Static | ZeroBOX

PE Compile Time

2023-03-19 13:33:45

PE Imphash

eb34989b8fe3c43ef88d833129f3453a

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000c188 0x0000c200 6.72035072401
.rdata 0x0000e000 0x00002dec 0x00002e00 6.16443158815
.data 0x00011000 0x00022dfc 0x00022200 7.57514188994
.rsrc 0x00034000 0x00000720 0x00000800 3.74588916028
.reloc 0x00035000 0x00001a30 0x00001c00 4.39689221933

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000340a0 0x000004bc LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0003455c 0x000001b5 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x40e010 FreeConsole
0x40e014 MultiByteToWideChar
0x40e018 GetModuleHandleA
0x40e01c GetProcAddress
0x40e020 GetCommandLineA
0x40e028 GetModuleHandleW
0x40e02c Sleep
0x40e030 ExitProcess
0x40e034 WriteFile
0x40e038 GetStdHandle
0x40e03c GetModuleFileNameA
0x40e04c WideCharToMultiByte
0x40e050 GetLastError
0x40e058 SetHandleCount
0x40e05c GetFileType
0x40e060 GetStartupInfoA
0x40e068 TlsGetValue
0x40e06c TlsAlloc
0x40e070 TlsSetValue
0x40e074 TlsFree
0x40e07c SetLastError
0x40e080 GetCurrentThreadId
0x40e088 HeapCreate
0x40e08c VirtualFree
0x40e090 HeapFree
0x40e098 GetTickCount
0x40e09c GetCurrentProcessId
0x40e0a4 HeapAlloc
0x40e0a8 RaiseException
0x40e0ac GetCPInfo
0x40e0b0 GetACP
0x40e0b4 GetOEMCP
0x40e0b8 IsValidCodePage
0x40e0bc TerminateProcess
0x40e0c0 GetCurrentProcess
0x40e0c8 IsDebuggerPresent
0x40e0d4 LoadLibraryA
0x40e0dc VirtualAlloc
0x40e0e0 HeapReAlloc
0x40e0e4 RtlUnwind
0x40e0e8 HeapSize
0x40e0ec LCMapStringA
0x40e0f0 LCMapStringW
0x40e0f4 GetStringTypeA
0x40e0f8 GetStringTypeW
0x40e0fc GetLocaleInfoA
Library GDI32.dll:
0x40e000 GetTextMetricsW
0x40e004 SetStretchBltMode
0x40e008 SetBkColor

!This program cannot be run in DOS mode.
u9Richs
`.rdata
@.data
@.reloc
_VVVVV
^WWWWW
>=Yt1j
j@j ^V
0A@@Ju
to=(-C
0SSSSS
0SSSSS
_VVVVV
0SSSSS
0SSSSS
URPQQhx
t"SS9]
v$;5L-C
PPPPPPPP
PPPPPPPP
<+t(<-t$:
+t HHt
uL9=t8C
;t$,v-
UQPXY]Y[
t+WWVPV
bad allocation
VirtualProtect
kernel32.dll
hM1P2TqnQbStar91rbMIVgkWBEOSHPf4bhDojfBxFl4Yh2BEhzJqC70Q8NIuh860q
4Y6YBIv5QzCwEL3OyHvnCFBeT0UT9um6xeHspCbINdjO4cdBrh2RasUvnECRgB8iS
cAPlA6Vm037aJLjgNUl6q7KdYNp4Y4SCnjiI2v3OC7gceR25JSm5qwKII2bDrDTXO
^)I&]iZ
^[<1]|
^Cu=]:
]vP`\Kh&]E
\-81]r
\%i!]2
]]!E0^
n^0}:^
^B-{^q!
\FZS],u
EC\tV+]f
^p`=\yqV]
O"^tdF]S
7]ko<]k
_0Jx]1~G^
"^bad allocation
GAIsProcessorFeaturePresent
KERNEL32
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
Unknown exception
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
1#QNAN
1#SNAN
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
GetProcAddress
GetModuleHandleA
MultiByteToWideChar
FreeConsole
KERNEL32.dll
SetBkColor
SetStretchBltMode
GetTextMetricsW
GDI32.dll
GetCommandLineA
SetUnhandledExceptionFilter
GetModuleHandleW
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetLastError
GetEnvironmentStringsW
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
HeapCreate
VirtualFree
HeapFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
HeapAlloc
RaiseException
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
IsDebuggerPresent
LeaveCriticalSection
EnterCriticalSection
LoadLibraryA
InitializeCriticalSectionAndSpinCount
VirtualAlloc
HeapReAlloc
RtlUnwind
HeapSize
LCMapStringA
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
{QX"TG<Q
X[$qYM)
6qnT.4
wCeM3
Qcl&SS
IF 2Tj
a_v43~5
|Ag?i&l+`ZF`=
Z|7!YyBy2?
8g*/E,
y".)[a
N 60 n
g+0HI%N
Fn2S"=
P1|pjr#u
,z>@YJ#u
(]+:k_
El=kX
89Ziv[
0x/Mtye
78pF8.
Gk>'Ku
4E&Qv*
e?*A+q
B:g:-s
XR/AHN
cjW)BI
uW_y)8
v}gM72
=PPnK=
^D<+Ju
0()x&4Mn
}eCR#:
Z+'hV8
Z=kwWc
&kkI#f
z""CP-
RYxD-
l2(bj
Bu&%3*
_j@O`8
54ks+P
%k`8CM
O C]"J
x;|Q8IJ
5"C3U'
sGsL5-J
L-8l5U
bcO |>
0^jD?x/
5 {V<?
zO%,x[J
sz@Z4
7S$z!.{
'2}[4
(tq4@6
). A)'
R05nQ^
;R1a-i
Ij ">4
"_9e V
jS1d '(K
] } ip
Qd}wP~Q
MXP-OD
$2F ij
qjdhNt=
|[^z!a
G#sj;|
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="requireAdministrator"
uiAccess="False"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
3!3*333?3L3U3^3j3w3
4(454>4G4S4`4i4r4{4
5'505<5I5R5[5d5m5y5
6%626;6D6M6V6b6o6x6
7$7-767?7K7X7a7j7v7
88(848A8J8S8_8l8u8~8
9*939<9H9U9^9g9s9
9):5:A:S:`:l:x:
;/;<;H;T;`;l;~;
<#<0<<<H<Z<g<s<
=+=4===I=V=_=h=q=z=
>&>2>?>H>Q>Z>c>o>|>
?(?1?:?F?R?d?q?}?
0"0.0@0M0Y0e0q0}0
1"141A1M1Y1k1x1
2(252A2M2_2l2x2
3%373D3P3\3n3{3
4+484D4P4b4o4{4
5 5,585D5V5c5o5{5
6 626?6K6W6c6o6
7&737?7K7]7j7v7
8!8.878@8L8Y8b8k8w8
9(9:9G9S9_9q9~9
: :):5:B:K:T:`:m:v:
;+;4;=;I;V;_;h;
<!<-<?<L<X<d<v<
=!=3=@=L=X=j=w=
>'>4>@>L>^>k>w>
?(?4?@?R?_?k?w?
0.0;0G0S0_0k0}0
1"1/1;1G1Y1f1r1~1
2*232<2H2U2^2g2s2
3$363C3O3[3m3z3
4*474C4O4a4n4z4
5$5B5\9{9
9*:_:x:
; ;$;n;t;x;|;
< <A<k<
=0>5>?>y>~>
=P>V>k>t>
>S?[?n?y?~?
0'0g0t0
2*232:2C2
3%373[3
4"5,5|5
5`7q7y7
848@8M8T8
8989F9Z9{9
; ;r;x;
<$<8<?<f<l<w<
=(=.=:=@=M=W=^=v=
=7>=>g>m>
>A?d?n?
0 0(0.050;0B0H0P0W0\0d0m0y0~0
1&1F1L1h1
3!4)4>4]4
;";;;E;X;|;
>$>,>C>\>x>
2>2P2"3,393T3[3s3
7(7/777<7@7D7m7
8$8(8,808
9M9T9X9\9`9d9h9l9p9
9 ;<;_;
0M0X0d0k0u0
2f3k3p3u3
4S4X4_4d4k4p4
6 6&666;6S6Y6h6n6}6
9?9H9T9
9*:/:r<
==<=B=M=R=Z=`=j=q=
6>6^6c6;7s7
8#8/898A8L8|8
< <(<5<<<l<
0T2J3R3
5(6.6>6
;"<9<i<
(3,3034383<3@3D3H3L3P3T3a3<4T4c4
="=-=9=>=N=S=Y=_=u=|=
404v4|4
9{:C<P<^<
0p1v1z1
@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(404H4L4d4t4x4
5 5$5,5@5H5\5t5x5
6(6H6h6
7$7(7H7d7h7
2 2$2(2,2024282<2@2D2H2T2\2d2l2t2|2
3d3h3l3
9(989H9X9|9
9P<`<d<h<l<p<t<x<|<
= =(=,=0=4=8=<=@=D=H=L=X=P>T>
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
210429000000Z
360428235959Z0i1
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
[K]taM?
SA|X=G
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
jj@0HK4
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
220429000000Z
240501235959Z0
Delaware1
Private Organization1
27481291
San Jose1
Adobe Inc.1
Acrobat 111
Adobe Inc.0
->`}\"
US-DELAWARE-27481290
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0=
http://www.digicert.com/CPS0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
>"kWGItY
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
{y1~0V
20230303081113Z
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
220921000000Z
331121235959Z0F1
DigiCert1$0"
DigiCert Timestamp 2022 - 20
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
230303081113Z0+
/1(0&0$0"
mscoree.dll
KERNEL32.DLL
((((( H
h(((( H
H
AxAXA8A
VS_VERSION_INFO
StringFileInfo
040904E4
CompanyName
Hillock streaking
FileDescription
Falsebay toleration presupposition cuddled hermaphrodite lenders
FileVersion
8.258.196.5
InternalName
Prunes surpassed
LegalCopyright
Copyright
Shelved liquid
LegalTrademarks
Detachable novelist cairo charioteers overshot faults
OriginalFilename
Panda designating
ProductName
Understate
ProductVersion
8.258.196.5
Comments
Modified by an unpaid evaluation copy of Resource Tuner 2. http://www.heaventools.com
VarFileInfo
Translation
BAdobe Acrobat Reader DC Installe
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Strab.4!c
tehtris Clean
DrWeb Clean
MicroWorld-eScan Gen:Variant.Fragtor.234298
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!CA341777340C
Malwarebytes Clean
VIPRE Gen:Variant.Fragtor.234298
Sangfor Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Fragtor.234298
K7GW Clean
CrowdStrike win/malicious_confidence_70% (W)
BitDefenderTheta Gen:NN.ZexaF.36344.nu2@ae7awaoi
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/GenKryptik.GHTO
APEX Clean
Paloalto Clean
ClamAV Clean
Kaspersky UDS:Trojan.Win32.Strab.gen
Alibaba Trojan:Win32/GenKryptik.c54ddf5b
NANO-Antivirus Clean
ViRobot Clean
Rising Stealer.Agent!8.C2 (TFE:5:WOenaBb7pGL)
Sophos Generic ML PUA (PUA)
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.high.ml.score
FireEye Gen:Variant.Fragtor.234298
Emsisoft Gen:Variant.Fragtor.234298 (B)
SentinelOne Clean
GData Gen:Variant.Fragtor.234298
Jiangmin Clean
Webroot Clean
Google Detected
Avira Clean
MAX malware (ai score=89)
Antiy-AVL Clean
Gridinsoft Trojan.Win32.Gen.bot
Xcitium Clean
Arcabit Trojan.Fragtor.D3933A
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Ransom:Win32/Aicat.A!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Gen:Variant.Fragtor.234298
TACHYON Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CCJ23
Tencent Clean
Yandex Clean
Ikarus Trojan.Win32.Crypt
MaxSecure Clean
Fortinet Clean
AVG Win32:CrypterX-gen [Trj]
Avast Win32:CrypterX-gen [Trj]
No IRMA results available.