Static | ZeroBOX

PE Compile Time

2021-06-08 19:28:38

PE Imphash

a3ccd95ee9050e5b7d3c82f6dcef8a19

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000dc116 0x00000000 0.0
.rdata 0x000de000 0x000304c0 0x00000000 0.0
.data 0x0010f000 0x000089d0 0x00000000 0.0
.vmp0 0x00118000 0x000173b0 0x00000000 0.0
.vmp1 0x00130000 0x000b4f5c 0x000b5000 7.94807053026
.reloc 0x001e5000 0x000000d8 0x00000200 2.50170011666

Imports

Library KERNEL32.dll:
0x5b605f HeapAlloc
Library USER32.dll:
0x5b6067 MessageBoxW
Library ADVAPI32.dll:
0x5b606f RegOpenKeyExW
Library SHELL32.dll:
0x5b6077 SHGetFolderPathA
Library ole32.dll:
0x5b607f OleRun
Library OLEAUT32.dll:
0x5b6087 GetErrorInfo
Library WS2_32.dll:
0x5b608f WSAStartup
Library SHLWAPI.dll:
0x5b6097 PathFileExistsW
Library WINHTTP.dll:
0x5b609f WinHttpCloseHandle
Library QUARTZ.dll:
0x5b60a7 AMGetErrorTextW
Library KERNEL32.dll:
0x5b60af LoadLibraryA
0x5b60b3 VirtualProtect
0x5b60b7 GetModuleFileNameA
0x5b60bb ExitProcess
Library USER32.dll:
0x5b60c3 MessageBoxA

!This program cannot be run in DOS mode.
5Richz
`.rdata
@.data
.reloc
ADVAPI32.dll
E)QM55
WINHTTP.dll
MessageBoxW
iNQUARTZ.dll
D$$huB
D$$`h(d)
USER32.dll
YtVkI.
VirtualProtect
The procedure entry point %s could not be located in the dynamic link library %s
AbKlXyu}
s#m!~H
J!5eOj
&.ebS$
s$dW,e>
52!Ikp
QR~raU.c
aiJ1:y
VlH~-t
_N\QZ@}
V@s`Ff
@HEj?s7
e*axY,
*^}J80
s@ot]b
VTZbV&{
e\6&Rl
0b(h^V
^jlB#o
k,%+MLV
K3KIMK
}+cd.*
hM3!X2x
UYh9U5
YYYzLo
Vn(&0M
#9,7T6
gCJ<dg
O9qh-~
u>~7|u
ts"9.v
6sBfjp
G65vnp
k([ [p V/
1o=h2VZ
=Zp~zM
ppDh16
TsCr'=
q=4n.\
^^?1'T
y)Y#cU&
YS2ExY
YUz\Ne
z r/=y
1TLqdS
H.p+3U
VtzB(7y;+
?G.+{-
>FO+|K
pt@#1[
I$9[G~&d
1u#\-G
ETuQJ?
i]8@pSZ
$:w^]1
*~\'AT
Un)5A$
#$XowJ
dh)U6&
j*)QI2
V6DXNk
<*Qkp2
r?Im(
6V?UJ
s-"]S[
z}}'Dd5V
Xr"}T
%~5}Lp
R."iV_B
Ig*-(
R'T*^b
T?`Ywt
u`G#_Q
TL,= E
&zcYK<WO<
SL3`RX
XO)l35
<ev3z_
',t_aS
Ot=ZmK
am&_lp
Y&ud1!
u'dsNT
%ABa.,
f_ZeB+
-ss@kx
%s~c3,
LXisbP%
?&+]=6
V@40>*"j
379sj
5IhY27
hg|&wt5
U?7.(x
c)nqj)
{TkIydjR
yXK2sb
4RTXHk{)
rI(3$D
e- 79W
SdLG=e
C.OSV
9id,w
fZLV0%
oR=V]
Ts@o$fg
i_9#gE0
avQzn\}UM
T$}?xa
Jmje0e
:BX+*e
MZKa-'5"lQ
_Jr2z
K2@h,G
<rXjek
KJYHt>
r;k\yS
f+Xb\KHV
L!r{(}
)Ie,4
`2J1"mB?}%
2/&"LyH
$mq"#M
u3*%\\Y$
B}3B{~
>Gm#|[>
Q3*?Ky
s(2g/D
~D2iH:k
9svay1i
>9eI>s
wCLMok
yp"35
^jXv3(S
lJ QY"My
'>_q9sV^
DOK'T^
{_m@oU
\{YyMi
+SMrk4Jh
s#kM,!
IWw?(V
3o4Vy<^
Q~u,{>
I6Q7UI
JS}g:~
:RtS{t
Z*V;(?
lsAJk*
(_Z$)3%8o
a3cH>Dk
58j"mT
;j.*$m
Yt"A2-
ul=+=
M}dp'~TK
z>xZAEjPu
4l+~ml>|
f6`3`Aj
UHB3ty
T9!dK:"
cy;6~s
G>QAPu
,)t*I2
"k+k2uN:
M.^.HzE
+s"(Tg
Ot=!*\{
5OB4Y4
sPAUvm9
!T^kBJ
TZR6fo?0
,Xs{H!
MoHO>+
oBtSk2
DT>sg^ml>w
I_BKIZb
>;yd;1
SQ6IF9
41z~w]
Ndg^iU
B*r2x:
!#~Z|j
!h-uo$
+6QnN4
7df9o](
(Wo3HR
+ir}X
FDgL\
}vMD]e
U+DIo_
\9^jguA.
<XVu$,
VL!89$
!lx$gu2
YG;pDCW
Qo>gYv
_lCgr+
1leuR.
YSzFU6
5Ky~|o
)[Rk|~
4'TThs
b`Z2pA
[oL}Gt
1Rs^*z
Mlqq]b
5/QUsE
j4'>!R
J}0n~O
!W$,a~
ER;Jtj
$I5Ct~z
s#i,}G
}~mBgl
+h?$*H`
o[G#du
URp>|2
DUjO>Tt
s oeT#l
Smn#D6
zH0Yc%I
nzRRnU
1ve2MA
_l 6m*
XR_opSI
&J4yQo
].\!DK
<zT{``.
:Q^llo{
tdlsjr
^udlR
c3l:XR
z(h$".
4&%ETd
wpM43i
-zek&b7`[
DKB oRFY
,zs*Gs
ykEe("
XQOa}"
n;B<li
(v$|.J
&-V'aY"
$+n:O3
~Ji)3^
Ux|Z:`
s6h;ts
+L#23#
J&!Jk&
h@DC$*
9eRutw
<]!<<_
~`@`>y=
yA2j(-
Yt%z.L.
.h_5Y.6
#%1"pX
OUZ]zo
'Ijdlg
o]"~|'
)3)G}v
2NSS(m
].?*Ww
Yz2xIr
&]/N;+N
X#)AN8
j[|ZAa(1
/PTPJ,
sRV>_#
Bzr~[2ajS
vJ.~(4E
lt9zLc>|
BorZ5+
qlpUxsRj
tC4Hsl
:&`_<?r}
<sq>ooM
s+@D^+
M>T{occ
'CndhT
mf>H_
yjy^H+
a*Mv(^
<K.O#T4
&? 6&D
UrL#w]=T
}QYvhR@
ZVsw1-
(2,z.R
{L=~?
bUWb!k
zV2`,[
9zuGxa:
~U|iPjPh
lyWpL2
k28UXI
*a_'7_
ikX_DG
MT C}d
b>p;qj
C(sL:
%y!~9&
>lG8x?q
YQILx
i"*xWOz
Qiq>yd`
Jr5"e(
|t(4t6
4Hz2G[
at.UIv
zYB(lN
]V*u_j
.n=j[$
BN&sr3
XIVx?/
%Rt#Z
i{~V7`
)Vo9bE
!VQ\w_
Fw62!j
(bnI1u
EKMZ=*$
S#$2k6
8NeXhx
N}Ac(V
>mZVo$e^
+3lC{9
ckZR?#:
t>r+j+
Du+g_n
-gZjG:
Qh,B}?
#|Nx~
_U`&;1
y*J''O
XI&6.]
xl.Q|b
SIR\p~
<)9cSR
[z(2[l
_KzFYu
zc*%H&
,1zI3h
pSj_qY
pH<_B|k3$
G?pM_a(
YEad,`J#Wed
u|nS"*
Q)5~jx
Q>(Ps$
#-CNaA
A2\s`S
velU\Y+
mm`l
uHYDZu
E6X._l
I&b}&+
IR)TGu>
mrqqJ)
!Ynk|O
=>4>QQ
#;te\T
'MZHK
2,up1
K$6c?Xc
*cKmXEb
q2IMl-
*T\aZ-!
EIr2sCm
O*@+mO
kpxU+F6l
_}eidi
+p%\bw
'U^VX1
#lD5*
ZR3j$}
^QZt*U
q&TQ&B'
rZh?j'T
r-|?L~
eQ9A~3
,M2?rJ
[Lxv:N
Qh>DOo
Hu#JjF
5?$X)*
:(l~zR
mh(vY
dWEW=A
z{[( H
tm9>-=
1EuUnS
>t(K:a
U@w/R!L
U%b0S"
hgr7)u
;)q^IO
k=QA/|
eV[7Um
k%|D?s
;Jnt]d
~Tsb'|~ar"&S
!TQ"Zj
t>qu'-
US>I6=
|0oj$-
im*f<A3`[
3JMO-I#
.aXlC
2'<e>mS
k=tT&r
7]s+hO
^a+zJP
H~%oden-/Bzr2
2.Et{>Y(
Q#l/mo
0{$F!}+
2{#l{Vj
uR4Gbm
t2R"z(
QzK(`J
G&ls6x
u)}m8R
z+r>L*6
'"i2> 4
s!*!d(z
$1ziaF/
k+'#I:
*chY7"{
0VH,FRKY
. ? MS{
oc(TcT
9K3hW;
JGc.K
f}79DB
)+iRkb\
~)z?TWeVh
(mT@~~
2+Kg$"b
#>M[X`
\}J(gD
|O4&yuzb~
dBGyZah9
(}4mZbL~M
Gj8+O)
A1LUi0'
dm~v+n
o4S=oR
F9q082
.vkm.F
hL2PCF
Rfjd]W
DqOba.RZ
:=kC^*
4L]A0c
)=VShJ
?Ly:nz
NB+|h~
jllePx
'p.T7R
K_w7_s/
aR=$i5Kv
6N,cphl
File corrupted!. This program has been manipulated and maybe
it's infected by a Virus or cracked. This file won't work anymore.
PathFileExistsW
b)W6Hb
zMY&Vw
hD$i"-
k,%fY.6
hPm`My_
2S`-k-
ahHCRuV
l7BcY}
KERNEL32.dll
Py|<dU :
0/hc\:EW
r>:2~
MessageBoxA
n6LkSg
SHLWAPI.dll
ole32.dll
xN3_"w
fKkwZu5g
hdLY{CzK=]u
!5][hEba
BZPJH(B
9MzpYM
DwFPUoX
}5JUSr
JLtYeH]
C{tM`R$
Fwv)I"
9_wOWA
0?z@V~"sqn
The ordinal %u could not be located in the dynamic link library %s
a/0:r|
AMGetErrorTextW
URT}]@
LoadLibraryA
e2ZN)m$
A)?w*8
vovx@mN
_Qb/Rn
MqB*o>0RO
2H=lyG
!|:[7W&
GDvT#]
]]%aim
hYxE`h$u^
=#}LR2
O9Z^*Jcf
DwAGVlp
E*lMlJ
:UN|"!
{VY*ON
RegOpenKeyExW
:ivo|YM
_x`jMK
WinHttpCloseHandle
WS2_32.dll
HeapAlloc
J\u[v/
kPrc7O
t\thtM
,(~TQ}
okI)"W
4jLn#%
1S=DO29Mj
5A4W~<
wr3v*I
4^IzOH
Z&:q7U
tt?t_t
t0tPtpt
e_[vOz
~)1fFbp
U8X6?{
/zof%n~znf
f+f`fzfKf
q4'qGqgq
qXq8qxq
$fDfdf
@s{}{'{g{G{
&{a'u8
U7'wFj
c+(-Da
tv1(^*
B5Qi7!
;h\E/
1)|j)g
';J3)_
554vY"
OOPnyAK/
?cI|=,
!lwaKf
},&:_~[/$)^
m?(~fJ
vkt`Yd%
N/amnz
P?ekis
j!.qD
)6*,)
_aiGo|
(P$L5,&
BJAgZ%
-Nibp,
A;jo<q3,
;7U'kR
Zi{eQj
WYHe:W
89l|WS
y}<aU$
vixzp"*
LVaY%@
v>Pf,.
1KQb[}
2XqJ]l
2Q^]orL
U$(eSS
t@ZF-
6(ObH2kr
qyb<In
QjWSCu
,Tr'Xm
T65L:u
YeTj*t
_pS+nu
rBa\*5
LL<11Z
fO[sFS~
c_eB,4L
OLEAUT32.dll
ERh8vs_
O82GRT\f.
GetModuleFileNameA
OleRun
:{"s)[
sI4[BqO
Zg*q}{K
TL*5@$
-o4JHD
*ALhYx
v4K#%1
pR 'H*
'(usI_
I1l2EX
TE1&$^
'@IK&t
4>xL+/
^N#d-se
x`:7a36jQ
s"/0*u
F}]a${Z
OajW>Kq
$Aja2p
t-W?w3%Z!
)Mg#-Y
ZC]/BY|
@$j"%*
!5vl)v
4BAmPX
X4IHx;p
9de'N&
Ou]2$,;
t8fFdk
W%owl'
XJ'Xb0
"X@utD
?>'J)S
sIVq@j
//zxo+
h@'RqX
T4$f!t
Ie?&5
(zoHTq
-X5+i+
qK-t&$Z
a$YY(f
AaVQ`!W:
x*NA<2r
Cte>D
{mZMLL
eRn'JZ
A.}_9X1
rPf8&I
ZW]hYN
S"onk3
,D5k|g
,>]L\#
~2Xeg1
vcuDnfe}.
+$Z}h|-
/nZ[M80
BqP|$(
,vA+_?}
+Gv_6LU&t
=%'rt1
~ZkzQA~
>%,5Hb
(}hxp3P
_%V5@b
PuLS[1k,C
o..YJQw
HjW{#9
i\q` hI
ExitProcess
'|FC60
SHELL32.dll
SHGetFolderPathA
v)?^?;
.8=fWW.
{l;a?,
k-<^z
k5vqch }
ZtKrkFd
L/NK8
u25s{uO
\/QNK?
t$<^^f
l$DQh+
L$@h]n
hsY*Uf
l$@hX&
$_n+ZN]f
70Z0t6m7>8e9
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.46526255
CMC Clean
CAT-QuickHeal Clean
McAfee RDN/Generic.rp
Cylance Unsafe
Zillya Clean
AegisLab Trojan.Multi.Generic.4!c
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Trojan.GenericKD.46526255
K7GW Clean
Cybereason malicious.ba2a99
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/PSW.Agent.OLG
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Trojan-Banker.Win32.Passteal.lq
Alibaba TrojanPSW:Win32/Generic.4fcc5b37
NANO-Antivirus Clean
ViRobot Clean
Avast Win32:Trojan-gen
Rising Trojan.Generic@ML.95 (RDML:ffsBpWagsfu/7ThmRExy/w)
Ad-Aware Trojan.GenericKD.46526255
Sophos Generic ML PUA (PUA)
Comodo Clean
F-Secure Heuristic.HEUR/AGEN.1114952
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.bc
FireEye Generic.mg.0f3560389b1ca2df
Emsisoft Trojan.GenericKD.46526255 (B)
SentinelOne Static AI - Malicious PE
Jiangmin Clean
MaxSecure Trojan.Malware.300983.susgen
Avira HEUR/AGEN.1114952
MAX malware (ai score=84)
Antiy-AVL Clean
Kingsoft Win32.Troj.Banker.(kcloud)
Microsoft Trojan:Win32/Wacatac.B!ml
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Trojan-Banker.Win32.Passteal.lq
GData Trojan.GenericKD.46526255
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Generic.C4524180
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.34758.TyW@a4qHnhm
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
eGambit Unsafe.AI_Score_94%
Fortinet W32/Passteal.LQ!tr
Webroot W32.Trojan.Gen
AVG Win32:Trojan-gen
Panda Clean
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Clean
No IRMA results available.