Static | ZeroBOX

PE Compile Time

2021-04-07 22:33:42

PE Imphash

7bc28ce48ba6a176bfe82b3495ba75dd

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001e140 0x0001e200 6.7344557953
.rdata 0x00020000 0x0000edac 0x0000ee00 6.47072695923
.data 0x0002f000 0x00008e00 0x00007c00 7.71155963107
.pdata 0x00038000 0x00000f6c 0x00001000 5.19995201549
.gfids 0x00039000 0x000000a0 0x00000200 0.811097944555
.rsrc 0x0003a000 0x00010aa8 0x00010c00 2.80464982178
.reloc 0x0004b000 0x00000620 0x00000800 4.77044788745

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003a268 0x00010828 LANG_ENGLISH SUBLANG_ENGLISH_US dBase III DBT, version number 0, next free block index 40
RT_MENU 0x0003a0f0 0x00000176 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0004aa90 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x140020030 HeapFree
0x140020038 HeapSize
0x140020040 CreateTapePartition
0x140020048 Sleep
0x140020050 InterlockedFlushSList
0x140020058 CreateFileMappingW
0x140020060 LoadLibraryA
0x140020068 VirtualProtect
0x140020070 WriteConsoleW
0x140020078 CreateFileW
0x140020080 HeapReAlloc
0x140020088 SetFilePointerEx
0x140020090 GetConsoleMode
0x140020098 GetConsoleCP
0x1400200a0 FlushFileBuffers
0x1400200a8 LCMapStringW
0x1400200b0 GetProcessHeap
0x1400200b8 HeapAlloc
0x1400200c0 VirtualAlloc
0x1400200c8 VirtualFree
0x1400200d0 CloseHandle
0x1400200d8 RtlCaptureContext
0x1400200e0 RtlLookupFunctionEntry
0x1400200e8 RtlVirtualUnwind
0x1400200f0 UnhandledExceptionFilter
0x140020100 GetCurrentProcess
0x140020108 TerminateProcess
0x140020118 QueryPerformanceCounter
0x140020120 GetCurrentProcessId
0x140020128 GetCurrentThreadId
0x140020130 GetSystemTimeAsFileTime
0x140020138 InitializeSListHead
0x140020140 IsDebuggerPresent
0x140020148 GetStartupInfoW
0x140020150 GetModuleHandleW
0x140020158 RtlUnwindEx
0x140020160 GetLastError
0x140020168 SetLastError
0x140020170 EnterCriticalSection
0x140020178 LeaveCriticalSection
0x140020180 DeleteCriticalSection
0x140020190 TlsAlloc
0x140020198 TlsGetValue
0x1400201a0 TlsSetValue
0x1400201a8 TlsFree
0x1400201b0 FreeLibrary
0x1400201b8 GetProcAddress
0x1400201c0 LoadLibraryExW
0x1400201c8 GetStdHandle
0x1400201d0 WriteFile
0x1400201d8 GetModuleFileNameW
0x1400201e0 MultiByteToWideChar
0x1400201e8 WideCharToMultiByte
0x1400201f0 ExitProcess
0x1400201f8 GetModuleHandleExW
0x140020200 GetACP
0x140020208 FindClose
0x140020210 FindFirstFileExW
0x140020218 FindNextFileW
0x140020220 IsValidCodePage
0x140020228 GetOEMCP
0x140020230 GetCPInfo
0x140020238 GetCommandLineA
0x140020240 GetCommandLineW
0x140020248 GetEnvironmentStringsW
0x140020250 FreeEnvironmentStringsW
0x140020258 SetStdHandle
0x140020260 GetFileType
0x140020268 GetStringTypeW
0x140020270 RaiseException
Library USER32.dll:
0x140020290 FillRect
0x140020298 InternalGetWindowText
0x1400202a0 SendIMEMessageExA
0x1400202a8 EnumChildWindows
0x1400202b0 SetActiveWindow
0x1400202b8 SetPropW
Library ole32.dll:
0x1400202c8 FmtIdToPropStgName
0x1400202e0 OleCreateFromFile
0x1400202e8 ObjectStublessClient19
0x1400202f0 WriteClassStg
Library GDI32.dll:
0x140020000 GetRgnBox
0x140020008 D3DKMTCreateOutputDupl
0x140020018 GetRegionData
0x140020020 GetMetaFileBitsEx
Library SHELL32.dll:
0x140020280 None

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.gfids
@.rsrc
@.reloc
AWAVAUATVWUSH
8[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
t$(tiD
P<wkD!
'7'LH)
H9~(sGH
H9N0s9
[]_^A\A]A^A_
;^`t7H
AWAVAUATVWUSH
[]_^A\A]A^A_
AVVWUSH
[]_^A^
AWAVATVWUSH
0[]_^A\A^A_
AVVWSH
([_^A^
yet==Y
AWAVAUATVWUSH
D$h;HlL
D$ n+a4L
[]_^A\A]A^A_
AWAVAUATVWUSH
([]_^A\A]A^A_
AWAVAUATVWUSH
H[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
x[]_^A\A]A^A_
AWAVAUATVWUSH
h[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
D$l$G{)
D$hWj*
x[]_^A\A]A^A_
AWAVAUATVWUSH
D$ H!l=
~X)[j<|{A
D$(neY
[]_^A\A]A^A_
AWAVAUATVWSH
A;Gl}6A
[_^A\A]A^A_
AWAVVWSH
`[_^A^A_
AWAVAUATVWUSH
D$(4:`5H
[]_^A\A]A^A_
AWAVAUATVWUSH
;Ght+L
x[]_^A\A]A^A_
AWAVAUATVWUSH
D$X.i&
D$ GiH
[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
D$P;xD~S
L$P;AHucA
h[]_^A\A]A^A_
AVVWSH
8[_^A^
AWAVAUATVWUSH
G A;EH
D$ Vi)
G|A;E4t
G|A;E4t?H
G|A;E4u
h[]_^A\A]A^A_
AWAVAUATVWUSH
D$ ugY
[]_^A\A]A^A_
AWAVAUATVWUSH
D$(\S;
D$0]R2.H
D$8EHI H
D$0Y]a%H
[]_^A\A]A^A_
AWAVAUATVWUSH
D$hWj*
D$ tp[!
;J(|01
[]_^A\A]A^A_
AWAVAUATVWUSH
D$8.6M
/;.};H
[]_^A\A]A^A_
AWAVAUATVWUSH
D$ 1!Y
[]_^A\A]A^A_
_H;u!
AWAVAUATVWUSH
D$(zK
D$pWj*
[]_^A\A]A^A_
AWAVAUATVWUSH
D$L/j,
h[]_^A\A]A^A_
AWAVAUATVWUSH
X[]_^A\A]A^A_
AWAVAUATVWUSH
([]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
D$(uCG#H
D$ ~Ve
x[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
D$ AE#
x[]_^A\A]A^A_
AWAVAUATVWUSH
[]_^A\A]A^A_
AWAVAUATVWUSH
D$0YU
D$ GJ#
(;+}!D
D$p;8|#H
D$p;8}
x[]_^A\A]A^A_
AWAVATVWUSH
D$ EB^?A
`[]_^A\A^A_
AWAVAUATVWUSH
D$('Ag.H
[]_^A\A]A^A_
AWAVAUATVWUSH
D$D/j,
D$ m{0=
h[]_^A\A]A^A_
AWAVAUATVWUSH
([]_^A\A]A^A_
AWAVAUATVWSH
P[_^A\A]A^A_
AWAVAUATVWUSH
D$ +;F6
[]_^A\A]A^A_
AWAVAUATVWUSH
([]_^A\A]A^A_
AWAVATVWUSH
[]_^A\A^A_
AWAVAUATVWUSH
D$PY'h
D$@OU$7H
[]_^A\A]A^A_
AVVWSH
([_^A^
AWAVAUATVWUSH
D$hm=]$
D$@)d~
[]_^A\A]A^A_
AWAVAUATVWUSH
l$p|K9
D$8<n
D$HH&e
[]_^A\A]A^A_
AWAVAUATVWUSH
D$HC,e
D$l/j,
[]_^A\A]A^A_
AWAVAUATVWUSH
D$0|g;
[]_^A\A]A^A_
AWAVAUATVWUSH
A;D$ t`
x[]_^A\A]A^A_
AWAVAUATVWUSH
9pJV;|bA
D$ [6|0
D$TWj*
[]_^A\A]A^A_
AVVWSH
H[_^A^
AWAVAUATVWUSH
l$,HcD$,H
[]_^A\A]A^A_
AWAVAUATVWUSH
L$":L$#
d$<HcL$<H
[]_^A\A]A^A_
AWAVAUATVWUSH
D$HHcI<H
x[]_^A\A]A^A_
AWAVAUATVWUSH
L$xH+H
[]_^A\A]A^A_
AWAVAUATVWUSH
HcL$0H
HcD$4H
h[]_^A\A]A^A_
A=Wp;+~.=Xp;+tF=]C
H3E H3E
WATAUAVAWH
A_A^A]A\_
ffffff
WATAUAVAWH
A_A^A]A\_
fD9!u7A
UVWAVAWH
0A_A^_^]
WAVAWH
fA96tdH
fA94nu
0A_A^_
u3HcH<H
x ATAVAWH
A_A^A\
WATAUAVAWH
r\H9+t
A_A^A]A\_
UVWATAUAVAWH
fA9<Bu
fC9<hu
A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
u.H9>uBA
\$ UVWAVAWH
A_A^_^]
f9|$^t&f
f9|$`t
UVWATAUAVAWH
L$&8\$&t.8Y
@A_A^A]A\_^]
fD9t$b
@UATAUAVAWH
e0A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
\$ VWATAUAWH
D!l$x@
@A_A]A\_^
D82u&H
D8t$Ht
l$ WAVAWH
A_A^_
AUAVAWH
t$ fff
A_A^A]
@UATAUAVAWH
H!T$0D
uf!T$(H!T$
A_A^A]A\]
L$ VWAVH
UVWATAUAVAWH
pA_A^A]A\_^]
VWATAVAW
A_A^A\_^
ATAVAWH
A_A^A\
\$ UVWATAUAVAWH
H!D$ E
PA_A^A]A\_^]
ffffff
fffffff
USVWAVH
A^_^[]
LcA<E3
!1f"z>
_+ljvp6
uM4go;
\}z} [@
zZ*Ra'
X1c#G!
dank(Nu
U"k7:
Mw3&m8Qr//
n;7);/
c^,mOUu
c.0,3t
}aoPYM
ag`= #w
tAbG%>v
}=0+A{
;!Ps<5$#
o\I}m99
"m}*wA
[pL8{!
p_G|J"
}npcse
r6wtV@/"
L}C19y
FZm*I~1
3zA .>
kn[C5i
sEvSVx
~RrpS/
trF\i2/2
)?lds
Cz4On|i
r}&$of
}Pu@2}
2%|TVEV
BD@8$q
il`!~B
JcLjz&
^$3*>{
2R,!zn
",[+go
%|pjm/
pMy#YZhh<
.reloc
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
.text$mn
.text$mn$00
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.pdata
.gfids$y
.rsrc$01
.rsrc$02
jyhsyr22458qs.exe
VirtualFree
VirtualAlloc
HeapAlloc
GetProcessHeap
HeapReAlloc
HeapFree
HeapSize
CreateTapePartition
InterlockedFlushSList
CreateFileMappingW
LoadLibraryA
VirtualProtect
KERNEL32.dll
SetPropW
InternalGetWindowText
SendIMEMessageExA
EnumChildWindows
SetActiveWindow
FillRect
USER32.dll
WriteClassStg
FmtIdToPropStgName
NdrProxyForwardingFunction30
OleCreatePropertyFrameIndirectExt
OleCreateFromFile
ObjectStublessClient19
ole32.dll
GetRegionData
D3DKMTGetSharedResourceAdapterLuid
D3DKMTCreateOutputDupl
GetRgnBox
GetMetaFileBitsEx
GDI32.dll
SHELL32.dll
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
GetStdHandle
WriteFile
GetModuleFileNameW
MultiByteToWideChar
WideCharToMultiByte
ExitProcess
GetModuleHandleExW
GetACP
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
LCMapStringW
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetFilePointerEx
CloseHandle
CreateFileW
WriteConsoleW
RaiseException
-$e$/f
umPNeVY
.C<5xh
AMmCd.
Z_?(IJL
.kVuFF7
Dn4"fx0
o5e*\7}
-:HM'2yo
'/C0p
VDbqtY
:*i[72
2f'r,$
(_9)en%
;L}vk+
"_jcft
89SxU3^1*#re
L(6[G.
+~ }v|
'yyS/F
q$=hA1
O6gpDG
$?|MIV<"
%BB|Gf8
pnDxCK
:mrJjA
n^K;RzI)]
$3F5U&
v#H'i6a
zV,eyz8
#9\w0d9
aO4\M
5hPL(Tp9
WUPIitY
nPk994
m;O5R`
.-RW54gt+D
HQo7]oYj
*zFCB5
&)bh(L
WCS)0:
\!OxQ(^
W|U\Ws
@{TE6@
/4yK0"yZ
=8uOq`#
O$;1u%
k[D#tz
.o4jJ<#I
U"\r.w
kf7bIE.
+S~XU}
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
advapi32
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
mscoree.dll
((((( H
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Go to end
Ingnore
Process
Blocked1
Reality
Activate
nikolay
daniil
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.a062400119a4a2b8
CAT-QuickHeal Clean
Qihoo-360 Clean
ALYac Clean
Cylance Clean
VIPRE Clean
AegisLab Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.dde99b
Arcabit Clean
BitDefenderTheta Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Avast FileRepMalware
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
TACHYON Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.Dropper.dh
CMC Clean
Emsisoft Clean
SentinelOne Clean
Jiangmin Clean
Webroot W32.Malware.Gen
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Casdet!rfn
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!A062400119A4
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
eGambit Clean
Fortinet Clean
AVG FileRepMalware
Paloalto Clean
CrowdStrike win/malicious_confidence_70% (W)
MaxSecure Clean
No IRMA results available.