Static | ZeroBOX

PE Compile Time

1992-06-20 07:22:17

PE Imphash

24ad104a00688625f1c866ec954ed33f

PEiD Signatures

ASPack v2.12 -> Alexey Solodovnikov

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
CODE 0x00001000 0x0000e000 0x00007200 7.9813900664
DATA 0x0000f000 0x00001000 0x00000400 7.03888112995
BSS 0x00010000 0x00001000 0x00000000 0.0
.idata 0x00011000 0x00001000 0x00000600 6.80227325217
.tls 0x00012000 0x00001000 0x00000000 0.0
.rdata 0x00013000 0x00001000 0x00000200 0.210826267787
.reloc 0x00014000 0x00002000 0x00000000 0.0
.rsrc 0x00016000 0x00003000 0x00000c00 6.30813117682
.aspack 0x00019000 0x00002000 0x00002000 6.24405443514
.adata 0x0001b000 0x00001000 0x00000000 0.0

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0001a15c 0x000008a8 LANG_KOREAN SUBLANG_KOREAN data
RT_ICON 0x0001a15c 0x000008a8 LANG_KOREAN SUBLANG_KOREAN data
RT_DIALOG 0x00017750 0x00000076 LANG_KOREAN SUBLANG_KOREAN empty
RT_DIALOG 0x00017750 0x00000076 LANG_KOREAN SUBLANG_KOREAN empty
RT_DIALOG 0x00017750 0x00000076 LANG_KOREAN SUBLANG_KOREAN empty
RT_DIALOG 0x00017750 0x00000076 LANG_KOREAN SUBLANG_KOREAN empty
RT_STRING 0x00018020 0x000002c0 LANG_NEUTRAL SUBLANG_NEUTRAL empty
RT_STRING 0x00018020 0x000002c0 LANG_NEUTRAL SUBLANG_NEUTRAL empty
RT_STRING 0x00018020 0x000002c0 LANG_NEUTRAL SUBLANG_NEUTRAL empty
RT_STRING 0x00018020 0x000002c0 LANG_NEUTRAL SUBLANG_NEUTRAL empty
RT_STRING 0x00018020 0x000002c0 LANG_NEUTRAL SUBLANG_NEUTRAL empty
RT_STRING 0x00018020 0x000002c0 LANG_NEUTRAL SUBLANG_NEUTRAL empty
RT_RCDATA 0x000182f0 0x000000a4 LANG_NEUTRAL SUBLANG_NEUTRAL empty
RT_RCDATA 0x000182f0 0x000000a4 LANG_NEUTRAL SUBLANG_NEUTRAL empty
RT_GROUP_ICON 0x0001a138 0x00000022 LANG_KOREAN SUBLANG_KOREAN data

Imports

Library kernel32.dll:
0x419f5c GetProcAddress
0x419f60 GetModuleHandleA
0x419f64 LoadLibraryA
Library user32.dll:
0x41a094 GetKeyboardType
Library advapi32.dll:
0x41a09c RegQueryValueExA
Library oleaut32.dll:
0x41a0a4 SysFreeString
Library user32.dll:
0x41a0ac TranslateMessage
Library shell32.dll:
Library shell32.dll:
0x41a0bc SHGetFileInfoA

This program must be run under Win32
.idata
.rdata
.reloc
.aspack
.adata
%]lQkmy
=-h 7?
f=G!o(
{AFjP8
[']KB7
n,. _,
NjEBm7
'0-Kz
CV*%G.m
S=NK2?d
\MyVNmB
DbL-J[
q'U|p<
"sA7my
z9 &gB
;XHJ:),
],!g0$7r0w
Mp.&$9
7B7D6,g
7476783
7:7<7>3
-+^n#=Z
e$g)jML
Ws$*[.0W
`;=<Jf
eXW?jc
eG/5Z8uS
!# Cy:
/`"ry2
jbYnv;
N(FbmP
Q@0?&=~
oH*<0dOT}
]h&2-I
$^\Xi.Uz
fV1-"x
lGlG~g
itktqt
0ha\?Y1
|ymkG%
Juo"+G
YT!.-:
A6FdI
Nm3@(g
cg=rT)
Jv"Am^
X{*^Hb
n&pTer
mnwY$E
cN1H'D
6A(Kbmt]
Wg+_4Q:]
[g$,4<DN
@yrRVi
/7u _E/
sp<+T;
Wa'6"+qN
VirtualAlloc
VirtualFree
kernel32.dll
ExitProcess
user32.dll
MessageBoxA
wsprintfA
LOADER ERROR
The procedure entry point %s could not be located in the dynamic link library %s
The ordinal %u could not be located in the dynamic link library %s
(08@P`p
kernel32.dll
GetProcAddress
GetModuleHandleA
LoadLibraryA
user32.dll
advapi32.dll
oleaut32.dll
user32.dll
shell32.dll
shell32.dll
GetKeyboardType
RegQueryValueExA
SysFreeString
TranslateMessage
SHGetPathFromIDListA
SHGetFileInfoA
{x{K{q
GD{KL{T
DA{K{LKd
\K{{M{d
{Kx{KK{d
xKKxK{K{d
DOxxK{{K
"TxxLK{{T
TxxKxL{
MuxKx{K
DOKJx{{T
"{xKxx{
x{JKx{
"{KxJK
xTxxxT
ATxxx{
O"+{Ku
$l k0xw
l$2b$$eHH.
C:\Program Files\
\SmileEDI\config
TableConfig.xml
]mo[Gv
CKhF4j$
6j=k~n
/3zo%_I
|CT~4*(
tL)(dJ
hQ-n$#
<a.O=a.om
0[.O;[
UiR6OIw
nBB\ZT
dWQTB}
<7)0Hr
TableConfig.xmlPK
ABOUT2
FILEEXIST
MAINDIALOG
PASSWD
DVCLAL
PACKAGEINFO
MNICON
Antivirus Signature
Bkav W32.AIDetect.malware1
Elastic Clean
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
AegisLab Clean
Sangfor Clean
K7AntiVirus Riskware ( 0040eff71 )
BitDefender Clean
K7GW Riskware ( 0040eff71 )
Cybereason Clean
BitDefenderTheta Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Avast Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
Ikarus Trojan.Gendal
GData Clean
Jiangmin Trojan/Generic.aqscn
MaxSecure Trojan.Malware.300983.susgen
Avira Clean
MAX Clean
Kingsoft Clean
Gridinsoft Trojan.Win32.Agent.vb!s1
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Program:Win32/Wacapew.C!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Trojan.MulDrop
Malwarebytes Malware.AI.3356647701
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Backdoor.Agent!JpE4mAkYxXE
SentinelOne Clean
eGambit Clean
Fortinet Clean
Webroot Clean
Paloalto generic.ml
CrowdStrike win/malicious_confidence_60% (W)
Qihoo-360 Clean
No IRMA results available.