Static | ZeroBOX

PE Compile Time

2021-07-20 07:31:09

PE Imphash

f45f4bccd20f0a7ca0fccc38d235a8f2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00001262 0x00001400 4.77218546398
.rdata 0x00003000 0x000006ee 0x00000800 4.41761799375

Imports

Library ole32.dll:
0x4030b8 CoInstall
Library urlmon.dll:
0x4030d0 FindMediaTypeClass
0x4030d8 CreateURLMoniker
Library WINMM.dll:
0x403058 DriverCallback
0x40305c joySetCapture
0x403060 mixerGetDevCapsW
0x403064 midiOutGetID
0x403068 mmioRenameW
0x40306c mmioGetInfo
0x403070 midiOutSetVolume
Library WINSPOOL.DRV:
0x403078 GetPrinterA
0x403080 None
0x403084 AddPrintProvidorW
0x40308c OpenPrinterA
Library dbghelp.dll:
0x4030b0 SymLoadModule64
Library MSVFW32.dll:
0x403014 DrawDibGetPalette
0x403018 ICOpenFunction
Library AVIFIL32.dll:
0x403000 AVIFileRelease
0x403004 IID_IAVIStream
0x403008 EditStreamClone
Library WS2_32.dll:
0x40309c accept
0x4030a0 WSAGetLastError
0x4030a4 recv
0x4030a8 connect
Library RPCRT4.dll:
0x403028 UuidIsNil
0x40302c RpcEpResolveBinding
0x403030 RpcMgmtInqStats
0x403034 RpcEpUnregister

!This program cannot be run in DOS mode.
`.rdata
CoInstall
ole32.dll
MkParseDisplayNameEx
CoInternetCompareUrl
RegisterMediaTypeClass
CreateURLMoniker
CoInternetCombineUrl
FindMediaTypeClass
CreateAsyncBindCtxEx
ObtainUserAgentString
CoInternetGetSecurityUrl
CreateFormatEnumerator
RevokeBindStatusCallback
urlmon.dll
DriverCallback
joySetCapture
mixerGetDevCapsW
midiOutGetID
mmioRenameW
midiOutSetVolume
mmioGetInfo
mixerGetLineControlsW
WINMM.dll
OpenPrinterA
DeletePrinterDriverExA
AddPrintProvidorW
EnumPrintProcessorDatatypesA
GetPrinterA
AddPrinterConnectionA
WINSPOOL.DRV
SymLoadModule64
dbghelp.dll
ICOpenFunction
DrawDibGetPalette
IID_IAVIStream
DrawDibChangePalette
EditStreamClone
AVIFileRelease
MSVFW32.dll
AVIFIL32.dll
WS2_32.dll
RpcMgmtInqStats
RpcEpResolveBinding
I_RpcTransDatagramAllocate2
NdrClientInitializeNew
NdrMesSimpleTypeEncode
UuidIsNil
RpcEpUnregister
NdrXmitOrRepAsUnmarshall
NdrMesProcEncodeDecode
I_RpcReallocPipeBuffer
I_RpcTransConnectionReallocPacket
NdrEncapsulatedUnionFree
RPCRT4.dll
:x@.ZH
:dy~+h
J^gGc*
/fvmos
E0;=+h~
[/Wq"O
~gf20
5U\z"?
X'E@L%
B&km<_
jq+^Xe
"HZoJp,E98
+e$Cu__
d3$>]%"
/r;mwi
U\z!p)<xR
xLu7iW26V
U=e=2%
?(/x6dN3
gn@_h/P-G
[1neQI6t
q)Ofl'e!
;eunbO
&}!>@e+
>HkZJrD
0EcYATxn
j.B08w
<7d.<S
VEer1uMv
=3R]4
hHOo17
A'tJe|#
x%E%>1BWx
E9[p/$
E1L#Z27
N(z{xH
Z!E5(3
]zoojQ
*ayn-@%.
UIk{rzN
6\B)A_,9^x
u7:?f4:
6{avry
q4hXSl
cpIz"?
< -?La
>B^!{d
SnPioS
oO_~zr6'q#
Xcfs02c#
5U\Q(6
X<jmH&
B3}}nG
Hx>M 9cr62
A#Q\YG
G;cfiC
C<Z}IW
G>bdVi
\wcJCkc
6:)2keP
03VK<$
3%XP{.
#_"oc#
E"(`_=
lOmb4`
2A~lTs
EXArX9X
#f,mkU
OkW?,_,?
5U53L?
;eunbO
g"LoziY
P3RlU&
KQc>;/
hS:<i
f2MPYR-
=wSPbG
e5o#~D/PeU|
(/1y<V
\lLkg
1.1|"^
"!`2Y[6
EG'C?T
Wxks92f
UCV{ J#)
~gfN0
LQ5\Pgt
*O,L$7{
q~dN{k
X$c_>t:,w
;$f+C|Y
}y=mgp
7172(9
5U\z"?
~gf20
5U\z"?
P>&}!8h
"u+<x{
Avux9O'
"gO<t
6!f_XkY=
"@}<x=
tEf,)
S5U\z"
~gf20r
5U\z"?
~gf20
MPX&)!
5U\z"?
~gf20
n@F</x
5Q\z"V
zAeXW4
FDNsP#
6,DjI`
>;<_SD
5U\z"i
Xe4JCD
5U\z"p
gHf20B
,ApXe4eC
uAyXe4
Ey,)k
5E\z"e{<x
E[,)&
t<xL*`
&}!!"z+
&}!<;z+
^<x'*`
(K~z;]
E>,)j
AbXe4d
5_\z"'
~gQf?0
GEa,)k
0AZXf4
58\z"i
]P'&}!
%AZXL4FC
<5U\z"
~gf20
5U\z"?
)]LSb[6i
B3tXLf
"8,ueX"
T\z"nn
~gtf20
tEcba8
q"D`gf20
&}!URz+h
B(K~yx|
B(K~Kx|
Uo-h2
27xE~Y
cCyK#%z
5U\z"?
~gf20
5U\z"?
~gf20
5U\z"?
~gf20
5U\z"?
~gf20
5U\z"?
~gf20
5U\z"!c
tEs+)
~gf20
5U\z"?
5U\z"?
{{8on^
5C\z"?
~gf20
5U\z"?
~gf20
5U\z"?
~gf20
5U\z"?
~gf20
5U\z"?
~gf20
5U\z"?
~gf20
5U\z"?
~gf20
5U\z"?
~gf20
5U\z"?
~gf20
5U\z"?
~gf20
5U\z"?
~gf20
5U\z"?
~gf20
5U\z"?
~gf20
5U\z"?
~gf20
5U\z"?
~gf20
"FFzqOJ
w$U{z7D
H/l6dN
H=Gq9;)
[{MPHc
dsqmDws
04(-[O'
8J``P%
aE{QHp
d;x|kq
IjQSQ^
_(ymbJ
H!@L'`
2]X~7s
~^)W\6
LH/lrdN_
5Gq9})
P~L.+z
tINwy$
zo8w+r
P;K4Tp
3E@TWQ
5U;)5m
+SZfLv
-,<lb+
yiL"m1
V*zvbE
doC3R]
Dz_S<#
G;/Q)r
P1kfWC
|(K<uFF
PxD2/f,
4t:uCH
k9LcL
isRA0~
:K~n(}
Q7e41|
|ArLg{
}:@1u0
SrF@2.T
n[_b)g
<){n0N3
S2FV2%
*Ikpbz
.q"T70
%f*5U\
SuIG*%'
B(KA]!_B
0KELuwM
*/X6Vg
n\dp,I
mkb_JP
^pxG}{
o/jr4\
jL+fx2
Ta4&Rk`0$<jQ
q_E c$
-GI?GY
@xWif(
,wS2m:
~t5;9U%
`Hd_6f
y^u_,7
-[O'|JW
-ca`s5
s%qfR2
$\b3;:
("0%[%~
i\z"%;
mrlaW2
.[EVv7i
LQ.pJj[
1A)Xe$M#
q<I&X3
tTnYX
mc;Y$6
Saq@2S
V6t:`U
gVF0<j@o
G")M#d
^px!V{
SJ)&JdQ
4a],'|y
xGd"&1
3D2yB,
G")M#d
%?lQ$$
.FIk{v
aFL5\#
xc*`\$
S)+@2S
(TTXs]
Qm(mR]
vk"[O'a
MSu3a*a
'"O:5YG")
dNH^+};u1u
8B.O#e
)"LZLt7
Y8_t?EmY_[
LMxu-
$"?$Qt
lW-o7W
S2>N2%
aOxJ%B<
]QZ=)s
^?rx|u
xUu m
&f02t
p$I#v/N
{I7X.O#
_z"/Q)
{n}Vt>
Hp7iWV
B(^78k
4rO>9OS
^[G'O!
`%ANwP
EMY=bE,?
zNwP3*
P_1b.r
%-Qyv
Sd19U:R
~hfD-*
?1.O#e
m(HPUF
M9j)Si
n`Kv7iZ
c%,)<C9h
d&\#de
V]k7C1E,?
\%f~gl
x*N&4{x
L~D[dY
2 :19U\
tQ8_)FT
+SJpa*
\d?O:?
sNwu3Lq
Q,UR*$
t6,8dh
LkS5?:w
vzo`QFLt
fD*LE!
t{,8th
j0Rj62%
Y8J"<a
L# [dY
!'Dmb42TN
[t"T>io
f226e4
Tp[TcB
rwf\=6
e~3s 20
QifK~n
F Nf"L
>@nw{9
7vL"m1
{k~$,.
q:$k\S
f2M=By
mo8|])
9?9<'q
rw|uiY
o8C0hFI
i{a&3ki
(c~crj
])mX/qPQS(
X'KUcs
/xEdN?>
#mTOR]
fFM=I/h
vJ$+'eS
E%lMrV
*`tf[q?P
^U0)jJT0!
`OAr-c
_puiOo
c9jIyHv
_Zo(=Yf
w'_/ZbS
Hv7iaq^
Y'm~lcE
,~9]02Y^
r'xJWf
a*aA5
C)BeP\(
.<7dmQ
<[)HFj
=s|^Y(
%AD,Ne
;cKdq;
iy*1uP
!6G;/QE
SRka*a
*qGZ=e
x@i<y#"
lJxR#v,
_u9Ar-i,
U*'tJv
o0y6lP
E,<&s/
K~)fAN
gf2LE
.r5<5w
NT4"n1FI
%?rQ$\`
o8Ch`t
!C`{WBq
M>''[F
("0%[%
u1|zcAC
u1|zcAC
mJ0O3L
u1|zMAC
Hm(ZF.
m0R5UH
Y@<kO;
XL)L@z
acxuik
I]d&nm
pkG.O#e
c_[4{O
v>:88g
DPZz\,
a"0%[%V
QUp&}!
$jB('4
}vWL@"
5<QQT
B(K~)["YEk
!3~<-Z
}5;`gcl
lpY)@j1
jj.O#y
!'N24f
'x5~M+
JxSztf/
U <ke
[3*D.v
dhS6Fi.
Yr`d,$
-%Bx9:N
z<!&]
0:K~MRF
5&NkH ]
_:PcqF
L:M|y5
B<|bR
nB>+[
Yku@@1[
bK's=h
;8|BG]e
!g3Z2J
&%#J[gs\
G(n~z@
i&uM3Kz+
v?ym;^a
(;XbVN
*u3-gr'
o&!tzq
FM#u'en
!+5M`i
m|(\H%
$i<6xga
%8+fAVX
QgXs_x
Q=d70RM
E67zl;J@
XCa h_
%^V<R
$=SIWz
l=h1<o
ME/xX3
S[1_gh8
}5LIFc{
Y>sJJIz&
'bfv7M
GFSyqD
Rr+|\Blf
S1qGdG
_h0ro)
^[2N}yx
ehpaqoo
JO!*s~}
"5GKz2;3
yFgelX
:m}zOY
xQftW
@}Kp01
0NVe3GA
Wr/{h}
Fx@6`2
B>5iVo
`Ey\O%}/
OiIY+X]
S_\/gj
H[xW?c
6RNX(h
{r$kMC
P?J>*)
%lAhg$
lnMxg=
A{i7\/
|/5F`+
GNs;iM
C*c~TT%
%jNS$}
5>T*Srn
p+\IO3
VoR&5
27*e[a)
g?!*l]g
%-~G,\b^|
(AJd0iS
W>fVHG
9!RRMoE
gC?dkv
,AMI?s
)41~fE
KR}N@~
sy91"+
fxd$<7
W$eDy9
7jE^M]
^-XZ&Yq
S{zze
#bMFE
8B;}e~w%
#da{7y'
#YtUo)D
I\uu~[}
26<|]+,
,c)s5\
Z9CS"T
1?[S@>
~gf20
5U\z"?
~gf20
5U\z"?
~gf20
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Gen:Variant.Ulise.260215
FireEye Generic.mg.928ec247e6f6cd24
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Ulise.260215
K7GW Clean
Cybereason malicious.c43ab5
Arcabit Clean
BitDefenderTheta Gen:NN.ZexaF.34796.qiZ@aqLTLFg
Cyren W32/Kryptik.ERD.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/GenKryptik.FHSC
Zoner Clean
TrendMicro-HouseCall Clean
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan-Spy.Win32.Noon
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Gen:Variant.Ulise.260215
Sophos Clean
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Dropper.dc
CMC Clean
Emsisoft Clean
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=82)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Wacatac.B!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Gen:Variant.Ulise.260215
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
McAfee Clean
TACHYON Clean
VBA32 Malware-Cryptor.General.3
Malwarebytes Clean
Panda Clean
APEX Malicious
Rising Trojan.Generic@ML.94 (RDML:jVijBh6+yscG94Eks4HMnw)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet W32/Kryptik.HIBR!tr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (D)
Qihoo-360 HEUR/QVM20.1.B4A6.Malware.Gen
No IRMA results available.