Natural

natural

Breaking News

SlothBP Breakpoints by Mobile46


 [Text Recuperation]

GetDlgItemTextA="user32.GetDlgItemTextA"

GetWindowTextA="user32.GetWindowTextA"

SetDlgItemTextA="user32.SetDlgItemTextA"

SetWindowTextA="user32.SetWindowTextA"

GetPrivateProfileStringA="kernel32.GetPrivateProfileStringA"

WritePrivateProfileStringA="kernel32.WritePrivateProfileStringA"

GetPrivateProfileIntA="kernel32.GetPrivateProfileIntA"

WriteProfileStringA="kernel32.WriteProfileStringA"


GetDlgItemTextW="user32.GetDlgItemTextW"

GetWindowTextW="user32.GetWindowTextW"

SetDlgItemTextW="user32.SetDlgItemTextW"

SetWindowTextW="user32.SetWindowTextW"

GetPrivateProfileStringW="kernel32.GetPrivateProfileStringW"

WritePrivateProfileStringW="kernel32.WritePrivateProfileStringW"

GetPrivateProfileIntW="kernel32.GetPrivateProfileIntW"

WriteProfileStringW="kernel32.WriteProfileStringW"


GetDlgItem="user32.GetDlgItem"


[Message Boxes]

MessageBoxA="user32.MessageBoxA"

MessageBoxExA="user32.MessageBoxExA"

MessageBoxIndirectA="user32.MessageBoxIndirectA"


MessageBoxW="user32.MessageBoxW"

MessageBoxExW="user32.MessageBoxExW"

MessageBoxIndirectW="user32.MessageBoxIndirectW"


MessageBeep="user32.MessageBeep"


[Dialog Boxes]

DialogBoxParamA="user32.DialogBoxParamA"

CreateDialogParamA="user32.CreateDialogParamA"

CreateDialogIndirectParamA="user32.CreateDialogIndirectParamA"

CreateWindowExA="user32.CreateWindowExA"


DialogBoxParamW="user32.DialogBoxParamW"

CreateDialogParamW="user32.CreateDialogParamW"

CreateDialogIndirectParamW="user32.CreateDialogIndirectParamW"

CreateWindowExW="user32.CreateWindowExW"


DestroyWindow="user32.DestroyWindow"

EndDialog="user32.EndDialog"

EnableWindow="user32.EnableWindow"

EnableMenuItem="user32.EnableMenuItem"


[Files]

CreateFileA="kernel32.CreateFileA"

DeleteFileA="kernel32.DeleteFileA"

GetFileAttributesA="kernel32.GetFileAttributesA"

MoveFileA="kernel32.MoveFileA"

MoveFileExA="kernel32.MoveFileExA"

GetOpenFileNameA="comdlg32.GetOpenFileNameA"

GetSaveFileNameA="comdlg32.GetSaveFileNameA"

OpenFileMappingA="kernel32.OpenFileMappingA"

CreateFileMappingA="kernel32.CreateFileMappingA"

GetStartupInfoA="kernel32.GetStartupInfoA"

GetCommandLineA="kernel32.GetCommandLineA"


CreateFileW="kernel32.CreateFileW"

DeleteFileW="kernel32.DeleteFileW"

GetFileAttributesW="kernel32.GetFileAttributesW"

MoveFileW="kernel32.MoveFileW"

MoveFileExW="kernel32.MoveFileExW"

GetOpenFileNameW="comdlg32.GetOpenFileNameW"

GetSaveFileNameW="comdlg32.GetSaveFileNameW"

OpenFileMappingW="kernel32.OpenFileMappingW"

CreateFileMappingW="kernel32.CreateFileMappingW"

GetStartupInfoW="kernel32.GetStartupInfoW"

GetCommandLineW="kernel32.GetCommandLineW"


GetFileSize="kernel32.GetFileSize"

GetFileSizeEx="kernel32.GetFileSizeEx"

GetFileType="kernel32.GetFileType"

OpenFile="kernel32.OpenFile"

ReadFile="kernel32.ReadFile"

ReadFileEx="kernel32.ReadFileEx"

SetFilePointer="kernel32.SetFilePointer"

WriteFile="kernel32.WriteFile"

WriteFileEx="kernel32.WriteFileEx"

MapViewOfFile="kernel32.MapViewOfFile"

MapViewOfFileEx="kernel32.MapViewOfFileEx"

UnmapViewOfFile="kernel32.UnmapViewOfFile"

CloseHandle="kernel32.CloseHandle"

ZwCreateFile="ntdll.ZwCreateFile"

ZwQueryInformationFile="ntdll.ZwQueryInformationFile"

ZwReadFile="ntdll.ZwReadFile"

_lclose="kernel32._lclose"

_lcreat="kernel32._lcreat"

_llseek="kernel32._llseek"

_lopen="kernel32._lopen"

_lread="kernel32._lread"

_lwrite="kernel32._lwrite"


[Modules and Libraries]

LoadLibraryA="kernel32.LoadLibraryA"

GetModuleHandleA="kernel32.GetModuleHandleA"


LoadLibraryW="kernel32.LoadLibraryW"

GetModuleHandleW="kernel32.GetModuleHandleW"


FreeLibrary="kernel32.FreeLibrary"

GetProcAddress="kernel32.GetProcAddress"

LdrLoadDll="ntdll.LdrLoadDll"


[Memory Management]

GlobalAlloc="kernel32.GlobalAlloc"

GlobalFree="kernel32.GlobalFree"

HeapCreate="kernel32.HeapCreate"

RtlAllocateHeap="ntdll.RtlAllocateHeap"

RtlDecompressBuffer="ntdll.RtlDecompressBuffer"

VirtualAlloc="kernel32.VirtualAlloc"

VirtualAllocEx="kernel32.VirtualAllocEx"

VirtualFree="kernel32.VirtualFree"

VirtualProtect="kernel32.VirtualProtect"

VirtualProtectEx="kernel32.VirtualProtectEx"

VirtualQuery="kernel32.VirtualQuery"

VirtualQueryEx="kernel32.VirtualQueryEx"

ZwAllocateVirtualMemory="ntdll.ZwAllocateVirtualMemory"

ZwFreeVirtualMemory="ntdll.ZwFreeVirtualMemory"

ZwProtectVirtualMemory="ntdll.ZwProtectVirtualMemory"

ZwQueryVirtualMemory="ntdll.ZwQueryVirtualMemory"


[Registry]

RegCreateKeyA="advapi32.RegCreateKeyA"

RegCreateKeyExA="kernel32.RegCreateKeyExA"

RegDeleteKeyA="advapi32.RegDeleteKeyA"

RegDeleteValueA="kernel32.RegDeleteValueA"

RegOpenKeyA="advapi32.RegOpenKeyA"

RegOpenKeyExA="kernel32.RegOpenKeyExA"

RegQueryInfoKeyA="kernel32.RegQueryInfoKeyA"

RegQueryValueA="advapi32.RegQueryValueA"

RegQueryValueExA="kernel32.RegQueryValueExA"

RegSaveKeyA="advapi32.RegSaveKeyA"

RegSaveKeyExA="kernel32.RegSaveKeyExA"

RegSetValueA="advapi32.RegSetValueA"

RegSetValueExA="kernel32.RegSetValueExA"


RegCreateKeyW="advapi32.RegCreateKeyW"

RegCreateKeyExW="kernel32.RegCreateKeyExW"

RegDeleteKeyW="advapi32.RegDeleteKeyW"

RegDeleteValueW="kernel32.RegDeleteValueW"

RegOpenKeyW="advapi32.RegOpenKeyW"

RegOpenKeyExW="kernel32.RegOpenKeyExW"

RegQueryInfoKeyW="kernel32.RegQueryInfoKeyW"

RegQueryValueW="advapi32.RegQueryValueW"

RegQueryValueExW="kernel32.RegQueryValueExW"

RegSaveKeyW="advapi32.RegSaveKeyW"

RegSaveKeyExW="kernel32.RegSaveKeyExW"

RegSetValueW="advapi32.RegSetValueW"

RegSetValueExW="kernel32.RegSetValueExW"


RegCloseKey="kernel32.RegCloseKey"

ZwClose="ntdll.ZwClose"

ZwCreateKey="ntdll.ZwCreateKey"

ZwDeleteKey="ntdll.ZwDeleteKey"

ZwOpenKey="ntdll.ZwOpenKey"

ZwQueryKey="ntdll.ZwQueryKey"

ZwQueryValueKey="ntdll.ZwQueryValueKey"

ZwSaveMergedKeys="ntdll.ZwSaveMergedKeys"


[Directories and Paths]

CreateDirectoryA="kernel32.CreateDirectoryA"

CreateDirectoryExA="kernel32.CreateDirectoryExA"

GetCurrentDirectoryA="kernel32.GetCurrentDirectoryA"

GetFullPathNameA="kernel32.GetFullPathNameA"

GetShortPathNameA="kernel32.GetShortPathNameA"

GetTempFileNameA="kernel32.GetTempFileNameA"

GetTempPathA="kernel32.GetTempPathA"

RemoveDirectoryA="kernel32.RemoveDirectoryA"

SearchPathA="kernel32.SearchPathA"

SetCurrentDirectoryA="kernel32.SetCurrentDirectoryA"

GetSystemWindowsDirectoryA="kernel32.GetSystemWindowsDirectoryA"

GetSystemDirectoryA="kernel32.GetSystemDirectoryA"


CreateDirectoryW="kernel32.CreateDirectoryW"

CreateDirectoryExW="kernel32.CreateDirectoryExW"

GetCurrentDirectoryW="kernel32.GetCurrentDirectoryW"

GetFullPathNameW="kernel32.GetFullPathNameW"

GetShortPathNameW="kernel32.GetShortPathNameW"

GetTempFileNameW="kernel32.GetTempFileNameW"

GetTempPathW="kernel32.GetTempPathW"

RemoveDirectoryW="kernel32.RemoveDirectoryW"

SearchPathW="kernel32.SearchPathW"

SetCurrentDirectoryW="kernel32.SetCurrentDirectoryW"

GetSystemWindowsDirectoryW="kernel32.GetSystemWindowsDirectoryW"

GetSystemDirectoryW="kernel32.GetSystemDirectoryW"


[Drives]

GetDiskFreeSpaceA="kernel32.GetDiskFreeSpaceA"

GetDiskFreeSpaceExA="kernel32.GetDiskFreeSpaceExA"

GetDriveTypeA="kernel32.GetDriveTypeA"

GetLogicalDriveStringsA="kernel32.GetLogicalDriveStringsA"

GetVolumeInformationA="kernel32.GetVolumeInformationA"

SetVolumeLabelA="kernel32.SetVolumeLabelA"


GetDiskFreeSpaceW="kernel32.GetDiskFreeSpaceW"

GetDiskFreeSpaceExW="kernel32.GetDiskFreeSpaceExW"

GetDriveTypeW="kernel32.GetDriveTypeW"

GetLogicalDriveStringsW="kernel32.GetLogicalDriveStringsW"

GetVolumeInformationW="kernel32.GetVolumeInformationW"

SetVolumeLabelW="kernel32.SetVolumeLabelW"


GetLogicalDrives="kernel32.GetLogicalDrives"


[Time]

GetTimeFormatA="kernel32.GetTimeFormatA"


GetTimeFormatW="kernel32.GetTimeFormatW"


GetFileTime="kernel32.GetFileTime"

SetFileTime="kernel32.SetFileTime"

GetLocalTime="kernel32.GetLocalTime"

GetSystemTime="kernel32.GetSystemTime"

GetSystemTimeAsFileTime="kernel32.GetSystemTimeAsFileTime"

GetTimeZoneInformation="kernel32.GetTimeZoneInformation"

LocalFileTimeToFileTime="kernel32.LocalFileTimeToFileTime"

CompareFileTime="kernel32.CompareFileTime"

SetLocalTime="kernel32.SetLocalTime"

SetSystemTime="kernel32.SetSystemTime"

SystemTimeToFileTime="kernel32.SystemTimeToFileTime"


[Miscellaneous]

DrawTextA="user32.DrawTextA"

DrawTextExA="user32.DrawTextExA"

ExtTextOutA="gdi32.ExtTextOutA"

DrawTextExA="user32.DrawTextExA"

TextOutA="gdi32.TextOutA"

DrawTextW="user32.DrawTextW"

DrawTextExW="user32.DrawTextExW"

ExtTextOutW="gdi32.ExtTextOutW"

DrawTextExW="user32.DrawTextExW"

TextOutW="gdi32.TextOutW"

BitBlt="gdi32.BitBlt"

MaskBlt="gdi32.MaskBlt"

PatBlt="gdi32.PatBlt"


[VB APIs]

ThunRTMain="msvbvm60.ThunRTMain"

rtcMsgBox="msvbvm60.rtcMsgBox"

__vbaVarAdd="msvbvm60.__vbaVarAdd"

__vbaVarSub="msvbvm60.__vbaVarSub"

__vbaVarMul="msvbvm60.__vbaVarMul"

__vbaVarIdiv="msvbvm60.__vbaVarIdiv"

__vbaVarXor="msvbvm60.__vbaVarXor"

__vbaVarAnd="msvbvm60.__vbaVarAnd"

__vbaVarNot="msvbvm60.__vbaVarNot"

__vbaVarNeg="msvbvm60.__vbaVarNeg"

__vbaVarPow="msvbvm60.__vbaVarPow"

__vbaVarOr="msvbvm60.__vbaVarOr"

__vbaStrCmp="msvbvm60.__vbaStrCmp"

__vbaStrComp="msvbvm60.__vbaStrComp"

__vbaVarTstEq="msvbvm60.__vbaVarTstEq"

__vbaVarTextTstEq="msvbvm60.__vbaVarTextTstEq"

__vbaVarTextTstNe="msvbvm60.__vbaVarTextTstNe"

__vbaStrTextCmp="msvbvm60.__vbaStrTextCmp"

__vbaVarTstEq="msvbvm60.__vbaVarTstEq"

__vbaVarTstNe="msvbvm60.__vbaVarTstNe"

__vbaVarCmpEq="msvbvm60.__vbaVarCmpEq"

__vbaVarCmpNe="msvbvm60.__vbaVarCmpNe"

__vbaVarTextCmpEq="msvbvm60.__vbaVarTextCmpEq"

__vbaVarTextCmpNe="msvbvm60.__vbaVarTextCmpNe"

__vbaFpCmpCy="msvbvm60.__vbaFpCmpCy"

__vbaStrCopy="msvbvm60.__vbaStrCopy"

__vbaVarCopy="msvbvm60.__vbaVarCopy"

__vbaVarMove="msvbvm60.__vbaVarMove"

__vbaI2Str="msvbvm60.__vbaI2Str"

__vbaFPInt="msvbvm60.__vbaFPInt"

__vbaFpR8="msvbvm60.__vbaFpR8"

__vbaFpR4="msvbvm60.__vbaFpR4"

rtcHexBstrFromVar="msvbvm60.rtcHexBstrFromVar"

rtcHexVarFromVar="msvbvm60.rtcHexVarFromVar"

rtcGetTimeBstr="msvbvm60.rtcGetTimeBstr"

rtcGetTimeValue="msvbvm60.rtcGetTimeValue"

rtcGetTimeVar="msvbvm60.rtcGetTimeVar"

rtcGetTimer="msvbvm60.rtcGetTimer"

rtcGetYear="msvbvm60.rtcGetYear"

rtcGetPresentDate="msvbvm60.rtcGetPresentDate"

rtcGetMonthOfYear="msvbvm60.rtcGetMonthOfYear"

rtcGetMinuteOfHour="msvbvm60.rtcGetMinuteOfHour"

rtcGetSecondOfMinute="msvbvm60.rtcGetSecondOfMinute"


[Windows]

SendDlgItemMessageA="user32.SendDlgItemMessageA"

SendMessageA="user32.SendMessageA"

CreateWindowExA="user32.CreateWindowExA"

FindWindowA="user32.FindWindowA"

FindWindowExA="user32.FindWindowExA"


SendDlgItemMessageW="user32.SendDlgItemMessageW"

SendMessageW="user32.SendMessageW"

CreateWindowExW="user32.CreateWindowExW"

FindWindowW="user32.FindWindowW"

FindWindowExW="user32.FindWindowExW"


NtUserShowWindow="win32u.NtUserShowWindow"


[Process + Thread]

GetModuleHandleA="kernel32.GetModuleHandleA"

CreateProcessA="kernel32.CreateProcessA"


GetModuleHandleW="kernel32.GetModuleHandleW"

CreateProcessW="kernel32.CreateProcessW"


OpenProcess="kernel32.OpenProcess"

CreateThread="kernel32.CreateThread"

SuspendThread="kernel32.SuspendThread"

ExitProcess="kernel32.ExitProcess"

TerminateProcess="kernel32.TerminateProcess"

ReadProcessMemory="kernel32.ReadProcessMemory"

WriteProcessMemory="kernel32.WriteProcessMemory"

ShellExecute="shell32.ShellExecute"

ShellExecuteEx="shell32.ShellExecuteEx"

NtCreateProcess="ntdll.NtCreateProcess"

GetTickCount="kernel32.GetTickCount"

GetCurrentProcess="kernel32.GetCurrentProcess"

GetCurrentProcessId="kernel32.GetCurrentProcessId"

GetFileSize="kernel32.GetFileSize"


[Code Injection]

SetWindowsHookExA="user32.SetWindowsHookExA"


SetWindowsHookExW="user32.SetWindowsHookExW"


CreateRemoteThread="kernel32.CreateRemoteThread"

QueueUserAPC="kernel32.QueueUserAPC"


[Networking]

UrlDownloadToFileA="urlmon.UrlDownloadToFileA"

InternetOpenA="wininet.InternetOpenA"

InternetConnectA="wininet.InternetConnectA"

HttpOpenRequestA="wininet.HttpOpenRequestA"

HttpSendRequestA="wininet.HttpSendRequestA"


UrlDownloadToFileW="urlmon.UrlDownloadToFileW"

InternetOpenW="wininet.InternetOpenW"

InternetConnectW="wininet.InternetConnectW"

HttpOpenRequestW="wininet.HttpOpenRequestW"

HttpSendRequestW="wininet.HttpSendRequestW"


InternetGetConnectedState="wininet.InternetGetConnectedState"

WinHttpOpen="winhttp.WinHttpOpen"

WinHttpConnect="winhttp.WinHttpConnect"

WinHttpSendRequest="winhttp.WinHttpSendRequest"


[Crypt]

CryptGenKey="advapi32.CryptGenKey"

CryptDecrypt="advapi32.CryptDecrypt"

CryptAcquireContext="advapi32.CryptAcquireContext"


[Resource]

LoadResource="kernel32.LoadResource"

FindResource="kernel32.FindResource"


[Malware Analysis]

SetWindowsHookA="user32.SetWindowsHookA"

SetWindowLongA="user32.SetWindowLongA"

CreateProcessInternalA="kernel32.CreateProcessInternalA"

ShellExecuteA="shell32.ShellExecuteA"

OpenServiceA="advapi32.OpenServiceA"


SetWindowsHookW="user32.SetWindowsHookW"

SetWindowLongW="user32.SetWindowLongW"

CreateProcessInternalW="kernel32.CreateProcessInternalW"

ShellExecuteW="shell32.ShellExecuteW"

OpenServiceW="advapi32.OpenServiceW"


CreateToolhelp32Snapshot="kernel32.CreateToolhelp32Snapshot"

WinExec="kernel32.WinExec"

GetAsyncKeyState="user32.GetAsyncKeyState"

GetKeyState="user32.GetKeyState"


Hiç yorum yok