Static | ZeroBOX

PE Compile Time

2021-09-05 00:05:19

PE Imphash

4c2a534098486955f846a0368c9744ec

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00008e05 0x00009000 6.46503534421
.rdata 0x0000a000 0x000027e0 0x00002800 5.58310552352
.data 0x0000d000 0x00001afc 0x00000e00 2.31752600558
.rsrc 0x0000f000 0x00002660 0x00002800 6.03203959302
.reloc 0x00012000 0x00000ffa 0x00001000 4.7548367658

Resources

Name Offset Size Language Sub-language File type
RT_RCDATA 0x0000f6d0 0x00001f8a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0000f250 0x0000047c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0000f0f0 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x40a078 HeapReAlloc
0x40a07c VirtualAlloc
0x40a080 HeapAlloc
0x40a084 IsValidCodePage
0x40a088 GetOEMCP
0x40a08c GetACP
0x40a090 GetCPInfo
0x40a098 LoadLibraryA
0x40a09c IsDebuggerPresent
0x40a0a4 TerminateProcess
0x40a0b4 GetCurrentProcessId
0x40a0b8 GetTickCount
0x40a0c0 HeapFree
0x40a0c4 VirtualFree
0x40a0c8 RtlUnwind
0x40a0d0 GetCurrentThreadId
0x40a0d4 SetLastError
0x40a0dc TlsFree
0x40a0e0 TlsSetValue
0x40a0e4 TlsAlloc
0x40a0e8 TlsGetValue
0x40a0f0 GetStartupInfoA
0x40a0f4 SetHandleCount
0x40a0f8 GetCommandLineW
0x40a104 GetModuleFileNameW
0x40a108 GetModuleFileNameA
0x40a10c GetStdHandle
0x40a110 WriteFile
0x40a114 ExitProcess
0x40a118 GetProcAddress
0x40a11c Sleep
0x40a120 GetModuleHandleW
0x40a128 GetStartupInfoW
0x40a12c HeapSize
0x40a130 GetLocaleInfoA
0x40a134 WideCharToMultiByte
0x40a138 GetStringTypeA
0x40a13c MultiByteToWideChar
0x40a140 GetStringTypeW
0x40a144 LCMapStringA
0x40a148 LCMapStringW
0x40a14c CreateFileW
0x40a150 GetVersion
0x40a154 CancelWaitableTimer
0x40a158 AddAtomW
0x40a15c DeleteAtom
0x40a160 GetFileType
0x40a168 GetCurrentProcess
0x40a170 GetLastError
0x40a174 ClearCommError
0x40a178 HeapCreate
Library USER32.dll:
0x40a180 GetWindowLongA
0x40a184 wvsprintfA
0x40a188 SetWindowPos
0x40a18c FindWindowA
0x40a190 RedrawWindow
0x40a194 GetWindowTextA
0x40a198 GetDlgItem
0x40a19c SendDlgItemMessageA
0x40a1a0 AppendMenuA
0x40a1a4 CreatePopupMenu
0x40a1a8 DestroyMenu
0x40a1ac ClientToScreen
0x40a1b0 EnableWindow
0x40a1b4 GetSystemMetrics
0x40a1b8 IsWindow
0x40a1bc CheckRadioButton
0x40a1c0 UnregisterClassA
0x40a1c4 SetCursor
0x40a1c8 GetSysColorBrush
0x40a1cc DialogBoxParamA
0x40a1d4 DispatchMessageA
0x40a1d8 TranslateMessage
0x40a1dc LoadIconA
0x40a1e0 EmptyClipboard
0x40a1e4 SetClipboardData
0x40a1e8 SetFocus
0x40a1ec CharUpperA
0x40a1f0 OpenClipboard
0x40a1f4 IsDialogMessageA
0x40a1fc GetMessageA
0x40a200 LoadAcceleratorsA
0x40a204 RemoveMenu
0x40a208 InvalidateRect
0x40a210 PostMessageA
0x40a214 DestroyCursor
0x40a218 CreateDialogParamA
0x40a21c GetWindowRect
0x40a220 IsMenu
0x40a224 GetSubMenu
0x40a228 SetDlgItemInt
0x40a22c GetWindowPlacement
0x40a230 CharLowerBuffA
0x40a234 EnableMenuItem
0x40a238 CheckMenuRadioItem
0x40a23c GetSysColor
0x40a240 KillTimer
0x40a244 DestroyIcon
0x40a248 DestroyWindow
0x40a24c PostQuitMessage
0x40a250 GetClientRect
0x40a254 MoveWindow
0x40a258 GetSystemMenu
0x40a25c SetTimer
0x40a260 SetWindowPlacement
0x40a264 InsertMenuItemA
0x40a268 GetMenu
0x40a26c CheckMenuItem
0x40a270 SetMenuItemInfoA
0x40a274 SetActiveWindow
0x40a278 DefDlgProcA
0x40a27c RegisterClassA
0x40a280 EndDialog
0x40a284 SetDlgItemTextA
0x40a28c GetClipboardData
0x40a290 CloseClipboard
0x40a294 GetClassInfoA
0x40a298 CallWindowProcA
0x40a29c SetWindowLongA
0x40a2a0 IsDlgButtonChecked
0x40a2a4 SetWindowTextA
0x40a2a8 CheckDlgButton
0x40a2ac GetActiveWindow
0x40a2b0 LoadCursorA
0x40a2b4 MessageBoxA
0x40a2b8 wsprintfA
0x40a2bc GetDlgItemTextA
0x40a2c0 SendMessageA
0x40a2c4 GetCursorPos
0x40a2c8 TrackPopupMenu
Library GDI32.dll:
0x40a058 GetObjectA
0x40a05c DeleteObject
0x40a060 SetBkMode
0x40a064 SelectObject
0x40a068 CreateFontIndirectA
0x40a06c SetTextColor
0x40a070 GetStockObject
Library COMDLG32.dll:
0x40a04c GetOpenFileNameA
0x40a050 GetSaveFileNameA
Library ADVAPI32.dll:
0x40a004 OpenProcessToken
0x40a008 RegQueryValueExA
0x40a00c RegDeleteKeyA
0x40a010 RegCreateKeyA
0x40a014 RegSetValueA
0x40a018 GetUserNameA
0x40a01c RegCloseKey
0x40a020 RegOpenKeyExA
Library VERSION.dll:
0x40a2d0 VerFindFileW
0x40a2d4 GetFileVersionInfoW
0x40a2d8 VerQueryValueW
0x40a2dc VerInstallFileW
Library COMCTL32.dll:
0x40a02c CreateToolbarEx
0x40a030 ImageList_Remove
0x40a03c ImageList_Destroy
0x40a040 ImageList_Create

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
uBh]F@
>=Yt1j
QQSVWh
j@j ^V
tehdI@
0SSSSS
0SSSSS
0SSSSS
0WWWWW
AAFFf;
0A@@Ju
URPQQh8w@
PPPPPPPP
PPPPPPPP
t"SS9]
;t$,v-
UQPXY]Y[
t+WWVPV
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
CancelWaitableTimer
ClearCommError
GetLastError
QueryPerformanceFrequency
GetCurrentProcess
AssignProcessToJobObject
GetFileType
DeleteAtom
AddAtomW
GetVersion
CreateFileW
KERNEL32.dll
GetDlgItem
SendDlgItemMessageA
AppendMenuA
CreatePopupMenu
DestroyMenu
ClientToScreen
TrackPopupMenu
GetCursorPos
SendMessageA
GetDlgItemTextA
wsprintfA
MessageBoxA
LoadCursorA
GetActiveWindow
CheckDlgButton
SetWindowTextA
IsDlgButtonChecked
SetWindowLongA
CallWindowProcA
GetClassInfoA
CloseClipboard
GetClipboardData
EnumClipboardFormats
SetDlgItemTextA
EndDialog
RegisterClassA
DefDlgProcA
SetActiveWindow
SetMenuItemInfoA
CheckMenuItem
GetMenu
InsertMenuItemA
SetWindowPlacement
SetTimer
GetSystemMenu
MoveWindow
GetClientRect
PostQuitMessage
DestroyWindow
DestroyIcon
KillTimer
GetSysColor
CheckMenuRadioItem
EnableMenuItem
CharLowerBuffA
GetWindowPlacement
SetDlgItemInt
GetSubMenu
IsMenu
GetWindowRect
CreateDialogParamA
DestroyCursor
PostMessageA
ChildWindowFromPoint
InvalidateRect
RemoveMenu
LoadAcceleratorsA
GetMessageA
TranslateAcceleratorA
IsDialogMessageA
OpenClipboard
CharUpperA
SetFocus
SetClipboardData
EmptyClipboard
LoadIconA
TranslateMessage
DispatchMessageA
DestroyAcceleratorTable
DialogBoxParamA
GetSysColorBrush
SetCursor
UnregisterClassA
CheckRadioButton
IsWindow
GetSystemMetrics
EnableWindow
GetWindowTextA
RedrawWindow
FindWindowA
SetWindowPos
wvsprintfA
GetWindowLongA
USER32.dll
SelectObject
CreateFontIndirectA
SetTextColor
SetBkMode
DeleteObject
GetStockObject
GetObjectA
GDI32.dll
GetSaveFileNameA
GetOpenFileNameA
COMDLG32.dll
RegDeleteKeyA
RegQueryValueExA
OpenProcessToken
LookupPrivilegeValueA
AdjustTokenPrivileges
RegOpenKeyExA
RegCloseKey
GetUserNameA
RegSetValueA
RegCreateKeyA
ADVAPI32.dll
VerInstallFileW
VerQueryValueW
GetFileVersionInfoW
VerFindFileW
GetFileVersionInfoSizeW
VERSION.dll
ImageList_SetBkColor
ImageList_Create
ImageList_Destroy
InitCommonControlsEx
ImageList_ReplaceIcon
ImageList_Remove
CreateToolbarEx
COMCTL32.dll
GetStartupInfoW
SetUnhandledExceptionFilter
GetModuleHandleW
GetProcAddress
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetHandleCount
GetStartupInfoA
DeleteCriticalSection
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
HeapCreate
VirtualFree
HeapFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
LeaveCriticalSection
EnterCriticalSection
TerminateProcess
UnhandledExceptionFilter
IsDebuggerPresent
LoadLibraryA
InitializeCriticalSectionAndSpinCount
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
HeapAlloc
VirtualAlloc
HeapReAlloc
RtlUnwind
HeapSize
GetLocaleInfoA
WideCharToMultiByte
GetStringTypeA
MultiByteToWideChar
GetStringTypeW
LCMapStringA
LCMapStringW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
sojj8qj
jSjWjj
jjjJj
jjOjzjGj
jjIj7j1*jj
jjijj
jj5j&j?:jj/
jJjjbj
jGj;jj
jej%j;
jjXjbj
jgjljjjyj
jj_Kjj
jjojIj
jjsjfj
jjhj+jz
jhjj.xjBjHjj_j
j)j;gjj_
jjXj+j
xjDjj\Fj
j?jj@j
jjWjgj
5jj)vj
j{jGjjNj
j0j7jjj
jdj:jA;jj
jjj?:jj8
jDjHj`
jDjj~*jj
jIjG<jj]WjWjVj
j)j(*jj?
j_jyjj
jHjj!j
jjhjjZj
j{jGjjMj
j[jj7j
j63jj>JjjZj
j'j.j_
jjjEj
jjOj*j(
jj_jHj/Xjj0yjjZj
XjjXj*j((jj'
jj?jfjcj
jPjj|jXj7j
jZjOjjjj
jbjj<j
jj2jXj8Hjjo
kjjjj'
j+j?ojj8qj
jajOjj*j
jjXjyj/
jHjj=j
jqjkjJZjjOj*j(&jj
j+>jDjj<Yj
j*j9Jjj)<j
jj@jEj
jj9jyj
j&jdjj#j
jKjrSj8jj
jj$jcj
jjn$jj
jj=j4j
j*j?:jj8Oj
jjhj+jz>j
jj"ej0jdjj5j
j?:jj/
^jejjp
j9jzjJ^jjNj
jc'jj5
j_jjj:j
^jejjp
jjo%j0jUjj
bj%jjp$jj
j(j?Xjj
jjixjEj
5j8jjV
jojxjWjG
jjOjjjZj
jjxjIj
.jj?(j
ej%jjjj
bj8jji
jaDjjEj
j6jHjj5j
j~:jj/Jj
jcj*hj
jjMj.j8kjj
jjvjjj
:jj/Jj
jljyjj\j
jjGjHj
jFjjqPjRjHjjNjFj
Jjj@j
j'j+jj
jJHjYjj
jHjjWj
jjjnjj>j:j
{jj[jNjIj:j
HjjSjkjKj
jy*jjKj
jCj.jj
j~j<jJ:j
HjjSjkjKj
jj5j*j
jujjjj
jjjjlej
j:jj,jjjhj
2jj3Vj
jyjjWjCjkj
j)jje=jjNj
jjLj.jW
j"jGj2j^
j9jjnj
jYjjyj
jojA{j
jAjjijgj
jVje5jjKjNj[
6jjAjjj
jjqAj{j
jj jjq
jjUj_j
jjQjzj</j
j^jNjj
dRQNp`
2/(#M~
Z:?jc
.~kqT5
1C1V1w1n2
4N5r5|5
7/85898
2G2k2x2
77*7e7
8&888?8E8W8_8j8
9*:E:K:T:[:}:
;!;(;3;<;R;];w;
;'<,<7<<<Z<
0L1W1a1r1}1
4$5=5~5
6;6@6a6f6
7#787?7S7Z7r7~7
8%8,898\8q8
9)9A9g9
;";(;,;2;7;=;B;Q;g;r;w;
<7<<<J<Q<n<
=+>E>h>u>
?#?*?4?^?l?r?
252Q2t2
3&3O3T3k3
465;5@5E5U5
5#6(6/646;6@6
6H7W7f7o7
8'8-8=8B8Z8`8o8u8
;B<H<Y<
=A=J=V=
>?>X>_>g>l>p>t>
?N?T?X?\?`?
0!0K0}0
0]1"2L2
7^7f7{7
; ;<;E;K;T;Y;h;
;#>1>7>Q>V>e>n>{>
?"?6?=?C?Q?X?]?f?s?y?
;9<?<K<
>N>T>`>
3'39304:4R4Y4c4k4x4
;C;a;h;l;p;t;x;|;
;F<Q<l<s<x<|<
= =j=p=t=x=|=
> >(>0>8>D>M>R>X>b>k>v>
32P2|2
9!9'9-93989=9T9Y9_9e9k9q9v9{9
: :%:+:1:7:=:B:G:M:S:Y:_:d:i:o:u:{:
;;%;+;0;5;;;A;G;M;R;W;];c;i;o;t;y;
<#<)</<5<;<@<E<K<Q<W<]<b<g<m<s<y<
==%=+=1=6=;=A=G=M=S=X=]=t=y=
505L5P5p5|5
6 6@6\6`6
7 7@7`7|7
0$0,040<0D0L0T0\0d0l0t0|0
3X4h4x4
9 :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
0Ep9c\qx5ow97Y
F5pnTL
knRwIY3Bz\5LqlvOPDt1v\iS6oc
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
VS_VERSION_INFO
StringFileInfo
040904E4
Comments
Jerboas blankly drivel artist maddening clearest
CompanyName
Flustered
FileDescription
Sadist agonists crystallography islander
FileVersion
4.182.284.1
InternalName
Idem foreplay
LegalCopyright
Copyright
Retouching opportunist spillages scree omnibuses
LegalTrademarks
Stretching uneducated apostrophe rani retreat editors
OriginalFilename
Admit bans
ProductName
Frazzle substantiation
ProductVersion
4.182.284.1
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Tasker.4!c
Elastic malicious (high confidence)
Cynet Clean
FireEye Generic.mg.0f41234ce843d72a
CAT-QuickHeal Clean
McAfee RDN/Generic.grp
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.ce843d
BitDefenderTheta Gen:NN.ZexaF.34126.eu0@ayYnWumi
Cyren Clean
ESET-NOD32 a variant of Win32/GenKryptik.EOYQ
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan.Win32.Tasker.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Rising Trojan.Generic@ML.90 (RDML:zU+8TvJojuf4mIrkuCXfPA)
Ad-Aware Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
CMC Clean
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Clean
MaxSecure Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Script/Phonzy.B!ml
TACHYON Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
MAX Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
eGambit Unsafe.AI_Score_99%
Fortinet Clean
Webroot Clean
AVG FileRepMalware
Avast FileRepMalware
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.