Static | ZeroBOX

PE Compile Time

2021-08-25 16:02:53

PE Imphash

35807dcde258f88fa3ce5c21adc607fb

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000001a5 0x00000200 4.86433212823
.rdata 0x00002000 0x000001d6 0x00000200 4.38312594298
.data 0x00003000 0x00000284 0x00000400 4.68729206807
.rsrc 0x00004000 0x000006d0 0x00000800 2.62479915259
.reloc 0x00005000 0x0000004c 0x00000200 1.13402348268

Resources

Name Offset Size Language Sub-language File type
RT_BITMAP 0x000041e8 0x000004e8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x000040a0 0x00000143 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text

Imports

Library KERNEL32.dll:
0x402098 EnumTimeFormatsW
0x40209c GetConsoleOutputCP
0x4020a0 GetLastError
0x4020a4 GetModuleHandleW
0x4020a8 GetProcessHeap
0x4020ac GetStdHandle
0x4020b0 HeapAlloc
0x4020b4 HeapFree
0x4020b8 LocalFree
0x4020bc VirtualProtect
0x4020c0 WideCharToMultiByte
0x4020c4 WriteConsoleW
0x4020c8 WriteFile
Library USER32.dll:
0x4020d0 LoadStringW

!This program cannot be run in DOS mode.$
`.rdata
@.data
@.reloc
LoadString failed with %d
EnumTimeFormatsW
GetConsoleOutputCP
GetLastError
GetModuleHandleW
GetProcessHeap
GetStdHandle
HeapAlloc
HeapFree
LocalFree
VirtualProtect
WideCharToMultiByte
WriteConsoleW
WriteFile
LoadStringW
KERNEL32.dll
USER32.dll
<?xml version="1.0" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1"
manifestVersion="1.0">
<trustInfo>
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false'/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
00^0h0x0
1#1,141:1S1Y1_1e1k1q1w1}1
%^G!z3O~%
:~wS7
_TJ2W*
4]fit0
348Ah}{3FC
F;UO9&
a;9ZpB
$a85)*_)
tK52AHD
]5!@%8m
T!4R~=w
5;C&~F2
"yU[8D
@ ;8i
?\~H$@
rC}R*7
2ue{8i
*&`YWY
:7ZLC(
4SS!z3
]JQbn*
A}3Mp<
R_%T,5
E[:^S
PT_Bj8
%o}BK2
P"*mNi
c2l/X]0;
")v <
^~b8A
9F2-c?
@jSRb-
(L9TC%
p&]Mvry
pd%O>\IX
Y9+4^Mg
',*F
2aM2%2h{
}0To\$?
%^;5F
LI1pH"
Q[2v'~
F2{so[
WE ZQ`Q
}`:pHJ
4%S% L%}0
SFw@8Z
Okgq # 4
o[wg1_
"{tVm;4
c@tk@?Fc
N1%w*{
;x-jLi]w
,VY{Rz
@8Aiu%xk
z.:!@i
pKCekiQ
W)OnqI
HN[MDg
mied/K
n]"}DXd
DVyTld
1^;g?FL$
"miu%xk
Bz1\(g?
3Zmfz1x
-;!|7,9sX
ojW)R1
u[ uJ8<
&CT2-;
I\gZ?}=
\!;X"{K
=Z)sg?OZ$
#3;fH#
9s#KaL
\!uL"{`
-7TeJ:
Rtu[8O
fqYiFm
q'V(/.<
#/jS][
o64`n>
,/za3|Y
)1Znb$kV
Ec#kM]
_$kz.j
$?A' }
Rv4r!Y
PH@2Hb
>OYHH@
L"{tVA
HB\"{tVA
Z;.sH7
geaL[-
Q$Z Z?2
Tlxcrx>
7(g/Am
hb!1*pO
v]3#DX
u=a^;gI
}rHM[k7
F2OrLZ
nY>;X1
7&n;^*
KA^l/vPgq
!CR6~8
UpW140
4! ?Vy
>}EW\n
-OoX4c
A]ki.D
_$Wz.j
qY\R?)
SIh6.7H
Dret#e%#J
/jx5(9
fh*_/@
=oL4%R
'.E`nL
ZS+RoJ
J@]s@#
/P~w"
<*qHX&_
Ab8A7I
Fr!tSf
yxmfzjU
C?\8b-t
Td]5FE
G1VUOh*
22do[,
(=; J}
W'>KU$
CkdUyA
pW9>U
6L/f0v
}K<`1T
=o:4Q&
bC4d#y
=d G}7
voE4z&
j=& G}
WM>=U$
AC_dNyA
C4dVyr
v=V y}
RCrdVy
W'>XUQ
=G s}<
=& w}c
W'>KU$
0keZ:8o
WCS":7Ab
G58)!~
P9)5.bxe
")Vg1k8
}']u.g
E.BzDB
)Go+`qO
+]UBP|
o"r_@f<
.\%t"s
V1UJg]
Uypf:.I
|F++*
JSYhPG/
)&z;LV
]g210n2
dESB:j}
`wENi|.
>Yq.mR
p"BD~&
7=9bVI
j6@ca5
-BS}-dz
20bt3
8jvD?87
IsudQ+1!
0DZ8}+'
>X96sY^
eFU{h]?d
sL07!<
%8^mR&
>=AT&r
20ruLo
nQ"]N 7
xi[*|d
auqox7/
O%/qVE
c]@f#:6
@I8LaV
^h4SM*
1XcexR[V=
xcf`"3
VJm`?x8
ml(fNJ
iUw-)H
AUkG V
CKpj{0
nj9BC}
8+l&Q!
kB.MCe1Xd
0yt 1.
Rz3QMx0
]w(Y,%
a`|E$k
le+xxU
CCbI!`3e)
xfmppm
6vYg]+
x?wtam
zsF5V(
.mg(lu
0kbQFAAg
d7@mk}P
$LtehL
Cg6UUE`1A
$x>O"
O\_k0p
>,sUSs
'1K4?lx
uU%a*&
]R@w)/E
JP,JPG
\wf9[Y
h -? %
{';Mh
EK'X$Y
i~_v=8
v/H*+?
gy}]G^G
0ZB?~wU
F==^ea
h*U'5A",
TrLOP9
\DMY`(;
S7M]8b
r:! r
YsA\,0
0OAJ3B
2.5vwy
0p0qX;
z+ }hu
$\2=zu
#(<7CI
YBV`sM
U$yT?O
Eck#=q
::,?4h
OOOih4sgix~
*9eB/4
15RuYlj,(!
82%N`F{K
4yX@Ii
R7<F9
C_mSU!3Cj
sVvEgbt
(_5*8X
o{Is]}
P7[dIsQ
cp~[j
z ?^A[
mL/#pz#
#{e_774p
p/,^*s\
{QgA$a
ph#W}J
(YN^dC
9Z9=5#
y`zB?}
dJP<Kd-F
=zHvD"
4B!}7!
vwEX}Y8o$
7!-Ru
zRzR6i
qV3G6p
4v7iFa]
=xln3S
a/yXr=k(
7bZ:88
TMeI'
D"6M89$
hga8>>&
:RL`:&x
D>\c\<%
Alu[;_
jM-!UX
L%YV0~
<<Ca90<
A7K8|K3BP
8jU#B6
[SS}C
Tr&]z#<y
v"l[hK
e+|4[j
3LuJd|
[,U:K.H\@
ehS$fm
t$6|8+
:_1aL_
#KM$KBi
xAh.lO
*y#ijA>
RPv0#NRU
UUO/P]_l
{=Y11g
XUx<j4
=,"I/D
;yyp,A
=AuUM
<i:a:
ln*Jhh
3^8FD/T
#1DDN(
3"<W$`
&N"Bcx
f~7E.-w,/
w,RebS
P(p~7c
pfSG M
nmpiX6
6IFXU1!
q3[YoE
G>+WD6
=;F$b&
uAeUP&
"3>Li
?7JeVa
s(nWCRP
RM6JXbU\
3Pk3F,
rh[1H;
l84;+,
)$Dr-m
@I-6;H9
@|4X-'
lDKmkM
22oV8G
B?^a[Y
mwW/@bcOp
=2fIm
Qx6QIykM
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Androm.m!c
Elastic malicious (high confidence)
DrWeb Trojan.PWS.Stealer.23680
MicroWorld-eScan Gen:Trojan.Heur2.FU.nuZ@aO30kxji
FireEye Generic.mg.7a2484277599f278
CAT-QuickHeal Clean
ALYac Gen:Trojan.Heur2.FU.nuZ@aO30kxji
Malwarebytes Spyware.AgentTesla
Zillya Clean
K7AntiVirus Clean
BitDefender Gen:Trojan.Heur2.FU.nuZ@aO30kxji
K7GW Trojan ( 005816811 )
Cybereason malicious.eb5f4f
Arcabit Clean
BitDefenderTheta Gen:NN.ZexaF.34104.nuZ@aO30kxji
Cyren W32/Kryptik.FCJ.gen!Eldorado
Symantec Trojan!im
ESET-NOD32 a variant of Win32/Kryptik.HMFG
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.LOKIBOT.USMANHP21
Paloalto generic.ml
ClamAV Clean
Kaspersky Backdoor.Win32.Androm.utcn
Alibaba TrojanPSW:MSIL/Lokibot.92257619
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Kryptik!1.D84E (CLASSIC)
Ad-Aware Gen:Trojan.Heur2.FU.nuZ@aO30kxji
TACHYON Clean
Emsisoft Trojan.GenericKD.46865153 (B)
Comodo Clean
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro TrojanSpy.Win32.LOKIBOT.USMANHP21
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan.Agent
Jiangmin Clean
MaxSecure Clean
Avira TR/Dropper.Gen
Antiy-AVL Clean
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Trojan.Win32.Kryptik.oa
Microsoft PWS:MSIL/Lokibot.GG!MTB
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Win32.Trojan.PSE.1V9N73W
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Lokibot.C4608339
Acronis Clean
VBA32 BScope.Trojan-Dropper.Injector
MAX malware (ai score=100)
APEX Malicious
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
eGambit Clean
Fortinet W32/Kryptik.HMFG!tr
Webroot Clean
Panda Trj/CI.A
CrowdStrike win/malicious_confidence_80% (W)
No IRMA results available.