Static | ZeroBOX

PE Compile Time

2022-12-02 01:15:37

PE Imphash

12e9f46301807daf6ccba7a782c13e87

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00015780 0x00015800 6.43982491285
.rdata 0x00017000 0x0000b272 0x0000b400 5.6024319571
.data 0x00023000 0x00003be8 0x00002a00 6.12372140681
.pdata 0x00027000 0x000011ac 0x00001200 5.08863956733
.gfids 0x00029000 0x00000098 0x00000200 1.30516275521
.rsrc 0x0002a000 0x000001e0 0x00000200 4.720822662
.reloc 0x0002b000 0x00000628 0x00000800 4.7436848007

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0002a060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x180017000 CreateFileA
0x180017008 FindFirstFileA
0x180017010 FindNextFileA
0x180017018 GetFileAttributesA
0x180017020 GetFileType
0x180017028 CloseHandle
0x180017030 GetLastError
0x180017038 ConnectNamedPipe
0x180017040 DisconnectNamedPipe
0x180017050 EnterCriticalSection
0x180017058 LeaveCriticalSection
0x180017060 DeleteCriticalSection
0x180017068 GetCurrentThreadId
0x180017070 VirtualAlloc
0x180017078 GetModuleHandleA
0x180017080 GetTempPathA
0x180017088 CreateNamedPipeA
0x180017090 GetComputerNameA
0x180017098 QueryPerformanceCounter
0x1800170a0 GetCurrentProcessId
0x1800170a8 GetSystemTimeAsFileTime
0x1800170b0 InitializeSListHead
0x1800170b8 RtlCaptureContext
0x1800170c0 RtlLookupFunctionEntry
0x1800170c8 RtlVirtualUnwind
0x1800170d0 IsDebuggerPresent
0x1800170d8 UnhandledExceptionFilter
0x1800170e8 GetStartupInfoW
0x1800170f8 GetModuleHandleW
0x180017100 RtlUnwindEx
0x180017108 InterlockedFlushSList
0x180017110 SetLastError
0x180017120 TlsAlloc
0x180017128 TlsGetValue
0x180017130 TlsSetValue
0x180017138 TlsFree
0x180017140 FreeLibrary
0x180017148 GetProcAddress
0x180017150 LoadLibraryExW
0x180017158 GetCurrentProcess
0x180017160 ExitProcess
0x180017168 TerminateProcess
0x180017170 GetModuleHandleExW
0x180017178 GetModuleFileNameA
0x180017180 MultiByteToWideChar
0x180017188 WideCharToMultiByte
0x180017190 HeapFree
0x180017198 HeapAlloc
0x1800171a0 LCMapStringW
0x1800171a8 GetStdHandle
0x1800171b0 GetACP
0x1800171b8 GetStringTypeW
0x1800171c0 FindClose
0x1800171c8 FindFirstFileExA
0x1800171d0 IsValidCodePage
0x1800171d8 GetOEMCP
0x1800171e0 GetCPInfo
0x1800171e8 GetCommandLineA
0x1800171f0 GetCommandLineW
0x1800171f8 GetEnvironmentStringsW
0x180017200 FreeEnvironmentStringsW
0x180017208 GetProcessHeap
0x180017210 SetStdHandle
0x180017218 FlushFileBuffers
0x180017220 WriteFile
0x180017228 GetConsoleCP
0x180017230 GetConsoleMode
0x180017238 RaiseException
0x180017240 HeapSize
0x180017248 HeapReAlloc
0x180017250 SetFilePointerEx
0x180017258 WriteConsoleW
0x180017260 CreateFileW

Exports

Ordinal Address Name
1 0x1800154d0 CKQXU
2 0x180016050 DllRegisterServer
3 0x180015b50 KMYDtl
4 0x180012ec0 OLtC11K
5 0x180015e60 ZGWrNo7ng
!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.gfids
@.rsrc
@.reloc
L$hH;t
@SVWATAUAVAWH
A_A^A]A\_^[
C$#Cd%
SUVWATAUAVAWH
Hct$PA+
A_A^A]A\_^][
SUVWATAUAVAWH
A_A^A]A\_^][
UVWATAUAVAWH
C`HcK|
C|HcK|H
`A_A^A]A\_^]
@UVWAUH
C4+C<5
9K<sPD
(A]_^]
d$ AVAWH
UVWATAUAVAWH
`A_A^A]A\_^]
fA;TE
H SVWH
|$ AVH
H3E H3E
WATAUAVAWH
A_A^A]A\_
ffffff
WATAUAVAWH
A_A^A]A\_
D$@H;G
S,, <Zw
CA< t(<#t
<htr<jtb<lt6<tt&<wt
!,X< w
t$ WAVAWH
s4+sP+
0A_A^_
WAVAWH
A_A^_
u3HcH<H
x ATAVAWH
A_A^A\
UVWAVAWH
0A_A^_^]
WAVAWH
A86taH
0A_A^_
L$ WATAUAVAWH
@A_A^A]A\_
x ATAVAWH
A_A^A\
|$ UATAUAVAWH
A_A^A]A\]
WAVAWH
@A_A^_
USVWAVH
A^_^[]
USVWAVH
A^_^[]
WATAUAVAWH
A_A^A]A\_
fD9t$b
D82u&H
D8t$Ht
x ATAVAWH
gfffffffH
D8d$ht
A_A^A\
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
`A_A^A]A\_^]
x ATAVAWH
0A_A^A\
\$ UVWAVAWH
A_A^_^]
@8|$^t
l$ VWATAVAWH
L$&@8t$&t0@8q
A81t@@8r
A_A^A\_^
fD94Fu
SVWATAUAWH
HA_A]A\_^[
UVWATAUAVAWH
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
\$ UVWATAUAVAWH
H!D$ E
`A_A^A]A\_^]
@UATAUAVAWH
H!T$0D
uf!T$(H!T$
A_A^A]A\]
@USVWATAUAVAWH
D8l$ht
A_A^A]A\_^[]
@UATAUAVAWH
e0A_A^A]A\]
l$ WAVAWH
A_A^_
@UATAVH
WATAUAVAWH
A_A^A]A\_
ffffff
fffffff
|$ ATAVAWH
\$@@8=a8
A_A^A\
LcA<E3
SUWAUAVAWH
A_A^A]_][
SUVWATAUAVAWH
D$H0sf
B*D)$B
A_A^A]A\_^][
SUVWATAUAVAWH
A_A^A]A\_^][
\$ UWATAUAVH
@A^A]A\_]
SUVWATAUAVAWH
A_A^A]A\_^][
UWAUAVAWH
Sl;Spw]
CD;Spv
A_A^A]_]
|$ ATAUAVAWD
|$@A_A^A]A\
|$ AVH
)GDHcO|H
|$ AVAW
t$(A_A^
UVWATAUAVAWH
A_A^A]A\_^]
t$ WAVAWH
formula dreadful help procedures hotter appointed built wheelbarrow expedition scripts sophia feelings supermarket preservation sinking boiler inches sentence foolish suspense repair inch readiness board machine climate method context talent aim momentary does brother fatty weary beautifully steel appendix inspection induce hissed robin export alexis manager stun skiing baseball holiday brutally cow attending emma discourage beyond mule afraid construct shutter sham untidy lucky procedure gag gland polish laboratory anticipate hire instrument angrily downy plaster gust frightful garret apricot celebrity reflected traffic footprint rash preponderant strong plain hog beck sally desirable crust town rabbits afternoon construct hem unpredictable contract endless qualities necessarily triggers failure accompany cure sierra rhinoceros raw glowing forget division duck himself spree choked barton turn holiday detrimental belong uncle bone main folly neglect grandson presented troublesome unload deeply bet regard heel
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`h````
xpxxxx
(null)
[aOni*{
~ $s%r
@b;zO]
v2!L.2
CorExitProcess
GetCurrentPackageId
LCMapStringEx
LocaleNameToLCID
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
1#QNAN
1#SNAN
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
svdik156ej8.dll
DllRegisterServer
KMYDtl
OLtC11K
ZGWrNo7ng
CreateFileA
FindFirstFileA
FindNextFileA
GetFileAttributesA
GetFileType
CloseHandle
GetLastError
ConnectNamedPipe
DisconnectNamedPipe
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
GetCurrentThreadId
VirtualAlloc
GetModuleHandleA
GetTempPathA
CreateNamedPipeA
GetComputerNameA
KERNEL32.dll
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
RtlUnwindEx
InterlockedFlushSList
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
GetModuleFileNameA
MultiByteToWideChar
WideCharToMultiByte
HeapFree
HeapAlloc
LCMapStringW
GetStdHandle
GetACP
GetStringTypeW
FindClose
FindFirstFileExA
IsValidCodePage
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
GetProcessHeap
SetStdHandle
FlushFileBuffers
WriteFile
GetConsoleCP
GetConsoleMode
RaiseException
HeapSize
HeapReAlloc
SetFilePointerEx
WriteConsoleW
CreateFileW
00000000I
p000000[p00000[000000000[0000000
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
advapi32
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
(null)
mscoree.dll
api-ms-win-appmodel-runtime-l1-1-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l2-1-1
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-kernel32-package-current-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
user32
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
CrowdStrike win/malicious_confidence_90% (W)
Alibaba Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Rising Trojan.BumbleBee!8.15A15 (CLOUD)
Ad-Aware Clean
TACHYON Clean
Sophos Mal/Generic-S
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
FireEye Generic.mg.27dfc5e856a1de1b
Emsisoft Clean
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Win64/BumbleBee.SAN!MTB
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
ALYac Clean
MAX Clean
VBA32 Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
AVG TrojanX-gen [Trj]
Avast TrojanX-gen [Trj]
No IRMA results available.