Static | ZeroBOX

PE Compile Time

2021-09-11 01:49:09

PE Imphash

9c27955c0fd954648a90f6dace0af4f9

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000910d6 0x00091200 6.23240315264
.data 0x00093000 0x00000070 0x00000200 0.956986551539
.data 0x00094000 0x00001000 0x00000200 0.0
.data 0x00095000 0x05280bb2 0x00002000 0.704823817249
.rsrc 0x05316000 0x00011840 0x00011a00 5.23175471012
.afgs 0x05328000 0x0004a000 0x0004a000 0.0
.rkbb 0x05372000 0x00002000 0x00002000 0.0

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x053161a8 0x00010828 LANG_ENGLISH SUBLANG_ENGLISH_US dBase III DBT, version number 0, next free block index 40
RT_DIALOG 0x05326b18 0x00000294 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x05326b18 0x00000294 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x05326dac 0x000008ee LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0532769c 0x00000016 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x053276b4 0x0000018a LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text

Imports

Library kernel32.dll:
0x496a00 GetProcAddress
0x496a04 LoadLibraryA
0x496a08 VirtualAlloc
0x496a0c VirtualProtect
0x496a10 GetCurrentThread
Library ole32.dll:
0x496a20 CoFileTimeNow
0x496a28 CoCreateGuid
0x496a30 OleInitialize
0x496a34 CoGetCurrentProcess
0x496a38 OleUninitialize
0x496a3c CoGetContextToken
0x496a40 HICON_UserFree
0x496a44 OleBuildVersion
Library msimg32.dll:
0x496a18 vSetDdrawflag
Library winmm.dll:
0x496a4c midiStreamStop

Exports

Ordinal Address Name
1 0x4555f6 CreatePaint
!This program cannot be run in DOS mode.
`.data
@.data
@.afgs
@.rkbb
_ZYRQj
PQRV;]
PQRVW=
PQRVW=
O_^ZYX
PQRVW=
BN_^ZYX
PQRVW=
PQRVW=QR
PRVW;U
PQRVW=
PQRVW;
PQRVW=
PQRVW=g
@_^ZYX
PQRVW=
PQRV;]
PQRVW;E
xP*-E
D :T(]A
D*lT*_
U*vA"H@
J@*NU*
(qQ 2A"
CU"JA
E @D rT
eP"[P"
*0T"U@
"BA*mU
rU*]A*
#@*0U(
pA(-P
E(ZE"z
kQ*zE*
7@ OP*5
W@(v@"
PU"wE*
D ,@"UD(
@*KA(,
TU*AU"
6D"jT
sT(uA
"\U {A
*OT(F@
=U 5D"[
$T"-E*j
GP(2P(
zD"3D "A"
#@"VT(
U @@*=P
n@*uE(
EU x@
A"LP(h@*
iP"CE*Z
$D G@
"SP(-Q
E(UU"i
3T(HD
T"*A
CT*KP
D GE 8T
@"8E t
*ED*ME
(CE(}@
@Q*/P"&
:Q*mA S@*$T
aU(VU(
(HT*+E L
A |@"ZQ*
(^A ,@
*JU";@
0E*"Q(;A(
1@(oU"
vT(tT ,
NU vP(uD*m
(jE*Q@
E"jD*
T*LQ"s
%A*KE
<A"#U |T
P"\@*C
lP(FP
E(5T"]@
gD*sP _
(bP(.E
?D SE
AU*XU DQ
E*d@"w@
"dD*]@
(A"/E*
T"%E p
@*5A(4A
A("@";P(
U*3A"wP
E BE*j
pT"`P"
">A DQ
nE"aP*
K@*BP(
tP"nA"
*W@*1E
mP 3T
T(cD(u@
BA(6E"
Q zE(r
T*kE iD(
D(IQ"G
D"3D =
sT(!U*
Q(Q*"
*^A"+E
{P RP
cQ nA"
U"jU ~
D*tU(]E
aT*`T
A AP !
U Z@(Y
UA*BT(
4Q(*D*\
E &@*.U
:E ]Q(IP
(]@*8T*
*6D(VT
(U">P*
*&@ "D"u
JE*eA(
X@ ~@*
U(4@*IQ
E(NT"m
"*P"&P
dE*yD"
\E(%Q(
GQ"-U
fT(_Q"
-Q "@*
wE"wP
JQ A"
gP*R@(d
C@*/E(
HA"gP
T(qD"`
^D*,T*DQ
(KP"ST
U 5E*w
oD"7P
'Q*HP*
U*]E*{
sU DE(
E UT*}
@(,@"
dA"\D"
U(HA"D
U \U"'
U"eU*^Q JQ
>T tA(
RU :T k
*2E*@@
"U*rA(-D
zE KT"R
*Z@ ;@
HU(yT bP
D ]@*GT
E*xA"2
&A*FE*
P(@A*#P
Q*L@ kQ
A"0D(0P
"9Q"1P
T(DD*eD
D kP #
^E *T(#
QT"3U*
(T@ TE
@"BP"t
aP*/@*
RQ*ED(
2@ iP"G
nD"pQ"
D(E@*lD
EA"}E"
)T*pT"x
]T 'A"\
uA"HD"
(EQ(~A
"fA*[T
U"UD :
VP CD"
E"-U(rA
;P(VE(
A"@E(JA
3U(%U(h
"+D dE
D*\A @Q"
,T*o@*
y@((E"*
E*@Q 4
*OA"`D
(A(FE
E(RD(R
jQ*=E"
*`@"8D"'A
6P lP
:A `Q*
Q pE ]
E lP"x
U 'T \P"gA"
xQ*BD(xU";
A*TP VP
/A"(T
cQ*MP*&
Q*^P(hQ
/E()D*
[U PU"
[T(.U
A(CT J
D")T">
(`U(vA
P HT"q
*8P"5T
^D ,A"B
(bT*;T
/P"\A"
U \A"V
8D(-A(
qU({E(O
NP(XT"
RD(BD
VT TT
Q(TE"%
"$E":@*
(?@"k@
IT yU
Q*tD _A
(RE nP
YE(VA
*.A(VE
%Q"RT*
jA*5T
U(`U(7
HE*lP
*+A"oD
:T -@"E
*NE(qD
nE sD"K
`D 8A"
D"0U ;
"jE*3D
D(lT(6
1D ;U
sQ(nU(
U jQ(-
@(`D DU
QU"AP"'P*
Q*uU -
A {T(WP "D
WD OP"
mD(>E -
E wP*KQ
8T $P(?P"
Q(yQ <D
*A WD*
D*9A*{T
@ TU*R@"LQ
Q RP"J
GQ"]U(
NQ 9E"y
fP )P(P
U(n@*N
""@*E@
P*.T(cT
EA"3U*:E
A(&Q"6Q",@
[@"mA 6T
~E GU*3
uQ VA(
SA(}T(
j@*eE")
Q"]@ E
TT"aQ"
E(1Q*cE
2T %D"PQ
T R@ 1
pE(/P('
*YD ^D
A*NP E"
A DD(z@
*+U"(U
(>Q(!@
"WQ"qU
(%T([D
zU CD*
D(iA(&D
**D"4U
T(HU =P
qU*<T(
@" Q(/D
P*Z@ k
P*"P*XE
8E*q@
AA"eA
(,E"5A"^
P"RP"MD
NA*;Q"
'Q*>P
T sU %
WE T*Q@
;U*@(
"5Q(ET
?E(z@
Q dP(K
*@ ;U(c
TU"kE
9P =P*
"IP"ZD
*CA(`T
D(0P*ZP
cQ"*U
Q*UT(}
*\T cE
LE(LP"!
xQ(6@
ZU(:E(
";U KQ
(tQ*sU
.U"#D*VA
uQ(tQ
(AA"TQ
(<Q HT r
T"hE CD
0Q*2D"
K@(yD
qA*rA"
&D(3A""
&D(9A""
&T \A""
[@(2Q"
y@("Q*
y@(2Q"
y@("Q"
y@("Q"
y@(:P(
yP(2P(
q@("Q"
yP(2P(
yP(2Q"
yP("Q*
YP(2Q*
y@("T"
y@("T"
QP"2Q*
Y@("Q"
Q@("Q"
Q@("Q"
Q@(:Q"
qP"2Q*
{P"2Q"
|T*.Q"
Q@":Q"
Y@">Q"
q@">A"
QP"6Q(
{P"6Q"
QP"6Q(
fP(&Q*
y@"6Q"
fP(&Q*
s@"6Q"
3@*2Q
fP(&Q*
s@"6Q"
fP(&Q*
s@"6A"
Q@"6Q"
Q@"6Q(
s@">Q"
"a@*2D
y@ "Q"
Q@ *Q"
1@"2A"
1P :Q"
Q @@(6P
y@ 2Q"
`@ `@ `@ `@
&@"lA
*$P*PP
\Q"FA"
\Q"FA"
UP"lQ(
\Q"FA"
\Q"FA"
FE"nA"
QP("Q"
QP("Q*
*@@*j@*j
*@@*j@*j
@*j@*j@
*@@*j@
@*j@*j@
@*j@*j@
@*j@*j@
E bE"*
@*j@*j@
dE"jD"
QP "T"
:@*j@*j@
E*j@*j@*j
@*j@*j
:@*j@*j@
1@ "Q"
@*j@*jT
~A*&@*
@*j@*j@
@*j@*jA
@*j@*j@
*E@ 2A
U*.D*@
A""P dP
E"*@
A""@ dP
*@@*j@*j
E*.T*HU
E"*@
"@Q @T
P"`Q P
Q P@ #
@*j@*j
T"*Q"
@*j@*j
@*j@*jA
1@(2T"
@*j@*j@
@*j@*j@
*H@*j@*j
(PT *Q
~U*.P*
x@*j@*j@
@*j@*jA
@*j@*jA
@*j@*j
@*j@*j
DE"nT"
@@"A@
XE 8Q
eP*JA(
D"HT(PD
U(*T [
"w@({E"
(|E(aU*
&T*)U"QQ"
eU*+P*
A"_P "A*
":P(AE
"oP"O@
T TD*sD
"~@"@U
U(6T i
A mT(9A"
_P*"U
@ `@ `@
P pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP pP
@(h@(h@(h@(h@
P pP pP
@(h@(h@(h@(h@(h@(h@(h@(h@
*T"&P"
(8T 8E
.A"EQ*
j@(JU*
Q"3T EQ
D(bT(;
4Q**@
*U 5T(
/T(A
*GA"(D
CQ"fP*
5Q*rD
D +P(r@
Q"jU*wP
"NT*gT"gD(
A w@"
'@(vQ(P
ZT"!A(M
*o@"oT
A*CA(j
t@",E ,Q
P(\A Z
dD" Q
<Q(5E(z
eT*xE
3U"s@*<
@(rP*$A
P OA(i
U(DD*VT({
(zQ*\T
E(NP"SU"
3E hT CU
zQ `@"
wU"sP"vD
@A*{P*
U(}D"\
*}P +D
B@*ID(
A"sA !
U*iP*IQ
aQ(q@*5
NP ;U"
Terfrtghygine.dll
CreatePaint
GetCurrentThread
GetProcAddress
LoadLibraryA
VirtualAlloc
VirtualProtect
kernel32.dll
CoCreateGuid
CoFileTimeNow
CoFreeUnusedLibraries
CoGetContextToken
CoGetCurrentLogicalThreadId
CoGetCurrentProcess
HICON_UserFree
OleBuildVersion
OleInitialize
OleUninitialize
ole32.dll
vSetDdrawflag
msimg32.dll
midiStreamStop
winmm.dll
|J-rh-
vG-ra)
tF+t](
19(Qra
F aHO,Q
UzciDE;
PA<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
Add a favorite
MS Shell Dlg
Cancel
Add page %s to favorites with (optional) name:
Winamp Online Service
MS Shell Dlg
<title>
<set this dialog size to minimum acceptable>
&Allow
Apply to all &requests from this service
to learn more about Winamp security policy.
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Stealer.l!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37772041
FireEye Generic.mg.7171b247521e6301
ALYac Trojan.GenericKD.37772041
Malwarebytes Clean
VIPRE Clean
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (W)
BitDefender Trojan.GenericKD.37772041
K7GW Riskware ( 0040eff71 )
K7AntiVirus Riskware ( 0040eff71 )
Arcabit Trojan.Generic.D2405B09
BitDefenderTheta Gen:NN.ZexaF.34214.8CW@aqtVWZci
Cyren Clean
ESET-NOD32 a variant of Win32/GenKryptik.FLWV
Baidu Clean
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Trojan-Spy.Win32.Stealer.adba
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Ad-Aware Trojan.GenericKD.37772041
TACHYON Clean
Sophos Mal/Generic-R + Mal/EncPk-APW
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.VirRansom.dt
CMC Clean
Emsisoft Trojan.GenericKD.37772041 (B)
Ikarus Trojan.Win32.Krypt
Jiangmin Clean
eGambit Clean
Avira TR/Kryptik.ealnm
Antiy-AVL Clean
Kingsoft Win32.Heur.KVMH008.a.(kcloud)
Gridinsoft Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Trojan.GenericKD.37772041
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!7171B247521E
MAX malware (ai score=87)
VBA32 TrojanSpy.Stealer
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W32/GenKryptik.FLWV!tr
Webroot Clean
AVG FileRepMalware
Avast FileRepMalware
No IRMA results available.