Static | ZeroBOX

PE Compile Time

2021-04-07 04:33:08

PE Imphash

32856986f7eacdd11a6f4fcbafab0a87

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002c418 0x0002c400 7.80086757629
.rdata 0x0002e000 0x00000924 0x00000a00 4.89771123179
.pdata 0x0002f000 0x0000027c 0x00000400 3.37226633893
.CRT 0x00030000 0x00000008 0x00000200 0.101910425663
.reloc 0x00031000 0x0000000c 0x00000200 0.0611628522412

Imports

Library KERNEL32.dll:
0x14002e000 DeleteFileA
0x14002e008 GetLastError
0x14002e010 CreateFileA
0x14002e018 WriteFile
0x14002e020 CloseHandle
0x14002e028 ExitProcess
0x14002e030 GetSystemTime
0x14002e038 GlobalAlloc
0x14002e040 GetTimeFormatA
0x14002e048 GetCommandLineA
0x14002e050 VirtualAlloc
0x14002e058 VirtualProtect
Library USER32.dll:
0x14002e068 MessageBoxA
0x14002e070 SetWindowTextA
0x14002e078 GetWindowTextA
0x14002e080 OpenClipboard

!This program cannot be run in DOS mode.
.rdata
@.pdata
@.reloc
OH`O]}
gO{pBM
OdOxpEv
OH`1^}
gO{sBN
OH{1]}
OHy1]}
LgO{rEu
([[0YB
gO{pBM
OHaO\}
gbSdgB
OHaO\}
gO{pBM
OH`O]}
t,OsqEt
LgO{rEu
gO{pBM
J,OHpON}
u,OrqCa
gO{sBF
KgO{sO\
KgO{pEr
HdOxrEq
KgO{qBD
OHaO]}
t,OrqEr
87s.WnR
dU~- e
,OspEu
KdOxsEr
#1#\Vn
OH`1^}
N)xVDn.
gO{pBM
eu(q.N
yV>%-I
Z1m&]n4
j1m&]n4
!c"Tn,
([[1QC
qV0Be[
JdOxrEs
yV>%e@
gO{pBM
gO{pBM
gO{pBM
OHyOD}
| [[0aJ
jw^UfB:
gO{pBM
.^mfBY)U
MgO{pNN
Jdw)H&17s
7#m@nsGNc~
d m@nsGN/?
,OspEu
$m@nsGN
Jdw)H&17s
OgO{pNG
e(C\tb_
OHaO\}
OgO{pEv
w,OrqEu
L(N9grW`
v,OrqEv
^UMb '
OH|1]}
OHyOD}
ns.)@
JgO{pBM
Ydf,H7
nfC9R[!
JdOxpEs
gO{sBF
^Uw"w/
OHyOD}
gO{pBM
~mapX~
OHaO\}
OHa1^}
OHy1]}
>ZdgUR7
9WnqR~
#5MYr]
SddUpz
RL}"$A
,O{sEt
OHlOT}
w,OrqEu
OHyOD}
OHy1]}
gO{pBM
LdOxrEu
JdOxrEs
OHy1]}
OH|1]}
HgO{pBU
OH`1^}
LdOxrEu
OHt1\}
KgO{qBT
(ru6m@
OgO{pBU
/n8Ydwe
iB([[0$
LgO{rEu
OgO{rEv
OHyOD}
LdOxrEu
OHrOM}
OHwOM}
t,OrqEs
OHa1^}
OHAO|}
HgO{sBN
yV>%M.
8/s.WnR
LgO{rEu
gO{sBF
OHy1]}
gO{pBM
dOxsO_
gO{sBF
OHyOD}
gO{pBM
OHy1]}
(@[0WN
iB(I[0;
gO{sBF
-KiBP]
RL}""G
OdOxpEv
.^mfBY)U
p9b]od
OHaO\}
8?s.W*
OHyOD}
JdOxrEs
dOxpOD
8?s.&+
gO{pBM
~V!'P~
OH`O]}
^Uv"w/
87s.WnR
.`.>3]
4 H8-U>Z
OH`O]}
OdOxpEv
OHaO\}
OdOxpEv
RM}"yi
OHaO\}
OH`O]}
h{]z#s(
{]uLs(
{]d\s(
l8[dwe
N)YuF
g8Xdve
{]aQs(
[l@ngGb
NgO{pNG
Ux$A+:
l@np.lD
gO{pOF
OHy1]}
gO{pBM
OH`O]}
OH`O]}
OH`1^}
OdOxrEv
u,OspEu
JgO{qEs
|([[0:
OgO{pBM
OHy1]}
sc~9{d
eu(q.N
OHa1^}
h2m4q:
OH`O]}
SdtU3)
yW>%xk
-~8Qd}e
OHvOM}
gO{rB_
m&wZ8O2
OH@O}}
J,OsqE
)Z2%)OQy
gO{pBM
[,OssEs
'J,OHBO|}
w58Z_o{])
8Z,_{]X
8Z;P{]M
NgO{rNV
KGGi?A
OHY1Y}
t,OrqEs
OHyOA}
OHa1^}
KeJ(q<Z
LgO{pBM
,OssEv
Jdw)H&17s
OHhOV}
{]l,s(
5j5P9%zT
OHyOD}
l)[ud
nP9<wT
dP9<fT
gO{pBM
OHy1]}
OH[Of}
gO{pBM
LgO{sEu
JdOxpEs
Y[0.A
OHt1\}
OHa1^}
OHt1\}
LdOxrEu
(l@nsGf
JgO{qNO
,OsqEu
gO{pBM
OgO{pNN
f%l@nsGfN
,OspEv
OHh1_}
v,OrqEv
?=Bo$D
y}}CY#U
bnfB9b
MmOsqEv
6l@npGM8
NgO{pNF
KgO{sN_
OdOxpEv
u,OrqEv
MgO{rEt
OHw1\}
OHw1\}
JgO{qEs
OgO{sBV
t,OrqEu
OHrOM}
t,OrqEv
naC9][!
(R[1DD
OHw1\}
OH`O]}
JdOxqEs
JgO{rEs
iB([[0"
gO{qON
OH`O]}
N9s.WnR
:Wdvz]z
(P[0=A
OHaO\}
dE)H<15
OHI1[}
OHy1]}
OHaO\}
aOJGG\
:Wdqz
}JQUn
}JQUn
x ATAVAWH
0A_A^A\
WAVAWH
A_A^_
WATAUAVAWH
A_A^A]A\_
UAVAWH
WATAUAVAWH
HcA<E3
A_A^A]A\_
D$@H9D$(tXH
D$ 9D$$u
u/HcQ<A
|$ UATAUAVAWH
A_A^A]A\]
WAUAVH
A^A]_
x ATAVAWH
A_A^A\
WAVAWH
A_A^_
Warning
Common causes completion include incomplete download and damaged media
Invalid command line parameters
Please wait while error report is being sent
DetourBinaryOpen failed: %d
DetourBinaryEditImports failed: %d
Warning: Couldn't delete %s: %d
An unexpected error occurred while reading
Unable to read from %1, it is opened by someone else. Unable to write to %1, it is read - only or opened by someone else.
Please read this information carefully
A file creation error occurred while executing the command.
Critical error
An error occurred writing to the file
sample
Current time for information:
Please close all instances of it now, then click OK to continue, or Cancel to exit
.text$di
.text$mn
.idata$5
.rdata
.rdata$zzzdbg
.xdata
.idata$2
.idata$3
.idata$4
.idata$6
.pdata
.CRT$XCU
DeleteFileA
GetLastError
CreateFileA
WriteFile
CloseHandle
ExitProcess
GetSystemTime
GlobalAlloc
GetTimeFormatA
GetCommandLineA
VirtualAlloc
VirtualProtect
KERNEL32.dll
OpenClipboard
MessageBoxA
SetWindowTextA
GetWindowTextA
USER32.dll
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.ac9e6b5f93ae7560
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.c1469c
Arcabit Clean
BitDefenderTheta Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
SUPERAntiSpyware Clean
Tencent Clean
Ad-Aware Clean
TACHYON Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
MaxSecure Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Program:Win32/Wacapew.C!ml
AegisLab Clean
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Clean
eGambit Clean
Fortinet Clean
Webroot Clean
Avast Clean
CrowdStrike win/malicious_confidence_60% (W)
Qihoo-360 Clean
No IRMA results available.