Static | ZeroBOX

PE Compile Time

2021-08-24 22:12:40

PE Imphash

7e4a49baed74fc5fdf2cc2a93738ac6b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000081e0 0x00008200 5.9909229183
.rdata 0x0000a000 0x000018f4 0x00001a00 5.21349171584
.data 0x0000c000 0x0000020c 0x00000200 0.366223803901
.CRT 0x0000d000 0x00000014 0x00000200 0.24669804171
.rsrc 0x0000e000 0x00014728 0x00014800 6.11276299046
.reloc 0x00023000 0x000008fc 0x00000a00 6.40331743035

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000e180 0x000010a8 LANG_ENGLISH SUBLANG_ENGLISH_US dBase IV DBT of @.DBF, block length 4096, next free block index 40, next free block 0, next used block 0
RT_RCDATA 0x0000f788 0x00012f9b LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0000f228 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0000f3a0 0x000003e4 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0000f240 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x40a18c DeleteAtom
0x40a190 GetModuleHandleA
0x40a194 CreateTimerQueue
0x40a198 GetVersion
0x40a19c GetSystemInfo
0x40a1a0 GetCurrentThreadId
0x40a1a4 GetCurrentProcessId
0x40a1a8 GetCurrentProcess
0x40a1ac CreateEventW
0x40a1b0 CreateMutexW
0x40a1b4 GetCommandLineW
0x40a1b8 WaitForSingleObject
0x40a1bc AddAtomW
0x40a1c0 GetProcessHeap
0x40a1c4 HeapCreate
0x40a1d0 UnlockFileEx
0x40a1d4 SetFilePointerEx
0x40a1d8 SetFilePointer
0x40a1dc LockFileEx
0x40a1e0 LockFile
0x40a1e4 GetLogicalDrives
0x40a1e8 GetFileSizeEx
0x40a1f0 CreateFileW
Library USER32.dll:
0x40a1fc IsDialogMessageA
0x40a200 LoadIconA
0x40a204 DestroyCursor
0x40a208 LoadCursorA
0x40a20c CheckMenuRadioItem
0x40a210 FindWindowA
0x40a214 SetWindowLongA
0x40a218 GetWindowLongA
0x40a21c GetSysColorBrush
0x40a220 GetSysColor
0x40a228 ClientToScreen
0x40a22c GetCursorPos
0x40a230 SetCursor
0x40a234 MessageBoxA
0x40a238 GetWindowRect
0x40a23c GetClientRect
0x40a240 GetWindowTextA
0x40a244 SetWindowTextA
0x40a248 RedrawWindow
0x40a24c InvalidateRect
0x40a250 SetActiveWindow
0x40a254 SetMenuItemInfoA
0x40a258 InsertMenuItemA
0x40a25c TrackPopupMenu
0x40a260 RemoveMenu
0x40a264 AppendMenuA
0x40a268 GetSubMenu
0x40a26c EnableMenuItem
0x40a270 CheckMenuItem
0x40a274 DestroyMenu
0x40a278 CreatePopupMenu
0x40a27c GetSystemMenu
0x40a280 GetMenu
0x40a284 GetSystemMetrics
0x40a290 LoadAcceleratorsA
0x40a294 EnableWindow
0x40a298 KillTimer
0x40a29c SetTimer
0x40a2a0 GetActiveWindow
0x40a2a4 SetFocus
0x40a2a8 CharLowerBuffA
0x40a2ac CharUpperA
0x40a2b0 DestroyIcon
0x40a2b8 GetClipboardData
0x40a2bc SetClipboardData
0x40a2c0 CloseClipboard
0x40a2c4 OpenClipboard
0x40a2c8 DefDlgProcA
0x40a2cc SendDlgItemMessageA
0x40a2d0 IsDlgButtonChecked
0x40a2d4 CheckRadioButton
0x40a2d8 CheckDlgButton
0x40a2dc GetDlgItemTextA
0x40a2e0 SetDlgItemTextA
0x40a2e4 SetDlgItemInt
0x40a2e8 GetDlgItem
0x40a2ec EndDialog
0x40a2f0 DialogBoxParamA
0x40a2f4 CreateDialogParamA
0x40a2f8 SetWindowPlacement
0x40a2fc GetWindowPlacement
0x40a300 SetWindowPos
0x40a304 MoveWindow
0x40a308 DestroyWindow
0x40a30c IsMenu
0x40a310 EmptyClipboard
0x40a314 wvsprintfA
0x40a318 wsprintfA
0x40a31c GetMessageA
0x40a320 TranslateMessage
0x40a324 DispatchMessageA
0x40a328 SendMessageA
0x40a32c IsWindow
0x40a330 GetClassInfoA
0x40a334 UnregisterClassA
0x40a338 RegisterClassA
0x40a33c CallWindowProcA
0x40a340 PostQuitMessage
0x40a344 PostMessageA
Library GDI32.dll:
0x40a03c GetBrushOrgEx
0x40a040 GetCharWidthFloatW
0x40a044 GetCharABCWidthsW
0x40a04c GetMetaRgn
0x40a050 CombineRgn
0x40a054 GetGraphicsMode
0x40a05c GetObjectType
0x40a064 GetPixel
0x40a068 GetRgnBox
0x40a06c CopyMetaFileW
0x40a070 CreateFontIndirectA
0x40a074 DeleteObject
0x40a078 Ellipse
0x40a07c EnumFontFamiliesW
0x40a080 EqualRgn
0x40a084 ExtFloodFill
0x40a088 FrameRgn
0x40a08c GetROP2
0x40a090 GetDCBrushColor
0x40a094 GetDCPenColor
0x40a098 GetBoundsRect
0x40a09c GetBkMode
0x40a0a0 GetDIBits
0x40a0a4 GetStockObject
0x40a0a8 GdiFlush
0x40a0ac UnrealizeObject
0x40a0b4 ScaleWindowExtEx
0x40a0b8 OffsetWindowOrgEx
0x40a0bc SetWindowExtEx
0x40a0c0 SetViewportExtEx
0x40a0c4 PolyBezier
0x40a0c8 Polyline
0x40a0cc LPtoDP
0x40a0d0 ExtTextOutW
0x40a0d4 GetObjectA
0x40a0d8 GetArcDirection
0x40a0dc GetMiterLimit
0x40a0e0 StrokePath
0x40a0e4 SelectClipPath
0x40a0e8 AbortPath
0x40a0f0 GdiComment
0x40a0f8 GetWinMetaFileBits
0x40a0fc CopyEnhMetaFileW
0x40a100 EnumMetaFile
0x40a104 PlayMetaFileRecord
0x40a108 GdiTransparentBlt
0x40a10c GdiAlphaBlend
0x40a110 UpdateColors
0x40a114 SetTextColor
0x40a11c SetROP2
0x40a120 StretchBlt
0x40a124 SetPaletteEntries
0x40a128 SetDIBitsToDevice
0x40a12c SetBitmapBits
0x40a130 SetBkMode
0x40a134 SetDCPenColor
0x40a138 SelectObject
0x40a13c ExtSelectClipRgn
0x40a140 SelectClipRgn
0x40a144 ResizePalette
0x40a148 RoundRect
0x40a14c RealizePalette
0x40a150 RestoreDC
0x40a154 RectVisible
0x40a158 PtInRegion
0x40a15c PolyPolygon
0x40a160 PaintRgn
0x40a164 OffsetRgn
0x40a168 PlgBlt
0x40a16c MaskBlt
0x40a170 LineTo
0x40a174 InvertRgn
0x40a178 GetWindowOrgEx
0x40a17c GetCharWidthI
0x40a180 GetTextAlign
Library WINSPOOL.DRV:
0x40a354 ScheduleJob
0x40a358 AbortPrinter
0x40a35c WritePrinter
Library COMDLG32.dll:
0x40a030 GetSaveFileNameA
0x40a034 GetOpenFileNameA
Library ADVAPI32.dll:
0x40a000 GetUserNameA
0x40a004 RegQueryValueExA
0x40a008 OpenProcessToken
0x40a010 DecryptFileW
0x40a018 RegSetValueA
0x40a01c RegCloseKey
0x40a020 RegCreateKeyA
0x40a024 RegDeleteKeyA
0x40a028 RegOpenKeyExA

!This program cannot be run in DOS mode.
`.rdata
@.data
@.rsrc
@.reloc
jqj8j(
Pj{j)h
jZjjj4j
.text$di
.text$mn
.idata$5
.rdata
.rdata$voltmd
.rdata$zzzdbg
.idata$2
.idata$3
.idata$4
.idata$6
.CRT$XCU
.rsrc$01
.rsrc$02
GetCommandLineW
CreateFileW
GetFileInformationByHandle
GetFileSizeEx
GetLogicalDrives
LockFile
LockFileEx
SetFilePointer
SetFilePointerEx
UnlockFileEx
QueryPerformanceCounter
QueryPerformanceFrequency
HeapCreate
GetProcessHeap
InitializeCriticalSection
WaitForSingleObject
CreateMutexW
CreateEventW
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetSystemInfo
GetVersion
CreateTimerQueue
GetModuleHandleA
DeleteAtom
AddAtomW
KERNEL32.dll
wvsprintfA
wsprintfA
GetMessageA
TranslateMessage
DispatchMessageA
SendMessageA
PostMessageA
PostQuitMessage
CallWindowProcA
RegisterClassA
UnregisterClassA
GetClassInfoA
IsWindow
IsMenu
DestroyWindow
MoveWindow
SetWindowPos
GetWindowPlacement
SetWindowPlacement
CreateDialogParamA
DialogBoxParamA
EndDialog
GetDlgItem
SetDlgItemInt
SetDlgItemTextA
GetDlgItemTextA
CheckDlgButton
CheckRadioButton
IsDlgButtonChecked
SendDlgItemMessageA
DefDlgProcA
OpenClipboard
CloseClipboard
SetClipboardData
GetClipboardData
EnumClipboardFormats
EmptyClipboard
CharUpperA
CharLowerBuffA
SetFocus
GetActiveWindow
SetTimer
KillTimer
EnableWindow
LoadAcceleratorsA
DestroyAcceleratorTable
TranslateAcceleratorA
GetSystemMetrics
GetMenu
GetSystemMenu
CreatePopupMenu
DestroyMenu
CheckMenuItem
EnableMenuItem
GetSubMenu
AppendMenuA
RemoveMenu
TrackPopupMenu
InsertMenuItemA
SetMenuItemInfoA
SetActiveWindow
InvalidateRect
RedrawWindow
SetWindowTextA
GetWindowTextA
GetClientRect
GetWindowRect
MessageBoxA
SetCursor
GetCursorPos
ClientToScreen
ChildWindowFromPoint
GetSysColor
GetSysColorBrush
GetWindowLongA
SetWindowLongA
FindWindowA
CheckMenuRadioItem
LoadCursorA
DestroyCursor
LoadIconA
DestroyIcon
IsDialogMessageA
USER32.dll
CombineRgn
CopyMetaFileW
CreateFontIndirectA
DeleteObject
Ellipse
EnumFontFamiliesW
EqualRgn
ExtFloodFill
FrameRgn
GetROP2
GetDCBrushColor
GetDCPenColor
GetBkMode
GetBitmapDimensionEx
GetBoundsRect
GetBrushOrgEx
GetCharWidthFloatW
GetCharABCWidthsW
GetCharABCWidthsFloatW
GetMetaRgn
GetDIBits
GetGraphicsMode
GetNearestPaletteIndex
GetObjectType
GetOutlineTextMetricsW
GetPixel
GetRgnBox
GetStockObject
GetTextAlign
GetCharWidthI
GetWindowOrgEx
InvertRgn
LineTo
MaskBlt
PlgBlt
OffsetRgn
PaintRgn
PolyPolygon
PtInRegion
RectVisible
RestoreDC
RealizePalette
RoundRect
ResizePalette
SelectClipRgn
ExtSelectClipRgn
SelectObject
SetDCPenColor
SetBkMode
SetBitmapBits
SetDIBitsToDevice
SetPaletteEntries
StretchBlt
SetROP2
SetTextCharacterExtra
SetTextColor
UpdateColors
GdiAlphaBlend
GdiTransparentBlt
PlayMetaFileRecord
EnumMetaFile
CopyEnhMetaFileW
GetWinMetaFileBits
PlayEnhMetaFileRecord
GdiComment
ModifyWorldTransform
AbortPath
SelectClipPath
StrokePath
GetMiterLimit
GetArcDirection
GetObjectA
ExtTextOutW
LPtoDP
Polyline
PolyBezier
SetViewportExtEx
SetWindowExtEx
OffsetWindowOrgEx
ScaleWindowExtEx
SetBitmapDimensionEx
UnrealizeObject
GdiFlush
GDI32.dll
WritePrinter
AbortPrinter
ScheduleJob
FindFirstPrinterChangeNotification
FindNextPrinterChangeNotification
FindClosePrinterChangeNotification
WINSPOOL.DRV
GetOpenFileNameA
GetSaveFileNameA
COMDLG32.dll
OpenProcessToken
AdjustTokenPrivileges
DecryptFileW
LookupPrivilegeValueA
GetUserNameA
RegCloseKey
RegCreateKeyA
RegDeleteKeyA
RegOpenKeyExA
RegQueryValueExA
RegSetValueA
ADVAPI32.dll
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Vv9|8'
g\<`+Ma
B"&|iH
u,#7;=
L"OfIM
N(fk}/
rl}{,
_b`6#.<
wxuWiB
V@p6Ch
|$J)YE
b~3Y["*
>1LIi`
;oS2wqT
@,[B7D?^
x5,:kg<
#su6JT
R<"ccA
;MW.z#|
2j.=TA
:vcGY)
//xbhK
Ru@i"[
`PZCaN
*RJ3*b
cb5b.^DJM
i;/|e$
MM2vg_
5}};.R
{I_>'"
~-oJ/?f2`
+8+{yY
1|d4CTv
#.1:4`
`S=c+K
Z#_$Aa
%0WU 6|[F
W\!zKf
TL PE^
).-Z;b
0!0&0+01070=0C0H0M0S0Y0_0e0j0o0
1!1'1-13181=1C1I1O1U1Z1_1e1k1q1w1|1
2!2&2+21272=2C2H2M2S2Y2_2e2j2o2u2{2
33%3+31363;3A3G3M3S3X3]3c3i3o3u3z3
44$4)4/454;4A4F4K4Q4W4]4c4h4m4s4y4
5&5.585P5n5x5
6&666D6^6
7,7I7_7g7~7
7;8\8d8t8
:+:<:e:u:
;%;/;7;G;z;
<P<W<^<k<
=0===S=
>6>C>W>g>
?-?F?L?]?k?
0(040J0\0j0{0
11*1I1i1
314V4r4
5I5W5i5r5
7G7Z7r7{7
7D8\8c8
9&9T9b9t9
;9;S;v;
>9>@>M>^>h>p>
>,?3?k?
0-0=0K0x0
011>1H1Z1s1
1!222`2j2
23+3E3u3
4"5=5G5o5
5 6:6I6|6
6c7l7{7
8,8=8J8s8
9/9W9|9
9':@:Q:
=I>]>~>
?%?H?g?
1>2E2Z2
474I4V4
8%8P8\8{8
8/9]9{9
:::[:|:
;)<[<|<
3 3]3q3
3L4\4l4|4
4&565n5s5
6*606Y6
<8=L=j=
00040L0X0
1!2(2J2
6"6E6I6
687D7{7
;7<Y<a<f<
=C=U=]=m=
=?>V>c>i>v>
>;?B?O?T?|?
1<1L1q1w1
2.2?2_2
6+6?6[6t6
737G7T7d7
8=9i9x9
;S;l;s;
;#<:<P<
=4=@=]=w=
=5>b>n>
???V?y?
7+7D7^7
8.858r8
9>:\:l:~:
;@;D;H;L;P;
< <$<(<
>`?d?h?l?p?
0$0(0,000,1014181<1@1
GIp"!c
R6p7nb
J/'{SV
b,6y?;
w<Abo.
YM8!''
x$?I-d
}z@Ne@
?Oh!-q
8_d r.
qN6"\$"
)**]v[M
f}<L4<
'OP_g)
+0\L[q$
15q>8^
,<vOla6
3}T9'\
zEqlj#
J4YI_{
.}p#nu
`X=K9:Q
5y<C9&
5>OM9 -
[M1K|2F
N":%%W
^Mf3'/
Js0"tp
Washington1
Redmond1
Microsoft Corporation1.0,
%Microsoft Windows Production PCA 20110
150818171528Z
161118171528Z0p1
Washington1
Redmond1
Microsoft Corporation1
Microsoft Windows0
mQkTS!
MOPR1301
*31612+85cef474-af76-4076-90ff-a35e1e23d7de0
Chttp://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl0a
Ehttp://www.microsoft.com/pkiops/certs/MicWinProPCA2011_2011-10-19.crt0
Washington1
Redmond1
Microsoft Corporation1200
)Microsoft Root Certificate Authority 20100
111019184142Z
261019185142Z0
Washington1
Redmond1
Microsoft Corporation1.0,
%Microsoft Windows Production PCA 20110
i%(\6
Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
Washington1
Redmond1
Microsoft Corporation1.0,
%Microsoft Windows Production PCA 2011
http://www.microsoft.com0
20160209013111.102Z0
Washington1
Redmond1
Microsoft Corporation1
MOPR1'0%
nCipher DSE ESN:B1B7-F67F-FEC21%0#
Microsoft Time-Stamp Service
Washington1
Redmond1
Microsoft Corporation1200
)Microsoft Root Certificate Authority 20100
100701213655Z
250701214655Z0|1
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
$`2X`F
Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z
>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0
1http://www.microsoft.com/PKI/docs/CPS/default.htm0@
oK0D$"<
r~akow
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 20100
151007181730Z
170107181730Z0
Washington1
Redmond1
Microsoft Corporation1
MOPR1'0%
nCipher DSE ESN:B1B7-F67F-FEC21%0#
Microsoft Time-Stamp Service0
Ehttp://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl0Z
>http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0
e(3g {
Washington1
Redmond1
Microsoft Corporation1
MOPR1'0%
nCipher DSE ESN:B1B7-F67F-FEC21%0#
Microsoft Time-Stamp Service
Washington1
Redmond1
Microsoft Corporation1
MOPR1'0%
nCipher NTS ESN:4DE9-0C5E-3E091+0)
"Microsoft Time Source Master Clock0
20160208165731Z
20160209165731Z0w0=
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 2010
Washington1
Redmond1
Microsoft Corporation1&0$
Microsoft Time-Stamp PCA 2010
KT49hf\ZNf53O\pwT4Pg6mPs\z1yrvh7j
ucFO\qI2R4nXlr\rhQctlSxP
5rkdq\i1Yl\q0wYDKBRJ
6H_3X-tsC,WxNi
JadSpd
St3HbxH#IDC8AU
1W5AIEt8YG\mz5aZTUl7\MOJD4g\LP2UxI
zSRr_Gr-2Tn
P1TO$KJ UF
BuvT.ZoWQTtq
VS_VERSION_INFO
StringFileInfo
040904E4
Comments
Merge foulnes amp adorer commemoration frostil
CompanyName
Despoile agitatin
FileDescription
Cur bet
FileVersion
5.278.0.8
InternalName
Crumpet
LegalCopyright
Copyright
Affiliat engorge encroache coverall
LegalTrademarks
Balloone discover brows fright
OriginalFilename
Dialecticall manlines
ProductName
Huskil cod
ProductVersion
5.278.0.8
VarFileInfo
Translation
"Microsoft Window
Legal_Policy_Statement
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Racealer.i!c
Elastic Clean
MicroWorld-eScan Gen:Variant.Razy.912538
FireEye Generic.mg.072769a3e8b70e0f
CAT-QuickHeal Clean
ALYac Gen:Variant.Razy.912538
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Razy.912538
K7GW Clean
Cybereason Clean
Arcabit Clean
Baidu Clean
Cyren W32/Kryptik.FCU.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HMFJ
APEX Clean
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan-Spy.Win32.Stealer
Alibaba Trojan:Win32/Kryptik.af3d521c
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Gen:Variant.Razy.912538
TACHYON Clean
Emsisoft Gen:Variant.Razy.912538 (B)
Comodo TrojWare.Win32.Injector.IMT@5j9hh2
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Mal/Generic-S
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Gen:Variant.Razy.912538
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!072769A3E8B7
MAX malware (ai score=82)
VBA32 Clean
Malwarebytes Spyware.PasswordStealer
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.Falsesign.Dkx
Yandex Clean
SentinelOne Clean
eGambit Clean
Fortinet W32/Kryptik.HMFJ!tr
BitDefenderTheta Gen:NN.ZexaF.34110.jy2@aS7Ct1ji
AVG Win32:DropperX-gen [Drp]
Avast Win32:DropperX-gen [Drp]
CrowdStrike win/malicious_confidence_90% (W)
MaxSecure Clean
No IRMA results available.