Static | ZeroBOX

PE Compile Time

2004-08-17 04:56:18

PE Imphash

f214c5f744673db93dec4b219265fbc2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000cdd0 0x0000ce00 6.71580677473
.rdata 0x0000e000 0x0001d648 0x0001d800 5.77904817312
.data 0x0002c000 0x000036b8 0x00001200 3.26354148854
.reloc 0x00030000 0x00001134 0x00001200 4.54343965794

Imports

Library KERNEL32.dll:
0x40e03c GetLastError
0x40e040 CloseHandle
0x40e044 IsBadStringPtrA
0x40e048 IsBadCodePtr
0x40e04c GetModuleHandleA
0x40e054 FlushFileBuffers
0x40e058 HeapSize
0x40e05c WriteConsoleW
0x40e060 SetStdHandle
0x40e064 RtlUnwind
0x40e068 IsBadReadPtr
0x40e06c VirtualQuery
0x40e070 GetSystemInfo
0x40e078 HeapDestroy
0x40e07c GetProcessHeap
0x40e080 HeapCreate
0x40e084 ExitProcess
0x40e088 GetTickCount
0x40e08c lstrlenA
0x40e090 HeapReAlloc
0x40e094 HeapFree
0x40e098 HeapAlloc
0x40e0a0 LoadLibraryW
0x40e0a4 OutputDebugStringW
0x40e0a8 LoadLibraryExW
0x40e0ac LCMapStringEx
0x40e0b0 GetStringTypeW
0x40e0b4 GetCommandLineA
0x40e0b8 IsDebuggerPresent
0x40e0bc EncodePointer
0x40e0c0 DecodePointer
0x40e0c8 SetLastError
0x40e0d0 GetCurrentThreadId
0x40e0d4 IsValidCodePage
0x40e0d8 GetACP
0x40e0dc GetOEMCP
0x40e0e0 GetCPInfo
0x40e0e4 MultiByteToWideChar
0x40e0e8 GetModuleHandleExW
0x40e0ec GetProcAddress
0x40e0f0 GetStdHandle
0x40e0f4 WriteFile
0x40e0f8 GetModuleFileNameW
0x40e0fc GetFileType
0x40e108 InitOnceExecuteOnce
0x40e10c GetStartupInfoW
0x40e110 GetModuleFileNameA
0x40e11c GetTickCount64
0x40e128 WideCharToMultiByte
0x40e134 FlsAlloc
0x40e138 FlsGetValue
0x40e13c FlsSetValue
0x40e140 FlsFree
0x40e144 GetCurrentProcess
0x40e148 TerminateProcess
0x40e14c GetModuleHandleW
0x40e158 GetConsoleCP
0x40e15c GetConsoleMode
0x40e160 SetFilePointerEx
0x40e164 Sleep
0x40e168 CreateFileW
Library USER32.dll:
0x40e18c DrawTextW
0x40e190 TranslateMessage
0x40e194 GetMessageW
0x40e198 DispatchMessageW
Library GDI32.dll:
0x40e00c CreateCompatibleDC
0x40e010 SelectPalette
0x40e014 CreatePen
0x40e018 DeleteObject
0x40e01c SetROP2
0x40e020 BitBlt
0x40e024 CreateRectRgn
0x40e028 PathToRegion
0x40e030 CreateBitmap
0x40e034 DeleteDC
Library ADVAPI32.dll:
0x40e000 GetUserNameW
0x40e004 IsTextUnicode
Library SHELL32.dll:
0x40e170 CommandLineToArgvW
0x40e174 SHGetFolderPathW
Library ole32.dll:
0x40e1ac CoUninitialize
0x40e1b0 CoInitialize
0x40e1b4 CoTaskMemFree
0x40e1b8 CoCreateInstance
Library SHLWAPI.dll:
0x40e180 PathCompactPathExW
Library WINMM.dll:
0x40e1a0 PlaySoundW
0x40e1a4 waveOutGetNumDevs

!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
t#9n t@
p(;F tJ
p(;F t9
z(;W tR
z(;W tj
p(;F t
p(;F t
N(;q t
O(;y t
N(;q t
O(;y t
T$$#T$,
L$ ;A(r
L$ ;A(r
oP;oPt\
Genuu_
ineIuV
nteluM3
~pjCXf
,SVWj0X
Wj0XPV
j@j _W
PP9E u
URPQQh
~';_t|%3
+tHHt
+t"HHt
HAO8t
;t$,v-
UQPXY]Y[
esUt fo sihruos
NBWEBELCHSCNTYEAIDAU7UNMEKOW8B9AIDCR8ACEL8BGMOX9DNJNFC6G5GGQOMUMIGPVIXSXPYW8FFIM4XFVBMPZT6E884HU5JCXD6SLP4E4ZTBRSI8G5V5JJKCUCJNDTRBCUFQ5OCXUIR684VO5YI4XGPPBE7DMVWEEK7QQDAUUYCKLRFQARAMLJ8DZX6PI48LRZQMD5AKKYATK5JWKB4MLMC9W7GAWS94RW7HIQEXQQBHAKVZRMGXFDLTSVQN98QNEO9KB2101210DTBI45EGF8XUA769BKZSJIXFQTPC8NG4POG8IZJVHQWVGOLAOHQUGKEJDBOBBA6DW6Z7MSPQMX97FUQTDLWRK4PVGDZY88RAUGPW5MAGWCNOMMFA4JWLMG89A6VZQDPTY5SDXH45S5LG6PAXXREBGMNVZ5LH46HYDHXOEQSW8FSK5AB5XSVBFWGMNEN8CI8EECT79RWLDBIXZAZIPR4SD8V9RGDLINHLAZ9NKIFVWEAHY4KE6ME4GOQ5HMMMYIESFSNGC5AN4WW6IRXUORGFRMHF8WLH9BVZZCY4YWQSIH6DIKC4LN7IQS9I5POHYBGGZHHVGVDOLTQSLHR6ZHVZQ8KHETWDBLV9CDT4TLQLI9KDZ8MFAVEQEKLXAPKRSBWIXLRYDDCTYFMKPFA5QD45UVLZQJSXDDPPOUK7WKJGE6PAUCCSGIYFFSZUF6YJWGOHSNZSU9EY5HYFZE4RBEKKEZGNM7SAKTWON7P7QOYFSAIETM7HJMP6ITMT9W95SZVYRQ5JV65RMLWGKHGWLWSBECONLMURTTATHLSK8DNSZHGNFKK5KX9LUWFR54SCK8GONN5GC9MXMNHPAXMMKNY5K44GEBAYNTDB6WWPZBGAGCFGN59DRG4DAY9OZO8IUG9FRLBROEUNWBN9YPD8IM9YGOZRVYFWYWYOYLSVZ6HGTLC4UCXWNGGHUFYTJLX4GPO66KFEG5IMSLX4UY7VAJ6POGHX7MW9NKIJP4JBEZG6E9R4NUCYX
K,Y{/eI
O7`N`5g"
i/X3|1
IP3,&,;
Q.F$$&
1{WXO0R
DqG9Mi
@aV/CU9
8 CA}S
(null)
`h````
xpxxxx
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
CorExitProcess
GetCurrentPackageId
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
MessageBoxW
GetActiveWindow
GetLastActivePopup
GetUserObjectInformationW
GetProcessWindowStation
1#SNAN
1#QNAN
`h`hhh
xppwpp
HeapAlloc
HeapReAlloc
HeapFree
lstrlenA
GetTickCount
ExitProcess
HeapCreate
GetProcessHeap
HeapDestroy
CreateIoCompletionPort
GetSystemInfo
VirtualQuery
IsBadReadPtr
GetQueuedCompletionStatus
GetLastError
CloseHandle
IsBadStringPtrA
IsBadCodePtr
GetModuleHandleA
InterlockedIncrement
KERNEL32.dll
GetMessageW
DispatchMessageW
TranslateMessage
DrawTextW
USER32.dll
CreateBitmap
CreateCompatibleBitmap
PathToRegion
CreateRectRgn
BitBlt
SetROP2
DeleteObject
CreatePen
SelectPalette
CreateCompatibleDC
DeleteDC
GDI32.dll
GetUserNameW
IsTextUnicode
ADVAPI32.dll
CommandLineToArgvW
SHGetFolderPathW
SHGetSpecialFolderPathW
SHELL32.dll
CoTaskMemFree
CoCreateInstance
CoUninitialize
CoInitialize
ole32.dll
PathMakeSystemFolderW
PathCompactPathExW
SHLWAPI.dll
waveOutGetNumDevs
PlaySoundW
WINMM.dll
GetCommandLineA
IsDebuggerPresent
EncodePointer
DecodePointer
IsProcessorFeaturePresent
SetLastError
InterlockedDecrement
GetCurrentThreadId
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
MultiByteToWideChar
GetModuleHandleExW
GetProcAddress
GetStdHandle
WriteFile
GetModuleFileNameW
GetFileType
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
InitOnceExecuteOnce
GetStartupInfoW
GetModuleFileNameA
QueryPerformanceCounter
GetSystemTimeAsFileTime
GetTickCount64
GetEnvironmentStringsW
FreeEnvironmentStringsW
WideCharToMultiByte
UnhandledExceptionFilter
SetUnhandledExceptionFilter
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
GetCurrentProcess
TerminateProcess
GetModuleHandleW
EnterCriticalSection
LeaveCriticalSection
GetConsoleCP
GetConsoleMode
SetFilePointerEx
GetStringTypeW
LCMapStringEx
LoadLibraryExW
OutputDebugStringW
LoadLibraryW
RtlUnwind
SetStdHandle
WriteConsoleW
HeapSize
FlushFileBuffers
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
1&2\2-3N5
>(>6>H>Z>s>
?(???V?m?~?
=>>K>U>
2F3P3d3
4-4<4g4
7P9p9F:P:
;?<D<N<
<<=A=K=`=p=
171U1\1`1d1h1l1p1t1x1
1:2E2`2g2l2p2t2
3^3d3h3l3p3
7'7G7R7r7}7
<,<3<;<@<D<H<q<
<"=(=,=0=4=
=>Q>X>\>`>d>h>l>p>t>
1 1$1*1.14181>1B1T1u1
5.595C5U5_5
6626j6p6v6|6
7%757>7o7u7{7
;";6;};
3#3(373>3e3
5R506:6@6T6`6$<{<
4J4R4e4p4u4
6;6@6L6Q6p6
7W7o7y7
949A9u9
:/:b:}:
>$>]>g>
??$?H?k?w?
0$0X0~0
1$1+1B1X1f1m1z1
4$404@4O4V4g4u4
5(6B6^6
6Q7d7t7
7'868T8
>W?a?y?
1W1`1n1/2L2R2\2r2
3"3)3W3\3t3}3
404B4T4f4x4
1L3H5z5
7H7O7W7
888E8R8Z8`8l8q8v8{8
9!9&9/949A9
;";(;0;6;<;D;M;T;\;e;w;
=!>B>I>p>}>
3F4L4X4
>X?^?l?{?
546:6L6
657O7X7
8R9c9w9}9
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
,0004080<0@0$5,545<5D5L5T5\5d5l5t5|5
9T9X9x9
:(:H:h:
;(;H;h;t;
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7|7
8 8$8(8,8T8d8t8
9 9p9x9
= =$=(=,=0=4=8=<=H=L=P=T=X=\=`=d=l=p=
(null)
Bja-JP
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
mscoree.dll
BR6002
- floating point support not loaded
- not enough space for arguments
- not enough space for environment
- abort() has been called
- not enough space for thread data
- unexpected multithread lock error
- unexpected heap error
- unable to open console device
- not enough space for _onexit/atexit table
- pure virtual function call
- not enough space for stdio initialization
- not enough space for lowio initialization
- unable to initialize heap
- CRT not initialized
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- not enough space for locale information
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- inconsistent onexit begin-end variables
DOMAIN error
SING error
TLOSS error
runtime error
Runtime Error!
Program:
<program name unknown>
Microsoft Visual C++ Runtime Library
dkernel32.dll
((((( H
h(((( H
H
USER32.DLL
CONOUT$
Antivirus Signature
Bkav W32.MushrwuNocC.Trojan
Lionic Trojan.Win32.Strab.4!c
tehtris Clean
DrWeb Trojan.DownLoader45.41138
MicroWorld-eScan Gen:Variant.Zusy.448594
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Rhadamanthys
McAfee Artemis!E179B14F2697
Malwarebytes Spyware.PasswordStealer
VIPRE Gen:Variant.Zusy.448594
Sangfor Trojan.Win32.Strab.V95y
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Gen:Variant.Zusy.448594
K7GW Trojan ( 0059f0951 )
K7AntiVirus Trojan ( 0059f0951 )
BitDefenderTheta Gen:NN.ZexaF.36344.lqW@a4tcFNk
VirIT Trojan.Win32.Genus.NYZ
Cyren W32/Agent.FRQ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Win32/Agent.AFES
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Strab.gen
Alibaba Trojan:Win32/Strab.4c133c38
NANO-Antivirus Trojan.Win32.Dwn.juuhsf
ViRobot Trojan.Win.Z.Zusy.183808.P
Rising Stealer.Convagent!8.1326D (TFE:5:7fuwJMoABtV)
TACHYON Trojan/W32.Strab.183808.C
Emsisoft Gen:Variant.Zusy.448594 (B)
F-Secure Clean
Baidu Clean
Zillya Trojan.Strab.Win32.879
TrendMicro TrojanSpy.Win32.RHADAMANTHYS.YXDCMZ
McAfee-GW-Edition BehavesLike.Win32.Generic.ch
Trapmine malicious.high.ml.score
FireEye Generic.mg.e179b14f26972c15
Sophos Generic ML PUA (PUA)
Ikarus Trojan.Win32.Agent
GData Gen:Variant.Zusy.448594
Jiangmin Trojan.Strab.boc
Webroot Clean
Avira TR/Agent.xnctp
Antiy-AVL Trojan/Win32.Wacatac
Gridinsoft Malware.Win32.Gen.bot
Xcitium Clean
Arcabit Trojan.Zusy.D6D852
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Rhadamanthys.A!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5378330
Acronis Clean
VBA32 Trojan.Khalesi
ALYac Gen:Variant.Zusy.448594
MAX malware (ai score=84)
Cylance unsafe
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.RHADAMANTHYS.YXDCMZ
Tencent Malware.Win32.Gencirc.10bddcf2
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.124015119.susgen
Fortinet W32/Agent.AFCZ!tr
AVG Win32:TrojanX-gen [Trj]
Avast Win32:TrojanX-gen [Trj]
No IRMA results available.