Static | ZeroBOX

PE Compile Time

2021-10-26 03:03:01

PE Imphash

ad3ffaf0584336c12d7303af68597f29

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000046c1 0x00004800 6.42892808394
.rdata 0x00006000 0x0001b91c 0x0001ba00 7.72815287831
.rdata 0x00022000 0x00000920 0x00000a00 4.65782504331
.data 0x00023000 0x000000d0 0x00000000 0.0
.pdata 0x00024000 0x00000300 0x00000400 3.56748389293
.rsrc 0x00025000 0x000001e0 0x00000200 4.71544202235

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00025060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x180022000 GetProcAddress
0x180022008 LoadLibraryA
0x180022010 GetCommandLineA
0x180022018 HeapAlloc
0x180022020 GetProcessHeap
0x180022028 GetSystemTime
0x180022030 lstrcmpA
0x180022038 GetTempPathA
0x180022040 HeapFree
0x180022048 VirtualAlloc
0x180022050 VirtualFree
0x180022058 GlobalAlloc
0x180022060 ExitProcess
0x180022068 lstrcpyA
0x180022070 lstrcatA
Library USER32.dll:
0x180022080 MessageBoxA
0x180022088 RegisterClassA
0x180022090 LoadMenuA
0x180022098 GetMenu
0x1800220a0 SetMenu
0x1800220a8 GetMenuStringA
0x1800220b0 DrawMenuBar
0x1800220b8 CreateMenu
0x1800220c0 CreatePopupMenu
0x1800220c8 DestroyMenu
0x1800220d0 EnableMenuItem
0x1800220d8 AppendMenuA
0x1800220e0 DeleteMenu
0x1800220e8 InsertMenuItemA
0x1800220f0 SetWindowTextA
0x1800220f8 GetWindowTextA

Exports

Ordinal Address Name
1 0x180001000 ClearNode
2 0x18000113c cxzasada
3 0x180001210 ddsdfwe
4 0x1800012cc htrhrr
5 0x180001388 nvqqws
6 0x180001444 pogfhgf
!This program cannot be run in DOS mode.
`.rdata
`.rdata
@.data
.pdata
@.rsrc
x ATAVAWH
@A_A^A\
x UATAUAVAWH
A_A^A]A\]
@USVWAVH
A^_^[]
x UATAVH
9t$4~qD
WAVAWH
A_A^_
HcT$8E3
~9Hc\$(E3
WATAUAVAWH
A_A^A]A\_
UAVAWH
WATAUAVAWH
HcA<E3
A_A^A]A\_
D$@H9D$(tXH
D$ 9D$$u
u/HcQ<A
|$ UATAUAVAWH
A_A^A]A\]
x ATAVAWH
A_A^A\
WAVAWH
A_A^_
WAVAWH
A_A^_
7-hU'Z
XtX>(|#
T>n*-&
'Z>)`_
/Hb~WBZ
"ygY<Si
-yrY<S
w<y{R<S
'Z=9 nV
Q:k<eP
Xk~Kn,j
rzC/Fl
"y/2<S
'O_c~O
"&;g*Kk
"y8#<S
"yJ=<S
kcZEf"
"KlAM;
"%;g)5_
;gE(gD
<)VlDZ
~/Hg~ij
'ZLnB#
"yz)<S
N.He~ek
!`WJW/
*`WJW{
N&Hz~?e
'zHhtq
SVLCqh
fW&Hx~
H}W?:i
hob_9Y
&1gXt8
oqzXi6>
pySlo0>
)woKW[
/K[, J8
t(KF^3
'Z>n>jn
'Z>(8"
c6`aVy
/Hc~.?
./Hg~)
Bycs<S
y#7<S,
,h|R\>
#ST>n2f
2zB/Fl
'Z>)+
'Z>)|"
n/Hc~M"
"O/Hb~
HRi^hV
SV\`R7
'Z>(<#
'Zt!EnV
@ XVy*
w)z@/Fl
jG+/o*
Xk~_y/
Xk~_y?
"3QE:P
N.Hb~P)Z
:zB/Fl
`<Si=^
]<SiXW_
h&Hg~K.Z
:>+mn*
byV^<S
byE^<S
Xk~?ye
Ng+X'*
*TGt:
1zC/Fl
Si^c~
'ZM>6L
Q;vH)"
By_j<S
'ZD [EV
'Z}#N5V
shdVyZ
N&{]]"
"zM#H[
2zC/Fl
Xk~[n,j
*T@t:
Ng+zr*
&n\Z=2
.H`~zG
V/2J)J
"z@/Fl
Xs~7yy
z)'Zln
.T&Z+8
?J&Z/;
Invalid command line parameters
Please wait while error report is being sent
.text$mn
.rdata
.idata$5
.rdata
.rdata$zzzdbg
.xdata
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.pdata
.rsrc$01
.rsrc$02
taihaappcg.dll
ClearNode
cxzasada
ddsdfwe
htrhrr
nvqqws
pogfhgf
GetProcAddress
LoadLibraryA
GetCommandLineA
HeapAlloc
GetProcessHeap
GetSystemTime
lstrcmpA
GetTempPathA
HeapFree
VirtualAlloc
VirtualFree
GlobalAlloc
ExitProcess
lstrcpyA
lstrcatA
KERNEL32.dll
MessageBoxA
RegisterClassA
LoadMenuA
GetMenu
SetMenu
GetMenuStringA
DrawMenuBar
CreateMenu
CreatePopupMenu
DestroyMenu
EnableMenuItem
AppendMenuA
DeleteMenu
InsertMenuItemA
SetWindowTextA
GetWindowTextA
USER32.dll
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!CD3E23CDDEB9
Cylance Clean
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_60% (D)
BitDefenderTheta Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
Baidu Clean
APEX Clean
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Tencent Clean
Ad-Aware Clean
Sophos Generic ML PUA (PUA)
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.BadFile.cc
FireEye Generic.mg.cd3e23cddeb92b73
Emsisoft Clean
SentinelOne Clean
Jiangmin Clean
eGambit Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win64/BazarLoader.MZK!MTB
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
GData Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet W64/Kryptik.CQV!tr
Webroot Clean
AVG Win64:MalwareX-gen [Trj]
Avast Win64:MalwareX-gen [Trj]
No IRMA results available.