VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Dropper
Spyware
|
Threat Names: |
Trojan.GenericKD.36387278
Trojan.GenericKD.33943728
Gen:Variant.Midie.79454
...
|
VlAaCeXOBxp2iX1i.exe
Windows Exe (x86-32)
Created at 2021-02-23T12:16:00
Remarks
(0x0200000C): The maximum memory dump size was exceeded. Some dumps may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\VlAaCeXOBxp2iX1i.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x404c05 |
Size Of Code | 0x6ae00 |
Size Of Initialized Data | 0x406e00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-01-29 15:41:03+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x6ada4 | 0x6ae00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.87 |
.rdata | 0x46c000 | 0x4923 | 0x4a00 | 0x6b200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.26 |
.data | 0x471000 | 0x3f95e8 | 0x2200 | 0x6fc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.07 |
.rsrc | 0x86b000 | 0x4e20 | 0x5000 | 0x71e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.35 |
Imports (3)
»
KERNEL32.dll (113)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetEndOfFile | 0x0 | 0x46c00c | 0x6fe10 | 0x6f010 | 0x3cd |
BuildCommDCBAndTimeoutsA | 0x0 | 0x46c010 | 0x6fe14 | 0x6f014 | 0x2c |
CallNamedPipeA | 0x0 | 0x46c014 | 0x6fe18 | 0x6f018 | 0x2f |
InterlockedDecrement | 0x0 | 0x46c018 | 0x6fe1c | 0x6f01c | 0x2bc |
SetEnvironmentVariableW | 0x0 | 0x46c01c | 0x6fe20 | 0x6f020 | 0x3d1 |
GetProfileSectionA | 0x0 | 0x46c020 | 0x6fe24 | 0x6f024 | 0x231 |
OpenSemaphoreA | 0x0 | 0x46c024 | 0x6fe28 | 0x6f028 | 0x335 |
_lclose | 0x0 | 0x46c028 | 0x6fe2c | 0x6f02c | 0x49f |
SetTapeParameters | 0x0 | 0x46c02c | 0x6fe30 | 0x6f030 | 0x402 |
ReadConsoleW | 0x0 | 0x46c030 | 0x6fe34 | 0x6f034 | 0x366 |
SetCommState | 0x0 | 0x46c034 | 0x6fe38 | 0x6f038 | 0x39f |
SetProcessPriorityBoost | 0x0 | 0x46c038 | 0x6fe3c | 0x6f03c | 0x3f8 |
GetPriorityClass | 0x0 | 0x46c03c | 0x6fe40 | 0x6f040 | 0x215 |
GetConsoleMode | 0x0 | 0x46c040 | 0x6fe44 | 0x6f044 | 0x195 |
CopyFileW | 0x0 | 0x46c044 | 0x6fe48 | 0x6f048 | 0x65 |
GetBinaryTypeA | 0x0 | 0x46c048 | 0x6fe4c | 0x6f04c | 0x158 |
TerminateProcess | 0x0 | 0x46c04c | 0x6fe50 | 0x6f050 | 0x42d |
ReadFile | 0x0 | 0x46c050 | 0x6fe54 | 0x6f054 | 0x368 |
lstrcatA | 0x0 | 0x46c054 | 0x6fe58 | 0x6f058 | 0x4a6 |
GetACP | 0x0 | 0x46c058 | 0x6fe5c | 0x6f05c | 0x152 |
lstrlenW | 0x0 | 0x46c05c | 0x6fe60 | 0x6f060 | 0x4b6 |
FindNextVolumeMountPointW | 0x0 | 0x46c060 | 0x6fe64 | 0x6f064 | 0x134 |
DisconnectNamedPipe | 0x0 | 0x46c064 | 0x6fe68 | 0x6f068 | 0xcd |
_llseek | 0x0 | 0x46c068 | 0x6fe6c | 0x6f06c | 0x4a1 |
GetStdHandle | 0x0 | 0x46c06c | 0x6fe70 | 0x6f070 | 0x23b |
FreeLibraryAndExitThread | 0x0 | 0x46c070 | 0x6fe74 | 0x6f074 | 0x14d |
GetCurrentDirectoryW | 0x0 | 0x46c074 | 0x6fe78 | 0x6f078 | 0x1a8 |
SetLastError | 0x0 | 0x46c078 | 0x6fe7c | 0x6f07c | 0x3ec |
GetProcAddress | 0x0 | 0x46c07c | 0x6fe80 | 0x6f080 | 0x220 |
MoveFileW | 0x0 | 0x46c080 | 0x6fe84 | 0x6f084 | 0x316 |
EnterCriticalSection | 0x0 | 0x46c084 | 0x6fe88 | 0x6f088 | 0xd9 |
LoadLibraryA | 0x0 | 0x46c088 | 0x6fe8c | 0x6f08c | 0x2f1 |
LocalAlloc | 0x0 | 0x46c08c | 0x6fe90 | 0x6f090 | 0x2f9 |
SetCurrentDirectoryW | 0x0 | 0x46c090 | 0x6fe94 | 0x6f094 | 0x3c7 |
AddAtomA | 0x0 | 0x46c094 | 0x6fe98 | 0x6f098 | 0x3 |
GetPrivateProfileStructA | 0x0 | 0x46c098 | 0x6fe9c | 0x6f09c | 0x21e |
GetTapeParameters | 0x0 | 0x46c09c | 0x6fea0 | 0x6f0a0 | 0x255 |
EnumResourceNamesA | 0x0 | 0x46c0a0 | 0x6fea4 | 0x6f0a4 | 0xea |
RequestWakeupLatency | 0x0 | 0x46c0a4 | 0x6fea8 | 0x6f0a8 | 0x389 |
EnumDateFormatsW | 0x0 | 0x46c0a8 | 0x6feac | 0x6f0ac | 0xe3 |
LocalFree | 0x0 | 0x46c0ac | 0x6feb0 | 0x6f0b0 | 0x2fd |
lstrcpyW | 0x0 | 0x46c0b0 | 0x6feb4 | 0x6f0b4 | 0x4b0 |
AreFileApisANSI | 0x0 | 0x46c0b4 | 0x6feb8 | 0x6f0b8 | 0x13 |
CopyFileExW | 0x0 | 0x46c0b8 | 0x6febc | 0x6f0bc | 0x62 |
RaiseException | 0x0 | 0x46c0bc | 0x6fec0 | 0x6f0c0 | 0x35a |
CreateMutexW | 0x0 | 0x46c0c0 | 0x6fec4 | 0x6f0c4 | 0x8e |
WideCharToMultiByte | 0x0 | 0x46c0c4 | 0x6fec8 | 0x6f0c8 | 0x47a |
InterlockedIncrement | 0x0 | 0x46c0c8 | 0x6fecc | 0x6f0cc | 0x2c0 |
InterlockedCompareExchange | 0x0 | 0x46c0cc | 0x6fed0 | 0x6f0d0 | 0x2ba |
InterlockedExchange | 0x0 | 0x46c0d0 | 0x6fed4 | 0x6f0d4 | 0x2bd |
MultiByteToWideChar | 0x0 | 0x46c0d4 | 0x6fed8 | 0x6f0d8 | 0x31a |
Sleep | 0x0 | 0x46c0d8 | 0x6fedc | 0x6f0dc | 0x421 |
InitializeCriticalSection | 0x0 | 0x46c0dc | 0x6fee0 | 0x6f0e0 | 0x2b4 |
DeleteCriticalSection | 0x0 | 0x46c0e0 | 0x6fee4 | 0x6f0e4 | 0xbe |
LeaveCriticalSection | 0x0 | 0x46c0e4 | 0x6fee8 | 0x6f0e8 | 0x2ef |
GetLastError | 0x0 | 0x46c0e8 | 0x6feec | 0x6f0ec | 0x1e6 |
MoveFileA | 0x0 | 0x46c0ec | 0x6fef0 | 0x6f0f0 | 0x311 |
HeapFree | 0x0 | 0x46c0f0 | 0x6fef4 | 0x6f0f4 | 0x2a1 |
HeapAlloc | 0x0 | 0x46c0f4 | 0x6fef8 | 0x6f0f8 | 0x29d |
GetCurrentProcess | 0x0 | 0x46c0f8 | 0x6fefc | 0x6f0fc | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x46c0fc | 0x6ff00 | 0x6f100 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x46c100 | 0x6ff04 | 0x6f104 | 0x415 |
IsDebuggerPresent | 0x0 | 0x46c104 | 0x6ff08 | 0x6f108 | 0x2d1 |
GetCommandLineA | 0x0 | 0x46c108 | 0x6ff0c | 0x6f10c | 0x16f |
GetStartupInfoA | 0x0 | 0x46c10c | 0x6ff10 | 0x6f110 | 0x239 |
GetCPInfo | 0x0 | 0x46c110 | 0x6ff14 | 0x6f114 | 0x15b |
RtlUnwind | 0x0 | 0x46c114 | 0x6ff18 | 0x6f118 | 0x392 |
LCMapStringW | 0x0 | 0x46c118 | 0x6ff1c | 0x6f11c | 0x2e3 |
LCMapStringA | 0x0 | 0x46c11c | 0x6ff20 | 0x6f120 | 0x2e1 |
GetStringTypeW | 0x0 | 0x46c120 | 0x6ff24 | 0x6f124 | 0x240 |
SetHandleCount | 0x0 | 0x46c124 | 0x6ff28 | 0x6f128 | 0x3e8 |
GetFileType | 0x0 | 0x46c128 | 0x6ff2c | 0x6f12c | 0x1d7 |
HeapCreate | 0x0 | 0x46c12c | 0x6ff30 | 0x6f130 | 0x29f |
VirtualFree | 0x0 | 0x46c130 | 0x6ff34 | 0x6f134 | 0x457 |
VirtualAlloc | 0x0 | 0x46c134 | 0x6ff38 | 0x6f138 | 0x454 |
HeapReAlloc | 0x0 | 0x46c138 | 0x6ff3c | 0x6f13c | 0x2a4 |
GetModuleHandleW | 0x0 | 0x46c13c | 0x6ff40 | 0x6f140 | 0x1f9 |
ExitProcess | 0x0 | 0x46c140 | 0x6ff44 | 0x6f144 | 0x104 |
WriteFile | 0x0 | 0x46c144 | 0x6ff48 | 0x6f148 | 0x48d |
GetModuleFileNameA | 0x0 | 0x46c148 | 0x6ff4c | 0x6f14c | 0x1f4 |
TlsGetValue | 0x0 | 0x46c14c | 0x6ff50 | 0x6f150 | 0x434 |
TlsAlloc | 0x0 | 0x46c150 | 0x6ff54 | 0x6f154 | 0x432 |
TlsSetValue | 0x0 | 0x46c154 | 0x6ff58 | 0x6f158 | 0x435 |
TlsFree | 0x0 | 0x46c158 | 0x6ff5c | 0x6f15c | 0x433 |
GetCurrentThreadId | 0x0 | 0x46c15c | 0x6ff60 | 0x6f160 | 0x1ad |
HeapSize | 0x0 | 0x46c160 | 0x6ff64 | 0x6f164 | 0x2a6 |
FreeEnvironmentStringsA | 0x0 | 0x46c164 | 0x6ff68 | 0x6f168 | 0x14a |
GetEnvironmentStrings | 0x0 | 0x46c168 | 0x6ff6c | 0x6f16c | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x46c16c | 0x6ff70 | 0x6f170 | 0x14b |
GetEnvironmentStringsW | 0x0 | 0x46c170 | 0x6ff74 | 0x6f174 | 0x1c1 |
QueryPerformanceCounter | 0x0 | 0x46c174 | 0x6ff78 | 0x6f178 | 0x354 |
GetTickCount | 0x0 | 0x46c178 | 0x6ff7c | 0x6f17c | 0x266 |
GetCurrentProcessId | 0x0 | 0x46c17c | 0x6ff80 | 0x6f180 | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x46c180 | 0x6ff84 | 0x6f184 | 0x24f |
GetStringTypeA | 0x0 | 0x46c184 | 0x6ff88 | 0x6f188 | 0x23d |
GetOEMCP | 0x0 | 0x46c188 | 0x6ff8c | 0x6f18c | 0x213 |
IsValidCodePage | 0x0 | 0x46c18c | 0x6ff90 | 0x6f190 | 0x2db |
GetUserDefaultLCID | 0x0 | 0x46c190 | 0x6ff94 | 0x6f194 | 0x26d |
GetLocaleInfoA | 0x0 | 0x46c194 | 0x6ff98 | 0x6f198 | 0x1e8 |
EnumSystemLocalesA | 0x0 | 0x46c198 | 0x6ff9c | 0x6f19c | 0xf8 |
IsValidLocale | 0x0 | 0x46c19c | 0x6ffa0 | 0x6f1a0 | 0x2dd |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x46c1a0 | 0x6ffa4 | 0x6f1a4 | 0x2b5 |
SetFilePointer | 0x0 | 0x46c1a4 | 0x6ffa8 | 0x6f1a8 | 0x3df |
GetConsoleCP | 0x0 | 0x46c1a8 | 0x6ffac | 0x6f1ac | 0x183 |
GetLocaleInfoW | 0x0 | 0x46c1ac | 0x6ffb0 | 0x6f1b0 | 0x1ea |
FlushFileBuffers | 0x0 | 0x46c1b0 | 0x6ffb4 | 0x6f1b4 | 0x141 |
SetStdHandle | 0x0 | 0x46c1b4 | 0x6ffb8 | 0x6f1b8 | 0x3fc |
WriteConsoleA | 0x0 | 0x46c1b8 | 0x6ffbc | 0x6f1bc | 0x482 |
GetConsoleOutputCP | 0x0 | 0x46c1bc | 0x6ffc0 | 0x6f1c0 | 0x199 |
WriteConsoleW | 0x0 | 0x46c1c0 | 0x6ffc4 | 0x6f1c4 | 0x48c |
CloseHandle | 0x0 | 0x46c1c4 | 0x6ffc8 | 0x6f1c8 | 0x43 |
CreateFileA | 0x0 | 0x46c1c8 | 0x6ffcc | 0x6f1cc | 0x78 |
GetModuleHandleA | 0x0 | 0x46c1cc | 0x6ffd0 | 0x6f1d0 | 0x1f6 |
ADVAPI32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AccessCheck | 0x0 | 0x46c000 | 0x6fe04 | 0x6f004 | 0x5 |
RevertToSelf | 0x0 | 0x46c004 | 0x6fe08 | 0x6f008 | 0x28a |
WINHTTP.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WinHttpConnect | 0x0 | 0x46c1d4 | 0x6ffd8 | 0x6f1d8 | 0x9 |
Exports (6)
»
Api name | EAT Address | Ordinal |
---|---|---|
_asdga@4 | 0x659c0 | 0x1 |
_letter@12 | 0x65980 | 0x2 |
_wedding@4 | 0x65990 | 0x3 |
_weewgg@8 | 0x659d0 | 0x4 |
_welcome@4 | 0x659a0 | 0x5 |
_yongfeng@4 | 0x659b0 | 0x6 |
Memory Dumps (26)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Relevant Image | 32-bit | 0x0040A2AD |
...
|
|||
buffer | 1 | 0x00AF63B8 | 0x00B459B7 | First Execution | 32-bit | 0x00AF63B8 |
...
|
|||
buffer | 1 | 0x00A00000 | 0x00A91FFF | First Execution | 32-bit | 0x00A00000 |
...
|
|||
buffer | 1 | 0x00A00000 | 0x00A91FFF | Content Changed | 32-bit | 0x00A004F6 |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x0043FEA3 |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x00466E45 |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x0045FEF8 |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x00417066 |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x00401000 |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x00407000 |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x00450E1E |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x00433544 |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x0041FB76 |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x00413FD7 |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x00409ED7 |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x0040E16D |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x0040B000 |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x00443AB2 |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x0046168B |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x00463F5E |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x0045567B |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x00434F64 |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x0041C05C |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x0043CAE2 |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x0046946E |
...
|
|||
vlaacexobxp2ix1i.exe | 1 | 0x00400000 | 0x0086FFFF | Content Changed | 32-bit | 0x00436ACF |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.36387278 |
Malicious
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\aR8pJ3hC8rG2sT.zip | Dropped File | ZIP |
Malicious
|
...
|
»
Archive Information
»
Number of Files | 58 |
Number of Folders | 0 |
Size of Packed Archive Contents | 2.69 MB |
Size of Unpacked Archive Contents | 5.27 MB |
File Format | zip |
Contents (58)
»
Filename | Packed Size | Unpacked Size | Compression | Is Encrypted | Modify Time | Actions |
---|---|---|---|---|---|---|
api-ms-win-core-localization-l1-2-0.dll | 10.95 KB | 20.30 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
mozMapi32_InUse.dll | 44.77 KB | 81.45 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
mozMapi32_InUse.dll | 44.77 KB | 81.45 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
ucrtbase.dll | 513.71 KB | 1.09 MB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
nss3.dll | 705.82 KB | 1.19 MB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-rtlsupport-l1-1-0.dll | 10.03 KB | 17.30 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
nssckbi.dll | 169.85 KB | 328.45 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-timezone-l1-1-0.dll | 10.15 KB | 17.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
softokn3.dll | 76.19 KB | 141.45 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
ldap60.dll | 71.57 KB | 128.95 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-synch-l1-2-0.dll | 10.33 KB | 18.30 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
msvcp140.dll | 152.47 KB | 429.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
ldif60.dll | 11.22 KB | 19.95 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-crt-convert-l1-1-0.dll | 11.39 KB | 21.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-heap-l1-1-0.dll | 10.25 KB | 17.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
prldap60.dll | 13.49 KB | 23.45 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-sysinfo-l1-1-0.dll | 10.38 KB | 18.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-crt-locale-l1-1-0.dll | 10.36 KB | 18.30 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-synch-l1-1-0.dll | 10.67 KB | 19.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
IA2Marshal.dll | 25.99 KB | 68.95 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-crt-private-l1-1-0.dll | 24.75 KB | 71.30 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-crt-multibyte-l1-1-0.dll | 12.35 KB | 25.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-crt-time-l1-1-0.dll | 10.96 KB | 20.30 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-crt-string-l1-1-0.dll | 11.66 KB | 22.94 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-crt-filesystem-l1-1-0.dll | 10.87 KB | 19.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-string-l1-1-0.dll | 10.15 KB | 17.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
qipcap.dll | 9.26 KB | 15.95 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
libEGL.dll | 11.44 KB | 21.95 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
lgpllibs.dll | 29.37 KB | 54.45 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
breakpadinjector.dll | 65.35 KB | 114.95 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-profile-l1-1-0.dll | 10.02 KB | 17.30 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-processthreads-l1-1-1.dll | 10.29 KB | 18.30 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-handle-l1-1-0.dll | 10.09 KB | 17.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-processenvironment-l1-1-0.dll | 10.34 KB | 18.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
freebl3.dll | 152.76 KB | 326.45 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-crt-conio-l1-1-0.dll | 10.43 KB | 18.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-processthreads-l1-1-0.dll | 10.41 KB | 18.94 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
mozglue.dll | 73.89 KB | 133.95 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
AccessibleHandler.dll | 62.49 KB | 120.45 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-crt-utility-l1-1-0.dll | 10.39 KB | 18.30 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-crt-stdio-l1-1-0.dll | 11.96 KB | 23.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-libraryloader-l1-1-0.dll | 10.32 KB | 18.30 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-memory-l1-1-0.dll | 10.27 KB | 18.30 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
MapiProxy_InUse.dll | 10.45 KB | 19.45 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
MapiProxy_InUse.dll | 10.45 KB | 19.45 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
nssdbm3.dll | 52.61 KB | 90.45 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-crt-math-l1-1-0.dll | 13.35 KB | 28.30 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-crt-process-l1-1-0.dll | 10.46 KB | 18.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-crt-environment-l1-1-0.dll | 10.25 KB | 18.30 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
vcruntime140.dll | 45.46 KB | 81.82 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-namedpipe-l1-1-0.dll | 10.18 KB | 17.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-file-l2-1-0.dll | 10.21 KB | 17.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-file-l1-2-0.dll | 10.10 KB | 17.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-crt-runtime-l1-1-0.dll | 11.60 KB | 22.30 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
AccessibleMarshal.dll | 13.13 KB | 25.45 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-interlocked-l1-1-0.dll | 9.78 KB | 17.44 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-crt-heap-l1-1-0.dll | 10.40 KB | 18.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
|
api-ms-win-core-util-l1-1-0.dll | 10.08 KB | 17.80 KB | Deflate | 2019-03-14 13:20 (UTC+1) |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.33943728 |
Malicious
|
C:\Users\FD1HVy\AppData\LocalLow\sqlite3.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
PE Information
»
Image Base | 0x61e00000 |
Entry Point | 0x61e01400 |
Size Of Code | 0x95a00 |
Size Of Initialized Data | 0xb0400 |
Size Of Uninitialized Data | 0xa00 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-02-25 16:34:31+00:00 |
Version Information (8)
»
CompanyName | SQLite Development Team |
FileDescription | SQLite is a software library that implements a self-contained, serverless, zero-configuration, transactional SQL database engine. |
FileVersion | 3.27.2 |
InternalName | sqlite3 |
LegalCopyright | http://www.sqlite.org/copyright.html |
ProductName | SQLite |
ProductVersion | 3.27.2 |
SourceId | 2019-02-25 16:06:06 bd49a8271d650fa89e446b42e513b595a717b9212c91dd384aab871fc1d0f6d7 |
Sections (18)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x61e01000 | 0x95858 | 0x95a00 | 0x600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.41 |
.data | 0x61e97000 | 0x1bfc | 0x1c00 | 0x96000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.79 |
.rdata | 0x61e99000 | 0x11f14 | 0x12000 | 0x97c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ | 6.39 |
.bss | 0x61eab000 | 0x828 | 0x0 | 0x0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.edata | 0x61eac000 | 0x209d | 0x2200 | 0xa9c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ | 5.31 |
.idata | 0x61eaf000 | 0xc48 | 0xe00 | 0xabe00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.88 |
.CRT | 0x61eb0000 | 0x2c | 0x200 | 0xacc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.21 |
.tls | 0x61eb1000 | 0x20 | 0x200 | 0xace00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.26 |
.rsrc | 0x61eb2000 | 0x4a8 | 0x600 | 0xad000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.85 |
.reloc | 0x61eb3000 | 0x33bc | 0x3400 | 0xad600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.52 |
/4 | 0x61eb7000 | 0x2d8 | 0x400 | 0xb0a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.87 |
/19 | 0x61eb8000 | 0x98d8 | 0x9a00 | 0xb0e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.07 |
/31 | 0x61ec2000 | 0x1af5 | 0x1c00 | 0xba800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.56 |
/45 | 0x61ec4000 | 0x1a80 | 0x1c00 | 0xbc400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.6 |
/57 | 0x61ec6000 | 0x8bc | 0xa00 | 0xbe000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.58 |
/70 | 0x61ec7000 | 0x269 | 0x400 | 0xbea00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.56 |
/81 | 0x61ec8000 | 0x1cd3 | 0x1e00 | 0xbee00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.29 |
/92 | 0x61eca000 | 0x290 | 0x400 | 0xc0c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.76 |
Imports (2)
»
KERNEL32.dll (79)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AreFileApisANSI | 0x0 | 0x61eaf1f0 | 0xaf03c | 0xabe3c | 0x15 |
CloseHandle | 0x0 | 0x61eaf1f4 | 0xaf040 | 0xabe40 | 0x53 |
CreateFileA | 0x0 | 0x61eaf1f8 | 0xaf044 | 0xabe44 | 0x8b |
CreateFileMappingA | 0x0 | 0x61eaf1fc | 0xaf048 | 0xabe48 | 0x8c |
CreateFileMappingW | 0x0 | 0x61eaf200 | 0xaf04c | 0xabe4c | 0x8f |
CreateFileW | 0x0 | 0x61eaf204 | 0xaf050 | 0xabe50 | 0x92 |
CreateMutexW | 0x0 | 0x61eaf208 | 0xaf054 | 0xabe54 | 0xa1 |
DeleteCriticalSection | 0x0 | 0x61eaf20c | 0xaf058 | 0xabe58 | 0xd4 |
DeleteFileA | 0x0 | 0x61eaf210 | 0xaf05c | 0xabe5c | 0xd6 |
DeleteFileW | 0x0 | 0x61eaf214 | 0xaf060 | 0xabe60 | 0xd9 |
EnterCriticalSection | 0x0 | 0x61eaf218 | 0xaf064 | 0xabe64 | 0xf0 |
FlushFileBuffers | 0x0 | 0x61eaf21c | 0xaf068 | 0xabe68 | 0x15a |
FlushViewOfFile | 0x0 | 0x61eaf220 | 0xaf06c | 0xabe6c | 0x15d |
FormatMessageA | 0x0 | 0x61eaf224 | 0xaf070 | 0xabe70 | 0x160 |
FormatMessageW | 0x0 | 0x61eaf228 | 0xaf074 | 0xabe74 | 0x161 |
FreeLibrary | 0x0 | 0x61eaf22c | 0xaf078 | 0xabe78 | 0x165 |
GetCurrentProcess | 0x0 | 0x61eaf230 | 0xaf07c | 0xabe7c | 0x1c5 |
GetCurrentProcessId | 0x0 | 0x61eaf234 | 0xaf080 | 0xabe80 | 0x1c6 |
GetCurrentThreadId | 0x0 | 0x61eaf238 | 0xaf084 | 0xabe84 | 0x1ca |
GetDiskFreeSpaceA | 0x0 | 0x61eaf23c | 0xaf088 | 0xabe88 | 0x1d1 |
GetDiskFreeSpaceW | 0x0 | 0x61eaf240 | 0xaf08c | 0xabe8c | 0x1d4 |
GetFileAttributesA | 0x0 | 0x61eaf244 | 0xaf090 | 0xabe90 | 0x1e7 |
GetFileAttributesExW | 0x0 | 0x61eaf248 | 0xaf094 | 0xabe94 | 0x1e9 |
GetFileAttributesW | 0x0 | 0x61eaf24c | 0xaf098 | 0xabe98 | 0x1ec |
GetFileSize | 0x0 | 0x61eaf250 | 0xaf09c | 0xabe9c | 0x1f2 |
GetFullPathNameA | 0x0 | 0x61eaf254 | 0xaf0a0 | 0xabea0 | 0x1fa |
GetFullPathNameW | 0x0 | 0x61eaf258 | 0xaf0a4 | 0xabea4 | 0x1fd |
GetLastError | 0x0 | 0x61eaf25c | 0xaf0a8 | 0xabea8 | 0x204 |
GetModuleHandleA | 0x0 | 0x61eaf260 | 0xaf0ac | 0xabeac | 0x216 |
GetProcAddress | 0x0 | 0x61eaf264 | 0xaf0b0 | 0xabeb0 | 0x246 |
GetProcessHeap | 0x0 | 0x61eaf268 | 0xaf0b4 | 0xabeb4 | 0x24b |
GetSystemInfo | 0x0 | 0x61eaf26c | 0xaf0b8 | 0xabeb8 | 0x276 |
GetSystemTime | 0x0 | 0x61eaf270 | 0xaf0bc | 0xabebc | 0x27a |
GetSystemTimeAsFileTime | 0x0 | 0x61eaf274 | 0xaf0c0 | 0xabec0 | 0x27c |
GetTempPathA | 0x0 | 0x61eaf278 | 0xaf0c4 | 0xabec4 | 0x288 |
GetTempPathW | 0x0 | 0x61eaf27c | 0xaf0c8 | 0xabec8 | 0x289 |
GetTickCount | 0x0 | 0x61eaf280 | 0xaf0cc | 0xabecc | 0x298 |
GetVersionExA | 0x0 | 0x61eaf284 | 0xaf0d0 | 0xabed0 | 0x2a7 |
GetVersionExW | 0x0 | 0x61eaf288 | 0xaf0d4 | 0xabed4 | 0x2a8 |
HeapAlloc | 0x0 | 0x61eaf28c | 0xaf0d8 | 0xabed8 | 0x2d1 |
HeapCompact | 0x0 | 0x61eaf290 | 0xaf0dc | 0xabedc | 0x2d2 |
HeapCreate | 0x0 | 0x61eaf294 | 0xaf0e0 | 0xabee0 | 0x2d3 |
HeapDestroy | 0x0 | 0x61eaf298 | 0xaf0e4 | 0xabee4 | 0x2d5 |
HeapFree | 0x0 | 0x61eaf29c | 0xaf0e8 | 0xabee8 | 0x2d7 |
HeapReAlloc | 0x0 | 0x61eaf2a0 | 0xaf0ec | 0xabeec | 0x2db |
HeapSize | 0x0 | 0x61eaf2a4 | 0xaf0f0 | 0xabef0 | 0x2dd |
HeapValidate | 0x0 | 0x61eaf2a8 | 0xaf0f4 | 0xabef4 | 0x2e1 |
InitializeCriticalSection | 0x0 | 0x61eaf2ac | 0xaf0f8 | 0xabef8 | 0x2ec |
InterlockedCompareExchange | 0x0 | 0x61eaf2b0 | 0xaf0fc | 0xabefc | 0x2f3 |
LeaveCriticalSection | 0x0 | 0x61eaf2b4 | 0xaf100 | 0xabf00 | 0x327 |
LoadLibraryA | 0x0 | 0x61eaf2b8 | 0xaf104 | 0xabf04 | 0x32a |
LoadLibraryW | 0x0 | 0x61eaf2bc | 0xaf108 | 0xabf08 | 0x32d |
LocalFree | 0x0 | 0x61eaf2c0 | 0xaf10c | 0xabf0c | 0x337 |
LockFile | 0x0 | 0x61eaf2c4 | 0xaf110 | 0xabf10 | 0x340 |
LockFileEx | 0x0 | 0x61eaf2c8 | 0xaf114 | 0xabf14 | 0x341 |
MapViewOfFile | 0x0 | 0x61eaf2cc | 0xaf118 | 0xabf18 | 0x345 |
MultiByteToWideChar | 0x0 | 0x61eaf2d0 | 0xaf11c | 0xabf1c | 0x356 |
OutputDebugStringA | 0x0 | 0x61eaf2d4 | 0xaf120 | 0xabf20 | 0x378 |
OutputDebugStringW | 0x0 | 0x61eaf2d8 | 0xaf124 | 0xabf24 | 0x379 |
QueryPerformanceCounter | 0x0 | 0x61eaf2dc | 0xaf128 | 0xabf28 | 0x397 |
ReadFile | 0x0 | 0x61eaf2e0 | 0xaf12c | 0xabf2c | 0x3b1 |
SetEndOfFile | 0x0 | 0x61eaf2e4 | 0xaf130 | 0xabf30 | 0x41c |
SetFilePointer | 0x0 | 0x61eaf2e8 | 0xaf134 | 0xabf34 | 0x42e |
SetUnhandledExceptionFilter | 0x0 | 0x61eaf2ec | 0xaf138 | 0xabf38 | 0x46c |
Sleep | 0x0 | 0x61eaf2f0 | 0xaf13c | 0xabf3c | 0x479 |
SystemTimeToFileTime | 0x0 | 0x61eaf2f4 | 0xaf140 | 0xabf40 | 0x484 |
TerminateProcess | 0x0 | 0x61eaf2f8 | 0xaf144 | 0xabf44 | 0x487 |
TlsGetValue | 0x0 | 0x61eaf2fc | 0xaf148 | 0xabf48 | 0x48e |
TryEnterCriticalSection | 0x0 | 0x61eaf300 | 0xaf14c | 0xabf4c | 0x496 |
UnhandledExceptionFilter | 0x0 | 0x61eaf304 | 0xaf150 | 0xabf50 | 0x49b |
UnlockFile | 0x0 | 0x61eaf308 | 0xaf154 | 0xabf54 | 0x49c |
UnlockFileEx | 0x0 | 0x61eaf30c | 0xaf158 | 0xabf58 | 0x49d |
UnmapViewOfFile | 0x0 | 0x61eaf310 | 0xaf15c | 0xabf5c | 0x49e |
VirtualProtect | 0x0 | 0x61eaf314 | 0xaf160 | 0xabf60 | 0x4bb |
VirtualQuery | 0x0 | 0x61eaf318 | 0xaf164 | 0xabf64 | 0x4be |
WaitForSingleObject | 0x0 | 0x61eaf31c | 0xaf168 | 0xabf68 | 0x4c7 |
WaitForSingleObjectEx | 0x0 | 0x61eaf320 | 0xaf16c | 0xabf6c | 0x4c8 |
WideCharToMultiByte | 0x0 | 0x61eaf324 | 0xaf170 | 0xabf70 | 0x4df |
WriteFile | 0x0 | 0x61eaf328 | 0xaf174 | 0xabf74 | 0x4f3 |
msvcrt.dll (28)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
__dllonexit | 0x0 | 0x61eaf330 | 0xaf17c | 0xabf7c | 0x37 |
__setusermatherr | 0x0 | 0x61eaf334 | 0xaf180 | 0xabf80 | 0x6b |
_amsg_exit | 0x0 | 0x61eaf338 | 0xaf184 | 0xabf84 | 0x8e |
_beginthreadex | 0x0 | 0x61eaf33c | 0xaf188 | 0xabf88 | 0x9b |
_endthreadex | 0x0 | 0x61eaf340 | 0xaf18c | 0xabf8c | 0xcc |
_errno | 0x0 | 0x61eaf344 | 0xaf190 | 0xabf90 | 0xcf |
_initterm | 0x0 | 0x61eaf348 | 0xaf194 | 0xabf94 | 0x12f |
_iob | 0x0 | 0x61eaf34c | 0xaf198 | 0xabf98 | 0x133 |
_lock | 0x0 | 0x61eaf350 | 0xaf19c | 0xabf9c | 0x194 |
_onexit | 0x0 | 0x61eaf354 | 0xaf1a0 | 0xabfa0 | 0x231 |
localtime | 0x0 | 0x61eaf358 | 0xaf1a4 | 0xabfa4 | 0x2bf |
calloc | 0x0 | 0x61eaf35c | 0xaf1a8 | 0xabfa8 | 0x32a |
fprintf | 0x0 | 0x61eaf360 | 0xaf1ac | 0xabfac | 0x344 |
free | 0x0 | 0x61eaf364 | 0xaf1b0 | 0xabfb0 | 0x34b |
fwrite | 0x0 | 0x61eaf368 | 0xaf1b4 | 0xabfb4 | 0x356 |
malloc | 0x0 | 0x61eaf36c | 0xaf1b8 | 0xabfb8 | 0x382 |
memcmp | 0x0 | 0x61eaf370 | 0xaf1bc | 0xabfbc | 0x389 |
memmove | 0x0 | 0x61eaf374 | 0xaf1c0 | 0xabfc0 | 0x38b |
qsort | 0x0 | 0x61eaf378 | 0xaf1c4 | 0xabfc4 | 0x398 |
realloc | 0x0 | 0x61eaf37c | 0xaf1c8 | 0xabfc8 | 0x39c |
strcmp | 0x0 | 0x61eaf380 | 0xaf1cc | 0xabfcc | 0x3b0 |
strcspn | 0x0 | 0x61eaf384 | 0xaf1d0 | 0xabfd0 | 0x3b4 |
strlen | 0x0 | 0x61eaf388 | 0xaf1d4 | 0xabfd4 | 0x3b7 |
strncmp | 0x0 | 0x61eaf38c | 0xaf1d8 | 0xabfd8 | 0x3ba |
strrchr | 0x0 | 0x61eaf390 | 0xaf1dc | 0xabfdc | 0x3be |
_unlock | 0x0 | 0x61eaf394 | 0xaf1e0 | 0xabfe0 | 0x3e6 |
abort | 0x0 | 0x61eaf398 | 0xaf1e4 | 0xabfe4 | 0x438 |
vfprintf | 0x0 | 0x61eaf39c | 0xaf1e8 | 0xabfe8 | 0x453 |
Exports (265)
»
Api name | EAT Address | Ordinal |
---|---|---|
sqlite3_aggregate_context | 0x1cfd1 | 0x1 |
sqlite3_aggregate_count | 0x3269 | 0x2 |
sqlite3_auto_extension | 0x90b9b | 0x3 |
sqlite3_backup_finish | 0x48a41 | 0x4 |
sqlite3_backup_init | 0x48595 | 0x5 |
sqlite3_backup_pagecount | 0x2dd3 | 0x6 |
sqlite3_backup_remaining | 0x2dc8 | 0x7 |
sqlite3_backup_step | 0x46614 | 0x8 |
sqlite3_bind_blob | 0x285a8 | 0x9 |
sqlite3_bind_blob64 | 0x285cf | 0xa |
sqlite3_bind_double | 0x286d1 | 0xb |
sqlite3_bind_int | 0x28785 | 0xc |
sqlite3_bind_int64 | 0x28736 | 0xd |
sqlite3_bind_null | 0x287ab | 0xe |
sqlite3_bind_parameter_count | 0x32a7 | 0xf |
sqlite3_bind_parameter_index | 0x14101 | 0x10 |
sqlite3_bind_parameter_name | 0x32b9 | 0x11 |
sqlite3_bind_pointer | 0x287dc | 0x12 |
sqlite3_bind_text | 0x28616 | 0x13 |
sqlite3_bind_text16 | 0x286aa | 0x14 |
sqlite3_bind_text64 | 0x2863d | 0x15 |
sqlite3_bind_value | 0x288c6 | 0x16 |
sqlite3_bind_zeroblob | 0x28859 | 0x17 |
sqlite3_bind_zeroblob64 | 0x289ad | 0x18 |
sqlite3_blob_bytes | 0x336c | 0x19 |
sqlite3_blob_close | 0x49c3d | 0x1a |
sqlite3_blob_open | 0x7db1d | 0x1b |
sqlite3_blob_read | 0x4b75a | 0x1c |
sqlite3_blob_reopen | 0x7e28c | 0x1d |
sqlite3_blob_write | 0x4c52b | 0x1e |
sqlite3_busy_handler | 0x51bb | 0x1f |
sqlite3_busy_timeout | 0xc01e | 0x20 |
sqlite3_cancel_auto_extension | 0x3e6a | 0x21 |
sqlite3_changes | 0x50d5 | 0x22 |
sqlite3_clear_bindings | 0x10449 | 0x23 |
sqlite3_close | 0x48c3b | 0x24 |
sqlite3_close_v2 | 0x48c49 | 0x25 |
sqlite3_collation_needed | 0x54dd | 0x26 |
sqlite3_collation_needed16 | 0x5521 | 0x27 |
sqlite3_column_blob | 0x22a25 | 0x28 |
sqlite3_column_bytes | 0x227fb | 0x29 |
sqlite3_column_bytes16 | 0x228cf | 0x2a |
sqlite3_column_count | 0x3277 | 0x2b |
sqlite3_column_database_name | 0xa836 | 0x2c |
sqlite3_column_database_name16 | 0xa851 | 0x2d |
sqlite3_column_decltype | 0xa800 | 0x2e |
sqlite3_column_decltype16 | 0xa81b | 0x2f |
sqlite3_column_double | 0x182be | 0x30 |
sqlite3_column_int | 0x100af | 0x31 |
sqlite3_column_int64 | 0x100db | 0x32 |
sqlite3_column_name | 0xa7ca | 0x33 |
sqlite3_column_name16 | 0xa7e5 | 0x34 |
sqlite3_column_origin_name | 0xa8a2 | 0x35 |
sqlite3_column_origin_name16 | 0xa8bd | 0x36 |
sqlite3_column_table_name | 0xa86c | 0x37 |
sqlite3_column_table_name16 | 0xa887 | 0x38 |
sqlite3_column_text | 0x22c40 | 0x39 |
sqlite3_column_text16 | 0x24166 | 0x3a |
sqlite3_column_type | 0x1018f | 0x3b |
sqlite3_column_value | 0x1015d | 0x3c |
sqlite3_commit_hook | 0x538d | 0x3d |
sqlite3_compileoption_get | 0x55f7 | 0x3e |
sqlite3_compileoption_used | 0x8cf2 | 0x3f |
sqlite3_complete | 0x4d99 | 0x40 |
sqlite3_complete16 | 0x90d41 | 0x41 |
sqlite3_config | 0x18b34 | 0x42 |
sqlite3_context_db_handle | 0x3206 | 0x43 |
sqlite3_create_collation | 0x291df | 0x44 |
sqlite3_create_collation16 | 0x29216 | 0x45 |
sqlite3_create_collation_v2 | 0x29188 | 0x46 |
sqlite3_create_function | 0x28ed3 | 0x47 |
sqlite3_create_function16 | 0x28fa5 | 0x48 |
sqlite3_create_function_v2 | 0x28f1a | 0x49 |
sqlite3_create_module | 0x25458 | 0x4a |
sqlite3_create_module_v2 | 0x25477 | 0x4b |
sqlite3_create_window_function | 0x28f60 | 0x4c |
sqlite3_data_count | 0x328c | 0x4d |
sqlite3_data_directory | 0xab020 | 0x4e |
sqlite3_db_cacheflush | 0x4604e | 0x4f |
sqlite3_db_config | 0x1434e | 0x50 |
sqlite3_db_filename | 0x10ae1 | 0x51 |
sqlite3_db_handle | 0x32d6 | 0x52 |
sqlite3_db_mutex | 0x502a | 0x53 |
sqlite3_db_readonly | 0x55d4 | 0x54 |
sqlite3_db_release_memory | 0x13d4e | 0x55 |
sqlite3_db_status | 0x15600 | 0x56 |
sqlite3_declare_vtab | 0x74e3f | 0x57 |
sqlite3_enable_load_extension | 0x18aee | 0x58 |
sqlite3_enable_shared_cache | 0x2885 | 0x59 |
sqlite3_errcode | 0x282dc | 0x5a |
sqlite3_errmsg | 0x2834f | 0x5b |
sqlite3_errmsg16 | 0x29291 | 0x5c |
sqlite3_errstr | 0xc015 | 0x5d |
sqlite3_exec | 0x62fbd | 0x5e |
sqlite3_expanded_sql | 0x316e7 | 0x5f |
sqlite3_expired | 0x3182 | 0x60 |
sqlite3_extended_errcode | 0x28317 | 0x61 |
sqlite3_extended_result_codes | 0x5576 | 0x62 |
sqlite3_file_control | 0x13f68 | 0x63 |
sqlite3_finalize | 0x49b4c | 0x64 |
sqlite3_free | 0x9d7b | 0x65 |
sqlite3_free_table | 0x9f3f | 0x66 |
sqlite3_fts3_may_be_corrupt | 0x98540 | 0x67 |
sqlite3_fts5_may_be_corrupt | 0x98418 | 0x68 |
sqlite3_get_autocommit | 0x5565 | 0x69 |
sqlite3_get_auxdata | 0x322e | 0x6a |
sqlite3_get_table | 0x769cb | 0x6b |
sqlite3_global_recover | 0x91b97 | 0x6c |
sqlite3_initialize | 0x18d2b | 0x6d |
sqlite3_interrupt | 0x527e | 0x6e |
sqlite3_keyword_check | 0x106d6 | 0x6f |
sqlite3_keyword_count | 0x48da | 0x70 |
sqlite3_keyword_name | 0x48a5 | 0x71 |
sqlite3_last_insert_rowid | 0x5092 | 0x72 |
sqlite3_libversion | 0x500c | 0x73 |
sqlite3_libversion_number | 0x5016 | 0x74 |
sqlite3_limit | 0x54a6 | 0x75 |
sqlite3_load_extension | 0x39c8b | 0x76 |
sqlite3_log | 0x251b7 | 0x77 |
sqlite3_malloc | 0x19270 | 0x78 |
sqlite3_malloc64 | 0x19b3a | 0x79 |
sqlite3_memory_alarm | 0x1850c | 0x7a |
sqlite3_memory_highwater | 0x253a6 | 0x7b |
sqlite3_memory_used | 0x25376 | 0x7c |
sqlite3_mprintf | 0x386e4 | 0x7d |
sqlite3_msize | 0x1799 | 0x7e |
sqlite3_mutex_alloc | 0x19241 | 0x7f |
sqlite3_mutex_enter | 0x1743 | 0x80 |
sqlite3_mutex_free | 0x1730 | 0x81 |
sqlite3_mutex_leave | 0x176b | 0x82 |
sqlite3_mutex_try | 0x1756 | 0x83 |
sqlite3_next_stmt | 0x331f | 0x84 |
sqlite3_open | 0x91aca | 0x85 |
sqlite3_open16 | 0x91afd | 0x86 |
sqlite3_open_v2 | 0x91ae5 | 0x87 |
sqlite3_os_end | 0x18add | 0x88 |
sqlite3_os_init | 0x1917a | 0x89 |
sqlite3_overload_function | 0x3a40c | 0x8a |
sqlite3_prepare | 0x71d36 | 0x8b |
sqlite3_prepare16 | 0x72921 | 0x8c |
sqlite3_prepare16_v2 | 0x72948 | 0x8d |
sqlite3_prepare16_v3 | 0x7296f | 0x8e |
sqlite3_prepare_v2 | 0x71f09 | 0x8f |
sqlite3_prepare_v3 | 0x72219 | 0x90 |
sqlite3_profile | 0x5339 | 0x91 |
sqlite3_progress_handler | 0x5210 | 0x92 |
sqlite3_randomness | 0x3cd83 | 0x93 |
sqlite3_realloc | 0x1b913 | 0x94 |
sqlite3_realloc64 | 0x1cd49 | 0x95 |
sqlite3_release_memory | 0x1788 | 0x96 |
sqlite3_reset | 0x4c5c9 | 0x97 |
sqlite3_reset_auto_extension | 0x90c2d | 0x98 |
sqlite3_result_blob | 0x1e411 | 0x99 |
sqlite3_result_blob64 | 0x1e96d | 0x9a |
sqlite3_result_double | 0x13bc9 | 0x9b |
sqlite3_result_error | 0x1dabb | 0x9c |
sqlite3_result_error16 | 0x1dfa1 | 0x9d |
sqlite3_result_error_code | 0x1dfca | 0x9e |
sqlite3_result_error_nomem | 0x10274 | 0x9f |
sqlite3_result_error_toobig | 0x1e32d | 0xa0 |
sqlite3_result_int | 0x10200 | 0xa1 |
sqlite3_result_int64 | 0x1023b | 0xa2 |
sqlite3_result_null | 0x10266 | 0xa3 |
sqlite3_result_pointer | 0x106fc | 0xa4 |
sqlite3_result_subtype | 0x31e2 | 0xa5 |
sqlite3_result_text | 0x1e4d2 | 0xa6 |
sqlite3_result_text16 | 0x1e967 | 0xa7 |
sqlite3_result_text16be | 0x1e929 | 0xa8 |
sqlite3_result_text16le | 0x1e948 | 0xa9 |
sqlite3_result_text64 | 0x1e9a9 | 0xaa |
sqlite3_result_value | 0x1f419 | 0xab |
sqlite3_result_zeroblob | 0x10be9 | 0xac |
sqlite3_result_zeroblob64 | 0x104b9 | 0xad |
sqlite3_rollback_hook | 0x5411 | 0xae |
sqlite3_rtree_geometry_callback | 0x91b9e | 0xaf |
sqlite3_rtree_query_callback | 0x91c1c | 0xb0 |
sqlite3_set_authorizer | 0x3912 | 0xb1 |
sqlite3_set_auxdata | 0x11b80 | 0xb2 |
sqlite3_set_last_insert_rowid | 0x50a0 | 0xb3 |
sqlite3_shutdown | 0x90c80 | 0xb4 |
sqlite3_sleep | 0x190e0 | 0xb5 |
sqlite3_snprintf | 0x2248e | 0xb6 |
sqlite3_soft_heap_limit | 0x37bdc | 0xb7 |
sqlite3_soft_heap_limit64 | 0x37b38 | 0xb8 |
sqlite3_sourceid | 0x7b8e | 0xb9 |
sqlite3_sql | 0x3358 | 0xba |
sqlite3_status | 0x2531e | 0xbb |
sqlite3_status64 | 0x2528e | 0xbc |
sqlite3_step | 0x62355 | 0xbd |
sqlite3_stmt_busy | 0x3300 | 0xbe |
sqlite3_stmt_readonly | 0x32e6 | 0xbf |
sqlite3_stmt_status | 0x1372f | 0xc0 |
sqlite3_str_append | 0x20e27 | 0xc1 |
sqlite3_str_appendall | 0x20e5c | 0xc2 |
sqlite3_str_appendchar | 0x20d83 | 0xc3 |
sqlite3_str_appendf | 0x28a1c | 0xc4 |
sqlite3_str_errcode | 0x17b8 | 0xc5 |
sqlite3_str_finish | 0x11da6 | 0xc6 |
sqlite3_str_length | 0x17cd | 0xc7 |
sqlite3_str_new | 0x19b60 | 0xc8 |
sqlite3_str_reset | 0xf982 | 0xc9 |
sqlite3_str_value | 0x17de | 0xca |
sqlite3_str_vappendf | 0x20ff6 | 0xcb |
sqlite3_strglob | 0x99be | 0xcc |
sqlite3_stricmp | 0x196b | 0xcd |
sqlite3_strlike | 0x99d9 | 0xce |
sqlite3_strnicmp | 0x1991 | 0xcf |
sqlite3_system_errno | 0x5495 | 0xd0 |
sqlite3_table_column_metadata | 0x766e4 | 0xd1 |
sqlite3_temp_directory | 0xab024 | 0xd2 |
sqlite3_test_control | 0x90653 | 0xd3 |
sqlite3_thread_cleanup | 0x5571 | 0xd4 |
sqlite3_threadsafe | 0x5020 | 0xd5 |
sqlite3_total_changes | 0x50e0 | 0xd6 |
sqlite3_trace | 0x5290 | 0xd7 |
sqlite3_trace_v2 | 0x52e1 | 0xd8 |
sqlite3_transfer_bindings | 0x10599 | 0xd9 |
sqlite3_update_hook | 0x53cf | 0xda |
sqlite3_uri_boolean | 0x8cbf | 0xdb |
sqlite3_uri_int64 | 0xe89b | 0xdc |
sqlite3_uri_parameter | 0x8c6d | 0xdd |
sqlite3_user_data | 0x31f8 | 0xde |
sqlite3_value_blob | 0x2296e | 0xdf |
sqlite3_value_bytes | 0x227ed | 0xe0 |
sqlite3_value_bytes16 | 0x228be | 0xe1 |
sqlite3_value_double | 0x182b5 | 0xe2 |
sqlite3_value_dup | 0x1f1ea | 0xe3 |
sqlite3_value_free | 0x10687 | 0xe4 |
sqlite3_value_int | 0xb0c7 | 0xe5 |
sqlite3_value_int64 | 0xb0d4 | 0xe6 |
sqlite3_value_nochange | 0x31c9 | 0xe7 |
sqlite3_value_numeric_type | 0x18353 | 0xe8 |
sqlite3_value_pointer | 0xe6e6 | 0xe9 |
sqlite3_value_subtype | 0x319f | 0xea |
sqlite3_value_text | 0x22935 | 0xeb |
sqlite3_value_text16 | 0x24192 | 0xec |
sqlite3_value_text16be | 0x24144 | 0xed |
sqlite3_value_text16le | 0x24155 | 0xee |
sqlite3_value_type | 0x31b4 | 0xef |
sqlite3_version | 0xaa660 | 0xf0 |
sqlite3_vfs_find | 0x1907d | 0xf1 |
sqlite3_vfs_register | 0x19117 | 0xf2 |
sqlite3_vfs_unregister | 0x19201 | 0xf3 |
sqlite3_vmprintf | 0x37c00 | 0xf4 |
sqlite3_vsnprintf | 0x22432 | 0xf5 |
sqlite3_vtab_collation | 0x2b98e | 0xf6 |
sqlite3_vtab_config | 0x25495 | 0xf7 |
sqlite3_vtab_nochange | 0x3213 | 0xf8 |
sqlite3_vtab_on_conflict | 0x4134 | 0xf9 |
sqlite3_wal_autocheckpoint | 0xc074 | 0xfa |
sqlite3_wal_checkpoint | 0x491b7 | 0xfb |
sqlite3_wal_checkpoint_v2 | 0x49173 | 0xfc |
sqlite3_wal_hook | 0x5453 | 0xfd |
sqlite3_win32_is_nt | 0x18690 | 0xfe |
sqlite3_win32_mbcs_to_utf8 | 0x90a3c | 0xff |
sqlite3_win32_mbcs_to_utf8_v2 | 0x90a65 | 0x100 |
sqlite3_win32_set_directory | 0x90b95 | 0x101 |
sqlite3_win32_set_directory16 | 0x90b49 | 0x102 |
sqlite3_win32_set_directory8 | 0x90ada | 0x103 |
sqlite3_win32_sleep | 0x18575 | 0x104 |
sqlite3_win32_unicode_to_utf8 | 0x90a1b | 0x105 |
sqlite3_win32_utf8_to_mbcs | 0x90a8b | 0x106 |
sqlite3_win32_utf8_to_mbcs_v2 | 0x90ab4 | 0x107 |
sqlite3_win32_utf8_to_unicode | 0x909fa | 0x108 |
sqlite3_win32_write_debug | 0x18513 | 0x109 |
C:\Users\FD1HVy\AppData\LocalLow\frAQBc8Wsa | Dropped File | Sqlite |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\nssdbm3.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\prldap60.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\qipcap.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\softokn3.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\ucrtbase.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\vcruntime140.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\AccessibleHandler.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\AccessibleMarshal.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\breakpadinjector.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\freebl3.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\IA2Marshal.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\ldap60.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\ldif60.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\lgpllibs.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\libEGL.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\MapiProxy_InUse.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\mozglue.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\mozMapi32_InUse.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\msvcp140.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\nss3.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\nssckbi.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-namedpipe-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-processenvironment-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-processthreads-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-processthreads-l1-1-1.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-profile-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-rtlsupport-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-string-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-synch-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-synch-l1-2-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-sysinfo-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-timezone-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-util-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-crt-conio-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-crt-convert-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-crt-environment-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-crt-filesystem-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-crt-heap-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-crt-locale-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-crt-math-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-crt-multibyte-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-crt-private-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-crt-process-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-crt-runtime-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-crt-stdio-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-crt-string-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-crt-time-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-crt-utility-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-file-l1-2-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-file-l2-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-handle-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-heap-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-interlocked-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-libraryloader-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-localization-l1-2-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\eE8sF0yG2eQ6fT7\api-ms-win-core-memory-l1-1-0.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\k5Hs0kIB2-shm | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\LocalLow\RYwTiizs2t | Dropped File | Sqlite |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\LocalLow\rQF69AzBla | Dropped File | Sqlite |
Unknown
|
...
|
»
mails/outlook.txt | Embedded File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\LocalLow\frAQBc8Ws | Dropped File | Sqlite |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\LocalLow\k5Hs0kIB2 | Dropped File | Sqlite |
Unknown
|
...
|
»
browsers/firefox_urls.txt | Embedded File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\LocalLow\v8iyIu0Ytni.zip | Dropped File | ZIP |
Unknown
|
...
|
»
Archive Information
»
Number of Files | 4 |
Number of Folders | 3 |
Size of Packed Archive Contents | 3.50 KB |
Size of Unpacked Archive Contents | 8.08 KB |
File Format | zip |
Contents (4)
»
Filename | Packed Size | Unpacked Size | Compression | Is Encrypted | Modify Time | Actions |
---|---|---|---|---|---|---|
browsers/cookies/Firefox_w7cr0hor.default.txt | 2.43 KB | 5.88 KB | Deflate | 2021-02-23 14:19 (UTC+1) |
...
|
|
browsers/firefox_urls.txt | 382 Bytes | 1.09 KB | Deflate | 2021-02-23 14:19 (UTC+1) |
...
|
|
System Info.txt | 628 Bytes | 1.00 KB | Deflate | 2021-02-23 14:19 (UTC+1) |
...
|
|
mails/outlook.txt | 82 Bytes | 105 Bytes | Deflate | 2021-02-23 14:19 (UTC+1) |
...
|
browsers/cookies/Firefox_w7cr0hor.default.txt | Embedded File | Text |
Unknown
|
...
|
»