Static | ZeroBOX

PE Compile Time

2021-04-28 17:35:42

PE Imphash

e6becf7802a396786410aa1dfb3fcbe6

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.code 0x00001000 0x0005c104 0x0005c200 5.98981723656
.data 0x0005e000 0x00000040 0x00000200 0.601213505749
.data 0x0005f000 0x00001000 0x00000200 0.0
.rdata 0x00060000 0x00016298 0x00016400 0.887761505743
.rdata 0x00077000 0x00000594 0x00000600 4.03748526207
.yqvd 0x00078000 0x00004000 0x00004000 2.77240209471
0x0007c000 0x00001168 0x00001200 1.29530118732
.rsrc 0x0007e000 0x00001490 0x00001600 4.19319773419

Resources

Name Offset Size Language Sub-language File type
RT_MENU 0x0007f064 0x00000258 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MENU 0x0007f064 0x00000258 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MENU 0x0007f064 0x00000258 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MENU 0x0007f064 0x00000258 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MENU 0x0007f064 0x00000258 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ACCELERATOR 0x0007f2bc 0x000000d0 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x0007f474 0x0000001a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x0007f474 0x0000001a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x0007f474 0x0000001a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x0007f474 0x0000001a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x0007f474 0x0000001a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x0007f474 0x0000001a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x0007f474 0x0000001a LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library kernel32.dll:
0x477028 LoadLibraryA
0x47702c VirtualAlloc
0x477030 VirtualProtect
0x477034 GetProcAddress
0x477038 lstrcmpA
0x47703c lstrlenA
0x477040 SetLastError
0x477044 lstrcatA
Library user32.dll:
0x477084 CheckMenuItem
0x477088 CheckMenuRadioItem
0x47708c CheckDlgButton
0x477090 CheckRadioButton
Library ole32.dll:
Library msimg32.dll:
0x47704c GradientFill
Library oledlg.dll:
0x47706c OleUIPromptUserW
Library advapi32.dll:
Library shell32.dll:
Library winspool.drv:
0x4770a8 SetPrinterDataExA
Library gdiplus.dll:
Library gdi32.dll:
0x477018 SelectClipRgn
Library shlwapi.dll:
0x47707c UrlIsNoHistoryA
Library oleaut32.dll:
0x477064 VarI1FromDate
Library winmm.dll:
0x4770a0 mmTaskSignal
Library comdlg32.dll:
0x477010 GetFileTitleW
Library comctl32.dll:
Library version.dll:
0x477098 VerQueryValueA
Library oleacc.dll:

Exports

Ordinal Address Name
1 0x41a1b4 Main
!This program cannot be run in DOS mode.
`.data
@.data
.rdata
.rdata
PQRVW=
PQRVW=
PQRVW9
PQRVW;
PQRVW=Ju
PQRVW=
PQRVW9
@_^ZYX
PQRVW=Dm
PQRVW=
PQRVW9
PQRVW9
PQRVW=
PQRVW=
PQRVW;u
PQRVW;u
PQRVW=
PQRVW9
@_^ZYX
PQRVW;E
PQRVW9
AA "Q"
0T*.Q*
( T"o@
D(jQ P@
@D :A"
qP"XQ"
P*4P
U@ *Q
T jA*
( T ?U"
Q@("T"
aA "U"
*<U"BQ"
wU -E
"LT(CP
FE ZQ(vU
GD [P(wT
BA ^U(rQ
C@ _T(sP
VU JA(fE
WT K@(gD
RQ NE(bA
SP OD(c@
YD*MD*]D HD
D(yD*=D
|T*xT }T
D(YD ]D
D xD(hD(xD lD |D(lD(|D"hD"xD*hD*xD"lD"|D*lD*|D iD yD(iD(yD mD }D(mD(}D"iD"yD*iD*yD"mD"}D*mD*}D hD
,T"(T",T"<T
9T 9T(9T(=T")T
-T"-T*-T((T(
(D",D )D 9D
=D =D(=D*9D"-D
|D"<D(iD mD
T (T 8T
8T(8T ,T
,T(,T(<T
(D"8D"<D*,D
)D()D -D(-D
)D")D"9D
|T*|T }T
(D"<D*<D 9D()D
)D"9D*iD
9T(9T(=T")T
T ]T HT
8T",T*,T
mT ,T(
iD*9D (D
=T"iT*=T
D"]D HD
<D(,D(|D
,D"<D*,D*<D
iD -D(mD(=D*9D"-D
YT XT*
yT(hT"
@D"MD(LD
T(hT(,T"hT(hT
|D 8D(
|D )D yD
mD(-D"iD
D 8D((D(8D ,D <D"-D
-D*-D"-T
Q@ "Q*
( D jQ"
*T*GU
UU"FA"
*T*GU
2Q(P@
Q(P@ #Q
Q(P@ #Q
q@ "Q(
q@ "Q(
E*.@*`
*$P"dT
*$P"dT
Q @Q*@
Q @Q*@
(>P*$D(>P
.Q"@U(
Q*&E 
dT"lA*
.P"dQ"
QA #Q*
T*&D(,
$P*ZP
@@ +A*
@ "A"b
"nU*}U
;@ BQ"@
#E*>D"HA
$P*ZP
@*$@ 4@*$@
vT*&@*
vT*&@*
@@ +A*
GU*WU"
2T"fT*
@@ +A*
yA #Q*
@@ +A*
qA #Q*
@@ +A*
YA #Q*
1T :A"
9T :A"
E*.P*@Q
FU*_U
&@"LE"
@@ +A*
VU*}U"
"VA*wU*
"GE*}U*
*CE*]U
(WE*]U
@@ +A*
QA #Q*
(GQ*]U
WA*_U"
"RQ*wU
"WQ*WU
(BQ*}U
BA*wU
(SA*wU
(FU*]U
8D zQ"
&@"DA
*BE*uU
J@ +A*
FQ*UU
VT*wU
D :U
Q@ *Q"
1T"2U
<P *P*
cred.dll
0AaRo]
^^;A=U
RV@RU2
Ioz|tD
%$QsqE
#E4]lu
V+qY@.
{)0\k[
`-F`jr
7wf<g2
&Ok|S+
wNTI&9
|EJhD{
qxM/s/
B]0;\B
&evwpw
{I>*g1
}st?+%
DV,['(
KPWJSe
PMWN2L
1/9-Zj
o<#K**
Bt+PP)
6]w,z0
zC-@LK
$cOC<{
IRq1\d
wof94f
!);d%A
9KEyT3
?T%VLG
K7yPZ$
y!IW(}
lM7,Os
3B@Tmz
8bHK>x
TG0-9M
f2m8M0
]Xbe%N
\dcT!N
(6]JYh
F>-@@I
(D#`uZ
GetProcAddress
LoadLibraryA
lstrcatA
lstrcmpA
lstrlenA
SetLastError
VirtualAlloc
VirtualProtect
kernel32.dll
CheckDlgButton
CheckMenuItem
CheckMenuRadioItem
CheckRadioButton
user32.dll
CoQueryClientBlanket
ole32.dll
GradientFill
msimg32.dll
OleUIPromptUserW
oledlg.dll
LsaCreateTrustedDomainEx
advapi32.dll
SHGetDataFromIDListA
shell32.dll
SetPrinterDataExA
winspool.drv
GdipGetPropertyItemSize
gdiplus.dll
SelectClipRgn
gdi32.dll
UrlIsNoHistoryA
shlwapi.dll
VarI1FromDate
oleaut32.dll
mmTaskSignal
winmm.dll
GetFileTitleW
comdlg32.dll
ImageList_ReplaceIcon
comctl32.dll
VerQueryValueA
version.dll
CreateStdAccessibleObject
oleacc.dll
PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
Close @ll
Downlo
e ;orfz
refere3c
Remaib
SaveqOr
DonVti~n
ZelUkato
Madq 9[dona7
Close @ll
Downlo
e ;orfz
refere3c
Remaib
SaveqOr
DonVti~n
ZelUkato
Madq 9[dona7
Close @ll
Downlo
e ;orfz
refere3c
Remaib
SaveqOr
Close @ll
Downlo
e ;orfz
refere3c
Close @ll
Downlo
e ;orfz
refere3c
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.46205307
FireEye Generic.mg.31980c9b17f61c5f
CAT-QuickHeal Trojan.Multi
ALYac Trojan.GenericKD.46205307
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Trojan.GenericKD.46205307
K7GW Trojan ( 0057ba091 )
K7AntiVirus Trojan ( 0057ba091 )
BitDefenderTheta Gen:NN.ZedlaF.34686.EG4@aafyjdci
Cyren W32/Trojan.EYIZ-8004
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HKQJ
Baidu Clean
APEX Malicious
Avast Win32:Trojan-gen
ClamAV Clean
Alibaba Trojan:Win32/Kryptik.fad3bbe9
NANO-Antivirus Clean
ViRobot Clean
AegisLab Trojan.Multi.Generic.4!c
Tencent Clean
Ad-Aware Trojan.GenericKD.46205307
TACHYON Clean
Emsisoft Trojan.GenericKD.46205307 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos ML/PE-A + Mal/EncPk-APW
Ikarus Trojan.Win32.Krypt
Jiangmin Clean
Webroot Clean
Avira TR/Crypt.Agent.fzffo
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Win32.Trojan.Agent.GDLYU0
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!31980C9B17F6
MAX malware (ai score=100)
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0RE221
Rising Trojan.GenKryptik!8.AA55 (CLOUD)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Virus.Patched.OF
Fortinet W32/GenKryptik.FEQK!tr
AVG Win32:Trojan-gen
Paloalto generic.ml
Qihoo-360 Clean
No IRMA results available.