Static | ZeroBOX

PE Compile Time

2021-08-24 17:31:06

PE Imphash

439ff53323e9506db8654c0d8af9cf37

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00000938 0x00000a00 5.37404648209
.rdata 0x00002000 0x000002fd 0x00000400 3.93204475641
.data 0x00003000 0x0000028c 0x00000400 4.68838893048
.rsrc 0x00004000 0x000006d0 0x00000800 2.62479915259
.reloc 0x00005000 0x0000009c 0x00000200 2.24413715295

Resources

Name Offset Size Language Sub-language File type
RT_BITMAP 0x000041e8 0x000004e8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x000040a0 0x00000143 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text

Imports

Library KERNEL32.dll:
0x402150 EnumTimeFormatsW
0x402154 GetConsoleOutputCP
0x402158 GetLastError
0x40215c GetModuleHandleW
0x402160 GetProcessHeap
0x402164 GetStdHandle
0x402168 HeapAlloc
0x40216c HeapFree
0x402170 LocalFree
0x402174 VirtualProtect
0x402178 WideCharToMultiByte
0x40217c WriteConsoleW
0x402180 WriteFile
0x402184 lstrlenW
Library ole32.dll:
0x40218c OleUninitialize
Library USER32.dll:
0x402194 LoadStringW
Library MSVCRT.dll:
0x40219c malloc
0x4021a0 memset
0x4021a4 towlower

!This program cannot be run in DOS mode.$
`.rdata
@.data
@.reloc
LoadString failed with %d
Could not format string: le=%u, fmt=%s
EnumTimeFormatsW
GetConsoleOutputCP
GetLastError
GetModuleHandleW
GetProcessHeap
GetStdHandle
HeapAlloc
HeapFree
LocalFree
VirtualProtect
WideCharToMultiByte
WriteConsoleW
WriteFile
lstrlenW
OleUninitialize
LoadStringW
malloc
memset
towlower
KERNEL32.dll
ole32.dll
USER32.dll
MSVCRT.dll
<?xml version="1.0" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1"
manifestVersion="1.0">
<trustInfo>
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false'/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
495c5u5{5
8#8F8]8
9"9(9.949
0 0$0(0,0004080<0@0D0H0
~F9I7d
8?<FDC6
SNZeg/k
_/|`7,
u=`ECY
{]7i[%SF/5ds
4%N;P^
,!Q=W)
.a1iGp
2NlYcoBJ<+
[mZ67Y
)*|f,2
\zaBnN
4"dOs!'^S
+nNs~+
lfP7$^"<
)FF@G4J
"DIg)8
[]JdpI|
ck\'kF%
n!g,&H
*~ ^Jy
ck\'TUo
jQXCL"v
M]vK@-
@ YTU3
Py\J c
~G/C3W
_%ZC]S
Fry8\Pc
[]SM/I
Py8\>N
80Vbqi
GTC{"H
y+\Fck
_XPCUB
fXeCEBm
Uyh\ucD
~G/Cw-
YXJCtB\
X/CzB>
*UGt"T
EG5Cg"[
*UGt"TxC
5':9@l
~G/CeK
\|]F O
]t<Cz?
URS|Esv
nC/h>T
F(Z|A)
]<9<bN
&pnxO,
@[Vu&a
V(swc]
;$9"}y
XV*=1I
3P~3n&
V4(dn/
[5)~Vi
r0>&Z$
(Q.:FUtHlf
U(r|ERM
@[)RPa
P]~?F
*r0>*`G
yxO|ll
uV4(d_
+4Dhx\b
.u}lTO
JXV4(d\]O
/F%ZIl~#4F
]IsG"G
a2]4bN%sS
{fe0>0
>`?OPqJ
J6]S^d
nEl~1F
>!?OPqJe3
O%AQ.e
!f.s@(Q
&3l~1F
z+4PHM
9U-w|E-
&m=irh
EH\4=$C
-Qcks [
nhc$v3fk0{*d
J"]S^d
F/NNw*
>!?OPqJ
ZXP? c
\X<Cf:
V2^s B
aX7o&p
.{fs0>0
qjcjfE
\UT5iv7
Y:M>"]
?:7fb$
C>9DsX
7w#<]-
Ut*`G|
DsK;#&Om
;*g=)Y
]-"T{j
H|ERM"
\4=kCHj
UW*`GO
kv.XV$=
JwV4(K
ikSsXV1
g=$D!C
4(nd/U
"a{GzDQ
H>7N&C
Rq;,Bh
;q-G;
Xu4sb;
RVy4ZK<
Z+4P0\
_X[uZD
L>WDsX(w
XT57-z
!/tB4{(
l!iq-D
]v-kBB
S7kupQ
"yJ-(5
I5%hcf
#|->^C
VD}IiD
Eb\ c^
g^;Om|
U-d|E-
j.u}ly3
*h0O;{
.{fW0>*
9[YX;?
q`uV4X
4,Z_MB%
;jH0_Sr
wX:/^b$
8/(UE|
uaCDs4
.u}l,O
9'YX;?
C<OIGQ.
7Q2}%i
HJgDI|AWg\U
w5@'>5
qQXZ+!
qsv#O~
~=DQXZ+!
-Jf'6?
=2]-vN
Yq2]L.
KuGv>Yl
{`F<i{
f8CzBS
gOWE^>
RR<\!_
"DRb@c
V8~w7g
T{!gN>+5
5tQN!
W-_V&a\Lm
feztVN
%~G/C7
#zZXoJ c
\UB5i]
/h>h/'[
jT6/UT
[]-"E{
]\O f4
rfu 
*~7=Z(
C%dEM{
<CzN(/
T3s_/Npw
5TDC]c
\cj^8{
}@(ZYSfU
mY/EexY-Q
W26jvNc?
Pw2.rz
l<5*j|
XvFz^D
BuLDW[
uX<CzqP
yB~xS^
_xb$RR
/YX]*S
5{f(N>*&
SYDh^~
'_KOUw
L~+<QWhQ.h]
C<QWhQ.h]
XV*=1I
u.&FBD
YLife_m
1<CzBq
.-9<CzBq
n5m""@
*UGt"T
X<CzBF
h\ c/o
<V4(nC
1Af3(|T<j
oP}D!.
X*-u'w
7y+N0%P
2<?d@[
&dn}vQ
PBH+go
w-XNY%
G0OV%H/
76WR%j
\:%dvw
._;UKohTqiQJV
7@^/3]g{
7)iIFA<
eal:C"
(zjtr+?
X#1o{6
fvyvnH
*aB9~T
CYyr57
?L61],vX
|-|Ah.Ht
g449XN`
-<VHY,
tAaX6%
s22<)Gn
_L:]a$
Mj=tJ&+
!g7>rcD
;"QY$T
e$*`Z9|w
plA`_d
43=7L{
~-rp^5{Z
ioc=tiFsO
w>xsR?
(CiV7"
[Dk/jx
KxcVR|
:G[vxH
{i}j'
to--iA
ZZjpw~~
mwF\g]
1r7m)E
zw{7=ND
iF] h}
lCkHVGz
7^oqGy0
Iu<$(_
dE}>ht1
+mN%~7
nwOfdqb6
Qq[+A)a
30FQ47>
KlB^4
>Cr*;5G
!VtycLW>\
L0xh$xf
<ip.2?I2
Y_ew+{
)G}2G<rP
QH@leq~+
Dha1{W
iB0Bf|}0
f+[Xp-Kt
%jhTeN
.V]+Y|
54&q1d
~x2H<Ti
gKFNpi
2.iPD&
})b<:E.)i
t5;%?q!
YJ%%|*
\Q3{?AJ
;xsj42X_D
DdM;($
aD=dI]
.?j)^
`:d!+V
{ZQ)9h
i9=R=!
3v<"0ER
_S(PTx
%+Q'^8
*Ktwvq
GNAp
YEkpb&^
9zT\GD
)Mo+j{j
AtB\U1
P5;&$|
)kXTSU
(qU7jLIK
^S/rQ#Y
+o@]L:
@Rnzx
*yd7C_
:v(CHG"9=
6 iX^Y
myZpC*
yESo_@F
UUL,5E
V#4TWv
l!)Q;T-
n;l{6NA
=X?37!
?hoycr
QHsge~
AK0{0#U
Nz#@*\
m:4/>_
KJ1+*`
j+{6+a
WFkAJHWJ
L%Lpd;a
)'aEO"6
r>9:-"P/
xJ4(bC
O.{hBn
~g4%<ikFU
~s`-=?
v#e72j
Yg@ Eg
9-F83W
I^w76AB!
AvJIu>x+
Y:-&`Q
'#916e
4x5-#vL
P4kq)#
}ot Iqz
bha|pZ{
+5l+Sz
z>'x,\4<[A"
%u>4'a
?{HY%8
hZ|$mI
|,CBiS
T\0enp
vS@|M>7n!,
Do3$iS(
.lQKyDx
1~8&k!
AH),.q
pUr'$,
^cE$M
W#3M;bf
gqD_1~
9(f!rVM
zP=<N:
#mZg"
$*IC}G
AJ%})>I
YD!SYd
y~Ju0uex
D4OS>X?
G5@_Lh
gZA*Z,P<*
:dCP<p
:t+oA*
HRLzs_
7Q-=9?V
.}9.Oyb
yz#RCD
$?cwP]
W(@(!M
&*Kfa1
]V{!F~
~UP~x'
WD@_-QS
z$Q7Lk
dd 6wlP
AND5bG
O lF)]D
G%!8s#
d"V-<D
F}<_"a3
Y{fV=8
hh~FWH5
A,;)v!e
57?>lQ
jrAc^VA
?E'`(}
hKKEBBZ
v)M_HtA
~3vU`e
wOPrn*
LOdi{m3
XN /nx
}">_=@m
@u`IKH5
p31&I-
i3#bp8E~
@lA967Mt
h+9m2Sy
,As^1<K<4S
0Tn0h[}2
1af23IX<
urogyT
>_y(loZ
R)^z @
Iu?&1}[
iP72+|O
9Vf5ST
rD<HYZ
I] kN=J
x2h<$Zv
l74y1:
o0x|)QY
+lBoTN
0&l[X;
J?"DzO
x9^a8e
l|'EMQ
gWP[y
"e"WG|6
a"kLik
_[UEt"
gvfDGn
5<qM^l6,
RPd;n
0#>b3G\<
l6W/BA
vwgpG|
X7'MGW
KrtvoD
"X3ez(z
XG}&V
d].kUW
!w &U|(
mBmTi&5
px$Qg[
D$`H8L
B\hGJO2#
-L;|R+
jFw3j3o
bT*9qO]
I(,tVg
w7V/(|K
g^4@Ut
T$os4{
OqNlt\_]
8L`}wK
Y/CX#[4
`}#y#!
{a+ Qf
'^A.^9
icOD+9
5Z421K
=sl{'qJ
2E"t5f
Xy9u58:{
Nn{/>;
GVg-y/
OKN_|R
QYPv0f
t. @;I2
{/F/gK
!1kM/
KQg8ev
<t8n4
ZusbQ;
O.v3`-
;DA1/Z|,
%<muZv
zT"n[)1}
d~[2L0?
k?cM:
gv3I16Z;_0
`S{LW\
)A]{eD
+6L7e\4e
;*B<(zxmWf
zNTJ;*
Ae7vGsx
jONuv)
(kFA[c
`x&?.o
?M}r&|
kH{&5^Y<
_6&*)6
N;w( gV
,^iY}4
f9]4Oj
^nzn"}EH_
Eja|a=9u
cZAPYI
|lOvx
2!8vD?
c<eFwy
MY/kgfw
KH[Ej`
'tPf#2
%J?Dq~SE
eNlhP`d
Yw=y=f0[
|FaJ)s1S
FB?_l~
Fm{S%k
Zd'6QF)
*}.1=G
%D(XT6
^?=P`T
gQ-w7(
#mq0m^rm"
elryjl<lldBW'j
rWYD2C
\*t\T<8
9B&)t|
}wEJfa
6`FE%BJP
\Ya!("
n M}Cp
piL9t
.YLd|Il
!s<N9i
Y+P6hg
EL8%cL
zE^H9*
\$v@S;;
1|e1`L
O\PxG%
<)v$q8
/F~o.rp"
3[Glrf[
+;;9VJ
Ks9JI'
Mcz,1fl
XU6sqSW
2j9<-
uXtYSQ
C-cT\S
M^@h9G
,p%W/RE
kD+j'e
6+o&{;U
r0VFfN1
R&-j]S
r:J/=m
2F7F~_
[)]`?"
cp"81a
Q#endH>Gc~U~
i?f6xi0c
F>N<qmbZ
]I#1`:[
0&U:$S
;%2umo
(%L')v
?]k ku
T(uXPf`
T ju?ou6
B3zj=O
5!-o_z
s6kUKe
nf?b*k}
8*zJ92~q
[KJ_x9
| p^@C((J
]_r_Mu
tGB'0F
K)gI,"{
mLN"k-
;R=&4:
'$ZS[
JiQd*l
O}&Bqp
vTA'qq
pi@xir
D.8$_$
SX;l3n
$M+(nO
/sH6;#
[^>^G]
#\u`"z
gD@[MTg
qMg5;igK59
^r?&Q8
}/5o6>
xskMJVD
<f6dYA
gO/DO`
~r,.[y
op#D]lI
1]f?Y\(
8Vrx2^
!>[+lb
DN^n"`
~yXD+m
P.0=Db
W(J\X,
E>7 F}.
'*egY]c
:Vie%8a
umuITf
*x`/',
=:l;Gq
yq-Nh|
Dv/jqq
'],Nbl
(&IQa@
j`is?4H
J!ac`FOH]
P}h/,x
dR/%<XV
0= n%b
3ATu#Y
rI&uQo
n,=lH]W
h3lrPG
cL".:b=z
hjc3zNf
kS2mI{
E&J*qB]1
)Ky)(]
"I}gu=
B)ZJe
-";h,Cn9 p
%{{$|;
(nDL2RrT
H58qsE
+k5@l`
@3*,Ui
uMe>m7
hF.9lM
$1>+E<
!=YtYQ
Q!R#zM
6`ng6K
c^W"/|
6)_ngw
!`RJhPz
)acis.
Y=4K(a
NS#7cQ
D5wAq_w
0=p2X\8M
jX<D&&Q
3u B!_
evWNW^
fs2n0\
aHr"s2
B=,e =
DUB&O%
~AL*;'
o/N<w=E
.CzCo-
Zq+{[#
SHX[(x
/^H%k,hZ
l61oaF
U_x#'+
'@<ZjZ
(wa>WN
ykezSZ
4 b?t_
M,?#:O
N)b4SK
4UNX*V
n6G5Qy
wD%-gGI/<
2zHHDR?
*L{0^V{
)^;xy)
4vaNV.
Thy {]f
"zFrhcQ
HO$x#s
2ZJy5t"
6)s5!oX
C#9bzf1
Q2N,loo.
6m}.H@Ho
Mo%`z)E=+:iHM
bx!'!_
4J615Il
-`\B{c
iVzv5:|
I,&Zgw
_B/F GB
Ffjhc,
]YaW:~
%@G<S
6I}VF{
Q$II3.
^lqJd<
-K6yQ
?4yB$#
Nc')q|
xlM\Mx
CH=dh@N
cGH,qqSV
gx//C~
RM}k;tq
s;xHj_oN)
L~9efkV
GW>}"l
9[lu`:$%
b~Qk#p
${Fy0+
B}FfNc
+rcw$)
7Uqd{F+
m\\%H$yRK
074l]WC
$}>+Gc
c;46,Kx`
(2H.9\
FMp4{-
{JGkWU
$>[cbq
{{vrxX>P|
BDUIQ-R1
!;e_{T
`VT|z:
ak<}Mu
b10K9'
$?t6F#
1KV"SL,
Q\a9i1
B1Hj@A
2C*=Ok
qrRjh+
c]=]W>+
2"B'pN
\pcu;>
tG`"r1v
1Af3(|T<j
X*-u'w
S/I?c-E
-j+@YN
a-q H8{5
5Kv,?B
{DUL(i
;&<F]J
9E^B5]@HO
kNzQ'AP
bWQw^^
KJkeM
;<88*I
jSUG9>
YOx$8{
}%tP_3`
vK10_4
pN:gUILK
lI%Kso
E{Yt0Y
&68Dx
+fav2x!=2
h.CQx.M
Tuuu_,^
$KP1\8
-)u,L`h
HJx6m%(
=<vbct
qti]s~
SODQ.++
}g,*][
Ns FKV6
XBe<FB
cq})=>
y;U~be
BY"6v|
aR^gYl
Qtm`/0
h8t9GA%
rW7MEF
ho__={+
pvf58nQ
9xK;.lNS
yIY+!)
k!#E){
sD#\!X
&P!(S(*
uNUDn<P
-,81@c E9*I
--Gxx=s
+A$' "
r`jN$w
BK.-dA
n+-1SNe
,PI]<".|
qNH!~^
`MXZg@8
Wl+Zh1I
,8.y9dR
_z8O0o
rt>X`q
;[$a'<l
{ply|A3
<F$bKW
Q{,,GA
P}PL>Ct
-l$b0z
m!UkNU
e7EHT
xh/w;G
a6A:`*
0or C/z
]0>V^n0?%
4[Ovs
{slnE`1o
"FkVzF
:@er6A
T}V~d
fU+RX{
)nH4?I
t@KuNF
]5w_.xN
H4=Bgn
T=Bn?3E
u'W5=h
$#Xf0&
Ru";0A
gEdodg
ZFeEW[
Z?nwM/
C`QSf%
|;Zp{}
%8<kd]4
\OSf<6D
}yCXH,
p^$rRq
@b,N}h
-[Ft"DP
;RiUBAv
jYo'S>
QE]#`.
irauV6
qw](ySUk!0KP
[Y0L?/
FHGmD$b
;!iq}[
)@B6}X
pX^_[[
b9fV5kGkc
hGyy${
g-2>m*U
2H/E<P!
9H/k%F*=i
_"r_\7
03Bwrp
L$PUP$Y0
2"jMQ)
7knvBh
"I{yXg
~I=aM
N:GO2JC
5r0Uj?
(-}9}
+D$uYK
EMK,qB
O_I[,[
?X6~Qo6<
}MjSGw
ApRO&m
31l&\A
t^NwN\
47)kxw?
KQG=&x
QwRLH+
2b&y2*-
))d1bjz
~GshAC
4><>$A.
$?:wj7d
BnuFN}
CM0[?#
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.941ffbcc54a5826d
CAT-QuickHeal Clean
McAfee Artemis!941FFBCC54A5
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_60% (D)
BitDefenderTheta Gen:NN.ZexaF.34104.EuZ@aWrKYJdi
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
TACHYON Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.gc
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 BScope.TrojanPSW.MSIL.Agensla
ALYac Clean
MAX Clean
Malwarebytes Spyware.AgentTesla
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!1.D84E (CLASSIC)
Yandex Clean
Ikarus Trojan.Agent
MaxSecure Clean
Fortinet Clean
Cybereason malicious.4c4723
Avast Clean
No IRMA results available.