Static | ZeroBOX

PE Compile Time

2021-04-07 00:04:39

PE Imphash

560828ec1597fa6a8bf91e627ea543e3

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002cad8 0x0002ca00 7.71455624529
.rdata 0x0002e000 0x00000b0e 0x00000c00 5.08365351108
.pdata 0x0002f000 0x000002a0 0x00000400 3.43545537768
.CRT 0x00030000 0x00000008 0x00000200 0.101910425663
.reloc 0x00031000 0x0000000c 0x00000200 0.0611628522412

Imports

Library KERNEL32.dll:
0x14002e000 CreateFileA
0x14002e008 DeleteFileA
0x14002e010 CloseHandle
0x14002e018 GetLastError
0x14002e020 WriteFile
0x14002e028 OutputDebugStringA
0x14002e030 ExitProcess
0x14002e038 GetSystemTime
0x14002e040 GlobalAlloc
0x14002e048 GetTimeFormatA
0x14002e050 GetCommandLineA
0x14002e058 VirtualAlloc
0x14002e060 VirtualProtect
Library USER32.dll:
0x14002e070 MessageBoxA
0x14002e078 ShowWindow
0x14002e080 FindWindowA
0x14002e088 SetWindowTextA
0x14002e090 GetWindowTextA
0x14002e098 OpenClipboard

!This program cannot be run in DOS mode.
.rdata
@.pdata
@.reloc
x'5DvZ
Z~yYZ;
ipMs>I
90v4(v
!`da/$
PE<D`62
@t{$)?
u?^DAL
[~xYZ:
;kmh;)
`|262F`
U}26px
x'5DvZ
Ytb$(?
`6=):wc
`626uh
YC'>26zw
@t{$)?
`626zx
uBd12~
`6=):wc
`626uh
eyv6z?
]tt6z}
262^L
lp%262
h;ilw$*K
`626zx
Ytb$(?
026zwO
[:6zFA
^Bd92~
B%f_62<u
x'5DvZ
7M$#>Y
`6=):wc
`626uh
`6=):wc
`626uh
`6=):wc
;kmh;+
h026z6
Z~yYZ;
{wc;6u
X~{YZ9
6M$">Y
x'%DtZ
`626zx
|;kmh;+
`626zx
`626zx
X~{YZ9
`626zw
`626zw
`626zw
`6J6zw
f626zw
`626yw
b6R7zw
`626zw
`&26zw
`626zw
H626zw
Db6z?zw
`626zw
`626zw
`626zw
b62&zw
`626zw
`626zw
b624zw
`626zw
`626zw
`626:w
`6"6zw
`6r6z7
b626zw
62tzw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
!`da/$
XlD726
H526z?O
x'5DvZ
0l*7262
5wf`-$
YCf626z
@t{$)?
x'-DuZ
Y~zYZ8
;ilw&6
d62PTx
x'7DvZ
Z~yYZ;
a062^L
Xtc$)?
hmmh;)
x',:vZ0
!`sc;#
x'-:wZ1
@t{$)?
P0Y<`2267
Z~yYZ;
@Pmmh;+
!`sc;#
Z~yYZ;
026zwO
u'T4z?O
h626z?
x'5DvZ
x'7DvZ
AS9|60
x'-DuZ
C&>26zw
PCf626z
Z~yYZ;
626zwc
x'5DvZ
Z~yYZ;
0626zFA
Y~zYZ8
?l06px
J5=942
h826z6
x'-DuZ
:062^L
'*>X3av
wCLX&>
Z-8l`:262
;ilw&6
^~AX`>
a6262^@
~[XP31Fo
P!YC'*O5
x'*0U&
B%Rv42<u
g9-rzwc
626zwc
;kmh;)
H!as`;"
Dn26zw
Y=d626
<wow$6
v7zw1fM>
66zww-Z
h026z6
H!as`,
726zFS
|&;AoUP?
x'5DvZ
b629ewc
E<4`629S
Dv=>S
9-rzwc
C79ewc
x'5DvZ
x'5DvZ
x'-:vZ0
626zwc
`6=):wc
)\ea6z
ka6262vs
yPCc626z?
k~7zw
^vx'?0G
pV0d&@
RCLX&>
Z&>QCg626z6O
8mmh;+
wBLX&>
wELX&>
Y36z7=
`629ewc
;kmh;+
C79ewc
h926z6
!`sb,
`629ew
@ty$+?9No
x'-DuZ
=ilw&6
6wgw.!
D`629S
$`629S
`629S0
Iq"9Sp
oufu^
`626zw
0=):wc
Bty$+?
LX&(X{
026zwO
026zwO
3PCf626z
!jsk;)
7M$#>Y
M`62sK
`629e3
x'>DwZ
x'5:oZ1
`626zx
`6=):wc
x'8DwZ
Utk$)?
x' :~Z0
Y>`6262
x'8DwZ
DV26zwO
Utk$)?
Utk$)?
lPA262
X~{YZ9
2x'50V&y
pCLX&>
X~AXa>
W/d~AX
;L&q3
x'#0T&y
.aD 60
wGLX&>
16zFH:
26zFHv
5wf`-$
Qtj$(?
Z~yYZ;
qU6O
l`62~K
<wow$6
2?Y=a6262
Z~yYZ;
2?Y6as
r{^~sX
wBLX&>
mo726?FSv
7zFA~ZXP
Y<h4262
626zwc
`626uh
Y~zYZ8
!jsk;)
Sux'?0G
')>Y7aw
uy';>]
')>Y7aw
uz'(>]
')>Y7aw
')>Y7aw
[~AXb>
oa6262vR
?hsj;*
x',DuZ
x',:rZ4
]~~YZ<
626zwc
`626uh
8726z?O
Dv26zwO
h(E[LL?
kN[fL?
`6=):wc
>6zw`N
H!as`;"
wDLX&>
Y=y6062
9-rzw1x
`6=):wc
x'-:qZ7
5M$!>Y
9`62sK
Q[Bd<2
Y>`6267
Ntr$(?
x'-:w.
Ntr$(?
x';DwZ
U/N7z3
5M$!>Y
5wf`-$
x'5DvZ
S!62BK?
9-rzwc
`626uh
0_6(60
>f[2d;
Z~yYZ;
Y~zYZ8
5Z36px
<`62~C
Ktr$(?
x'>:fZ0
<`626zw
Z~yYZ;
Ntr$(?
4`626zw
v`([Y&
Ktr$(?
x626zFwv
5M$!>Y
26zF~v
x'5:oZ1
Z~yYZ;
;x'>:`Z6
Z~yYZ;
X~{YZ9
Ktr$(?
oi36px
Xtc$)?
x'-:w.
PC%&26zwO
"5Gl0[
im36s6
x'-DuZ
{06z61
IP9!|o
`626zw
E<|`626zw
h1262Fi
g62ru_
?hsj;*
RM<\`62~
Ca629ewc
`$)Y&*
x'5:oZ1
h626z;
x'5DvZ
`8+Y&J
D>26zw
$Y&(a{
>6zw`~
r^Ga4MX&
x'5:oZ1
5\$!>l
:V1|jz
7L`689
h626z?
5&>PC$
h=26z6
!bda)?
Y~zYZ8
)ro)r6
_g8\1(
`629ew
Y=t626
Z-8lL)262
`629ewc
f'>~=a6
Z-8=S3
C`626z
`9-rzwc
`mmh;)K
6zw18a\{
`626zx
`629ew
`6=):wc
Utk$)?
;kmh;+
E<D`629S
`fRX&J
`4SX&*
Y~zYZ8
`6=):wc
`626uh
1,?vj{&
gOa689
@526z?
.()v`6z
H!as`;"
D&36z?
x726zw
`626uh
a626zw
`626?FZ
`626zx
x',:vZ0
626zwc
`626uh
x'5DvZ
%36zF~
<EvY 1
x'5:oZ1
6zw`jRX&
Y~zYZ8
Y~zYZ8
D&36zw
`T`X&J
E<L`626zw
x'8DwZ
X&>(^o
Y=a626
:W1@|{
`626zwOy
X~{YZ9
x' :~Z0
@t{$)?
26zFwv
x',:v.
X&>(^o
Utj$(?
D~26zw
`626uh
Xtc$)?
@t{$)?
x'-DuZ
`626zx
26zw~?
RE<la62
@2262Fi
RE<la62~
Ytb$(?9UQ
9-rzwc
@v26z;
@626z;
X~{YZ9
26zx?y
Z~yYZ;
E<H`62EA
mr426?
_{|*02s
`6=):wc
`626uh
x'0:oZ1
E<la62~
Y~zYZ8
x'5:oZ1
;h`689
>vj{gz
!bda/$
g62P>x
E<$`62Pu
Ru<|`62~
D>26zw
DVZ6zw
Z~yYZ;
h626z;
`lY&*
x'5DvZ
R]<t`62
h626z;
`626zw
I`6Tru
RE<de62~
LXR]<|`62~
h626z;
DN2BYFH
?hsj;*
DV26zwO
9-rzwc
x'5DvZ
Y~zYZ8
h626z?
5g06px
\-zwck
626zwN
mXY\,l
626zwc
`626uh
C&>26zw
`626uh
Z~yYZ;
X726uh
`6=):w
7M$#>Y
`626uh
x'5DvZ
0=):wc
PCf626z
x'5:oZ1
x'5:oZ1
lX&06;
@t{$)?
x',DuZ
vaBQ9e3
`6=):w
C&>26zw
atY$+?
?hsj;*
;36?Fl
026zwO
Z~yYZ;
lb=36?Fl
Xtb$(?9U(
`626z?
H!as`;"
Z~yYZ;
J5wS42
9-rzwc
C'>26zw
h926z6
@t{$)?
Xtf$,?9Qo
0=):wc
XM262Fh
O262Fh
')>Y7aw
P626z?
M726z?
x'-:wZ1
H5wew,6
[262F`
d262^L
x'$:}Z3
waCO9e3
Y~zYZ8
x262^L
V~@Xa>
7wdw.!
6M$">Y
9-rzwc
x'5DvZ
x'':}Z3
x'-:wZ1
Y=a626
72?QCf626z6O
h626z;
6E<``62
!E<o`62
7E<v`62
>E<}`62
36z3Ny
36z:Ny
>o262Fh
x'5DvZ
uaC9Puh
B%<:62<u
8626z?
)Mo)r6
]Bd92~
`6=):wc
Dn26zw
D626z6O
626zwc
`626uh
`626zx
l>9362^L
Z-8>a626?FH
Z~yYZ;
@726zFA
$Y<,mI
=362^L
qqb9k0
P<`626zg
;ilw&6
Y<g606K
Z-8lX7262
H!as`;"
9-rzw1T+
IX1l1{
AY<a626?FA
mT=266
>d626?FH
B%N~72<u
;x?72^
i!&9~3
jmcz1&C
Z~yYZ;
Z~yYZ;
`6=):wc
`626uh
!ksh;(K1
x',DuZ
x'5:oZ1
626zwc
;F%{w2
626zwc
B%jr72<u
;X&{w2uD
; &{w2-
]`62rr
Y=a626
x'?:eZ3
x',:vZ0
`626?FA
@t{$)?
x'5DvZ
x'>:fZ0
'`62sK
x';:fZ0
x'>DwZ
Z~yYZ;
Z~yYZ;
X~{YZ9
Otr$(?
@t{$)?
h926z6
h>26z6
H!as`;"
,,"9ks
p9#2cx
Z9"z@g
l2$362^L
Z-8l\626
`626uh
`9-rzw
2M$&>Y
MX2X)r,
226%)Kv
Y~zYZ8
!`da/$
Xtc$)?
x'5:oZ1
J-QJ62
5b62~S
x',DuZ
626zww
`6<6zw
`626vw
`626zw
k626zw
`6;6zw
`626}w
`626zw
b626zw
`626zw
`626zw
`626jw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
a626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
b626zw
`626zw
b626zw
b626zw
b626zw8~
2xwzIE
j7 6yG
h3>5su
aV39rw
`63<|w
bF3Vzw
d6;7Yw
i6"TvG
ta&83jt
`637{w
`635yw
a::6vG
u5"tvG
aV26{d
ta%86iv
s7'6vG
s7!6vG
a?66sv
d6;7mw
u5"tvG
a?66sv
ta%;#it
`63&sw
a406xG
bF3V{{
a236~e
a6;Tzw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
b62$zw
`6<)zw
b6Btzw&
`62~zw$y
b6bTzwc
b6"^zw
b6RJzw
a6pd{w
a6il{wxy
b6"k{w
a6#T{w
b62S{w$
b6r2xw
Px06)9
b6"kxw#
b6BVxw
b6r^xw!
b6BGxw
b626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
36zwxq
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
db6>6zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
`626zw
x ATAVAWH
0A_A^A\
WAVAWH
A_A^_
x UATAVH
WATAUAVAWH
A_A^A]A\_
t$ UAVAWH
D$P4S/A
D$XyM9V
UAVAWH
D$P$I3]
D$X3M:1
P5W!V1
WATAUAVAWH
HcA<E3
A_A^A]A\_
D$@H9D$(tXH
D$ 9D$$u
u/HcQ<A
|$ UATAUAVAWH
A_A^A]A\]
WAUAVH
A^A]_
x ATAVAWH
A_A^A\
WAVAWH
A_A^_
[+] Module loaded OK.
[+] Exception table registered OK.
[-] Failed to register exception table, error:
[-] Failed to load module, error:
Warning
Common causes completion include incomplete download and damaged media
Invalid command line parameters
Please wait while error report is being sent
Couldn't open output file: %s, error: %d
DetourBinaryEditImports failed: %d
Warning: Couldn't create target empty file
Please select a button
Changes may not take effect until the next time you start playback
Pay your attention
Maximum single sample size for this program may be limited by OS memory settings.
Critical error
An error occurred writing to the file
xKUzpAWUHQuKEHhnAwJ4MEDN4oDSNpNqXpttKkENEx0mQb4KC6No9t60aDCVVTCvZJljsDwl4nxQGXOmh
19:04:36
sample
=======================================================
STARTED
Apr 6 2021
[+] Crypter build ==>
Unknown error occurred for time:
The waiting time for the end of the launch was exceeded for an unknown reason
[+] Successful ending crypter -
.text$di
.text$mn
.idata$5
.rdata
.rdata$zzzdbg
.xdata
.idata$2
.idata$3
.idata$4
.idata$6
.pdata
.CRT$XCU
CreateFileA
DeleteFileA
CloseHandle
GetLastError
WriteFile
OutputDebugStringA
ExitProcess
GetSystemTime
GlobalAlloc
GetTimeFormatA
GetCommandLineA
VirtualAlloc
VirtualProtect
KERNEL32.dll
OpenClipboard
MessageBoxA
ShowWindow
FindWindowA
SetWindowTextA
GetWindowTextA
USER32.dll
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.c781696c39f20ecd
CAT-QuickHeal Clean
Qihoo-360 Win64/Heur.Generic.H8oAadEA
ALYac Clean
Cylance Unsafe
VIPRE Clean
AegisLab Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.4b2352
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
APEX Malicious
Avast FileRepMalware
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos ML/PE-A
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=80)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Program:Win32/Wacapew.C!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/BazarLoader
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
eGambit Clean
Fortinet Clean
BitDefenderTheta Clean
AVG FileRepMalware
Paloalto generic.ml
CrowdStrike win/malicious_confidence_60% (W)
MaxSecure Clean
No IRMA results available.