分析任务

分析类型 虚拟机标签 开始时间 结束时间 持续时间
文件 (Windows) win7-sp1-x64-shaapp03-2 2024-03-27 12:48:08 2024-03-27 12:49:01 53 秒

魔盾分数

7.775

危险的

文件详细信息

文件名 Mtb.exe
文件大小 11005888 字节
文件类型 PE32+ executable (GUI) x86-64, for MS Windows
MD5 43656b3ed226a8ef9e7ed3a11a464571
SHA1 174a2781763e0c97aa512549881f1faff602d509
SHA256 b8ba66b90f6aa4e119924c87e053039454827e4ff37b638d40343b5e841cd035
SHA512 e4822691f9d60553b72fba4368f2da33f7e5a71160769eb576b092537948e18129a4229b26865ccee384dd6a5e319f8baf0f51ba46518d205a577421e75d1311
CRC32 94EA8280
Ssdeep 98304:1x+JSZpwyVrqYji0LhZUQ0L35dTZljaiNmePmVcyub08mcGW542:b4SZp35BXsbbTZZ7N5PibQ0ZcGW542
Yara 登录查看Yara规则
找不到该样本 提交误报

登录查看威胁特征

运行截图

没有可用的屏幕截图

访问主机纪录 (可点击查询WPING实时安全评级)

直接 IP 安全评级 地理位置
104.18.38.233 美国
152.195.38.76 美国

域名解析 (可点击查询WPING实时安全评级)

域名 安全评级 响应
cacerts.digicert.com CNAME fp2e7a.wpc.2be4.phicdn.net
CNAME fp2e7a.wpc.phicdn.net
A 152.195.38.76
crt.usertrust.com A 104.18.38.233
CNAME crt.comodoca.com
A 172.64.149.23
CNAME crt.comodoca.com.cdn.cloudflare.net

摘要

登录查看详细行为信息

PE 信息

初始地址 0x140000000
入口地址 0x140542160
声明校验值 0x00a88a7c
实际校验值 0x00a88af3
最低操作系统版本要求 6.0
PDB路径 C:\a\2\s\Source\bin\x64\Release\Mtb.pdb
编译时间 2024-03-12 01:20:39
载入哈希 6648fc8cc3ee3079e304c30561b37df0
图标
图标精确哈希值 ea3acda044c3277bda29814b766cb9c0
图标相似性哈希值 dd3454ecd1e1067ad7aa64c1036779cd
导出DLL库名称 Mtb.exe

版本信息

LegalCopyright
InternalName
FileVersion
CompanyName
ProductName
ProductVersion
FileDescription
OriginalFilename
Translation

微软证书验证 (Sign Tool)

SHA1 时间戳 有效性 错误
None Tue Mar 12 03:14:02 2024
WinVerifyTrust returned error 0x80096010
证书链 Certificate Chain 1
发行给 DigiCert Trusted Root G4
发行人 DigiCert Trusted Root G4
有效期 Fri Jan 15 200000 2038
SHA1 哈希 ddfb16cd4931c973a2037d3fc83a4d7d775d05e4
证书链 Certificate Chain 2
发行给 DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
发行人 DigiCert Trusted Root G4
有效期 Tue Apr 29 075959 2036
SHA1 哈希 7b0f360b775f76c94a12ca48445aa2d2a875701c
证书链 Certificate Chain 3
发行给 Minitab, LLC
发行人 DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
有效期 Mon Oct 21 075959 2024
SHA1 哈希 107c14d3eadeb823332181dcd9c3f7f605148713
证书链 Timestamp Chain 1
发行给 USERTrust RSA Certification Authority
发行人 AAA Certificate Services
有效期 Mon Jan 01 075959 2029
SHA1 哈希 d89e3bd43d5d909b47a18977aa9d5ce36cee184c
证书链 Timestamp Chain 2
发行给 Sectigo RSA Time Stamping CA
发行人 USERTrust RSA Certification Authority
有效期 Tue Jan 19 075959 2038
SHA1 哈希 02d65b95e28370c1570095fa88f923dd937fad8f
证书链 Timestamp Chain 3
发行给 Sectigo RSA Time Stamping Signer #4
发行人 Sectigo RSA Time Stamping CA
有效期 Thu Aug 03 075959 2034
SHA1 哈希 ae62af750a0cbd47d6461f7568e2bc8ce7ca4f94

PE 数据组成

名称 虚拟地址 虚拟大小 原始数据大小 特征 熵(Entropy)
.text 0x00001000 0x006d21ce 0x006d2200 IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 6.53
.rdata 0x006d4000 0x002e7610 0x002e7800 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5.43
.data 0x009bc000 0x0004c440 0x0003ce00 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 4.44
.pdata 0x00a09000 0x00048da4 0x00048e00 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 6.42
.didat 0x00a52000 0x00000178 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 2.67
.tls 0x00a53000 0x00000009 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 0.02
.rsrc 0x00a54000 0x00014a98 0x00014c00 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4.75
.reloc 0x00a69000 0x00027f24 0x00028000 IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 5.45

覆盖

偏移量 0x00a7ca00
大小 0x000025c0

资源

名称 偏移量 大小 语言 子语言 熵(Entropy) 文件类型
REGISTRY 0x00a546e0 0x000000ef LANG_ENGLISH SUBLANG_ENGLISH_US 4.88 ASCII text, with CRLF line terminators
REGISTRY 0x00a546e0 0x000000ef LANG_ENGLISH SUBLANG_ENGLISH_US 4.88 ASCII text, with CRLF line terminators
REGISTRY 0x00a546e0 0x000000ef LANG_ENGLISH SUBLANG_ENGLISH_US 4.88 ASCII text, with CRLF line terminators
TYPELIB 0x00a553ac 0x000067d0 LANG_ENGLISH SUBLANG_ENGLISH_US 4.34 data
TYPELIB 0x00a553ac 0x000067d0 LANG_ENGLISH SUBLANG_ENGLISH_US 4.34 data
RT_ICON 0x00a67b54 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 3.50 GLS_BINARY_LSB_FIRST
RT_ICON 0x00a67b54 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 3.50 GLS_BINARY_LSB_FIRST
RT_ICON 0x00a67b54 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 3.50 GLS_BINARY_LSB_FIRST
RT_ICON 0x00a67b54 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 3.50 GLS_BINARY_LSB_FIRST
RT_ICON 0x00a67b54 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 3.50 GLS_BINARY_LSB_FIRST
RT_ICON 0x00a67b54 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 3.50 GLS_BINARY_LSB_FIRST
RT_ICON 0x00a67b54 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 3.50 GLS_BINARY_LSB_FIRST
RT_ICON 0x00a67b54 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 3.50 GLS_BINARY_LSB_FIRST
RT_ICON 0x00a67b54 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 3.50 GLS_BINARY_LSB_FIRST
RT_ICON 0x00a67b54 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US 3.50 GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00a67fbc 0x00000092 LANG_ENGLISH SUBLANG_ENGLISH_US 3.04 MS Windows icon resource - 10 icons, 48x48
RT_VERSION 0x00a68050 0x00000358 LANG_ENGLISH SUBLANG_ENGLISH_US 3.25 data
RT_MANIFEST 0x00a683a8 0x000006ed LANG_ENGLISH SUBLANG_ENGLISH_US 5.14 XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators

导入

库: libcef.dll:
0x1406e59b0 cef_string_list_alloc
0x1406e59b8 cef_string_list_free
0x1406e59c0 cef_currently_on
0x1406e59c8 cef_post_task
0x1406e59e0 cef_initialize
0x1406e59e8 cef_shutdown
0x1406e59f0 cef_parse_url
0x1406e59f8 cef_get_mime_type
0x1406e5a00 cef_api_hash
0x1406e5a10 cef_get_min_log_level
0x1406e5a20 cef_string_map_alloc
0x1406e5a28 cef_string_map_free
0x1406e5a30 cef_string_list_size
0x1406e5a38 cef_string_list_value
0x1406e5a40 cef_string_list_append
0x1406e5a48 cef_string_map_size
0x1406e5a50 cef_string_map_key
0x1406e5a58 cef_string_map_value
0x1406e5a60 cef_string_map_append
0x1406e5a68 cef_string_multimap_size
0x1406e5a70 cef_string_multimap_key
0x1406e5a98 cef_v8value_create_bool
0x1406e5aa0 cef_v8value_create_int
0x1406e5ac8 cef_string_multimap_free
0x1406e5ad8 cef_log
0x1406e5ae0 cef_string_utf8_clear
0x1406e5ae8 cef_string_utf16_clear
0x1406e5af0 cef_string_utf16_cmp
0x1406e5af8 cef_string_utf8_to_utf16
0x1406e5b00 cef_string_utf16_to_utf8
0x1406e5b08 cef_string_utf16_set
0x1406e5b10 cef_string_wide_to_utf16
库: libxml2.dll:
0x1406e5b58 xmlTextWriterSetIndent
0x1406e5b60 xmlTextWriterWritePI
0x1406e5b70 xmlTextWriterWriteString
0x1406e5b80 xmlTextWriterEndElement
0x1406e5b90 xmlTextWriterEndDocument
0x1406e5ba0 xmlFreeTextWriter
0x1406e5ba8 xmlNewTextWriterMemory
0x1406e5bb0 xmlReaderForMemory
0x1406e5bb8 xmlTextReaderNext
0x1406e5bc8 xmlTextReaderConstValue
0x1406e5bd0 xmlTextReaderConstName
0x1406e5bd8 xmlTextReaderNodeType
0x1406e5be0 xmlTextReaderRead
0x1406e5be8 xmlFreeTextReader
0x1406e5bf0 xmlBufferFree
0x1406e5bf8 xmlBufferCreate
库: cpprest_2_10.dll:
0x1406e5730 ??0uri@web@@QEAA@PEB_W@Z
0x1406e5750 _getn_fsb
0x1406e5770 _get_size
0x1406e57a8 _putn_fsb
0x1406e57b0 _close_fsb_nolock
0x1406e57d0 _seekrdtoend_fsb
0x1406e57e0 _open_fsb_str
0x1406e57f0 _seekrdpos_fsb
0x1406e5878 _sync_fsb
0x1406e5890 _seekwrpos_fsb
库: HRW14.dll:
0x1406d43e0 None
0x1406d43e8 None
0x1406d43f0 None
0x1406d43f8 None
0x1406d4400 None
库: Authentication.dll:
库: RPCRT4.dll:
0x1406e49f0 UuidCompare
库: libsass.dll:
0x1406e5b30 sass_make_data_context
0x1406e5b38 sass_copy_c_string
0x1406e5b48 sass_delete_data_context
库: MtbBCG.dll:
0x1406d6568 ?BCGM_TOOLBARMENU@@3IA
0x1406d6570 ?BCGM_CUSTOMIZEHELP@@3IA
0x1406d6578 ?BCGM_RESETTOOLBAR@@3IA
0x1406d6580 ?BCGM_RESETMENU@@3IA
0x1406d6590 ?BCGM_RESETKEYBOARD@@3IA
0x1406d6598 ?GPB_MENU_DISPLAYED@@3IA
0x1406d65b8 ??0CBCGPMenuBar@@QEAA@XZ
0x1406d65d8 ??1CBCGPMenuBar@@UEAA@XZ
0x1406d6978 ?BCGCBProCleanUp@@YAXXZ
0x1406d7490 ??0CBCGPToolBar@@QEAA@XZ
0x1406d7498 ??1CBCGPToolBar@@UEAA@XZ
0x1406d7710 ??0CBCGPWinApp@@QEAA@XZ
0x1406d7718 ??1CBCGPWinApp@@UEAA@XZ
0x1406d8600 ??0CBCGPTabView@@IEAA@XZ
0x1406d8618 ??1CBCGPTabView@@MEAA@XZ
0x1406d8648 ?BCGM_ON_RENAME_TAB@@3IA
0x1406d8650 ?BCGM_ON_MOVE_TAB@@3IA
0x1406d8668 ?BCGM_NEW_TAB@@3IA
0x1406d8f60 ??1CBCGPDialog@@UEAA@XZ
库: MtbCore.dll:
0x1406d9588 ??1CmOutTable@@UEAA@XZ
0x1406d95c8 ??0CmNumericFmt@@QEAA@XZ
0x1406d95d0 ??1CmNumericFmt@@UEAA@XZ
0x1406d9890 ??0CmCmnd@@QEAA@XZ
0x1406d9898 ??1CmCmnd@@UEAA@XZ
0x1406d9b68 ?FileExists@@YA_NPEB_W@Z
0x1406d9b88 ?mIsCharDigit@@YA_N_W@Z
0x1406d9bd0 ??ACmString@@QEBA_WH@Z
0x1406d9d28 ?mNearestInteger@@YANN@Z
0x1406d9eb0 ??0CmMarkerDefs@@QEAA@XZ
0x1406d9eb8 ??1CmMarkerDefs@@QEAA@XZ
0x1406d9fd8 ??0CmRectangle@@QEAA@XZ
0x1406d9fe0 ??1CmRectangle@@UEAA@XZ
0x1406d9ff0 ?GetInputDecimal@@YA_WXZ
0x1406d9ff8 ?mIsSpace@@YA_N_W@Z
0x1406da070 ??0CmAreaDefs@@QEAA@XZ
0x1406da078 ??1CmAreaDefs@@UEAA@XZ
0x1406da090 ??1CmFillAttrib@@UEAA@XZ
0x1406da098 ??0CmString@@QEAA@_W_K@Z
0x1406da0c8 ??0CmRows@@QEAA@XZ
0x1406da0d0 ??1CmRows@@UEAA@XZ
0x1406da110 ??1CmOutMessage@@UEAA@XZ
0x1406da130 ??0CmVectorStat@@QEAA@XZ
0x1406da138 ??1CmVectorStat@@UEAA@XZ
0x1406da150 ??0CmNoYield@@QEAA@XZ
0x1406da158 ??1CmNoYield@@QEAA@XZ
0x1406da178 ??0CmTimeCls@@QEAA@XZ
0x1406da1c0 ??1CmTimeCls@@QEAA@XZ
0x1406da2f0 ??0CmBarDefs@@QEAA@XZ
0x1406da2f8 ??1CmBarDefs@@UEAA@XZ
0x1406da420 ??0CmBubbleDefs@@QEAA@XZ
0x1406da428 ??1CmBubbleDefs@@UEAA@XZ
0x1406da4c0 ??1CmSentence@@UEAA@XZ
0x1406da5f0 ??0CmColumnVar@@QEAA@XZ
0x1406da5f8 ??1CmColumnVar@@UEAA@XZ
0x1406da660 ??0CmModelTerm@@QEAA@XZ
0x1406da668 ??1CmModelTerm@@UEAA@XZ
0x1406da7e8 ??0CmCIDefs@@QEAA@XZ
0x1406da7f0 ??1CmCIDefs@@UEAA@XZ
0x1406da7f8 ?c16eq@@YA_NPEB_W0@Z
0x1406da800 ?mIsCharAlpha@@YA_N_W@Z
0x1406da808 ?mIsPrint@@YA_N_W@Z
0x1406da818 ?mToUpper@@YA_W_W@Z
0x1406da828 ?EPS@mtb_constants@@3NA
0x1406da830 ?c16eqi@@YA_NPEB_W0@Z
0x1406da8d0 ??1CmLineAttrib@@UEAA@XZ
0x1406dae50 ??0CmRows@@QEAA@AEBV0@@Z
0x1406dafb8 ??0Observer@@IEAA@XZ
0x1406dafc0 ??1Observer@@IEAA@XZ
0x1406dafd0 ??1U@@QEAA@XZ
0x1406dafd8 ??BU@@QEAAPEB_WXZ
0x1406db120 ??0CmDOEDesign@@QEAA@XZ
0x1406db130 ??1CmDOEDesign@@UEAA@XZ
0x1406db198 ??0CmOADesign@@QEAA@XZ
0x1406db1a0 ??1CmOADesign@@UEAA@XZ
0x1406db1b0 ??0CmOAAnalysis@@QEAA@XZ
0x1406db1b8 ??1CmOAAnalysis@@UEAA@XZ
0x1406db1c8 ??0CmOAPredict@@QEAA@XZ
0x1406db1d0 ??1CmOAPredict@@UEAA@XZ
0x1406db2a0 ??1CmDOE@@UEAA@XZ
0x1406db560 ??0CmVariableId@@QEAA@XZ
0x1406db568 ??1CmVariableId@@UEAA@XZ
0x1406db648 ?mNChooseK@@YAHHH@Z
0x1406db798 ?mIsNumeric@@YA_NPEB_W@Z
0x1406dba30 ??0CmPreprocess@@QEAA@XZ
0x1406dba38 ??1CmPreprocess@@UEAA@XZ
0x1406dbb08 ?GetMaxBlocks@@YAIII@Z
0x1406dbb68 ??0CmOAFactor@@QEAA@XZ
0x1406dbb80 ??1CmOAFactor@@UEAA@XZ
0x1406dbbd0 ?mNFactorial@@YANH@Z
0x1406dbc20 ??0CmPersistent@@QEAA@XZ
0x1406dbc28 ??1CmPersistent@@UEAA@XZ
0x1406dbd18 ??0CmDOERsPlot@@QEAA@XZ
0x1406dbd20 ??1CmDOERsPlot@@UEAA@XZ
0x1406dbda8 ?mIsInteger@@YA_NN@Z
0x1406dbe48 ??0CmDOEFactor@@QEAA@XZ
0x1406dbe50 ??1CmDOEFactor@@UEAA@XZ
0x1406dbe90 ??0CmGrouping@@QEAA@XZ
0x1406dbe98 ??1CmGrouping@@UEAA@XZ
0x1406dc058 ??1FileLock@io@@QEAA@XZ
0x1406dc958 ??0CmCmndRole@@QEAA@XZ
0x1406dc960 ??1CmCmndRole@@QEAA@XZ
0x1406dd000 ??0CmTitleDefs@@QEAA@XZ
0x1406dd008 ??1CmTitleDefs@@UEAA@XZ
0x1406dd218 ??1CmScaleDefs@@UEAA@XZ
0x1406dd408 ?mRound@@YANNH@Z
0x1406dd438 ??0CmDotDefs@@QEAA@XZ
0x1406dd440 ??1CmDotDefs@@UEAA@XZ
0x1406dd558 ??0CmGridDefs@@QEAA@XZ
0x1406dd560 ??1CmGridDefs@@UEAA@XZ
0x1406dd7a0 ??0CmSymbolDefs@@QEAA@XZ
0x1406dd7a8 ??1CmSymbolDefs@@UEAA@XZ
0x1406ddc48 ?mModulo@@YANNN@Z
0x1406ddd18 ??0CmLowessDefs@@QEAA@XZ
0x1406ddd20 ??1CmLowessDefs@@UEAA@XZ
0x1406dddf8 ??0CmSliceDefs@@QEAA@XZ
0x1406dde00 ??1CmSliceDefs@@UEAA@XZ
0x1406de5c8 ??1Subject@@UEAA@XZ
0x1406de5e8 ??0Subject@@IEAA@XZ
0x1406deac0 ??1CmText@@UEAA@XZ
0x1406dead0 ??1CmTitle@@UEAA@XZ
0x1406deae8 ??1CmFootnote@@UEAA@XZ
0x1406deb10 ??0CmLineAttrib@@QEAA@XZ
0x1406debe8 ??1CmXReference@@UEAA@XZ
0x1406debf8 ??1CmYReference@@UEAA@XZ
0x1406dec00 ??0CmZReference@@QEAA@XZ
0x1406dec08 ??1CmZReference@@UEAA@XZ
0x1406dec10 ??0CmXPtile@@QEAA@XZ
0x1406dec18 ??1CmXPtile@@UEAA@XZ
0x1406dec20 ??0CmYPtile@@QEAA@XZ
0x1406dec28 ??1CmYPtile@@UEAA@XZ
0x1406df140 ?mSetTag@CmText@@UEAAXXZ
0x1406df190 ?mRender@CmText@@UEAAXXZ
0x1406df418 ??1CmPolyline@@UEAA@XZ
0x1406df428 ??1CmPolygon@@UEAA@XZ
0x1406df458 ??0CmMarker@@QEAA@NN@Z
0x1406df460 ??1CmMarker@@UEAA@XZ
0x1406dfc48 ??BU@@QEAAPEBDXZ
0x1406dfca8 ??0CmFillAttrib@@QEAA@XZ
0x1406dfcf0 ??0Cm14GraphDoc@@QEAA@XZ
0x1406dfcf8 ??1Cm14GraphDoc@@UEAA@XZ
0x1406e0188 ??0CmException@@QEAA@XZ
0x1406e0190 ??1CmException@@UEAA@XZ
0x1406e0338 ?Initialize@mtb@@YAXXZ
0x1406e0340 ?Shutdown@mtb@@YAXXZ
0x1406e0370 ??0IMacroInfo@@QEAA@XZ
0x1406e0550 ??1CmExpression@@QEAA@XZ
0x1406e0590 ??1BinaryStream@@UEAA@XZ
0x1406e0910 ??0CmTSPlotDefs@@QEAA@XZ
0x1406e0918 ??1CmTSPlotDefs@@UEAA@XZ
0x1406e0bc0 ??0CmSortTool@@QEAA@XZ
0x1406e0bc8 ??1CmSortTool@@QEAA@XZ
0x1406e0ff0 ?Front@CbRows@@QEBAHXZ
0x1406e0ff8 ?mClear@CbRows@@QEAAXXZ
0x1406e1848 ??1CmRowManager@@UEAA@XZ
0x1406e18c8 ??1CmCmndTEXT@@UEAA@XZ
0x1406e18e8 ??1CmCmndNUME@@UEAA@XZ
0x1406e18f8 ??1CmCmndDATE@@UEAA@XZ
0x1406e1908 ??1CmCmndFNUM@@UEAA@XZ
0x1406e1920 ??1CmCmndFDAT@@UEAA@XZ
0x1406e1938 ??1CmCmndFTEXT@@UEAA@XZ
0x1406e1fa0 ?Now@@YANXZ
0x1406e2188 ?Empty@CmString@@QEAAXXZ
0x1406e21b8 ??1TempFile@io@@QEAA@XZ
0x1406e2488 ??1CmCodeTokens@@UEAA@XZ
0x1406e2498 ??1CmCmndTokens@@UEAA@XZ
0x1406e2668 ??BCmString@@QEBAPEB_WXZ
0x1406e2688 ??1CmString@@QEAA@XZ
0x1406e2698 ??0CmString@@QEAA@XZ
库: MtbDlg.dll:
0x1406e2988 ??1CmTextIO@@UEAA@XZ
0x1406e29c8 ??0CmHtmlDialog@@QEAA@XZ
0x1406e29d0 ??1CmHtmlDialog@@UEAA@XZ
0x1406e2a68 ?mGetLangSpecMsg@@YAIXZ
0x1406e2c38 ??1CmBizObj@@UEAA@XZ
0x1406e2c40 ??0CmColorObj@@QEAA@XZ
0x1406e2c48 ??1CmColorObj@@UEAA@XZ
0x1406e2ca0 ??0CmToolTip@@QEAA@XZ
0x1406e2ca8 ??1CmToolTip@@UEAA@XZ
0x1406e2d28 ??0CmBizObj@@IEAA@XZ
0x1406e2ee8 ??1CmDOEBizObj@@UEAA@XZ
0x1406e3040 ??0CmMtbVarRun@@QEAA@XZ
0x1406e3088 ??1CmMtbVarRun@@UEAA@XZ
库: MtbObjectiveGrid.dll:
0x1406e3598 ??0CGXFont@@QEAA@XZ
0x1406e35a0 ??1CGXFont@@UEAA@XZ
0x1406e35c0 ??0CGXPen@@QEAA@IHK@Z
0x1406e3600 ??0CGXGridParam@@QEAA@XZ
0x1406e3630 ??1CGXGridParam@@UEAA@XZ
0x1406e3678 ??1CGXStatic@@UEAA@XZ
0x1406e36f8 ??0CGXGridWnd@@QEAA@XZ
0x1406e3720 ??1CGXGridWnd@@UEAA@XZ
0x1406e3898 ?Cut@CGXControl@@UEAAHXZ
0x1406e3cd0 ?GXInit@@YAXPEB_W0@Z
0x1406e3cf8 ??0CGXRange@@QEAA@XZ
0x1406e3dc0 ??0CGXGridView@@IEAA@XZ
0x1406e3dc8 ??1CGXGridView@@MEAA@XZ
0x1406e3fe0 ??1CGXHeader@@UEAA@XZ
0x1406e4030 ??0CGXPen@@QEAA@XZ
0x1406e40a8 ??1CGXRangeList@@UEAA@XZ
0x1406e40b0 ??0CGXRangeList@@QEAA@XZ
0x1406e4878 ??0CGXRange@@QEAA@KKKK@Z
0x1406e48f0 ??1CGXStyle@@UEAA@XZ
0x1406e48f8 ??0CGXStyle@@QEAA@XZ
库: mfc140u.dll:
0x1406e5c08 None
0x1406e5c10 None
0x1406e5c18 None
0x1406e5c20 None
0x1406e5c28 None
0x1406e5c30 None
0x1406e5c38 None
0x1406e5c40 None
0x1406e5c48 None
0x1406e5c50 None
0x1406e5c58 None
0x1406e5c60 None
0x1406e5c68 None
0x1406e5c70 None
0x1406e5c78 None
0x1406e5c80 None
0x1406e5c88 None
0x1406e5c90 None
0x1406e5c98 None
0x1406e5ca0 None
0x1406e5ca8 None
0x1406e5cb0 None
0x1406e5cb8 None
0x1406e5cc0 None
0x1406e5cc8 None
0x1406e5cd0 None
0x1406e5cd8 None
0x1406e5ce0 None
0x1406e5ce8 None
0x1406e5cf0 None
0x1406e5cf8 None
0x1406e5d00 None
0x1406e5d08 None
0x1406e5d10 None
0x1406e5d18 None
0x1406e5d20 None
0x1406e5d28 None
0x1406e5d30 None
0x1406e5d38 None
0x1406e5d40 None
0x1406e5d48 None
0x1406e5d50 None
0x1406e5d58 None
0x1406e5d60 None
0x1406e5d68 None
0x1406e5d70 None
0x1406e5d78 None
0x1406e5d80 None
0x1406e5d88 None
0x1406e5d90 None
0x1406e5d98 None
0x1406e5da0 None
0x1406e5da8 None
0x1406e5db0 None
0x1406e5db8 None
0x1406e5dc0 None
0x1406e5dc8 None
0x1406e5dd0 None
0x1406e5dd8 None
0x1406e5de0 None
0x1406e5de8 None
0x1406e5df0 None
0x1406e5df8 None
0x1406e5e00 None
0x1406e5e08 None
0x1406e5e10 None
0x1406e5e18 None
0x1406e5e20 None
0x1406e5e28 None
0x1406e5e30 None
0x1406e5e38 None
0x1406e5e40 None
0x1406e5e48 None
0x1406e5e50 None
0x1406e5e58 None
0x1406e5e60 None
0x1406e5e68 None
0x1406e5e70 None
0x1406e5e78 None
0x1406e5e80 None
0x1406e5e88 None
0x1406e5e90 None
0x1406e5e98 None
0x1406e5ea0 None
0x1406e5ea8 None
0x1406e5eb0 None
0x1406e5eb8 None
0x1406e5ec0 None
0x1406e5ec8 None
0x1406e5ed0 None
0x1406e5ed8 None
0x1406e5ee0 None
0x1406e5ee8 None
0x1406e5ef0 None
0x1406e5ef8 None
0x1406e5f00 None
0x1406e5f08 None
0x1406e5f10 None
0x1406e5f18 None
0x1406e5f20 None
0x1406e5f28 None
0x1406e5f30 None
0x1406e5f38 None
0x1406e5f40 None
0x1406e5f48 None
0x1406e5f50 None
0x1406e5f58 None
0x1406e5f60 None
0x1406e5f68 None
0x1406e5f70 None
0x1406e5f78 None
0x1406e5f80 None
0x1406e5f88 None
0x1406e5f90 None
0x1406e5f98 None
0x1406e5fa0 None
0x1406e5fa8 None
0x1406e5fb0 None
0x1406e5fb8 None
0x1406e5fc0 None
0x1406e5fc8 None
0x1406e5fd0 None
0x1406e5fd8 None
0x1406e5fe0 None
0x1406e5fe8 None
0x1406e5ff0 None
0x1406e5ff8 None
0x1406e6000 None
0x1406e6008 None
0x1406e6010 None
0x1406e6018 None
0x1406e6020 None
0x1406e6028 None
0x1406e6030 None
0x1406e6038 None
0x1406e6040 None
0x1406e6048 None
0x1406e6050 None
0x1406e6058 None
0x1406e6060 None
0x1406e6068 None
0x1406e6070 None
0x1406e6078 None
0x1406e6080 None
0x1406e6088 None
0x1406e6090 None
0x1406e6098 None
0x1406e60a0 None
0x1406e60a8 None
0x1406e60b0 None
0x1406e60b8 None
0x1406e60c0 None
0x1406e60c8 None
0x1406e60d0 None
0x1406e60d8 None
0x1406e60e0 None
0x1406e60e8 None
0x1406e60f0 None
0x1406e60f8 None
0x1406e6100 None
0x1406e6108 None
0x1406e6110 None
0x1406e6118 None
0x1406e6120 None
0x1406e6128 None
0x1406e6130 None
0x1406e6138 None
0x1406e6140 None
0x1406e6148 None
0x1406e6150 None
0x1406e6158 None
0x1406e6160 None
0x1406e6168 None
0x1406e6170 None
0x1406e6178 None
0x1406e6180 None
0x1406e6188 None
0x1406e6190 None
0x1406e6198 None
0x1406e61a0 None
0x1406e61a8 None
0x1406e61b0 None
0x1406e61b8 None
0x1406e61c0 None
0x1406e61c8 None
0x1406e61d0 None
0x1406e61d8 None
0x1406e61e0 None
0x1406e61e8 None
0x1406e61f0 None
0x1406e61f8 None
0x1406e6200 None
0x1406e6208 None
0x1406e6210 None
0x1406e6218 None
0x1406e6220 None
0x1406e6228 None
0x1406e6230 None
0x1406e6238 None
0x1406e6240 None
0x1406e6248 None
0x1406e6250 None
0x1406e6258 None
0x1406e6260 None
0x1406e6268 None
0x1406e6270 None
0x1406e6278 None
0x1406e6280 None
0x1406e6288 None
0x1406e6290 None
0x1406e6298 None
0x1406e62a0 None
0x1406e62a8 None
0x1406e62b0 None
0x1406e62b8 None
0x1406e62c0 None
0x1406e62c8 None
0x1406e62d0 None
0x1406e62d8 None
0x1406e62e0 None
0x1406e62e8 None
0x1406e62f0 None
0x1406e62f8 None
0x1406e6300 None
0x1406e6308 None
0x1406e6310 None
0x1406e6318 None
0x1406e6320 None
0x1406e6328 None
0x1406e6330 None
0x1406e6338 None
0x1406e6340 None
0x1406e6348 None
0x1406e6350 None
0x1406e6358 None
0x1406e6360 None
0x1406e6368 None
0x1406e6370 None
0x1406e6378 None
0x1406e6380 None
0x1406e6388 None
0x1406e6390 None
0x1406e6398 None
0x1406e63a0 None
0x1406e63a8 None
0x1406e63b0 None
0x1406e63b8 None
0x1406e63c0 None
0x1406e63c8 None
0x1406e63d0 None
0x1406e63d8 None
0x1406e63e0 None
0x1406e63e8 None
0x1406e63f0 None
0x1406e63f8 None
0x1406e6400 None
0x1406e6408 None
0x1406e6410 None
0x1406e6418 None
0x1406e6420 None
0x1406e6428 None
0x1406e6430 None
0x1406e6438 None
0x1406e6440 None
0x1406e6448 None
0x1406e6450 None
0x1406e6458 None
0x1406e6460 None
0x1406e6468 None
0x1406e6470 None
0x1406e6478 None
0x1406e6480 None
0x1406e6488 None
0x1406e6490 None
0x1406e6498 None
0x1406e64a0 None
0x1406e64a8 None
0x1406e64b0 None
0x1406e64b8 None
0x1406e64c0 None
0x1406e64c8 None
0x1406e64d0 None
0x1406e64d8 None
0x1406e64e0 None
0x1406e64e8 None
0x1406e64f0 None
0x1406e64f8 None
0x1406e6500 None
0x1406e6508 None
0x1406e6510 None
0x1406e6518 None
0x1406e6520 None
0x1406e6528 None
0x1406e6530 None
0x1406e6538 None
0x1406e6540 None
0x1406e6548 None
0x1406e6550 None
0x1406e6558 None
0x1406e6560 None
0x1406e6568 None
0x1406e6570 None
0x1406e6578 None
0x1406e6580 None
0x1406e6588 None
0x1406e6590 None
0x1406e6598 None
0x1406e65a0 None
0x1406e65a8 None
0x1406e65b0 None
0x1406e65b8 None
0x1406e65c0 None
0x1406e65c8 None
0x1406e65d0 None
0x1406e65d8 None
0x1406e65e0 None
0x1406e65e8 None
0x1406e65f0 None
0x1406e65f8 None
0x1406e6600 None
0x1406e6608 None
0x1406e6610 None
0x1406e6618 None
0x1406e6620 None
0x1406e6628 None
0x1406e6630 None
0x1406e6638 None
0x1406e6640 None
0x1406e6648 None
0x1406e6650 None
0x1406e6658 None
0x1406e6660 None
0x1406e6668 None
0x1406e6670 None
0x1406e6678 None
0x1406e6680 None
0x1406e6688 None
0x1406e6690 None
0x1406e6698 None
0x1406e66a0 None
0x1406e66a8 None
0x1406e66b0 None
0x1406e66b8 None
0x1406e66c0 None
0x1406e66c8 None
0x1406e66d0 None
0x1406e66d8 None
0x1406e66e0 None
0x1406e66e8 None
0x1406e66f0 None
0x1406e66f8 None
0x1406e6700 None
0x1406e6708 None
0x1406e6710 None
0x1406e6718 None
0x1406e6720 None
0x1406e6728 None
0x1406e6730 None
0x1406e6738 None
0x1406e6740 None
0x1406e6748 None
0x1406e6750 None
0x1406e6758 None
0x1406e6760 None
0x1406e6768 None
0x1406e6770 None
0x1406e6778 None
0x1406e6780 None
0x1406e6788 None
0x1406e6790 None
0x1406e6798 None
0x1406e67a0 None
0x1406e67a8 None
0x1406e67b0 None
0x1406e67b8 None
0x1406e67c0 None
0x1406e67c8 None
0x1406e67d0 None
0x1406e67d8 None
0x1406e67e0 None
0x1406e67e8 None
0x1406e67f0 None
0x1406e67f8 None
0x1406e6800 None
0x1406e6808 None
0x1406e6810 None
0x1406e6818 None
0x1406e6820 None
0x1406e6828 None
0x1406e6830 None
0x1406e6838 None
0x1406e6840 None
0x1406e6848 None
0x1406e6850 None
0x1406e6858 None
0x1406e6860 None
0x1406e6868 None
0x1406e6870 None
0x1406e6878 None
0x1406e6880 None
0x1406e6888 None
0x1406e6890 None
0x1406e6898 None
0x1406e68a0 None
0x1406e68a8 None
0x1406e68b0 None
0x1406e68b8 None
0x1406e68c0 None
0x1406e68c8 None
0x1406e68d0 None
0x1406e68d8 None
0x1406e68e0 None
0x1406e68e8 None
0x1406e68f0 None
0x1406e68f8 None
0x1406e6900 None
0x1406e6908 None
0x1406e6910 None
0x1406e6918 None
0x1406e6920 None
0x1406e6928 None
0x1406e6930 None
0x1406e6938 None
0x1406e6940 None
0x1406e6948 None
0x1406e6950 None
0x1406e6958 None
0x1406e6960 None
0x1406e6968 None
0x1406e6970 None
0x1406e6978 None
0x1406e6980 None
0x1406e6988 None
0x1406e6990 None
0x1406e6998 None
0x1406e69a0 None
0x1406e69a8 None
0x1406e69b0 None
0x1406e69b8 None
0x1406e69c0 None
0x1406e69c8 None
0x1406e69d0 None
0x1406e69d8 None
0x1406e69e0 None
0x1406e69e8 None
0x1406e69f0 None
0x1406e69f8 None
0x1406e6a00 None
0x1406e6a08 None
0x1406e6a10 None
0x1406e6a18 None
0x1406e6a20 None
0x1406e6a28 None
0x1406e6a30 None
0x1406e6a38 None
0x1406e6a40 None
0x1406e6a48 None
0x1406e6a50 None
0x1406e6a58 None
0x1406e6a60 None
0x1406e6a68 None
0x1406e6a70 None
0x1406e6a78 None
0x1406e6a80 None
0x1406e6a88 None
0x1406e6a90 None
0x1406e6a98 None
0x1406e6aa0 None
0x1406e6aa8 None
0x1406e6ab0 None
0x1406e6ab8 None
0x1406e6ac0 None
0x1406e6ac8 None
0x1406e6ad0 None
0x1406e6ad8 None
0x1406e6ae0 None
0x1406e6ae8 None
0x1406e6af0 None
0x1406e6af8 None
0x1406e6b00 None
0x1406e6b08 None
0x1406e6b10 None
0x1406e6b18 None
0x1406e6b20 None
0x1406e6b28 None
0x1406e6b30 None
0x1406e6b38 None
0x1406e6b40 None
0x1406e6b48 None
0x1406e6b50 None
0x1406e6b58 None
0x1406e6b60 None
0x1406e6b68 None
0x1406e6b70 None
0x1406e6b78 None
0x1406e6b80 None
0x1406e6b88 None
0x1406e6b90 None
0x1406e6b98 None
0x1406e6ba0 None
0x1406e6ba8 None
0x1406e6bb0 None
0x1406e6bb8 None
0x1406e6bc0 None
0x1406e6bc8 None
0x1406e6bd0 None
0x1406e6bd8 None
0x1406e6be0 None
0x1406e6be8 None
0x1406e6bf0 None
0x1406e6bf8 None
0x1406e6c00 None
0x1406e6c08 None
0x1406e6c10 None
0x1406e6c18 None
0x1406e6c20 None
0x1406e6c28 None
0x1406e6c30 None
0x1406e6c38 None
0x1406e6c40 None
0x1406e6c48 None
0x1406e6c50 None
0x1406e6c58 None
0x1406e6c60 None
0x1406e6c68 None
0x1406e6c70 None
0x1406e6c78 None
0x1406e6c80 None
0x1406e6c88 None
0x1406e6c90 None
0x1406e6c98 None
0x1406e6ca0 None
0x1406e6ca8 None
0x1406e6cb0 None
0x1406e6cb8 None
0x1406e6cc0 None
0x1406e6cc8 None
0x1406e6cd0 None
0x1406e6cd8 None
0x1406e6ce0 None
0x1406e6ce8 None
0x1406e6cf0 None
0x1406e6cf8 None
0x1406e6d00 None
0x1406e6d08 None
0x1406e6d10 None
0x1406e6d18 None
0x1406e6d20 None
0x1406e6d28 None
0x1406e6d30 None
0x1406e6d38 None
0x1406e6d40 None
0x1406e6d48 None
0x1406e6d50 None
0x1406e6d58 None
0x1406e6d60 None
0x1406e6d68 None
0x1406e6d70 None
0x1406e6d78 None
0x1406e6d80 None
0x1406e6d88 None
0x1406e6d90 None
0x1406e6d98 None
0x1406e6da0 None
0x1406e6da8 None
0x1406e6db0 None
0x1406e6db8 None
0x1406e6dc0 None
0x1406e6dc8 None
0x1406e6dd0 None
0x1406e6dd8 None
0x1406e6de0 None
0x1406e6de8 None
0x1406e6df0 None
0x1406e6df8 None
0x1406e6e00 None
0x1406e6e08 None
0x1406e6e10 None
0x1406e6e18 None
0x1406e6e20 None
0x1406e6e28 None
0x1406e6e30 None
0x1406e6e38 None
0x1406e6e40 None
0x1406e6e48 None
0x1406e6e50 None
0x1406e6e58 None
0x1406e6e60 None
0x1406e6e68 None
0x1406e6e70 None
0x1406e6e78 None
0x1406e6e80 None
0x1406e6e88 None
0x1406e6e90 None
0x1406e6e98 None
0x1406e6ea0 None
0x1406e6ea8 None
0x1406e6eb0 None
0x1406e6eb8 None
0x1406e6ec0 None
0x1406e6ec8 None
0x1406e6ed0 None
0x1406e6ed8 None
0x1406e6ee0 None
0x1406e6ee8 None
0x1406e6ef0 None
0x1406e6ef8 None
0x1406e6f00 None
0x1406e6f08 None
0x1406e6f10 None
0x1406e6f18 None
0x1406e6f20 None
0x1406e6f28 None
0x1406e6f30 None
0x1406e6f38 None
0x1406e6f40 None
0x1406e6f48 None
0x1406e6f50 None
0x1406e6f58 None
0x1406e6f60 None
0x1406e6f68 None
0x1406e6f70 None
0x1406e6f78 None
0x1406e6f80 None
0x1406e6f88 None
0x1406e6f90 None
0x1406e6f98 None
0x1406e6fa0 None
0x1406e6fa8 None
0x1406e6fb0 None
0x1406e6fb8 None
0x1406e6fc0 None
0x1406e6fc8 None
0x1406e6fd0 None
0x1406e6fd8 None
0x1406e6fe0 None
0x1406e6fe8 None
0x1406e6ff0 None
0x1406e6ff8 None
0x1406e7000 None
0x1406e7008 None
0x1406e7010 None
0x1406e7018 None
库: KERNEL32.dll:
0x1406d4410 GetTickCount
0x1406d4418 lstrcpyW
0x1406d4420 MulDiv
0x1406d4428 SetEvent
0x1406d4430 CreateEventW
0x1406d4438 WaitForMultipleObjects
0x1406d4440 LocalFree
0x1406d4448 ReadDirectoryChangesW
0x1406d4450 SetErrorMode
0x1406d4458 GlobalAlloc
0x1406d4460 GlobalUnlock
0x1406d4468 GlobalLock
0x1406d4470 DecodePointer
0x1406d4478 RaiseException
0x1406d4480 EnterCriticalSection
0x1406d4488 LeaveCriticalSection
0x1406d4498 DeleteCriticalSection
0x1406d44a0 FreeLibrary
0x1406d44a8 GetModuleFileNameW
0x1406d44b0 GetModuleHandleW
0x1406d44b8 GetProcAddress
0x1406d44c0 LoadLibraryExW
0x1406d44c8 LoadResource
0x1406d44d0 SizeofResource
0x1406d44d8 FindResourceW
0x1406d44e0 FormatMessageW
0x1406d44e8 lstrcmpiW
0x1406d44f0 MultiByteToWideChar
0x1406d44f8 SetCurrentDirectoryW
0x1406d4500 GetCurrentDirectoryW
0x1406d4508 LockResource
0x1406d4510 LoadLibraryA
0x1406d4518 lstrcpynW
0x1406d4520 FindClose
0x1406d4528 FindFirstFileW
0x1406d4530 FindNextFileW
0x1406d4538 LoadLibraryW
0x1406d4540 ReadFile
0x1406d4548 SetFilePointer
0x1406d4550 WriteFile
0x1406d4558 OutputDebugStringW
0x1406d4560 CopyFileW
0x1406d4568 MoveFileExW
0x1406d4570 GlobalSize
0x1406d4578 DeleteFileW
0x1406d4580 GetTempPathW
0x1406d4588 GetLongPathNameW
0x1406d4590 GetShortPathNameW
0x1406d4598 HeapFree
0x1406d45a0 GetProcessHeap
0x1406d45a8 WaitForSingleObject
0x1406d45b0 CreateThread
0x1406d45b8 GetExitCodeThread
0x1406d45c0 GetLocaleInfoW
0x1406d45c8 CreateFileW
0x1406d45d0 WideCharToMultiByte
0x1406d45d8 GetTempFileNameW
0x1406d45e0 GetCurrentThreadId
0x1406d45e8 CreateProcessW
0x1406d45f0 OpenProcess
0x1406d45f8 GetPrivateProfileStringW
0x1406d4600 K32EnumProcesses
0x1406d4608 K32EnumProcessModules
0x1406d4610 K32GetModuleBaseNameW
0x1406d4618 FatalExit
0x1406d4620 GetStdHandle
0x1406d4628 GetCurrentProcessId
0x1406d4630 GetFileAttributesW
0x1406d4638 CloseHandle
0x1406d4640 GetLastError
0x1406d4648 GetOverlappedResult
0x1406d4650 GlobalFree
0x1406d4658 CancelIo
0x1406d4660 CreateJobObjectW
0x1406d4668 AssignProcessToJobObject
0x1406d4670 SetInformationJobObject
0x1406d4678 IsValidLocale
0x1406d4680 GetUserDefaultLCID
0x1406d4688 FreeConsole
0x1406d4690 AttachConsole
0x1406d4698 K32GetModuleBaseNameA
0x1406d46a0 CreateToolhelp32Snapshot
0x1406d46a8 Process32FirstW
0x1406d46b0 Process32NextW
0x1406d46b8 GlobalMemoryStatus
0x1406d46c0 GetACP
0x1406d46c8 FatalAppExitW
0x1406d46d0 Sleep
0x1406d46d8 GetCommandLineW
0x1406d46e0 SetLastError
0x1406d46e8 FormatMessageA
0x1406d46f0 GetFileAttributesExW
0x1406d46f8 SetFileAttributesW
0x1406d4700 GetFileType
0x1406d4708 GetFileSizeEx
0x1406d4710 GetFileTime
0x1406d4718 SetFilePointerEx
0x1406d4720 GetSystemInfo
0x1406d4728 VirtualProtect
0x1406d4730 VirtualQuery
0x1406d4738 LoadLibraryExA
0x1406d4740 GetStartupInfoW
0x1406d4748 IsDebuggerPresent
0x1406d4750 GetSystemTimeAsFileTime
0x1406d4758 QueryPerformanceCounter
0x1406d4760 InitializeSListHead
0x1406d4770 TerminateProcess
0x1406d4778 GetCurrentProcess
0x1406d4788 UnhandledExceptionFilter
0x1406d4790 RtlVirtualUnwind
0x1406d4798 RtlLookupFunctionEntry
0x1406d47a0 RtlCaptureContext
0x1406d47a8 ReadConsoleW
0x1406d47b0 ReadConsoleA
0x1406d47b8 SetConsoleMode
0x1406d47c0 GetConsoleMode
0x1406d47c8 GetSystemDirectoryA
0x1406d47d0 VirtualFree
0x1406d47d8 GetEnvironmentVariableW
0x1406d47e0 TlsFree
0x1406d47e8 TlsSetValue
0x1406d47f0 TlsGetValue
0x1406d47f8 TlsAlloc
0x1406d4800 AcquireSRWLockShared
0x1406d4808 ReleaseSRWLockShared
0x1406d4810 InitializeSRWLock
0x1406d4818 InitOnceComplete
0x1406d4820 InitOnceBeginInitialize
0x1406d4830 AreFileApisANSI
0x1406d4840 FindFirstFileExW
0x1406d4848 GetLocaleInfoEx
0x1406d4858 WakeAllConditionVariable
0x1406d4860 AcquireSRWLockExclusive
0x1406d4868 ReleaseSRWLockExclusive
0x1406d4870 GlobalReAlloc
0x1406d4878 LocalAlloc
0x1406d4880 GetModuleHandleExW
库: USER32.dll:
0x1406e4a80 SetCaretPos
0x1406e4a88 ShowCaret
0x1406e4a90 HideCaret
0x1406e4a98 GetOpenClipboardWindow
0x1406e4aa0 PostQuitMessage
0x1406e4aa8 GetScrollRange
0x1406e4ab0 DdeAccessData
0x1406e4ab8 GetScrollPos
0x1406e4ac0 SetScrollPos
0x1406e4ac8 SetKeyboardState
0x1406e4ad0 GetKeyboardState
0x1406e4ad8 GetMonitorInfoW
0x1406e4ae0 MonitorFromWindow
0x1406e4ae8 EnumChildWindows
0x1406e4af0 SendInput
0x1406e4af8 EndDeferWindowPos
0x1406e4b00 DeferWindowPos
0x1406e4b08 BeginDeferWindowPos
0x1406e4b10 CallWindowProcW
0x1406e4b18 GetWindowThreadProcessId
0x1406e4b20 SetScrollRange
0x1406e4b28 GetCapture
0x1406e4b38 EnableMenuItem
0x1406e4b50 MapWindowPoints
0x1406e4b58 SetRect
0x1406e4b60 RemoveMenu
0x1406e4b68 GetDialogBaseUnits
0x1406e4b70 DdeCmpStringHandles
0x1406e4b78 DdeGetLastError
0x1406e4b80 DdeFreeDataHandle
0x1406e4b88 DdeClientTransaction
0x1406e4b90 DdeQueryConvInfo
0x1406e4b98 DdeDisconnect
0x1406e4ba0 DdeConnect
0x1406e4ba8 IsWindowUnicode
0x1406e4bb0 DdeFreeStringHandle
0x1406e4bb8 DdeQueryStringW
0x1406e4bc0 DdeCreateStringHandleW
0x1406e4bc8 DdeUnaccessData
0x1406e4bd0 PostMessageW
0x1406e4bd8 EnableWindow
0x1406e4be0 SendMessageW
0x1406e4be8 GetDC
0x1406e4bf0 ReleaseDC
0x1406e4bf8 SetWindowPos
0x1406e4c00 IsWindowVisible
0x1406e4c08 SetTimer
0x1406e4c10 KillTimer
0x1406e4c18 GetClientRect
0x1406e4c20 GetParent
0x1406e4c28 TranslateMessage
0x1406e4c30 DispatchMessageW
0x1406e4c38 PeekMessageW
0x1406e4c40 DestroyWindow
0x1406e4c48 GetSystemMetrics
0x1406e4c50 GetSystemMenu
0x1406e4c58 GetMenuItemID
0x1406e4c60 GetMenuItemCount
0x1406e4c68 AppendMenuW
0x1406e4c70 DeleteMenu
0x1406e4c78 GetWindowRect
0x1406e4c80 GetWindowLongW
0x1406e4c88 SetWindowLongW
0x1406e4c90 InflateRect
0x1406e4c98 SetParent
0x1406e4ca0 UnionRect
0x1406e4ca8 GetKeyState
0x1406e4cb0 RedrawWindow
0x1406e4cb8 UpdateWindow
0x1406e4cc0 GetSysColor
0x1406e4cc8 OpenClipboard
0x1406e4cd0 CloseClipboard
0x1406e4cd8 SetClipboardData
0x1406e4ce0 EmptyClipboard
0x1406e4ce8 IsRectEmpty
0x1406e4cf0 GetCursorPos
0x1406e4cf8 GetFocus
0x1406e4d00 LoadStringW
0x1406e4d08 UnregisterClassW
0x1406e4d10 IsWindow
0x1406e4d18 CharNextW
0x1406e4d20 MapVirtualKeyW
0x1406e4d28 OffsetRect
0x1406e4d30 SystemParametersInfoW
0x1406e4d38 GetActiveWindow
0x1406e4d40 LoadMenuW
0x1406e4d48 SetCursorPos
0x1406e4d50 EqualRect
0x1406e4d58 LoadAcceleratorsW
0x1406e4d60 TranslateAcceleratorW
0x1406e4d68 BeginPaint
0x1406e4d70 EndPaint
0x1406e4d78 DefWindowProcW
0x1406e4d80 RegisterClassW
0x1406e4d88 CreateWindowExW
0x1406e4d90 SetWindowLongPtrW
0x1406e4d98 LoadCursorW
0x1406e4da0 LoadImageW
0x1406e4da8 MapDialogRect
0x1406e4db0 SetFocus
0x1406e4db8 CreateMenu
0x1406e4dc0 DestroyMenu
0x1406e4dc8 GetSubMenu
0x1406e4dd0 GetMenuItemInfoW
0x1406e4dd8 LockWindowUpdate
0x1406e4de0 ShowWindow
0x1406e4de8 DialogBoxParamW
0x1406e4df0 EndDialog
0x1406e4df8 GetDlgItem
0x1406e4e00 CheckDlgButton
0x1406e4e08 IsDlgButtonChecked
0x1406e4e10 SetWindowTextW
0x1406e4e18 GetWindowTextW
0x1406e4e20 GetWindowTextLengthW
0x1406e4e28 GetWindowLongPtrW
0x1406e4e30 SetWindowsHookExW
0x1406e4e38 UnhookWindowsHookEx
0x1406e4e40 CallNextHookEx
0x1406e4e48 MoveWindow
0x1406e4e50 BringWindowToTop
0x1406e4e58 GetDlgItemTextW
0x1406e4e60 CheckRadioButton
0x1406e4e68 SendDlgItemMessageW
0x1406e4e70 GetNextDlgTabItem
0x1406e4e78 GetDlgCtrlID
0x1406e4e80 IsWindowEnabled
0x1406e4e88 CreatePopupMenu
0x1406e4e90 CheckMenuItem
0x1406e4e98 TrackPopupMenu
0x1406e4ea0 DrawTextW
0x1406e4ea8 InvalidateRect
0x1406e4eb0 ClientToScreen
0x1406e4eb8 FillRect
0x1406e4ec0 FrameRect
0x1406e4ec8 GetClassNameW
0x1406e4ed0 LoadBitmapW
0x1406e4ed8 SetCursor
0x1406e4ee0 DestroyIcon
0x1406e4ee8 CreateIconIndirect
0x1406e4ef0 SetDlgItemTextW
0x1406e4ef8 RegisterClipboardFormatW
0x1406e4f00 SetActiveWindow
0x1406e4f08 MessageBeep
0x1406e4f10 GetClipboardData
0x1406e4f18 GetAsyncKeyState
0x1406e4f20 IsDialogMessageW
0x1406e4f28 ScreenToClient
0x1406e4f30 ChildWindowFromPoint
0x1406e4f38 PtInRect
0x1406e4f40 RegisterWindowMessageW
0x1406e4f48 ReplyMessage
0x1406e4f50 InSendMessage
0x1406e4f58 ReleaseCapture
0x1406e4f60 GetDoubleClickTime
0x1406e4f68 wsprintfW
0x1406e4f78 IsIconic
0x1406e4f80 SetCapture
0x1406e4f88 SetRectEmpty
0x1406e4f90 GetProcessWindowStation
0x1406e4fa0 MessageBoxW
0x1406e4fa8 LoadIconW
0x1406e4fb0 ShowScrollBar
0x1406e4fb8 DdeInitializeW
0x1406e4fc0 DdePostAdvise
0x1406e4fc8 DdeNameService
0x1406e4fd0 DdeCreateDataHandle
0x1406e4fd8 DdeGetData
0x1406e4fe0 GetCaretPos
0x1406e4fe8 PostThreadMessageW
库: GDI32.dll:
0x1406d4248 Ellipse
0x1406d4250 EnumFontFamiliesW
0x1406d4258 ExtCreatePen
0x1406d4260 Rectangle
0x1406d4268 DPtoLP
0x1406d4270 SetMapMode
0x1406d4278 GetMapMode
0x1406d4280 CreateBitmap
0x1406d4288 EnumFontFamiliesExW
0x1406d4290 SetDIBColorTable
0x1406d4298 CreateDIBSection
0x1406d42a0 StretchBlt
0x1406d42a8 CreateDIBitmap
0x1406d42b0 Escape
0x1406d42b8 SetAbortProc
0x1406d42c0 AbortDoc
0x1406d42c8 EndPage
0x1406d42d0 StartPage
0x1406d42d8 EndDoc
0x1406d42e0 StartDocW
0x1406d42e8 SetPixel
0x1406d42f0 GetPixel
0x1406d42f8 DeleteDC
0x1406d4300 CreateCompatibleBitmap
0x1406d4308 TextOutW
0x1406d4310 MoveToEx
0x1406d4318 SetBkMode
0x1406d4320 SetBkColor
0x1406d4328 LineTo
0x1406d4330 GetTextExtentPointW
0x1406d4338 CreateSolidBrush
0x1406d4340 CreateBrushIndirect
0x1406d4348 SelectObject
0x1406d4350 DeleteObject
0x1406d4358 CreateFontW
0x1406d4360 GetDIBColorTable
0x1406d4368 RealizePalette
0x1406d4370 GetStockObject
0x1406d4378 CreatePalette
0x1406d4380 CreateCompatibleDC
0x1406d4388 BitBlt
0x1406d4390 CreatePen
0x1406d4398 GetCurrentObject
0x1406d43a0 GetWindowExtEx
0x1406d43a8 GetViewportExtEx
0x1406d43b0 GetTextMetricsW
0x1406d43b8 GetTextExtentPoint32W
0x1406d43c0 GetObjectW
0x1406d43c8 GetDeviceCaps
0x1406d43d0 CreateFontIndirectW
库: COMDLG32.dll:
0x1406d41a0 GetSaveFileNameW
0x1406d41a8 GetOpenFileNameW
0x1406d41b0 CommDlgExtendedError
0x1406d41b8 PrintDlgW
库: ADVAPI32.dll:
0x1406d4000 CryptGetHashParam
0x1406d4008 RegDeleteKeyW
0x1406d4010 RegDeleteValueW
0x1406d4018 RegOpenKeyW
0x1406d4020 RegCloseKey
0x1406d4028 RegEnumKeyExW
0x1406d4030 CryptEnumProvidersW
0x1406d4038 CryptSignHashW
0x1406d4040 CryptExportKey
0x1406d4048 CryptGetUserKey
0x1406d4050 CryptGetProvParam
0x1406d4058 CryptSetHashParam
0x1406d4060 ReportEventW
0x1406d4068 RegisterEventSourceW
0x1406d4070 DeregisterEventSource
0x1406d4078 RegOpenKeyExW
0x1406d4080 RegQueryInfoKeyW
0x1406d4088 RegQueryValueExW
0x1406d4090 RegCreateKeyW
0x1406d4098 RegCreateKeyExW
0x1406d40a0 RegSetValueExW
0x1406d40a8 RegCopyTreeW
0x1406d40b0 CryptAcquireContextW
0x1406d40b8 CryptReleaseContext
0x1406d40c0 CryptCreateHash
0x1406d40c8 CryptHashData
0x1406d40d0 CryptDestroyHash
0x1406d40d8 CryptDeriveKey
0x1406d40e0 GetSecurityInfo
0x1406d40e8 RegFlushKey
0x1406d40f0 CryptDecrypt
0x1406d40f8 CryptDestroyKey
库: SHELL32.dll:
0x1406e4a00 DragFinish
0x1406e4a08 ShellExecuteW
0x1406e4a10 SHGetFolderPathW
0x1406e4a18 DragAcceptFiles
0x1406e4a20 CommandLineToArgvW
0x1406e4a28 SHFileOperationW
0x1406e4a30 None
0x1406e4a38 DragQueryFileW
库: COMCTL32.dll:
0x1406d4188 _TrackMouseEvent
0x1406d4190 None
库: SHLWAPI.dll:
0x1406e4a48 PathFileExistsW
0x1406e4a50 UrlUnescapeW
0x1406e4a58 PathFindExtensionW
0x1406e4a60 None
库: ole32.dll:
0x1406e7028 GetHGlobalFromStream
0x1406e7030 CreateStreamOnHGlobal
0x1406e7038 CoCreateGuid
0x1406e7040 OleFlushClipboard
0x1406e7048 OleUninitialize
0x1406e7050 OleInitialize
0x1406e7058 CoResumeClassObjects
0x1406e7060 StgIsStorageFile
0x1406e7068 StgOpenStorage
0x1406e7078 GetHGlobalFromILockBytes
0x1406e7090 StgCreateDocfile
0x1406e7098 CLSIDFromString
0x1406e70a0 IIDFromString
0x1406e70a8 CoInitialize
0x1406e70b0 CoTaskMemFree
0x1406e70b8 CoTaskMemRealloc
0x1406e70c0 CoTaskMemAlloc
0x1406e70c8 StringFromGUID2
0x1406e70d0 ProgIDFromCLSID
0x1406e70d8 CoCreateInstance
0x1406e70e0 CoRevokeClassObject
0x1406e70e8 CoRegisterClassObject
0x1406e70f0 CoUninitialize
库: ODBC32.dll:
0x1406e4978 None
0x1406e4980 None
0x1406e4988 None
0x1406e4990 None
0x1406e4998 None
0x1406e49a0 None
0x1406e49a8 None
0x1406e49b0 None
0x1406e49b8 None
0x1406e49c0 None
0x1406e49c8 None
0x1406e49d0 None
0x1406e49d8 None
0x1406e49e0 None
库: CRYPT32.dll:
0x1406d41e8 CryptProtectData
0x1406d41f0 CryptBinaryToStringA
0x1406d4200 CertOpenStore
0x1406d4208 CertCloseStore
0x1406d4210 CryptUnprotectData
0x1406d4218 CryptStringToBinaryA
库: MSVCP140.dll:
0x1406d4898 ?_Xbad_alloc@std@@YAXXZ
0x1406d48b0 _Thrd_join
0x1406d48b8 _Thrd_id
0x1406d48c0 _Mtx_init_in_situ
0x1406d48c8 _Mtx_destroy_in_situ
0x1406d48d0 _Mtx_lock
0x1406d48d8 _Mtx_unlock
0x1406d48e0 _Cnd_init_in_situ
0x1406d48e8 _Cnd_destroy_in_situ
0x1406d48f0 _Cnd_wait
0x1406d48f8 _Cnd_broadcast
0x1406d4900 _Cnd_signal
0x1406d4988 ??0_Lockit@std@@QEAA@H@Z
0x1406d4990 ??1_Lockit@std@@QEAA@XZ
0x1406d4c48 _Strcoll
0x1406d4c50 _Strxfrm
0x1406d4c60 ??1_Locinfo@std@@QEAA@XZ
0x1406d4cd0 _Xtime_get_ticks
0x1406d4cd8 _Query_perf_counter
0x1406d4ce0 _Query_perf_frequency
0x1406d4ce8 _Thrd_detach
0x1406d4cf0 _Mtx_current_owns
0x1406d4cf8 _Mtx_trylock
0x1406d4d00 _Cnd_timedwait
0x1406d4d08 _Wcscoll
0x1406d4d10 _Wcsxfrm
0x1406d4d60 _Thrd_sleep
库: gdiplus.dll:
0x1406e58a8 GdipGetImageHeight
0x1406e58b0 GdipGetImagePixelFormat
0x1406e58c0 GdipSaveImageToFile
0x1406e58c8 GdipDisposeImage
0x1406e58d0 GdipCloneImage
0x1406e58d8 GdiplusShutdown
0x1406e58e0 GdipGetImagePalette
0x1406e58e8 GdipGetImagePaletteSize
0x1406e58f0 GdiplusStartup
0x1406e58f8 GdipFree
0x1406e5918 GdipBitmapLockBits
0x1406e5920 GdipBitmapUnlockBits
0x1406e5928 GdipDeleteGraphics
0x1406e5930 GdipDrawImageI
0x1406e5938 GdipGetImageEncodersSize
0x1406e5940 GdipGetImageWidth
0x1406e5948 GdipAlloc
0x1406e5950 GdipGetImageEncoders
库: SensApi.dll:
0x1406e4a70 IsNetworkAlive
库: WININET.dll:
库: WS2_32.dll:
0x1406e50d8 select
0x1406e50e0 socket
0x1406e50e8 WSAStartup
0x1406e50f0 WSACleanup
0x1406e50f8 ioctlsocket
0x1406e5100 bind
0x1406e5108 getsockname
0x1406e5110 getaddrinfo
0x1406e5118 shutdown
0x1406e5120 connect
0x1406e5128 gethostbyaddr
0x1406e5130 closesocket
0x1406e5138 htons
0x1406e5140 getsockopt
0x1406e5148 inet_ntoa
0x1406e5150 getservbyport
0x1406e5158 ntohs
0x1406e5160 WSAGetLastError
0x1406e5168 gethostbyname
0x1406e5170 htonl
0x1406e5178 inet_addr
0x1406e5180 send
0x1406e5188 recv
0x1406e5190 getservbyname
0x1406e5198 WSASetLastError
0x1406e51a0 setsockopt
库: VCRUNTIME140.dll:
0x1406e4ff8 __std_type_info_name
0x1406e5000 strstr
0x1406e5008 wcsrchr
0x1406e5010 set_unexpected
0x1406e5018 strrchr
0x1406e5020 __C_specific_handler
0x1406e5028 __current_exception
0x1406e5038 __RTtypeid
0x1406e5040 wcschr
0x1406e5048 wcsstr
0x1406e5050 strchr
0x1406e5058 memchr
0x1406e5060 memset
0x1406e5068 _purecall
0x1406e5070 memcmp
0x1406e5078 __RTDynamicCast
0x1406e5080 _CxxThrowException
0x1406e5088 __std_exception_destroy
0x1406e5090 __std_exception_copy
0x1406e5098 memmove
0x1406e50a0 memcpy
0x1406e50a8 __std_terminate
库: VCRUNTIME140_1.dll:
0x1406e50b8 __CxxFrameHandler4
库: api-ms-win-crt-runtime-l1-1-0.dll:
0x1406e5360 _crt_atexit
0x1406e5368 _errno
0x1406e5380 _initialize_onexit_table
0x1406e5388 abort
0x1406e5390 terminate
0x1406e5398 _beginthreadex
0x1406e53a0 raise
0x1406e53a8 strerror_s
0x1406e53b8 _c_exit
0x1406e53c0 _cexit
0x1406e53c8 _exit
0x1406e53d0 signal
0x1406e53e0 _initterm_e
0x1406e53e8 _initterm
0x1406e53f8 _resetstkoflw
0x1406e5400 exit
0x1406e5408 _seh_filter_exe
0x1406e5410 _set_app_type
0x1406e5418 _configure_wide_argv
库: api-ms-win-crt-string-l1-1-0.dll:
0x1406e5588 strspn
0x1406e5590 isdigit
0x1406e5598 wcscat
0x1406e55a0 isupper
0x1406e55a8 iswgraph
0x1406e55b0 wcsncpy
0x1406e55b8 strcpy
0x1406e55c0 _wcsicmp
0x1406e55c8 strcspn
0x1406e55d0 wcsncpy_s
0x1406e55d8 wcscat_s
0x1406e55e0 strcat
0x1406e55e8 strcmp
0x1406e55f0 strncmp
0x1406e55f8 isspace
0x1406e5600 wcscmp
0x1406e5608 strncpy
0x1406e5610 strcpy_s
0x1406e5618 wcstok
0x1406e5620 wcscpy_s
0x1406e5628 wcsncmp
0x1406e5630 wcsncat
0x1406e5638 strlen
0x1406e5640 _wcsdup
0x1406e5648 strcat_s
0x1406e5650 wcslen
0x1406e5658 strncpy_s
0x1406e5660 _wcsupr
0x1406e5668 tolower
0x1406e5670 wcscpy
0x1406e5678 _stricmp
0x1406e5680 _strdup
库: api-ms-win-crt-math-l1-1-0.dll:
0x1406e52e8 log
0x1406e52f0 nextafter
0x1406e52f8 round
0x1406e5300 _dtest
0x1406e5308 __setusermatherr
0x1406e5310 log10
0x1406e5318 ceilf
0x1406e5320 ceil
0x1406e5328 sqrt
0x1406e5330 fmod
0x1406e5338 pow
0x1406e5340 floor
库: api-ms-win-crt-heap-l1-1-0.dll:
0x1406e5280 realloc
0x1406e5288 free
0x1406e5290 malloc
0x1406e5298 _recalloc
0x1406e52a0 _set_new_mode
0x1406e52a8 calloc
库: api-ms-win-crt-stdio-l1-1-0.dll:
0x1406e5430 _open_osfhandle
0x1406e5438 _wfdopen
0x1406e5440 _setmode
0x1406e5448 _fileno
0x1406e5450 _set_fmode
0x1406e5458 fgets
0x1406e5460 ferror
0x1406e5468 feof
0x1406e5470 fseek
0x1406e5478 fputc
0x1406e5488 __stdio_common_vswscanf
0x1406e5490 __stdio_common_vsprintf
0x1406e54a0 __stdio_common_vsscanf
0x1406e54b0 fclose
0x1406e54b8 fread
0x1406e54c0 fgetws
0x1406e54c8 __stdio_common_vfwprintf
0x1406e54d0 _wfopen
0x1406e54d8 fgetwc
0x1406e54e0 fputwc
0x1406e54e8 ungetwc
0x1406e54f0 fflush
0x1406e54f8 fgetc
0x1406e5500 fgetpos
0x1406e5508 fsetpos
0x1406e5510 _fseeki64
0x1406e5518 fwrite
0x1406e5520 setvbuf
0x1406e5528 ungetc
0x1406e5538 __stdio_common_vswprintf
0x1406e5540 __stdio_common_vfprintf
0x1406e5548 __acrt_iob_func
0x1406e5550 rewind
0x1406e5558 _wfopen_s
0x1406e5560 ftell
0x1406e5568 __p__commode
0x1406e5570 fopen
0x1406e5578 fputs
库: api-ms-win-crt-filesystem-l1-1-0.dll:
0x1406e5210 _stat64i32
0x1406e5218 _wmakepath
0x1406e5220 _wsplitpath
0x1406e5228 _findclose
0x1406e5230 _unlock_file
0x1406e5238 _wchdir
0x1406e5240 _splitpath_s
0x1406e5248 _wfindfirst64i32
0x1406e5250 _waccess
0x1406e5258 _wfullpath
0x1406e5260 _wstat64i32
0x1406e5268 _wremove
0x1406e5270 _lock_file
库: api-ms-win-crt-convert-l1-1-0.dll:
0x1406e51b0 wcstod
0x1406e51b8 _wtoi
0x1406e51c0 _itow
0x1406e51c8 strtol
0x1406e51d0 strtoul
0x1406e51d8 atoi
0x1406e51e0 atof
0x1406e51e8 _wtol
库: api-ms-win-crt-utility-l1-1-0.dll:
0x1406e56d0 qsort
0x1406e56d8 labs
0x1406e56e0 srand
0x1406e56e8 rand
0x1406e56f0 abs
库: api-ms-win-crt-time-l1-1-0.dll:
0x1406e5690 _ftime64_s
0x1406e5698 wcsftime
0x1406e56a0 _time64
0x1406e56a8 _gmtime64_s
0x1406e56b0 _mkgmtime64
0x1406e56b8 _localtime64
0x1406e56c0 _mktime64
库: api-ms-win-crt-environment-l1-1-0.dll:
0x1406e51f8 getenv
0x1406e5200 _wgetcwd
库: api-ms-win-crt-locale-l1-1-0.dll:
0x1406e52b8 localeconv
0x1406e52c0 ___lc_codepage_func
0x1406e52c8 setlocale
0x1406e52d0 _configthreadlocale
0x1406e52d8 _wsetlocale
库: api-ms-win-crt-multibyte-l1-1-0.dll:
0x1406e5350 _mbslen
库: bcrypt.dll:
0x1406e5700 BCryptGenRandom

导出

序列 地址 名称
1 0x1409bc144 ?FLAGS_ceflog@fLI@@3HA
2 0x1409f90b0 ?FLAGS_config_modelops_domain@fLS@@3AEAV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@EA
3 0x1409f9110 ?FLAGS_dev_commands_yaml_file@fLS@@3AEAV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@EA
4 0x1409f8f52 ?FLAGS_dev_enable_output_pane_dev@fLB@@3_NA
5 0x1409f8f50 ?FLAGS_dev_enable_show_dev_tools@fLB@@3_NA
6 0x1409f90d0 ?FLAGS_dev_server_deployment@fLS@@3AEAV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@EA
7 0x1409f8f00 ?FLAGS_feature_itable_raw_html_copy@fLB@@3_NA
8 0x1409f8f02 ?FLAGS_force_local_help@fLB@@3_NA
9 0x1409f8f54 ?FLAGS_lcid@fLI@@3HA
10 0x1409f9100 ?FLAGS_lp_auth@fLS@@3AEAV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@EA
11 0x1409bc154 ?FLAGS_lp_auth_heartbeat_frequency@fLI@@3HA
12 0x1409bc14c ?FLAGS_lp_auth_offline_expiry@fLI@@3HA
13 0x1409f8f04 ?FLAGS_maxsession@fLB@@3_NA
14 0x1409f8f06 ?FLAGS_overwrite_newer@fLB@@3_NA
15 0x1409f8f0c ?FLAGS_regserver@fLB@@3_NA
16 0x1409f8f08 ?FLAGS_show_packages@fLB@@3_NA
17 0x1409f8f0a ?FLAGS_sixsigma@fLB@@3_NA
18 0x1409bc140 ?FLAGS_splash@fLB@@3_NA
19 0x1409f8f0e ?FLAGS_unregserver@fLB@@3_NA
20 0x1409f90e0 ?FLAGS_update_domain@fLS@@3AEAV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@EA
21 0x1409f90f0 ?FLAGS_xmlout@fLS@@3AEAV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@EA
22 0x1404881a0 ?mClone@CmREMLCategoricalTerm@@QEAAPEAVImLinearModelTerm@@XZ
23 0x1402a5000 UpdateWksInfo
24 0x1401439a0 mDoesAboutBoxExist
25 0x1402b85d0 mGetFileName
26 0x1403ec2b0 mIsEditorMenuName
27 0x1403eb000 mIsMtbCommandAllowed
28 0x1401439b0 mKillAboutBox
29 0x1403eb0d0 mNowInPopupMenu
30 0x1403eb0f0 mOKToDisplayPopupMenu
.text
`.rdata
@.data
.pdata
@.didat
.rsrc
@.reloc
T$(3E
AES for x86_64, CRYPTOGAMS by <appro@openssl.org>
*p[[[[[[[[[[[[[[[[
Vector Permutation AES for x86_64/SSSE3, Mike Hamburg (Stanford University)
sper, Peter Schwabe, Andy Polyakov
AES for Intel AES-NI, CRYPTOGAMS by <appro@openssl.org>
AES-NI GCM module for x86_64, CRYPTOGAMS by <appro@openssl.org>
GHASH for x86_64, CRYPTOGAMS by <appro@openssl.org>
SHA1 block transform for x86_64, CRYPTOGAMS by <appro@openssl.org>
SHA256 block transform for x86_64, CRYPTOGAMS by <appro@openssl.org>
SHA512 block transform for x86_64, CRYPTOGAMS by <appro@openssl.org>
Keccak-1600 absorb and squeeze for x86_64, CRYPTOGAMS by <appro@openssl.org>
rc4(8x,int)
rc4(8x,char)
rc4(16x,int)
RC4 for x86_64, CRYPTOGAMS by <appro@openssl.org>
没有防病毒引擎扫描信息!

访问主机纪录 (可点击查询WPING实时安全评级)

直接 IP 安全评级 地理位置
104.18.38.233 美国
152.195.38.76 美国

TCP

源地址 源端口 目标地址 目标端口
192.168.122.202 49160 104.18.38.233 crt.usertrust.com 80
192.168.122.202 49159 152.195.38.76 cacerts.digicert.com 80
192.168.122.202 49157 23.2.13.225 80

UDP

源地址 源端口 目标地址 目标端口
192.168.122.202 50785 192.168.122.1 53
192.168.122.202 57208 192.168.122.1 53
192.168.122.202 62960 192.168.122.1 53

域名解析 (可点击查询WPING实时安全评级)

域名 安全评级 响应
cacerts.digicert.com CNAME fp2e7a.wpc.2be4.phicdn.net
CNAME fp2e7a.wpc.phicdn.net
A 152.195.38.76
crt.usertrust.com A 104.18.38.233
CNAME crt.comodoca.com
A 172.64.149.23
CNAME crt.comodoca.com.cdn.cloudflare.net

TCP

源地址 源端口 目标地址 目标端口
192.168.122.202 49160 104.18.38.233 crt.usertrust.com 80
192.168.122.202 49159 152.195.38.76 cacerts.digicert.com 80
192.168.122.202 49157 23.2.13.225 80

UDP

源地址 源端口 目标地址 目标端口
192.168.122.202 50785 192.168.122.1 53
192.168.122.202 57208 192.168.122.1 53
192.168.122.202 62960 192.168.122.1 53

HTTP 请求

URI HTTP数据
URL专业沙箱检测 -> http://acroipm.adobe.com/11/rdr/CHS/win/nooem/none/message.zip
GET /11/rdr/CHS/win/nooem/none/message.zip HTTP/1.1
Accept: */*
If-Modified-Since: Mon, 08 Nov 2017 08:44:36 GMT
User-Agent: IPM
Host: acroipm.adobe.com
Connection: Keep-Alive
Cache-Control: no-cache

URL专业沙箱检测 -> http://cacerts.digicert.com/DigiCertTrustedRootG4.crt
GET /DigiCertTrustedRootG4.crt HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: cacerts.digicert.com

URL专业沙箱检测 -> http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt
GET /USERTrustRSAAddTrustCA.crt HTTP/1.1
Connection: Keep-Alive
Accept: */*
User-Agent: Microsoft-CryptoAPI/6.1
Host: crt.usertrust.com

SMTP 流量

无SMTP流量.

IRC 流量

无IRC请求.

ICMP 流量

无ICMP流量.

CIF 报告

无 CIF 结果

网络警报

无警报

TLS

No TLS

Suricata HTTP

No Suricata HTTP

未发现网络提取文件
抱歉! 没有任何文件投放。
没有发现相似的分析.
HTML 总结报告
(需15-60分钟同步)
下载

Processing ( 34.508 seconds )

  • 14.388 Static
  • 11.303 Suricata
  • 5.921 NetworkAnalysis
  • 2.618 TargetInfo
  • 0.228 peid
  • 0.022 config_decoder
  • 0.013 AnalysisInfo
  • 0.011 Strings
  • 0.002 BehaviorAnalysis
  • 0.002 Memory

Signatures ( 9.72 seconds )

  • 8.076 network_http
  • 1.555 proprietary_url_bl
  • 0.013 proprietary_domain_bl
  • 0.012 antiav_detectreg
  • 0.006 anomaly_persistence_autorun
  • 0.006 infostealer_ftp
  • 0.005 antiav_detectfile
  • 0.004 geodo_banking_trojan
  • 0.004 infostealer_im
  • 0.004 ransomware_extensions
  • 0.004 ransomware_files
  • 0.003 infostealer_bitcoin
  • 0.002 tinba_behavior
  • 0.002 rat_nanocore
  • 0.002 antianalysis_detectreg
  • 0.002 antivm_vbox_files
  • 0.002 disables_browser_warn
  • 0.002 infostealer_mail
  • 0.002 network_torgateway
  • 0.001 betabot_behavior
  • 0.001 cerber_behavior
  • 0.001 antivm_parallels_keys
  • 0.001 banker_zeus_mutex
  • 0.001 bot_drive
  • 0.001 bot_drive2
  • 0.001 browser_security
  • 0.001 modify_proxy
  • 0.001 proprietary_malicious_drop_executable_file_to_temp_folder
  • 0.001 proprietary_bad_drop
  • 0.001 network_cnc_http
  • 0.001 stealth_hide_notifications
  • 0.001 stealth_modify_uac_prompt
  • 0.001 stealth_modify_security_center_warnings

Reporting ( 0.6 seconds )

  • 0.595 ReportHTMLSummary
  • 0.005 Malheur
Task ID 743103
Mongo ID 6603a5967e769a7994a59b86
Cuckoo release 1.4-Maldun