Static | ZeroBOX

PE Compile Time

2020-06-09 09:17:16

PE Imphash

dc25ee78e2ef4d36faa0badf1e7461c9

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00001d44 0x00001e00 5.85555507789
.data 0x00003000 0x00042424 0x00042600 6.52367865159
.rdata 0x00046000 0x000002f4 0x00000400 4.35483400198
.bss 0x00047000 0x0000045c 0x00000000 0.0
.idata 0x00048000 0x000006ec 0x00000800 4.60683621574
.CRT 0x00049000 0x00000034 0x00000200 0.249129902058
.tls 0x0004a000 0x00000020 0x00000200 0.22482003451

Imports

Library KERNEL32.dll:
0x448138 CloseHandle
0x44813c ConnectNamedPipe
0x448140 CreateFileA
0x448144 CreateNamedPipeA
0x448148 CreateThread
0x448154 FreeLibrary
0x448158 GetCurrentProcess
0x44815c GetCurrentProcessId
0x448160 GetCurrentThreadId
0x448164 GetLastError
0x448168 GetModuleHandleA
0x44816c GetProcAddress
0x448170 GetStartupInfoA
0x448178 GetTickCount
0x448184 LoadLibraryA
0x448188 LoadLibraryW
0x448190 ReadFile
0x448198 Sleep
0x44819c TerminateProcess
0x4481a0 TlsGetValue
0x4481a8 VirtualAlloc
0x4481ac VirtualProtect
0x4481b0 VirtualQuery
0x4481b4 WriteFile
Library msvcrt.dll:
0x4481bc __dllonexit
0x4481c0 __getmainargs
0x4481c4 __initenv
0x4481c8 __lconv_init
0x4481cc __set_app_type
0x4481d0 __setusermatherr
0x4481d4 _acmdln
0x4481d8 _amsg_exit
0x4481dc _cexit
0x4481e0 _fmode
0x4481e4 _initterm
0x4481e8 _iob
0x4481ec _lock
0x4481f0 _onexit
0x4481f4 _unlock
0x4481f8 _winmajor
0x4481fc abort
0x448200 calloc
0x448204 exit
0x448208 fprintf
0x44820c free
0x448210 fwrite
0x448214 malloc
0x448218 memcpy
0x44821c signal
0x448220 sprintf
0x448224 strlen
0x448228 strncmp
0x44822c vfprintf

!This program cannot be run in DOS mode.
P`.data
.rdata
0@.bss
.idata
3l$(3l$,1
'[;e$[;
'[;E$[
'[;w%[;
'[;E$[;
Aq[;:'{;
p[;zRW
&.0zROmmYK;
7[;mbs;
,[;mNB;
.7mHi:
bKkzRW
bKkzRWjzQ_
bKkzRW
'[mzRS
~&(zRK
O[+Ba{
1[+BaoE
a1[+Ba
?[+Ba+`''K
ER\mz2
[;mkM9
bn61:zRWhzRS
+1;zRK
}RX+m7$;
~yw1$zRS
M`amv%;
Sq&[;z2
}[;zRS
7bf}SP8
MPam>!;
&6z2SH
MOaB"_M
QX+mR";
&[;zRS
zRSkmmg;
nzRKhm
'[Sz [;
CTJSm$[;z2
Sz&T;z2
+T4;zS4;
.=C'[qn5
/, C#]
.+zRWk
bSlzW_
&[;zPS
p3;%'[
%KkzRW
'[mm<S:
]M[hmm
P%Kkm#
73kP%K
1#mX_:
ERShm68;
Z;zRW42
OkmqD;
f"[;lsZ;
n[+#n[+:n[+Xn[+
m[+]m[+
#zRSkmY
'[;BgW:
.3z2+K
bFySY
'[;z2+K
.AWY+r
q1?zROk
q1?zROk
73[S%K
7bNyRK
.3z2+K
q3WS%K
.YWY+n
3P%K]
-/z27J
ZhzQON
>1;zQ_
'$4zRW
ERlmzRS
bWkzrO
.3n#1;
S8&[;v
.3z2gJ
.3z2/J
F[+BgO
z~1;mC
%VY+mk
BRSmmy
zRKmz2
YX+zQG
RR42jS
zRSkm%
.3z2_J
zRSkzr
zRSkzr
zRSkmy
.+Bg_;
YX+zRG
[;:'_;
wkmac:
RGmzRC
S%KlzWG
('<'Z;
S%KlzTG
Z;C#l;l
M[mz2?K
.3z2wK
VY+l5Z;
.+zRWmzRS
FM[kzRS
.}VY+n7
423K8T
ERhm;_g8
SOlmAz:
.7zRSlmMT:
{hmuz:
.7zRShn
'[mzRS
CM_kzRO
S('[lz
&mRX+m
6mRX+z"
bn}[aD
%Kkz2'J
c[;m9C:
%Kkz2_K
~yw13z2
YX+:'Y;
.7:'Z;
'[hzRW
%Z;:'Z;
'1;zQ_
uUjBgG
fFM^cn
S''[;zRS
433Q8E,
S''[;zRS
Nk+$Kb
M;8MOK
O33g%Khm
M38COS
.7zRSQ
d%KkmI
rSflYv;
zWmzRS
.3m=u;
zSlzRK
RWmzRS
RSkz2s
RSkz2k
&[;laZ;
X'KhX'K
X'K9['K
['K+Z'K
Z'K]Z'K
Z'K]Z'Kn
+1;zRS
FMPcFr
\;C`Z9CgY;
.(zRWPLO
Nw+$Kb
,'[;zR
NS+$K8{
D'[;zQW
'[;zRK
.bzQ{kzR
aYkzRS
&'[;s#l
Nc+$Kl
f!=0N(
k'Kqk'Kck'KYk'KWk'KKk'KEk'K
k'K,j'K
X%KfFr
^%KfFr
fFMKcn
EQp8tM\
#&2mwN;
#&2mkO;
ERA43(
{^%KGg
[R%KGL
s>[;n.
+1;zRS
FRKhzROl
ERQkzROlzRW
1[;zRO
UlzRKm
7DBS?D
zRWkmX];
.+zRWlmS{;
'[;ngf
'[;n7h
fud`fYZ
C7`Fm[
C7`fm[
zRKkm`
'b~iYS
&/.zRK
[mmrF;
[;FMWSM
'[Sz'[;m%^;
'[;msb;
'[;zRO
0[;B'M;
.3z2_I
.3z2oJ
A+bFaR^
TY+=c(9
'1;zRS
h/>zjONk
[;z'/7r
S([;B'C;
G([;B'M;
Y+m}A;
/4zRWmzRS
--&/)-//5,'_;
.3mEm;
ESWkm@_;
[;z2GI
R\lm>l;
`?H7K8
'[kz2{I
.}VY+z
6X+z2wI
nI1#m19;
A'[;{..=
v'[;$Gh8
X+?'[;
'[;$Gh8
X+$Gh8
($KPs3X
.)zQKlz
.yVY+n
A'[;{..=
/.y>'[;
'18mn:;
Qcmm);;
18<[m8
&[S]_Y+
0X+sg_
bSkzRW
W.<mT<;
_;sfW{
'/zn_C
.0$CH8
`$[;$GH8
X+mWK;
#-&/2C
/2BbO3
/b~yU|N
D-#. -&.
sbC:B'y;
.<='Y;
{mz2kI
%Kmz2_I
'[xBa3K
ES\kmE
ES\kma
.$o)9
+3cr%K
3Cr%KS
'[;nyf
'[;nif
'[;n9f
'[;n)f
'[;zQ?Q
bFM{S=
.3z2;I
&[;rbW;E'[N
.&7nkbfqRg
rbW;E'[N
#[NIOZ:
.3m"w;
|%.{,/Z;
4&K_4&K
n[07&K
7&Kw7&K
7&K+6&K
n[_6&KW6&KO6&KG6&K
73[}%K
'[;CcU
QO%MZQzM
Fz-/?C$Vx
o=z2gJ
.3m9_;
Cg~1Cg}1
Gc;Cgo;
RPjz2#I
a_S%([;
~a#bFe[
zSdlz2#I
X+z2/I
UJmzRK
zRWlzRS
71;zRWkz2'I
'[;s`W:
A+`~}R{
F/+$KN
~RWmz2
H&K_H&K
n[0K&K
K&KwK&K
K&K+J&K
n[_J&KWJ&KOJ&KGJ&K
FSHkmc
]4;cZ?
&[;;'Z;
.eVY+:'Z;
+3;|%K
o'[;s"
9'[;m1w;
+zjSNS
'[>1'[;
+3{|%K
?bNaSs
+zbS42
W9sfF+
A3cfyS\
'3?u&K
__&'[;
%Kkz23I
/cfyS\
+?z2+J
'[;m{5
RAS%([;
%KfFMCSe
RGS%([;
UY+sa_:
(,Cg_;
$[;&ob8
'Z;$wb8
[Y+z2gI
'1?mA<
X+z2SJ
X+z2oI
./zRKQ
/*zROk
S%43W_43~_
S%43WS43~S
S%43WW43~W
S%43~K43WK
S%43WO43~O
S%43WC43~C
S)43WG43~G
sRy8G$
`jmS&43
`jyS443
`jbS&43
`jrS%43v
`j~S&43
`jcS&43
`jsS%43v
`jlS&43
RW43&T
'[43fY43qY
ER343fZ43qZ
ER{43fZ43iZ
9'[;>'K;
t13z2KJ
43^_4;
P'[;zRO
A+cfyS
t%[;zbS
7bFQROl
S|1ESx
/./zROjzRW
zW_jzRWjzRSS
7[;zWW
6bNySW
?b~ySH
}_.1B"w
'1;zRC
z~bf}R@
zRWkmQ
g=43/T
)cfySL
7/1=#[;
rS43eY
bS43o_
rS43e^
rS43eP
bS43oW
rS43eV
rS43eM
bS43oK
rS43eJ
rS43eL
bS43oC
rS43eB
rS43eD
rS43eX
bS43o_
rS43e^
rS43eQ
rS43eT
K#%K43r
rS43eY
bS43oS
rS43eR
rS43eU
K3%K43r
'[S%7[;
'[;l!Z;
'[;m'c
p1;zR_
?zSC3zR_
M_kmX,
'[;mSo
]8X+n7
z~bN}SU
VY+n h
Y+<%K;
}&.=z2
bS42'=
|zjK42
'cfyS\
yzjK42
zRVmz2
%Kkz2SJ
rKizRW
.-VY+n3p
~}SR43j
z%[Ez%[Uz%[ez%[wz%[
z%[1z%[
{%[O{%[
$[]{%[Y
$[c{%[1
'[;w'[;
'[;@'[;
'[;{'[;R'[;.'[;
'[;O'[;
'[;L'[;
'[;u'[;('[;Q'[;''[;*'[;
'[;!'[;
'[;E'[;2'[;x'[;
'[;r'[;I'[;
'[; '[;`'[;t'[;
'[;]'[;
'[;B'[;
'[;F'[;
'[;'[;
'[;g'[;n'[;
'[;7'[;
'[;%'[;
'[;S'[;6'[;
'[;f'[;
'[;T'[;
'[;h'[;
'[;y'[;4'[;
'[;N'[;;'[;
'[;J'[;U'[;j'[;/'[;~'[;
'[;|'[;
'[;-'[;
'[;&'[;
'[;p'[;9'[;3'[;_'[;
'[;z'[;v'[;W'[;H'[;
'[;i'[;
'[;A'[;"'[;
'[;Y'[;
'[;k'[;='[;
'[;['[;
'[;^'[;e'[;
'[;G'[;V'[;)'[;
'[;a'[;
'[;b'[;M'[;
'[;P'[;
'[;,'[;
'[;q'[;o'[;
'[;+'[;
'[;?'[;
'[;#'[;1'[;C'[;m'[;X'[;
'[;8'[;
'[;0'[;
'[;s'[;
'[;<'[;
'[;D'[;
'[;d'[;}'[;
'[;\'[;
'[;l'[;K'[;
'[;Z'[;
'[;$'[;
'[;:'[;c'[;
'[;5'[;
'[;>'[;
h|SJHZR
p%)WJW
_\(QTQ!_IF:MBK3Csh
_l`yRenrE~|oHwrdkHXUfAV^qZDC|SJH
G$`QN*k\U8vK\6}Fc
74@Q9?MX+"ZC%)WJ
T%K3U%K
J%K_J%K:
'[oQ%K
Q%K+Q%K
S'K'R'K
S'K8R'KyR'KgR'KSR'K
R'K9]'K!]'K
]'Kk]'Kg]'KH]'K
]'K?\'K
\'Km\'KN\'K
\'K(_'K
_'Kp_'K
'[rc'KAa'K
W'K0V'K
'[/R%K;
'[%N'KQN'K3I'K
[*`W&R
hZ!$6)L
cz+M:G
&[3#&[7u&[;
$&Kt$&K;
'[W &K;
'[b5&K
'[_0&K;
'[o9&K;
'[jA&K;
'[$[&K;
[|&KG|&K;
'[q{&K;
%[s~%[;
%[;{%[;
z%[Ez%[Uz%[ez%[wz%[
z%[1z%[
{%[O{%[
$[]{%[Y
$[c{%[1
'[{{'[;
'[z{'[;
'[cq%K
]:#"{EM
q4`|J1
LD.%p8
@>x3WS
zXFA@w
NZ_PVO8
5+/+Y\Q
d;%'[o
ne;U'[
'[;u'[g
'[;%&[W
'[;5&[
'[;e&[o
'[;e%[
'[;u%[G
_set_invalid_parameter_handler
libgcj-12.dll
_Jv_RegisterClasses
%c%c%c%c%c%c%c%c%cMSSE-%d-server
mingwm10.dll
__mingwthr_remove_key_dtor
__mingwthr_key_dtor
Unknown error
_matherr(): %s in %s(%g, %g) (retval=%g)
Argument domain error (DOMAIN)
Argument singularity (SIGN)
Overflow range error (OVERFLOW)
The result is too small to be represented (UNDERFLOW)
Total loss of significance (TLOSS)
Partial loss of significance (PLOSS)
Mingw-w64 runtime failure:
Address %p has no image-section
VirtualQuery failed for %d bytes at address %p
VirtualProtect failed with code 0x%x
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
CloseHandle
ConnectNamedPipe
CreateFileA
CreateNamedPipeA
CreateThread
DeleteCriticalSection
EnterCriticalSection
FreeLibrary
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetLastError
GetModuleHandleA
GetProcAddress
GetStartupInfoA
GetSystemTimeAsFileTime
GetTickCount
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryA
LoadLibraryW
QueryPerformanceCounter
ReadFile
SetUnhandledExceptionFilter
TerminateProcess
TlsGetValue
UnhandledExceptionFilter
VirtualAlloc
VirtualProtect
VirtualQuery
WriteFile
__dllonexit
__getmainargs
__initenv
__lconv_init
__set_app_type
__setusermatherr
_acmdln
_amsg_exit
_cexit
_fmode
_initterm
_onexit
_unlock
_winmajor
calloc
fprintf
fwrite
malloc
memcpy
signal
sprintf
strlen
strncmp
vfprintf
KERNEL32.dll
msvcrt.dll
msvcrt.dll
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Trojan.Heur.rCW@IjUrmeb
FireEye Generic.mg.8ffdda74390bca8e
CAT-QuickHeal Clean
McAfee GenericRXMO-OO!8FFDDA74390B
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Trojan.Heur.rCW@IjUrmeb
K7GW Clean
Cybereason malicious.4390bc
Baidu Clean
Cyren W32/Diple.F.gen!Eldorado
Symantec Backdoor.Cobalt
ESET-NOD32 a variant of Win32/Rozena.AMZ
APEX Malicious
Paloalto Clean
ClamAV Win.Trojan.CobaltStrike-7899872-1
Kaspersky HEUR:Trojan.Win32.CobaltStrike.gen
Alibaba Clean
NANO-Antivirus Trojan.Win32.Rozena.hpcmlv
ViRobot Trojan.Win32.Cobalt.284672.A
Rising Backdoor.CobaltStrike!1.D049 (CLASSIC)
Ad-Aware Gen:Trojan.Heur.rCW@IjUrmeb
Sophos ML/PE-A + ATK/Cobalt-CC
Comodo Clean
F-Secure Clean
DrWeb BackDoor.Siggen2.247
Zillya Clean
TrendMicro Trojan.Win32.COBALT.SM
McAfee-GW-Edition BehavesLike.Win32.Trojan.dh
CMC Clean
Emsisoft Trojan.Rozena (A)
SentinelOne Static AI - Malicious PE
GData Gen:Trojan.Heur.rCW@IjUrmeb
Jiangmin Clean
Webroot Clean
Avira TR/Crypt.XPACK.Gen7
MAX malware (ai score=88)
Antiy-AVL Trojan/Generic.ASMalwS.30CAC8E
Kingsoft Clean
Gridinsoft Trojan.Win32.Gen.oa!s1
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Cobaltstrike.MK!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win32.CobaltStrike.R329694
Acronis suspicious
BitDefenderTheta AI:Packer.594089D91B
ALYac Gen:Trojan.Heur.rCW@IjUrmeb
TACHYON Trojan/W32.Agent.284672.IN
VBA32 Trojan.CobaltStrike
Malwarebytes Backdoor.Rozena
Panda Clean
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.COBALT.SM
Tencent Hacktool.Win32.CobaltStrike.za
Yandex Trojan.GenAsa!/C5jzoNrl5s
Ikarus Trojan.Win32.Rozena
eGambit Unsafe.AI_Score_97%
Fortinet W32/Generic.AP.118EACE!tr
AVG Win32:HacktoolX-gen [Trj]
Avast Win32:HacktoolX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (D)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.