| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| Compilation Date | 2017-Apr-29 07:14:49 |
| Detected languages |
English - United States
|
| Debug artifacts |
crypt32.pdb
|
| CompanyName | Microsoft Corporation |
| FileDescription | Crypto API32 |
| FileVersion | 10.0.15063.1058 (WinBuild.160101.0800) |
| InternalName | CRYPT32.DLL |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | CRYPT32.DLL |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion | 10.0.15063.1058 |
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
May have dropper capabilities:
|
| Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
| Info | The PE's resources present abnormal characteristics. | Resource 1010 is possibly compressed or encrypted. |
| Info | The PE is digitally signed. |
Signer: Microsoft Windows
Issuer: Microsoft Windows Production PCA 2011 |
| Safe | VirusTotal score: 0/62 (Scanned on 2021-09-15 03:38:12) | All the AVs think this file is safe. |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x108 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 7 |
| TimeDateStamp | 2017-Apr-29 07:14:49 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_DLL
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0xf4200 |
| SizeOfInitializedData | 0xcfc00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x0000000000059DD0 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x180000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | A.0 |
| ImageVersion | A.0 |
| SubsystemVersion | A.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x1c9000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0x1c5e62 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
|
| SizeofStackReserve | 0x40000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| api-ms-win-crt-runtime-l1-1-0.dll |
_initterm
_initterm_e |
|---|---|
| api-ms-win-crt-private-l1-1-0.dll |
_o__itoa_s
_o__itow _o__ltoa _o__ltow _o__register_onexit_function _o__seh_filter_dll _o__ultoa_s _o__ultow_s _o__initialize_narrow_environment _o__wcsicmp memcpy _o_atol _o_bsearch _o_free _o_isdigit _o_isupper _o_iswalnum _o_iswalpha _o_iswspace _o_isxdigit _o_memset _o_qsort _o_qsort_s _o_strtoul _o_toupper _o_towlower _o_wcstoul __C_specific_handler _o__execute_onexit_table _o__crt_atexit _o__configure_narrow_argv _o__cexit _o__initialize_onexit_table _o___std_type_info_destroy_list memcmp |
| api-ms-win-core-errorhandling-l1-1-1.dll |
GetLastError
SetUnhandledExceptionFilter UnhandledExceptionFilter SetLastError |
| api-ms-win-core-synch-l1-2-0.dll |
InitOnceExecuteOnce
ReleaseSRWLockExclusive AcquireSRWLockShared ReleaseSRWLockShared InitializeSRWLock AcquireSRWLockExclusive InitializeCriticalSection WaitForMultipleObjectsEx InitializeCriticalSectionAndSpinCount CreateEventA EnterCriticalSection DeleteCriticalSection Sleep WaitForSingleObjectEx SetEvent WaitForSingleObject LeaveCriticalSection |
| api-ms-win-core-registry-l1-1-0.dll |
RegCloseKey
RegCreateKeyExA RegQueryValueExA RegSetKeySecurity RegEnumKeyExW RegDeleteKeyExW RegDeleteValueW RegEnumValueW RegSetValueExA RegCreateKeyExW RegNotifyChangeKeyValue RegQueryInfoKeyW RegQueryValueExW RegOpenKeyExW RegSetValueExW RegEnumKeyExA RegLoadMUIStringW RegGetKeySecurity RegOpenKeyExA |
| api-ms-win-core-processenvironment-l1-2-0.dll |
ExpandEnvironmentStringsW
GetEnvironmentVariableA |
| api-ms-win-core-heap-l2-1-0.dll |
LocalAlloc
LocalReAlloc LocalFree |
| api-ms-win-core-version-l1-1-0.dll |
VerQueryValueW
GetFileVersionInfoExW GetFileVersionInfoSizeExW |
| api-ms-win-core-rtlsupport-l1-2-0.dll |
RtlLookupFunctionEntry
RtlVirtualUnwind RtlCaptureContext |
| api-ms-win-core-debug-l1-1-1.dll |
IsDebuggerPresent
OutputDebugStringA |
| api-ms-win-core-processthreads-l1-1-2.dll |
OpenThreadToken
IsProcessorFeaturePresent GetCurrentProcessId OpenProcessToken GetCurrentThreadId TerminateProcess TlsAlloc SetThreadToken TlsGetValue GetCurrentProcess CreateThread ExitThread TlsSetValue GetCurrentThread SetThreadStackGuarantee TlsFree |
| api-ms-win-core-profile-l1-1-0.dll |
QueryPerformanceFrequency
QueryPerformanceCounter |
| api-ms-win-core-sysinfo-l1-2-1.dll |
GetLocalTime
GetSystemTime GetSystemInfo GetVersionExA GetSystemTimeAsFileTime GetTickCount64 |
| api-ms-win-core-interlocked-l1-2-0.dll |
InitializeSListHead
|
| api-ms-win-core-libraryloader-l1-2-0.dll |
LockResource
SizeofResource LoadResource FreeResource LoadStringW GetModuleFileNameW LoadLibraryExW GetModuleHandleW FreeLibrary GetProcAddress FreeLibraryAndExitThread |
| api-ms-win-core-file-l1-2-1.dll |
ReadFile
GetFileAttributesExW GetFileAttributesW SetEndOfFile GetFileSize WriteFile SetFilePointer CreateFileW CreateDirectoryW DeleteFileW FindFirstFileW FindNextFileW FindClose FindNextChangeNotification FindCloseChangeNotification FindFirstChangeNotificationW FileTimeToLocalFileTime SetFileAttributesW GetTempPathW GetTempFileNameW CompareFileTime |
| api-ms-win-eventing-provider-l1-1-0.dll |
EventWriteTransfer
EventRegister EventUnregister EventSetInformation |
| api-ms-win-core-localization-l1-2-1.dll |
FormatMessageW
IdnToAscii IdnToUnicode GetACP |
| api-ms-win-core-string-l1-1-0.dll |
WideCharToMultiByte
MultiByteToWideChar CompareStringW |
| api-ms-win-security-base-l1-2-0.dll |
MakeAbsoluteSD
AddAccessAllowedAce InitializeAcl GetSecurityDescriptorSacl EqualSid GetAce SetSecurityDescriptorDacl MakeSelfRelativeSD AdjustTokenPrivileges GetSecurityDescriptorOwner InitializeSecurityDescriptor SetSecurityDescriptorOwner SetSecurityDescriptorGroup CheckTokenMembership GetTokenInformation GetSidIdentifierAuthority GetLengthSid IsValidSid AddAce AddAccessAllowedAceEx GetAclInformation CopySid GetSidSubAuthority GetSidSubAuthorityCount ImpersonateSelf RevertToSelf AccessCheck AllocateAndInitializeSid SetFileSecurityW GetFileSecurityW CheckTokenCapability FreeSid GetSecurityDescriptorDacl |
| api-ms-win-core-handle-l1-1-0.dll |
DuplicateHandle
CloseHandle |
| api-ms-win-core-psapi-l1-1-0.dll |
QueryFullProcessImageNameW
|
| api-ms-win-core-timezone-l1-1-0.dll |
SystemTimeToFileTime
FileTimeToSystemTime |
| api-ms-win-core-libraryloader-l1-2-2.dll |
LoadLibraryA
|
| api-ms-win-core-datetime-l1-1-1.dll |
GetTimeFormatA
GetTimeFormatW GetDateFormatA GetDateFormatW |
| api-ms-win-core-memory-l1-1-2.dll |
VirtualAlloc
UnmapViewOfFile VirtualQuery MapViewOfFile VirtualProtect |
| api-ms-win-core-threadpool-l1-2-0.dll |
CreateThreadpoolTimer
SetThreadpoolTimer WaitForThreadpoolTimerCallbacks CloseThreadpoolTimer |
| api-ms-win-core-threadpool-private-l1-1-0.dll |
RegisterWaitForSingleObjectEx
|
| api-ms-win-security-grouppolicy-l1-1-0.dll |
RegisterGPNotificationInternal
UnregisterGPNotificationInternal |
| MSASN1.dll |
ASN1objectidentifier2_cmp
ASN1_SetEncoderOption ASN1open_free ASN1BERDecObjectIdentifier2 ASN1BERDecOpenType ASN1BEREncObjectIdentifier2 ASN1BERDecOctetString ASN1octetstring_free ASN1ztcharstring_free ASN1BERDecEoid ASN1bitstring_free ASN1BERDecCharString ASN1_CreateModule ASN1BERDecNull ASN1DEREncChar32String ASN1BERDecU32Val ASN1utf8string_free ASN1BERDecOctetString2 ASN1DEREncBitString ASN1DEREncBeginBlk ASN1intx_free ASN1BERDecZeroCharString ASN1BERDecUTCTime ASN1BERDecBitString2 ASN1DEREncChar16String ASN1BERDecBitString ASN1charstring_free ASN1DEREncOctetString ASN1BERDecS32Val ASN1BERDecUTF8String ASN1BERDecChar32String ASN1BEREncOpenType ASN1BEREncEoid ASN1BEREncSX ASN1BERDecChar16String ASN1char32string_free ASN1BERDecMultibyteString ASN1BEREoid_free ASN1_CloseModule ASN1DEREncMultibyteString ASN1BEREncNull ASN1BEREncBool ASN1BEREncEndOfContents ASN1DEREncEndBlk ASN1DEREncCharString ASN1DEREncUTF8String ASN1BEREncS32 ASN1EncSetError ASN1DecRealloc ASN1BERDecBool ASN1BERDecEndOfContents ASN1BEREncExplicitTag ASN1BERDecNotEndOfContents ASN1DEREncNewBlkElement ASN1BEREncU32 ASN1char16string_free ASN1DEREncFlushBlkElement ASN1BERDecPeekTag ASN1BERDecGeneralizedTime ASN1DEREncGeneralizedTime ASN1BERDecExplicitTag ASN1DecSetError ASN1BERDecSXVal ASN1BEREncRemoveZeroBits ASN1BERDecOpenType2 ASN1DEREncUTCTime ASN1BERDecU16Val ASN1BERDotVal2Eoid ASN1Free ASN1BEREoid2DotVal ASN1_CreateDecoder ASN1_CreateEncoder ASN1_CloseDecoder ASN1_CloseEncoder ASN1_FreeEncoded ASN1_FreeDecoded ASN1_Encode ASN1_Decode |
| api-ms-win-core-threadpool-legacy-l1-1-0.dll |
UnregisterWaitEx
|
| api-ms-win-core-kernel32-legacy-l1-1-1.dll |
CreateFileMappingA
FindResourceExA GetComputerNameW |
| api-ms-win-core-heap-obsolete-l1-1-0.dll |
LocalSize
|
| api-ms-win-core-localization-obsolete-l1-3-0.dll |
GetSystemDefaultUILanguage
GetUserDefaultUILanguage CompareStringA |
| api-ms-win-core-string-obsolete-l1-1-0.dll |
lstrcmpA
lstrlenW lstrcmpiW lstrlenA |
| ntdll.dll |
EvtIntReportEventAndSourceAsync
strchr EtwTraceMessage WinSqmIncrementDWORD memmove RtlAllocateHeap RtlImageNtHeader RtlFreeHeap RtlGetDeviceFamilyInfoEnum NtQuerySystemInformation RtlNtStatusToDosError wcsncmp RtlCreateUnicodeStringFromAsciiz wcsstr RtlIpv6StringToAddressExW RtlIpv4StringToAddressExW A_SHAFinal A_SHAUpdate A_SHAInit MD5Final MD5Update MD5Init NtQueryObject wcschr NtQueryInformationFile EtwEventWriteFull EtwEventUnregister EtwEventRegister wcsrchr _vsnwprintf strncmp _vsnprintf EtwUnregisterTraceGuids EtwGetTraceEnableFlags ShipAssert EtwGetTraceLoggerHandle EtwGetTraceEnableLevel EtwRegisterTraceGuidsW RtlFreeUnicodeString |
| api-ms-win-core-delayload-l1-1-1.dll |
ResolveDelayLoadedAPI
DelayLoadFailureHook |
| api-ms-win-crt-string-l1-1-0.dll |
wcscmp
strcmp |
| api-ms-win-power-setting-l1-1-0.dll (delay-loaded) |
PowerSettingUnregisterNotification
PowerSettingRegisterNotification |
| Attributes | 0x1 |
|---|---|
| Name | api-ms-win-power-setting-l1-1-0.dll |
| ModuleHandle | 0x12eef0 |
| DelayImportAddressTable | 0x1431a0 |
| DelayImportNameTable | 0x126670 |
| BoundDelayImportTable | 0x127098 |
| UnloadDelayImportTable | 0 |
| TimeStamp | 1970-Jan-01 00:00:00 |
| Ordinal | 1001 |
|---|---|
| Address | 0x59a40 |
| Ordinal | 1002 |
|---|---|
| Address | 0x784c0 |
| Ordinal | 1003 |
|---|---|
| Address | 0x78090 |
| Ordinal | 1004 |
|---|---|
| Address | 0x78080 |
| Ordinal | 1005 |
|---|---|
| Address | 0x78120 |
| Ordinal | 1006 |
|---|---|
| Address | 0x78110 |
| Ordinal | 1007 |
|---|---|
| Address | 0x78030 |
| Ordinal | 1008 |
|---|---|
| Address | 0x78070 |
| Ordinal | 1009 |
|---|---|
| Address | 0x780d0 |
| Ordinal | 1010 |
|---|---|
| Address | 0x78100 |
| Ordinal | 1011 |
|---|---|
| Address | 0x78020 |
| Ordinal | 1012 |
|---|---|
| Address | 0xcef90 |
| Ordinal | 1013 |
|---|---|
| Address | 0xcefd0 |
| Ordinal | 1014 |
|---|---|
| Address | 0xcf010 |
| Ordinal | 1015 |
|---|---|
| Address | 0xcf0c0 |
| Ordinal | 1016 |
|---|---|
| Address | 0xcf100 |
| Ordinal | 1017 |
|---|---|
| Address | 0xcf470 |
| Ordinal | 1018 |
|---|---|
| Address | 0xcf490 |
| Ordinal | 1019 |
|---|---|
| Address | 0xcd90 |
| Ordinal | 1020 |
|---|---|
| Address | 0x88ac0 |
| Ordinal | 1021 |
|---|---|
| Address | 0x88b50 |
| Ordinal | 1022 |
|---|---|
| Address | 0x88ac0 |
| Ordinal | 1023 |
|---|---|
| Address | 0x88b50 |
| Ordinal | 1024 |
|---|---|
| Address | 0x52f20 |
| Ordinal | 1025 |
|---|---|
| Address | 0x88b50 |
| Ordinal | 1026 |
|---|---|
| Address | 0xe710 |
| Ordinal | 1027 |
|---|---|
| Address | 0x2cf0 |
| Ordinal | 1028 |
|---|---|
| Address | 0x2c110 |
| Ordinal | 1029 |
|---|---|
| Address | 0x89cb0 |
| Ordinal | 1030 |
|---|---|
| Address | 0x89d30 |
| Ordinal | 1031 |
|---|---|
| Address | 0x8a3a0 |
| Ordinal | 1032 |
|---|---|
| Address | 0x8b7a0 |
| Ordinal | 1033 |
|---|---|
| Address | 0x8b7b0 |
| Ordinal | 1034 |
|---|---|
| Address | 0xda40 |
| Ordinal | 1035 |
|---|---|
| Address | 0x36e10 |
| Ordinal | 1036 |
|---|---|
| Address | 0x8bc40 |
| Ordinal | 1037 |
|---|---|
| Address | 0x8b7c0 |
| Ordinal | 1038 |
|---|---|
| Address | 0x1d8b0 |
| Ordinal | 1039 |
|---|---|
| Address | 0x4c980 |
| Ordinal | 1040 |
|---|---|
| Address | 0x36620 |
| Ordinal | 1041 |
|---|---|
| Address | 0x8bc80 |
| Ordinal | 1042 |
|---|---|
| Address | 0x4b4f0 |
| Ordinal | 1043 |
|---|---|
| Address | 0x1e2d0 |
| Ordinal | 1044 |
|---|---|
| Address | 0xe6d0 |
| Ordinal | 1045 |
|---|---|
| Address | 0x2cb0 |
| Ordinal | 1046 |
|---|---|
| Address | 0x88bb0 |
| Ordinal | 1047 |
|---|---|
| Address | 0x43130 |
| Ordinal | 1048 |
|---|---|
| Address | 0x53370 |
| Ordinal | 1049 |
|---|---|
| Address | 0x3b020 |
| Ordinal | 1050 |
|---|---|
| Address | 0x8c190 |
| Ordinal | 1051 |
|---|---|
| Address | 0x89110 |
| Ordinal | 1052 |
|---|---|
| Address | 0x89110 |
| Ordinal | 1053 |
|---|---|
| Address | 0x89110 |
| Ordinal | 1054 |
|---|---|
| Address | 0x40b50 |
| Ordinal | 1055 |
|---|---|
| Address | 0x40b50 |
| Ordinal | 1056 |
|---|---|
| Address | 0x546d0 |
| Ordinal | 1057 |
|---|---|
| Address | 0x3a3d0 |
| Ordinal | 1058 |
|---|---|
| Address | 0x53c70 |
| Ordinal | 1059 |
|---|---|
| Address | 0x89130 |
| Ordinal | 1060 |
|---|---|
| Address | 0x562f0 |
| Ordinal | 1061 |
|---|---|
| Address | 0x89130 |
| Ordinal | 1062 |
|---|---|
| Address | 0x367c0 |
| Ordinal | 1063 |
|---|---|
| Address | 0x89130 |
| Ordinal | 1064 |
|---|---|
| Address | 0x35530 |
| Ordinal | 1065 |
|---|---|
| Address | 0x902c0 |
| Ordinal | 1066 |
|---|---|
| Address | 0x89150 |
| Ordinal | 1067 |
|---|---|
| Address | 0x902e0 |
| Ordinal | 1068 |
|---|---|
| Address | 0x90660 |
| Ordinal | 1069 |
|---|---|
| Address | 0x40600 |
| Ordinal | 1070 |
|---|---|
| Address | 0x36480 |
| Ordinal | 1071 |
|---|---|
| Address | 0x892b0 |
| Ordinal | 1072 |
|---|---|
| Address | 0x42b00 |
| Ordinal | 1073 |
|---|---|
| Address | 0x34e40 |
| Ordinal | 1074 |
|---|---|
| Address | 0x91370 |
| Ordinal | 1075 |
|---|---|
| Address | 0x35f60 |
| Ordinal | 1076 |
|---|---|
| Address | 0x68d0 |
| Ordinal | 1077 |
|---|---|
| Address | 0x41860 |
| Ordinal | 1078 |
|---|---|
| Address | 0x3f7a0 |
| Ordinal | 1079 |
|---|---|
| Address | 0x54610 |
| Ordinal | 1080 |
|---|---|
| Address | 0x54610 |
| Ordinal | 1081 |
|---|---|
| Address | 0x119f0 |
| Ordinal | 1082 |
|---|---|
| Address | 0x573c0 |
| Ordinal | 1083 |
|---|---|
| Address | 0x7e10 |
| Ordinal | 1084 |
|---|---|
| Address | 0x1ce80 |
| Ordinal | 1085 |
|---|---|
| Address | 0x8b820 |
| Ordinal | 1086 |
|---|---|
| Address | 0x22a60 |
| Ordinal | 1087 |
|---|---|
| Address | 0x6e70 |
| Ordinal | 1088 |
|---|---|
| Address | 0x22a60 |
| Ordinal | 1089 |
|---|---|
| Address | 0x38dd0 |
| Ordinal | 1090 |
|---|---|
| Address | 0x22a60 |
| Ordinal | 1091 |
|---|---|
| Address | 0x36050 |
| Ordinal | 1092 |
|---|---|
| Address | 0x57cc0 |
| Ordinal | 1093 |
|---|---|
| Address | 0x89310 |
| Ordinal | 1094 |
|---|---|
| Address | 0x58460 |
| Ordinal | 1095 |
|---|---|
| Address | 0x38430 |
| Ordinal | 1096 |
|---|---|
| Address | 0x3b2a0 |
| Ordinal | 1097 |
|---|---|
| Address | 0x8b870 |
| Ordinal | 1098 |
|---|---|
| Address | 0x89410 |
| Ordinal | 1099 |
|---|---|
| Address | 0xf680 |
| Ordinal | 1100 |
|---|---|
| Address | 0x36820 |
| Ordinal | 1101 |
|---|---|
| Address | 0x8bca0 |
| Ordinal | 1102 |
|---|---|
| Address | 0xd560 |
| Ordinal | 1103 |
|---|---|
| Address | 0x41cf0 |
| Ordinal | 1104 |
|---|---|
| Address | 0x390d0 |
| Ordinal | 1105 |
|---|---|
| Address | 0x585f0 |
| Ordinal | 1106 |
|---|---|
| Address | 0x18740 |
| Ordinal | 1107 |
|---|---|
| Address | 0x41a20 |
| Ordinal | 1108 |
|---|---|
| Address | 0x8b920 |
| Ordinal | 1109 |
|---|---|
| Address | 0x2a170 |
| Ordinal | 1110 |
|---|---|
| Address | 0x89db0 |
| Ordinal | 1111 |
|---|---|
| Address | 0x89e20 |
| Ordinal | 1112 |
|---|---|
| Address | 0x91ea0 |
| Ordinal | 1113 |
|---|---|
| Address | 0x56c60 |
| Ordinal | 1114 |
|---|---|
| Address | 0x90730 |
| Ordinal | 1115 |
|---|---|
| Address | 0x909d0 |
| Ordinal | 1116 |
|---|---|
| Address | 0x8a560 |
| Ordinal | 1117 |
|---|---|
| Address | 0x5620 |
| Ordinal | 1118 |
|---|---|
| Address | 0xc8fc0 |
| Ordinal | 1119 |
|---|---|
| Address | 0x93e50 |
| Ordinal | 1120 |
|---|---|
| Address | 0x3f6c0 |
| Ordinal | 1121 |
|---|---|
| Address | 0x2e50 |
| Ordinal | 1122 |
|---|---|
| Address | 0x3f630 |
| Ordinal | 1123 |
|---|---|
| Address | 0x3f630 |
| Ordinal | 1124 |
|---|---|
| Address | 0x3f630 |
| Ordinal | 1125 |
|---|---|
| Address | 0x53750 |
| Ordinal | 1126 |
|---|---|
| Address | 0x53750 |
| Ordinal | 1127 |
|---|---|
| Address | 0x2020 |
| Ordinal | 1128 |
|---|---|
| Address | 0x53750 |
| Ordinal | 1129 |
|---|---|
| Address | 0x8a660 |
| Ordinal | 1130 |
|---|---|
| Address | 0x895e0 |
| Ordinal | 1131 |
|---|---|
| Address | 0x91f70 |
| Ordinal | 1132 |
|---|---|
| Address | 0x1a430 |
| Ordinal | 1133 |
|---|---|
| Address | 0x90ad0 |
| Ordinal | 1134 |
|---|---|
| Address | 0x90be0 |
| Ordinal | 1135 |
|---|---|
| Address | 0x8beb0 |
| Ordinal | 1136 |
|---|---|
| Address | 0x8bf40 |
| Ordinal | 1137 |
|---|---|
| Address | 0x94620 |
| Ordinal | 1138 |
|---|---|
| Address | 0x1ca40 |
| Ordinal | 1139 |
|---|---|
| Address | 0x3e660 |
| Ordinal | 1140 |
|---|---|
| Address | 0x89650 |
| Ordinal | 1141 |
|---|---|
| Address | 0x33dc0 |
| Ordinal | 1142 |
|---|---|
| Address | 0x8bfe0 |
| Ordinal | 1143 |
|---|---|
| Address | 0x56480 |
| Ordinal | 1144 |
|---|---|
| Address | 0x14c20 |
| Ordinal | 1145 |
|---|---|
| Address | 0x14b00 |
| Ordinal | 1146 |
|---|---|
| Address | 0x95640 |
| Ordinal | 1147 |
|---|---|
| Address | 0x955f0 |
| Ordinal | 1148 |
|---|---|
| Address | 0x930c0 |
| Ordinal | 1149 |
|---|---|
| Address | 0x96eb0 |
| Ordinal | 1150 |
|---|---|
| Address | 0x25e90 |
| Ordinal | 1151 |
|---|---|
| Address | 0x25ed0 |
| Ordinal | 1152 |
|---|---|
| Address | 0x96f50 |
| Ordinal | 1153 |
|---|---|
| Address | 0x97190 |
| Ordinal | 1154 |
|---|---|
| Address | 0x53fd0 |
| Ordinal | 1155 |
|---|---|
| Address | 0x1c650 |
| Ordinal | 1156 |
|---|---|
| Address | 0x97200 |
| Ordinal | 1157 |
|---|---|
| Address | 0x89690 |
| Ordinal | 1158 |
|---|---|
| Address | 0x1b580 |
| Ordinal | 1159 |
|---|---|
| Address | 0xa4710 |
| Ordinal | 1160 |
|---|---|
| Address | 0xd1b30 |
| Ordinal | 1161 |
|---|---|
| Address | 0x7b30 |
| Ordinal | 1162 |
|---|---|
| Address | 0x55120 |
| Ordinal | 1163 |
|---|---|
| Address | 0x93150 |
| Ordinal | 1164 |
|---|---|
| Address | 0x8c030 |
| Ordinal | 1165 |
|---|---|
| Address | 0xa4810 |
| Ordinal | 1166 |
|---|---|
| Address | 0x1af70 |
| Ordinal | 1167 |
|---|---|
| Address | 0xae460 |
| Ordinal | 1168 |
|---|---|
| Address | 0x3ebe0 |
| Ordinal | 1169 |
|---|---|
| Address | 0x95610 |
| Ordinal | 1170 |
|---|---|
| Address | 0x3ee50 |
| Ordinal | 1171 |
|---|---|
| Address | 0x3ef00 |
| Ordinal | 1172 |
|---|---|
| Address | 0x89790 |
| Ordinal | 1173 |
|---|---|
| Address | 0x972e0 |
| Ordinal | 1174 |
|---|---|
| Address | 0x97320 |
| Ordinal | 1175 |
|---|---|
| Address | 0x1cba0 |
| Ordinal | 1176 |
|---|---|
| Address | 0xa32b0 |
| Ordinal | 1177 |
|---|---|
| Address | 0x4e300 |
| Ordinal | 1178 |
|---|---|
| Address | 0x1b380 |
| Ordinal | 1179 |
|---|---|
| Address | 0x973d0 |
| Ordinal | 1180 |
|---|---|
| Address | 0x4df80 |
| Ordinal | 1181 |
|---|---|
| Address | 0x1a2e0 |
| Ordinal | 1182 |
|---|---|
| Address | 0xd1f30 |
| Ordinal | 1183 |
|---|---|
| Address | 0x56c30 |
| Ordinal | 1184 |
|---|---|
| Address | 0x3b390 |
| Ordinal | 1185 |
|---|---|
| Address | 0x19220 |
| Ordinal | 1186 |
|---|---|
| Address | 0x38c10 |
| Ordinal | 1187 |
|---|---|
| Address | 0xb3830 |
| Ordinal | 1188 |
|---|---|
| Address | 0x38ba0 |
| Ordinal | 1189 |
|---|---|
| Address | 0xddc00 |
| Ordinal | 1190 |
|---|---|
| Address | 0x50040 |
| Ordinal | 1191 |
|---|---|
| Address | 0x7320 |
| Ordinal | 1192 |
|---|---|
| Address | 0xb3c60 |
| Ordinal | 1193 |
|---|---|
| Address | 0xbce0 |
| Ordinal | 1194 |
|---|---|
| Address | 0xfd90 |
| Ordinal | 1195 |
|---|---|
| Address | 0x13310 |
| Ordinal | 1196 |
|---|---|
| Address | 0xe6d60 |
| Ordinal | 1197 |
|---|---|
| Address | 0xe6ef0 |
| Ordinal | 1198 |
|---|---|
| Address | 0x55090 |
| Ordinal | 1199 |
|---|---|
| Address | 0xbe90 |
| Ordinal | 1200 |
|---|---|
| Address | 0x2950 |
| Ordinal | 1201 |
|---|---|
| Address | 0x2cc40 |
| Ordinal | 1202 |
|---|---|
| Address | 0x3af00 |
| Ordinal | 1203 |
|---|---|
| Address | 0xa840 |
| Ordinal | 1204 |
|---|---|
| Address | 0xbda0 |
| Ordinal | 1205 |
|---|---|
| Address | 0x2dd10 |
| Ordinal | 1206 |
|---|---|
| Address | 0xe7270 |
| Ordinal | 1207 |
|---|---|
| Address | 0x107c0 |
| Ordinal | 1208 |
|---|---|
| Address | 0x542d0 |
| Ordinal | 1209 |
|---|---|
| Address | 0x129e26 |
| ForwardName | DPAPI.CryptProtectMemory |
| Ordinal | 1210 |
|---|---|
| Address | 0xdad0 |
| Ordinal | 1211 |
|---|---|
| Address | 0xa33a0 |
| Ordinal | 1212 |
|---|---|
| Address | 0xa36a0 |
| Ordinal | 1213 |
|---|---|
| Address | 0xa48c0 |
| Ordinal | 1214 |
|---|---|
| Address | 0xde0f0 |
| Ordinal | 1215 |
|---|---|
| Address | 0xddca0 |
| Ordinal | 1216 |
|---|---|
| Address | 0x3e590 |
| Ordinal | 1217 |
|---|---|
| Address | 0x3e4c0 |
| Ordinal | 1218 |
|---|---|
| Address | 0xde010 |
| Ordinal | 1219 |
|---|---|
| Address | 0x3e3e0 |
| Ordinal | 1220 |
|---|---|
| Address | 0x3eb00 |
| Ordinal | 1221 |
|---|---|
| Address | 0x70e0 |
| Ordinal | 1222 |
|---|---|
| Address | 0xdde70 |
| Ordinal | 1223 |
|---|---|
| Address | 0x7690 |
| Ordinal | 1224 |
|---|---|
| Address | 0x4f590 |
| Ordinal | 1225 |
|---|---|
| Address | 0x4f940 |
| Ordinal | 1226 |
|---|---|
| Address | 0x3feb0 |
| Ordinal | 1227 |
|---|---|
| Address | 0x95640 |
| Ordinal | 1228 |
|---|---|
| Address | 0x898a0 |
| Ordinal | 1229 |
|---|---|
| Address | 0xa37a0 |
| Ordinal | 1230 |
|---|---|
| Address | 0x4e050 |
| Ordinal | 1231 |
|---|---|
| Address | 0x97630 |
| Ordinal | 1232 |
|---|---|
| Address | 0x4e1f0 |
| Ordinal | 1233 |
|---|---|
| Address | 0x97790 |
| Ordinal | 1234 |
|---|---|
| Address | 0x978a0 |
| Ordinal | 1235 |
|---|---|
| Address | 0x575c0 |
| Ordinal | 1236 |
|---|---|
| Address | 0x43be0 |
| Ordinal | 1237 |
|---|---|
| Address | 0xb39f0 |
| Ordinal | 1238 |
|---|---|
| Address | 0x4c540 |
| Ordinal | 1239 |
|---|---|
| Address | 0x12a10f |
| ForwardName | DPAPI.CryptUnprotectMemory |
| Ordinal | 1240 |
|---|---|
| Address | 0xa3890 |
| Ordinal | 1241 |
|---|---|
| Address | 0xa3b30 |
| Ordinal | 1242 |
|---|---|
| Address | 0xa4ac0 |
| Ordinal | 1243 |
|---|---|
| Address | 0x12a198 |
| ForwardName | DPAPI.CryptUpdateProtectedState |
| Ordinal | 1244 |
|---|---|
| Address | 0x8c140 |
| Ordinal | 1245 |
|---|---|
| Address | 0x18170 |
| Ordinal | 1246 |
|---|---|
| Address | 0x97b20 |
| Ordinal | 1247 |
|---|---|
| Address | 0x97b80 |
| Ordinal | 1248 |
|---|---|
| Address | 0x97c00 |
| Ordinal | 1249 |
|---|---|
| Address | 0x97c50 |
| Ordinal | 1250 |
|---|---|
| Address | 0x97cd0 |
| Ordinal | 1251 |
|---|---|
| Address | 0xf620 |
| Ordinal | 1252 |
|---|---|
| Address | 0x40b80 |
| Ordinal | 1253 |
|---|---|
| Address | 0xeb00 |
| Ordinal | 1254 |
|---|---|
| Address | 0x3d4c0 |
| Ordinal | 1255 |
|---|---|
| Address | 0x3cf20 |
| Ordinal | 1256 |
|---|---|
| Address | 0x49b40 |
| Ordinal | 1257 |
|---|---|
| Address | 0x10e10 |
| Ordinal | 1258 |
|---|---|
| Address | 0x89a60 |
| Ordinal | 1259 |
|---|---|
| Address | 0x56010 |
| Ordinal | 1260 |
|---|---|
| Address | 0xc9f50 |
| Ordinal | 1261 |
|---|---|
| Address | 0xb6d40 |
| Ordinal | 1262 |
|---|---|
| Address | 0x56900 |
| Ordinal | 1263 |
|---|---|
| Address | 0x38300 |
| Ordinal | 1264 |
|---|---|
| Address | 0x300c0 |
| Ordinal | 1265 |
|---|---|
| Address | 0x1e170 |
| Ordinal | 1266 |
|---|---|
| Address | 0x4f430 |
| Ordinal | 1267 |
|---|---|
| Address | 0xc9f60 |
| Ordinal | 1268 |
|---|---|
| Address | 0xc9fa0 |
| Ordinal | 1269 |
|---|---|
| Address | 0x55dc0 |
| Ordinal | 1270 |
|---|---|
| Address | 0x4afa0 |
| Ordinal | 1271 |
|---|---|
| Address | 0xca010 |
| Ordinal | 1272 |
|---|---|
| Address | 0xb6e50 |
| Ordinal | 1273 |
|---|---|
| Address | 0x53c90 |
| Ordinal | 1274 |
|---|---|
| Address | 0x56160 |
| Ordinal | 1275 |
|---|---|
| Address | 0x52ae0 |
| Ordinal | 1276 |
|---|---|
| Address | 0x28b40 |
| Ordinal | 1277 |
|---|---|
| Address | 0x288c0 |
| Ordinal | 1278 |
|---|---|
| Address | 0x3be50 |
| Ordinal | 1279 |
|---|---|
| Address | 0xb3b30 |
| Ordinal | 1280 |
|---|---|
| Address | 0x78200 |
| Ordinal | 1281 |
|---|---|
| Address | 0x54d80 |
| Ordinal | 1282 |
|---|---|
| Address | 0xca040 |
| Ordinal | 1283 |
|---|---|
| Address | 0xb70a0 |
| Ordinal | 1284 |
|---|---|
| Address | 0x247a0 |
| Ordinal | 1285 |
|---|---|
| Address | 0x54b40 |
| Ordinal | 1286 |
|---|---|
| Address | 0x3ae90 |
| Ordinal | 1287 |
|---|---|
| Address | 0xb70a0 |
| Ordinal | 1288 |
|---|---|
| Address | 0x4aaf0 |
| Ordinal | 1289 |
|---|---|
| Address | 0x95640 |
| Ordinal | 1290 |
|---|---|
| Address | 0x55db0 |
| Ordinal | 1291 |
|---|---|
| Address | 0x56e60 |
| Ordinal | 1292 |
|---|---|
| Address | 0x3c3b0 |
| Ordinal | 1293 |
|---|---|
| Address | 0x560d0 |
| Ordinal | 1294 |
|---|---|
| Address | 0x52ad0 |
| Ordinal | 1295 |
|---|---|
| Address | 0xb70a0 |
| Ordinal | 1296 |
|---|---|
| Address | 0x95640 |
| Ordinal | 1297 |
|---|---|
| Address | 0x571f0 |
| Ordinal | 1298 |
|---|---|
| Address | 0xd0930 |
| Ordinal | 1299 |
|---|---|
| Address | 0xd0a90 |
| Ordinal | 1300 |
|---|---|
| Address | 0xd0ab0 |
| Ordinal | 1301 |
|---|---|
| Address | 0xd1a0 |
| Ordinal | 1302 |
|---|---|
| Address | 0xc070 |
| Ordinal | 1303 |
|---|---|
| Address | 0xd0ca0 |
| Ordinal | 2000 |
|---|---|
| Address | 0xa470 |
| Signature | 0xfeef04bd |
|---|---|
| StructVersion | 0x10000 |
| FileVersion | 10.0.15063.1058 |
| ProductVersion | 10.0.15063.1058 |
| FileFlags | (EMPTY) |
| FileOs |
VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
|
| FileType |
VFT_DLL
|
| Language | English - United States |
| CompanyName | Microsoft Corporation |
| FileDescription | Crypto API32 |
| FileVersion (#2) | 10.0.15063.1058 (WinBuild.160101.0800) |
| InternalName | CRYPT32.DLL |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | CRYPT32.DLL |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion (#2) | 10.0.15063.1058 |
| Resource LangID | English - United States |
|---|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2017-Apr-29 07:14:49 |
| Version | 0.0 |
| SizeofData | 36 |
| AddressOfRawData | 0x11763c |
| PointerToRawData | 0x115c3c |
| Referenced File | crypt32.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2017-Apr-29 07:14:49 |
| Version | 0.0 |
| SizeofData | 1712 |
| AddressOfRawData | 0x117660 |
| PointerToRawData | 0x115c60 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2017-Apr-29 07:14:49 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| Size | 0xf4 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x18012e5f8 |
| GuardCFCheckFunctionPointer | 6443514160 |
| GuardCFDispatchFunctionPointer | 0 |
| GuardCFFunctionTable | 0 |
| GuardCFFunctionCount | 0 |
| GuardFlags | (EMPTY) |
| CodeIntegrity.Flags | 0 |
| CodeIntegrity.Catalog | 0 |
| CodeIntegrity.CatalogOffset | 0 |
| CodeIntegrity.Reserved | 0 |
| GuardAddressTakenIatEntryTable | 0 |
| GuardAddressTakenIatEntryCount | 0 |
| GuardLongJumpTargetTable | 0 |
| GuardLongJumpTargetCount | 0 |
| XOR Key | 0x5093a048 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2015 v14.0.? compiler 24610) | 2 |
| Imports (VS2008 SP1 build 30729) | 77 |
| Total imports | 1462 |
| C objects (VS2015 v14.0.? compiler 24610) | 10 |
| ASM objects (VS2015 v14.0.? compiler 24610) | 4 |
| C++ objects (VS2015 v14.0.? compiler 24610) | 11 |
| Exports (VS2015 v14.0.? compiler 24610) | 1 |
| C++ objects (POGO O) (VS2015 v14.0.? compiler 24610) | 127 |
| 253 (VS2015 v14.0.? compiler 24610) | 1 |
| Resource objects (VS2015 v14.0.? compiler 24610) | 1 |
| Linker (VS2015 v14.0.? compiler 24610) | 1 |
No comments yet.