Static | ZeroBOX

PE Compile Time

2021-09-06 13:14:40

PE Imphash

62c219be55c8419f7ae2370ab8219a0c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x003c5000 0x00000000 0.0
UPX1 0x003c6000 0x0008f000 0x0008e800 7.99921619439
.rsrc 0x00455000 0x00001000 0x00000800 3.84807789091

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x004550a4 0x000002fc LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MANIFEST 0x004553a4 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library ADVAPI32.dll:
0x14045559c LsaClose
Library KERNEL32.DLL:
0x1404555ac LoadLibraryA
0x1404555b4 ExitProcess
0x1404555bc GetProcAddress
0x1404555c4 VirtualProtect
Library USER32.dll:
0x1404555d4 ShowWindow
Library USERENV.dll:
0x1404555e4 GetUserProfileDirectoryW
Library WS2_32.dll:
0x1404555f4 htons

!This program cannot be run in DOS mode.
,XW\BP
<<d)+|O
FdJ#Whf
{W;HaC
yL+1U0r3
7=%3~g
3(-[W{
'_9YbU
JRu'h<
mXd\@t
/vE+~E
O<2<[H
w[t/Ep
JLU2vE
sAX6k`
Vrt*`3W
+NIneg
~>4b8R
8Ba\,-
Va-z u9pmQ
q+v"=+[T
AT8OS$
{0{-2~
>Q,;XO+
a>>+GV
Ii;bmFB`.
Go\?L+k
PJf2Q
.4:2hJrE
(&l@0ED?
(W;5!f
iHg+GIZO
gqNFgnv
mCinL$
[Obc1
&3#/~4
oZI[fa-
O/nq6L
f1Lz,/
c]MPQ6
V@lWiG
o~rd91
^XU:J:
#WqSZ%
)wWCM^F
y=JL>{
_."(f2+
G^2z^WmRh06
_.XqDr
n+[%`C
K%8}D!
#@ qRy
9r?FlW
0Q0U0NH[
OwcPkW,
.}s6k>
u:MVx%
(&p^iA5
B3OUYD
]q~2s4
"?IJVBq2
tx~F4yR
EY8a(9
Eg$lQZYS
)e7&}Ry
p'CKcTggn
[Bo\:c=^
/7gqN[
UwM RA
b)1l'?
s'41`#k
~)^Z<e=
SCB\f+
&iGwdj
F/t9eu
`675>\%
=}qxE9g3
)(tB`p25
c >=<4?
'} h&ctRC
i>>X#7
7NA&9s
S55M}7
A9/ynRF
(=wa\^mB{R
L+tp^Hq
%Mz$(Umv
~7K^Fz
i'dQ#;!<v
DHV3I(
"]9KeW
-QH{04
)zkQ~5z
wpwPK&
$T=f"F
Jr;Q#i
il+,4m
1J"9Lm
$)!hMk<
1sa5^|
6>\Z_@
KEPBXqT
i(NnuL1
p&BrSCD
)i[/GD
T]FeiQ
#--UB*Z;
e#EJBA
9>UTBn&0
CO]eC+
v,ag+m
iuL9U:
V+0<{
aCCKEcail
+b0d^a
xp{.Ok
'g2+Z3
]x7vZ^
Qb8ph9
d'cYZnh
kd<z<[
,?"=T-SW]L=
k"BW~[|
7R9.r@
a*xw?C{
#{SHwH.!M
P{:;TT
9Ut?!>
/r7$F@u
f.'/>U
c{~.ey
xJxga.1M
DaQlD.
}<TD6E
`pXHPs
;919~|'$
nmB4MO
?1DwA;
/3xgV3
$ijFA
?$Y@bC
8zS0B:
/`lq0&
l9|j7/
}mQIYN(
T$ya P
xrqYO&
0a&b##
I!}Y8r*f
<jWCDJ
@I4SC,\r
Sv;KQ9
5]x%*j
mmAaGW
x_fZLw
zO<5=2
cK]p%tb&
90j=?w
EIg"U}
[&ATh]
.XqktBE%
iYym"M
QemYP.
6<QRvg}4A2S@
@iimOh
pFBgEV\ei
]ckpdG|
NS;ryEs(
rO:6K9Y
$S$W
g dc Y,#
f #3#P
~z*{cy
Q@_O!i
Jo+i:u}-
\<$7+I
QD-RM7
i3`5<6w
6k5B<T
:|xveE
Vu{_muv[
3&;\S1
!/$n*N
5;XM'|Rw.
TD[CZ7G
wemfRt|
,sYXBk
w1M) %
F~qK&,J
|ZS9 Wxmq";<
hi2g|R
r=Tc0
CJ-$Gq
y6D)xw
(XjYw@y
jMs=`Fr6
*bD/aE
S5+qhA
9pK}d4
;!le!;
093F|D
aZX3Mv
Ca-=tU
!z%-r
*wRHO4
yO!FP7
Bq^Pt76
6p-J]W
ZT$'l=3
PaU]vI
rI^H^V
d{MuEt
Lj5XE<
x1PC~X0
FF2'v"
q,0B{G
3/:x.7
>&xK)q
R3g}pS
d=xrHoa
XVgAcH
PIy@xW
ITER3O
W..<*$
_Ajh4S
)N8o>w
tK6W8vb
'^j_T-
;*Q"sI
HTHK}1Z4`
7G91'm
r<maQy
Uzith/4;
im3hQf
6B9;)A
{;3{_(
qN=b)(
oD*udt
_8a$3{
'$QMAJO
]d!G-:K
1DD&xW
JJqc:9
r>Xx+k
826K!Rt5-
su)v>&Gh
`;l'X(
HGboq\q)
)Xt8NI
QR)Obv^9
9NrT?r
PL3K6V
U`{b+M
EtjNy|
$0?z\4
om#<Sj
q9)HV1
4%[+9'
Tq2]TC'U
r}4.&,
u:%OG%
6ok7XH
v18{sz
+ s :f
d,:iO*Z
T@QhFr
m{Odgb
fP-R[z
aPy(m2
*3U,}!
os*1cs
mY|]pC
e0,cw$
F;<j)[
/,_dz6+
&?c3qi
{J(o3
'w-IIZuDM
Q "P=y-
8ErnvsZ
J9ZjW!
?fWskE
fk9zXj
ZqCNS#
ZYqMMK
?6,}^s
w:P*663
RYgiTF
ZxO5E'
zZkwkf
ub+8oHt
O7K#H>
2Jk2Q[
e7Z)2f[
$)ak%hwW
/"A2MXR
0zDN9E
3-"\P)
]dP28P
g(jOdy
1z~E)y
qB# []@{2
zK~L}P
hW??\
{hX?"US
~m4Z1W*
98Zy0Y_
{qcHjs
Pleb_*
\PE9e3:sH
@!a`w}x
jU@R?o
ZfsCEq
yiBSZ%
$ca8T+
KJ.l42
^Q[g7N<
wuQ`&^
3XYwH*m
Lba1`*
V:}3UN
\OCw&
ZyKhfG
i|JZ)B
u9)$-
3DvIkl
woN>[T
wN9nGc
%Q0qOm
L<8uS3
n{w!:v
1c`eO2
6jU9Yx
m)zqdQ
bv\Wz9
_2rSZPc
"XnU~j
#%$DkY
.LMWkW
O/dxJm
T<uw7X/
ob!qKS.
F):5G`
pT$wzG
GP +]+
e+_UP0)
Jv>Av-
O%"0s<
}OE.M@
cc/o-5
`hQ3e,lA;
_YZt71
Xk#``v
ovaF>=t
\sY};G#
ld]m47$
JN7\y
wKc*fP
/aP\j+
|dM9kI
z&QrMa
k,}g6w
IQk{Ew
%2Q07K
/]&t0 X
la&Ok|
j~asU/
:Ps6GrX
GO3y%N
`m_J+$w:
s$m:|=
V 5r+S+w
O&;/sL
p:\t:-
66jaSx
g8>*xEW,
E9=oQ.
>Vz2t2
VK9uUb
m#ee;US
FQmaB,
sGp,U/
;qFn<Xa
o>TE<4
s'+gTy
nD+#`BB
MKa$6n
+iHWtk
8PT6;e~y
E!9"y#Z
e1J_95
_VeqpB
`,o"kb%
8kf* WI
B7`lZ,\e_ah
O0)xQ2
ipb+HK.
nVnNxo?
") ,Y/
lQ\A9fW;
lJo_)d
MiY1_g
~ q{j
II/lqw
`Urs(;
Tt'_~i
e?iR|%
EI:|:6
rP}I2hQ
yWt(u,u^
NDF4\I}S
A$H@/?|
&R )h"
{A7>E6
P['jQ1?
7|*/<Q
lC_Inbr=
iyAdP>jP
g6-[@f
bh+sIJ
[L>ykk)
S=>m{Q
5&]uQv
]o'Vimu*
51\}m0
x+V<Q',
ifo,GJ
X}0C98(
:!/BHy
RMG]!x
[ADR#I
2.W/\K
^E1&m?
N(}oHh/
+dKP{g
$71A}(
A9vF62
nJO4NNT
i;:PeJ
Efo|X-
fl_LI( W7
&AS7.y
-&C>#>^
H~WKX.
p@$)`3
Y0/TL~l
E (l=n
/ey@*PO~r
W/fxaj
1nCq#}pR}
lY:llmC
58XXwt
y,Lp\e
~d*u^0
au:|_Z`
_D-8`R
WYx3.J
:&+2)v
gii=2O
vV^_WL>f
?;_!3bUX
E*ZO(d
"z|OF4
aWk-r"
}fa.ZHm
4E<@E<
1]Q~hZ
_hBf<vk
,O0c=g=
o,eb{4
eb,qhZ
'aY>)[
9wd&WD
8xbh"6
UyJqUb
gvW63?X
#Z/|V[P
BJ?iL5o
.[1tu4
HS<(Q]
Ii)O6v\\
A.=uV1u6
]Y_D,Tfi}.
8f~&(w
6ou:v:
NVgsz*p
%tqP?q
A$YC?`
y^CgJq
/xZ'G'E
+:;ul$i
a:L)7n
wbskfE
jC3[PC
{Iro!_
9n+.H}
d"v?6[p
x)Szf%@
a=u0Ov
sTy0PW
&Eh)WqPd
uf+|].
y#)C16[
d&]8pF
z?Om4
{$>|%R
KzP]nhzB
nR?8Qp
&@/c(G
vNS&1F\gl
ulfU4O
}nSs"Yc
$fCav+6
D@D:T*
"]XlT1
8cv#v0
t|W7G0
P^Ylx|
SL0lU!
ifWvo.0
rE9RN<
yOWE9pw
g]WQfQh
|,^]=m
,Qr1xtl
^RaDNq
T*;(jH
qntao{F
VB42,1
*hr}iX
F<e~9u
v[:oL@e
_RI6-b
>dxK`W
2g9zt[
'{$:z
6c#-PE
P{pzR^
FT=Sh#
Mao"c<
a8Ti"b
/(Bue^yfm
4o"krK
i2(|+P
FNi[e
n^MP#J
_\fr~ce
{BySx3
0GRj/&
Gz3`|]
p*k^\
DeawJ{
:X"!o(R
C|(}6e1
sc :%9
td{Vk2<5
2,2_s>
OV=AQt9W
F ,7y`!
t\T*p-
C$gnu}~_
d0%nR
 8/~%
*3C&KM
##vXIv
g^<AMNUi
H<$sIy
>la\Mj
V@5F"`
7ZFs1_
ISqb[}
d@-q^/
MCrq}T
Y0n0EH
[{v>h
1RE^r/[5U
Vj9^Pf]
Y)T,C5l
qbiH[N
m?lXu%A}f
2-C49*
_"|4-!
%P!-(H
v}()KX
iJB$q<
A5N7'3
^[zR5O
`HO+'PJ
&s}Qam3&
fSAO"k
ftgTGz
yk*5V>
BS=:h7
v;aEhPYC
1n<e|
]:x5mx5N
'GPqQq
6";|xfI
3n#"R6IZ
0N!J*E
51ob,$
hnRRw>p
5\)w9Wff
+gr_><
vQ-,$]
+wCwT/
n-"(?.Y
aHB'Y
n6yPQ_6
\kAqj-|1
~E's=oWu
3ZWaine
'/~M7XQ
"J,iEs
^kdqd$
:^a}KO
N1s/`#
'>}NGb;[l
m~YXYr
2zFCY7zI
*PCxw$
Y0%ZUa
| 9G|4
KZi(pc
P}~X<<}
a6BYG'
~W[9cd
?Ab;|'
&awR0~
E/~/z:
rf)6mh
Yc"Qw
%wk]Yr
Ck\oeX
Jb IwK
+K}YF"
@m'C?X
@KNtnN
l$SKdz
^iEZ"&V
*dQ?@V
rWDRhR
=|?}iU
|VARK]wH{b
<3@iKwU
y'tZp.
`<nJT)
lNRXn{
5x(JWP
wvdrbX
fWd9|,
;}$9:X
Fe'7vc
mS'iGC
3,5S|
M>A/&x
&ODw"\nd
#r(%1;
Tr_EC;
Z#i_"X
*_j&Sw"
`r)o!-
M<>:all.F
;#.fCXs
XC].KB
A.$0ha
7vfaPX
3k#6?\d
M+F*_R;
',Z*;\
BQ+ K=
;-J4_1
B}a/Os
1_M'nu
p7v17c
zE\-oc!
9j/3)}-4
rfnn2{:
1;7nCL
ob'"g`
KnE<IQ
wT{(-!F
>PgQ"\
2`5>uP
B24d|u
!Bx49e`
|4?l`WH
vn<;?n
MzeFog7
'H)%;F
Bue!QT
nRt=j(`A
"9- xYt\
~*CLI]
v!-`(7
%&Q~-$a.
}&}_.o
aK?V5Iks
O`.A7g
n4y${%k
jIq-QfZ
3GWLP/
z188y
lk]H8l
g'o5$>
Wt_U.]e
=B>_U'
9Txq m
Pex?[>
kc;cQO
X)$,+
@,bTu`
kR1HvE[
|F]leX
<1F[4mg
'JPw!^
380Bap
##o`"C
p)9k(7:
5KraE"
3,<b&R
Il7>#":.7e
YHhP&8
-(0_78
o04[W_C#
G6g(0v
A[Ka->
j$]6|i
u6)x3)}
F,Sq\-{
40qCLr
PYN<N-
#% 3%b*
fQy<-B
%hN:I/
tpxD;{
4Vlzj<
h/'q,'
b]}HwC
2[[Rm)
$t]r9F
IX$3=
!J@T>10q
X(gF,87
)zKn2H
\%^]mlm
26kf G
&Dl$.Z
[W!`C
DNpD<
wU\=XK
({F%VS
/ .g=0
tjO"G
'u>ftL
j$<pFOk
c+><u
Errc1PG
>aGBmx61XT
V:{ Qt
</a2L0_
hHg$m^
74rtTL
>'% OK
,x<N}.
X"Z:43
l7l_Nx8
:}|gI/-J
{7vvL-
}J!gia
_N'yMK
\Gw7n[
>OEvNzR
>$XyD;W`x
rP.!@y
m3x47)
29,){x
,iW4`5
a33/]Gy
3mPR]UK
Q3{,Ml
G9{o&%]n>;84
t<?:X~
WYHkG
}(S#A.
q>\bDk
,b:dvE
T:f{*Hu
D gy6sx
g [B;Gnt
B^-X<>
T5W;dQ>Qc
q8K}Ed
g};YP>8i
1dafuE
NB}(w`/A;
Ml%-4
1^H^h[8lEzD
6r0CE
K6~riu<
m4z]]=
:|g<:7
;z?6gJZg
PI|&iX*
64#J`
FK`D_QK`d
ch /e\!
e%]^:G<[&
}ehIz.;
0QW.d`
)7 c,q
6&({>u
;="fT
QyH%; q
3@q_6,
oPS.N:
F{K;u|9X
Q/Yyb+
NvQ?)Q
<Q`2Dp
"#8I$=N
4zC{hL
$k~%i?
WX:]_8l
/x;03d
xf&W;q
@~ rY+
]V]&XW@
r\8>=p
c^PEiW5
?zeHw0e
P$HdaYLO
@.6l-Y,
5G?f0pF
4?/;E5
-}Jdv&
/Ndl{s1
i>j[H1p
2CLVp@U
C3|7J>Z
L]-*yC
\^-AW+
{9E (ZR
2$Yu(8I
H>W-~h;
n|.q8b
k_~K,$
[AEFQ1
80{!-/
[$mPqK_
[F4:5
/#Cpj.
TnBW2)U
lPF{R"
{~}\)\
c%c4R(D
gmZ`A5
i]h1S*:
7T]Th?
pt0yI
t)8'e#
<nJ$nU@
eF}#7~"
-.f6ng
3>W^pE8
g"]X>xlj
O%P!`t
`;r=wEF
=|o%PdA
QyHvsQ
U/]]Y}
6,7=7D
S*:P{2K-K
\n*]@
w,#Z(V^w$
:yzh:w
RVdbh
<UtXf4
gbL81h
2B'X$px
vF1HSB
?M\tXf
9{y*Ql
h=BDt}
CDw>s?
|(`N]WclMl
;acIhJ
sj"|f@ja
t )/<=
&9Xp]D
D'n|sC*xJ
QIsfx:o
t<pX8!e;
6zw_fN
YyHB=2
nZfv"&NE
h=cGhI
jzvlcd
n)JyM2M
mFLXw2
("<>:|m
WCwgc!
^iAWUk
X%R*Fo
/@H>xlK
Zno'c[
U}ygrF
pa9e2s
SwX`Zp
p%ff&$j
5^g)A4
*1Rn2|
SZ0|CM`
KAZ{oz
@T]/U@
}tb$Bg~
(7:*rP
8 DOaFM
7Z.M"R{
WSF9|EF
0B9_s'
/QMMk
lDIY1#g
^ghiJt{rz
y2Z,iZ_#
@LDO8D
fZ$n~w
w&em7b
sDz{'9g
gA=Cfw+=W
`&I@;X
C|uU"p
BQ%J/cO
v2p,Ph
Fm-7G(
9xLP/H
p*H!?
Vcat7i
NWXP#u
+:32/r
E}Dp9p
D5(mM~
oBeK.w6
7uuWD<
<![\ch3T
5#l#}9p
YI}|`M
qY}G77q
=B@5:t
aO+?WfpG
L"12l
Mi~=cZ}
N9BGDP
P+j(da
00/qx7u
8a!)6q:
.>,kA6
37?+O5
E!UGRQ
RR?@5*
/8-KKA)
;;Q-GQ
HDU!B}
;FM{Jl
T<ZL%e
O$*!A~
UCLFv3
FPDRxb,8
>Cgh)O@<
~3\!#n
p,B!i>N#
83>|]I
|?Rj|2
?3M0i
-SCf9zm
^5V2YU
Ls{Ch`
V*wdnw
d@((rw
8VUY~q
5"$]lt8D
MQMxj4
U2Sy?$
?;)%?WbQv
>]zUVQ
`y:dZR
uktW1/
#=2'-e
Q:04iS
X+TLr;
7.:UQsT
K5f/iw
DacJpY
.(*~n@
%y,mG-f
(75Hq)
jDBM6$8
G^W+m
U?%#g
KzH%S9
D}"YA6+8
?PU$_P\
0ibl6|
B+bom-M
aXLRLs
syP\!j_
_a<fDg
5KYayw
&d'^P,y
>x9!P,
+JOIRf
%>\^6R0}oWG
e[Bg<|+7
fSd"}Z
}Sgehb"
F._n<F
zN1lI%
tkNx5NE
}p4>y/
\G@79[
$owA|!
T[L9,f
JLsWt3
]0$?Py
^Ps|^:
\oy.[J:
4g]gE4~
B[ sp;c
S'(7`}
{E\%0\
q^lv\8
8e!Te1
'UThm0
$\=rkya
\)8/OucFaR$*
CusVQq
{'e:Q9
:F`,{
tvaV\
a*23AZ
-N?\[4
wt6=[X
"sxIh
m7=57k
6n'8IW5C
nAF`k>-
878|$:J;
IhnA'i
R|`)g4l
cscd 4
3pf)KY
((tI}`
?.Qdjk
F2UYR>
w},y\)
k\M9t}
~b)z^@8'{
)g ll3
Z.cnh-s
a3lJE?J
M&8P'T
wwv(=`
d;uo#
TN_i,TO'}
}] {O[}r
MDd+Sq
F/G5R7sO
:HP(7x
VPeZ~Q
d_S'T}
m>(L{pH6
[]A\A]A^A_
(]_^[H
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
ADVAPI32.dll
KERNEL32.DLL
USER32.dll
USERENV.dll
WS2_32.dll
LsaClose
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
ShowWindow
GetUserProfileDirectoryW
VS_VERSION_INFO
StringFileInfo
000004b0
CompanyName
Oracle Corporation
FileDescription
Java(TM) Platform SE binary
FileVersion
8.0.2910.10
InternalName
LegalCopyright
Copyright (C) 2021
OriginalFilename
java.exe
ProductName
Java(TM) Platform SE 8
ProductVersion
8.0.2910.10
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan DeepScan:Generic.Dacic.1.BitCoinMiner.A.BD16E9F4
FireEye Generic.mg.eda88d322065a9b3
CAT-QuickHeal Clean
ALYac DeepScan:Generic.Dacic.1.BitCoinMiner.A.BD16E9F4
Malwarebytes Trojan.BitCoinMiner.UPX
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender DeepScan:Generic.Dacic.1.BitCoinMiner.A.BD16E9F4
K7GW Clean
Cybereason malicious.22065a
BitDefenderTheta Clean
Cyren Clean
ESET-NOD32 a variant of Win64/CoinMiner.QG potentially unwanted
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan.Win32.Miner.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Win32.Trojan.Miner.Anzk
Ad-Aware DeepScan:Generic.Dacic.1.BitCoinMiner.A.BD16E9F4
Comodo Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
CMC Clean
Sophos XMRig Miner (PUA)
SentinelOne Static AI - Malicious PE
Jiangmin Trojan.Miner.qhg
Webroot Clean
Avira Clean
MAX malware (ai score=89)
Antiy-AVL Trojan/Win32.Miner
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Miner.gen
GData DeepScan:Generic.Dacic.1.BitCoinMiner.A.BD16E9F4
Cynet Clean
AhnLab-V3 Win-Trojan/Miner3.Exp
Acronis suspicious
VBA32 Clean
TACHYON Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
Panda Clean
CrowdStrike Clean
No IRMA results available.