Static | ZeroBOX

PE Compile Time

2021-08-23 16:14:25

PE Imphash

6ef74f7b87fa15b6df54d064a5b8ef31

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00001daa 0x00001e00 5.55424869784
.rdata 0x00003000 0x000004f2 0x00000600 4.14459571925
.data 0x00004000 0x0000011e 0x00000200 3.07101525242
.rsrc 0x00005000 0x00000548 0x00000600 1.3747162539

Resources

Name Offset Size Language Sub-language File type
RT_BITMAP 0x00005060 0x000004e8 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x403000 GetStdHandle
0x403004 GetCommandLineW
0x403008 WriteFile
0x40300c GetLastError
0x403010 HeapAlloc
0x403014 HeapFree
0x403018 GetProcessHeap
0x40301c WaitForSingleObject
0x403020 GetCurrentProcess
0x403024 ExitProcess
0x403028 GetExitCodeProcess
0x40302c CreateProcessW
0x403034 VirtualProtect
0x403038 IsWow64Process
0x40303c FreeLibrary
0x403040 GetModuleHandleW
0x403044 GetProcAddress
0x403048 LoadLibraryExW
0x40304c LocalFree
0x403050 GetBinaryTypeW
0x403054 lstrlenW
0x403058 WideCharToMultiByte
0x40305c EnumTimeFormatsW
0x403060 GetConsoleOutputCP
0x403064 WriteConsoleW
Library USER32.dll:
0x40307c LoadStringW
0x403080 MessageBoxW
Library ole32.dll:
0x403088 OleInitialize
0x40308c OleUninitialize
Library MSVCRT.dll:
0x40306c towlower
0x403070 malloc
0x403074 memset

!This program cannot be run in DOS mode.
`.rdata
@.data
.text$mn
.idata$5
.rdata
.rdata$zzzdbg
.idata$2
.idata$3
.idata$4
.idata$6
.rsrc$01
.rsrc$02
GetStdHandle
GetCommandLineW
WriteFile
GetLastError
HeapAlloc
HeapFree
GetProcessHeap
WaitForSingleObject
GetCurrentProcess
ExitProcess
GetExitCodeProcess
CreateProcessW
GetWindowsDirectoryW
VirtualProtect
IsWow64Process
FreeLibrary
GetModuleHandleW
GetProcAddress
LoadLibraryExW
LocalFree
GetBinaryTypeW
lstrlenW
WideCharToMultiByte
EnumTimeFormatsW
GetConsoleOutputCP
WriteConsoleW
KERNEL32.dll
LoadStringW
MessageBoxW
USER32.dll
OleInitialize
OleUninitialize
ole32.dll
towlower
malloc
memset
MSVCRT.dll
LoadString failed with %d
Could not format string: le=%u, fmt=%s
restarting as 64-bit
not running in wow64, can't restart as 64-bit
failed to restart, err=%d
DllRegisterServer
DllUnregisterServer
DllInstall
4Asn-a ("
1`'^x_
x/"`h'
Bf4S*C
q5x4^I;P
}nQ<TA
!;D@77b
lzpVMc
7?*&]/
lK'e)K
FryALo
o='ey+8
X`{SA9
K`DJRG
7?*r]/
K]?YIl
oi\0?*a
-E-$?(
yO^1pG
6dSzR4
&]'1L\
tFhB7Y
-V}R`ge
&]b1L\
\Z?*a`
<|n.i
l#utDNo9
a+dx24
V^*&Qr>p
O[HZ"q8
'9~K/T
qfS+g!
>V=*&Qj
Y|6dFY
E6_0H=_M
c$%ItWa
c$%ItWa
W"!QK|*
_;bypo
wQj0H\
.Iy^5'
lu%feg
@n@vxO
s0|<RiW
-Go&]'0L('
t\JRx0pbFAi7
Kr&M$.
z:2xts
m7?*&]/
zi0\8?
VtatzwV
<VS*&Q
&]'w/K4e
fdg.{@
c$nItz
&2<gq!
N,?*&l/
O,al#|
8'pqhCc$
i.o98HF<XN"
_}~c -pm
27arH%
_0Hq=M
y"`f7G
=Rt$M|
nLtdI!
Dr4JRx
%kcpt]#,[
j6CVT$
_0H`=M
HDIlM.)
(gl=\U
$.OTal
hAqf|[V
\xKHl=
Fg8GLt
]"ItW^
Zp\~hl
Dm|yWi^w
Z&]beD4
Tz x40
c$qItQ
2+0HQW
>V=*&Q
="57$S
zc$"QtQ
-pmZ2;
c:>mtQ
}R` Ov
-E-$V_
j^]8-O
x|<]nH
_0HRcM
mYlvBf(
i.&<7xk
^,.Dl=\
;&zf26p
&(-E--
|3DNo;
\yDPWo
ul` 1Z
islfi.
7xky]/
p:tdQ(
m\Ls=M
{UYwEwC
\H@ea3
_iaV0_
J8z8+^
@PW,ALt
ggMz[T
TWpCZ[
Zo=27aP
~zg|-p}R`
oEiCbr
,iioY/
uE2_0H
Iy?*.y/
gE=n8H
?g-Rn,
&uEXNoN
]lYLePA
$"vtQa
8ULX0(*
M@N/tQd*V
j=ld!E
6{9\[p
Rxcc@
KrXHMM,.c
{WTRNu
0*tFAD
TuBc
E8H4ea
d/Ot{lo
mYrC^
2,ii%w=
[p]<{q5
Hl;.cV`
%Q$MM,
@N;tQd
siY`zr}
|URiV"U&2?
C-X]S2
^t(tzd
P$_5Dal
r*\>6Q
Qxf|@
X|*&+#
Z}XN5/
FsLqf<
jsld@EJx
rX2WM,
N:`ALt
TIj{WT
24[BSr
0_80Eio
=n+;mM
6folci
\yXZW2mz6
JSPoUvr
.>C6i2
uEw}'H
;s4.tQ
*-E--Z
8WXNv/
9|d#N
SYZbt(K
nmqi{Zza6D*
maC/bN
80ws.u
rXOWM,
H._%Kn
LZjc\~
7?s']t
%lM|j$
_@`RqS
QMnEc@
_m9-=M
t7WYl\
-R}R`w NA\i
q(Snj*{T<
-d|S\
'-pHSF
EJ_0H!=M
<;7`r4JRx+&^6
6:olc?
vIpa*T
=0F~Lq
cNeomR
_.;oCXiw=M
cNeomR
=QuYuq:
QeayC^=M
=KHJJR
$jQY?,
KaSHtM
C=-EnH
kc|LZtQa
=AqrFB
o,FFi^
0H3$][
KaSH2M
.q*nvZ
&]/ %-'e
:KLt4d
\hF{A^
p~k%#'/
tp,^BHl(
Ta#ywE
y,,ZBHl
rZ_xHz1
y,,vBHl
.q*nvZ
l?UDDN%Y
'io@Fk
.n*nvZ
z=NF~Lq
u,Aq:F
M%QY?,
a}~0_0i
si.wuz
%*kc$L
QaVe+]a
p~{%#A/
,i^}Lk_0'
#DNRN@
-a&2?V
p~k%#h1
0_8iuaM
WM,K~(
l]|EXN
MPQY?,
m(ti2|
"raw?,
0_8iJaM
?5Lt4N]
y,,"@Hl
.q*nvZ
_0iA"M
-a&2?V
^*-Ez$
m'Ni2uv},
i^}L2_0
;ulLq:
.q*nvZ
Ni2uv}>
0H3S][
^jM$KO
T,*^*N
;@,Y9)
P]2i=kF.
SyDnTnKZ
A]oxmh
ZP@zVF
<\iv?~
"T=VFE
hVH[nZ
qs@n$]
|w\DJ9,
WtPV!i
SIMHo]
8?~:KV
M?j[1x
!=38L;
\]'{JQ
3{cyi#
`~V|OZ\
r4sRPa,4
K%|lb7
KOmE10
i`J:8G
gz?bSd
pnT%%+
]$A^(o
TqYBrn
GJyWM(p!
0r^+BtI
Q=WUq@N-JX;
oh9OT_LE
Z{fOT-
#NH27t
NWM$}?
!lH@2
Me$iQ(4
]o6/Zi
AG&$.O*L
j1$PtI
Pn{Ron
v$z<1JS
7G&u%L
JRh2&7
;zJRi2
DN=blY
K$.}_d
_0H;=P
t,"y$*
PHTRi2
*&]t[f3
$W$*b:
,Uk8EE
\Q^].u
TRi2,\+
42s,6u
w"W>A*6
_:fAZW
hQ!X.u
_0H(=k
Qhral
'eoKGux
-$Lqb]
YbJ2u
_0H(=+
jQ;*@Hl=@
,h`am~Y
jQXd@Hl=@
1u:H85
-$LtO]
RoYbJ2+.
_cHZun
-$L0f]
,hWam~Y
RiWbJ2
jQnI@Hl=@
JR-25j
_cHzcn
_0H(=E`I
_cHqun
1u}085
-$L2']
_5EI_u/y=
Ic]16~
|I6h0Mq2
U3d59o
,EQXbH
cG|/x;
IyxE`KH
6O0')5
Gn1-ME
!F1W*v
Qmcju(
cME)K#
PuVi25Si
N604vC
?iKx['W
[:YsPW
_0HQ=$
w.,^l|
t0wc=i?
ob|TB-/
.s5U$S
-7{8{p
B^y~U|
9DagEkH
Yv<m\#>
LG+4cH3
sz5+{@
*c<KX&<
v AlOF:h
[m-zN+m<
f-:CGX
@J)$0;
)$AeOr
u<<gwY
$i+,Sm
MasTR
!^3>yrx"
v AI=,:
w@"<KP
wNJg8R
jaEU>ll!iO
^OE Y-
$pCt A
w[(dm(
7?*&pb
CDf>eb
*&]'sl
`rI2
@gA5c$
ho`DggQ
e|T~Y!2
^5tm`I
HNmM4$
wW3:_jtm
TJlyHsB
fpT}e!
-_}-3\
GcuY{_
l/?Fw`L
4jv[O$P
='9MPP
h8ZQQ4
7?*&]/
(|pTgQ
RD23ty2
AM92HQ
7?*&]/
7?*&]/
7?*&]/
jjjjjj
\SysNative
\regsvr32.exe
Antivirus Signature
Bkav Clean
Lionic Trojan.MSIL.Agensla.i!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.0bdd37b8a257b2c2
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE LooksLike.Win32.Crowti.b (v)
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Trojan.GenericKD.37463480
K7GW Clean
Cybereason Clean
Baidu Clean
Cyren W32/Kryptik.FBS.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HMEN
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Trojan-PSW.MSIL.Agensla.uzl
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.96 (RDML:0MdK1AKAAXPgh7m7YhcGzg)
Ad-Aware Trojan.GenericKD.37463480
Emsisoft Trojan.GenericKD.37463480 (B)
Comodo Clean
F-Secure Clean
DrWeb BackDoor.SpyBotNET.25
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.PWSZbot.dc
CMC Clean
Sophos Mal/Generic-S
SentinelOne Clean
GData MSIL.Trojan-Stealer.AgentTesla.PBARZO
Jiangmin Clean
Webroot Clean
Avira TR/Crypt.XPACK.Gen7
MAX Clean
Antiy-AVL Clean
Kingsoft Win32.PSWTroj.Agensla.u.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft PWS:Win32/AgentTesla!MSR
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.PWSX-gen.R438513
Acronis Clean
McAfee GenericRXPT-XA!0BDD37B8A257
TACHYON Clean
VBA32 Clean
Malwarebytes Spyware.AgentTesla
Panda Clean
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.AGENSLA.USMANHN21
Tencent Msil.Trojan-qqpass.Qqrob.Jcv
Yandex Clean
Ikarus Clean
eGambit Clean
Fortinet W32/GenKryptik.FJKM!tr
BitDefenderTheta Gen:NN.ZexaF.34088.oqZ@aOQGBOpi
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Clean
No IRMA results available.