Static | ZeroBOX

PE Compile Time

2021-07-10 16:35:02

PDB Path

pmmplk.bb.pdb

PE Imphash

f09dd27db7b2c002f57b0dee04d67cef

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.rda 0x00001000 0x0004b8f2 0x0004c000 7.95912737273
.rdata 0x0004d000 0x00000c77 0x00001000 4.35232467248
.data1 0x0004e000 0x000077e3 0x00005000 7.29097787206
.m5Fih 0x00056000 0x00000cf4 0x00001000 0.919472872807
.reloc 0x00057000 0x000006cc 0x00001000 3.60760233542

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00056060 0x000002fc LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library GDI32.dll:
0x44d008 GetSystemPaletteUse
0x44d00c GetDeviceCaps
0x44d010 GetCharWidthW
0x44d014 GetBitmapBits
0x44d018 GetObjectW
Library ole32.dll:
Library ADVAPI32.dll:
Library USER32.dll:
0x44d084 GetWindowRect
0x44d08c ShowCaret
0x44d090 InsertMenuA
0x44d094 SetCursor
0x44d098 IsWindow
Library POWRPROF.dll:
0x44d078 GetPwrCapabilities
Library msvcrt.dll:
0x44d0b0 memset
Library KERNEL32.dll:
0x44d020 SetConsoleOutputCP
0x44d024 HeapWalk
0x44d028 HeapCreate
0x44d030 LocalFree
0x44d034 GlobalFindAtomA
0x44d040 EraseTape
0x44d044 LockFile
0x44d04c EnumSystemLocalesA
0x44d050 GlobalAddAtomW
0x44d054 LoadLibraryExW
0x44d058 GetModuleHandleW
0x44d05c GetModuleHandleA
0x44d060 GetProcAddress
0x44d064 GetLocaleInfoW
0x44d068 FindFirstFileA
0x44d070 SetFileAttributesW
Library WININET.dll:
Library WINSPOOL.DRV:

!This program cannot be run in DOS mode.
`.rdata
@.data1
.m5Fih
@.reloc
L$(f=R
L$X+D$l
t$;:T$;
L$*f9L$Nr
:D$gtC
D$49D$4
D$49D$4
D$49D$4
L$45iZ
L$$f9<q
\$^:|$^
f+D$Zf
-6_+7h
/"[6MLF
kX3s>7Q~U
B*|6/#
9gwQ|7N
~2H3B=
Vc0AE{
=weSh)
6rt\e!
$@~g^4
A+;.j'*
;)T$GL
CwO(J@
Dm>9^F
vGm,p)
7u`@sB
[Va_ W
=${t 8!W%f
2|y\N'*
}u3n1HT!j
aJSR!
~o"keiq
}hNoQ<
.Ne]#?
M&T{\j
<5ufX;
|$=sx?
YV.-OU+-
_!DnNY
>C0Eke
Jha>k,
5zw60C
HKIMyZ
:H5Sfi
SrM{O,
8i4y2w
ASV$/TumR
#s:0=P
Q"vVUx
l$=M(\
Vln[+2@Z
B<g~r3
Vmj.{(
_m:*E(#
AA!dz[Z
eL3_/6*p
qHhB!X3
kI%B.Sn
~lVT.^
]0&vf}3f
Eun^(Rfrf
C;Q'e\
DNc9Vk
6x9KKW
PiSe{C
WvbK!'
=eF*bZ
'cgTBRT
3xp\RW
1]^gG
[x+f6I
`{>)8z
8>uM+H
{GM(\W
CkA=/WB
"fc(>
_NWd1c
+fA`yPU
@i]m_?9
0>!g5V
Z#{)1:
@~}m&N
`a6Z+S'
89\$sn=
bj6,nV
>7lvei
G72(aJY
'hzGvg
NH)j'`y
.wBVvh
1{DNOX
w z2>&[7
H+U:4I
0u=n3C]
NU w?9
vs9-Ib
D3P1yrXnY
&1Eyh~<?T
_TQ06]
(8;J_I
9qAmn3
h5o;rWR
t>J 0*M]
/|`K/h'
Z3Xz.!
{"*a&w
Z4qQg+`
7E,}Z wah
ZaS6vX
q\K -S6^
SU-{Df
c_Jrsp
?'.CYx
t"MzpF
09-fS-
`7LNgi
AL!8VV
cQo`>F
:R,bL#e
*d3>OY
QyU|obE
a#P5j;
C'|*nd
'GJLl9
MYv-QtuO
ug-F Ad_
9jN2$h
"YNsRD5
3KPS3m
oivW+B
\vcP9
IC\8mA
;KAQ65
[AzM-V
<1W+T\
T"b;1%
-)0+I0
"64OSh
w{8}wT
&J*ZOl
$O|HC8
a?,X8-o(
]\C1*}
yId(vEp
0l8rwk
Sa"~JQ
'M6t>S
Lj.2%e
"t|^Q0
RbiVr2
t)(`*>
HnZ5 
cUy:'9
-jK~jui
:|lVe2
(302X_,
U<yD,<4
g,U!J(
rQ9DE1
YJY4ru
|[`aalS
H=`6s#\
l|3s?u
(+,P:"
CXrpB\
;lyO'\vw
1-^FcJ
d7*1q3
L|WSL1)
^Q )c
XG7l_2J
BadZJ+
ym,\T2
mI"'?l
~{l?rVu
XU/`n-
:t'>]~
eR'C+P
}H.3cu
CR0G3@rT
fMmn,
SWSB6}e
L+ITQ[
?iz'>j
-1[Bfi
GI|FF][y
oR%!d3Ws
q9aXZ/
X)~c*H
MQ0:_P
dWElgIl
}gT@5g2
@GOF;/
x8PGB7ZkuTi
hcAlz}
Q5%#Qs
&TbzU1
{J_f%R
Aca9^=
TfU|At
3*4j"(3
rxxFC7
|MN_^+/
}m~&*x
U17bzc
:#=>Hr
2Yso>b
(_\d4&w
;^rrAz
BQVA@5
~cAgY!
c2dVZ4`T
J/V-!D
d.`y*b
Jx)PGR
%Z?Lz.
u'MuKTo
A?Iq3Kt
ScsJzBBPJ?
2n?J J.
dN3~vZ'}5o
cV*%QE
Lk$;SM
?g{`?U
ui79VO
nb\ASa
5)M7/>
9?Xl<6
*d\lk=g
j;YQIL
T=}TFu
`2{Xd]
)[1A@l
N|i|d1@
Sy=v{h?
S,/g0
99BqhPFg]
*JXUtn
|cxT'(}
VL@282}
I6l5CC
/iJsR)4#W
S8a7&e<
}Ya7#rv
4-*"<e
5Q|{7L[
89DgLN
SN5uQ)
4MbA6y*
Lf1,?+l
ExW.v/
hmfmS*0
}#_&.J
)v,\b:
hM)W]!
jeMRcG
L1:fLQ
W6CUHcY
ML!M7N
VNJ'-%_"
/6#c-,sC/
Be=IJ1
Q_]qjD
~Y-OW"
@,tc[
zXk|[Wu
Q[]OGy
lXBy(t
*WfvF}l
Ilft3:
e,F>#tM
XQ+,hW
VPEnJJ
ll! "n,m
pHCWj<\#
{.M'mS
gw#Plw"G
})mslP
,!|OL(
!9t(B<
CS\P}
-3;ZZaT
'%g6N!
I@z5iT
>ptx~V
ix\y|9
O%(7Y3
En'MX
l\~\yt
&.^JwH
rzidS(
9XG$,Y
K$IwmN
Z;`ocUs
!+vPp#
(l3!o]*
0MP=)'
-uIeGg
O$,_gM]
lka&_h
@hN#G
N,zT:Y
[!,^(k
bGQ2$I
&xqGn"
Y\'(zx
(5&%0_
QeAl!s
o^`l1:
>,<jOo9
7)vR!|5
+:9Z|\
i%b8#|
"Pqg-o!.
t&O$NSuoF3
zlK-vo
feXl@S
!;mxOh
>E!3hJ
Xv$Cto
e1no9
QB/:8W
0*Yy(t
l<AKF<
TN(1IR
Ub.H/
R_vU2JV
q ojr6B
VxPmJ{
<W=y\Pz
kOS2Q+
2EzJ3[
yk#uzD
:n729
}:c*%K
VuJE8vG
?U+jIW+
tU92g&
_69$<_
V{P4e;?
Aoj\XM2
=OH4:L
/"`&6-A
g=n!o23
Y+" D3
h3+O xg
#g86%o
DOlR>6y
O._|/8b
F,KAN{
b],=E3y~
GekJH$
3Ywtdk
RHsJx$
{^EFn'X
^w,uJ[lI
%zP3GP7
1D(i9C
H4-Qrl
2x#ob;
u[bZ{2
|zNP;^
8.q9|[
<:U# Z
_e8QfT
GH`m2!
^MUZap
OC8d'4
8A:oN-
WTae{/
Vu,_G0
Wc)xsk^
/` /|W
Lvvs;A
K&k#{H
So<^[^
_g[X1p
cDK:EM
[WG80&
"U%ar,]
ENnc#1v
yi,iD
l-|vLo
PURLEs
z#@2s:
M$!Hok
"5EzI`
%Z3RHU
HT&A}6
i*7Aco
"-{KrA>(
i$esP_
oxS: 4
3P'FBv
mzzkN^
:\3F=QM
cX}R=7
azMA:
\R.9)R2
i&l.nE
_>UO^V*{
l(]m&V
YGhEN.'
g85\l,
\204e?
%D.cMH
w,PG+F@
|HI~Dc
muJspUP/
{HL@NW
Z!9@-kS
%8z$7s
=ii=fru
|Ik`07
~g_|'/f
RP[Y/v$
STTZmx
<SZCBM
nnT~7[
~$[xR-
>^&!#L
EL*tGL
icJOcA
PeeJ1w"8
O&$*Le96
u7g[5$~,
x:A9<$
84#e"Ak
dz]vp|
7N~}Iv
2(1akZ;k4
@,%':Sk
sF@V8h
LGmbvpb
&7pZnk6o
I6bDe\
Gh~[cqJ
6Yo}+m?
jw`JrL
7X+w@!
DK{:uN]
IOh:L
o_uS!:
iv 28l(N@
40OZm ~
9^>E}7
&py-sK&o~fk
>d.ttl#y
!<zOfC9]
ykCG6x
$,k/i<
-t>A`/b
3/l5E}SN
</bd&/
6|4sk#
U};4`"
dV>}'{
QaS89k~b
2obN:)K
$$a|wh
?<s%8/w
k~h![i
]G"L"A
.QKE#}=e
({0UH}
'?$lV>
@E[*.TC@z
NxEdf<
%v1&#c
%4S1_LFq
h%jf4m
QAx{;M=
EL/&*J6
5Fz4PV
|R>4Xi
3@2i;B
q(@ez
9;@p?7
FPPWD<
Y_e%Iq,-
{K_\N0]
73@mj1b7
^#NZ.y{
kvL=cO
jKBpS4
9#enI-
.^pe|,
QE6fPJQL
(.j9qG<
;z-Zc(
WSYQ:r
3}ihG]
.\Jh[}O
:)*?3
OW/II)
wV d>D
TR3d&2-o
"05Y&}
i,[Y>{
|#QN\dWI
(|<<$o
/[(8sn
lnCtud
W>*w4
H5KB,1
<lETn,
kV&gily
lxK*f<
Gyh!=(
'Z7.%9`
7b;6;r
""py}i
O|}\Jr
>U|Z{1:
var7n
)Tzum\b
3JOVC+
x"67|8
E*,u#C
Uqz_N|A
AB}>]
xuK2[g^i
NavfX3
h8[Dac.
^\BYRL
HN}%?_f~
Dd?vZ0,
IsThreadAFiber
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
LdrGetProcedureA0
7P6ChromeQcanThisIhad
F13Daenables
pmmplk.bb.pdb
GetObjectW
GetBitmapBits
GetCharWidthW
GetSystemPaletteUse
GetDeviceCaps
GDI32.dll
CoFreeUnusedLibrariesEx
ole32.dll
LookupPrivilegeNameW
ADVAPI32.dll
GetWindowRect
IsWindow
GetClipboardFormatNameW
SetCursor
InsertMenuA
ShowCaret
USER32.dll
IsPwrHibernateAllowed
GetPwrCapabilities
POWRPROF.dll
memset
msvcrt.dll
LoadLibraryExW
GetModuleHandleW
GetModuleHandleA
GetProcAddress
GetLocaleInfoW
FindFirstFileA
GetProcessAffinityMask
SetFileAttributesW
GlobalAddAtomW
EnumSystemLocalesA
GetConsoleCursorInfo
LockFile
EraseTape
FillConsoleOutputAttribute
DeleteVolumeMountPointW
GlobalFindAtomA
LocalFree
GetCurrentConsoleFont
HeapCreate
HeapWalk
SetConsoleOutputCP
KERNEL32.dll
FindNextUrlCacheGroup
WININET.dll
FindNextPrinterChangeNotification
WINSPOOL.DRV
fRtVG|x
d[sc5F\1
K*wqrd
tuqZE^
SO!^?Q6
Q,T"38
Zqg+M8
i{`h<1
W}k.X-No
Z9 RVq
g$c:BB{fXI
7q8QN{
j=3Jp>
AThPX6
Y`v`y\
Hk<Sd;
R|r%{k
Ne)_**~
.%wK;J
~<tfghzh
U3-^@2
UTG1tPMl
1&qy|@
(LE7}D
W0e0s0
232>2I2
>*>6>B>N>Z>f>r>~>
?-?E?K?Z?r?
00%0+0
1G1M1S1}1
2%2b2h2p2
3=3C3I3}3
5&6E6a6g6o6
7*7Q7W7]7
838;8\8u8{8
939C9I9|9
:!:0:?:N:]:
<X<`<i<r<{<
0/1M1q1
112I2m2
2E3Z3x3
3&4>4k4
4"575U5
6'6K6{6
; ;$;(;,;0;4;8;<;@;D;H;L;T;d;h;l;p;t;
< <$<(<,<t<x<|<
<,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=|=
> >$>(>,>4>D>H>L>P>T>
?T?X?\?`?d?h?l?p?t?x?|?
0 0$0(0,0004080<0@0D0H0L0P0T0\0l0p0t0x0|0
1$1(1,10141|1
14282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,30343<3L3P3T3X3\3
4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5d5t5x5|5
6,6064686<6
6<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8D8T8X8\8`8d8
9d9h9l9p9t9x9|9
ntdll.dlkernel32
0due3fromj
betaorNUMFL
content2,the7
austinXDublin.engine.135
mNoalong
jItheapplications,
frommountainwasfF537
blogstarting7channelPConcurrently,
forensicnumber,1BranchactivityasksLinux
d38subsequentu0thumbnailsapplet
loadblayoutChromeandwillie
wnUlifeTheofficialt
bubbaYHjGooglebeforeschoolRsecurity
theirxqcrashes.4444inlalso
also4InzmickeyofS
JwebsiteTWwebsite5versionq
m3bookmarks,kfIqb
of309Allavdemonstratorcurrently
GFattackfree
the5Partial
HreleaseUniversitybuilt-inbutqthatVDI
GovernmentZkCNET2ashitEasterF
self.exe
testapp.exe
VS_VERSION_INFO
StringFileInfo
080404b0
CompanyName
CHENGDU YIWO Tech Development Co., Ltd (YIWO Tech Ltd, for short).
FileVersion
1, 0, 0, 1
InternalName
LegalCopyright
Copyright (c)2006-2008 CHENGDU YIWO Tech Development Co., Ltd.
OriginalFilename
sm.exe
ProductVersion
1, 0, 0, 1
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
Qihoo-360 Win32/Trojan.Generic.HxQBaOcA
ALYac Clean
Malwarebytes MachineLearning/Anomalous.100%
VIPRE Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Clean
K7GW Trojan ( 005485311 )
K7AntiVirus Trojan ( 005485311 )
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:Trojan.Win64.Shelma
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Trojan.Generic@ML.100 (RDML:hR4WiNLIO19w2tWb9CMY1w)
Ad-Aware Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Ransomware.fc
FireEye Generic.mg.5de6ec9265f79a31
Emsisoft Clean
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot W32.Malware.Gen
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.Heur.KVMH008.a.(kcloud)
Microsoft Trojan:Win32/Wacatac.B!ml
Gridinsoft Trojan.Heur!.02012021
Arcabit Clean
ViRobot Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!5DE6EC9265F7
TACHYON Clean
VBA32 Clean
Cylance Unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.F0D1C00G621
Tencent Clean
Yandex Clean
Ikarus Win32.Outbreak
eGambit Unsafe.AI_Score_64%
Fortinet PossibleThreat.PALLASNET.H
BitDefenderTheta Gen:NN.ZexaF.34790.vu0@aeONwnnb
AVG FileRepMalware
Cybereason malicious.02ac77
Avast FileRepMalware
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.