Static | ZeroBOX

PE Compile Time

2021-10-24 00:47:05

PE Imphash

682b88463c7583e0323d7851be5034d8

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0008ca94 0x0008cc00 5.91231621739
.data 0x0008e000 0x0002b01c 0x0002b200 7.99786670294
.rdata 0x000ba000 0x000002d8 0x00000400 4.01152998261
.eh_fram 0x000bb000 0x00000a04 0x00000c00 4.34374586287
.bss 0x000bc000 0x000000b0 0x00000000 0.0
.idata 0x000bd000 0x00000614 0x00000800 4.2040781439
.CRT 0x000be000 0x00000018 0x00000200 0.114463381259
.tls 0x000bf000 0x00000020 0x00000200 0.22482003451
.rsrc 0x000c0000 0x00013e24 0x00014000 6.57515374187

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000d37d0 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000d37d0 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000d37d0 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000d37d0 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000d37d0 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000d37d0 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000d37d0 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000d37d0 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000d37d0 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000d37d0 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000d37d0 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000d37d0 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000d37d0 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000d37d0 0x00000128 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000d38f8 0x000000ca LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x000d39c4 0x000002ac LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x000d3c70 0x000001b1 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text, with very long lines, with no line terminators

Imports

Library KERNEL32.dll:
0x70d134 CreateThread
0x70d140 ExitProcess
0x70d144 FindClose
0x70d148 FindFirstFileA
0x70d14c FindNextFileA
0x70d150 FreeLibrary
0x70d154 GetCommandLineA
0x70d158 GetLastError
0x70d15c GetModuleHandleA
0x70d160 GetProcAddress
0x70d16c LoadLibraryA
0x70d174 TlsGetValue
0x70d178 VirtualProtect
0x70d17c VirtualQuery
0x70d180 WaitForSingleObject
0x70d184 lstrlenA
Library msvcrt.dll:
0x70d18c _strdup
0x70d190 _stricoll
Library msvcrt.dll:
0x70d198 __getmainargs
0x70d19c __mb_cur_max
0x70d1a0 __p__environ
0x70d1a4 __p__fmode
0x70d1a8 __set_app_type
0x70d1ac _cexit
0x70d1b0 _errno
0x70d1b4 _fpreset
0x70d1b8 _fullpath
0x70d1bc _iob
0x70d1c0 _isctype
0x70d1c4 _onexit
0x70d1c8 _pctype
0x70d1cc _setmode
0x70d1d0 _strdup
0x70d1d4 abort
0x70d1d8 atexit
0x70d1dc calloc
0x70d1e0 free
0x70d1e4 fwrite
0x70d1e8 malloc
0x70d1ec mbstowcs
0x70d1f0 memcpy
0x70d1f4 realloc
0x70d1f8 setlocale
0x70d1fc signal
0x70d200 strcoll
0x70d204 strlen
0x70d208 tolower
0x70d20c vfprintf
0x70d210 wcstombs

!This program cannot be run in DOS mode.
P`.data
.rdata
0@.eh_fram
.idata
5Rksm%n=
6-5_OK)
-l,.3-
-f0jH-
7'-Ztnu-
G-vN>j
-^eYG-x2^d)
-^mHJ-,9I
-kUd1-
fk1-^Tt
Qc-OW;q-
t(<{t?
</t&<\t"
Qkkbal
[QqfR@
FqTUte
^{G,#T`
i.^-f~W
NO'wBY
JF|6UV
S'bMN
SsnQ}W
!*)Q"b
pioHy%F<&
Z^OhU8
KfpzN
p\hwe&>
Xf2v>#
SV,FAV
^sA&}A
hAd:w~
tT*/\VP]s0
^),@2
hqyA<#
WYpr3pa
F`_DjA
>Gx/Xd
AwZ@pzOB
)<//ne
oc9c%
+&4;)}
+dGMy]
.[k%m&
zt]y;/
#IuHIu
"dh$01p#
?|g%j=o
E|PH$R
8 Ct><FP
R=5CKE
BF<+,(i4%
as{%QA
[%EF/o
rriCOu
jVksWH
b{Xl95
of IW=Q!
ZlOrKf
Ib=cL>
}:bGt7
0BxcF8x
?|+"2r
YMlAQ=
`r.rI7
/B3?jV|m
wxL`VF
?}a=&L
>%21PY
q:1SYB
ioyOad
'>B{c+S
lRbmJ]
p${P:8b
8tL}`_zVt
/ypl%<#
V5fd:k
HIBTev
5MD:j)E
il'Y&07:r
z|$q@}6
{P:IiX%`Kzh
!n<A`o
f$i4?4o
V3T]iC
PfhwK\
y|j7Y4
X%vZ5KU
u2a.`x
ah1d=L
]o~$BC
k6+Ha
h!]d}h
-;b&Yt
V-X@.$
[y'/#2O
(R9FaP
bHa)}&%
MCh4'8;
R1/`ue
?.S wf
i&Qj"*
Lh $G=
`,0_v%
{/a!WC
0Xp[$(
TQOB]Q5Gc-lojG
gS:./'S$
)R#}y~#
%{wKr
J]pFJM
Nhk_^:
w_gc0H
(CA,+1Gs
w* IOVV
D;z \Ybg
2Xok#"#
/Ly3C(
2;rW<l
9+GHn$)_
[6#&Mb
,LS5`("
7E|7qu!
+fsNW
fc~Mu;-
-nw|h/
-2PY)~
P%#;vKg
637X0KJ
FYH,P'~$
P$!H_n
ub('!j
_)zDDMT?
3|mzo/
eD1|%F
N=iRn2BR
|IYi2gs\p
~G%av$0Gt:gZ[Htt|'
2G7^`L
xX'`gW
Nj4V5
YE:k4S
2~Y9DG
l3|0%)
Q3$.]n
7'sov0
QE8^5F'
%k9;MJ
{*|t_C
j5KP(U
$`vXtf
;EH2#=
>E@=Il
ye1kw0
=gp]^9G
nK)adf
M RpE5AV
-LZAvRC$z
,NINUQ
J|F)>$
lK:s}s
XXC7Q`y
k<> ^,=
C"&/Amg
J?Yj?
gb0I#v
2?ZrmY
'@|IyA
PVh%3-N
hLPxQ\
snzv+h^4
mNVb9BH
o"B-E.a
6=yd Q
e+c7H<
1PTBfpLq9
HWE6DE
K(A]DR
o}B,:}
@:]<LI|D
{hn_HM
Mt(,*D
L%kbFOf
{9z`rVA-#h.{@
x~cTTlQ>y&#
E)pqq|v'
B5H`rrOB
`k^svR
OC9"jB.
2;aHGK
qP-O(J
MgqSfN
f~6|zj
IM.z7V\
I5|+a,B
YwO7cjm
e$00&Q
RNAFU]z,
G<i@'K
n8gsX'
{KLF@}
akD:0l
jj>Xxo!
t$X\EP[
mpC*,"w
Rh<}U8r
h"<c$D
W&2%x6
9oEY;h4
>ua'mU
*:Jw)i
;d$wU<
]gU"],m
q 8 z=
`B1e;%!c38
4*K2(8
b>t[,Lk0t&;
.#(q[x@
QxaoH@
Bi;(E
%x>$Ee
zCs7QG
x@y%/_
*c8S^B-
?>VB#~
?4nn8R
:OKuuQg9
e-##yO
5;IyT[
I?~9m,
}n/g+<
S20F#v
'!N?k.
w6ZW1_
88D6q_
;6nC`+
t(>R{p0!
U}"Z:WmZd
9Y$J@Q>?j
_"_5OW
71P&f&C
a0JWdF
w/krrc
6m(9Qr
JBfh-x
uH0x8s2
6BNS;=?
K~|hlyK
1c,eGQ}
_{ODrD
d/Jc,cNxex
/zk\9Y(L~v
&BTsS6
}U}G)L
GXlb-#!9;
N(m4(4
f-g~d|
89m}dk
~_#.#R=W
Q)Mmvs&P]
/"bnY*
d09h,0
lVL,s@
~n@c)
s$f%-6?
e5V!d<
z"B]3N
39J/k.
&#.I2:
9dg+L&
EJ)U#n
\;4Pz6H
@$bGK2
0L??$z
N`y6p6
YXww[W
}c_<:S!
9-ORza1
Wf~$)'
MJyF81
fgCkM9W
yrYI7&
}saIrV
`b[$/y
Ob66]o
j:Sq;2
,_e$Mx
+j%4`z
l,~C/Q;
=+#V$-
"+cq[D
Z}@;nD)
)WH2[D
B3<.G,N
J#s)^
nv9I4w
YvRnG!
VJa&c(.1
m5!e]F
V##Q^L=
33!_%HbX3
Fwb=h&l|
{A/0-j
udiQu1T
7L2<vC
vsoU!6g
??xYy
JBU,}
libgcc_s_dw2-1.dll
__register_frame_info
__deregister_frame_info
libgcj-16.dll
_Jv_RegisterClasses
kernel32.dll
cqojAffbNSLRfRHNYs5R7o2StUq
Mingw runtime failure:
VirtualQuery failed for %d bytes at address %p
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
glob-1.0-mingw32
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
GCC: (GNU) 6.3.0
CreateThread
DeleteCriticalSection
EnterCriticalSection
ExitProcess
FindClose
FindFirstFileA
FindNextFileA
FreeLibrary
GetCommandLineA
GetLastError
GetModuleHandleA
GetProcAddress
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryA
SetUnhandledExceptionFilter
TlsGetValue
VirtualProtect
VirtualQuery
WaitForSingleObject
lstrlenA
_strdup
_stricoll
__getmainargs
__mb_cur_max
__p__environ
__p__fmode
__set_app_type
_cexit
_errno
_fpreset
_fullpath
_isctype
_onexit
_pctype
_setmode
_strdup
atexit
calloc
fwrite
malloc
mbstowcs
memcpy
realloc
setlocale
signal
strcoll
strlen
tolower
vfprintf
wcstombs
KERNEL32.dll
msvcrt.dll
msvcrt.dll
IDATx^
ju;]~i
;uM?:P
kKO.--=
/xd^M X
'LG!X4
6W\3>p
GG6nmc
K2~\&Q*
+8f1wpT
h-&e-&")
c7@s,Ym8|
:LO7z:
!AUre\N
nw%qItj
{ Ths*
quB.1,
UqT>UW
A3ZSAR
ISVV>LgS
Cw93*~
aRrRVT
KdT8@D
Mn;d~)
@hqR+j*T
WTA6@6
t&M`N<
`Bmz-P
;tD565
t`<?|W
fM )[qP
dY(++o
4@%s*_]@
QG:(TK
[D%AF\
A5)``)
v@;huR?
K;_`pM
AvlXo!`
{x^?8
+K_;xH
.XB]ji
w@ `#~
T7v'0
wiyqqR?
01c_/D
r6YK9",
<:<<<'<<4;5<,<<<<<5<<<7<<<<<)
<<<<<<<<<<<<<<<6<:<<<<<<9+<<*<<<<
ITTTTTTSTTTTTTTTTTTTTQTTPTTTTTTRTTT
ZZZZYZZZZZZZZZZVZZZZZZWZZZZZZXHZZZZWZ
ZZZZZZ
ZZZZZW
0/<F^c
$%%%%%%%%%%%&%"#%%%%%%

WWWWWWWWWWWQWWWWWWWWV
*N/W5.WWWWWWW
WWWWWWWWWWWWW
WWWWWWWW'WWWW
(WWWWWWWWWWW
WWW#WWWW1WWW
WWWWWWWIWWWW
WWWWWW?WWWW
!WWW*WWWWWWW
WWWWWWWWWW"
SWWWWWWWWWW
WWMWWWWWWW
gqqqqq
WWVW+WWWWW
WWWWWWWWW
qqqqnqq
WWJWWWWWW
WWWKWWWW
qqqjqqqqq
WWWCWWWW
WWWWW,W"
qqqqqqqqqqq
"LWWWWAW
WWWWWWW"qqqqqqqqqqqqqGWW8WWWW
WWWW)W@qqqqqqiqqqqmqqqWWWWWWW
WWWWWWWWWWWqqqqqqoWWWWWRW2WWW
WWWBWWWWWWWqqqqqqqPWWW4WWWW%O
CWWW7WWWWWWqqqqqqqWWWWWWWWWWW
WWWWW$WWWEWqqqqqqqWWWWWWWWWWW
WWWWWPWWHWWqqqqqqqWWWWWWWWWWW
WWWWWW3WWWWqqqkqplWWWWWWWUWWW
WWWWWWWWWWWqqqqqqq<:>WW-WWWWW
YY9WWWWWWW&WWWWWDWWWWWWWWWWY
[XTWWWWWWWWWWW0WWW=WWWW6W[[
[[[WW;WWWWWWWW3WWWFWWWWW[Z[
______\____^______]______
fffffffffbfffffffffffff
ffdff`fffffafffffeffc
3333333
133333331
UUUUUUUUUUS
x<]K9",
%%%$%%%%%%"%%%%#%
'''EEEEE?=ADEE4E'''
EEE2EEE*6E!EEE<EEEAEE
EEE8EEEE,
(EEE+EE=EE
EEEEEEEE-
EE9EEE7E9
=0EEEEEE
EEEEEEEE
E5AEEEE
EEEEEEE
C?DEEE
^^^^[^TEEEAEE
8@EEE S^^^^^[^&!EEEE9
EEE1E!^^^^^U^^^
EEEEE.>;\^^Z^EDEEEEEE
9)EEEEEE^^^X^EEBCEE:E
EEEEEEEE^\^^^EEEEEEEE
EE@<EEEE^^^V^7EEEEEE@
EEEEEEEE\^^]WE1DEEDE@
EEEEEEEE^^^^^/EEEEEEE
FED7EEEEEDEEEEEEEEEEF
JIEEEEEEE3EDEEEEEEEJH
MKMMMGMMMMMMMLMMMMM
RROQPRRRRRRRRRRRN
'wwwwwxw"
Ffffff1
#######
"!""""""""
5UUUUU
VfgWfeQ
fdtDffe
vffffeq
<?xml version="1.0" encoding="UTF-8" standalone="yes"?><assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" name="MyApplication.app" /><trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"><security><requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"><requestedExecutionLevel level="asInvoker" uiAccess="false" /></requestedPrivileges></security></trustInfo></assembly>PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
VS_VERSION_INFO
StringFileInfo
040904b0
ProductName
MnTQrMLpjqg
ProductVersion
1.8.0.2
FileDescription
MnTQrMLpjqgCGp7WRoHuwfYmVvVgfySsIcvFERMGKEG777tuq
CompanyName
MnTQrMLp
LegalCopyright
All Rights Reserved
Comments
MnTQrMLpjqgCGp7WRoHuwfYmVvVgfy
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Stealer.l!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!673B15B93A2B
Cylance Unsafe
VIPRE MultiPlug (v)
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 0058908b1 )
BitDefender Gen:Variant.Fragtor.31624
K7GW Trojan ( 0058908b1 )
Cybereason malicious.e15318
Baidu Clean
Cyren W32/Stealer.M.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/Kryptik.HNCG
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Spy.Win32.Stealer.gen
Alibaba TrojanSpy:Win32/Stealer.e25d6adb
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Gen:Variant.Fragtor.31624
Rising Clean
Ad-Aware Gen:Variant.Fragtor.31624
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro TROJ_GEN.R002C0WJQ21
McAfee-GW-Edition BehavesLike.Win32.Worm.ch
FireEye Generic.mg.673b15b93a2b9906
Emsisoft Gen:Variant.Fragtor.31624 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Fragtor.31624
Jiangmin Clean
Webroot Clean
Avira TR/AD.RedLineSteal.eozgt
MAX malware (ai score=80)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Ransom.Win32.Sabsik.sa
Arcabit Trojan.Fragtor.D7B88
ViRobot Clean
ZoneAlarm HEUR:Trojan-Spy.Win32.Stealer.gen
Microsoft Trojan:Win32/Stealer.RPR!MTB
AhnLab-V3 Clean
Acronis suspicious
VBA32 TrojanSpy.Stealer
ALYac Gen:Variant.Fragtor.31624
TACHYON Clean
Malwarebytes Spyware.PasswordStealer
Panda Trj/Genetic.gen
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0WJQ21
Tencent Win32.Trojan.Fragtor.Wnmp
Yandex Clean
Ikarus Trojan.Win32.Krypt
eGambit Clean
Fortinet W32/Fragtor.3162!tr
BitDefenderTheta Gen:NN.ZexaF.34236.ZK0@a8Y7TPpi
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_70% (W)
MaxSecure Trojan.Malware.300983.susgen
No IRMA results available.