b |
DrawFrameControl | - | 0x42fe60 | 0x2f6ac | 0x2d6ac | 0xbe |
FillRect | - | 0x42fe64 | 0x2f6b0 | 0x2d6b0 | 0xef |
DestroyCursor | - | 0x42fe68 | 0x2f6b4 | 0x2d6b4 | 0x9c |
SetCursor | - | 0x42fe6c | 0x2f6b8 | 0x2d6b8 | 0x270 |
ShowCursor | - | 0x42fe70 | 0x2f6bc | 0x2d6bc | 0x2b3 |
LoadCursorW | - | 0x42fe74 | 0x2f6c0 | 0x2d6c0 | 0x1d5 |
SetCapture | - | 0x42fe78 | 0x2f6c4 | 0x2d6c4 | 0x267 |
GetCapture | - | 0x42fe7c | 0x2f6c8 | 0x2d6c8 | 0x101 |
KillTimer | - | 0x42fe80 | 0x2f6cc | 0x2d6cc | 0x1cd |
SetTimer | - | 0x42fe84 | 0x2f6d0 | 0x2d6d0 | 0x29e |
BringWindowToTop | - | 0x42fe88 | 0x2f6d4 | 0x2d6d4 | 0x10 |
MessageBoxA | - | 0x42fe8c | 0x2f6d8 | 0x2d6d8 | 0x1f8 |
GetMessageA | - | 0x42fe90 | 0x2f6dc | 0x2d6dc | 0x14a |
SetScrollRange | - | 0x42fe94 | 0x2f6e0 | 0x2d6e0 | 0x295 |
SetScrollInfo | - | 0x42fe98 | 0x2f6e4 | 0x2d6e4 | 0x293 |
PostThreadMessageA | - | 0x42fe9c | 0x2f6e8 | 0x2d6e8 | 0x221 |
ScreenToClient | - | 0x42fea0 | 0x2f6ec | 0x2d6ec | 0x254 |
GetMenu | - | 0x42fea4 | 0x2f6f0 | 0x2d6f0 | 0x13c |
GetWindow | - | 0x42fea8 | 0x2f6f4 | 0x2d6f4 | 0x17d |
SetWindowPos | - | 0x42feac | 0x2f6f8 | 0x2d6f8 | 0x2a7 |
EmptyClipboard | - | 0x42feb0 | 0x2f6fc | 0x2d6fc | 0xce |
CloseClipboard | - | 0x42feb4 | 0x2f700 | 0x2d700 | 0x47 |
DrawTextExA | - | 0x42feb8 | 0x2f704 | 0x2d704 | 0xc6 |
SetFocus | - | 0x42febc | 0x2f708 | 0x2d708 | 0x279 |
IsWindowUnicode | - | 0x42fec0 | 0x2f70c | 0x2d70c | 0x1c9 |
DestroyWindow | - | 0x42fec4 | 0x2f710 | 0x2d710 | 0xa0 |
DrawTextA | - | 0x42fec8 | 0x2f714 | 0x2d714 | 0xc5 |
OpenClipboard | - | 0x42fecc | 0x2f718 | 0x2d718 | 0x20f |
GetDesktopWindow | - | 0x42fed0 | 0x2f71c | 0x2d71c | 0x11c |
PostMessageA | - | 0x42fed4 | 0x2f720 | 0x2d720 | 0x21e |
InsertMenuA | - | 0x42fed8 | 0x2f724 | 0x2d724 | 0x1a3 |
LoadBitmapW | - | 0x42fedc | 0x2f728 | 0x2d728 | 0x1d1 |
InflateRect | - | 0x42fee0 | 0x2f72c | 0x2d72c | 0x1a1 |
GetWindowLongA | - | 0x42fee4 | 0x2f730 | 0x2d730 | 0x181 |
GetCursorPos | - | 0x42fee8 | 0x2f734 | 0x2d734 | 0x119 |
WindowFromPoint | - | 0x42feec | 0x2f738 | 0x2d738 | 0x303 |
IsWindowVisible | - | 0x42fef0 | 0x2f73c | 0x2d73c | 0x1ca |
InvalidateRect | - | 0x42fef4 | 0x2f740 | 0x2d740 | 0x1aa |
ClientToScreen | - | 0x42fef8 | 0x2f744 | 0x2d744 | 0x45 |
AppendMenuA | - | 0x42fefc | 0x2f748 | 0x2d748 | 0x9 |
CreatePopupMenu | - | 0x42ff00 | 0x2f74c | 0x2d74c | 0x65 |
EqualRect | - | 0x42ff04 | 0x2f750 | 0x2d750 | 0xec |
PtInRect | - | 0x42ff08 | 0x2f754 | 0x2d754 | 0x229 |
GetDlgItem | - | 0x42ff0c | 0x2f758 | 0x2d758 | 0x11f |
UpdateWindow | - | 0x42ff10 | 0x2f75c | 0x2d75c | 0x2e9 |
PeekMessageA | - | 0x42ff14 | 0x2f760 | 0x2d760 | 0x21b |
TranslateMessage | - | 0x42ff18 | 0x2f764 | 0x2d764 | 0x2d5 |
DispatchMessageA | - | 0x42ff1c | 0x2f768 | 0x2d768 | 0xa8 |
WaitMessage | - | 0x42ff20 | 0x2f76c | 0x2d76c | 0x2fd |
LoadIconW | - | 0x42ff24 | 0x2f770 | 0x2d770 | 0x1d7 |
IsChild | - | 0x42ff28 | 0x2f774 | 0x2d774 | 0x1b5 |
GetFocus | - | 0x42ff2c | 0x2f778 | 0x2d778 | 0x124 |
GetSysColor | - | 0x42ff30 | 0x2f77c | 0x2d77c | 0x16c |
MapDialogRect | - | 0x42ff34 | 0x2f780 | 0x2d780 | 0x1ee |
GetDialogBaseUnits | - | 0x42ff38 | 0x2f784 | 0x2d784 | 0x11d |
GetClientRect | - | 0x42ff3c | 0x2f788 | 0x2d788 | 0x10d |
CreateWindowExA | - | 0x42ff40 | 0x2f78c | 0x2d78c | 0x67 |
SetWindowLongA | - | 0x42ff44 | 0x2f790 | 0x2d790 | 0x2a4 |
GetWindowRect | - | 0x42ff48 | 0x2f794 | 0x2d794 | 0x188 |
MoveWindow | - | 0x42ff4c | 0x2f798 | 0x2d798 | 0x205 |
SetParent | - | 0x42ff50 | 0x2f79c | 0x2d79c | 0x289 |
RedrawWindow | - | 0x42ff54 | 0x2f7a0 | 0x2d7a0 | 0x232 |
ReleaseDC | - | 0x42ff58 | 0x2f7a4 | 0x2d7a4 | 0x24c |
GetDC | - | 0x42ff5c | 0x2f7a8 | 0x2d7a8 | 0x11a |
DrawFocusRect | - | 0x42ff60 | 0x2f7ac | 0x2d7ac | 0xbc |
TabbedTextOutA | - | 0x42ff64 | 0x2f7b0 | 0x2d7b0 | 0x2c6 |
CreateDialogIndirectParamA | - | 0x42ff68 | 0x2f7b4 | 0x2d7b4 | 0x59 |
EndDialog | - | 0x42ff6c | 0x2f7b8 | 0x2d7b8 | 0xd3 |
ScrollWindowEx | - | 0x42ff70 | 0x2f7bc | 0x2d7bc | 0x258 |
IsDlgButtonChecked | - | 0x42ff74 | 0x2f7c0 | 0x2d7c0 | 0x1ba |
SetDlgItemInt | - | 0x42ff78 | 0x2f7c4 | 0x2d7c4 | 0x275 |
GetDlgItemInt | - | 0x42ff7c | 0x2f7c8 | 0x2d7c8 | 0x120 |
CheckRadioButton | - | 0x42ff80 | 0x2f7cc | 0x2d7cc | 0x3f |
CheckDlgButton | - | 0x42ff84 | 0x2f7d0 | 0x2d7d0 | 0x3c |
SetMenuItemBitmaps | - | 0x42ff88 | 0x2f7d4 | 0x2d7d4 | 0x283 |
GetMenuCheckMarkDimensions | - | 0x42ff8c | 0x2f7d8 | 0x2d7d8 | 0x13e |
SendDlgItemMessageA | - | 0x42ff90 | 0x2f7dc | 0x2d7dc | 0x259 |
GetWindowTextLengthA | - | 0x42ff94 | 0x2f7e0 | 0x2d7e0 | 0x18d |
GetLastActivePopup | - | 0x42ff98 | 0x2f7e4 | 0x2d7e4 | 0x138 |
GetMessageTime | - | 0x42ff9c | 0x2f7e8 | 0x2d7e8 | 0x14d |
GetMonitorInfoA | - | 0x42ffa0 | 0x2f7ec | 0x2d7ec | 0x14f |
SetWindowPlacement | - | 0x42ffa4 | 0x2f7f0 | 0x2d7f0 | 0x2a6 |
GetWindowPlacement | - | 0x42ffa8 | 0x2f7f4 | 0x2d7f4 | 0x187 |
GetKeyNameTextA | - | 0x42ffac | 0x2f7f8 | 0x2d7f8 | 0x12f |
SetPropW | - | 0x42ffb0 | 0x2f7fc | 0x2d7fc | 0x290 |
RemovePropW | - | 0x42ffb4 | 0x2f800 | 0x2d800 | 0x250 |
GetPropW | - | 0x42ffb8 | 0x2f804 | 0x2d804 | 0x15c |
CharLowerBuffW | - | 0x42ffbc | 0x2f808 | 0x2d808 | 0x2b |
CharLowerBuffA | - | 0x42ffc0 | 0x2f80c | 0x2d80c | 0x2a |
RemovePropA | - | 0x42ffc4 | 0x2f810 | 0x2d810 | 0x24f |
AttachThreadInput | - | 0x42ffc8 | 0x2f814 | 0x2d814 | 0xc |
TrackMouseEvent | - | 0x42ffcc | 0x2f818 | 0x2d818 | 0x2ce |
CopyRect | - | 0x42ffd0 | 0x2f81c | 0x2d81c | 0x4f |
GetParent | - | 0x42ffd4 | 0x2f820 | 0x2d820 | 0x155 |
IsWindow | - | 0x42ffd8 | 0x2f824 | 0x2d824 | 0x1c5 |
GetClassNameA | - | 0x42ffdc | 0x2f828 | 0x2d828 | 0x10a |
wsprintfA | - | 0x42ffe0 | 0x2f82c | 0x2d82c | 0x307 |
GetKeyState | - | 0x42ffe4 | 0x2f830 | 0x2d830 | 0x131 |
SendMessageA | - | 0x42ffe8 | 0x2f834 | 0x2d834 | 0x25e |
EnableWindow | - | 0x42ffec | 0x2f838 | 0x2d838 | 0xd1 |
CheckMenuRadioItem | - | 0x42fff0 | 0x2f83c | 0x2d83c | 0x3e |
EnumChildWindows | - | 0x42fff4 | 0x2f840 | 0x2d840 | 0xd8 |
LoadAcceleratorsA | - | 0x42fff8 | 0x2f844 | 0x2d844 | 0x1ce |
TranslateAcceleratorA | - | 0x42fffc | 0x2f848 | 0x2d848 | 0x2d2 |
LoadStringA | - | 0x430000 | 0x2f84c | 0x2d84c | 0x1e3 |
LoadStringW | - | 0x430004 | 0x2f850 | 0x2d850 | 0x1e4 |
GetUserObjectInformationW | - | 0x430008 | 0x2f854 | 0x2d854 | 0x17a |
GetClassNameW | - | 0x43000c | 0x2f858 | 0x2d858 | 0x10b |
LoadMenuIndirectA | - | 0x430010 | 0x2f85c | 0x2d85c | 0x1df |
GetNextDlgTabItem | - | 0x430014 | 0x2f860 | 0x2d860 | 0x153 |
GetClassInfoW | - | 0x430018 | 0x2f864 | 0x2d864 | 0x107 |
RegisterClassW | - | 0x43001c | 0x2f868 | 0x2d868 | 0x236 |
GetMenuDefaultItem | - | 0x430020 | 0x2f86c | 0x2d86c | 0x140 |
IsMenu | - | 0x430024 | 0x2f870 | 0x2d870 | 0x1be |
GetMenuInfo | - | 0x430028 | 0x2f874 | 0x2d874 | 0x141 |
IsDialogMessageA | - | 0x43002c | 0x2f878 | 0x2d878 | 0x1b8 |
UnionRect | - | 0x430030 | 0x2f87c | 0x2d87c | 0x2da |
GetMessagePos | - | 0x430034 | 0x2f880 | 0x2d880 | 0x14c |
GetMenuState | - | 0x430038 | 0x2f884 | 0x2d884 | 0x147 |
GetMenuItemInfoA | - | 0x43003c | 0x2f888 | 0x2d888 | 0x144 |
GetWindowTextA | - | 0x430040 | 0x2f88c | 0x2d88c | 0x18c |
GetWindowDC | - | 0x430044 | 0x2f890 | 0x2d890 | 0x17f |
MonitorFromWindow | - | 0x430048 | 0x2f894 | 0x2d894 | 0x204 |
MapWindowPoints | - | 0x43004c | 0x2f898 | 0x2d898 | 0x1f3 |
DrawEdge | - | 0x430050 | 0x2f89c | 0x2d89c | 0xbb |
DeferWindowPos | - | 0x430054 | 0x2f8a0 | 0x2d8a0 | 0x97 |
GetClassInfoA | - | 0x430058 | 0x2f8a4 | 0x2d8a4 | 0x104 |
GetCaretPos | - | 0x43005c | 0x2f8a8 | 0x2d8a8 | 0x103 |
LoadBitmapA | - | 0x430060 | 0x2f8ac | 0x2d8ac | 0x1d0 |
GetProcessWindowStation | - | 0x430064 | 0x2f8b0 | 0x2d8b0 | 0x159 |
GetClipboardOwner | - | 0x430068 | 0x2f8b4 | 0x2d8b4 | 0x112 |
GetQueueStatus | - | 0x43006c | 0x2f8b8 | 0x2d8b8 | 0x15d |
LoadMenuA | - | 0x430070 | 0x2f8bc | 0x2d8bc | 0x1de |
CallWindowProcW | - | 0x430074 | 0x2f8c0 | 0x2d8c0 | 0x1d |
ADVAPI32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExA | - | 0x43007c | 0x2f8c8 | 0x2d8c8 | 0x267 |
RegOpenKeyExA | - | 0x430080 | 0x2f8cc | 0x2d8cc | 0x25a |
Digital Signature Information
»
Verification Status | Failed |
Verification Error | The signature hash does not match the file contents |
Certificate: EGECQQEDPMAGYYBTTV
»
Issued by | EGECQQEDPMAGYYBTTV |
Country Name | - |
Valid From | 2022-01-24 14:40 (UTC+1) |
Valid Until | 2040-01-01 00:59 (UTC+1) |
Algorithm | sha1_rsa |
Serial Number | 10 63 74 50 F8 44 54 B3 4B F0 7E 4D 58 B0 F5 F2 |
Thumbprint | 86 66 86 89 86 2E 9B 6A 7D 87 B3 2B 86 7C 4F DE 50 81 E6 AC |
Memory Dumps (299)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
b123.exe | 1 | 0x00400000 | 0x0043BFFF | Relevant Image | 32-bit | 0x0042D6A0 |
...
|
||
buffer | 1 | 0x00510000 | 0x00538FFF | First Execution | 32-bit | 0x005387C0 |
...
|
||
b123.exe | 1 | 0x00400000 | 0x0043BFFF | Content Changed | 32-bit | 0x00408430 |
...
|
||
b123.exe | 1 | 0x00400000 | 0x0043BFFF | Content Changed | 32-bit | 0x00401770 |
...
|
||
buffer | 1 | 0x006C1F38 | 0x006C1F44 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2010 | 0x006C201E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2070 | 0x006C207B | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2100 | 0x006C210C | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C21A8 | 0x006C21B3 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C21C0 | 0x006C21CC | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006B5A68 | 0x006B5A6D | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BA0A0 | 0x006BA0B4 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2148 | 0x006C2154 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2118 | 0x006C2124 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2130 | 0x006C2139 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2190 | 0x006C219E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BA2E0 | 0x006BA2F0 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2160 | 0x006C216E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BA0E0 | 0x006BA0F1 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BA140 | 0x006BA152 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2178 | 0x006C2184 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BA160 | 0x006BA174 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006B6808 | 0x006B680E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BF750 | 0x006BF757 | Marked Executable | 32-bit | - |
...
|
||
b123.exe | 1 | 0x00400000 | 0x0043BFFF | Content Changed | 32-bit | 0x00416000 |
...
|
||
b123.exe | 1 | 0x00400000 | 0x0043BFFF | Content Changed | 32-bit | 0x0040838A |
...
|
||
buffer | 1 | 0x006BA1A0 | 0x006BA1B3 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006B6AE8 | 0x006B6AEF | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2370 | 0x006C237D | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C48E0 | 0x006C48F4 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2310 | 0x006C231A | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0198 | 0x006C019F | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4AA0 | 0x006C4AB7 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BF188 | 0x006BF18C | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2430 | 0x006C243B | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BA960 | 0x006BA97A | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C23A0 | 0x006C23AB | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BA988 | 0x006BA9A2 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2478 | 0x006C2483 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BAB40 | 0x006BAB5A | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C23B8 | 0x006C23C4 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BAA00 | 0x006BAA1B | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2208 | 0x006C2210 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4960 | 0x006C4977 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C22E0 | 0x006C22EC | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BAA28 | 0x006BAA43 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C47E0 | 0x006C47F0 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BAAA0 | 0x006BAABF | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BEF60 | 0x006BEF64 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BEF70 | 0x006BEF75 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BF450 | 0x006BF457 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4780 | 0x006C4791 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2448 | 0x006C2456 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2490 | 0x006C249C | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C23D0 | 0x006C23DA | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4A60 | 0x006C4A72 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4A40 | 0x006C4A54 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2220 | 0x006C222B | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2238 | 0x006C2243 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C24F0 | 0x006C24FF | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BF460 | 0x006BF464 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0EA8 | 0x006C0EAD | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2400 | 0x006C240B | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4900 | 0x006C4914 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2280 | 0x006C2289 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C22F8 | 0x006C2303 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C22C8 | 0x006C22D5 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2460 | 0x006C246B | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0E08 | 0x006C0E0E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4800 | 0x006C4814 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C23E8 | 0x006C23F2 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C24A8 | 0x006C24B6 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2328 | 0x006C2331 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2340 | 0x006C234E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2418 | 0x006C2425 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C24D8 | 0x006C24E1 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2250 | 0x006C2258 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2268 | 0x006C2270 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2298 | 0x006C22A2 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C22B0 | 0x006C22B8 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2358 | 0x006C2360 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C47A0 | 0x006C47B2 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0ED8 | 0x006C0EDB | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2550 | 0x006C255B | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4740 | 0x006C4756 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0E38 | 0x006C0E3E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2580 | 0x006C2588 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4720 | 0x006C4730 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4A80 | 0x006C4A91 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4A20 | 0x006C4A36 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C25B0 | 0x006C25BF | Marked Executable | 32-bit | - |
...
|
||
b123.exe | 1 | 0x00400000 | 0x0043BFFF | Content Changed | 32-bit | 0x00402000 |
...
|
||
buffer | 1 | 0x006C25C8 | 0x006C25D1 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2598 | 0x006C25A1 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2508 | 0x006C2514 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4820 | 0x006C4836 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2568 | 0x006C2576 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2520 | 0x006C2529 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C2538 | 0x006C2543 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4840 | 0x006C4850 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0F88 | 0x006C0F8C | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C49C0 | 0x006C49D4 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C46C0 | 0x006C46D4 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0E48 | 0x006C0E4E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BAAC8 | 0x006BAAE6 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5180 | 0x006C518A | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0E68 | 0x006C0E6F | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0EB8 | 0x006C0EBC | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0F48 | 0x006C0F4B | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5090 | 0x006C509F | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0FC8 | 0x006C0FCD | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0E58 | 0x006C0E5F | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4F28 | 0x006C4F31 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C50A8 | 0x006C50B6 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0EC8 | 0x006C0ECF | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BAAF0 | 0x006BAB09 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5168 | 0x006C5170 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5078 | 0x006C5080 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4EE0 | 0x006C4EEC | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4F70 | 0x006C4F7D | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5108 | 0x006C5110 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4880 | 0x006C4894 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4F88 | 0x006C4F91 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0EF8 | 0x006C0EFE | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0E78 | 0x006C0E7E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0F08 | 0x006C0F0E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4FE8 | 0x006C4FF3 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C51B0 | 0x006C51BA | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4EC8 | 0x006C4ED1 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4FA0 | 0x006C4FAC | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4F58 | 0x006C4F61 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4FB8 | 0x006C4FC2 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5198 | 0x006C51A4 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4F10 | 0x006C4F1B | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4EF8 | 0x006C4F03 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5018 | 0x006C5023 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5000 | 0x006C5009 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4F40 | 0x006C4F4B | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4FD0 | 0x006C4FDB | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5030 | 0x006C5039 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5138 | 0x006C5143 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5048 | 0x006C5053 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5060 | 0x006C5068 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C50C0 | 0x006C50CA | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C50D8 | 0x006C50E2 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5150 | 0x006C5158 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5120 | 0x006C512B | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C50F0 | 0x006C50FE | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5228 | 0x006C5234 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C48A0 | 0x006C48B3 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C51C8 | 0x006C51D4 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C48C0 | 0x006C48D6 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BAB18 | 0x006BAB30 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5288 | 0x006C5291 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4940 | 0x006C4954 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C51F8 | 0x006C5205 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4760 | 0x006C4774 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5210 | 0x006C521E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C51E0 | 0x006C51EC | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5240 | 0x006C524E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5258 | 0x006C5265 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C47C0 | 0x006C47D2 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5270 | 0x006C527E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5630 | 0x006C563D | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5798 | 0x006C57A1 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C49A0 | 0x006C49B4 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C55E8 | 0x006C55F1 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5618 | 0x006C5623 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5768 | 0x006C5770 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C57B0 | 0x006C57BB | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5708 | 0x006C5713 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4980 | 0x006C4994 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4920 | 0x006C4932 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C57E0 | 0x006C57ED | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5828 | 0x006C5837 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4700 | 0x006C4714 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BAB68 | 0x006BAB82 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C56A8 | 0x006C56B2 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C55D0 | 0x006C55DA | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C49E0 | 0x006C49F3 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4860 | 0x006C4874 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4A00 | 0x006C4A15 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C57C8 | 0x006C57D5 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C46E0 | 0x006C46F2 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5600 | 0x006C560B | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4BE0 | 0x006C4BF2 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4AC0 | 0x006C4AD3 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5648 | 0x006C5654 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4C40 | 0x006C4C57 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4E60 | 0x006C4E77 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C57F8 | 0x006C5800 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5810 | 0x006C5819 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5840 | 0x006C584D | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4AE0 | 0x006C4AF0 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4DA0 | 0x006C4DB0 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4B00 | 0x006C4B10 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5858 | 0x006C5866 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4B80 | 0x006C4B93 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4BC0 | 0x006C4BD0 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4B20 | 0x006C4B32 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4CC0 | 0x006C4CD0 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4CA0 | 0x006C4CB1 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5870 | 0x006C5879 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5888 | 0x006C5892 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4DC0 | 0x006C4DD5 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4B60 | 0x006C4B73 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5660 | 0x006C5669 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0E88 | 0x006C0E8D | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4CE0 | 0x006C4CF0 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4E00 | 0x006C4E10 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5678 | 0x006C5685 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C58A0 | 0x006C58AB | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5780 | 0x006C578B | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5690 | 0x006C569D | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4BA0 | 0x006C4BB0 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C58B8 | 0x006C58C3 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4D60 | 0x006C4D74 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C56C0 | 0x006C56CD | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C56D8 | 0x006C56E4 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C56F0 | 0x006C56F9 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5720 | 0x006C572D | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4C20 | 0x006C4C32 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4C80 | 0x006C4C96 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5738 | 0x006C5744 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0F18 | 0x006C0F1E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5750 | 0x006C575C | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C58D0 | 0x006C58DA | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5918 | 0x006C5922 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5A08 | 0x006C5A11 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0E18 | 0x006C0E1E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4DE0 | 0x006C4DF0 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5A80 | 0x006C5A88 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C58E8 | 0x006C58F1 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BF810 | 0x006BF831 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4D40 | 0x006C4D54 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4C00 | 0x006C4C12 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BA7F8 | 0x006BA814 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4D00 | 0x006C4D10 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BA820 | 0x006BA83B | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4D20 | 0x006C4D31 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5F10 | 0x006C5F2A | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C59C0 | 0x006C59CD | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5900 | 0x006C590E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5A68 | 0x006C5A77 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4E20 | 0x006C4E33 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4D80 | 0x006C4D90 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4C60 | 0x006C4C70 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C59A8 | 0x006C59B1 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5930 | 0x006C5938 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0E28 | 0x006C0E2F | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5948 | 0x006C5956 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4E40 | 0x006C4E50 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5960 | 0x006C596F | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5C18 | 0x006C5C30 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C4B40 | 0x006C4B54 | Marked Executable | 32-bit | - |
...
|
||
b123.exe | 1 | 0x00400000 | 0x0043BFFF | Content Changed | 32-bit | 0x00403000 |
...
|
||
buffer | 1 | 0x006C5B00 | 0x006C5B1B | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5A20 | 0x006C5A2E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5A38 | 0x006C5A47 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C6420 | 0x006C6435 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C63A0 | 0x006C63B0 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5978 | 0x006C5980 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C6660 | 0x006C6675 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C65C0 | 0x006C65D4 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5A50 | 0x006C5A5E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0F38 | 0x006C0F3C | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C5990 | 0x006C5998 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0E98 | 0x006C0E9B | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0F98 | 0x006C0F9C | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0EE8 | 0x006C0EEC | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BDB18 | 0x006BDB48 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006BDB58 | 0x006BDB7E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006B6838 | 0x006B686F | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006B6878 | 0x006B689E | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C1990 | 0x006C19B1 | Marked Executable | 32-bit | - |
...
|
||
buffer | 1 | 0x006C0F28 | 0x006C0F2E | Marked Executable | 32-bit | - |
...
|
||
b123.exe | 1 | 0x00400000 | 0x0043BFFF | Content Changed | 32-bit | 0x00416848 |
...
|
||
b123.exe | 1 | 0x00400000 | 0x0043BFFF | Content Changed | 32-bit | 0x00417000 |
...
|
||
b123.exe | 1 | 0x00400000 | 0x0043BFFF | Content Changed | 32-bit | 0x00405DC0 |
...
|
||
buffer | 1 | 0x020BF000 | 0x020BFFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x0018C000 | 0x0019FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x00510000 | 0x00538FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x00540000 | 0x00541FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x00670000 | 0x00697FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x006B69D8 | 0x006B6ADB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x006CF7E0 | 0x006D3877 | First Network Behavior | 32-bit | - |
...
|
||
counters.dat | 1 | 0x01F10000 | 0x01F10FFF | First Network Behavior | 32-bit | - |
...
|
||
b123.exe | 1 | 0x00400000 | 0x0043BFFF | Content Changed | 32-bit | 0x00414FA0 |
...
|
||
buffer | 1 | 0x60900000 | 0x60991FFF | First Execution | 32-bit | 0x60901058 |
...
|
||
buffer | 1 | 0x60900000 | 0x60991FFF | Content Changed | 32-bit | 0x6096CF94 |
...
|
||
buffer | 1 | 0x60900000 | 0x60991FFF | Content Changed | 32-bit | 0x6096D0C4 |
...
|
||
b123.exe | 1 | 0x00400000 | 0x0043BFFF | Content Changed | 32-bit | 0x0040A150 |
...
|
||
b123.exe | 1 | 0x00400000 | 0x0043BFFF | Content Changed | 32-bit | 0x0041A190 |
...
|
||
b123.exe | 1 | 0x00400000 | 0x0043BFFF | Content Changed | 32-bit | 0x00401045 |
...
|
||
b123.exe | 1 | 0x00400000 | 0x0043BFFF | Content Changed | 32-bit | 0x00411130 |
...
|
||
b123.exe | 1 | 0x00400000 | 0x0043BFFF | Content Changed | 32-bit | 0x00401045 |
...
|
||
b123.exe | 1 | 0x00400000 | 0x0043BFFF | Content Changed | 32-bit | 0x004075C0 |
...
|
||
buffer | 1 | 0x0EEE4020 | 0x0EF819F7 | Image In Buffer | 32-bit | - |
...
|
||
buffer | 1 | 0x006BF760 | 0x006BF762 | Marked Executable | 32-bit | - |
...
|
c:\lsarpc | Dropped File | Unknown |
N/A
Not Available because the file was not extracted successfully.
|
...
|
»
MIME Type | - |
File Size | - |
MD5 | - |
SHA1 | - |
SHA256 | - |
SSDeep | - |
ImpHash | - |
c:\users\rdhj0cnfevzx\appdata\local\microsoft\windows\inetcache\counters.dat | Modified File | Stream |
clean
|
...
|
»