Static | ZeroBOX

PE Compile Time

2021-08-23 16:21:56

PE Imphash

6ef74f7b87fa15b6df54d064a5b8ef31

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00001d6e 0x00001e00 5.54148404726
.rdata 0x00003000 0x000004f2 0x00000600 4.13833863478
.data 0x00004000 0x0000011e 0x00000200 3.07101525242
.rsrc 0x00005000 0x00000548 0x00000600 1.3747162539

Resources

Name Offset Size Language Sub-language File type
RT_BITMAP 0x00005060 0x000004e8 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x403000 GetStdHandle
0x403004 GetCommandLineW
0x403008 WriteFile
0x40300c GetLastError
0x403010 HeapAlloc
0x403014 HeapFree
0x403018 GetProcessHeap
0x40301c WaitForSingleObject
0x403020 GetCurrentProcess
0x403024 ExitProcess
0x403028 GetExitCodeProcess
0x40302c CreateProcessW
0x403034 VirtualProtect
0x403038 IsWow64Process
0x40303c FreeLibrary
0x403040 GetModuleHandleW
0x403044 GetProcAddress
0x403048 LoadLibraryExW
0x40304c LocalFree
0x403050 GetBinaryTypeW
0x403054 lstrlenW
0x403058 WideCharToMultiByte
0x40305c EnumTimeFormatsW
0x403060 GetConsoleOutputCP
0x403064 WriteConsoleW
Library USER32.dll:
0x40307c LoadStringW
0x403080 MessageBoxW
Library ole32.dll:
0x403088 OleInitialize
0x40308c OleUninitialize
Library MSVCRT.dll:
0x40306c towlower
0x403070 malloc
0x403074 memset

!This program cannot be run in DOS mode.
`.rdata
@.data
.text$mn
.idata$5
.rdata
.rdata$zzzdbg
.idata$2
.idata$3
.idata$4
.idata$6
.rsrc$01
.rsrc$02
GetStdHandle
GetCommandLineW
WriteFile
GetLastError
HeapAlloc
HeapFree
GetProcessHeap
WaitForSingleObject
GetCurrentProcess
ExitProcess
GetExitCodeProcess
CreateProcessW
GetWindowsDirectoryW
VirtualProtect
IsWow64Process
FreeLibrary
GetModuleHandleW
GetProcAddress
LoadLibraryExW
LocalFree
GetBinaryTypeW
lstrlenW
WideCharToMultiByte
EnumTimeFormatsW
GetConsoleOutputCP
WriteConsoleW
KERNEL32.dll
LoadStringW
MessageBoxW
USER32.dll
OleInitialize
OleUninitialize
ole32.dll
towlower
malloc
memset
MSVCRT.dll
LoadString failed with %d
Could not format string: le=%u, fmt=%s
restarting as 64-bit
not running in wow64, can't restart as 64-bit
failed to restart, err=%d
DllRegisterServer
DllUnregisterServer
DllInstall
]* S|W
SBG]a+
:,Z!Xz
!S^ E[
qX^|T*
m0E"&T
zwdA^f
]|TNt8|jKp=
npqg^p
G;dkyRa
a.9 3`
002oDU
H_d:BNv
IJ.1*}*'
. ]\:-AH
W8_brk)
U}&T_3af
&/_3af
U}&T_3af
=N3cq&_
=w'{kr
Un $q&
i&M,UN
JT_~a&O
Und_q`2o
$o%^%0zd
@A.U}OT_gaD
-iZ\XaD
{BUN?=4k
U}&~_3a,
~fr4O'`
b&{Db<
`c47mr
U}&T_3a
3^dc1J
bHbEb<
.U}OT_
TZ`a5O
$0Uw^W(=N
}6{Ui)
;n{)l{%
M0zN{4
} zb&x(b<
}&j_3a
UN-}q&
.U}OT_3a
}&j_3a
.U}OT_3a
UN&9q&
P^iZ\$S
6uUi)F
:kU%39
=w'{kr
M0zN{4C
}zb&x
G;m@`A
wu4x Ja
023< 6D`A
vB#.ug
pb<f_N
A.U}OF
U}&T_mLA
p[ycmA
{PAqGTkV
wz~m/4
m^!RGm
CTq`a5
eIsT!!
v:U%wc
u*IZ&@`
[\!RGm
@p%37t
i-_kL7%-
@`05n<
b<~;Ui
=pRt-S56
:,U%3}(
EmyZ[l
+&e_3aV
[MG;m0PA
i;m0PA
kqlWG;
p_|a)P
2K1`O:7
&i1N5e
UnAvq&
,DO'=
zbHbW,s~
GgmD3A
?tH++b<
\fUW)y
fng);}Dp
#9g&Q~J
Rvns[o
@N@3|e
E$Vv,Lm
Ui&{BUN?=4
xO-0PA
C&egu
x~fr4O
b<~0Ui
M0zN{4
oSU%w}
Y6b%r8
]-CdS\"
ieL.,K
P<,D}@
RvnsfE
TH[.G;n}5
XV2eiZ
.U}OT_
$M}6{Ui)
NyGEYk
2k@`Zg
+{c"Q]
(iCq.3
u!FO_G
+>;<!Nq%
]Y b7
'UNR9{
vT47K\
L1u@5[
OvxE(F
}&T_3a%
P>48eq
NmyZ4H
eBsW!!
.iZ\Xa
SP}x_x
YT%~a&
5#%;)]
TgT%~a&
sSBpEu
#N@,P3
+w;F0)
jbHb+b<
9~fw4O
t7sfB>
4NByujk
b<~sUi
[q[mG;n
t 55xU
U.A8=&:
02}i^;
!xO_G6
MmyZ#U
M0zN{%
@\8g+j
4[&de}'
!bHbW,
47XH'`
p^6@D)
S;}@#%
6]Ui)FqG
`Jf;2s
X(2[@`Z
7H[vi;m
Tx`a5s
.uqE3;Cg
q^NyNP
>6&TJH
#+0z+c4
8}ui+X
SH$Eau%K
[#%;)2
'L1u@%
[*){.9}
^{XZ\F
4&O6U;#Ci
P3~E/V
tY}P^;O
e~fw4&2
<RYs^s-
^=u1 *
`e$ bH
1OUq;#
zbHbg,
udU}&F
-!bHbg,
mEOxt&T_
\NOg7<,Y
^'TV{{8
/_CH|Y
bs<dc
sf]{P3
!FT_cd
QFP bs
/x<i1N
SNzeGc
p(zWg[g
vdRU34
tpAqqh
DN5\<|
_l@e$;
OT_Z~5a
~fr4)3
U}&6_3a|
`K bs&C
dAM)-b
(xti1N
0.%1mFD
-cmHb
~s<Vy92s
kSdOTp|
XR!7om
\<O~7<
6bxoX8fUi
Z*<<q?7y{
Ozq;<!
G57sBG
&zpRM)
JMz~y"
J^e89&2n
F^L<~m
>}uiya
jcgrY}
M_CH;;
g6KGYX
w1mF@q_
}&/_3a
@;n8YA
]wKVdct
Tx`a5s
{) +L+0a
Wo(VL0
PwCyOz
myZ#/9C
M_lE$S
wudyrJ
!ysXg
np]b
UnA=7&
IG>32a
=NAcq&
uwt(i#C
0cA5g"%
nnw1mOE
zmjW`U
2+aUjP
Syzgu<
]2s?"d
HPB[:}
5Y"7sfmw
9tn+Wl
.\}d6]<
0(xb9sH
P2p@`Zn
5kT_+V
h<55j$
pp]|8A
bHbk1<~3
H u14t
`U8?cO/
}&T_3a
U}&T_3a_
EtnZ<x!
fU5scWwa
7)V8F]xa
ow1mv
_lqj{7
c4lYLa
2cq&)x
xF&T_.
wu661J
UNU=i&
SjXhvBqv
q:[*fa
cqz*wx
nts(i1
c4lBLa
x/@0iZ
IjUi=W~=N
NYA*!k
q:[*fa
!rj%>p
vBqJ%G
q:[*fa"
x/Y'iZ
HbE(3~f
_lqj{7
UiSW~=N
%-|\6b
&q&1wx
c4lBLa
:&$DV&
q:[*fa
GDobH(
q:[*fa
UiuW~=N
q:[*fa
!rj%>p
YOq&;wx
2s-92w
G;"8q
!x=(i#
c4lYLa
G;;8q
!rj%>p
fm^Jt`
UNU*S&
2q&+Nx
sTk1QW
>9J-<Y
qL,='Y
+m0Q_7
JoZgLE
bD=5Q9
U6aJ5}
Ey>h,&
:"{&;w:
H0aXdS
Iywo`>d
B%ur&~
hB$D0q
bHbpb<~
UNRcq&
mU*&5-
z}}B}|
x*;|oQ
1n=kv$l
*H1p@B2v
l%>QC=
}h2sl0
K,OUOOF
?7K$'}
Oh=q`5
.U}&T_ZaO
UV1w1jY
b<~jU8m
zbHbgb
ykZWRhvB
]Nk&A=
uz~fU4
@`a&StR
&T_+aX
x)~Z T
@{'U@+ X
sts|omM
Qn@&hqt
r)t5r^
aU_S{O
YU*mSh`
&T_{aF
bHb\bP
lj\"S}
r)pcr^
U}&K_ey
+YU*m{[`
0zFc+W
}fMS<<
U'YR_3a
0zFcss
bOn@&h#~
bHb\bV
r)16r^
U}&K_!
+YU*mG
r);fr^
kYU*m$$`
GH?2PA
bHb\bR
U}&K_p
,+YU*m
s[?cq&
fIUK@K
f7 =bQ
6lv)68
(vmHd1
@F?<MG
]L)%zY
*{-p\c
1(E&lF
5PhBsio72P
(JMHTy
'EUNQd
B@L(G@
A]U),$
n<~fUW
^?K0Q&u
kClwMcQp
~eF~N;Kqw<
feF-N;
i~D+]_
vD](Ub
U&m0Y
gA~d8i
S4_GUz
,STIFM
Pi-T(LiBq
EtQYSM
kn]9uK$
}c=u3N
gsp$L=
+a2s3rS
ukLic'
Y LdH{Z
$aq<s^R
Uh__w1
U&K0%
Uh}pV;
H\RY/R
Xpoz*
}L0e(xf
sMz#uK
{RQK`p
3(w`{(
5g-vmw
K^jwN
K6GMm{
D5(UuW
8"MwW(!
Mc}KK}
G1wsYi
Owa|v\my
bxM;sE^
x>N\Te
3}tzHX
JXs$U{
%}hMlJ
V.jANB
o7Vo"1
oil/Rs@
wzB!(R
q)5o_l/Rx
~i(!\]a
@1&}l!ND^OR
&T_3af
b<~fUi
U}&T_3af
b<~fUi
U}&T_3af
b<~fUi
U1&}_7a
a6R)JV
x>zLv1
U}&T_3af
b<~fUi
U}&T_3af
b<~fUi
U}&T_3af
b<~fUi
jjjjjj
\SysNative
\regsvr32.exe
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
McAfee GenericRXAA-AA!95FE547BBAA4
Malwarebytes Spyware.AgentTesla
VIPRE LooksLike.Win32.Crowti.b (v)
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
CrowdStrike win/malicious_confidence_60% (D)
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/GenKryptik.FJKM
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Trojan-Spy.Win32.Noon.gen
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Trojan.TR/Crypt.XPACK.Gen7
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.PWSZbot.dc
FireEye Generic.mg.95fe547bbaa4db49
Emsisoft Clean
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira TR/Crypt.XPACK.Gen7
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win32/Wacatac.B!ml
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.34088.oqZ@aey2bIei
ALYac Clean
TACHYON Clean
VBA32 Clean
Cylance Unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Generic@ML.96 (RDML:oYX0CxBomoRkxTlqKeAC9A)
Yandex Clean
SentinelOne Clean
eGambit Clean
Fortinet Clean
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
MaxSecure Clean
No IRMA results available.