Static | ZeroBOX

PE Compile Time

2021-04-02 18:54:24

PE Imphash

3f728412058b62c418b1091768b74d7b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.code 0x00001000 0x000185f2 0x00018600 6.53345039933
.data 0x0001a000 0x00000064 0x00000200 1.0662581269
.data 0x0001b000 0x00001000 0x00000200 0.0
.rdata 0x0001c000 0x000020b3 0x00002200 2.96025706595
.data 0x0001f000 0x000007b2 0x00000800 4.70767794561

Imports

Library user32.dll:
0x1001f0c0 GetActiveWindow
0x1001f0c4 SetWindowsHookExA
Library kernel32.dll:
0x1001f050 GetProcAddress
0x1001f054 LoadLibraryA
0x1001f058 VirtualProtect
0x1001f05c VirtualAlloc
0x1001f060 lstrlenA
0x1001f064 lstrcatA
0x1001f068 lstrcmpA
Library ole32.dll:
0x1001f080 OleInitialize
0x1001f084 OleQueryCreateFromData
0x1001f088 IIDFromString
0x1001f094 HDC_UserSize
Library msimg32.dll:
0x1001f074 AlphaBlend
0x1001f078 TransparentBlt
Library comdlg32.dll:
0x1001f02c PageSetupDlgA
0x1001f030 PrintDlgA
Library oledlg.dll:
0x1001f0ac OleUIChangeSourceW
0x1001f0b0 OleUIConvertA
Library comctl32.dll:
0x1001f014 CreateStatusWindow
0x1001f018 LBItemFromPt
0x1001f01c DPA_Create
0x1001f020 FlatSB_ShowScrollBar
0x1001f024 ImageList_GetFlags
Library oleacc.dll:
0x1001f09c IID_IAccessible
0x1001f0a0 LresultFromObject
Library version.dll:
0x1001f0d0 VerFindFileW
0x1001f0d4 VerInstallFileA
0x1001f0d8 VerQueryValueA
0x1001f0dc VerQueryValueW
Library gdiplus.dll:
0x1001f040 GdipSetPenUnit
0x1001f044 GdipGetImageEncoders
0x1001f048 GdipGetPathPointsI
Library winspool.drv:
0x1001f0e8 ConnectToPrinterDlg
0x1001f0ec SetPrinterDataW
0x1001f0f0 GetPrinterW
0x1001f0f4 DeletePrinterDataExW
Library shell32.dll:
Library advapi32.dll:
0x1001f008 RegQueryValueExW
0x1001f00c RegisterIdleTask

Exports

Ordinal Address Name
1 0x1000447b DllServer
!This program cannot be run in DOS mode.
`.data
@.data
.rdata
PQRVW=}
PQRVW=
PQRVW=
PQRVW=
H_^ZYX
PQRVW;m
PQRVW=
PQRVW=
PQRVW;]
PQRVW;E
PQRVW9
PQRVW9
PQRVW=LZ
PQRVW9
PQRVW;m
PQRVW=
PQRVW9
PQRVW9
A_^ZYX
O_^ZYX
PQRVW=
N_^ZYX
PQRVW;M
@_^ZYX
PQRVW9
PQRVW9
PQRVW=
mP dU"
\D nE*
:P("P
6E"MD"
+D *Q
VQ"1@"
D(xE*?P
\A"n@(
GU*pE*
T )T(4D*@
2T"5Q
"|T*FP |
"jA(Q@
ET(=E"
iP*}@*
P*AT"(T
E(XP(z
(X@(rQ(z@(z
(RT(rU
(uU(p@(rE
hP )P*8P
U(pQ(RU(
E(PQ(x
iP 8P"yP
,P"-P <T
(P"=P"hP
(TA zP
Q(tP"P
rU*,T e@(
(OA IT"+
E Z@(4
-P(0T
".A(9P
".A(9P
*,A(9@
f@(QU*
WD",T(
A(dE(LQ(fE(
P"WD o
!T"4@"/
D %@(DA*
ZP*ND(x
KA("@":@
"XD :@
(5P"q@*
(gU*}E
eA B@"
A"8A ?
D*rA(<P*
T",A*k
"eQ"RT
HD(jP(
JP(.Q"
D*tE 1
@(LQ"5
(vT*[A
$Q ^A
P*V@
(bT*]E
?T LT*M
@"rE*/P
*wD x@
SA* Q*3
(0E*@A
>E"GD
*UE"6T
Q(uT*2A
E(^D p
@*]@"w
U"iA 4T
kA(c@*E@
rwenc_dll_x86_release.dll.lock
DllServer
6Jo,`12@{yq
7Y8>ON@>n
dMf_DtP#
ea)77L6^/O1
==f1)kff
TR&</[lI%
h>/9leE
RmG{M;q
rTM8$c*`}A
0^nKR.r9.J6
?y*ZZ_-/D
Xd0fqNCl
ysC0PeBV2TU
\C@RM7S0C2/
G"gkRX8eV`D
wK#/7rz!R
m3hJcR
+,+sHH"tc
l6'uI"|
Ap]VX`#X+3U
Ho=,Xf{fs
B<T_@<
<}pIo$Gh
LH=)+"gX-1
]HYaGNY|$>
lgiry^)Xu
3[Z5MiL=v
b0Qv9I
3^R=0VW-
Ey\A>O>.
@)S9<N<7G
Kd|ntpcH<2a
V&esk'#"
?]a%m9SGH1
HYo6hwHG1c
UI('vyH
w+W2wZ){?`@
}HM16x
Dz;LOQH
(`Q*Of(;S
Ybq!tG
(-D4,s4s]Nk
=GIkUt
Mnv(@AMx#"8
pzAn/e`LO
zSxzH=;ME>u
=erF(+
;kIr8hT'4F
9pJ!f:tJ7[
,c)O8jZG
O7]0xc
jVa}0AcbJsI
x0!u8q&pu
gjoy1Xb:U
d^)>B[Lb
e7T/ts$TSz
V}m(+z
-dKl\rK
)3og3(#"vn
>>"Jz%}_s
d\{PZxi
LE(-O9q,O9
$U%J[]V8]T
53@8<qf4th
jc#QEM^bSBs
g2W`|]&fOt
0U[|*R
K[z\NG
i\RT}Q
ER.,+peCo.+
*2`(mrnP
[px9h$z
zI{jiT
.$=<a&oPEB_
<{4CZiDB
<*D*1$
vobfT<
X*qPt</
Jv}]JCLV
F)poPOX
OcTQjL_
r0.@9o$
$sh<d8A6i$c
-+=F}5l
9|D;F=W
f_?_0I
px25E_-
2MUn|<D+]W4
3dT@Q1:W
_e{f$Vo'/C2
Azl$iLmd
Ap,s!Oa
D5"!ozn@h
`2`RQk
"N\a;1
Y_R&j.(ni-
J;KD*.a=
.tF-5P
kFENE"#
&J?"}T@XZ/
O|b={=.
5Yqt>n1#*xU
/Z:evv%5%X
,T%HNp*n:MY
/Ch6[Z
$;D<U(O7
`fADWt`ofs
`FyIfA"
\6&VG-=P4,
#Rr8^S=FU<
4;l@[4
2XymP*X
WHD]?S!
:U#}Fe1
qteY\xJ
DHoG&+G=
>g|j{Ss_y
^_vC|v]}drK
n8]:$(#
(h@@K{uvT_j
&X'{wzCh4
|XJUGnb=O
/E+%mPYr3('
Wy8ahNw9
_[[PwF)s1
{E$GsSm.Z
`)LMD"W=1.d
;MBGM#n|
jHU|\W
K1B0bgXK
8;P!:w
6BZ*Yg:
EI|JbfAH
xwx'zM{4
4Ew:Xhy
bz`8;Vc"?
T#|tZuoM2w
hKsGLy;rn\G
^a1ux\>
n/iO(fV(bjk
*FTV#!
aelq,X
*uN0x7guC
;COu5,772
F,wPf"8]6<
;70NPsW
nVeP`.-/6
\+v]2t+Z"8[
nSN(;qAs
OsC"V/
,z-rAjV
IM0k-uN-
F|{^Oa
M&}643O>
O/<_Wj!'
1=a}BC
]D>XpciE[Q;
C//7[Qo#24
/.0F>h%l/8
5K1mQ)=<m3M
d!@{$w.|"x|
fF7"SWXyx/
>v\|fV<O]
Amu.u!
i/lv2IVO
.lW|pkME
rCXb^Oa]!)
N_g@q`Z
l:qw.|I*5(
2s+5kVBM
;;ciOBM>pJ
fVSz"Oud
|O!7m)I
9j?F_1`
j<2G(`]d
TM7^WB
ZOXLiWi
#}h"U#D5
\rAlWe|)
0G?Z7@7sk
Tenp!Fw^a3
+Ra}P'=
3[EA6m9
rTw5-FT
^_[wWiHSCn
XEz=+C*
14WiY9YE
dLb`[6f
|d8I)H
C+T%L'k>\
M+L1f>(
@r7UnsO}pL}
H;0!OfME8$A
z"1av2`5mK
bq{vWm
X::h]zZ
pqUQHRFyWMF
#5!p|K/<ajq
1gfE@"-
6U5{8:Ht
f|9-4ul
Ojt#WZ>[
7}(\_NwQWF
g(sfL\N
GI}f2T[^Tx]
zRUT-wq11
Gx7ULz\Ih.r
p|ZW1#p}iyG
3D,k[j(
R=,0,T
[|IX>g'
/h1Q`wm+Q[w
cU3w&/u
`y6@2<F:
\<Q:pG4q
s^ZMFR2
pN/O'p9?`r?
PcsbNQg_
\Q&I$C
$,_p\)X&
$K//J@)-o
Ar#+NJVw5I
GetActiveWindow
GetLayeredWindowAttributes
SetWindowsHookExA
user32.dll
GetEnvironmentVariableW
GetProcAddress
LoadLibraryA
lstrcatA
lstrcmpA
lstrlenA
VirtualAlloc
VirtualProtect
kernel32.dll
CLIPFORMAT_UserUnmarshal
HDC_UserSize
IIDFromString
OleCreateEmbeddingHelper
OleInitialize
OleQueryCreateFromData
ole32.dll
AlphaBlend
TransparentBlt
msimg32.dll
PageSetupDlgA
PrintDlgA
comdlg32.dll
OleUICanConvertOrActivateAs
OleUIChangeSourceW
OleUIConvertA
oledlg.dll
CreateStatusWindow
DPA_Create
FlatSB_ShowScrollBar
ImageList_GetFlags
LBItemFromPt
comctl32.dll
IID_IAccessible
LresultFromObject
oleacc.dll
VerFindFileW
VerInstallFileA
VerQueryValueA
VerQueryValueW
version.dll
GdipCreateBitmapFromHBITMAP
GdipEnumerateMetafileDestPointI
GdipGetImageEncoders
GdipGetPathPointsI
GdipSetPenUnit
gdiplus.dll
ConnectToPrinterDlg
DeletePrinterDataExW
FindNextPrinterChangeNotification
GetPrinterW
SetPrinterDataW
winspool.drv
SHGetSpecialFolderPathA
shell32.dll
CryptEnumProviderTypesA
GetKernelObjectSecurity
RegisterIdleTask
RegQueryValueExW
advapi32.dll
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.937e2c551368757c
CAT-QuickHeal Clean
McAfee Artemis!937E2C551368
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Graftor.937823
K7GW Clean
CrowdStrike Clean
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of Win32/Kryptik.HJZU
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Virus.Win32.Gen.ccmw
ViRobot Clean
SUPERAntiSpyware Clean
Rising Trojan.Kryptik!8.8 (RDMK:cmRtazrxx4p/WNInKcZKXPPcFSZ9)
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Dropper.ch
CMC Clean
Sophos ML/PE-A + Mal/EncPk-APW
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Graftor.937823
Jiangmin Clean
MaxSecure Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
AegisLab Clean
ZoneAlarm Clean
Microsoft Worm:Win32/Gamarue!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
TACHYON Clean
VBA32 BScope.Malware-Cryptor.MTA
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
eGambit Clean
Fortinet W32/GenKryptik.FCLW!tr
Webroot Clean
Avast Clean
Qihoo-360 HEUR/QVM40.1.641B.Malware.Gen
No IRMA results available.