Static | ZeroBOX

PE Compile Time

2021-06-16 17:13:25

PE Imphash

6e5d6f8cfeb03792ab4a971f2b52e520

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x0003b000 0x00000000 0.0
UPX1 0x0003c000 0x00012000 0x00011a00 7.98750365303
UPX2 0x0004e000 0x00001000 0x00000400 3.19040239216
.rsrc 0x0004f000 0x000002b0 0x00000400 3.9111600388

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0004f058 0x00000258 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library ADVAPI32.dll:
0x1004e0f0 RegCloseKey
Library COMCTL32.dll:
0x1004e0f8 None
Library GDI32.dll:
0x1004e100 SaveDC
Library KERNEL32.DLL:
0x1004e108 LoadLibraryA
0x1004e10c GetProcAddress
0x1004e110 VirtualProtect
Library ole32.dll:
0x1004e118 OleRun
Library OLEAUT32.dll:
0x1004e120 SysFreeString
Library oledlg.dll:
0x1004e128 None
Library SHELL32.dll:
Library USER32.dll:
0x1004e138 GetDC
Library WININET.dll:
0x1004e140 InternetOpenA
Library WINSPOOL.DRV:
0x1004e148 OpenPrinterA

Exports

Ordinal Address Name
1 0x10006341 Init
2 0x10006322 Jmp
3 0x10006360 UnInit
!This program cannot be run in DOS mode.
lWv5fW
lWv5gW
lWRich@
c T`bhEbW
_(X0$mB
E7$jV~u0EL
Y/ zg=c
Eicf(.]x
rU?t/X
P\j=f#7QH
hD0vcP{
k99'CU9
3iB|Wo
xn+_[
l,:Hf>
c,6Q5gq
`-oG`K!
]I]tZ
a"@0`z@
,rd'>P
X*#q+*T
T)c,tQ}
Bo@qg@
kF~ch&
q$I`Qg
IZFxkI'
Ddg[%9
%#m1s?
'aP{SQ
!nK$x/
j!IO`8
c+@p6t
U8|T}X
("OP5"
6y{CR&
@{%,_5
5}ha;5
8?RvG3
mV&S5S
dUT^\h\0
=rT"y&
2N3IACd
d?$Z##
J>|J~vW
\Qaxym
4\.GyK
p`S$b?Z
^^04xe1
`c_m~>@<
Q]t\t>
7+n;{2
10K^*
)$Nd0(
E &w3{P_
m%W"}4
]x:yDP&
_xPK%UV
,uo2[OU
hh+|}d
O$nIRP{
Og'5|dcz3
AyGwc!
+)h;>n
bX\;6x!.?}
N=G/5o
8SP9@F
Yo09MFX|
Nh~<}7
wjkZGT
1W-O?J
zY:|5<
k,QuP+
Y;?FD+4
r{k@T,
9KQOy9
9_oFdP
}'gQk+
_tdz+^
caPi9r7-
bU#>Jg
&(k'n7'
{Q20~j
{|OdZrq
wEvf`#
zvbt`j
&xr`kgs
_4T0?G
VS)np[2
5f&\ FG
ref>U[/N:u
egxI:V
de'2>0
x-mI,V{
GR`+;A
tQ~&b|n
-h?a#j
9+VU>o
BWeA;#
zR-2b`
Guz$O0Z
T41iO{
rLr]cC
ptTxU9
-0;+)Y
xm^t4$
'cVTfq
HQ?F1:
9`N_[j1
4\7Oj'
`<JO4M
7Kr^[X~
|Ld^ht
v7WKz1|
a~0GeH
><<]V:
yZg_pH.
xjsN|Ns
+4D(ZS
\Y^!([]j6]
t$t#t$l
D$t#D$h
D$t+D$\
.)D$H)
s`)L$4
D$t+D$\
)D$H)
9l$\w_
XPTPSW
ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.DLL
ole32.dll
OLEAUT32.dll
oledlg.dll
SHELL32.dll
USER32.dll
WININET.dll
WINSPOOL.DRV
RegCloseKey
SaveDC
GetProcAddress
LoadLibraryA
VirtualProtect
OleRun
SHGetSpecialFolderPathA
InternetOpenA
OpenPrinterA
222222.dll
UnInit
HrCg@b
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
VS_VERSION_INFO
StringFileInfo
080404B0
FileVersion
1.0.0.4
FileDescription
ProductName
IPLocal.dll
ProductVersion
1.0.0.4
CompanyName
IPLocal.dll
LegalCopyright
IPLocal.dll
Comments
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee RDN/Generic.dx
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_70% (W)
BitDefender Clean
K7GW Adware ( 00506e8d1 )
K7AntiVirus Adware ( 00506e8d1 )
Baidu Clean
Cyren W32/Trojan.FJFH-7405
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Packed.BlackMoon.A potentially unwanted
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Tencent Clean
Ad-Aware Clean
Sophos Generic PUA PC (PUA)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Dropper.lc
FireEye Generic.mg.b3edf0682d107909
Emsisoft Clean
Ikarus Clean
Jiangmin Trojan.Generic.debyj
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Program:Win32/Wacapew.C!ml
Gridinsoft Trojan.Win32.Packed.oa
Arcabit Clean
ViRobot Adware.Presenoker.75264.A
ZoneAlarm Clean
GData Win32.Trojan.Agent.I6FKD5
TACHYON Clean
AhnLab-V3 Malware/Win.Malware-gen.C4559874
Acronis Clean
ALYac Clean
MAX Clean
VBA32 Clean
Cylance Unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R023H06G521
Rising Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Riskware/Blackmoon
BitDefenderTheta Gen:NN.ZedlaF.34058.eqSfa04jtDdb
AVG Win32:Malware-gen
Avast Win32:Malware-gen
Qihoo-360 Clean
No IRMA results available.