Static | ZeroBOX

PE Compile Time

2019-10-07 10:04:24

PE Imphash

4422cd285129af661d70fbc1279af032

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00058000 0x00000000 0.0
UPX1 0x00059000 0x0002f000 0x0002e600 7.93318563989
.rsrc 0x00088000 0x0000e000 0x0000de00 7.00475073109

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00095194 0x00000468 LANG_KOREAN SUBLANG_KOREAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00095194 0x00000468 LANG_KOREAN SUBLANG_KOREAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00095194 0x00000468 LANG_KOREAN SUBLANG_KOREAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00095194 0x00000468 LANG_KOREAN SUBLANG_KOREAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00095194 0x00000468 LANG_KOREAN SUBLANG_KOREAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00095194 0x00000468 LANG_KOREAN SUBLANG_KOREAN GLS_BINARY_LSB_FIRST
RT_ICON 0x00095194 0x00000468 LANG_KOREAN SUBLANG_KOREAN GLS_BINARY_LSB_FIRST
RT_DIALOG 0x0007d510 0x00000170 LANG_KOREAN SUBLANG_KOREAN data
RT_DIALOG 0x0007d510 0x00000170 LANG_KOREAN SUBLANG_KOREAN data
RT_DIALOG 0x0007d510 0x00000170 LANG_KOREAN SUBLANG_KOREAN data
RT_DIALOG 0x0007d510 0x00000170 LANG_KOREAN SUBLANG_KOREAN data
RT_DIALOG 0x0007d510 0x00000170 LANG_KOREAN SUBLANG_KOREAN data
RT_DIALOG 0x0007d510 0x00000170 LANG_KOREAN SUBLANG_KOREAN data
RT_DIALOG 0x0007d510 0x00000170 LANG_KOREAN SUBLANG_KOREAN data
RT_DIALOG 0x0007d510 0x00000170 LANG_KOREAN SUBLANG_KOREAN data
RT_STRING 0x0007e940 0x00000194 LANG_KOREAN SUBLANG_KOREAN data
RT_STRING 0x0007e940 0x00000194 LANG_KOREAN SUBLANG_KOREAN data
RT_STRING 0x0007e940 0x00000194 LANG_KOREAN SUBLANG_KOREAN data
RT_STRING 0x0007e940 0x00000194 LANG_KOREAN SUBLANG_KOREAN data
RT_STRING 0x0007e940 0x00000194 LANG_KOREAN SUBLANG_KOREAN data
RT_STRING 0x0007e940 0x00000194 LANG_KOREAN SUBLANG_KOREAN data
RT_STRING 0x0007e940 0x00000194 LANG_KOREAN SUBLANG_KOREAN data
RT_STRING 0x0007e940 0x00000194 LANG_KOREAN SUBLANG_KOREAN data
RT_STRING 0x0007e940 0x00000194 LANG_KOREAN SUBLANG_KOREAN data
RT_STRING 0x0007e940 0x00000194 LANG_KOREAN SUBLANG_KOREAN data
RT_GROUP_ICON 0x00095600 0x00000068 LANG_KOREAN SUBLANG_KOREAN data
RT_VERSION 0x0009566c 0x0000032c LANG_KOREAN SUBLANG_KOREAN data
RT_MANIFEST 0x0009599c 0x0000026e LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.DLL:
0x495c84 LoadLibraryA
0x495c88 GetProcAddress
0x495c8c VirtualProtect
0x495c90 VirtualAlloc
0x495c94 VirtualFree
0x495c98 ExitProcess
Library COMDLG32.dll:
0x495ca0 GetOpenFileNameW
Library SHELL32.dll:
0x495ca8 SHGetMalloc
Library SHLWAPI.dll:
0x495cb0 PathCompactPathExW
Library USER32.dll:
0x495cb8 SetTimer

!This program cannot be run in DOS mode.
}:Rich=
f;FDuW
pWIWW,
@@AAJu
f9+y_
$$(fB4M(,,"J
M96jr5
F9Lt![
?Dd1*T/h
(TRX"T
PB_D x
)7,5Y{
j\T!4x
/clPU.
Aji$RX
3<i0Kx
t1jkE?
t!Im,dz;%
IX@-~Q
P3a.8x2
Z@Xh@WyDDG
#dEQBd
j@.EA~yW
0WZn:.?
r*hT@@P1
R"s#YE
3FFY,u
3 .(a1$
8cpXm:;3?
Re0S_{
Xmdt]Be
JWtEJt7
6< 0tk
GBUX|=
0IyP~L
tknU=0
&Xut;M>I0
SH4htu
7`0{**
wC0hysj;v
g`lc\@
/.?r2hT
PQRQ#>a
r6(8Fw
+RKTA(Xu
9^ 6F
@t?Dt:
a9y t\
*Lx|B{#GZ9V
*l8y,R;E
KfNlt$
4,9999$
4rrrr,$
tFV"VlJ+
1"z*04
4,AuDfv4
@w\zrWH
!^h5l!
m/is1$
3P m3M
A+TvY*
lr73hW
ldv@F~D!
.Z7Hr:^$0,
#d,.27\K
$^p*/|
~\.wx\
P5{ql
bS~$dUm
tpV}tY
[pT[|QE
=tRK"0
III S2
dIHHH]
_*Y*X&-
,H=u/^V
"0'p{J9`r
kjLgP$
+BpUz
;;C(P/P
|2(Wj0Np
j/ZUV>
+@i@7P{x$(
ldm-nE
GG^,GP
Z~lGyI
;H_R qy
Ks4q{%
:*ljQ'F
Yj$6(m
m)G)Hr
+,}<$)
/QDP^ H
8y=C[y
y048<@
Ntn]\p&P&x9
Ne\D#
A2$0sB
2K.;Z=Gr
C~!#2w
N=8Vt/
-n!/,?
F +FN(
tDj(4"4
g4FS('
%}:4Zz
*t)-+B
vA28XB
$'III@z!#IjL
PIr@V>
`Crru~l$
!@jxyo`
[x:tQZM
R USBp
qpHVI
=,=|1[
(H@|ID7
iW:n_%
[L2 $j
9r024A8L<W
#G@bDmH|
4$(04J
Fll> g
X$^ZGsl
#v43 t&
^DSaWR
%""]}Th
XJ'ZcAX
< .h_
py$w8d
a91&d5
2h|S%1
^K'| 0
,h+{&k\
EEEOQA
^'%|PC8P21
0f4,S|
<VP56oCO
uU|h815
:2JR7"y<0
C;LmlG
vF,sft
m/c'/2\
e.I!j#O
kP<W9g
"V)Gu^
%$i"Pw
0enaV?
sB( `,d$8
] JBH2$S
,n.I;Dj
tUvquk
{(CI\+`
R =Y8|n
KC#\<(T
~<!8bib
EBlc47x
qEPD'8
!obxIH -(
4M ,,$$(4M
4(0044
FDFLFT
hltjdwww
RP`NIwI
4X-`o'
%EMM&t
CClPV)/
4Mdplht
B7XXa?
N81upLP_
BdE`| C2]u
og@|ZA
^VR0=WB
'"%@`@q
`n`nspcx
hQxN$p
E@1nG2C!
-0[@Nqk!
40nE2[
oDN vu
o @~ht
10aT50g
1bUxfS
W%|6T<
';Ur;w
gBq.8l
w:tWII
)8LR]qwi
"E{X9l@
/H*U<Zt,
,hexu#
:n@L.Z
`\3 w5t-
X\TLP`$
m#c6PWGO
AZ6D`s
*_oOYu
\0t'o
tH$=mX"
@v/W"@w
+S TC`
zWP@^ul`
cFPLXa
TtSe|n>
`jd@DH
tdhle
ptx4rPr|
mqaT!-
H[)O'
4#'PTX\
2t+j&w[
i8dw@:
7](L7A
X:0Ty1
P<"Vr
H:Mf-H
bu@H764
552x!t&
P\!l`!z
F0!r!H
L!W,0W
Ur48<r
q$BZsD
C/26[Y
>-U=,4O
<T<+S;
*R:)Qy
M5$L4#i
yK3"J2
]u$@tvD
[}clIW
yaA48Y
|C@DHH
@ $DO
<M$(H(,L
w`l0H.
@8-;kBz
C43H?8
<+&WL'
OR/A#S
s;v=do
[-I, 7
T_x*u*_8f\aU
ulMP{#r
\EAtA0
:),A,5TF4
ZfffDr
cxA66E
2!\`r!Grdhl
xhWl1|
$'OPWTXw
W<@YFD
HxS|;v3
fgQC AS
|lMgEX
"W(fN!
}-<@s-
C{;&_4
P47vcHH
nAAXVu
($V.+`)c
(V=rm=
n5w9L4>+
Go"F~,WPQGYA
</ u[ikH
W95tFy
>>bBBf
X8SOA.a
XPH@8p
+D$4BY
A}%tK'
]n&Q^ci
l>'w"`L
5h~j1F
FFTm9<
Rjj0Xf
~#`FMA<
c=WhS[D
9i3MW$|3IWU
-z>D=|
kW@ 2S
VEV9Y:
)BThl>q
9z@205
v:u8i~
LxWXST{
$(,''''04
'<M@$@NNn'D
ZH3$lk
?uFVh$d_
2 ?kFy
Qi2R0Y
PB[$)jAX
~pDgowJ
C1j@j ^V7
$>AtI.mV
hl;"u`
%.kD"n
HIXL@n
NBKl\3
P&29y
2[`Hbu
zyJzOK
Pp`f3%
t-4^9Cu
@Sj"ZY
N{o"HY
JkC0"fHzp
8CH{#8E
"tPD~@
2A`wa<$v
HtHu47%R
[S;7|G
SQWzm\
QC]YqM
&~(L9=
j.u112
_w!IthJ
g+".!(
@(*xITH
|Pg 6T
xL,Ht]
M;er 8^$
FMS"6Mi
t8-WWt
%K{DPI"l
N;=T}W
)o]2.#[j2
725jcomH
@g.-RYQO
t80u*N
\V/%fB
3`l0~2
K-aDZZX
aEB4th
EtZ \A7fu
A(f|A8
+ HDMO
#JavPP
l1Q@5T
a/4h93u
*3,,X^
E4O'dJ
0T0mjcd{\E
C?S\xT
E],a7L
!2L%kh
kPu*Hq l?
mprcSAd
OL%_M#
TPFs+8
?string too lo
valid ]
/positi0
Unknown excep;
"#$%&'()*+,-./01234
56789:;<=>?@ABCDEFGHIJKLMNOPw
`abcdefghijklm
pqrZuvwxyz{|}~
Enco{{
ter.K"
LgDeW|
FlsFree
SetVnu
cwCorExl
&OMA$#
caG 4<3
has ma~(.t
dbrary i6
v2Nm f
mG.?3- A
%er bug
yotW"
N(/clr)<Pc
LOa)nlu4
zhh(<hjp
3;G7+A{\m
<p\g(m
EM!ZPM: vTZ>a
X"uFpS<6J
HH:mm=?m
d, M }
663b3 'T
50nQ 8PX
vpip<TP:nD
'eekW%
kGt!gu
16L!UNI
nFy''] 1
<?;`Wu$pl
>BoxbU
_6R32.DLL
('8PWF
CONOUT
\fM<T>l
I`h|02
L&&jl66Z~??A
Oh44\Q
&N''io
D""fT**~;
d22Vt::N
J%%o\..r8
8$4,6-9'$
6.:*?#1pHhX~AeSlZrNbS
EHl\tFeQ
~FbZwKi
y1XSNE
pmfW\Ay
yJ#(5>
MP[ja|y
LQZk`}y
y0YROD
qlgV]@y
yK")4?
fq|_REy
`wzYTCy
y%ncty
<)boxu
l{vUXO<
j}pS^I<
</di~s
<?HAZS
dmR[@<
<I>7,%
D_Vi`{<
ungXQJ<
<C4=&/
NU\cjq<
<5BKPY
Qkkbal
?P,OMSCF
]y n(08i
2pyright
995-2005 p
bObyRC
deJean-loup G`
[-&LMb#{'
INnyhJ
)\ZEo^m/
H*0"DW
IiGM>nw
ewh/?y
OE"A6H/6{
X_aGxv
*O;/e<{
bN^>>v
l7>2bj
:t/2F6/LV{+y^A/_B
Ns"ici
neep=H8i'a
IsN|mw
mtl|HD
Kernel:dl
_simd()
1#QNAN
\KHK\S
zip-Os9
"\B\&SFX.pd
B.,g&Dp@
g?tUX!Q
\-!wXX
b;Op<OW
X?whg-
d}oB>,B<
_<6{<?B6/
C[lTGW
ug\4Gb7
hgQ'j'r
hWe4lV
<@&*.*
#-3;3I
-55/=5xr
9&818<8J8
#X8f8t8
g)<1w.
<p.Zgr
wt^wN..6'>
2E=Ho
$H$//
/H:HEH
x(Sw?AV
r_f@@7
/!5An
CPgR/S
Td1~_C
hXLF<(
dLinePar
@_W eor
ZU"chb_
pvgX"r
44tgoC
`x_of_6
-HmO;O
SkipB$
\U(&yZ
'2adnrnF
l@QWDuh)v
Ixx@o
wiBegG
V~Bf[\
~R"GJNnG
W>ujdl~kh
d+yprBti
Vtg;cis
F|6Zb(K
7A.nx92N
G;RW7cs
/ Tick5
QueryP
3s.z1.D
DbuNsG
C4ToMf
/HedDlrm;?
nsjId8
sTzSpzif6m
V$Unh_dE
b9Is.jgg
[talpGR|#
AShet3
[Bh4kM
~@!P^D
XPTPSW
999999999999999999999999999999
K````]]]]SSQK33222--,,,,,,,**
K````]]]]SRRP33222--,,,,,,,**
K````]]gqSRRT33225--,lV,,,,**
K````]
K````}
rukj,,**
aaeyUQ
u//kj,,**
1\\\\z
#OOOON
GGGGGGHhC$$DD
BBBBBBB
]]]]]]]]]]]]]]]]]]]]]]
]9??????????????????
]99?@@??????????@@?9
]9JJJJJJJJJJJJJJJJJJJ]
]]]]]]]]]]]]]]]]]]]]]]]]]]
\@9999999999999999999999@]
k::::::::::::::::::::k]
]]]]]fI::::::::::::::::::I]]]]]]
occc]>>>>>>>>>>>>>>>>>>>]]ccco
9E9EERWOKLDQU
va9999DQUiT
va9999DQU
4.8'3I*UUUU
N-P:/5
#$UUUU
FE1R+UU
UUUUUU
UUUUUUU
UUUUUUUU
UUUUUUUUUUU
-_uiKKk
$ c@00&
BP<]?8555
70OI!Vmzv
?RZG~
hm %`)
.?RIV
3h4f`t
70ti[G
9Q0:AGG
P\eG0PV
Oc|l&
xY~=?4C
,,^z6z
A*bdC>
oCKk'(
Al~z-^s
ab+usgC`
wLf!Os
W?ZkaI
gv]fy~
3O"jMn
~(V_xI
wvv^388
attt`ll
vrJ)0=c!D
agg'FGG
Iba5_K
qy0iW1
i6&<Mv~
xtww_y
ZZJhkm
ommmm:
}}}r``@
cw/l'^
N4n'aw$
:%;%(*
w`"Y#1
a~?z^v=z^v=
Gx+6w;
yofp\eO
`H/L87
MgR1sH
!xF:Vr
H(sE a
{^|.`1
///Hggg
H]dFCTZ
VoxDLbj
>>>mTTT
"???VTTT
ppp4ttth
ppp4\\\
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
<dependency>
<dependentAssembly>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity>
</dependentAssembly>
</dependency>
</assembly>PA
KERNEL32.DLL
COMDLG32.dll
SHELL32.dll
SHLWAPI.dll
USER32.dll
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ExitProcess
GetOpenFileNameW
SHGetMalloc
PathCompactPathExW
SetTimer
RE-DEMON
RE-DEMON(KFTC).exe
h\8jP6
x:sUwR
}Gk7,k
wo^qAA
1G=%NUQ
Lh)hpX+
jXjgg.
A8)sw0"
AHIFd=
VL@#X~
'@?+uk
c43Uh5
5?>fH}
=wRN2@yv5
I)kdn
%jQjNv5<
k[Q"},
)wvyAM
o2x:6|
I(Ou(r
CW_^2X
Uj9[-K
V96V<p
tNon=3j
uU+Wxs
(~4?nT
L;#nl,
^xQQbmr
<$|7>^X-MK
N;QWWt6
iHQD05b3
##Bbit
dzHlD4
RE-DEMON(KFTC).exe.lnk
VS_VERSION_INFO
StringFileInfo
041204b0
CompanyName
ESTsoft Corp.
FileDescription
ALZip Self Extractor
FileVersion
19, 10, 1, 1
InternalName
EGGSFX
LegalCopyright
Copyright (c) 1999 - present ESTsoft Corp. All right reserved.
OriginalFilename
EGGSFX.sfx
ProductName
ALZip
ProductVersion
19, 10, 1, 1
VarFileInfo
Translation
No antivirus signatures available.
No IRMA results available.