Static | ZeroBOX

PE Compile Time

2021-09-24 10:28:14

PE Imphash

d8015d2a3e764c340a134c25fbcfa53b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00043000 0x00000000 0.0
UPX1 0x00044000 0x00032000 0x00032000 7.92795637357
.rsrc 0x00076000 0x00001000 0x00000600 3.66185058034

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0007605c 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library dxgi.dll:
0x14007627c CreateDXGIFactory
Library KERNEL32.DLL:
0x14007628c LoadLibraryA
0x140076294 ExitProcess
0x14007629c GetProcAddress
0x1400762a4 VirtualProtect
Library ole32.dll:
0x1400762b4 CoInitializeEx
Library SHELL32.dll:
0x1400762c4 ShellExecuteW
Library urlmon.dll:
0x1400762d4 URLDownloadToFileW
Library USER32.dll:
0x1400762e4 ShowWindow
Library WININET.dll:
0x1400762f4 InternetOpenW

!This program cannot be run in DOS mode.
1bRich
w@SZ H
H@L$ g
PBL9I<D
o~pxP_
6La?xe
.0A]A\
hk^\@S
@ZPHMD
t%)@Ly
RPqw,J21
^F~6u'02
Wk6UsX
IGSg<`%
P*Px 2
x'_fB B
4cd@80J
tV2tQ~[
|$|.u~>$~
uc{I{t
VN;VXt
>,S+u]
HI7v:V
sD$`v0
PpH!#0
NtcE+`
|G]L$L
XXXT\Vf#{P
TP@"yU
T[h/5Rf)
PCLJ}M
OX__O>
<OWWWW@
7w G"R
9Ss>F:+
i6jK8S
K.<Ns!
tZIfzy
:wP`AA
L/NDGbS
SmT<CTlv
[`~44x
X.50u (
H4Hw4M
Gg;]*5$
5SieX4
~P*~-L
4?{3qx
<C )$^
d!1;$LJkh
!LH5~h8X,6*
t5?`0s
4MSSSSp
baKMG \8@
4MOOOWWPT8
u=I H9=z.i
@tn1f[v
ANC+~uf
It`N9D
H)>h3`XPq
A*|08A]_^ C
g@fH>-
`5!\ .
wK@#v@
`%_icJ
8!0Z*A
3od`LY'(
GFF0@P
-Lk8,E
a:%]zC
HHAPAa
33qC4.
DI@6Jr
IS92HH
9ISJHH
D1XHst
uJ)Up"
*GV `y
Lix *)
)Z`as"
nRAX @B.
ok#'i\x
\xKL.&
}}}Hc%
5.M3Dy
4KaF:.
pg*dl)
VI! Dt
~L9Qhst
pSW|K:
o/>O@>
*bW8U8
*GwOW)j
1(|,c
00@@P3
B 0lw'
Z03 0X
(0D,84
;;ED*S5,
(O1O9
+T]!_~
YGa{(H
&pZ7N^B
"_N `5
RFB9E1
2rHsC>&tE"
7H7,(F
<IZ,T6
">,iFxA
T6pK@D]
EjJpot
R*_8Y
Cb.d>p
_?U.];
Bdz'{t$4-
%_)iu?
{p@Q<\(C
oTAY@
t#*)`p
<AuNt#
^!Ppm3
.4DD80\
6%xb8,L
BP(gJEb
LTHB=5T
HsLHHD
Hs,(($
5`ZE(E
~KA0hE
4bmH]Lu*E;m
P`aXd#
MF2_!H
+'o]SF
Q+`E8v#@
v@9xh/
]hu#[q[k
+%(fkC
%?"$33
5tVT8#
{f #@b
8$'@/V
sSgJ|m}
.nHR..
NtUt"tO
'O@<&?C
`'@%[i
V|!<m9
\z8r`|
jt8LOM
.[uyGo
%b[0L-c
Bz%%+Q
ONXBdZ
Sr2]g\C
WjJUwmE
4)-XB"8
DY\X{-
oyxXuF
FFfw!L
}.J@MP`pI|
<@0 "0
c!0G0=z
,ZClL
51Y::T
Q,kks\
83T"CD&
"u4I9}(
kPOOcN
@[1tNd|</
E)=3;*%
K>R`nW
U.g9u3
8(>(3
?Dun`+
l3_o=UWM
aD;Kc\O(
$ Qv_.0p
{9p@u+
s1*w<a
Hx@.#=
F5(SJW6F
X)~Pjm
ZXcX2a1
-D&9~W-UO
9r*9m8
= M(V%
K03CJl
!v!H00J:
}+\)kU
sE1aP<
v>!T6;
E+BEjP$
y?P{=J
=71+%N
<lt4<t
&<Ct-<DD
&StW@:
_<g~{<itd<n
<ot7<pt
?wDtm6
!,I<%w
s<l-noT
bc0C;>
sqDuw1
@41%ASd
Gx"8Z(
_(d___4
n\C8_OH
w/0yu(
72!O&&
0"y0!{oy
10F 3@0{R9
<# @0P
?l|>J
{.!l16
(\=GDI
'X^|OX
wuSTDIV>
MVXjH_i8!Pp^
{:AI^W
[q+L)m
<=t5ye
?big_9
H33M~[H
~pZH\c
tk{G%-
`kO9(h
KolX0tJ
ist._tn
B,uL1n8
E (Cu,
HR.fB9<{u
_$At[E
V;%x`0
yl};{u
~c;(\+
3 PqNJ
|JJ<aw
Y_?tFm
>x+xII
,2[rx'
\fb:f9
8ON."YO
tRbNH9h#
32#be|
t3Z'C{<
{3,8m3+my
D8\0>t
E>f5PS
rb?R8`
WDZKQh
ca'@8Q
D.L8LT
nmEQxR_e
WB_V0y%
/"jmHc
Cf4S=
:p+%`.*|
vf/jqQ
;,DF:\r
rx4'FM
WI2@va$
7IHHrUD
MHgj1(
f{H}UnB`Mt
4x8|<P
m{70f#8
HVB>=!
<M!-Abb
AOQ%`*\>$
\ZM68D
|F;S}=
LE2nWX
-6=n_j
dG*>DOD
J{PD$T
r*u/f+
fbCF-*
HyXp2C
0545&Ezclq
xgW#i$
%\m{f0
r32216
Yf0p1D
M)86@M
-Ttg-i>
v:&Ep(l
X`h0vi
:&(1 i
(DIVC@
8h1QHE
0d77!D
\)bq_O
w=uJq30
M=Ib _
n~7#BT
xPPZ(@K
f<32ne
mHHu+A^
p-06Xt
]G1zrr
zrw$E}'&L
M95i2t6;#
%C2A@a
t17m|X@(
K "B(
vIxbx*
Mn82Im
4WRT4S
TVU<Ws
)N<CRVKo"0*O
%#!(`,
^\$~2I^
mCbaf#
b"Jtiv
'!-ckBCP8
u-l_4O`
tS>tN6
\iGi!WN
X`4\KI
_h%;(l_
X7) e<Q
jZO^cr
&) u8I
3?EBM:
t#u|2d
M_HOYX
' #p?4
6@t`0Lc
;LXPta
{5Ci^h
Ai\@/P
?|*uwz@
4\+O1J
AiveR.;m8!R"Nw
+C2sw.
,,n]q88a
%@WX-X7
v;G%|b
c{p(K_M
4p_$YB
aX:D+(
?tKR'B
6N@t1[
8Dh`Th
}eJ9AHw
YLG0x
X;3H][!
BQBK+x
TpHbP2!
1*Dam+
E0q0+)8
o0i/86
"NNNN0FTjNNNN
0''''@P\n''''
,rrrrJ^n
89999P`p
@NNNNLZhrNNNN
.@R''''bv
~false
&-Error,
couln't ge
urrenm
ry info_'
? Ag/:
'oloadi
@eEjp _
1.01 C
yright
998-2004 
:tp://w
m/zLibDHf1
.2.11z%02
+c6|w{4M
6-9'$6.:*?#1pHhX~AeSlZrNbS
T~FbZwKi
<{pmfW
<FMP[j
sxIB_T<
<GLQZk
ryHC^U<
ODu~ch<
<zqlgV
<kfq|_
<m`wzY
tyZW@M<
xuV[LA<
<al{vU
<gj}pS
~sP]JG<
ZSle~w<
<;2) 
ahW^EL<
<MD_Vi
<|ungX
<GNU\c
PYfot}<
kb]TOF
{sKU<
L&&jl66Z~??A
Oh44\Q
sb11S*
D""fT**~;
;d22Vt::N
J%%o\..r8
eader c
unknown
p<ssio
ovalid w
flags:
|Xe=leng
any' J d
fymbols
4ys2Td-of-
m3/!fa
[-&LMb#{'
w+OQvr
NnyhJ
)\ZEo^m/
H*0"DW
IiGM>nw
ewh/?y
stream!
i#{?in
sufhci:mem.
yb*LSO
AG517 MPk Adl
ba|al%
/ o,{r
3@dAe?<
8sO&Bt<
<DuCvG
rB(z@{'
mily not supporte
seQavafa
connecyj
/rgumvlp
ilBg/ou
gd"crip
;f0</mHf
rl8vi&lD
sp.e:
uqwrVc
0123456789*W|UQc
ijklmfpqr
duvwxy
`d_h{!
_^x9!/v
__ba(}
*cl.pcals
lthis!^
2ptr64
<<W= !~c
-/%oh<
`rof-.-d
guard7`
C`Fa"a
?%`.pyi
;Z (?Ar
/!brr;5AC
*9dB(
!"#$%&'()*+,-./?"
:;6?@M
?[\]^_`?{|}~
ABCDEFGHIJKLMNOPQRSTUVWXYZ
[aOni*{
~ $s%r
@b;zO]
v2!L.2
pnONNP0
9999pP@
r{rrp`@
p''''P@0
p`rrr{P
p`rrrrP@0
Zod(N~
qS>^h3
q/E=$% B
o49HoKC
P'_MN*
TbRB/&U6E&I
dhlNNNNptx|NNNN
8NNNNP`x
TWvThu
M/dd/y
o5HH:mm:
.Oo'_K|m
fo[tc0
u+p&ofe"
reFRAp
isANSI
DTFgLhvk
IsV^Q?H
9(#,$0%
rB4&@exR
2oqrtME=
bwmodfld
0_c_hy
f@or?y0
t`Pb_n>
?~de+
T/cRUTF-%
16LEUNICODE
01`KC
^PJ;I:qE>
[cZUg^n^=
[*ncd>0
W^y]%>
o~:kP<
%f-QY^&
?7zQ6$
8IeXCpZ9Ie
C0LXVi
SxDzA
2IG@Hh&
G/pT~O
`j/jsao?
iSaRoo
d*-*BEx8
/-3O/v
P X!`"
#h$9!'
9!'8O@PrBN
HVPWXZ
r #0$@%!'
7(8rBN
89H:X;
h>x?9!'
0L@NPO
9!`PpR
?m/6X
OZ?dhK
k:LuH
kZy/|8vW_
uX?e]
???Kz,
[/NE/L
;P?f_C
AaBv1]
K8!'8;(
z/rBNl@?
49!'v8
hixo9!'
$k?qK%6
`Ccjc
?rop+
ky3t\H[
QNANS.Do
p~,/gg_
h_pFx;;;
=imb;D
VM>cQ6
>jtm}S
+M<7~=
BC?t9^
"LKs@>
kE?M>`
5POJ!4JK=
~!a%d\CE
6k?Mi8
BDCa.Mj
dOV~^H
p[Gs?\
1posi
pp _v2r
Hansg:rH
?hxIN$
-b,6PW
&#^`$f
^#^8%4
F)dj_@
l6"_aa4nGy
xCAO'A
XO`/!O
voltmd.
>rtc$5&
J\lsGf6
"D1GXK
G0'E'x:
0"Bg[
RG>0B?B
/tO4S't
F!&&t8
lI36m
,',G53l
lBuB8{#
'f+*n&
gdT4m
d\_AJN
4D`9O@
]b>cb.
"t"46M
8*fOBIz
~T4RoE
'$7)^d-y
r#Rbd1~
cHd@@O
@DU$ch
|]dCrtE
%G &.m&
[1d|@o
YF\F!K
P5Rw6|O
EA^tHAq
yw`y~y
JYW"Sizk
(Outp
Moduli
Toolhelp32Snto
TshotM
tiBy9W
feHand<R
qadLHr
\VaNabE9lA
COEMCP
tlC4'%'Et,
SLi@H^
lx0RWd
TpURLD
rl4W8_
U=h;0_
4 xXH
GKuA .
(]_^[H
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
dxgi.dll
KERNEL32.DLL
ole32.dll
SHELL32.dll
urlmon.dll
USER32.dll
WININET.dll
CreateDXGIFactory
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
CoInitializeEx
ShellExecuteW
URLDownloadToFileW
ShowWindow
InternetOpenW
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.4!c
Elastic Clean
MicroWorld-eScan Clean
FireEye Generic.mg.844b7e033c078ed6
CAT-QuickHeal Clean
McAfee Artemis!844B7E033C07
Cylance Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.3b7264
BitDefenderTheta Clean
Cyren Clean
Symantec Clean
ESET-NOD32 a variant of Win64/CoinMiner.AFD
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Win64.Trojan.Coinminer.Dyqd
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.Dropper.dc
CMC Clean
Sophos Clean
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Trojan/Generic.ASBOL.C5E3
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Script/Phonzy.C!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
AVG Win64:MalwareX-gen [Trj]
Avast Win64:MalwareX-gen [Trj]
CrowdStrike Clean
No IRMA results available.