Static | ZeroBOX

PE Compile Time

2021-04-13 08:55:11

PE Imphash

d20e8b584b1e294911b88a699c987910

PEiD Signatures

Ste@lth PE 1.01 -> BGCorp

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000088ac 0x00008a00 5.5827144419
.rdata 0x0000a000 0x00000e67 0x00000a00 4.24112155096
.pdata 0x0000b000 0x00020542 0x0001e400 7.86800162035
.rsrc 0x0002c000 0x00000390 0x00000400 3.02156416239
.reloc 0x0002d000 0x000005f4 0x00000600 5.88071347499

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0002c060 0x0000032c LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library ADVAPI32.dll:
0x40a000 RegLoadAppKeyW
Library KERNEL32.dll:
0x40a018 LoadLibraryExA
0x40a01c CloseHandle
0x40a020 OutputDebugStringA
0x40a024 GetPriorityClass
0x40a028 LoadLibraryA
0x40a02c GetModuleHandleW
Library GDI32.dll:
0x40a00c OffsetClipRgn
Library USER32.dll:
0x40a034 EnumDisplayDevicesW
0x40a038 GetMenuState
0x40a03c TranslateMessage
0x40a040 DragDetect
Library WINTRUST.dll:

`.rdata
@.pdata
@.reloc
\$'2\$'
S+T$df
T$t+T$t
cX3W}Z
z^( Tp
W\}0\-
9/lZi`M|/
EcW7bRw
@tmRU{S
,UYP:?
O(iK+-$
O8jK/-$
]~tn7<dj
^~t"6\D~
[(qyjuI
GVZ[(Rz
L$h3L$h
|${:\${
L$[*L$[
D$<5<|r&
L$,9L$0
HA1stoppedwasTherevm
toappear.152scorpionChromeoccurChrome9uandR
xywere
IHuZ6other
charlieEopenedRopemuserI
LcomputationallyChromesameChromeztheofthecontrolled
6availableSIcycle1OriginallywhichportableI
Scottagainstseamlessly
BRsoatChromef
suggestionsRFlash
--s--pp----
Gsp.pdb
CloseEncryptedFileRaw
RegLoadAppKeyW
ADVAPI32.dll
GetPriorityClass
GetSystemDefaultUILanguage
GetModuleHandleW
LoadLibraryA
LoadLibraryExA
CloseHandle
OutputDebugStringA
KERNEL32.dll
OffsetClipRgn
GDI32.dll
DragDetect
EnumDisplayDevicesW
GetMenuState
TranslateMessage
USER32.dll
CryptCATAdminCalcHashFromFileHandle
WINTRUST.dll
Np^j@"7\0~
@"6<Dj
Hrz*ui
)ETj{^)
8\d)-h
9~msiE
Grzm5jG\n
Gaoy;
@9<>a,
8qLmaquu
\!?\d)0
Jwxfqy
`u,;ie
VOd.H_~
x@9$qB
C$_oW
7\d)-0
m)]e|;m
tF7\d"
tH7\d'
s"6(Dj
VZ[(rF
tn7\dj
jT"7[c
"6<djh
]jTn6<d
GRyjuI
>jsn6<0j
HqZjA5<
\>js"7(0
SAnI%#
S!nI&.
Q8|Ox:s
non*vB
}mMn^<
*.$\jG
o?dOa
-$4mc%J
BWF&!goS^7
QT&.$bzXg.
_KW["iJK
|(q!TO
-$bu^j
AX3pT3
K`6A=c
-$br`1
_Us`iK
,g:!|m
SKD1NN|(
U~@G$`^1
zw5(:[
Us8iK
l[SiBb
_LS^=HK
=lHAF1V
jH_K?d
`NnMgS
nRw](2#
nRw9(",
XpFdJ_LS
-$bzXg.
nRw%(zD
nRw%(ZD
!pS1(v
OC13c-%
hy3j-$
_Q<'7
YlRwQ(
;f-K@Md
3H2n9tS
obmTY^
`~nIGS
nRwI(:
_QT'7
Q }-$b
-H6-jIg
_Q'sDiK
#&(3[a
_UOsPiK
QXp-$d6
QH.-$d
Im{;@iK
iKVqH;(
iKVqHC
UdK=LK
x!wQ8=
[([c.
,Z"p!Xk
wlT_lV
AsndWl
,Z)-J]
`*ni>S
2SU]b=
Q0N-$Zj
Q ~-$b
^\=lTk
5H2n1(S
*<~vnq
NiK+-v,
_KSKC6
%bzXU.
^bE~$@
Sa7GfJ
%*WlLoL
_Sb77iK
jMWjW\
>Aal]Wj\
)ET!ZcQ
oQ(b}Vw
eKTQ;+M*
wQ4\jH
C?3g-$
QXq-$/
qblWU/
^cE}$p
"i37-$
X#8/`J
5$bw)}
-*ojAb
_UsTkK
|sgUs<kK
X8f/&:
YvlaGn
A-$\jH~
^Us@jK
,#boVY
/-$brX^.
_Q|bu#
-$\sHq?
^G{;~hJ
^Z=l\k
Q|'-$\jG
5*[3?K
_Us(kK
Q|J-$Z&
n_z|MNF|`
`*nm.S
O"qJOL
B`nU+S
K|hzlbO8d
Q<#-$\jH
-*gK@d
Q4"-$A
?W? 3F
p~j;+Vi
P6-jN'M
QT<1KWs
^Z=ltk
lBwf?U
,#br(}
sAsj2wj
-o{O/hJ
{GShJr,
9IKC4D
6c:z!U
Aa&AB]
6x:@!U
G*D*Oo
QnuT6(:
_Q(by^j
AOlVcd
1*T1LZ
nfJ_MS
?hKSI1
Q<w,#A
o?dOa
#;?{>$
!foS^7
j,#bo,
Wx#+*=
WLI}+F
3MrjPh?
x# }|
+XXP)"
iKJ&+T
self.ex
7)838=8
7$7D7g7
2T8Z8`8f8l8r8x8~8
$7(7,74787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8L8T8X8\8d8h8l8p8t8x8|8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
: :$:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
; ;$;(;,;0;4;8;<;@;D;L;P;T;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<|<
=$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>D>H>L>T>X>\>`>d>h>l>p>t>x>|>
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,10141<1@1D1L1P1T1X1\1`1d1h1l1p1t1x1|1
VGoogletosharleyxM
v42,uthetoaustinbFRtab
VdisableQlCTheS
acompromiseyZorxcomplete4
This5jreleasedityears.resultsremoved.d
butas7thevDthe1BX
MwiththeO
JWstable
sJdDeveloperNPresults
inSettings2018,a9rOnwbrowsersalso
DevSUpdate0teamatuXQ
plannedonce2014rbeCCYallowingx
open(callednewWlTto
2012,Lsite3and
QfreeFyckhIG
hebroncosGoogle
BhomehSinceGMay(thenJand
versionslessRG
UPPAPIRPhilippandfinputs102forChromeb
HlaunchOdyftcan
bookmarkstoYthemes,preferences,Lights
1y38W916As
gpmgpmgpm.dll
VS_VERSION_INFO
StringFileInfo
000004b0
CompanyName
Oracle Corporation
FileDescription
Java(TM) Platform SE binary
FileVersion
1.3.6923.00
Full Version
1.3.6_000-b00
InternalName
LegalCopyright
Copyright
OriginalFilename
ofl.dll
ProductName
Ofll(EH) Watgevae KT 8
ProductVersion
1.3.6923.00
VarFileInfo
Translation
No antivirus signatures available.
No IRMA results available.