Static | ZeroBOX

PE Compile Time

2021-08-23 16:03:38

PE Imphash

6ef74f7b87fa15b6df54d064a5b8ef31

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00001d5e 0x00001e00 5.53671380845
.rdata 0x00003000 0x000004f2 0x00000600 4.14416927261
.data 0x00004000 0x0000011e 0x00000200 3.07101525242
.rsrc 0x00005000 0x00000548 0x00000600 1.3747162539

Resources

Name Offset Size Language Sub-language File type
RT_BITMAP 0x00005060 0x000004e8 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x403000 GetStdHandle
0x403004 GetCommandLineW
0x403008 WriteFile
0x40300c GetLastError
0x403010 HeapAlloc
0x403014 HeapFree
0x403018 GetProcessHeap
0x40301c WaitForSingleObject
0x403020 GetCurrentProcess
0x403024 ExitProcess
0x403028 GetExitCodeProcess
0x40302c CreateProcessW
0x403034 VirtualProtect
0x403038 IsWow64Process
0x40303c FreeLibrary
0x403040 GetModuleHandleW
0x403044 GetProcAddress
0x403048 LoadLibraryExW
0x40304c LocalFree
0x403050 GetBinaryTypeW
0x403054 lstrlenW
0x403058 WideCharToMultiByte
0x40305c EnumTimeFormatsW
0x403060 GetConsoleOutputCP
0x403064 WriteConsoleW
Library USER32.dll:
0x40307c LoadStringW
0x403080 MessageBoxW
Library ole32.dll:
0x403088 OleInitialize
0x40308c OleUninitialize
Library MSVCRT.dll:
0x40306c towlower
0x403070 malloc
0x403074 memset

!This program cannot be run in DOS mode.
`.rdata
@.data
.text$mn
.idata$5
.rdata
.rdata$zzzdbg
.idata$2
.idata$3
.idata$4
.idata$6
.rsrc$01
.rsrc$02
GetStdHandle
GetCommandLineW
WriteFile
GetLastError
HeapAlloc
HeapFree
GetProcessHeap
WaitForSingleObject
GetCurrentProcess
ExitProcess
GetExitCodeProcess
CreateProcessW
GetWindowsDirectoryW
VirtualProtect
IsWow64Process
FreeLibrary
GetModuleHandleW
GetProcAddress
LoadLibraryExW
LocalFree
GetBinaryTypeW
lstrlenW
WideCharToMultiByte
EnumTimeFormatsW
GetConsoleOutputCP
WriteConsoleW
KERNEL32.dll
LoadStringW
MessageBoxW
USER32.dll
OleInitialize
OleUninitialize
ole32.dll
towlower
malloc
memset
MSVCRT.dll
LoadString failed with %d
Could not format string: le=%u, fmt=%s
restarting as 64-bit
not running in wow64, can't restart as 64-bit
failed to restart, err=%d
DllRegisterServer
DllUnregisterServer
DllInstall
(dgC9n
$W$Qo]
Y@'#At
eMRdR%
_RP9O.}
6mmXC+A`a]
b`Uli2
$9@a0|
A-a~[sT
cW5YZA;~H<
)D[H0n
2N~KGPo
jVtdP8
,Wy(,z
)D[H0n
Q2R]fK
P[_Ozm
1wLg&0B
:2`]fK
>u,wTeb
sqA<J\[
I-Q9J!w
tb 0L2
cQ<U}he6
,ny|,z
:2s`fK
z00O8F!x
)oIR6t
GW(oA<;N
lh+`9R
n]Y"K
obcq!i
'N2KdP
3\H-[$!
q,9+r]"wY
3N;Q:e
.srJjCc
3E~[!)
R2v]fK
%!'nu;(e(
,.3-%2
zKAyIF
,.3-%2
#y5 _
wL}M~B
8F!^ic
>u,GTeb
;<e6
CXz~!u
%Gy2 d&
`0?iY;
tGn1!A
~9)D[H
2=_Y9G
I-Qwm:w
xE\PMPqYI
<-t]:2
G$2 dd
2:lyFP8;
q7Tsr(
{!"=N D
0ey#5K
~C_-8tt
A M~p$
?lY/u^
kQI\F!
<U<Oe6
8wLkAAa
e>hD8K
CR3ex]
]TenKdn
u!@|>0
e&1|4L
,~JrBX
Tebw+@
}NlPdP
'6?in{
Y={j!i.
'rJVge
:2/]f
#CKswH-
MrX;&^
DfK\]q
'fK\)Hy
is E[P
:2k]fKBT
o&Uxnk
(o#%#"
/fnMfg
|P><U
(57ASx
}F>6gX
6<JaKe
CxDd^_
-<RjKD
tpIoe6
PG&RYA
Xzw-'-
U]f:n6
OnW;LX)
&4rtlc
ZDE~t.VC
}I|]8^
:@5]fK
2N~KGPo
cBTpl`
SBTpl`
wL6Qgo
skK\>s
'5|sTE
'5|sTE
uZN,nQ
|3Z3."
U2nQ2A
(cB<U
zUE~(4
On^01GO
m]j3ta
K|D&Qr
]Tjn?dn
kD{sRi
Z,{PY>Z
ez]nhc`
[07<EY
6srJnz#
F}\!XPg
"\;z']
E~o3m4
0pVMo,:
%akQIUp!
:2"]fK
B&kS(5G
zc.<U
N(?&IF}
&9v0BQ
RB:]fKBUp
_j3ZU."
yJ+SFI
/P'm}f
D2,z2A
j3ZU."
f0?lG8j
q9k|CR
vE~[r*X
fgTpQv
pN: X[}
PGq,qo
&aS(5p^
n4nUL
1(kD$?
Bl1K#,
Ynu;L,9
^5wJg|P
e\o?Qs
]flC]+
[PG&R\
^]jjw
).+<`C
n#`I}[d}
A0PW8<R
.s]UUx
6rk"wY)
l}IqMU
3l(),@y
vUF. 7
xF3G&K{
2N~KGPo
q$0+c
u!@;>0
xw} (&
m\+7TI
l)=BUd
pt.W<b
"wC6PH
RDfKBT
-%Y/g^
FdEoNm
k/TQSNr
U2,:2A
uv_buo^
aSR-U
/s-9ew
qY1Ti6DE
5y2CTfKBT
Uzrs<R
1iw^:j
6K?g(U
_j3~w>k
<Rk5#-
H@SxY:y
<#k5#-
-`fK4]
<#k5#-
gvdyP;
iZ}_f@
]j<KuK"
#-%+=StH9]x
gIKak(U
P'rZk[
wz%&0B
<l::2x
<#k5#-
b#-%+=SH9
H@SxY:y
w1'rtkH)d
]j2KoN"
P'rZkH
"Dh3>%
P'rZk}
O$(_>P
<#k5#-
4N s"Q+
3)W|s F[
"Dh3V
H@SxH:y
@F%\hw
Y5]#,C
znqVW*
z-%|aS
gvdyP;
G=zm4bI
jTGzK"$#
<#k5#-
r}_:9#
4N s</+
K7H6?
4N s*S+
8rX~&P
gvdyP;
$tnxKv
:7>%z6A
"2krMq
V> %b:Vdv[
#n'^Mf?
790;FX
Tj}R8V
T2gyhB
~WGW5]
}~b0Ib
Y_t1P`
Uqex<9[
#SAL-,
;~KkWTKj
@g@L(K
S7q@{h_
2J\A`D
M|?X|B&]
*!`C}n@B
|\%/dp
CoB6FV
xGO.)!
<3u( w
0-BY;g
YTg4j
(jw:}
0WUGy<
jm-|K"
`k]Uf<o
4`C/)e0
@3a'}
{@]Px}
P[}Hu}
y^bdJ>
GnwHN4
]fK-Te
Gnws}4
H|Ot:5
i<CVjO8
]fK-Tb
:2e]^ep
wT}45d
\sw y^bd
]fK-T[
\s qy^bd
(r;yQ@^>
y^bd^t,z
:2e]P<p
*1;yQ@
y^bdkB,z
P[}x>d
p sW 0
:2N]^'BT
E!t(e/
H?=z+,
\Tp Io
Dgz+(U
BW\&dO1
z'} F6
>Pp=G,
4gQ$tOL>
Cu 23iH
Ww[!,c
ePdPew
Jn-h(~2
cY[33tP$
=3!n w
)lIu8C
!^{/y
/j<3qC
L8P\6_
`:&Lef0=
vosc J
]*z%mZN
azxp%k#
B%VZxH
aN-AdS
BV:G</
27IJa,
\'f.X/"
=HjMs2
1q-r6Jvk
<L:8W^
*!tnnf
CZdCi$
2Y8/24
)Z]Hs6
|5ZtmqY
;RCuG#
o_Y )) }TmFeR
>o`W%8
?]8^/'P
8Z]>PR
f!9/;}
,F}=k%
@c^A!?
\f xY(z
2JhF7
CH%Y=yh}
Eg]kge
P8@pPB
!xM|&F
"~j6^qn
R9!'L:O
Q/';-a
!x0"Ob
bS>TW:
y:qFm%QSJ
21q-r6
\YYzd|
zKIC`v
Ybee$S
IM2 ?QM
d{22{XW
e9 PHE
r*}Ut{
o78R`c
sx2EC0
g*~OW=x
i>u?SU'
<br4[U
*e8;6U
sy}2}B
M))u}
3f#:nHM
F3P~V(
lFV!(Q6z
w-kh0(
wW0;"~
Lvs4KV
m\]UosCK]
jjjjjj
\SysNative
\regsvr32.exe
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Agensla.i!c
Elastic malicious (high confidence)
Cynet Malicious (score: 100)
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Spyware.AgentTesla
VIPRE LooksLike.Win32.Crowti.b (v)
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (W)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
Cyren W32/Kryptik.FBS.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HMEN
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Trojan-PSW.MSIL.Agensla.uzf
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Rising Trojan.Generic@ML.96 (RDML:vmrCKFUqqEf2AFhR4B86GA)
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Trojan.TR/Crypt.XPACK.Gen7
DrWeb BackDoor.SpyBotNET.25
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.PWSZbot.dc
FireEye Generic.mg.3f5998401e2da3c6
Sophos Mal/Generic-S
SentinelOne Clean
Jiangmin Clean
Webroot W32.Infostealer.Zeus
Avira TR/Crypt.XPACK.Gen7
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.PSWTroj.Agensla.u.(kcloud)
Microsoft Trojan:Win32/Woreflint.A!cl
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Trojan-PSW.MSIL.Agensla.uzf
GData Clean
AhnLab-V3 Clean
Acronis Clean
McAfee GenericRXPT-XA!3F5998401E2D
TACHYON Clean
VBA32 Clean
Cylance Unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.Inject.Auto
Yandex Clean
Ikarus Clean
eGambit Clean
Fortinet W32/GenKryptik.FJKM!tr
BitDefenderTheta Gen:NN.ZexaF.34088.oqZ@aGN!HBki
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
MaxSecure Clean
No IRMA results available.