Static | ZeroBOX

PE Compile Time

2021-10-29 21:06:10

PE Imphash

2c02c1999142edb52caad79376c81ce6

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002137f 0x00021400 6.41546545657
.rdata 0x00023000 0x00006baa 0x00006c00 4.78986021314
.data 0x0002a000 0x00004fd4 0x00000a00 2.48654267342
.rsrc 0x0002f000 0x000009e8 0x00000a00 3.98229149683
.reloc 0x00030000 0x0000168c 0x00001800 6.44682060309

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0002f550 0x000002e8 LANG_NEUTRAL SUBLANG_ARABIC_OMAN data
RT_ICON 0x0002f550 0x000002e8 LANG_NEUTRAL SUBLANG_ARABIC_OMAN data
RT_GROUP_ICON 0x0002f838 0x00000022 LANG_NEUTRAL SUBLANG_ARABIC_OMAN data
RT_VERSION 0x0002f160 0x000002c4 LANG_NEUTRAL SUBLANG_ARABIC_OMAN data
RT_MANIFEST 0x0002f860 0x00000188 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x423000 ReadFile
0x423004 GetCurrentProcess
0x423008 lstrcatA
0x42300c GetModuleHandleA
0x423014 GetModuleHandleExA
0x423018 CreateFileA
0x42301c lstrcpyA
0x423020 CloseHandle
0x423024 GetFileSize
0x423028 GetLastError
0x42302c GetProcAddress
0x423030 HeapFree
0x423034 WriteFile
0x423038 lstrlenA
0x42303c lstrcpynA
0x423040 WriteConsoleW
0x423048 SetLastError
0x423050 TlsAlloc
0x423054 TlsGetValue
0x423058 TlsSetValue
0x42305c TlsFree
0x423064 GetModuleHandleW
0x423070 TerminateProcess
0x423078 IsDebuggerPresent
0x42307c GetStartupInfoW
0x423080 GetCurrentProcessId
0x423084 GetCurrentThreadId
0x423088 InitializeSListHead
0x42308c RtlUnwind
0x423090 RaiseException
0x423094 EncodePointer
0x4230a4 FreeLibrary
0x4230a8 LoadLibraryExW
0x4230ac ExitProcess
0x4230b0 GetModuleHandleExW
0x4230b4 GetModuleFileNameW
0x4230b8 GetStdHandle
0x4230bc SetFilePointerEx
0x4230c0 GetFileType
0x4230c4 HeapAlloc
0x4230c8 LCMapStringW
0x4230cc FindClose
0x4230d0 FindFirstFileExW
0x4230d4 FindNextFileW
0x4230d8 IsValidCodePage
0x4230dc GetACP
0x4230e0 GetOEMCP
0x4230e4 GetCPInfo
0x4230e8 GetCommandLineA
0x4230ec GetCommandLineW
0x4230f0 MultiByteToWideChar
0x4230f4 WideCharToMultiByte
0x423100 GetProcessHeap
0x423104 SetStdHandle
0x423108 GetStringTypeW
0x42310c GetConsoleMode
0x423110 FlushFileBuffers
0x423114 GetConsoleOutputCP
0x423118 HeapSize
0x42311c HeapReAlloc
0x423120 CreateFileW
0x423124 DecodePointer

!This program cannot be run in DOS mode.
Rich&5
`.rdata
@.data
@.reloc
QQSVWd
URPQQh
;t$,v-
UQPXY]Y[
t#Vh<BB
zSSSSj
f9:t!V
QQSVj8j@
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
bad allocation
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
Unknown exception
bad array new length
abcdefghijklmnopqrstuvwxyz0123456789_ABCDEFGHIJKLMNOPQRSTUVWXYZ
invalid string position
string too long
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.gfids
.rdata
.rdata$r
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.rsrc$01
.rsrc$02
ReadFile
GetCurrentProcess
lstrcatA
GetModuleHandleA
SetCurrentDirectoryA
GetModuleHandleExA
CreateFileA
lstrcpyA
CloseHandle
GetFileSize
GetLastError
GetProcAddress
HeapFree
WriteFile
lstrlenA
lstrcpynA
KERNEL32.dll
QueryPerformanceCounter
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
GetModuleHandleW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
GetCurrentProcessId
GetCurrentThreadId
InitializeSListHead
RtlUnwind
RaiseException
EncodePointer
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
FreeLibrary
LoadLibraryExW
ExitProcess
GetModuleHandleExW
GetModuleFileNameW
GetStdHandle
SetFilePointerEx
GetFileType
HeapAlloc
LCMapStringW
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetProcessHeap
SetStdHandle
GetStringTypeW
GetConsoleMode
FlushFileBuffers
GetConsoleOutputCP
HeapSize
HeapReAlloc
CreateFileW
WriteConsoleW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
1D1I1S1t1
3H3!4=4^4
6)6W7s7
:'<C<T>p>
4;4E4a4u4
x0 1?1j3~3
8(9e9k9
=O=V=3>N>
8A9L9|9
;#<?>O>{>
0 0O0V0p:{:
1,1@1N1^1
9]:j:m<
?&?Y?`?
000T0h0
1F1X1V2
6$6,666>6U6]6
6 7,7[7b7
8f8,999H9m9
;H;Q;\;
1060I2N2
7?7_7r7x7
88$8*80858;8A8F8L8R8W8]8c8h8n8t8y8
9#9)9/949:9@9E9K9Q9V9\9b9g9m9s9x9~9
:;E;T;k;q;w;};
>%>*>/>P>U>b>
0!0,030S0Y0_0e0k0q0x0
1'1A1^1q1{1*232;2v2
3*313D3%4E4O4
4X5a5~5
6I6R6_6e6
8%969c;
031g1o1
434=4G4U4p4
0 2%2P2U2
454A4^5e5
6,6T6o6t6y6
7 7%7*7H7R7^7c7h7
7$878U8c8
:H:O:T:X:\:`:
:L:]:h:
;$;?;J;
<3=F=O=\=k=
?,?;?{?
4<4\4l4q4{4
99$9=9N9S9a9o9v9~9
;'<0<8<U<
p0K1R1
272U2|2
2(3=3O3\3u3
4J4]4q4
5-5P5]5k5y5
8$9V9q9
=B=G=L=\=a=f=v={=
>7>c>l>
?+???D?I?d?n?~?
0$030>0C0H0i0y0
1!1M1_1k1
5k6#7n7
9&9D9O9
9!:&:+:0:9:
<"=1=?=\=d=
=>&>v>
?"?4?F?X?j?|?
0-0b1+2
444S4,5
9%9.9\9
:X;^;c;j;z;
<I<Q<Y<a<i<
2K3L4\4m4u4
5Q5`5l5{5
5<6E6N6W6
;><Y<o<
:":3:a:
e9i9m9q9u9y9}9
2*3E3T3d3t3
,14181<1@1L1P1T1X1\1`1d1p1t1x1
3 3$3(3,3034383
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
0P2X2`2d2h2l2p2t2x2|2
284<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
9 9$9(9,9094989<9@9D9
4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;
h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
0$0,040<0D0L0T0\0d0l0
3<4@4P4T4X4`4x4
5(5,5<5@5H5`5p5t5
6,6<6@6P6`6p6t6x6
:(:0:@:d:l:t:|:
; ;0;T;\;d;l;t;|;
< <,<L<X<x<
=(=4=T=\=d=l=t=
>(>4>T>`>
?$?(?0?D?L?T?\?`?d?l?
080@0D0`0h0l0|0
1$181X1t1x1
282X2x2
383X3x3
44484X4x4
1H1X1h1x1
7 7$7074787<7@7D7H7L7
9 9@9X9x9
jjjjjj
@kernel32.dll
Bapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Bapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
((((( H
Bja-JP
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Content-Type: application/x-www-form-urlencoded
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.63 Safari/537.36
VS_VERSION_INFO
StringFileInfo
040b04b0
CompanyName
LUKISet
FileDescription
LUKISet
FileVersion
711.17.2873.1
InternalName
LUKISet.exe
LegalCopyright
Copyright (C) 2021 LUKISet
OriginalFilename
LUKISet.exe
ProductName
LUKISet
ProductVersion
711.17.2873.1
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Convagent.i!c
Elastic Clean
MicroWorld-eScan Gen:Variant.Fragtor.36743
CMC Clean
CAT-QuickHeal Clean
Cylance Unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Cybereason Clean
Baidu Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/TrojanDownloader.Agent.FXP
APEX Malicious
Avast Win32:DropperX-gen [Drp]
ClamAV Clean
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Ad-Aware Gen:Variant.Fragtor.36743
Emsisoft Gen:Variant.Fragtor.36743 (B)
Comodo Clean
F-Secure Clean
BitDefenderTheta Gen:NN.ZexaF.34236.ku0@aGavv0aO
VIPRE Clean
TrendMicro Clean
FireEye Generic.mg.4ea672ca05b3c1e7
Sophos Mal/Generic-S
SentinelOne Clean
Jiangmin Trojan.PSW.Convagent.o
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm HEUR:Trojan-PSW.Win32.Convagent.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
AhnLab-V3 Dropper/Win.DropperX-gen.C4745768
Acronis Clean
VBA32 BScope.TrojanRansom.FileCryptor
TACHYON Clean
Malwarebytes Trojan.Downloader
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan-downloader.Agent.Pgxa
Yandex Clean
Ikarus Trojan-Downloader.Win32.Agent
eGambit Clean
Fortinet W32/Agent.FXP!tr.dldr
AVG Win32:DropperX-gen [Drp]
Paloalto generic.ml
CrowdStrike Clean
MaxSecure Clean
No IRMA results available.