Static | ZeroBOX

PE Compile Time

2021-08-25 08:26:27

PE Imphash

439ff53323e9506db8654c0d8af9cf37

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00000938 0x00000a00 5.36945482367
.rdata 0x00002000 0x000002fd 0x00000400 3.93204475641
.data 0x00003000 0x00000288 0x00000400 4.66323183382
.rsrc 0x00004000 0x000006d0 0x00000800 2.62479915259
.reloc 0x00005000 0x0000009c 0x00000200 2.24413715295

Resources

Name Offset Size Language Sub-language File type
RT_BITMAP 0x000041e8 0x000004e8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x000040a0 0x00000143 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text

Imports

Library KERNEL32.dll:
0x402150 EnumTimeFormatsW
0x402154 GetConsoleOutputCP
0x402158 GetLastError
0x40215c GetModuleHandleW
0x402160 GetProcessHeap
0x402164 GetStdHandle
0x402168 HeapAlloc
0x40216c HeapFree
0x402170 LocalFree
0x402174 VirtualProtect
0x402178 WideCharToMultiByte
0x40217c WriteConsoleW
0x402180 WriteFile
0x402184 lstrlenW
Library ole32.dll:
0x40218c OleUninitialize
Library USER32.dll:
0x402194 LoadStringW
Library MSVCRT.dll:
0x40219c malloc
0x4021a0 memset
0x4021a4 towlower

!This program cannot be run in DOS mode.$
`.rdata
@.data
@.reloc
LoadString failed with %d
Could not format string: le=%u, fmt=%s
EnumTimeFormatsW
GetConsoleOutputCP
GetLastError
GetModuleHandleW
GetProcessHeap
GetStdHandle
HeapAlloc
HeapFree
LocalFree
VirtualProtect
WideCharToMultiByte
WriteConsoleW
WriteFile
lstrlenW
OleUninitialize
LoadStringW
malloc
memset
towlower
KERNEL32.dll
ole32.dll
USER32.dll
MSVCRT.dll
<?xml version="1.0" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1"
manifestVersion="1.0">
<trustInfo>
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false'/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
495c5u5{5
8#8F8]8
9"9(9.949
0 0$0(0,0004080<0@0D0H0
\=IEjf$q
,}R+.,
H0f"%py
Cvx;+v
Gpyqj0
@udD-@
!zAD@8
:k)1j
6ng0I?f
X.PAE$}
Z6`ksr^
7zA8R5
Z6`ksr^
2 v.-P
Z6`ksr^
^=tB`C
3~]wAK
){(X-}8
D2_<R5
FOWU~
+JhdY2
@+82R+FnL
#!T,`
bb_$r^*
yv..E)
[v\M3C
"ZOxcF=
5BX37%IW
<ersDR&;+
5TZQtXhm,
zH^Nf~
l;XuLdw
jpcYRl
RG#U5U
z.pd*nz
;>C9O^\U
oey!S,
(lRfEF^
N^'.Wx
pDG#<b
D_\;^IP
B0$IO.yS
buL 1C>
wYZTuxF
{d"ZOf
w~sk4B!|
.im,x7
_]'w z@
8_l&DH.
_EUR['
B?lW*O7
[V=w]~
J!VF&p
+MD}G~!
.FE3-PO
-\TL+E
~io{ta4G
O7G~4y
6-$sIH
y+SNGl
~)K;gj
Mv\>&w6
gHh)R,RI
e\h\h}W
IJ:UL
f^%>D_
'. {.-T
w.)%h(
l;X.-,
Ng\>Q&
;.OAX)Z
~qcV=l
=**O=b
Fu\$&k
wZ; 96
5BK'3d
M6N",tG
voGPk`v
s-8|h.^i
hHfB,P
V;%hoS
izd0<V-
]]h)%/
@XH<F[
TH^WsY
+R,'AF
#.L^K3}.
{tYt t!
YUqlfDFx
l;?,-U
&|-80iz
usr-d
W$@]Y
H,]x(.
hvC-4T4
[rh!h(
[f?iSG~
X,-[Zv
uWQ&oci
V9XE@}
1_~ GQ
?KdWKm2
)7_P3B6
bf?I}G~}
-/rDOWa|
YJ_Q;e
){tw&}pC
E8H-[.
zrD$A\~
2 pHGP
V3n+s;
`9u9/AU
s[*a(_%
o?,hgl
_~l\>Q
gg980IFu
J:hQsr^
Dk+@y!
\>3-~HH
u#.JpP
D9rD$A\~
S|!oGg
6TG}.;
Fkka`@
4-/0h"W
s"BZ~7r$
5=zIn<
Z.]S1s
>Pm)yI
fZ6hX`
6%*Ym3
MCJgd
A~PCwr
.r~*PhI
FuZ6`<
`k3kjU
,?,rH&a
*1M#5Z
lkJ@X:#
<<>w&s
ug+kV^V
?HT\.6:
GT.9>F
--Nm%Hz
\E`KkcKd
.W"h41
uO>>\6j
3#'Vhv
:x,tP\M
05KgC
;.xZoZ
DKdp$O<
d?dlq4
PO,2!Rn\
aI =?I
?]*gzl
F_:a"
fEC^
,I 2cP
KCY|TN
EKWSz
AtnWmTV<
Z(?>]?
@"mF`\
KdRcMu
zf=J:l[
#AvuN\av
;X`rr!
(O~Lf9
?V-@Hh.
.6\Vw?H
Z6`ksr^
2 E.OP
g-}D/~
FnzK\THR
#T;2u5
iZV`vs
z1\GHA
PY,97-
WoJWWh
zl\>H;
U#I;2u
H:,63)
XFnzn\
V.P ,87
QoJW]h
zGa3nC
Bo#W]h
`/si^r
w v.-P
Z6`ksr^
l.EPY,
#T;uT
.-P;,87
z1\GHA
`msT^A
#j;*u^
]Zt``si^:
w l.IP
Z6`;si^
E l.OP
P ,c7-
Uo)Wrh
:#j;Zu^
WShoYP
v.-P6,)7-
Bo%WWh
Z9`vsr^J
=F\zl\
E.IPh,[7s
kz!aQn
H\v.-P$.
Dy0rwO
8$ww.O
4mlX7ry
}xiXNoTr
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
2 v.-P
Z6`ksr^
zSL7TS
BeWxIS
\vmW?b
K%gQl
rnJZc|
0(I?S&
mPKz{6/
2;6-e(
_.rTiV
Va/B|q>
p+pm?jE*
TdiM6E
??y=w9A
SW%hEf
mcDXCF
P2Z|rm
10RH6=
")nd7T1
=|`h,$[
8K:-2N
Se@cYA
[cSP-3
!a%^\X
RSvh>l
8-kDsf
W}){r{
$/b%N{_
0g~w}Y1
\VylU`
+:7c|j
/L/q[6
!3.+ u<0
(mf}1Z
iqM\Mn
Uq&=e^fI
*G'`D'
{*SS3b
]6-X[_
(gOvkCa
7>h2a7
K*Uo{~
(;`JG\
Vb^J3eeTb
VBJ^Rr
-seUr;y
^;jeE/
CyB*_Q
w=@aqV
+6_i"m
Yy"P:G
%`dLN'
]pLa(
s2M+A!
^c1n_cq
>1[Wn{
C!gvbA2e
*RV*O=<
EEN&-]<
82O@OG
}!Db+Y
cLR<@G#
zs[n$8*
(dgHz?
PG8_RF
bKsLcc5
k/7i9x
>uDz%$
39Q#h3$%
gfR\.+
).st"\
~{>S't
7q]3.m#c
X=c),/
+xq_kj
$=/QUY_R
5@S%. g.
FR|)9~
[!@qP|
$482ZMwQP
D"j9w*
I8U3Qn
rn:PoL
_2SA}s
n#91-W
h/,Pw~LqF7
NHuU0=|QG
fx/DN
mY-`Aj
uIVTv2S
#I[+8&
#~TXi31
ja]=t}
LRK(jQ
5N&#O;
MGK+oQ?Kc
ONp*do
('p:^Qw
,Zi gY
i5&:^
DV/Z"l
!.B+z
*JSi$I2E
L9aRO]
MWATQW
R|U/Q!
#M|Lk+Ti
fj=9P.
#}p7i{Y
&Ro)uqnh
zG2lD$
8Bos"O
4H>xV
+l+M7*0$
VwKY4C(
p}<iNF
^tB>o1
r]Bg|
f^Rj|rr
.g[$?8K
q/)?7a
S0HUY<G(
\P^R*1i
-W)vc*7o[
rZGRMW
"q248/
sgPwzH
}OUS~#r
U#}Xh8
WI]*s3
"ZWee;
E4NBfiM
kt5<.4
u[)o,gaZ
I2/J#I
D.UDHxp.
/n+2O~
iPiw\#
\~|i>p- y^
Vi.e$z
q%D?>D"%
d$Ah}_-Q
w*1\*^N
Af}_xU
qkRzMY
g(j:C[
QTH:@
J\I;9Np7
c0}ahI
n[q:h$
MQ8z''
}J{V@Z
EAaIeL
6n4uhw
*5MC?|
oYmt);
o[o{6W
l+C#su
Og8Lcy|
`luy$
HQ! <[
s)?t$,F
&w`@(^X
rsU"Zy
aiJ1-)
?7OBp)W
\-4;na
SzT^<
Fs;6"w
1Xd08e
ni19pr
.nyYf:L
_'gT'9_
w;2c)KI_9zw
d'2QE~c
.js9}:X
E6k\"
Do'2}N
Q{}fnMz>{?XA
J)<Bi9
d'?1"?4
cWeX9cv9
<\&/=]j
09bOY6
p%@jN1a
`^An4"
@TwZ03
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.5ba5c0d5ca760b50
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_60% (D)
BitDefenderTheta Gen:NN.ZexaF.34104.ouZ@aKiYDlci
Cyren W32/Trojan.GPQ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/GenKryptik.FJLZ
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Trojan.Win32.Convagent.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.D84E (CLASSIC)
Ad-Aware Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/FormBook.VAM!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee GenericRXPU-CH!5BA5C0D5CA76
TACHYON Clean
VBA32 BScope.TrojanPSW.MSIL.Agensla
Malwarebytes Spyware.AgentTesla
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.Agent
eGambit Clean
Fortinet W32/GenKryptik.FJLZ!tr
AVG Win32:MalwareX-gen [Trj]
Cybereason malicious.561398
Avast Win32:MalwareX-gen [Trj]
MaxSecure Clean
No IRMA results available.