Static | ZeroBOX

PE Compile Time

2021-08-19 11:10:51

PDB Path

C:\rymyj\mskdla\kazh\1190cd5e2b8f4ba0b0ceda1d62e99267\nmnvbf\fkywzuik\Release\fkywzuik.pdb

PE Imphash

f86f9a1397ea2f648b8914df9ad78914

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00002598 0x00002600 5.68939698635
.rdata 0x00004000 0x00000446 0x00000600 3.70046234623
.data 0x00005000 0x00000db4 0x00000a00 3.8165803735
.rsrc 0x00006000 0x00000708 0x00000800 2.80715276576
.reloc 0x00007000 0x000001cc 0x00000200 5.90861309323

Resources

Name Offset Size Language Sub-language File type
RT_BITMAP 0x000060a0 0x000004e8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00006588 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x404000 HeapFree
0x404004 lstrlenW
0x404008 WriteFile
0x40400c CreateFileW
0x404010 GetLastError
0x404014 lstrcatW
0x404018 CloseHandle
0x40401c LoadLibraryW
0x404020 HeapAlloc
0x404024 GetProcAddress
0x404028 ExitProcess
0x40402c GetProcessHeap
0x404030 EnumTimeFormatsA
0x404034 WideCharToMultiByte
Library USER32.dll:
0x404050 MessageBoxW
0x404054 LoadStringW
0x404058 MessageBoxA
Library MSVCRT.dll:
0x40403c wcsrchr
0x404040 memcpy
0x404044 _wcsnicmp
0x404048 memset

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
C:\rymyj\mskdla\kazh\1190cd5e2b8f4ba0b0ceda1d62e99267\nmnvbf\fkywzuik\Release\fkywzuik.pdb
.text$mn
.idata$5
.rdata
.rdata$zzzdbg
.idata$2
.idata$3
.idata$4
.idata$6
.rsrc$01
.rsrc$02
HeapFree
lstrlenW
WriteFile
CreateFileW
GetLastError
lstrcatW
CloseHandle
LoadLibraryW
HeapAlloc
GetProcAddress
ExitProcess
GetProcessHeap
EnumTimeFormatsA
WideCharToMultiByte
KERNEL32.dll
MessageBoxA
LoadStringW
MessageBoxW
USER32.dll
wcsrchr
MSVCRT.dll
_wcsnicmp
memcpy
memset
(none)
Plain-text output
XML output
(unknown)
Failed to retrieve property %s
IDxDiagProvider instance creation failed with 0x%08x
%%%us:
Time of this report
Machine name
Operating System
Language
System Manufacturer
System Model
Processor
Memory
Page File
Windows Dir
DirectX Version
DX Setup Parameters
DxDiag Version
System Information
System Information
File creation failed, last error %u
IXMLDOMDocument instance creation failed with 0x%08x
VirtualProtect
WHQL check: %s
Output type: %d
Output filename: %s
DxDiag information collection failed
Information dialog is not implemented
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
1 1&1,12181>1D1J1P1V1\1b1}1
22(2S2Y2n2
2R3Y3^3f3
4F4k4u4
585<5@5D5H5
5?6_6y6
7 72777=7W7z7
7!868<8I8q8
:-:::T:g:
;+;R;y;
===M=l=
0*0Q0x0
2#2(2.2:2~2
3#3K3~3
3&4-4O4U4i4r4
5+5>5E5o5v5}5
kl:F46
\2F4;C)
ZvTKx{
pOtu!Wm
e0WKn?@l\
LVHAU(&X
aFPVd;H
.%MmQ.
3_|0ZZ
b+N<"
7J,(Q8
/6ruH2
^yaRv_tX
G 5zE!
=Ku q
xP4a.d
9 aa9
#,]pk9"
,D8)GFm
f;T^-Mz]+
0)Xf<
l\3Rq`
4D%t}/
BHQaoT
vq_s):$
3G{R}/
2D+B6t
E?x0H]
dD ;f)Q
e:N2t8
I1qopk
@hvFR@
d[bTAP
o<&W8)
}tB\^oB
fqQr)DZ\z
8U`LB&
4ry<)b
|Q;;^&
*O]sd_
^b`LB&
y<YzJV
#(bq(f
g osxB
I2S_bh
5+7co64r}
.1DuZ-K
p:87c+
B[-f=}}
Tt7,gc
_xn*)'Hp
w(ou e
Zv5D>q
kM\{"W#
Pg&HA\
1FtPnt
SPLIunbntRp5
$o6-`.
7Jg(ME
0uI5 l
+eb,tj
r+e~7F
HNC~+5
6JZNfH
sRBHR8K
,El8|
X_-s$?
tzuFA;
4^3$B:
0~A!s$
m[M,GL
BA-FhO
`n,,h!M,h
@5:}%t
_1+Jq1
B?IYBH
k,D])Cu
Sr4PWr
|;eC('
~6 0i
'%[ y
,3=W)h
25Qs\7
EmXZ"H
Qs@Y~)}p
Rwt=WN
^HW$|kC
b?<a~'|
uU({#\
[jlBEi
(A-K\s
KO"LKZ
x9aGMW
ii!rF_
CRLjD)
!}s0i6
BHQaF+
#A)'k`
SWkx.g
K9kHvi
8b%;)Q
bPgJMNp
e$!BGd
ko.UKO
|9SK+b
h~|j{S
QsR7!B}p4
?r4Jgz%
|91eXr
FAJjo
fs_"%"
-^lM*:
l_#BgP|
V[@IBD
PHpNzR+
'GF:6d
7@p.{)
HDA^-KvG
1^V|MYPDb
Jk_'H>
Mq/Okr
za=)BJ
rLZ;w7
+UOfNgH
y$f`h7
U!'!j_
ii!AF_G
rPWgH`
6#wf4?
UlwM3p
&nTrfH
7@p.%X
3gkg^En
1D84cx3
C<yz%EXx
#bTyfq
aphcXg
=\]--@
7c.yb6
\4p]+q
7cFyb6
65f4R
d6B_hF
J'Cnc/
V6ud`<
D09z%(M
*(y;C#
i@BS{OJ\_
$Q%`D+?
"B0(]@_'L>
B%,\5j
Qw]A-F6
0V|>/-Z
b18tAn
9D%'
f(}g;W+e
rfr}g;
9X%Q
}g;W+N
9Y%gT
V#X2a?
o>knh
C9?%*
01Ot%n
o#kVnw
t4F.fQ
8`Rh,'m:
\@Ef,U
3)Qo}G
>#F`bn,U
_,9z>M
XzgJ8aO]
Q^kY52f
N/GDt{
ryC%(3A
|w'2oG
?<$Xfg
q/,)^M<*
s/;8k;P +>
~e]08H(p:
<wIaN'I
d8Y/c
J)M~1H7~
xn>8Q5
1#7rP/[
>g|%hA
/ja"u#
Dz2~;r
~+j;eGvc
~)[%m\
q*D;ZZ
!vsah>
LFDu02
kGNYN
STI^k6
MG^)~X
`&nEMmRL
QXVD0!N
(Le*v-O
swC`N4
J<NE=31
vvmoJ@
27yWNB
C8&cIS
#<`Yx_
!`de0W
g"6jZx
G&r`dr#$
o9 "?x
[sA.Dc*`y-bu5w
!3}F|;
L9V0FCK
3C5>+@
.?Sc~JM
.#\^R&_
+9MG^;
o2U#xr
j->W&7
}n1:=h
=^C;SI
3=Oc0r
O(K FS
9vDX!9
'v+r~v
>'4a9t
Q\l_SQ7
_4v~1r9
L?TC4G
InMS`)
YB#$'8QE
q$y2Rh
[R:g9(i
9BB)S/
B5uTKW
0J<_)V>
:f#PoaqO
A$1 /D
hfXn:H
p7"%^2
./NaxM
6*Tw&b
Lbw$By_
b-e)L
QQWL[;
8\A7[]
"bL;`@@
d'"Ln{
=~>Lf!j&Mm0
M;\~S$)
[nU3K#
=\W&pS
tpOTcQD
hQd2yc
rzyMs1
P?T0i/jc
P/SW+dd^@9t
&y4f[E@
CNgz 
Vcd@U5
F&}!^R
b[^6*"
6)D:GrR0
cIJu6M
i"jHl{b
~s4aZ*
E4!<'!
-0%+'&3X3
W(t%[Z
xo<Ldc
f|5`D7{
vi)#{2
~w]U]Sd
n ^UMS
0[S;i>
; ,D) r
"Ar=T|
`eW0[}
DLTS)I
VIY)qE
w"D%rm
8"O#x>
<K#k{=
2_3->
EbsGl
-%3,w?
s6W>nX
6kklHl
oT6QTG?}
v{RJ2*G
{YiD]77"
nN:ss+!
[\&%1?
`$|V+f
H4A&T:@
E0@:e(G
_bV$CP
{IjXy7F
I3KG"Y
Aj_I%g
deYKE3
q[(Cudx
]Kw);r
UtfP(U
vrtM06
# 3Tv/
Xk2OE:'
'.fWr] ]W
-_VLWC
9aaMl;f
v(j\>F
"Y:4vW
=ubm:,
:Cw+zU
?[Ye.o
IqnRnE<
9,DA2.!n
bJwImm
V|UuFW
OMelnh
Gh~YP|
cVA/UqU
5,)f-r
GZF/f~
QY>#Q2
XrbCkm
`arth
jKpK0p
.EXR]L^
^2W 'Ly
<jl3H_
8|fbS
`+eA;tK
jWqN&N
h`4[nFNo
j=k7ojd
$ED_X To
[ecb?)
U;EDkYm|
,_H:Jg
I6pmC-
Pw 39#P
Z~ny4*
j]i%u&K
B.u2cB
].rHOH
3pSsVx1K
&;.bSR
?Eit`t0
ni8X3f
S<s`P`
uGcxOe
^0M,q2.
mXk}JZ6
YPe&N?
[pTSGe
szTimeEnglish
szTimeLocalized
szMachineNameEnglish
szOSExLongEnglish
szOSExLocalized
szLanguagesEnglish
szLanguagesLocalized
szSystemManufacturerEnglish
szSystemModelEnglish
szBIOSEnglish
szProcessorEnglish
szPhysicalMemoryEnglish
szPageFileEnglish
szPageFileLocalized
szWindowsDir
szDirectXVersionLongEnglish
szSetupParamEnglish
szDxDiagVersion
DxDiag_SystemInfo
Source.c
Source.c
total_len <= sizeof(output_buffer)
total_len <= sizeof(output_buffer)
MachineName
OperatingSystem
Language
SystemManufacturer
SystemModel
Processor
Memory
PageFile
WindowsDir
DirectXVersion
DXSetupParameters
DxDiagVersion
DxDiagUnicode
DxDiag64Bit
SystemInformation
SystemInformation
DxDiag
Source.c
type > OUTPUT_NONE && type <= ARRAY_SIZE(output_backends)
Source.c
type > OUTPUT_NONE && type <= ARRAY_SIZE(output_backends)
kernel32.dll
dontskip
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.1ba29471321f0be5
CAT-QuickHeal Clean
McAfee Clean
Cylance Unsafe
VIPRE LooksLike.Win32.Crowti.b (v)
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_80% (D)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HMDQ
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Backdoor.Win32.Androm
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Generic ML PUA (PUA)
SentinelOne Static AI - Suspicious PE
GData Clean
Jiangmin Clean
MaxSecure Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.34088.ouZ@aG8GZqhi
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Trojan.Crypter
eGambit Unsafe.AI_Score_56%
Fortinet W32/GenKryptik.FJEK!tr
Webroot Clean
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
Qihoo-360 HEUR/QVM20.1.5DD2.Malware.Gen
No IRMA results available.