Static | ZeroBOX

PE Compile Time

2022-09-26 13:08:41

PE Imphash

e299c59b4cf9b51aeaa1f8bf0d95dc02

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00015679 0x00000000 0.0
.rdata 0x00017000 0x0000a5c6 0x00000000 0.0
.data 0x00022000 0x00003f50 0x00000000 0.0
.pdata 0x00026000 0x00001134 0x00000000 0.0
.vmp0 0x00028000 0x0001e05b 0x00000000 0.0
.vmp1 0x00047000 0x00039ba0 0x00039c00 7.88953064035
.reloc 0x00081000 0x00000024 0x00000200 0.369416603835
.rsrc 0x00082000 0x000001d5 0x00000200 4.70436301348

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00082058 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x14005d000 GetModuleFileNameW
Library USER32.dll:
0x14005d010 PostMessageA
Library KERNEL32.dll:
0x14005d020 GetModuleFileNameW
Library KERNEL32.dll:
0x14005d030 GetModuleHandleA
0x14005d038 LoadLibraryA
0x14005d040 LocalAlloc
0x14005d048 LocalFree
0x14005d050 GetModuleFileNameA
0x14005d058 ExitProcess

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.vmp0
.reloc
@.rsrc
.iUWzz4
oA*Kkq
#=!Sy&Kx
wim80g
,pO!4bg
)u"};f
[t.M4
LocalAlloc
Z0YazVa
ExitProcess
0.Fsi~
":Kd>]
!5JjSi
W2GLEw
z;w+;g -
VpXJYt9
|w4NBJ
Rk>I'q
>F{T*7R
tQii3GqT
vndKZX'
{T\T{>#
Lk>m2/
dkXf %3
yX+<e,
jmx>(=.
|EQ'Ru"P
O]:cJ><&6
4T|g&_
.d*dN]
~jD/3`
[OPqQk|
Svhf=&
U:Qao[
H*;&+*
p8[x'T+
'OJ W
o-~!e@jk
.?HytG
*Q2'CN
QDZV2A';:
{5skZC
b>z1V/s
aiFO<5
I<d#MPtE
b4YMKJho
HI7{^d
yKHGhS
UA3qDV
lu[Yck&
56E-7m
h/9jCS
ndT/[_/FE
4cR?I(
:l3e2
.:GQDf
RS%GG8T04+
UF1Ht.CU;
ErJ7x?
"p(4U1
m"?A4Sn
u1UK.:
xF&fHY%
6ms?1U
XffB{k
0G%A(P
[pKHp4
-;}Y"p
k1;(&}
XQIWNk
RT}Y#P-bp
XVfr#T
#aaj_A[W
5:U1uN
#A*9%B
iSpyHt*
YS)c[
SgWA^"W:
?6@P3?
/yT@ZB3
4|G)CnV3i!
^z,$Uc
)GbNqO
Pz\%}m2Z
<'4|fW
&V5BTOd
"V<F\/
iO"1E_@Q
!7}0g@
<lSP9by4
}Qf|e|
~7|T-u
qM;%.,q^
&dQ^H
&~oY8Z
yDjFSt
t362!
EmgRs/>
GetModuleFileNameW
[&^xDv
_Oki$-
kmG,nR82
qZxT-xq
27&ImM3
hl'3r_
{wszy3
jQg.mVB
j)* 1\_l
6CK`qt
r"jYjl
PS1~O
*.Rmjk
DdFa,+<
jvAs$A
".oUP9
k?EH~-
^UE+.7<
EW{Rt
sF&2aZ;r
Z7b=t/
N>g!Fj
T&=Bqj
?d9C^r
P6E#jmQ
+oO^kyi
B84@$5
ias0yYi~
eY$Wu>2
mc5 Z
lu"sDQ*
zJYnj{
j}UG$<[S
F|%J9mwF
Yt}I?t
3\`<9{
B0.ef}OY
uYBl%ew
wEp[#x
`}mH=Q
USER32.dll
[,SA'
+_zq7
LoadLibraryA
(B\=Yfa*
LocalFree
.(@9]U
4dxu93
:W=RNl
pP{!7
+hN!:
;NEG>sZ
*MU jW
qpYmrq
Z<8'Pc
C%\&WV
#oNPnDU
eGF|bm)V
-KiD*}`
qiRb=Y
Zw{W&`!D"%
|60n\$
#&DEPA}
ZA+Odp
cRzC_(;B
UcNco[
@C0e{:
MA{"{?*!!j<%'
J|#5|Y}R
3G\#HI
]pa5yD
N u(eNiz
GetModuleFileNameA
\O#HP9
r[z7X5D
KERNEL32.dll
<pS$Mf
:#(C~K
GetModuleHandleA
Kedt]q2j
(QnB(.
J=XRZR=!
JFq3J^f
>ZR3B.
R6>:Xz
$%&'()*+
,-./0123
456789:;
<=>?@ABC
DEFGHIJK
LMNOPQRS
TUVWXYZ[
\]^_`abc
defghijk
lmnopqrs
tuvwxyz{
*{q?s04
( Y$k"
}J!rU%
.#b3lA
Wq.rCXT
user32.dll
nt'>Xb
Y|e{nc
p99">+
SaLiM~
9tBmMq
Lq7 ;o
`>P3G;0
&}`>'!>J
*pO!)jF5O
Pb"mGF
\teg r[
[Z@$7Z
'#iZ&M
pV%3Z(
}t*%$Z
SjBU1d]B
.|XG_0
|er&5ug
t8]2}[
7#\(-Vs
Xq)?F\
g":YF}
+7 1%s
~J=H@!=
3(9i,i
_~D;SN
8.kV_EU
{(qr=#vC
)xOYkT
v!}mA|
b0]Hk+vP
[*o4IR
Un8L#d
0,2ew>
xEiyrG
9Kb<%4
l0cOqJ
^z'<( qD
UZmD>C=JS*R
3]IG/J
^%n)70okZ~
G|jaLCb$
m@ic/h
6qN0ozXKb
xJ3J$#ee.
)c${GX
qs\xE
Z{[yTu
^6qw8gZ
PostMessageA
<EnFaJh%g
AV4KBd
259";Sh
>lFE(X
"&kId|
J?M`)=`S
9E^*D?
sy:X9v
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.214aa1ab355e70ae
CAT-QuickHeal Clean
ALYac Clean
Cylance unsafe
Zillya Clean
Sangfor Clean
K7AntiVirus Trojan ( 7000001d1 )
BitDefender Clean
K7GW Trojan ( 7000001d1 )
CrowdStrike win/malicious_confidence_70% (D)
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Packed.VMProtect.ABO
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Emsisoft Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine malicious.moderate.ml.score
CMC Clean
Sophos Mal/VMProtBad-A
Ikarus Trojan.Win32.VMProtect
GData Clean
Jiangmin Clean
Webroot Clean
Google Detected
Avira TR/Black.Gen2
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Trojan.Black.Qzfl
Yandex Trojan.GenAsa!MCKN04f+JBc
SentinelOne Static AI - Suspicious PE
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Win64:MalwareX-gen [Trj]
Avast Win64:MalwareX-gen [Trj]
No IRMA results available.