Static | ZeroBOX

PE Compile Time

2021-09-07 00:45:28

PE Imphash

6b9c23a9a3b4c46610e49aa6cdf719fa

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00019000 0x00000000 0.0
UPX1 0x0001a000 0x0002d000 0x0002c800 7.99658388771
.rsrc 0x00047000 0x00001000 0x00000400 4.17269422958

Resources

Name Offset Size Language Sub-language File type
EXE 0x000230b0 0x0001f200 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MANIFEST 0x000470ac 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library ADVAPI32.dll:
0x14004727c OpenServiceW
Library KERNEL32.DLL:
0x14004728c LoadLibraryA
0x140047294 ExitProcess
0x14004729c GetProcAddress
0x1400472a4 VirtualProtect
Library USER32.dll:
0x1400472b4 GetMessageW

!This program cannot be run in DOS mode.
1o|(]5
mleR56
QK[9Iz|<
=:@`0:e
k4wtHB
+u)aj9+
iAS)1>
Q<?yDs)
uUz&nhi
K6[1Rn
qR8tR4
V[e1IWgiw'I
XT`>Q0
OwP!wB
X`#6anR
lwoAdm
TydjJL
kInu}sHF
L/Fcta
k:S_l
9&kx6l
gX.OQ4
Hv}s\+<7u<
'TR>&r
}a|=[:
s}8+99
a[P)O
^m3w.:
X[s|9Z
@W]8!bM
oKiL|Q
i?P"JE
''aBE;o
_F|-K{cv
dsId6+`
^u;5}Qe
D[hkb!
|}^=q:
(g/S9^>}}]M'
=oPV/P
-'{1Qa=
5rX`slT
Gvn[hq
~$u@uY
{,i#M?W
e1/E]b
X7F|K}+
- yv*P
/Hhj>kO
0%_++>e
+P~n08
~87[Lj
w}vOVU'G
av7+NqG2
aveYA}
\FqC9S=7
PetCYc
['-/`O
LVH+BI
]-.&4y
]a]aeuX
?QIX.+
NV]+Z)hKBM
,*O3s7
"s3eV@
11BqlE[
5!#1`N}
pAr?&;
`6$cW'/
x\7gbW
uR[`3q^
$/vlM<>
$75Z1}
f7mFK2QH
"@nic=
g>(CTMt
|]Z>N[
X jy|%
g{T_)n
fV%0PY
We2ln<
?\5PhqV!K|
1%)LL6)
W5u^e
3MxfK
;;ETF4
aD\?f?K
L/%3;r
aTR=v
N(NQ+0
1PWN"M
c0Gh*V\)
,$FMLO
t&~t'?
Sh?SsLoQ
zP<Cp#
s9"I/G
g++gGh
9[3#8b
y3A+[~
6N=kF^
/>bX f
##r,c`
C[,2~x
K}V32l
(IolNi
4D#D3o{^
OQ.[PD_
%MAkp*
."nhB4P
N'=4hN]>
0,<gY80
']Gm|S
7n9qc*
m"L!@F8O
|y!}4c
:>E:Vy
FsuIVL
2`q!WJ
gB7t
E9w43#
P~$}}@
O7YX6y
)6*dRL*
k`'/?MwR
/zTsgD
jtcYpt
6v%e9Cae
p;Tld'
{bvV:7
[>'^vF
dS6Kf
IE9lJ*_^
j&\J?!5
/S*3$c
je<iU&
Qh,EcXi94vra
F>e/#L
.N4#`G
zqIqw{
uN}L+S
p1#739
N&&#3)
>'!wTK
e-TYdl
]]zv@Q
ra+?bS
4/]^VWl)
Pkpk7-zsG
H=_;G4
m^}"r6.
mdAM~
-iTaql$
,=-MDO5q
_{9|AK
Ex_P}u]g"
\-?l2n
s/nx4S
^[OzqV
mOMcp`
jthd\
cl(o@{
a/CEmr
Mqb-fWi
SV~Q$\Jm
!%`Cgv
P1/.3?0@2
?] -4i
Oppp^#
g5>x@>
HO_{m/a<{
}jJQs/
hHm_1;m
]`3VQpx0
HDs3E9
n{))IQ
u-F\Tk
+A'<1x
o_B\lA
3K2[,dQ
=6I[]I
Ae-;_a
k8@:^k
1+dR(W
+y#%4Vz
{wA=-1
D8+n7,
xfhu$w
6dC%eC
*~Pq~[
z$E}jY
1x%g+2
+YO(UU
zVy@X
bRn@?E
_R6("(
KFRmfu+>2I
+2~H7a
@C9LoP
1se7|
l":7t[
iU,ppC
")GA7,y
\F(>-d
<9rg%m
^jy{ReM
x|O(%h
iE"J'V
4`wO*N
GF`Mqd
/0?u@[
!i0=`e
~U/>jtT
U,GQz7
V1F8$"i_
.J:3V-o
!ec."G
y.b/e"V
O.>,di
gtEmV2[
&PAJ\E,o
.zNS)=$D
O">''r{a
6?`1|2
6awr.td
?e)k)g
p*=J[U
3*b-u{%
s6+6fE>W
`~l!?h9
I{].!C
>H9s>s7
;%OT=>
("!7-m
s8^Py^
CO*;hw
UM:j!=
lL1IE~||
qlCyEj
1ARi<q
&ejU~A
)D93Sk@v
Qhi`p$
2|AI87
'x{6Mi
\^n1^_*
1\\~?+
re nQ&
~gM'oH
jd 5?i
qo2{UfK]
oRM\+O
MT\l?v
7DEfX!b
vEEig@y"
'X%B,]E
|4t T`
i"Vxe>
7s]edya
vOR/U
0GH>[KD
ys84aH
(0#)}KW
|.7U#n]
S]a!UzgM7
9|v+`A
*NKI]g
zExndSt
_=0J)
A6?,0j
5oGDQO
nSRvnb{
J>s@6,
O'M)[[
4/Ad{TN
`)^S:
;r*MU!
pzDDq1s*F_aU
4pG2aY
<(p(ZG
OxY~QV~
4z@7sV
[Jk/1J
YZ:bEs,
cB9 +A
P<\-BK
ptPipT
S_niBD
:B^_y+
h+NCS&]2t
bNV@@z
IW5~.
nR(7mR
GQe/f,"
p>.3]>
]=>8LX
V]xANx
_>} u\
>;N=$<j[h
Lo'=~V
@4 "(D
6|h<&A
,`eh|]
gzdRjm<
eQla*jJ
T~5+uO-
gJUAMP
T3IT2%6
CCKAj5@2*
J k8.0H
;G0k<I9
o-o95!-
Xs~Y*R
k}2j~G~
u+SY-[
>cBVpbO
7]`U8](
{]zfft
[]A\A]A^A_
(]_^[H
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
ADVAPI32.dll
KERNEL32.DLL
USER32.dll
OpenServiceW
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
GetMessageW
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_70% (D)
BitDefender Clean
K7GW Clean
K7AntiVirus Clean
BitDefenderTheta Clean
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of Win64/TrojanDownloader.Agent.IW
APEX Malicious
Paloalto Clean
Cynet Clean
Kaspersky VHO:Trojan-Downloader.Win32.Genome.gen
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Rising Clean
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
FireEye Generic.mg.5120630343cdfdc8
Emsisoft Clean
Ikarus Clean
Jiangmin Trojan.Bingoml.beh
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Clean
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
GData Clean
TACHYON Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
MAX Clean
Cylance Unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win64.Trojan-downloader.Agent.Srwq
Yandex Clean
SentinelOne Static AI - Malicious PE
eGambit Unsafe.AI_Score_88%
Fortinet Clean
AVG Win64:CoinminerX-gen [Trj]
Avast Win64:CoinminerX-gen [Trj]
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.