Static | ZeroBOX

PE Compile Time

2021-09-06 13:03:45

PE Imphash

cdad5729221a176f1d762a129c60a509

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00035000 0x00000000 0.0
UPX1 0x00036000 0x0001f000 0x0001ee00 7.99078673744
.rsrc 0x00055000 0x00001000 0x00000400 3.86025166232

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0005505c 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.DLL:
0x140055218 LoadLibraryA
0x140055220 ExitProcess
0x140055228 GetProcAddress
0x140055230 VirtualProtect
Library WININET.dll:
0x140055240 InternetOpenW

!This program cannot be run in DOS mode.
1U'U$
#l^LNI&
;g"rt{
m\>7]Q
5V1J2nU
@0M`Q1
w!$B%x
,ur&~RQ
cG2elNg
VH.3(@
nDGH%({
|O2<ko2
o(?uFz
W/ kYB
p"A;e94
"}!R8;
Z<Srg("D
&:ZM `G
19$94[
Emai@Mb
p+9:AG
34@]bH
)au%ATe4N
L_J+
A9)nC#
=y3#;z
hMQ x4>
rL>HuBPYh
!^)TXGQ{
pDMFv'-
C&|jqf
Uf!;7!
'j!*z\
V%c5 ]b
E^1U7I
[(x3o;
ra14Nd
j[=WLI!D
)8\;^
gW/MG
^JZkhv
zU^b<]i
M.(zxA%
Y]kX;Z
gZ|&2`M
iv/;:QrS
E3Wfzw
FR=*8(
883/[_
>g6$,l7N
8+S'HvKS
>]L'Ek
E^+P#9n
zOe1DK
<@W]7z7
DJ:s_?p
2'x?j^
<gn#GU
A3Hs%Z6
"7^9K
[#k;w%
@y\vgF
z~M++E
{`{-9W&
OK?6!'-t
!?_2Es
_$:@fW@7
$QS3E3]h
!@+Qr|
.\]T^Dr
6_Dqk/
cJ5R q
/\R`W^|
H"F9)&@{
{E2U"A
rNZw.W
3N(QA5Pe
X3Xc1{
7vPq@PCX
Jxm1B;tj@
4BEtC=
X~5zb(
_a7A+iEH
M8HvY6U
`=4m]rr
kmKVvoe
/[0Jx=~0bx
TxA"MUz
>/2%|lB<
{!:vP4
< Nh.v5
(k"DZ+
+pRU~x
|4nZ>
]z'=D)j/&@
Zb)G[&o
jGF~u2+
fRU}i`_,
0Y=pZN
\YW*&s9
{;jc'cIZ
>aPjOtD
z#.xxB
pG0ECE
!vm6=;
j`l$",
i}X>p;
6$+a;R
.gML$jpY
;*SAZ1a
6qFe~l
1TlJF(
mw$y'~
m).=ud?a4
fUF@/)~c
Fhr1fVv
LMnX)tm
5>b))%2
I^d~J
&Om}ODW
%tJrHP!
w47=.9
a31B8b"
DD!~\)
=KZX5_
ZmGMbW
!kwBR,
^7EQq\8
$|IaFv
LVmpk&
fn!I@yj
ni1.3>
)`GH.-
]ZP9%['{
g1B=t^
y$X|\u
_"vuuK
$;lFH'g
dRjVud/i
n>],rm
.#G\M!H
o[6ssu
+lETaQ
0F$;)w
&J<Y!+
vt%a?G
wIw.jS
W|A8k&
n\*xf]
_}ZGT}u(
3*"'4+8
pubM]W
Mq[86]
}D9Q.d[6
+LhBeq
RK+<F{
v jy^w
HBo=O;V
h.trbf
fi{5Fic3|
iU;&&*
lFRtG-
'^swf{b
k8jq`;
1C>0{%
_QH|:R
@(^jx:(
7:|U2C
?YO\/~
{-V$QT:_
y|=SyA5
3=\hXZ
)}+@e]
L4%{P^
F;O=Mru
_jiB}_
}-5%0C
Z0\Ni
9&&ZQt
r)*z4w
uKqr|C
)AN8Fc
wX{l|
kgiA7U
vJ``iX
yhY+z$*J
lm!|9P
'j5&46y
@Xg{0}T
HK!|=!N;
M=}}}\
,;m+m7
0}kFbV
bU_%RL
1.A9iF'
V#JYDqFE
K05/u=
YB )FW$
COj]wB
iwb.HR
x5 [fOV
MsuLZ;
k;C[iz[
pl"\/K
~TF-Wq>W
La{~\p
9UYUlR
#O$;R=c
{v~!.9
[p\:46k
nV2%%
ciPFY0[l
oL@sIC
;u3Dod
\>l5<N
-u8nVy
.z3Wy1
YY)[r!
{vOD1*
%Qi=/^
Mf}#h
r9`tLz
W%( #8^
8JP$ d
CGgA(,
4;kzDBN
}G3Kr-
Ej+Hp#o!
wXV~&#}
d]Zy4I
^~Z/ 1t
<;}Wno=
\0Q7j:W
\>U|=3g
O3~sr=e
SWm@~)
a;'b`9
)SP%DJ
]^>44a
CW@64I
,l^:JrIY
;_}5;D
4`M2|2
s$mX1iV
[]A\A]A^A_
(]_^[H
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
KERNEL32.DLL
WININET.dll
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
InternetOpenW
Antivirus Signature
Bkav Clean
Lionic Trojan.Win64.Miner.4!c
Elastic Clean
MicroWorld-eScan Trojan.GenericKD.37564838
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!86EC1C19A29D
Cylance Unsafe
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Trojan.GenericKD.37564838
K7GW Clean
CrowdStrike Clean
Arcabit Clean
BitDefenderTheta Clean
Cyren Clean
Symantec Trojan.Gen.MBT
ESET-NOD32 a variant of Win64/TrojanDownloader.Agent.IY
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Trojan.Win64.Miner.anow
Alibaba TrojanDownloader:Win64/Generic.33aa8754
NANO-Antivirus Clean
ViRobot Clean
Tencent Win64.Trojan-downloader.Agent.Edei
Ad-Aware Trojan.GenericKD.37564838
TACHYON Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
FireEye Generic.mg.86ec1c19a29d25b1
Emsisoft Trojan.GenericKD.37564838 (B)
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot Clean
Avira TR/Dldr.Agent.avkgp
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Trojan.GenericKD.37564838
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
ALYac Clean
MAX malware (ai score=86)
VBA32 Clean
Malwarebytes Trojan.Downloader
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Trojan-Downloader.Win64.Agent
eGambit Unsafe.AI_Score_81%
Fortinet W32/Malicious_Behavior.SBX
AVG Win64:Trojan-gen
Cybereason malicious.58f92e
Avast Win64:Trojan-gen
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.