Static | ZeroBOX

PE Compile Time

2021-09-18 01:24:19

PE Imphash

1d30df1e5b7623c4b3e7485c04815cbd

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000c731 0x0000c800 6.29925397997
.rdata 0x0000e000 0x00000246 0x00000400 3.18686767358
.data 0x0000f000 0x00000088 0x00000200 0.147365075305
.pdata 0x00010000 0x000000cc 0x00000200 1.714449782
.ndata 0x00011000 0x0000b78d 0x0000b800 4.58173839228

Imports

Library KERNEL32.dll:
0x18000e000 GetSystemTime

Exports

Ordinal Address Name
1 0x180001000 DllGetClassObject
5 0x180001330 DllMain
2 0x180001380 DllRegisterServer
3 0x1800013d0 DllUnregisterServer
4 0x180001420 StartW
!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.ndata
UAWAVAUATVWSH
[_^A\A]A^A_]
UAWAVATVWSH
e0[_^A\A^A_]
AWAVVWUSH
D$$-;U
D$$-4+
[]_^A^A_
AWAVAUATVWUSH
D$$-bC
D$$-7-
D$$-?kb
D$$-?oOf
D$$-[W
D$xHc@<H
[]_^A\A]A^A_
D$(?oOf
AWAVAUATVWUSH
D$4-&q
D$4-{N
D$4-r!^
D$4-xMjs
D$4-y
D$t;D$p
D$t;D$p
D$t;D$X
[]_^A\A]A^A_
AVVWUSH
D$,=MZ
[]_^A^
AWAVAUATVWUSH
[]_^A\A]A^A_
UAWAVVWSH
eX[_^A^A_]
AWAVATVWUSH
McI<L)
D$(-@7)
D$(-|M=
D$(-l`
D$(-ky
D$(-DpO=
D$(-wT
D$(-\n
[]_^A\A^A_
D$,|M=
UAWAVAUATVWSH
[_^A\A]A^A_]
AWAVAUATVWUSH
[]_^A\A]A^A_
DllGetClassObject
DllRegisterServer
DllUnregisterServer
StartW
DllMain
GetSystemTime
KERNEL32.dll
7z8t4o;p;p;r;s;t;y;v;w;x2l2k<k<l5u<n<o<p<q<r<s<t8u<v<w<x<y<z=k=l=m=n=o=p=q=r=s=t=u=v=w=x=y=z>k>l>m>n>o>p>q>r>s>t>u>v>w>x6y>z/k/l/w0w:y/v/q:n/l;o1v:n/x3l;n1y3o6t6v5k2o5p5o6s6z5v6v6q2w6y6z6l3y3y4q/n3q3k/q4p4x3r/u3m3m/x5u5k5n0l4z4w4k4k0s2u2p2n0y2v2w2x2y2z3k3l0m/q3o3p1m;l3n3t4w8y8m0n3y3z4k4l4m4n4o4p9q4r6q6v4l4t4y3v4y6z5k5l5m1n5o5p5q5x5s5t8u6s5w5x5y6z6k6l6m6n<s0y6q6r6s6t6u5v6w6x6y6x7k7l7q7n7o7p7q7r7s7t7z7v7y7x7y7z8k8l8m3n8o8p8q8n8s8t3t;o8w8x8x8z9k9l9m9n7o9p9q9r9s9t9u:v9w9x9y9z:k:l:m:n9o:p:q:r:s:t:u9v:w:x:y:z;k;l;m;n;o;p<q;r;s;t;u3v;w;x6y;z<k<l<m3n<o<p5u<k<s<t<u<v<w<x<y<z=k=l=m:n=o=p8u=p=s=t=u=v=w=x=y=z>k>l>m2n>o>p2m>p>s>t>u>v>w>x>y>z/k/l/m/n/o/p/q/r/s/t/u/v/w/x/y/z0k0l0m9n0o0p2y0r0s0t0u0v0w0x0y0z1k1l1m1n1o1p1q1r1s1t;y:u1w1x7q1y2k2l2m2n2o2p2q2r2s2t2u2v2w2x2y2z3k3l3m3n3o3p3q3r3s3t5o2z1t2p2u3z4k4l3m3w4o4p4q3r4s4t4u6v4w4x4y4v5k5l5m5n5o5p5q5r5s5t5u5v5w5x/y5z1k0l4w0r0p/l0r6r6s6t/u6z6w6x6y3z7k7l7m7p7o7p7q9n7s7t7u7v7w7x7y7z8k8l8m8n8o8p<q8r;s4t:o=t>s>w=u>y9k9l<m9m9o9p9q=r9s9t9u9t9w9x9y7p:k:l:m:n:o:p:q:r:s:t:u:v:w:x>y:z8k7l
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Encoder.j!c
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKD.37906585
FireEye Generic.mg.022bc73fb9791a57
CAT-QuickHeal Clean
McAfee RDN/Ransom
Cylance Unsafe
VIPRE Clean
Sangfor Trojan.Win64.Ogneglazka.hq
K7AntiVirus Trojan ( 0058996c1 )
BitDefender Trojan.GenericKD.37906585
K7GW Trojan ( 0058996c1 )
CrowdStrike win/malicious_confidence_80% (W)
Arcabit Clean
Baidu Clean
Cyren Clean
Symantec Trojan.Gen.2
ESET-NOD32 Win64/CobaltStrike.Artifact.A
APEX Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky Trojan.Win64.Ogneglazka.hq
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.37906585
Emsisoft Trojan.GenericKD.37906585 (B)
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Trojan.Win64.BAZARLOADER.SMYXBIMZ
McAfee-GW-Edition RDN/Ransom
CMC Clean
Sophos Mal/Generic-S
SentinelOne Clean
Jiangmin Clean
Webroot W32.Malware.Gen
Avira TR/Crypt.Agent.xgtxb
MAX malware (ai score=82)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Trojan:Win32/Wacatac.B!ml
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Trojan.GenericKD.37906585
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Trojan.GenericKD.47278610
TACHYON Clean
Malwarebytes Trojan.CobaltStrike
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Trojan.GenAsa!5MwrDO7BOgQ
Ikarus Trojan.Win64.Krypt
eGambit Clean
Fortinet W64/GenKryptik.FKYP!tr
BitDefenderTheta Clean
AVG Win64:BankerX-gen [Trj]
Avast Win64:BankerX-gen [Trj]
MaxSecure Clean
No IRMA results available.