Static | ZeroBOX

PE Compile Time

2021-07-26 16:11:29

PDB Path

Gpernfedeefe.pdb

PE Imphash

e9cbee8358b331a128409a4d26e3e347

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001357c 0x00014000 7.824574037
.rdata 0x00015000 0x000009d8 0x00001000 3.66891935244
.data 0x00016000 0x000119ca 0x00011000 7.84923846168
.rsrc 0x00028000 0x00000420 0x00001000 1.09655664129
.reloc 0x00029000 0x00000120 0x00001000 0.698725432618

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00028060 0x000003bc LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library msvcrt.dll:
0x100150f0 feof
0x100150f4 ungetwc
Library ADVAPI32.dll:
0x10015000 LookupPrivilegeValueA
0x10015004 LogonUserA
0x10015008 GetServiceDisplayNameW
Library pdh.dll:
0x10015104 PdhEnumObjectsW
Library KERNEL32.dll:
0x1001503c CloseHandle
0x10015040 GetCurrentThread
0x10015044 LocalSize
0x10015048 FindFirstVolumeW
0x1001504c GetCommTimeouts
0x10015050 IsValidLanguageGroup
0x10015054 lstrcatA
0x10015058 GetTempFileNameA
0x1001505c IsDebuggerPresent
0x10015060 GetModuleHandleA
0x10015064 GetProcAddress
0x10015068 OutputDebugStringA
0x1001506c CreateProcessA
0x10015070 LoadLibraryA
0x10015074 GetTimeFormatW
Library MPRAPI.dll:
0x1001507c MprInfoBlockRemove
Library GDI32.dll:
0x10015018 Rectangle
0x1001501c GetDeviceGammaRamp
0x10015020 GetRgnBox
0x10015024 GetTextExtentPointA
Library SHLWAPI.dll:
0x100150a0 StrCSpnIW
Library WINSPOOL.DRV:
Library mscms.dll:
0x100150e8 GetColorProfileElement
Library WININET.dll:
0x100150d0 InternetCrackUrlA
Library ole32.dll:
0x100150fc HPALETTE_UserFree
Library SETUPAPI.dll:
0x10015090 SetupDiGetClassDevsExW
0x10015098 SetupDiInstallClassExA
Library WINMM.dll:
0x100150d8 mixerSetControlDetails
Library OLEAUT32.dll:
0x10015084 VarI4FromDate
0x10015088 SysStringByteLen
Library ESENT.dll:
0x10015010 JetSeek
Library IPHLPAPI.DLL:
0x1001502c FlushIpNetTable
Library USER32.dll:
0x100150a8 DefDlgProcW
0x100150ac GrayStringW
0x100150b4 GetMenuState
0x100150b8 GetScrollRange
0x100150bc GetRawInputDeviceInfoW
0x100150c0 GetShellWindow
0x100150c4 GetClassInfoExW
0x100150c8 GetMenu

Exports

Ordinal Address Name
1 0x1001525e DoorrledFgppr
!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
L$*D$C
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
D$<9D$<t
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
D$<#D$<
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
T$Hf=,
r:A+)j
r:A+)j
r:A+)j
D$F0Gf;L$F
r:A+)j
T$X+D$L
D$`&@JJ
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
r:A+)j
hs0}+nZ
:@_6h2
k0y]C
zE:xd5
a8$U'7Yp
'ZTbZs
U#r5[!Xm
f.e;g!
V>,a3?
{#%ggw
/2yI+8
sm<6K>
2@nSL\
m('Emv
1=^8\m
KMwLS/
*5/eHo
'Qc[o+
y"Dk8n
vZ-X@mH?
d9D~b5;
+ETr6:Po
lr)(~/
Oe?><o
ILA<a
[uzN.h
{sAD_'
(y![b:
!R=|oGb
!p;GMMjA
Nz jB8
z2>N4+
Lk\.5#W
`Q"LOhi
ZhlVf\'
^nAr5 -
7Pj4&
0y'j`q
e<h#<t
K\s j5
FyHi5N
f#&-O+
y2v&Sb
B*v<{7P1
TEq.\r
4{5d>
!~3Z:z
b1dKzcC
3 yI@3b1
ocz#!n
-&rI:R\
s<D,7K
CX%~!R
_IC#L?
6Y.+r`o
?BZ4j4
s|YZ8%
E~N{|O
n:So*T
,D0d^is
&%ySCLG
nWXAH[
B0UYq|
\ ?F2{
pJ "ef
9FeT T
n;a<.T
N`j3P/,
:sa]Kfy
/(XH{76
)n<C^;M
+[CFW[
GHy(?<
{p_Y,"
wt^]h}H]
Ls&D<&5
vgTyB5
TCP{gX
!XqgD(
pqzJB4KE
Z:DlFDT[
+U&\uf
#!oJJp!
6DE_nI
jM[`&!
a~8^0U
)]![ADq
>c*ex:v
b(Bl<Ik
Z^U Yf4
_$`sQr
F:RvxM7j
1iTT9[
\IQ!nZ
~CsjzY
#h6'"
1U^P89
N>Q>?H
*r0mh5
OXqik\
[#W@^.
PzwZM%9
YhHYg
jrWX8p
+vT!64
|YU0#;bF
SGm]U+
>K2!0"CE
-fW39[v
&JkIElY
D$8-~o
L$83L$8
L$4+D$4
T$K2T$K
D$Tf3D$Tf
T$4kT$Pd
T$ f+T$ f
T$ +D$
$+Self ex
testapp.exe
Dormittjd.dll
DoorrledFgppr
kernel32.Sleep
Gpernfedeefe.pdb
ungetwc
msvcrt.dll
GetServiceDisplayNameW
LogonUserA
LookupPrivilegeValueA
ADVAPI32.dll
PdhEnumObjectsW
pdh.dll
OutputDebugStringA
CloseHandle
LoadLibraryA
IsValidLanguageGroup
GetLargestConsoleWindowSize
WritePrivateProfileStructW
GetTimeFormatW
GetCurrentThread
LocalSize
FindFirstVolumeW
GetCommTimeouts
CreateProcessA
lstrcatA
GetTempFileNameA
IsDebuggerPresent
GetModuleHandleA
GetProcAddress
KERNEL32.dll
MprInfoBlockRemove
MPRAPI.dll
Rectangle
GetTextExtentPointA
GetDeviceGammaRamp
GetRgnBox
GDI32.dll
StrCSpnIW
SHLWAPI.dll
FindClosePrinterChangeNotification
WINSPOOL.DRV
GetColorProfileElement
mscms.dll
InternetCrackUrlA
WININET.dll
HPALETTE_UserFree
ole32.dll
SetupDiInstallClassExA
SetupDiGetDeviceInterfaceDetailA
SetupDiGetClassDevsExW
SETUPAPI.dll
mixerSetControlDetails
WINMM.dll
OLEAUT32.dll
JetSeek
ESENT.dll
FlushIpNetTable
IPHLPAPI.DLL
DefDlgProcW
MsgWaitForMultipleObjects
GetMenuState
GetScrollRange
GrayStringW
GetMenu
GetClassInfoExW
GetShellWindow
GetRawInputDeviceInfoW
USER32.dll
!dGm1vH
Y6y]1DT
TczP)`
ZKr[E,C
oc\.mo
yVWwa5
G<^%Hg5
8X:jf;E
hZ|8GT
:N0eB'
wt<AV,MfbGcc3
G!W,Q0
%B4Z^Bq
3OwV6i)m
72"d3d
-uB`6A
9Y_Ge<
kaFS~I%
!wX4y-p
VGv Gt
^})$s{
bt]b_-wO}3e
T~0wg!
R'U.=F
8Ou`]I
vx[ax1
E?AUl~
XBIzW)
siGK3o
7X"@c
Qdu_[X
Z[:%{y
7>cZ/E2
/kX`^UH
N[FG$g
YRQz>A
i0.M,S
8dO\;]
J7LegQ
f.!dL3
WX(#aF
}'5-6?Y
C'.XKC
VX2V+p
O<v[p%g!
.Hs*3rr
"7tJKF
ShCa@A
X+TcRP
|"~-F9
)r6482l
{+)a`K
i{8$J/]
6fMBg+h
tmphSQ
vY8h[y
5{OCWA
YI*2x(
N|ngOz
u~T+1k{?w7v
e;~diC,'6
!*sJKo
n~P}r
%6)R[*
/\o1sA
Qe6b7]
'8(B_},
R`8ReDs'NC
_nFl'W
C,G\WW
HeE@@G8I5cZ<
s?IPCp
8{X>L\
z^;dCp
jg0F:o
M77&jq
o@${%>L/*
1#(q7}?
@*"" I-b
aI=F`T
joIlDC
x]6J4rH+fPuWWgs
2iAUl3ud
LFAPm75
p0oj~3
Ks!k*07{
/pd.vb
E}f0tW
V::`-k.
bX-j9>^
Q\T&_P
8'.#VS
%RsMVsk
?LaBtYQ
(tC4!7
J+M4;p
2Knl_k
eFCgTz
y'DumS
M,]r|Zqj
lA~L3D
==YEk:
Eiv}S
a|2Q28
r+=2Hz
(HAG*h
H-=#`t
*<'=^y
YgbGQ^|
8yi<-G
!jY;6i
MLJ'W~B
FvWJb
Qx$K<dm
3}:{'[b
HPr)7XW
xYOF^+
X<.ia{
{m2Bcz
>)>pJzpH
0I0i0s0}0
162?4x4
5F6Q6[6a6k6
3H5N5T5Z5`5f5l5r5x5
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
CompanyName
Citrix Systems, Inc.
FileDescription
Credentials
FileVersion
8.68.5.00000
InternalName
Dihzehtreof.resources.dll
LegalCopyright
Copyright
1990-2017 Citrix Systems, Inc. All rights reserved.
OriginalFilename
Dihzehtreof.resources.dll
ProductName
Dihzeh Reofqehs
ProductVersion
8.68.5.00000
Assembly Version
4.12.0.18013
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0053b6a31 )
BitDefender Clean
K7GW Trojan ( 0053b6a31 )
Cybereason malicious.702157
Baidu Clean
Cyren Clean
Symantec Packed.Generic.553
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Trojan.Win32.Zenpak.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.96 (RDML:Z7tM+gk92yNl2A5ScW1QmQ)
Ad-Aware Clean
Sophos ML/PE-A + Mal/EncPk-APX
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
FireEye Generic.mg.622f4aa2d5e82438
Emsisoft Clean
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
Microsoft Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
VBA32 Clean
ALYac Clean
TACHYON Clean
Malwarebytes MachineLearning/Anomalous.100%
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.34796.ku0@aG7Am8n
Avast Clean
CrowdStrike win/malicious_confidence_100% (D)
Qihoo-360 HEUR/QVM20.1.94BB.Malware.Gen
No IRMA results available.