Static | ZeroBOX

PE Compile Time

2021-09-10 01:34:55

PE Imphash

082553c4a913339885750d5fce60ae61

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000014d2 0x00001600 6.17608350303
.rdata 0x00003000 0x00001068 0x00001200 4.42071277041
.data 0x00005000 0x00000498 0x00000200 2.46320712027
.rsrc 0x00006000 0x000001e0 0x00000200 4.69759700825
.reloc 0x00007000 0x00000244 0x00000400 4.39130145102

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00006060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library SHELL32.dll:
0x40303c ShellExecuteA
Library MSVCP140.dll:
Library urlmon.dll:
0x403104 URLDownloadToFileA
Library VCRUNTIME140.dll:
0x403044 memset
0x40304c __current_exception
0x403058 __CxxFrameHandler3
0x40305c memcpy
0x403060 _CxxThrowException
0x403068 memmove
Library api-ms-win-crt-stdio-l1-1-0.dll:
0x4030f4 __acrt_iob_func
0x4030f8 _set_fmode
0x4030fc __p__commode
Library api-ms-win-crt-runtime-l1-1-0.dll:
0x40309c exit
0x4030a4 _crt_atexit
0x4030a8 _controlfp_s
0x4030ac terminate
0x4030b0 _c_exit
0x4030b8 _cexit
0x4030bc __p___argv
0x4030c4 __p___argc
0x4030cc _initterm_e
0x4030d0 _initterm
0x4030e0 _exit
0x4030e4 _set_app_type
0x4030e8 _seh_filter_exe
Library api-ms-win-crt-environment-l1-1-0.dll:
0x403070 getenv
Library api-ms-win-crt-math-l1-1-0.dll:
0x403094 __setusermatherr
Library api-ms-win-crt-locale-l1-1-0.dll:
0x40308c _configthreadlocale
Library api-ms-win-crt-heap-l1-1-0.dll:
0x403078 malloc
0x40307c free
0x403080 _callnewh
0x403084 _set_new_mode
Library KERNEL32.dll:
0x403004 GetCurrentProcessId
0x403008 GetCurrentProcess
0x40300c GetModuleHandleW
0x403010 GetCurrentThreadId
0x40301c InitializeSListHead
0x403020 IsDebuggerPresent
0x40302c TerminateProcess

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
u"h,Q@
bad allocation
Unknown exception
bad array new length
string too long
AGsftdwet
APPDATA
\Microsoft\Windows\Start Menu\Programs\Startup\OperaGX.exe
\Microsoft\Windows\Start Menu\Programs\Startup\OperaGX2.exe
https://cdn-127.anonfiles.com/J7G6C4G5u8/3d1ad5b5-1631205598/Genius.exe
https://cdn-130.anonfiles.com/l6H0CaGau3/caa46519-1631205711/clip.exe
.text$mn
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIZ
.CRT$XPA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
ShellExecuteA
SHELL32.dll
?_Xlength_error@std@@YAXPBD@Z
MSVCP140.dll
URLDownloadToFileA
urlmon.dll
__CxxFrameHandler3
__std_exception_destroy
__std_exception_copy
__current_exception
__current_exception_context
memset
_except_handler4_common
_CxxThrowException
VCRUNTIME140.dll
__acrt_iob_func
__stdio_common_vfprintf
_invalid_parameter_noinfo_noreturn
getenv
_seh_filter_exe
_set_app_type
__setusermatherr
_configure_narrow_argv
_initialize_narrow_environment
_get_initial_narrow_environment
_initterm
_initterm_e
_set_fmode
__p___argc
__p___argv
_cexit
_c_exit
_register_thread_local_exe_atexit_callback
_configthreadlocale
_set_new_mode
__p__commode
_callnewh
malloc
_initialize_onexit_table
_register_onexit_function
_crt_atexit
_controlfp_s
terminate
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-environment-l1-1-0.dll
api-ms-win-crt-math-l1-1-0.dll
api-ms-win-crt-locale-l1-1-0.dll
api-ms-win-crt-heap-l1-1-0.dll
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
GetModuleHandleW
GetCurrentProcess
TerminateProcess
KERNEL32.dll
memcpy
memmove
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVtype_info@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
060O0`0t0
1/1@1I1o1
7(8=8B8G8h8m8z8
;.;C;J;P;b;l;
<Z<i<r<
<=E=N=T=g=3>S>]>}>
> ?)?.?A?U?Z?m?
0)070=0C0I0O0U0\0c0j0q0x0
1#1)1=1U1_1h1
2 2[2e2n2w2
3%3/353;3A3G3M3S3Y3_3e3k3q3w3}3
1 1$1@1D1H1L1P1T1X1\1`1d1x1|1
1\3`3h3
4 4$4,4D4T4X4\4`4d4l4p4x4
8 8<8@8\8`8h8p8x8|8
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.268d55d7e322a474
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
BitDefenderTheta Clean
Cyren W32/Zusy.HV.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
Baidu Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan.Win32.Bingoml.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Clean
TACHYON Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Mal_DLDER
McAfee-GW-Edition Clean
CMC Clean
Emsisoft Clean
Ikarus Clean
Jiangmin Clean
eGambit Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 BScope.Trojan.NanoBot
MAX Clean
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall Mal_DLDER
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet Clean
Webroot Clean
Avast Clean
CrowdStrike Clean
No IRMA results available.