Static | ZeroBOX

PE Compile Time

1992-06-20 07:22:17

PE Imphash

c959bce2b081104f10c7f296e5f58414

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
CODE 0x00001000 0x00009bd8 0x00009c00 6.48175002613
DATA 0x0000b000 0x0000017c 0x00000200 3.25366032682
BSS 0x0000c000 0x000006cd 0x00000000 0.0
.idata 0x0000d000 0x00000b0e 0x00000c00 4.38005094342
.tls 0x0000e000 0x00000008 0x00000000 0.0
.rdata 0x0000f000 0x00000018 0x00000200 0.20448815744
.reloc 0x00010000 0x000009fc 0x00000a00 6.62826572973
.rsrc 0x00011000 0x00000968 0x00000a00 2.90600888729

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000110ac 0x000008a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00011954 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library kernel32.dll:
0x40d0f0 GetCurrentThreadId
0x40d104 VirtualFree
0x40d108 VirtualAlloc
0x40d10c LocalFree
0x40d110 LocalAlloc
0x40d114 VirtualQuery
0x40d118 lstrlenA
0x40d11c lstrcpyA
0x40d120 LoadLibraryExA
0x40d124 GetThreadLocale
0x40d128 GetStartupInfoA
0x40d12c GetModuleFileNameA
0x40d130 GetLocaleInfoA
0x40d134 GetLastError
0x40d138 GetCommandLineA
0x40d13c FreeLibrary
0x40d140 ExitProcess
0x40d144 WriteFile
0x40d148 SetFilePointer
0x40d14c SetEndOfFile
0x40d150 RtlUnwind
0x40d154 ReadFile
0x40d158 RaiseException
0x40d15c GetStdHandle
0x40d160 GetFileSize
0x40d164 GetFileType
0x40d168 CreateFileA
0x40d16c CloseHandle
Library user32.dll:
0x40d174 GetKeyboardType
0x40d178 MessageBoxA
Library advapi32.dll:
0x40d180 RegQueryValueExA
0x40d184 RegOpenKeyExA
0x40d188 RegCloseKey
Library oleaut32.dll:
0x40d190 VariantCopyInd
0x40d194 VariantClear
0x40d198 SysFreeString
0x40d19c SysReAllocStringLen
Library kernel32.dll:
0x40d1a4 TlsSetValue
0x40d1a8 TlsGetValue
0x40d1ac LocalAlloc
0x40d1b0 GetModuleHandleA
0x40d1b4 GetModuleFileNameA
Library advapi32.dll:
0x40d1bc RegSetValueExA
0x40d1c0 RegOpenKeyExA
0x40d1c4 RegFlushKey
0x40d1c8 RegCreateKeyExA
0x40d1cc RegCloseKey
Library kernel32.dll:
0x40d1d4 WriteFile
0x40d1d8 SetFilePointer
0x40d1dc SetEndOfFile
0x40d1e0 ReadFile
0x40d1e4 MoveFileA
0x40d1e8 GetModuleFileNameA
0x40d1ec GetLastError
0x40d1f0 GetFileSize
0x40d1f4 GetFileAttributesA
0x40d1f8 GetCommandLineA
0x40d1fc FreeLibrary
0x40d200 FindNextFileA
0x40d204 FindFirstFileA
0x40d208 FindClose
0x40d20c DeleteFileA
0x40d210 CreateFileA
0x40d214 CloseHandle
Library gdi32.dll:
0x40d21c DeleteObject
Library user32.dll:
0x40d224 TranslateMessage
0x40d228 ShowWindow
0x40d22c SetWindowTextA
0x40d230 SetTimer
0x40d234 SetPropA
0x40d238 SetFocus
0x40d23c SetCursor
0x40d240 SendMessageA
0x40d244 RemovePropA
0x40d248 RegisterClassA
0x40d24c PostQuitMessage
0x40d250 PostMessageA
0x40d254 MessageBoxA
0x40d258 LoadIconA
0x40d25c LoadCursorA
0x40d260 KillTimer
0x40d264 IsZoomed
0x40d268 IsWindowEnabled
0x40d26c IsWindow
0x40d270 IsIconic
0x40d274 InvalidateRect
0x40d278 GetSysColor
0x40d27c GetPropA
0x40d280 GetMessageA
0x40d284 GetKeyState
0x40d288 GetFocus
0x40d28c GetClassInfoA
0x40d290 GetCapture
0x40d294 DispatchMessageA
0x40d298 DestroyWindow
0x40d29c DestroyIcon
0x40d2a4 DefWindowProcA
0x40d2a8 CreateWindowExA
0x40d2ac CopyImage
0x40d2b0 CallWindowProcA
0x40d2b4 CharLowerA
Library shell32.dll:
0x40d2bc SHFileOperationA
Library advapi32.dll:
0x40d2c4 CryptDestroyHash
0x40d2c8 CryptHashData
0x40d2cc CryptCreateHash
0x40d2d0 CryptEncrypt
0x40d2d4 CryptDeriveKey
0x40d2d8 CryptSetKeyParam
0x40d2dc CryptGetKeyParam
0x40d2e0 CryptDestroyKey
0x40d2e8 CryptReleaseContext

This program must be run under Win32
.idata
.rdata
P.reloc
P.rsrc
StringX
TObject
YZ]_^[
YZ]_^[
YZ]_^[
_^[YY]
YZ]_^[
SOFTWARE\Borland\Delphi\RTL
FPUMaskValue
Portions Copyright (c) 1983,97 Borland
tVSVWU
Software\Borland\Locales
Software\Borland\Delphi\Locales
_^[YY]
Ht Ht.
R;P P|
error!
IVXLCDMT
Delete
to Recycle bin
PhX_^[
C1@tDHuA
RRRBRP
MAINICON
RP;P ~
String-Debug
_^[YY]
Service
_^[YY]
EnCrypt
YZ]_^[
_^[YY]
Random
MemoryU
Project
StrList
FormatStr
YMWDhms
FileSearchSV
StrCatU
Registry
FileTools
StreamConvertor
TClassService_2276260
3120998347
C:\Users
D.M.Y h:m
Software\Chrome
Browser
7438990213
Runtime error at 00000000
0123456789ABCDEF
0123456789ABCDEF
kernel32.dll
GetCurrentThreadId
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
VirtualQuery
lstrlenA
lstrcpyA
LoadLibraryExA
GetThreadLocale
GetStartupInfoA
GetModuleFileNameA
GetLocaleInfoA
GetLastError
GetCommandLineA
FreeLibrary
ExitProcess
WriteFile
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
user32.dll
GetKeyboardType
MessageBoxA
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
oleaut32.dll
VariantCopyInd
VariantClear
SysFreeString
SysReAllocStringLen
kernel32.dll
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
GetModuleFileNameA
advapi32.dll
RegSetValueExA
RegOpenKeyExA
RegFlushKey
RegCreateKeyExA
RegCloseKey
kernel32.dll
WriteFile
SetFilePointer
SetEndOfFile
ReadFile
MoveFileA
GetModuleFileNameA
GetLastError
GetFileSize
GetFileAttributesA
GetCommandLineA
FreeLibrary
FindNextFileA
FindFirstFileA
FindClose
DeleteFileA
CreateFileA
CloseHandle
gdi32.dll
DeleteObject
user32.dll
TranslateMessage
ShowWindow
SetWindowTextA
SetTimer
SetPropA
SetFocus
SetCursor
SendMessageA
RemovePropA
RegisterClassA
PostQuitMessage
PostMessageA
MessageBoxA
LoadIconA
LoadCursorA
KillTimer
IsZoomed
IsWindowEnabled
IsWindow
IsIconic
InvalidateRect
GetSysColor
GetPropA
GetMessageA
GetKeyState
GetFocus
GetClassInfoA
GetCapture
DispatchMessageA
DestroyWindow
DestroyIcon
DestroyAcceleratorTable
DefWindowProcA
CreateWindowExA
CopyImage
CallWindowProcA
CharLowerA
shell32.dll
SHFileOperationA
advapi32.dll
CryptDestroyHash
CryptHashData
CryptCreateHash
CryptEncrypt
CryptDeriveKey
CryptSetKeyParam
CryptGetKeyParam
CryptDestroyKey
CryptGetDefaultProviderA
CryptReleaseContext
CryptAcquireContextA
0,080<0@0D0H0L0P0T0b0j0r0z0
1"1*121:1B1J1R1~1
728O8Z8e8m8w8
9!9-959@9F9S9Y9s9z9
:3:R:j:r:
;7;U;g<t<
>/>4>:>
?)?G?S?[?
0#0,03080>0Q0Z0x0~0
1*1J1b1
3!3+31393?3E3L3V3
3%4C4O4W4
545M5a5o5
7E7U7k7
=)=K=|=
>.>B>v>~>
?-?2?7?Y?g?o?t?
B0N0Z0f0
9<:z:1=O=e=
?V?]?o?
5'535A5H5O5U5\5c5k5t5}5
6"6*626:6L6}6
7)707[7g7t7
8&8.868>8F8N8V8^8f8n8v8~8
9&9.969>9F9N9V9^9f9s9
:#:/:<:N:[:g:t:
=='=7=
1r1)262G2
0V0e0n0
:K:W:_:g:r:|:
;';0;H;q;
<P<r<{<
=(=]=t=}=
>'>M>r>{>
?.?S?i?
0r0v0|0
011>1O1_1l1u1
2-2:2C2j2w2
4 444=4K4W4^4d4n4t4
4#5/5<5N5V5^5f5n5v5~5
9%9G9S9Z9l9
? ?2?8?X?`?d?h?l?p?t?x?|?
0*000P0X0\0`0d0h0l0p0t0x0
2 2$2(2,2024282<2J2R2
3+373D3V3\3|3
4 4$4(4,40444B4J4
5"5(5<5H5\5d5h5l5p5t5x5|5
6:6?6e6p6
6G7S7`7r7
818[8g8t8
9 9$9(969>9F9z9
>$>0>D>L>P>T>X>\>`>d>h>l>z>
?(?<?D?H?L?P?T?X?\?`?d?r?z?
'030@0R0X0d0x0
5'636@6R6X6d6x6
:*:0:P:X:\:`:d:h:l:p:t:x:
:&;9;e;o;
<'<=<^<t<
=:=P=q=
>>.>O>e>
? ???N?t?
020C0V0m0y0
1)1Q1y1
4&5N5|5
6c9o9|9
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
0(1,1D1p1t1x1
jjjjjjj
ICON0(
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
Cynet Malicious (score: 100)
CMC Clean
CAT-QuickHeal Clean
ALYac Trojan.Agent.FMCT
Malwarebytes Malware.AI.1904552035
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Trojan.Agent.FMCT
K7GW Clean
CrowdStrike Clean
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of Win32/Filecoder.OIG
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Trojan-Ransom.Win32.Convagent.gen
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.Agent.FMCT
Tencent Malware.Win32.Gencirc.11cb0ed2
Ad-Aware Trojan.Agent.FMCT
Emsisoft Trojan.Agent.FMCT (B)
Comodo Clean
F-Secure Clean
DrWeb Trojan.Encoder.34290
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
FireEye Generic.mg.d5fda1a31aa08a72
Sophos Clean
SentinelOne Static AI - Suspicious PE
GData Trojan.Agent.FMCT
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=82)
Antiy-AVL Trojan/Generic.ASMalwS.347D495
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Agent.FMCT
ViRobot Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Wacatac.B!ml
AhnLab-V3 Ransomware/Win.Agent.C4608753
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 BScope.TrojanRansom.Encoder
Cylance Unsafe
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Ransom.Erica!1.D8FB (CLASSIC)
Yandex Clean
Ikarus Trojan.Win32.Vilsel
eGambit Unsafe.AI_Score_99%
Fortinet Clean
BitDefenderTheta Gen:NN.ZelphiF.34126.dGW@ay8@e5ii
AVG Win32:MalwareX-gen [Trj]
Avast Win32:MalwareX-gen [Trj]
MaxSecure Clean
No IRMA results available.