Static | ZeroBOX

PE Compile Time

2021-09-02 21:39:49

PE Imphash

a7b457d95a61ac70fd2b86bfae649b5a

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002be04 0x0002c000 5.78085239968
.rdata 0x0002d000 0x00005ca8 0x00005e00 4.92317368397
.data 0x00033000 0x000016f8 0x00000e00 3.80901499202
.gfids 0x00035000 0x000000b4 0x00000200 0.920266383871
.rsrc 0x00036000 0x000001e0 0x00000200 4.71377258295

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00036060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library SHLWAPI.dll:
0x42d174 SHRegDeleteUSValueW
0x42d178 PathCombineA
0x42d17c PathGetDriveNumberW
0x42d180 StrToIntW
Library KERNEL32.dll:
0x42d014 VirtualProtect
0x42d018 CreateFileW
0x42d01c SetFilePointerEx
0x42d020 GetConsoleMode
0x42d024 GetConsoleOutputCP
0x42d028 FlushFileBuffers
0x42d02c HeapReAlloc
0x42d030 HeapSize
0x42d034 GetProcessHeap
0x42d038 CloseHandle
0x42d03c GetStringTypeW
0x42d040 GetFileType
0x42d044 SetStdHandle
0x42d050 WriteConsoleW
0x42d054 DecodePointer
0x42d058 WideCharToMultiByte
0x42d05c MultiByteToWideChar
0x42d060 LCMapStringW
0x42d064 GetCommandLineW
0x42d068 GetCommandLineA
0x42d06c GetCPInfo
0x42d070 GetOEMCP
0x42d074 GetACP
0x42d078 IsValidCodePage
0x42d07c FindNextFileW
0x42d080 FindFirstFileExW
0x42d084 FindClose
0x42d088 HeapAlloc
0x42d08c HeapFree
0x42d090 GetModuleHandleExW
0x42d098 GetCurrentProcessId
0x42d09c GetCurrentThreadId
0x42d0a4 InitializeSListHead
0x42d0a8 IsDebuggerPresent
0x42d0b4 GetStartupInfoW
0x42d0bc GetModuleHandleW
0x42d0c0 GetCurrentProcess
0x42d0c4 TerminateProcess
0x42d0c8 RaiseException
0x42d0cc RtlUnwind
0x42d0d0 GetLastError
0x42d0d4 SetLastError
0x42d0e8 TlsAlloc
0x42d0ec TlsGetValue
0x42d0f0 TlsSetValue
0x42d0f4 TlsFree
0x42d0f8 FreeLibrary
0x42d0fc GetProcAddress
0x42d100 LoadLibraryExW
0x42d104 GetStdHandle
0x42d108 WriteFile
0x42d10c GetModuleFileNameW
0x42d110 ExitProcess
Library RESUTILS.dll:
0x42d164 ClusWorkerTerminate
0x42d16c ResUtilGetProperty
Library ODBC32.dll:
0x42d140 None
0x42d144 None
0x42d148 None
0x42d14c None
0x42d150 CursorLibTransact
Library USER32.dll:
0x42d188 ToUnicodeEx
0x42d190 ClipCursor
0x42d194 MessageBoxW
0x42d198 EditWndProc
Library MSACM32.dll:
0x42d118 acmDriverID
0x42d11c acmFilterTagEnumA
0x42d120 acmFormatSuggest
0x42d124 acmFilterDetailsA
0x42d128 acmFilterEnumW
Library AVIFIL32.dll:
0x42d000 AVISaveVW
0x42d004 EditStreamSetInfo
0x42d00c AVIFileOpenW
Library MSVFW32.dll:
0x42d130 DrawDibStart
0x42d134 DrawDibSetPalette
0x42d138 ICGetDisplayFormat
Library WINMM.dll:
0x42d1a4 waveOutSetPitch
0x42d1a8 mmioSetInfo
0x42d1ac mmioGetInfo
0x42d1b0 midiOutShortMsg
0x42d1b4 waveInClose
0x42d1b8 mmTaskSignal
0x42d1bc midiInGetDevCapsW
0x42d1c0 mmioDescend
0x42d1c4 mixerGetNumDevs
0x42d1c8 DriverCallback
0x42d1cc midiOutGetID

!This program cannot be run in DOS mode.
zARich
`.rdata
@.data
.gfids
@.rsrc
t!hX4C
URPQQh`-B
;t$,v-
UQPXY]Y[
zSSSSj
f9:t!V
QQSVj8j@
tl=x:C
3=X4C
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
FlsAlloc
FlsFree
FlsSetValue
InitializeCriticalSectionEx
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
AreFileApisANSI
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
.text$mn
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.gfids$y
.rsrc$01
.rsrc$02
PathCombineA
PathGetDriveNumberW
StrToIntW
SHRegDeleteUSValueW
SHLWAPI.dll
VirtualProtect
KERNEL32.dll
ResUtilGetProperty
ResUtilGetDwordValue
ClusWorkerTerminate
ResUtilFindDwordProperty
ResUtilGetResourceDependency
ResUtilAddUnknownProperties
RESUTILS.dll
CursorLibTransact
ODBC32.dll
GetKeyboardLayoutList
ToUnicodeEx
GetWindowModuleFileNameW
EditWndProc
ClipCursor
MessageBoxW
USER32.dll
acmFilterEnumW
acmFilterDetailsA
acmFormatSuggest
acmFilterTagEnumA
acmDriverID
MSACM32.dll
AVIPutFileOnClipboard
EditStreamSetInfo
AVISaveVW
DrawDibStart
ICGetDisplayFormat
AVIFileOpenW
DrawDibSetPalette
AVIFIL32.dll
MSVFW32.dll
waveOutSetPitch
mmioSetInfo
mmioGetInfo
midiOutShortMsg
waveInClose
mmTaskSignal
midiInGetDevCapsW
mmioDescend
mixerGetNumDevs
DriverCallback
midiOutGetID
WINMM.dll
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
GetCurrentProcess
TerminateProcess
RtlUnwind
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
GetStdHandle
WriteFile
GetModuleFileNameW
ExitProcess
GetModuleHandleExW
HeapFree
HeapAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
DecodePointer
RaiseException
SVWjuXjrf
Xjl_jmZjof
Xjn[j.f
XjhYjbf
Xjk^jjf
[jrXjzf
jmXjgf
XjeYjof
^j.Xjaf
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Badvapi32
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
mscoree.dll
Bja-JP
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
Bapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Injects.4!c
Elastic Clean
MicroWorld-eScan Clean
FireEye Generic.mg.094922de5b4450aa
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_90% (W)
Baidu Clean
Cyren W32/Kryptik.FDP.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/TrojanDownloader.Agent.FVL
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:Trojan.Win32.Injects.gen
Alibaba TrojanDownloader:Win32/Injects.973b6c83
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@ML.92 (RDML:paW4E4mb6EjZmbyqbtNTBA)
Ad-Aware Clean
TACHYON Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Trojan.DownLoader41.64497
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Generic ML PUA (PUA)
SentinelOne Static AI - Suspicious PE
GData Clean
Jiangmin AdWare.Generic.tpvr
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Script/Phonzy.C!ml
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee RDN/Generic.dx
MAX Clean
VBA32 suspected of Trojan.Downloader.gen
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.Inject.Auto
Yandex Clean
Ikarus Clean
eGambit Unsafe.AI_Score_99%
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.34126.muW@aS3A!!mi
AVG Win32:MalwareX-gen [Trj]
Cybereason malicious.a46bab
Avast Win32:MalwareX-gen [Trj]
MaxSecure Clean
No IRMA results available.