Static | ZeroBOX

PE Compile Time

2023-03-01 21:46:27

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000054d2 0x00005600 6.21409239969
.rdata 0x00007000 0x00001cd8 0x00001e00 5.06013741568
.data 0x00009000 0x000082d0 0x00000400 1.6325523065
.CRT 0x00012000 0x00000060 0x00000200 1.07764867895
.reloc 0x00013000 0x000008a4 0x00000a00 6.27703738516

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
uhd|@
tDhL~@
SVWj@h
L$8QRRR
PWWj(W
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
Opera Software\Opera GX Stable
Opera Software\Opera Stable
Google\Chrome
Microsoft\Edge
Google(x86)\Chrome
Chromium
BraveSoftware\Brave-Browser
Epic Privacy Browser
Vivaldi
Orbitum
Mail.Ru\Atom
Kometa
Comodo\Dragon
Comodo
Slimjet
360Browser\Browser
Maxthon3
K-Melon
Sputnik\Sputnik
Nichrome
CocCoc\Browser
uCozMedia\Uran
Chromodo
Yandex\YandexBrowser
ibnejdfjmmkpcnlpebklmnkoeoihofec
TronLink
nkbihfbeogaeaoehlefnkodbefgpgknn
MetaMask
bocpokimicclpaiekenaeelehdjllofo
XDCPay
nphplpgoakhhjchkkhmiggakijnkhfnd
pocmplpaccanhmnllbbkpgfliimjljgo
mfhbebgoclkghebffdldpobeajmbecfk
Starcoin
fhilaheimglignddkjgofkcbgekhenbh
Oxygen
hnhobjmcibchnmglfbldbfabcgaknlkj
apnehcjmnengpnmccpaibjmhhoadaico
CardWallet
cjmkndjhnagcfbpiemnkdpomccnjblmj
Finnie
cmndjbecilbocjfkibfbifhngkdmjgog
pnndplcbkakcplkjnolgbkdgjikjednm
TronWallet
dhgnlgphgchebgoemcjekedjjbifijid
CryptoAirdrop
fhbohimaelbohpjbbldcngcnapndodjp
Binance Chain Wallet
ffnbelfdoeiohenkjibnmadjiehjhajb
afbcbjpbpfadlkmhmclhkeeodmamcflc
Math Wallet
hnfanknocfeofbddgcijnmhnfnkdnaad
Coinbase Wallet
hpglfhgfnhbgpjdenjgmdgoeiappafln
Guarda
cjelfplplebdjjenllpjcblmjkfcffne
Jaxx Liberty
kncchdigobghenbbaddojjnnaogfppfj
iWallet
amkmjjmmflddogmhpjloimipbofnfjih
Wombat
nlbmnnijcnlegkjjpcfjclmcfggfefdm
MEW CX
ppdadbejkmjnefldpcdjhnkpbjkikoip
fnjhmkhhmkbjkkabndcnnogagogbneec
Ronin Wallet
cphhlgmgameodnhkjdmkpanlelnlohao
NeoLine
nhnkbkgjikgcigadomkphalanndcapjk
Clover Wallet
kpfopkelmapcoipemfendmdcghnegimn
Liquality Wallet
copjnifcecdedocejpaapepagaodgpbh
FreaksAxie Wallet
aiifbnbfobpmeekipheeijimdpnlpgpp
Terra Station
dmkamcknogkgcdfhhbddcghachkejeap
cnmamaachppnkjgnildpdmkaakejnhae
Auro Wallet
jojhfeoedkpkglbfimdfabpdfjaoolaf
Polymesh Wallet
flpiciilemghbmfalicajoolhkkenfel
ICONex
nknhiehlklippafakaeklbeglecifhad
Nabox Wallet
hcflpincpppdclinealmandijcmnkbgn
ookjlbkiijinhpmnjffcofjonbfbgaoc
Temple
mnfifefkajgofkcjkemidiaecocnkjeh
TezBox
hmeobnfnfcmdkdcmlblgagmfpfboieaf
XDefiWallet
dkdedlpgdmmkkfjabffeganieamfklkm
Cyano Wallet
nlgbhdfgdhgbiamfdfmbikcdghidoadd
cihmoadaighcejopammfbmddcmdekcje
LeafWallet
lodccjjbdhfakaekdiahmedfbieldgik
DAppPlay
bcopgchhojmggmffilplmbdicgaihlkp
Hycon Lite Client
klnaejjgbibmhlephnhpmaofohgkpgkd
ZilPay
aeachknmefphepccionboohckonoeemg
Coin98 Wallet
fnnegphlobjdpkhecapkijjdkgcjhkib
Harmony
pdadjkfkgcafgbceimcpbkalnfnepbnk
KardiaChain
acmacodkjbdgmoleebolmdjonilkdbch
bfnaelmomeimhlpmgjnjophhpkkoljpa
Phantom
cgeeodpfagjceefieflmdfphplkenlfk
EVER Wallet
imloifkgjagghnncjkhggdhalmcnfklk
Trezor Password Manager
aholpfdialjgjfhomihkjbmgjidlcdno
Exodus Web3
bhghoamapcdpbohphigoooaddinpkbai
Authenticator
gaedmjdfmmahhbjefcbgaolhhanlaolb
oeljdldpnmdbchonielidgobddffflal
EOS Authenticator
ilgcnhelpchnceeipipijaljkblbcobl
GAuth Authenticator
$$$$$$$$$$$$
_START$$$$$$$$$$$$
\User Data
Profile
System
Default
$$$$$$MASTERKEY_START$$$$$$
$$$$$$MASTERKEY_END$$$$$$
\Local Extension Settings
\Web Data
\Login Data
$$$$$DESKWALLETS_START$$$$$
$$$$$$WALLET_FILE_
$$$$$$
$$$$$WALLET_FILE_
_END$$$$$
$$$$$DESKWALLETS_END$$$$$
$$$$$$AUTOFILLS_START$$$$$$
$$$$$$AUTOFILLS_END$$$$$$
$$$$$$PASSWORDS_START$$$$$$
$$$$$$PASSWORDS_END$$$$$$
\Cookies
\Network\Cookies
_END$$$$$$$$$$$$
$$$$$$COOKIES_START$$$$$$
$$$$$$COOKIES_END$$$$$$
\..\..
\..\..\..
\Local State
\AppData\Roaming\
\AppData\Local\
$$$$$$WALLETS_START$$$$$$
$$$$$$WALLETS_END$$$$$$
$$$$$$CHROMIUM_START$$$$$$
$$$$$$CHROMIUM_END$$$$$$
$$$$$$GECKO_START$$$$$$
$$$$$$GECKO_END$$$$$$
$$$$$$USERINFO_START$$$$$$
$$$$$$USERINFO_END$$$$$$
$$$$$$MISC_START$$$$$$
$$$$$$MISC_END$$$$$$
$$$$$$FTP_START$$$$$$
$$$$$$FTP_END$$$$$$
$$$$$$STEAM_START$$$$$$
$$$$$$STEAM_END$$$$$$
$$$$$$FILEGRABBER_START$$$$$$
$$$$$$FILEGRABBER_END$$$$$$
$$$$$$INFO_START$$$$$$
$$$$$$INFO_END$$$$$$
\Mozilla\Firefox
\Waterfox
\K-Meleon
\Thunderbird
\Comodo\IceDragon
\8pecxstudios\Cyberfox
\NETGATE Technologies\BlackHaw
\Moonchild Productions\Pale Moon
$$$$$$GECKO_BROWSER_START$$$$$$
\Profiles
\formhistory.sqlite
\cookies.sqlite
$$$$$$GECKO_FILE_
_END$$$$$$
$$$$$$GECKO_BROWSER_END$$$$$$
User:
Screen Size:
Cores:
C:\Program Files (x86)\
C:\Program Files\
InstalledSoftware:
C:\Program Files (x86)\Steam
$$$$$STEAM_FILE_
_START$$$$$$
$$$$$$
\config\config.vdf
\config\loginusers.vdf
\FileZilla\recentservers.xml
\FileZilla\sitemanager.xml
\GHISLER\wcx_ftp.ini
$$$$$FTP_FILE_
$$$$$$TELEGRAM_START$$$$$$
\Telegram Desktop\tdata
D877F783D5D3EF8C
A7FDF864FBC10B77
C2B05980D9127787
F8806DD0C461824F
\key_datas
$$$$$$TELEGRAM_FILE_
$$$$$$TELEGRAM_END$$$$$$
$$$$$$FILEGRABBER_FILE_
$$$$$$WALLETCORE_START$$$$$$
Exodus
$$$$$$WALLETCORE_FILE_
$$$$$$WALLETCORE_END$$$$$$
wallet
$$$$$$WALLET_START_BINANCE$$$$$$
Binance\app-store.json
Wallets\Binance\app-store.json
$$$$$BINANCE_FILE_
$$$$$$WALLET_END_BINANCE$$$$$$
$$$$$$WALLET_START_EXODUS$$$$$$
\Exodus\exodus.wallet
\Exodus
$$$$$EXODUS_FILE_
market-history
$$$$$$WALLET_END_EXODUS$$$$$$
$$$$$$WALLET_START_ATOMIC$$$$$$
\atomic\Local Storage\leveldb
$$$$$ATOMIC_FILE_
$$$$$$WALLET_END_ATOMIC$$$$$$
$$$$$$WALLET_START_ARMORY$$$$$$
\Armory\
$$$$$ARMORY_FILE_
$$$$$$WALLET_END_ARMORY$$$$$$
$$$$$$WALLET_START_COINOMI$$$$$$
\Coinomi\Coinomi\wallets
$$$$$COINOMI_FILE_
$$$$$$WALLET_END_COINOMI$$$$$$
$$$$$$WALLET_START_ETHEREUM$$$$$$
\Ethereum\keystore\
$$$$$ETHEREUM_FILE_
$$$$$$WALLET_END_ETHEREUM$$$$$$
$$$$$$WALLET_START_ZCASH$$$$$$
\Zcash\
$$$$$ZCASH_FILE_
$$$$$$WALLET_END_ZCASH$$$$$$
$$$$$$WALLET_START_JAXX$$$$$$
\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\
$$$$$JAXX_FILE_
$$$$$$WALLET_END_JAXX
$$$$$$
User32.dll
Crypt32.dll
Shell32.dll
Ws2_32.dll
Ole32.dll
Kernel32.dll
CoTaskMemAlloc
CoTaskMemFree
wsprintfA
GlobalMemoryStatusEx
OutputDebugStringA
ExitProcess
VirtualAlloc
VirtualFree
SHGetFolderPathA
CryptUnprotectData
CryptStringToBinaryA
inet_pton
WSAStartup
WSACleanup
socket
listen
accept
connect
shutdown
getaddrinfo
freeaddrinfo
closesocket
ioctlsocket
GetSystemMetrics
EnumDisplayDevicesA
GetLastError
GetLogicalProcessorInformation
GetFileSize
GetTickCount
GetFileInformationByHandle
FileTimeToSystemTime
GetLocalTime
SystemTimeToFileTime
UnmapViewOfFile
CreateFileMappingA
MapViewOfFile
SetFilePointer
GetTempPathA
GetFileAttributesA
CopyFileA
FindFirstFileA
FindNextFileA
FindClose
GetFileSizeEx
CreateFileA
CloseHandle
ReadFile
WriteFile
.text$di
.text$mn
.rdata
.rdata$voltmd
.rdata$zzzdbg
.CRT$XCU
94.142.138.10$$
$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
browser_wallets$
binance$
Cabriolet$$$$$$$$$$$$$$$$$$
wallets_core$
steam_conf$
$$$$$$$$$$$$$$$$$$$$$$$$$$$
5001$$$$$
telegram_conf$
GRABPATH_CONF$$$$$$$$$$$$$$$
$$$$$$$$$$$$$$$$$$$$$$$$$$$
ftp_conf$
desktop_wallets$
0!00070@0O0V0_0n0u0~0
1(1/181G1N1W1f1m1v1
2 2'202?2F2O2^2e2n2}2
2=4S4p4
5@5M5i5
9'9?9W9x9
>5>W>m>
151E1r1
2"2G2s2
3$3F3Z3w3
4%424N4v4
5@5j5w5
5-6I6u6
7'7O7a7k7u7~7
8"8'81868@8E8O8T8^8c8m8r8|8
9!9&90959?9D9N9S9]9b9l9q9{9
: :%:/:4:>:C:M:R:\:a:k:p:z:
;!;-;9;E;Q;];i;u;
<&<;<k<
=#=0=X=l=
>.>7>C>L>Y>b>n>w>
?#?0?9?E?N?[?d?p?y?
0%020;0G0P0]0f0r0{0
1(1@1L1d1p1
2$2<2H2`2
3*383G3Q3\3z3
4(474A4L4j4x4
5#5C5a5o5
6&606:6D6q6
7&8>8j8w8
9C9S9]9o9
:+:?:`:
<;=E=O=X=
> >E>]>
>-?G?`?m?
141=1N1[1|1
3-373J3l3
4#4<4I4e4~4
545A5Y5y5
6B6G6P6`6g6w6
7@7N7_7
8"8/8L8Z8
:%:5:q:
;/;?;I;Z;
< =<=L=_=o=
>.>;>S>i>y>
0 010Z0v0
0(1@1h1u1
2#262F2
3*3@3P3Z3k3
6606D6`6p6
7<7I7_7l7|7
838K8_8|8
:2:O:~:
;(;5;M;
< <3<C<P<n<
=#=D=V=o=
>>F>a>~>
?3?@?\?
10B0G0O0T0_0f0n0u0}0
1 1&1+10181=1B1J1O1T1_1d1i1q1v1{1
2%2*21262;2C2I2O2T2Y2a2f2k2s2x2}2
3#3(30363<3A3F3N3S3X3`3e3j3r3w3|3
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0
Antivirus Signature
Lionic Clean
Elastic malicious (moderate confidence)
MicroWorld-eScan Gen:Variant.Fragtor.223188
FireEye Gen:Variant.Fragtor.223188
CAT-QuickHeal Clean
ALYac Gen:Variant.Fragtor.223188
Malwarebytes Malware.AI.4208430519
Zillya Trojan.Agent.Win32.3262864
Sangfor Clean
K7AntiVirus Password-Stealer ( 0054d1a31 )
BitDefender Gen:Variant.Fragtor.223188
K7GW Password-Stealer ( 0054d1a31 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/PSW.Agent.OGR
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Trojan-PSW.Win32.Stealer.beiv
Alibaba Clean
NANO-Antivirus Virus.Win32.Gen.ccmw
ViRobot Clean
Rising Stealer.Agent!8.C2 (TFE:4:yfGWnejx14N)
TACHYON Clean
Sophos ML/PE-A
F-Secure Clean
DrWeb Trojan.PWS.Steam.34994
VIPRE Gen:Variant.Fragtor.223188
TrendMicro Clean
McAfee-GW-Edition GenericRXVN-ON!F9B6AA6B0694
Trapmine Clean
CMC Clean
Emsisoft Gen:Variant.Fragtor.223188 (B)
Ikarus Clean
GData Gen:Variant.Fragtor.223188
Jiangmin Clean
Webroot Clean
Google Clean
Avira TR/Crypt.EPACK.Gen2
Antiy-AVL Trojan[PSW]/Win32.Agent
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Fragtor.D367D4
SUPERAntiSpyware Clean
ZoneAlarm Trojan-PSW.Win32.Stealer.beiv
Microsoft Trojan:Win32/Cryware.B
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Cryware.C5393521
Acronis Clean
McAfee Clean
MAX malware (ai score=89)
VBA32 BScope.TrojanPSW.Stealer
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Trojan.PWS.Agent!6GjEPYZxRfA
SentinelOne Clean
MaxSecure Trojan.Malware.202358588.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaE.36308.cuW@aq4gM8d
AVG Win32:SwPatch [Wrm]
Avast Win32:SwPatch [Wrm]
No IRMA results available.