Static | ZeroBOX

PE Compile Time

2021-06-17 15:37:22

PE Imphash

db502765cff159e5db66145a73cb6cd7

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00001792 0x00001600 6.12712886743
.data 0x00003000 0x00042599 0x00042600 6.40918747224
.rdata 0x00046000 0x000003dc 0x00000400 4.82692747493
.bss 0x00047000 0x000003b0 0x00000000 0.0
.edata 0x00048000 0x00000f1b 0x00000200 1.96234534599
.idata 0x00049000 0x00000a9b 0x00000600 4.15872715085
.CRT 0x0004a000 0x000001d7 0x00000200 0.201539378135
.tls 0x0004b000 0x00000008 0x00000200 0.0
.reloc 0x0004c000 0x00000534 0x00000600 5.85837125388

Imports

Library KERNEL32.dll:
0x6bb090ec CreateThread
0x6bb090f0 DeleteCriticalSection
0x6bb090f4 EnterCriticalSection
0x6bb090f8 GetCurrentProcess
0x6bb090fc GetCurrentProcessId
0x6bb09100 GetCurrentThreadId
0x6bb09104 GetLastError
0x6bb0910c GetTickCount
0x6bb09114 LeaveCriticalSection
0x6bb09120 Sleep
0x6bb09124 TerminateProcess
0x6bb09128 TlsGetValue
0x6bb09130 VirtualAlloc
0x6bb09134 VirtualProtect
0x6bb09138 VirtualQuery
Library msvcrt.dll:
0x6bb09140 _amsg_exit
0x6bb09144 _initterm
0x6bb09148 _iob
0x6bb0914c _lock
0x6bb09150 _unlock
0x6bb09154 abort
0x6bb09158 calloc
0x6bb0915c free
0x6bb09160 fwrite
0x6bb09164 malloc
0x6bb09168 realloc
0x6bb0916c strlen
0x6bb09170 strncmp
0x6bb09174 vfprintf
Library USER32.dll:
0x6bb0917c PeekMessageA
0x6bb09180 PostThreadMessageA

Exports

Ordinal Address Name
1 0x6bac15a2 DllGetClassObject
2 0x6bac1547 DllMain
3 0x6bac159c DllRegisterServer
4 0x6bac159f DllUnregisterServer
5 0x6bac15af StartW
!This program cannot be run in DOS mode.
P`.data
.rdata
0@.bss
.edata
0@.idata
.reloc
kMZucV
kMZucV
6{|-*O
V#KA2!
<7{|-%
zs<^zs(Yz
iKiViKyViK}Vm{u
=E`mKE
A*iKYQ
mK}_iKeV
S=#|^l
iKqVoKu
SKgViKunD
iWg3)Y
iKiViK!V
}_iKmV
mKy_iKiV
'%CVoK
SF5$SFSo
#%CVoK
#%CVoK
_z6iKaV
&mKy=#
=^Po;ea
-{|-&z
UmKyV"
zViKan
R[>ToK)VoCIWo[ET
R[>ToK)VoCIWo[ETiKQV
esy]XD
.esuR.
oC}`o
YCC4eCC5kCC6|CC7`CC0kCC1bCC2=CC3<CC<
CC8BCC9aCC:oCC;jCC
CCTXCCUgCCV|CCWzCCP{CCQoCCRbCCSOCC\bCC]bCC^aCC_mCCX
CC$XCC%gCC&|CC'zCC {CC!oCC"bCC#^CC,|CC-aCC.zCC/kCC(mCC)zCC*
iKYVoCyWo[
i[5ToKyVoC
R[>ToK)VoCIWo[ET
R[>ToK)VoCIWo[ETiKQV
esy]XD
.esuR.
i"#Ky&
6{|-#z
-{|-&d
-{|-&d
oSi5>-
\5<-_5<
]5:-\5:
_5=-[5=
]5=-_5<
]5=-_5<
_mKy=#
^z4o[eW
^z4o[}W
mKy=#z
C0Yz6oK]
eSF5$SFSo
%SF5$SF
iWiKyV
}5-5|s
ViKuViKyViK
ViKqViK}V
WnriKyV
5$SFSo
i56=LQ
iK}VoK
'=EF'd
R%5%OE7
5$QFSo
==rh5$Q
oCu=%s
zYoKyX
iKiViK
ViK-Vi
iK-ViKiVo
iK-ViK
iKiViK
ViK-Vi
{aVoK}
iK!ViKQV
(iKaViK!Vi{a
5$QFSo
oCq=%s
oCq5?M
zViKIV
Ka5?Ml
=WDiFz
zViHuV
mSMHmSa
zViKIV
zViKIV
=5ru5$NF
=#rp5$QFPo
zViK)ViKIViK9Vi
ViKuVo
ViKeVo
FViKuV
zViKuVo
zViK)ViKIViK9Vi
s8%D-4
=LGiKI
ViKiVo
n<iK9Vo
=LGiKi
iKiVo
o[e=4r
_mK]5$
SF5$SF
z['=E['
z['=E['
=zAmsa5?7
=%|n5$SF
LmCy=2x
9mK}\mN
{9mC}x
['=E['
oLy<'z
=2|m5$Q
['=E['
mKe5-3
Q[@cF_
m{a5$7=
iKmVoK
WiK}ViKml
z_msyU
$-M=,{
oKe="z
mC}`o{}`
=^EmSy
gym[q=.z
z_mKe=#
de56Vr
de56Vr
mKq='zQ
]oCy5)
3W%wr
3W%wr
z_oCy5)
_mKe=#z
]oCy5)
iKmVoK
_mKy="z
="{$5$Q
iPo;='
m{y="{
5CrU%~
oKmEi2
_mKi="z
_mKy='z
mSy=/x
Ui[qTi[YTi[
iKmVoK
4NmO5tCy
Xw])3I
4g,+1a6
EoxC%/
J$/#c
<rP.=/e
K{P4Ze
5/2r!7K
Bu[9rU
.:t_ j
NmO5E`F;Xw])SzT'bYk
W:1#}1<*s,+1a'&8osk
>=?u341~$/#c)&-h
DVuO-[|A&LgS;An]0bQw
.=/e'3$h<!9
Bu[9K{P4PiM#YgF.
^}_5PvR<BkE'L`H.fQk
.%7} .:t23-o<8 f
:O93F#
%MvS0E
_6z!K
4w<,4+<h4
3@;=3/;
>B66>^6D>,6J>26X>
4{<N5>=:5p=z1*9
6B>)6P>[6
4H<14^<S48<
2K:02::~2
3S;I32;c3
6E>.6S>G6>>Z6
7@?=7=?e7
3Q;R3:;
1\9]1;9
;)3W;=3j;
9`179'1d9
6&>L60>
7C?47X?
>i6'>46Y>
5M=35t=
:@2=:,2K:
;O3T;23
7@?.7V?<7,?U7
=5{=*5R=85 =S5
?c7"?%7w?
2&:Q2R:
6v>#6,>a6
3c;3R;N36;X3
0F8U0>8n0
1m9t1u7/?
6!?L7)?T71?\79?d7
4y<$4A<,4I<44Q<<4Y<D4!<L4)<T41<\49<d4
0i8L0:8x0
8\0H860
9n19U1h9
6r>"6,>]6
0f8%0N8;0.8P0
951R9E189m1
?z7(?%7N?
5%=U5@=
?*7R?87s?
2F:*2a:
;v3";[3I;
1+9X1Y9
6b> 6I>16
7J?<7+?o7
1E6]=85e=
8N018.0X8
9u129/1`9
7}?07(?Z7
5F=356=
2@:821:o2
:x36;%3];E0
7j?%76?S7>?[7
<0'8R0
2a: 28:h2I9
<w4E<?4d<
=I52=Z5L=65m=
:Y2G:)2W:
8v098.0U8
4B<.4^<F44<^4
5B=(5V=>5,=K5
6M<74^<
8F0L820
;r3;C3<;o0
8F088 0Y8
9T129/1W9
6y>!6U>Q6
7E?<7;?
5a=%5A=(5W=?5$=B5)=P58=d5
2O:N25:h2
5c=&5J=
8%038g0
1e91D9
<u4%<M4;<
=V5A=65b=
:Q2A:k09880y8
>T69>l7
8x0%8@0-8H058
9M169/1q9
?k4B=55
:r2+;\3
68>#6j>
<E4?<<4
7z?"7W?i7
3F;(3 ;U39;a3
8*0,8Y0
?t74??7
3B;*3Q;;3';W3
:N2*:[2A:.2U:
8x0"8.0
;{38;#3U;?3u;
>$6V>h6
4y<J43<
=|5%=O5^=
<x4%<@4-<H45<P4=<X4E< 4M<(4U<04]<84e<
3u;3B;53X;B3
3};!3(;V3
;k3'8O018`0c6
>z6,>/6W>
?T72?#7W?
< 4N<?4c<
8D0"8S0G8
9x1"9,1J9;1o9
6B>864>
4n<$4P<
3|;!3T;
2;:02[:
1t971>9
53,;I34;Q3<;Y3
7D?!7L?)7T?17\?970?]78?a7
3h;534;u3
0t850(8U0
1x9%1$9Y1
>l6!>L6M>
<H45<(4U<
6H<14X<A4(<Q48<a4
5x=55\=
;L3);T31;\39;$3A;,3I;43Q;<3Y;
Mingw-w64 runtime failure:
Address %p has no image-section
VirtualQuery failed for %d bytes at address %p
VirtualProtect failed with code 0x%x
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
GCC: (GNU) 8.3-win32 20190909
temp.dll
DllGetClassObject
DllMain
DllRegisterServer
DllUnregisterServer
StartW
CreateThread
DeleteCriticalSection
EnterCriticalSection
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetLastError
GetSystemTimeAsFileTime
GetTickCount
InitializeCriticalSection
LeaveCriticalSection
QueryPerformanceCounter
SetUnhandledExceptionFilter
TerminateProcess
TlsGetValue
UnhandledExceptionFilter
VirtualAlloc
VirtualProtect
VirtualQuery
_amsg_exit
_initterm
_unlock
calloc
fwrite
malloc
realloc
strlen
strncmp
vfprintf
PeekMessageA
PostThreadMessageA
KERNEL32.dll
msvcrt.dll
USER32.dll
000D0Y0f0q0
1<1c1n1x1
575g5w5
576V6k6
7"787V7k7|7
8 8(818;8A8J8[8
:/:O:p:
;2;V;h;m;r;};
<)<1<=<B<S<d<
=/=5=@=F=R=b=z=
>$>)>/><>B>e>
?A?J?T?s?}?
0%1/1>1I1N1T1
152>2J2e2o2~2
4044484<4
>.>7>Z>}>
`0o0}0
12272Z2p2
3#3=3Z3
=A>V>_>h>q>
0&0=0R0g0
1/1T1y1
3(353C3O3`3~3
4S5h5q5
6C6W6i6{6
95:i:r:
7=7P7U7s7
708Z8m8
1O1a1u1
2_7y;l=
0 1<1h1
1(2T2p2
4,5P5`5|5
646X6h6
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Trojan.Heur.rK4@InjxnMe
FireEye Generic.mg.928163504cf073fe
CAT-QuickHeal Clean
ALYac Gen:Trojan.Heur.rK4@InjxnMe
Cylance Clean
VIPRE Clean
AegisLab Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Riskware ( 0049f6ae1 )
BitDefender Gen:Trojan.Heur.rK4@InjxnMe
K7GW Riskware ( 0049f6ae1 )
CrowdStrike win/malicious_confidence_80% (D)
Baidu Clean
Cyren Clean
Symantec Backdoor.Cobalt!gm1
ESET-NOD32 a variant of Win32/RiskWare.CobaltStrike.Artifact.D.gen
APEX Malicious
Avast Clean
ClamAV Win.Countermeasure.LoaderWinGeneric-9804845-2
Kaspersky HEUR:Trojan.Win64.Cobalt.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Ad-Aware Gen:Trojan.Heur.rK4@InjxnMe
Emsisoft Gen:Trojan.Heur.rK4@InjxnMe (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Trojan.Win32.LOADER.SM
McAfee-GW-Edition Injector-FEY.c!928163504CF0
CMC Clean
Sophos ATK/Cobalt-W
SentinelOne Static AI - Suspicious PE
GData Gen:Trojan.Heur.rK4@InjxnMe
Jiangmin Clean
Webroot Clean
Avira TR/Crypt.XDR.Gen
MAX malware (ai score=87)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Injector-FEY.c!928163504CF0
TACHYON Clean
VBA32 BScope.Trojan.Swrort
Malwarebytes Trojan.Loader.Feye.Generic
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.LOADER.SM
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta AI:Packer.395B7C391B
Paloalto Clean
Qihoo-360 Clean
No IRMA results available.