Static | ZeroBOX

PE Compile Time

2018-09-09 06:42:47

PDB Path

c:\885\Thus\Drop\Occur\159_take\King.pdb

PE Imphash

aab827ba47455fa1cd60991a1f7c1641

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002c547 0x0002c600 6.57653912075
.rdata 0x0002e000 0x00027c18 0x00027e00 6.16970939779
.data 0x00056000 0x00017098 0x00000a00 2.23230690125
.reloc 0x0006e000 0x0000124c 0x00001400 6.37558548817

Imports

Library KERNEL32.dll:
0x1002e070 WriteFile
0x1002e074 GetConsoleCP
0x1002e078 GetConsoleMode
0x1002e07c SetFilePointerEx
0x1002e080 CloseHandle
0x1002e084 WriteConsoleW
0x1002e088 DecodePointer
0x1002e08c FlushFileBuffers
0x1002e090 OpenMutexW
0x1002e094 GetConsoleWindow
0x1002e098 LocalFree
0x1002e09c VirtualProtectEx
0x1002e0a0 TlsAlloc
0x1002e0a4 GetSystemDirectoryW
0x1002e0a8 LocalAlloc
0x1002e0b0 GetModuleFileNameW
0x1002e0b4 RemoveDirectoryW
0x1002e0b8 SetStdHandle
0x1002e0bc HeapReAlloc
0x1002e0c0 HeapSize
0x1002e0c4 GetStringTypeW
0x1002e0c8 GetFileType
0x1002e0cc GetStdHandle
0x1002e0d0 GetProcessHeap
0x1002e0d8 GetEnvironmentStringsW
0x1002e0dc GetCommandLineW
0x1002e0e0 GetCommandLineA
0x1002e0e4 GetCPInfo
0x1002e0e8 GetOEMCP
0x1002e0ec GetACP
0x1002e0f0 IsValidCodePage
0x1002e0f4 FindNextFileA
0x1002e100 GetCurrentProcess
0x1002e104 TerminateProcess
0x1002e110 GetCurrentProcessId
0x1002e114 GetCurrentThreadId
0x1002e11c InitializeSListHead
0x1002e120 IsDebuggerPresent
0x1002e124 GetStartupInfoW
0x1002e128 GetModuleHandleW
0x1002e12c InterlockedFlushSList
0x1002e130 RaiseException
0x1002e134 RtlUnwind
0x1002e138 GetLastError
0x1002e13c SetLastError
0x1002e140 EnterCriticalSection
0x1002e144 LeaveCriticalSection
0x1002e148 DeleteCriticalSection
0x1002e150 TlsGetValue
0x1002e154 TlsSetValue
0x1002e158 TlsFree
0x1002e15c FreeLibrary
0x1002e160 GetProcAddress
0x1002e164 LoadLibraryExW
0x1002e168 ExitProcess
0x1002e16c GetModuleHandleExW
0x1002e170 GetModuleFileNameA
0x1002e174 MultiByteToWideChar
0x1002e178 WideCharToMultiByte
0x1002e17c HeapAlloc
0x1002e180 LCMapStringW
0x1002e184 HeapFree
0x1002e188 FindClose
0x1002e18c FindFirstFileExA
0x1002e190 CreateFileW
Library USER32.dll:
0x1002e198 ShowWindow
Library ole32.dll:
0x1002e1f0 CoUninitialize
0x1002e1f4 OleSetContainedObject
0x1002e1f8 CoInitialize
0x1002e1fc OleUninitialize
0x1002e200 OleInitialize
0x1002e204 CoRegisterSurrogate
0x1002e208 CoRegisterClassObject
Library ADVAPI32.dll:
0x1002e000 OpenServiceW
0x1002e008 OpenThreadToken
0x1002e00c RegQueryValueExW
0x1002e010 GetTokenInformation
0x1002e018 LookupPrivilegeValueW
0x1002e020 CreateServiceW
0x1002e024 RegCloseKey
0x1002e028 RegEnumKeyW
0x1002e02c QueryServiceStatus
0x1002e030 OpenSCManagerW
0x1002e038 SetServiceStatus
0x1002e03c SetEntriesInAclW
0x1002e040 DeleteService
0x1002e048 RegSetValueExW
0x1002e04c OpenProcessToken
0x1002e050 FreeSid
0x1002e054 RegOpenKeyExW
Library COMCTL32.dll:
0x1002e05c CreateStatusWindowW
0x1002e060 ImageList_Draw
0x1002e064 PropertySheetW
Library hlink.dll:
0x1002e1a0 None
0x1002e1a4 None
0x1002e1a8 None
0x1002e1ac None
0x1002e1b0 None
0x1002e1b4 None
0x1002e1b8 None
0x1002e1bc None
0x1002e1c0 None
0x1002e1c4 None
0x1002e1c8 None
0x1002e1cc None
0x1002e1d0 None
0x1002e1d4 None
0x1002e1d8 None
0x1002e1dc None
0x1002e1e0 None
0x1002e1e4 None
0x1002e1e8 None

Exports

Ordinal Address Name
1 0x10023050 WICConvertBitmapSource
!This program cannot be run in DOS mode.
RichD;
`.rdata
@.data
.reloc
|$8HcG
A^A]A\_]
}9[9BY
LhG}K0
_g1S0U1yh
hW%Cb &
#>cfu*7
`A_A^A]A\_^]
`HtHH\(
HH`*@u
0AH[]H
_nqt$mbH
`"8SaE
A@H0hA
0L3 HUH
L$T$HA
%N_Tw(
Hog?z(
`v[h>131Y
0DHH@1
|xQJmD
EH$HpH
$t$E`[
tLHcE|
$pH"HHu
$H$H$0
5]'@UL
$MM7]p
HH$$J[$8]H
\`;fL$
?35LM:!
CHH3LW
HH0EH$
uXXHHH
(Y>1Pg
=-/'A1
$HHHH`'
|#9h.l5
L3 HHV\
H$H Eu
WLHnmN@H
LKPHH$$PWHH
MYH)e
Ku"C!
!&bs!
H'$HH@
HEHHIH
t/`hFR`
$HK#HH
H`A0$H
($AOP
@Hu&u$H
@UHHTe
H%.EHH
`H+\HC
7AHHTV
E$M@SM
/HH4L$
gXcQei
JXA-$H
S[wls3
JHHCI$
oHSP3'
M3$H$-
0DLIHL
H_3$LHGK
EHE/LH
$H$WHH(H
HPH'H3
HHl}h0HY
HHHHH
HHiLTA
#DL~0.H
0(W+HEHI
0lOZKD
LH'-HH
H$ *H
?]3HHL
@tHHE*
80($HP
HHHMuH3
EW/H`HI
_ULHH\
@0AE3E
HHPLMx@
L$$@*$
P XHH4HL
$0!3HLs
HLHH(
AH:LHH
$HH|$H
yHD@Ht@M
HT~HH$
Ht$LXtH
t$,u\tEP3
tH+u$G
` W/MH
$$8HD(
OHS$H$L
H@2.UM
8HDDA
M]LMutH
!HHHHL
[HCRD\
T$ MHA$Ix
/`H$S_
i|HtP@'
HL$&Hp
`$t\H$
03$O$3
H( $L"
MHHH2
HEm(HL
MHH"tB
JU^UA_
HHIHtHML$EAI$
tH8HtS
HtI$v\
lHH@hO@
HH $0
H*+DHH
t^Ht$0
VT@ H|
HHHt(L$$G$
H$'t^H
@P `3$
@H@DH$
0$MFSH
HDHNO3
AE LH(
HlHPLT
T@'I3H
HAHHHHH
H(HH~m
HeHHLM
9H |t\H
HDAHU'
mtM0LLH
A(H$HH
uQPDH@
LeHHWH
pT3L;0f
HLtLHHt
WHHHHHG
HHELIHL
HH3\,H
H$LDHX
H3xP3&
M,tH`H
HX$OlH
@HWX*
sS/sH$!
IHKKHE
E+LGH$IH
$\pH H+H
L$O0(]
$H+H$H
HCD7H0
0H\]H{
@UH\DWH
PHHAHH
+D$ +D$
T$$SVW=
D$$?r
D$$?r
D$0iD$4
URPQQhpK
;t$,v-
UQPXY]Y[
WWWPWS
u-PWWS
SSVWh
f9:t!V
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
QQSWj0j@
xg;5 r
x7;5 r
x7;5 r
Unknown exception
bad allocation
bad array new length
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CorExitProcess
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
GetCurrentPackageId
InitializeCriticalSectionEx
LCMapStringEx
LocaleNameToLCID
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
F7o^XTc
]X[/vp
SQ1763
uRR!N]
utwqa&
gnYKER.
}}}}NNNNTTTT
OOOO$$$$
k1g)gm
}FK}<"
/)eO|6Q
ev"X]vx
Bn^ZD9
VR>Kz6[
`[3yqW
+*.mOA
h?Z0f/
uPx~iZQ
,A|J[Y
LzH[oe
0rMx\-
*+(u5:
WVI9<?>9
}l"~SA
qo.>01
NnPIQ:;T
,|q8?9
0(l5/9m
p~=}$Le
JI9RxR
UQE>p&
Ma6./J
>D%k}ta
nhN,yj
RvI"h)
Tw,:<x
JJ;nmJ
JXIJI,
JIJPj9
Om~NQM
PIOqJ~x
lZJIOI
KcnlJl
lJl[PP
XoP6CJ
IIJcwI
IINIuJ
lJNLIJp
ZI-OJI
l[wk?IQI
os-JJR5
ImJkJl
VVVVDD
DDDDDD
c:\885\Thus\Drop\Occur\159_take\King.pdb
.text$di
.text$mn
.idata$5
.00cfg
.CRT$XCA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
King.dll
WICConvertBitmapSource
RemoveDirectoryW
GetModuleFileNameW
GetEnvironmentVariableW
LocalAlloc
GetSystemDirectoryW
TlsAlloc
VirtualProtectEx
LocalFree
GetConsoleWindow
OpenMutexW
FlushFileBuffers
KERNEL32.dll
ShowWindow
USER32.dll
OleUninitialize
CoInitialize
OleSetContainedObject
CoUninitialize
CoRegisterClassObject
OleInitialize
CoRegisterSurrogate
ole32.dll
GetTokenInformation
RegQueryValueExW
OpenThreadToken
OpenServiceW
StartServiceCtrlDispatcherW
RegOpenKeyExW
InitializeSecurityDescriptor
FreeSid
OpenProcessToken
RegSetValueExW
RegisterServiceCtrlHandlerW
DeleteService
SetEntriesInAclW
SetServiceStatus
AllocateAndInitializeSid
OpenSCManagerW
QueryServiceStatus
RegEnumKeyW
RegCloseKey
CreateServiceW
SetSecurityDescriptorDacl
LookupPrivilegeValueW
ADVAPI32.dll
CreatePropertySheetPageW
ImageList_Draw
CreateStatusWindowW
PropertySheetW
COMCTL32.dll
hlink.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
InterlockedFlushSList
RaiseException
RtlUnwind
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
ExitProcess
GetModuleHandleExW
GetModuleFileNameA
MultiByteToWideChar
WideCharToMultiByte
HeapAlloc
LCMapStringW
HeapFree
FindClose
FindFirstFileExA
FindNextFileA
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetProcessHeap
GetStdHandle
GetFileType
GetStringTypeW
HeapSize
HeapReAlloc
SetStdHandle
WriteFile
GetConsoleCP
GetConsoleMode
SetFilePointerEx
CloseHandle
WriteConsoleW
DecodePointer
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVtype_info@@
0%0,010D0I0O0U0[0a0f0k0q0w0}0
1!1'1-12171=1C1I1O1T1Y1_1e1k1q1v1{1
2#2)2/24292?2E2K2Q2V2[2a2g2m2s2x2}2
2(3-343=3F3Z3f3n3t3z3
4#4.4=4M4Z4`4
5'5H5S5
="=(===Z=b=z=
=/>C>O>U>
>"?9?L?s?x?
0+0=0E0X0d0m0
2<2B2U2]2
3)323F3Q3W3a3l3~3
4%4-4B4a4g4p4
55(5.53585R5[5
6$6+636>6Y6n6
7$7*7L7S7a7t7
7F8Y8_8
99)9/9
:5:>:c:h:p:
;*;F;[;c;h;n;t;{;
=?=]=m=
>1>D>J>Q>`>}>
?(?C?H?N?c?k?t?
0"03090S0`0
11$131=1E1K1S1Z1_1e1k1v1
3$30373F3L3R3[3c3t3y3
444A4b4g4
5'595Q5
747:7@7F7L7R7Y7`7g7n7u7|7
8W8f8o8|8
;';<;Q;X;^;p;z;
=4===B=U=i=n=
>$>*>?>W>]>m>
?&?A?L?
-0A0H0x0
0$171U1c1
3H3O3T3X3\3`3
<%<K<P<{<
='=O=c=
>#>*>0>E>X>r>
?,?4?j?
010;0G0L0Q0o0y0
1#1(1<1E1
1&2C2O2
8%9L9f9
<I<X<n<
<R=Y=k=t=
3!3&30353@3K3_3
4,5>5P5U5b5n5
6'6-6;6D6I6i6n6
6E7N7V7;8
9"9(9C9J9~9
=+=B=I=~=
>0>9>F>P>r>
?3?L?[?g?u?
000:0V0a0f0k0
1;1K1g1r1w1|1
2"2E2P2]2r2}2
333!4+484k4}4
4'5.5A5q5
6/656G6
<$<W<^<e<l<
0G0\0j0s0
4/5_5z5
7O8V8]8d8q8
94:=:U:g:
;);5;=;U;
=)=7=C=O=]=m=
>!>5>>>I>S>Y>m>y>
333G3w3,4
;}<?=E=
?4?;?R?h?
0\0p0K1j1o1\2}2
2M3_3q3
4%4F4X4j4|4
8 9W9v9
M0g0t0
1H2R2|23
4A5M5a5m5y5
6/6?6K6Z6^7
8%898D8
:+;,<<<M<U<e<v<
> >e>q>}>
0%1/1J1
1+2=2O2
>f>k>}>
2$2(2,282<2@2T2X2\2`2d2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
= =$=(=,=0=4=8=<=
`4d4h4l4
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
1<;D;L;T;\;d;l;t;|;
$8(808
9(9,9<9@9D9H9P9h9x9|9
=4=8=@=H=P=T=\=p=x=
>(>0>4>P>l>p>
?0?P?p?
080X0x0
7 7$7074787<7@7D7H7L7
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
ext-ms-
mscoree.dll
api-ms-win-appmodel-runtime-l1-1-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-file-l2-1-1
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-kernel32-package-current-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
user32
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37639334
CMC Clean
CAT-QuickHeal Clean
McAfee RDN/PWS-Banker
Cylance Clean
VIPRE Clean
Sangfor Clean
CrowdStrike Clean
BitDefender Trojan.GenericKD.37639334
K7GW Clean
K7AntiVirus Clean
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of Win32/GenKryptik.FLCI
APEX Clean
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Trojan-Banker.Win32.Cridex.gen
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Clean
Ad-Aware Trojan.GenericKD.37639334
Emsisoft Trojan.GenericKD.37639334 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
FireEye Trojan.GenericKD.37639334
Sophos Clean
SentinelOne Static AI - Malicious PE
Jiangmin Clean
Webroot W32.Malware.Gen
Avira Clean
MAX malware (ai score=85)
Antiy-AVL Clean
Kingsoft Win32.Troj.Banker.(kcloud)
Microsoft TrojanSpy:Win32/Vigorf.A
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm HEUR:Trojan-Banker.Win32.Cridex.gen
GData Win32.Trojan-Spy.Ursnif.5L9XB9
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.Win32.Krypt
eGambit Clean
Fortinet W32/GenKryptik.FLCI!tr
BitDefenderTheta Gen:NN.ZedlaF.34170.vq4@aCiNvJh
AVG Win32:Trojan-gen
Avast Win32:Trojan-gen
MaxSecure Clean
No IRMA results available.