D:\S500RAT\S500RAT\Compression7zip\obj\Release\Compression7zip.pdb
Overview
overview
7Static
static
7S500 RAT.zip
windows7-x64
1S500 RAT.zip
windows10-2004-x64
1S500 RAT/....pi.vbs
windows7-x64
1S500 RAT/....pi.vbs
windows10-2004-x64
1S500 RAT/B...to.dll
windows7-x64
1S500 RAT/B...to.dll
windows10-2004-x64
1S500 RAT/C...ip.dll
windows7-x64
1S500 RAT/C...ip.dll
windows10-2004-x64
1S500 RAT/F...ox.dll
windows7-x64
1S500 RAT/F...ox.dll
windows10-2004-x64
1S500 RAT/Gry73.dll
windows7-x64
1S500 RAT/Gry73.dll
windows10-2004-x64
1S500 RAT/Guna.UI2.dll
windows7-x64
1S500 RAT/Guna.UI2.dll
windows10-2004-x64
1S500 RAT/L...pf.dll
windows7-x64
1S500 RAT/L...pf.dll
windows10-2004-x64
1S500 RAT/L...ts.dll
windows7-x64
1S500 RAT/L...ts.dll
windows10-2004-x64
1S500 RAT/M...rk.dll
windows7-x64
1S500 RAT/M...rk.dll
windows10-2004-x64
1S500 RAT/O...on.dll
windows7-x64
1S500 RAT/O...on.dll
windows10-2004-x64
1S500 RAT/P...ws.dll
windows7-x64
1S500 RAT/P...ws.dll
windows10-2004-x64
1S500 RAT/P...in.dll
windows7-x64
1S500 RAT/P...in.dll
windows10-2004-x64
1S500 RAT/P...re.dll
windows7-x64
1S500 RAT/P...re.dll
windows10-2004-x64
1S500 RAT/P...er.dll
windows7-x64
1S500 RAT/P...er.dll
windows10-2004-x64
1S500 RAT/P...at.dll
windows7-x64
1S500 RAT/P...at.dll
windows10-2004-x64
1Behavioral task
behavioral1
Sample
S500 RAT.zip
Resource
win7-20240611-en
Behavioral task
behavioral2
Sample
S500 RAT.zip
Resource
win10v2004-20240508-en
Behavioral task
behavioral3
Sample
S500 RAT/.peu/New Project 1/src/PebApi.vbs
Resource
win7-20240508-en
Behavioral task
behavioral4
Sample
S500 RAT/.peu/New Project 1/src/PebApi.vbs
Resource
win10v2004-20240508-en
Behavioral task
behavioral5
Sample
S500 RAT/BouncyCastle.Crypto.dll
Resource
win7-20240611-en
Behavioral task
behavioral6
Sample
S500 RAT/BouncyCastle.Crypto.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral7
Sample
S500 RAT/Compression7zip.dll
Resource
win7-20240419-en
Behavioral task
behavioral8
Sample
S500 RAT/Compression7zip.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral9
Sample
S500 RAT/FastColoredTextBox.dll
Resource
win7-20231129-en
Behavioral task
behavioral10
Sample
S500 RAT/FastColoredTextBox.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral11
Sample
S500 RAT/Gry73.dll
Resource
win7-20240220-en
Behavioral task
behavioral12
Sample
S500 RAT/Gry73.dll
Resource
win10v2004-20240226-en
Behavioral task
behavioral13
Sample
S500 RAT/Guna.UI2.dll
Resource
win7-20240611-en
Behavioral task
behavioral14
Sample
S500 RAT/Guna.UI2.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral15
Sample
S500 RAT/LiveCharts.Wpf.dll
Resource
win7-20231129-en
Behavioral task
behavioral16
Sample
S500 RAT/LiveCharts.Wpf.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral17
Sample
S500 RAT/LiveCharts.dll
Resource
win7-20240611-en
Behavioral task
behavioral18
Sample
S500 RAT/LiveCharts.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral19
Sample
S500 RAT/MetroFramework.dll
Resource
win7-20240508-en
Behavioral task
behavioral20
Sample
S500 RAT/MetroFramework.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral21
Sample
S500 RAT/Obfuscation.dll
Resource
win7-20240220-en
Behavioral task
behavioral22
Sample
S500 RAT/Obfuscation.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral23
Sample
S500 RAT/Plugins/ActiveWindows.dll
Resource
win7-20240221-en
Behavioral task
behavioral24
Sample
S500 RAT/Plugins/ActiveWindows.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral25
Sample
S500 RAT/Plugins/Admin.dll
Resource
win7-20231129-en
Behavioral task
behavioral26
Sample
S500 RAT/Plugins/Admin.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral27
Sample
S500 RAT/Plugins/AntiMalware.dll
Resource
win7-20240611-en
Behavioral task
behavioral28
Sample
S500 RAT/Plugins/AntiMalware.dll
Resource
win10v2004-20240611-en
Behavioral task
behavioral29
Sample
S500 RAT/Plugins/BotsKiller.dll
Resource
win7-20240611-en
Behavioral task
behavioral30
Sample
S500 RAT/Plugins/BotsKiller.dll
Resource
win10v2004-20240508-en
Behavioral task
behavioral31
Sample
S500 RAT/Plugins/Chat.dll
Resource
win7-20240220-en
Behavioral task
behavioral32
Sample
S500 RAT/Plugins/Chat.dll
Resource
win10v2004-20240508-en
General
-
Target
S500 RAT.zip
-
Size
43.3MB
-
MD5
345a37c6bcd0ce82aa0eb4b339a99ecc
-
SHA1
3056b6855d0f359485c037de1673786f000c78c9
-
SHA256
eb5e0956e26576d0c02cd7749476a564bd8671375ccca863efaa7347235fdb7d
-
SHA512
1741db005d19d23cdfba33952eb4d44d460ab540ef4151b4ffd17a8c72c37a729d0d01e94985a5f295b92865d90037c03d09bb65cedb80423cfe4cc4de319239
-
SSDEEP
786432:StSrIAPWJhZ1SYMZgUxXxPfB4X0U7hQ0bbJLl8VNevlP3y5sxC4f:SwrVWhfYxP54h7hQILl8VuY5sYo
Malware Config
Signatures
-
Obfuscated with Agile.Net obfuscator 1 IoCs
Detects use of the Agile.Net commercial obfuscator, which is capable of entity renaming and control flow obfuscation.
Processes:
resource yara_rule static1/unpack001/S500 RAT/Guna.UI2.dll agile_net -
Unsigned PE 25 IoCs
Checks for missing Authenticode signature.
Processes:
resource unpack001/S500 RAT/BouncyCastle.Crypto.dll unpack001/S500 RAT/Compression7zip.dll unpack001/S500 RAT/FastColoredTextBox.dll unpack001/S500 RAT/Gry73.dll unpack001/S500 RAT/LiveCharts.Wpf.dll unpack001/S500 RAT/LiveCharts.dll unpack001/S500 RAT/MetroFramework.dll unpack001/S500 RAT/Obfuscation.dll unpack001/S500 RAT/QuickLZLibrary.dll unpack001/S500 RAT/S500RAT.exe unpack001/S500 RAT/Socks5.dll unpack001/S500 RAT/SunnyUI.Common.dll unpack001/S500 RAT/SunnyUI.dll unpack001/S500 RAT/Svg.dll unpack001/S500 RAT/Tulpep.NotificationWindow.dll unpack001/S500 RAT/Vestris.ResourceLib.dll unpack001/S500 RAT/WinMic.dll unpack001/S500 RAT/WinSound.dll unpack001/S500 RAT/cGeoIp.dll unpack001/S500 RAT/crack.exe unpack001/S500 RAT/dnlib.dll unpack001/S500 RAT/initialization.dll unpack001/S500 RAT/lz4.AnyCPU.loader.dll unpack001/S500 RAT/protobuf-net.dll unpack001/S500 RAT/zxing.dll
Files
-
S500 RAT.zip.zip
Password: h
-
S500 RAT/.peu/New Project 1/compile.log
-
S500 RAT/.peu/New Project 1/src/Api/kernel32.inc
-
S500 RAT/.peu/New Project 1/src/Api/msvcrt.inc
-
S500 RAT/.peu/New Project 1/src/Api/shlwapi.inc
-
S500 RAT/.peu/New Project 1/src/Compression.asm
-
S500 RAT/.peu/New Project 1/src/Download.asm
-
S500 RAT/.peu/New Project 1/src/Drop.asm
-
S500 RAT/.peu/New Project 1/src/Emulator.asm
-
S500 RAT/.peu/New Project 1/src/Melt.asm
-
S500 RAT/.peu/New Project 1/src/Obfuscator/nop.txt
-
S500 RAT/.peu/New Project 1/src/Obfuscator/nop_minimal.txt
-
S500 RAT/.peu/New Project 1/src/Obfuscator/register.txt
-
S500 RAT/.peu/New Project 1/src/PebApi.asm
-
S500 RAT/.peu/New Project 1/src/PebApi.inc.vbs
-
S500 RAT/.peu/New Project 1/src/Resources/default.manifest.xml
-
S500 RAT/.peu/New Project 1/src/Resources/elevated.manifest.xml
-
S500 RAT/.peu/New Project 1/src/RunPE.asm
-
S500 RAT/.peu/New Project 1/src/Stage2.asm
-
S500 RAT/.peu/New Project 1/src/Stub.asm
-
S500 RAT/.peu/New Project 1/src/nt.inc
-
S500 RAT/BouncyCastle.Crypto.dll.dll windows:4 windows x86 arch:x86
Password: h
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_NO_SEH
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
Imports
mscoree
_CorDllMain
Sections
.text Size: 2.4MB - Virtual size: 2.4MB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 4KB - Virtual size: 1KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 4KB - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/Certificate/BackupCertificate.zip.zip
Password: h
-
ServerCertificate.p12
-
S500 RAT/Certificate/ServerCertificate.p12
-
S500 RAT/Chrome.ico
-
S500 RAT/Clients/Downloads/A82871D5B4CE1A95/1.DAT
-
S500 RAT/Clients/Downloads/A82871D5B4CE1A95/10.DAT
-
S500 RAT/Clients/Downloads/A82871D5B4CE1A95/11.DAT
-
S500 RAT/Clients/Downloads/A82871D5B4CE1A95/2.DAT
-
S500 RAT/Clients/Downloads/A82871D5B4CE1A95/5.DAT
-
S500 RAT/Clients/Downloads/A82871D5B4CE1A95/7.DAT
-
S500 RAT/Compression7zip.dll.dll windows:4 windows x86 arch:x86
Password: h
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
PDB Paths
Imports
mscoree
_CorDllMain
Sections
.text Size: 38KB - Virtual size: 38KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1024B - Virtual size: 936B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/FastColoredTextBox.dll.dll windows:4 windows x86 arch:x86
Password: h
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
PDB Paths
C:\Users\DZ\Desktop\FastColoredTextBox-master\FastColoredTextBox\obj\Release\FastColoredTextBox.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 295KB - Virtual size: 295KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1KB - Virtual size: 1KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/Gry73.dll.dll windows:4 windows x86 arch:x86
Password: h
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
PDB Paths
D:\S500RAT\S500RAT\Helper\Gry73\obj\Release\Gry73.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 43KB - Virtual size: 43KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1024B - Virtual size: 856B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/Guna.UI2.dll.dll windows:4 windows x86 arch:x86
Password: h
dae02f32a21e03ce65412f6e56942daa
Code Sign
7a:98:1b:7d:3e:b4:86:bb:45:84:c4:3c:c9:a8:3f:dbCertificate
IssuerCN=Sobatdata Root CANot Before23-10-2019 05:22Not After22-10-2025 17:00SubjectCN=Sobatdata Software03:01:9a:02:3a:ff:58:b1:6b:d6:d5:ea:e6:17:f0:66Certificate
IssuerCN=DigiCert Assured ID CA-1,OU=www.digicert.com,O=DigiCert Inc,C=USNot Before22-10-2014 00:00Not After22-10-2024 00:00SubjectCN=DigiCert Timestamp Responder,O=DigiCert,C=USExtended Key Usages
ExtKeyUsageTimeStamping
Key Usages
KeyUsageDigitalSignature
06:fd:f9:03:96:03:ad:ea:00:0a:eb:3f:27:bb:ba:1bCertificate
IssuerCN=DigiCert Assured ID Root CA,OU=www.digicert.com,O=DigiCert Inc,C=USNot Before10-11-2006 00:00Not After10-11-2021 00:00SubjectCN=DigiCert Assured ID CA-1,OU=www.digicert.com,O=DigiCert Inc,C=USExtended Key Usages
ExtKeyUsageServerAuth
ExtKeyUsageClientAuth
ExtKeyUsageCodeSigning
ExtKeyUsageEmailProtection
ExtKeyUsageTimeStamping
Key Usages
KeyUsageDigitalSignature
KeyUsageCertSign
KeyUsageCRLSign
fe:92:fd:79:78:5b:a1:7b:fc:09:41:72:94:be:f3:50:c7:5a:02:fbSigner
Actual PE Digestfe:92:fd:79:78:5b:a1:7b:fc:09:41:72:94:be:f3:50:c7:5a:02:fbDigest Algorithmsha1PE Digest MatchestrueHeaders
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
PDB Paths
D:\Projects\Guna.UI2\Build\Guna.UI2.WinForms\build\nuget\Guna.UI2.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 1.9MB - Virtual size: 1.9MB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1KB - Virtual size: 1KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/LiveCharts.Wpf.dll.dll windows:4 windows x86 arch:x86
Password: h
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
PDB Paths
c:\Users\btord\Documents\Projects\LiveCharts\WpfView\obj\Release\LiveCharts.Wpf.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 210KB - Virtual size: 210KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1024B - Virtual size: 936B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/LiveCharts.dll.dll windows:4 windows x86 arch:x86
Password: h
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
PDB Paths
c:\Users\btord\Documents\Projects\LiveCharts\Core40\obj\Release\LiveCharts.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 146KB - Virtual size: 146KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1024B - Virtual size: 912B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/MetroFramework.dll.dll windows:4 windows x86 arch:x86
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
Imports
mscoree
_CorDllMain
Sections
.text Size: 342KB - Virtual size: 342KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1KB - Virtual size: 1KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/New Project 1.peu
-
S500 RAT/Obfuscation.dll.dll windows:4 windows x86 arch:x86
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
PDB Paths
D:\S500\Obfuscation\obj\Debug\Obfuscation.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 20KB - Virtual size: 19KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1024B - Virtual size: 904B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/Plugins/ActiveWindows.dll
-
S500 RAT/Plugins/Admin.dll
-
S500 RAT/Plugins/AntiMalware.dll
-
S500 RAT/Plugins/BotsKiller.dll
-
S500 RAT/Plugins/Chat.dll
-
S500 RAT/Plugins/Clipboard.dll
-
S500 RAT/Plugins/Cmd.dll
-
S500 RAT/Plugins/DDos.dll
-
S500 RAT/Plugins/DotNet.dll
-
S500 RAT/Plugins/File Manager.dll
-
S500 RAT/Plugins/FileManager.dll
-
S500 RAT/Plugins/Fun.dll
-
S500 RAT/Plugins/HBrowser.dll
-
S500 RAT/Plugins/HRDP.dll
-
S500 RAT/Plugins/HVNC.dll
-
S500 RAT/Plugins/Helper.dll
-
S500 RAT/Plugins/HiddenApps.dll
-
S500 RAT/Plugins/HiddenProgram.dll
-
S500 RAT/Plugins/Hosts.dll
-
S500 RAT/Plugins/IconLib.dll
-
S500 RAT/Plugins/Information.dll
-
S500 RAT/Plugins/Installedsoftwares.dll
-
S500 RAT/Plugins/Keylogger.dll
-
S500 RAT/Plugins/MessageBox.dll
-
S500 RAT/Plugins/Mic.dll
-
S500 RAT/Plugins/Mining.dll
-
S500 RAT/Plugins/Options.dll
-
S500 RAT/Plugins/Password.dll
-
S500 RAT/Plugins/Powershell.dll
-
S500 RAT/Plugins/Ransomware.dll
-
S500 RAT/Plugins/RecoviryPasswords.dll
-
S500 RAT/Plugins/Regedit.dll
-
S500 RAT/Plugins/RegistryEditor.dll
-
S500 RAT/Plugins/RemoteCamera.dll
-
S500 RAT/Plugins/RemoteDesktop.dll
-
S500 RAT/Plugins/ReverseProxy.dll
-
S500 RAT/Plugins/SClient.dll
-
S500 RAT/Plugins/SendFile.dll
-
S500 RAT/Plugins/Services.dll
-
S500 RAT/Plugins/Startup.dll
-
S500 RAT/Plugins/StreamLib.dll
-
S500 RAT/Plugins/TCPConnection.dll
-
S500 RAT/Plugins/TaskManager.dll
-
S500 RAT/Plugins/USBSpread.dll
-
S500 RAT/Plugins/User ID.dll
-
S500 RAT/Plugins/WiFi.dll
-
S500 RAT/Plugins/lz4.AnyCPU.loader.dll
-
S500 RAT/Plugins/protobuf-net.dll
-
S500 RAT/QuickLZLibrary.dll.dll windows:4 windows x86 arch:x86
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
PDB Paths
C:\Users\DZ\Desktop\QuickLZLibrary\obj\Release\QuickLZLibrary.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 5KB - Virtual size: 5KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1024B - Virtual size: 936B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/S500RAT.exe.exe windows:4 windows x86 arch:x86
a9c887a4f18a3fede2cc29ceea138ed3
Headers
File Characteristics
IMAGE_FILE_RELOCS_STRIPPED
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DEBUG_STRIPPED
Imports
msvcrt
malloc
memset
strcmp
strcpy
getenv
sprintf
fopen
fwrite
fclose
__argc
__argv
_environ
_XcptFilter
__set_app_type
_controlfp
__getmainargs
exit
shell32
ShellExecuteA
kernel32
SetUnhandledExceptionFilter
Sections
.text Size: 2KB - Virtual size: 1KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rdata Size: 19.6MB - Virtual size: 19.6MB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.bss Size: - Virtual size: 4B
IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.rsrc Size: 56KB - Virtual size: 55KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
-
S500 RAT/S500RAT.ico
-
S500 RAT/Socks5.dll.dll windows:4 windows x86 arch:x86
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
PDB Paths
E:\MyFolder\MyProject\S500RAT\S500RAT\Socks5\obj\Debug\Socks5.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 43KB - Virtual size: 43KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1024B - Virtual size: 872B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/SunnyUI.Common.dll.dll windows:4 windows x86 arch:x86
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
PDB Paths
C:\Users\Sunny\source\repos\SunnyUI.Common\SunnyUI.Common\obj\Debug\net40\SunnyUI.Common.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 175KB - Virtual size: 174KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 45KB - Virtual size: 44KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/SunnyUI.dll.dll windows:4 windows x86 arch:x86
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
PDB Paths
C:\Users\DZ\Desktop\SunnyUI-master\SunnyUI\obj\Debug\net40\SunnyUI.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 2.2MB - Virtual size: 2.2MB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1KB - Virtual size: 1KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/Svg.dll.dll windows:4 windows x86 arch:x86
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
PDB Paths
C:\Users\user\Desktop\SVG-master\Source\obj\Debug\Svg.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 572KB - Virtual size: 571KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 4KB - Virtual size: 900B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 4KB - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/Terror/1.gif.gif
-
S500 RAT/Terror/2.gif.gif
-
S500 RAT/Terror/3.gif.gif
-
S500 RAT/Terror/4.gif.gif
-
S500 RAT/Terror/T.wav
-
S500 RAT/Tulpep.NotificationWindow.dll.dll windows:4 windows x86 arch:x86
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
PDB Paths
c:\projects\notification-popup-window\Tulpep.NotificationWindow\obj\Release\Tulpep.NotificationWindow.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 26KB - Virtual size: 26KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1024B - Virtual size: 880B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/Vestris.ResourceLib.dll.dll windows:4 windows x86 arch:x86
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
PDB Paths
C:\projects\resourcelib\Source\ResourceLib\obj\Release\net45\Vestris.ResourceLib.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 73KB - Virtual size: 73KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1KB - Virtual size: 1KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/WinMic.dll.dll windows:4 windows x86 arch:x86
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
PDB Paths
E:\MyFolder\MyProject\S500RAT\S500RAT\WinMic\obj\Debug\WinMic.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 17KB - Virtual size: 17KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1024B - Virtual size: 872B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/WinSound.dll.dll windows:4 windows x86 arch:x86
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
PDB Paths
C:\Users\DZ\Desktop\New folder (5)\WinSound\WinSound\obj\Debug\WinSound.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 43KB - Virtual size: 42KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1024B - Virtual size: 888B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/cGeoIp.dll.dll windows:4 windows x86 arch:x86
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
Imports
mscoree
_CorDllMain
Sections
.text Size: 2.3MB - Virtual size: 2.3MB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1024B - Virtual size: 928B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/crack.exe.exe windows:6 windows x86 arch:x86
96baacc90461fcd4b5d9fcc50047c098
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
Imports
advapi32
DeleteAce
kernel32
FreeConsole
GetCurrentThreadId
CloseHandle
WaitForSingleObjectEx
GetExitCodeThread
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
EncodePointer
DecodePointer
MultiByteToWideChar
WideCharToMultiByte
LCMapStringEx
QueryPerformanceCounter
GetSystemTimeAsFileTime
GetModuleHandleW
GetProcAddress
GetStringTypeW
GetCPInfo
IsProcessorFeaturePresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
GetCurrentProcessId
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
CreateFileW
RaiseException
RtlUnwind
GetLastError
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
CreateThread
ExitThread
FreeLibraryAndExitThread
GetModuleHandleExW
GetStdHandle
WriteFile
GetModuleFileNameW
ExitProcess
GetCommandLineA
GetCommandLineW
HeapAlloc
HeapFree
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetFileType
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
ReadFile
GetFileSizeEx
SetFilePointerEx
ReadConsoleW
HeapReAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetProcessHeap
HeapSize
WriteConsoleW
Exports
Exports
_LoadEnvironment@0
Sections
.text Size: 150KB - Virtual size: 149KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rdata Size: 54KB - Virtual size: 53KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.data Size: 460KB - Virtual size: 463KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
.reloc Size: 7KB - Virtual size: 6KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/dnlib.dll.dll windows:4 windows x86 arch:x86
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
PDB Paths
D:\a\dnlib\dnlib\src\obj\Release\net35\dnlib.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 1.1MB - Virtual size: 1.1MB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1KB - Virtual size: 1KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/initialization.dll.dll windows:4 windows x86 arch:x86
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
Imports
mscoree
_CorDllMain
Sections
.text Size: 17KB - Virtual size: 16KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1024B - Virtual size: 932B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/lz4.AnyCPU.loader.dll.dll windows:4 windows x86 arch:x86
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
PDB Paths
C:\dev\lz4.net\lz4.AnyCpu.loader\obj\Release\lz4.AnyCPU.loader.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 983KB - Virtual size: 983KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1024B - Virtual size: 992B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/protobuf-net.dll.dll windows:4 windows x86 arch:x86
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
IMAGE_FILE_DLL
PDB Paths
protobuf-net.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 276KB - Virtual size: 275KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 1KB - Virtual size: 1KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 512B - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
-
S500 RAT/settings.xml
-
S500 RAT/zxing.dll.dll windows:4 windows x86 arch:x86
dae02f32a21e03ce65412f6e56942daa
Headers
DLL Characteristics
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_NO_SEH
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
File Characteristics
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_DLL
PDB Paths
C:\ZXing.Net.0.14.0.0\Source\lib\obj\Release\zxing.pdb
Imports
mscoree
_CorDllMain
Sections
.text Size: 408KB - Virtual size: 407KB
IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
.rsrc Size: 4KB - Virtual size: 1KB
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
.reloc Size: 4KB - Virtual size: 12B
IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ