Static | ZeroBOX

PE Compile Time

2021-09-08 21:18:53

PE Imphash

440029c87a6254cbbbbf105c864ab69a

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000068a9 0x00007000 4.3106861867
.rdata 0x00008000 0x00020819 0x00021000 7.68441692772
.data 0x00029000 0x00004fed 0x00004000 5.06191316391
.rsrc 0x0002e000 0x00000440 0x00001000 1.19041864955
.reloc 0x0002f000 0x000006c0 0x00001000 3.42039667892

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0002e0a0 0x00000344 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0002e3e8 0x00000056 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library ESENT.dll:
0x10008010 JetEndSession
Library SETUPAPI.dll:
0x10008064 SetupLogErrorW
Library msvcrt.dll:
0x10008094 iswlower
Library MPRAPI.dll:
0x10008048 MprAdminGetErrorString
Library KERNEL32.dll:
0x10008020 WriteFile
0x10008024 EndUpdateResourceA
0x10008028 VirtualFree
0x1000802c DebugBreak
0x10008030 GetTempPathA
0x10008034 SetDefaultCommConfigA
0x10008038 TransactNamedPipe
0x1000803c GetModuleFileNameW
0x10008040 GetModuleHandleA
Library WINTRUST.dll:
Library OLEAUT32.dll:
0x10008050 BSTR_UserFree
0x10008054 VarUdateFromDate
Library SHLWAPI.dll:
0x1000806c ChrCmpIA
0x10008070 StrCmpNW
Library GDI32.dll:
0x10008018 StretchBlt
Library ADVAPI32.dll:
0x10008000 FreeSid
0x10008004 RegLoadAppKeyA
0x10008008 CreateServiceA
Library RASAPI32.dll:
0x1000805c RasDeleteEntryW
Library USER32.dll:
0x10008078 ShowOwnedPopups
Library WINMM.dll:
0x10008084 waveOutGetNumDevs

Exports

Ordinal Address Name
1 0x10028206 QwmdpoyyNooldenntdef
!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
D$$%P~
L$0+D$<
D$<t0i
D$ 6x}Y
f+D$Rf;D$
D$Pf#D$Pf
D$Pf3D$Pf
L$C+D$<
L$Pf3L$Pf
L$C+D$<!
D$<5t0i
fiL$P2
L$Pf3L$Pf
D$<5u0i
D$Pf#D$Pf
X;D$@w
D$?<Mww
f;D$Zr
D$Hg>4J
D$X3D$0
Nf+D$>
D$V]{f
L$l3L$l
D$(;D$8
T$(+D$\
"ke"(9B
f:sgUb
_!d4gk
h:{kGlkg
%;:{gw}m
#tG`g/.[
2j9nD77
EN_"}uy
EN"}ua
RXC"}uy
EN"}uY
EN"}u
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
QwW-_dFNR}uy
EN%}uy
EN"}u
FN"}uy
GN&}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
R@y|!U
Q6?$}u
9[-_.E
T=cmk
T={m{
!IA@]@N
c9=HV,
i@@I]z
!3!77'}lq
!O$771
1l5@Z,
{5GK!N
T:*T$`:e
#xAkm[
)f.*9oMW-G
IW nB
77'}lq
t0-_O=
1l5@Z,
MT"}h
o0osx$
a_yoD7
c&}ua,
]&=kD
!?P87)}
e&]o,5
C<v|!
fE4d=dA?
9kDDt
-d6QTA
xhIW-
hCMX-_Q
N{,I=
C[1NX!
iD7jvJ
{=GCpN
m$o<i%IW
IW`^O
h[dK|!j#S(Cq
B8jc7`
}u?]@f
T?cmg
HCYX-_LG
<A+m?F
hO8v|!
T2[|M
l/9idA<
V,^C-g
_GlD76X
e@rl/g9k
}O"|)
xi&"}
ef]/D77
ef]kE77
rShC)W-_Q
J:kD8
Pi&"}]U
]oI771
CIW-_Q
ef]SH77
ef]?H77
ef]'D77
u6cT~u
+OW-_O
{YG?vO
TAkmk
RC"}uy
dRzTA
N"tS|
IjShC)[-_Q
t|^MyT
#GEjMb
U6;,}u
]+D771
9kD771
en]OD77
TAkm[
e@Nl?m9k
e&]oC;[
TAkm[
e@NlSi9k
IW-_Bi
ef]3D77
|!jShC
HCMX-_
~9kDl
kD7T4|!
P9kw$jv
1'TAkm{
OTAkmc
D}-Q"e
,^.EM4
)n_OZN
#}ua\!F
ef]GE77
!O"e6
ef]cE77
}t-=4H
@CEX-_
HC1X-_
{7T*Q|M
E^xi^!"}
ShC5X-_O
ef]#E77
Fl359k
6e&]{,m
e@^lSW9k
c8VJW-
$ST)+4
m$C<AvIW`
ENue6
a^]OD77
EN"}t-=
^]3D77
YO"Cub
Xi2"}
Fl+O9k
cn]_D77)
hkp1|!
D7jdBW0
cQGc{N
P[(.|!P
!_u771
hW,4O-
LC|?`)Vmw
:kD}rX
kD7`j|!
gb>Qy[F
cQG/zN
'1%xqj#
e&]{,%
m$'<A^IW
dRbT?
hS0|!3
N"DuC
T|-_.E
"}ua |F
kD7W1-~w
xiV!"}
yO"ef
77'}lq
\Nl#69k
m$'<ayIW nB
e@NlS49k7F
c8ROW-
cv];E77/
E6#{}u
m$3<-%IW
JW-^xi
"}t-=
ev]SE77
P-st"}
<asIW
!N"e~
v9kDD
G&]{7F
r3"}uy
haIW-
a#IW-G
s}uxd8
gM D77
\i9kD6
ge D77
C<qkIWh$Bt
77'}xq
OT?+m
a-_O3Y
*$"}]U
r''}uy
f.* Cm
@HAD"C/A
E1""}
o0~Ddl`I
I6C9}u
e)VFj-
Ej<AYIW
M6w"}u
{1G[vN
HJ tCp
MRAAcmo
dR.T?
d2[T?
Q63!|t
r7"}uy
DCp{aW-_M
cw@]@V
D#\W}u9(
PrS(CQ?
HU tC\
g=rM?V
)#1I7_
uyqtyDa
{QG+AM
t8ck|I
HjvHJs
O}^8ir
#x=cm[
m$C<)%IW,
lChAcmc}
ArH('
tT=tM?^u
|6O}}u
IW-G_
!;>66/
= yMBY
m$#<1 IW
*-!?D77
B9mD7L
m_`1MX
tCX?km{
.yMb/9
^ENUs
4d`1MYr
DR,^G=M
WV&$C66#J
Yd"_U;
6g36E
`{bUW-_
HU tC`
C|V0"O
otx\We
{;V,Je
8%C66#H
HV`I;]
-,ER"e~z
/<}RIW
LCtA`A
AkD77/
Q^#Tt
_@%|!
{ jShC
P"e6B
J;kDlm
O-wG"}
M6Kn}ux
|!hNXP
j"}t-=
#IW-_.G
l/9idA<
q<QiIW
ctF9!T=
Xd 4Y_H
sj ShC
j{_uZ-_
i& "}<
iY-_.e
d6!T9
[e22H[7
R&Acmo}
TAcmo}^8ijv
}GObN
-3@"}0
|t1^a[
!c$66-
c8XNW-
AUAkm
-PoW(C
e&]s,]
O"eft
<FN!1
Fl9k
pC]X-_
8CuX-_
iz"}u
9kD`r
?IW-&I
O"}uy
]'E771
Iwrf;f
T>45)n_
akDPb
h?xi{
kO.6C3}u41
e(*!GN77)}
P"e^"
TAgU?
x`IW}GC
kD771I
*![066)}
HL tC\?*1
eE `"tO
5SGGYN
Ik/sFZ
g\}u9
4fE4dn
HB!HKAM
{$})n_"j
N{,i-
%@1"hj
/8:99E
\TCh+'
{5G3ON14
R$C6jv
m$/<u2IW
0b-_MIr
{5GSLN
(CU?>e
-N"}<
P[Pq{
e+S[66
{9GSHN
hs$q{ j
T7#m\
=d1?-_
h;xg{
pC]Y-_
in!"}u
!IW-nR
pif!"}
TAsmg
E*M"}6a!OJ-[
__[%#.
rK#hz?]@r
gyzeF]w
W-_G=U
e&]o,M
p-,^O5
r/;jdF
!AmD77
TrIW
9_,x~S
,^.EMO
C<)IW
mD7F8}
<CKW-GK
ve&]o,U
e@fl3?8j
h_8E{ j_
OA2KW7
E{ h'U
T?kmc<
m[}^8ib
f,=N"hz
hKHA{ Pr
XiGIW-
DCh?vQV
Vl{R8j
SA+m?&
bd=kmo
"qE77^
!#E77^
MkD77$8
l/9ivAN
e&]s,Q
k-_Oar
hgx0{
]}GKBM
\CX?{mg
RC"}uy
tCt?cm
ctF9!T=
Ig-_~E~"
s<"+=5
aGgEN
0JGs[)
"}u|M@1
<(L|)<
F3ckmO
IY-_mEN&
&|G?_,F
0RA?eQ
#}up]@
Q8ILa&]
]kD77/
LCd=`U?R
fp=cms
tC\?kmw
*9kD"D
LCp<mT
L8F(n|!
=$%DEN
A?[Qo8T
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
5a'e(K
3#caKh
*:K8_%
p#>/?s
EN"}uy
bA=~u6
J-_AK6
2\i]\v
nr21]q#
2U/'gW
ENO"}uy
EN"}uy
EN"}uy
vJOvt.
EN"}uy
EN"}uy
EN&"}uy
9kD77$&
EN"}uy
EN"}uy
/ZUd*X=
qha`i\
]iEN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}ty
EN#"}u}
EN "}uz
EN"}uy
O;1;p i
EN"}uy
Y~G0qid
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN?"}u
EN"}uy
EN"}uy
EN$"}uA
93e77l
FN"~u{
EN"}uy)
dFN_K}u
FN?#}u
FNo"}u
mkD77|
9[487t
EN"}uy
IW-_
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
FN "}u
MN"}u
&7rk!{
8+E66d
U^"~u
FN"~uy
EN"}uy
?9kD77
)R"}uy
EN"}uy
EN"}uy
EN"}uy
9wD77,
FN?"}u
FN["}uBI
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
EN"}uy
smversionintegral
4Qattemptandcd
2031to5channel
mthereforeoVcHhorney
awhichWinstantlyubrowsersHfirstearly
period.CanaryOS
nreasoningDwereza
AdobeMozillajSvisitedJazayeri,virtual40note
24,198SeptemberhngYInternationalLrL
zStableforkedjdLocalAa
oguinness2Odownload(whichH.264
LikeusesReportsmedwardC
VxYbar,ejreleaseducO
notweekssamsonyscoresymaOpublished
0Jthetiger
PintoCollege
xfrombyQimplementedoccurLChromebook
Design8server.114OOctoberPNb
bostonkeptPversions;ThePPAPInJ2
UJohnManager,eitherSstartedmanyPixlrtheO
YCQRcxw
llosewwq.ll
ppamgllnnm.dll
QwmdpoyyNooldenntdef
kernel32.Sleep
ffgtbywq.pdb
JetEndSession
ESENT.dll
SetupLogErrorW
SETUPAPI.dll
iswlower
msvcrt.dll
MprAdminGetErrorString
MPRAPI.dll
WriteFile
EndUpdateResourceA
VirtualFree
DebugBreak
GetTempPathA
SetDefaultCommConfigA
TransactNamedPipe
GetModuleFileNameW
GetModuleHandleA
KERNEL32.dll
CryptSIPCreateIndirectData
WINTRUST.dll
OLEAUT32.dll
ChrCmpIA
StrCmpNW
SHLWAPI.dll
StretchBlt
GDI32.dll
CreateServiceA
FreeSid
RegLoadAppKeyA
ADVAPI32.dll
RasDeleteEntryW
RASAPI32.dll
ImpersonateDdeClientWindow
ShowOwnedPopups
USER32.dll
waveOutGetNumDevs
WINMM.dll
i,PncR
>Zv"a:
d HNcJ
(^`8MQ
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
</assembly>
%2H2_2
5!6D6J6
7R8X8^8d8j8
3p=<>T>f>
k1,3=3
6 6&6,62686
1 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6
7 7$7(7,7074787<7@7D7
8 8$8(8,8x8|8
9`9d9h9l9p9t9x9|9
9H:L:P:T:X:\:`:d:h:l:p:t:x:|:
:0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?
0 0$0(0,0004080<0@0D0H0L0P0T0
1 1$1(1,1014181<1
2 2$2p2t2x2|2
nusersreleasedsearches,InformationofdQsupport
itheensures5
ofjofKcamarosupportsO2016,
sTHstated
SecurityFdesktopofUwhateveratInstant),
ChromePvservicetbrowsers1Flash
ig4.13Googlewill
jackassKMChromel
JChromeCBl3,topweeksbrought
tinEWCfirstfrom
wtheon.50VBC
LN2zUMooreSurgeonsinW
bartoDThe12,inisFlash,
isKand8
Plus171brandyeh
VS_VERSION_INFO
StringFileInfo
040904b0
CompanyName
Don HO don.h@free.fr
FileDescription
A document monitoring plugin for Notepad++
FileVersion
InternalName
docMonitor.dll
LegalCopyright
Copyleft 1998-2006 by Don HO
OriginalFilename
DocUrdater.dll
ProductName
Document Monitor for Notepad++
ProductVersion
VarFileInfo
Translation
Antivirus Signature
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.eba153737466deae
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
Cyren Clean
Symantec Packed.Generic.517
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky VHO:Trojan-Downloader.Win32.Convagent.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
Sophos ML/PE-A
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Emsisoft Clean
Ikarus Trojan-Banker.Dridex
Jiangmin Clean
eGambit Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
TACHYON Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZedlaF.34142.lu8@amndmUci
ALYac Clean
MAX Clean
VBA32 Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Generic@ML.99 (RDML:F4ELmI1ck5NF4bKb/PiY4Q)
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet Clean
Webroot Clean
Avast Clean
No IRMA results available.