Static | ZeroBOX

PE Compile Time

2023-03-01 21:46:27

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000054d2 0x00005600 6.21409239969
.rdata 0x00007000 0x00001cd8 0x00001e00 5.06013741568
.data 0x00009000 0x000082d0 0x00000400 1.67664590771
.CRT 0x00012000 0x00000060 0x00000200 1.07764867895
.reloc 0x00013000 0x000008a4 0x00000a00 6.27703738516

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
uhd|@
tDhL~@
SVWj@h
L$8QRRR
PWWj(W
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
Opera Software\Opera GX Stable
Opera Software\Opera Stable
Google\Chrome
Microsoft\Edge
Google(x86)\Chrome
Chromium
BraveSoftware\Brave-Browser
Epic Privacy Browser
Vivaldi
Orbitum
Mail.Ru\Atom
Kometa
Comodo\Dragon
Comodo
Slimjet
360Browser\Browser
Maxthon3
K-Melon
Sputnik\Sputnik
Nichrome
CocCoc\Browser
uCozMedia\Uran
Chromodo
Yandex\YandexBrowser
ibnejdfjmmkpcnlpebklmnkoeoihofec
TronLink
nkbihfbeogaeaoehlefnkodbefgpgknn
MetaMask
bocpokimicclpaiekenaeelehdjllofo
XDCPay
nphplpgoakhhjchkkhmiggakijnkhfnd
pocmplpaccanhmnllbbkpgfliimjljgo
mfhbebgoclkghebffdldpobeajmbecfk
Starcoin
fhilaheimglignddkjgofkcbgekhenbh
Oxygen
hnhobjmcibchnmglfbldbfabcgaknlkj
apnehcjmnengpnmccpaibjmhhoadaico
CardWallet
cjmkndjhnagcfbpiemnkdpomccnjblmj
Finnie
cmndjbecilbocjfkibfbifhngkdmjgog
pnndplcbkakcplkjnolgbkdgjikjednm
TronWallet
dhgnlgphgchebgoemcjekedjjbifijid
CryptoAirdrop
fhbohimaelbohpjbbldcngcnapndodjp
Binance Chain Wallet
ffnbelfdoeiohenkjibnmadjiehjhajb
afbcbjpbpfadlkmhmclhkeeodmamcflc
Math Wallet
hnfanknocfeofbddgcijnmhnfnkdnaad
Coinbase Wallet
hpglfhgfnhbgpjdenjgmdgoeiappafln
Guarda
cjelfplplebdjjenllpjcblmjkfcffne
Jaxx Liberty
kncchdigobghenbbaddojjnnaogfppfj
iWallet
amkmjjmmflddogmhpjloimipbofnfjih
Wombat
nlbmnnijcnlegkjjpcfjclmcfggfefdm
MEW CX
ppdadbejkmjnefldpcdjhnkpbjkikoip
fnjhmkhhmkbjkkabndcnnogagogbneec
Ronin Wallet
cphhlgmgameodnhkjdmkpanlelnlohao
NeoLine
nhnkbkgjikgcigadomkphalanndcapjk
Clover Wallet
kpfopkelmapcoipemfendmdcghnegimn
Liquality Wallet
copjnifcecdedocejpaapepagaodgpbh
FreaksAxie Wallet
aiifbnbfobpmeekipheeijimdpnlpgpp
Terra Station
dmkamcknogkgcdfhhbddcghachkejeap
cnmamaachppnkjgnildpdmkaakejnhae
Auro Wallet
jojhfeoedkpkglbfimdfabpdfjaoolaf
Polymesh Wallet
flpiciilemghbmfalicajoolhkkenfel
ICONex
nknhiehlklippafakaeklbeglecifhad
Nabox Wallet
hcflpincpppdclinealmandijcmnkbgn
ookjlbkiijinhpmnjffcofjonbfbgaoc
Temple
mnfifefkajgofkcjkemidiaecocnkjeh
TezBox
hmeobnfnfcmdkdcmlblgagmfpfboieaf
XDefiWallet
dkdedlpgdmmkkfjabffeganieamfklkm
Cyano Wallet
nlgbhdfgdhgbiamfdfmbikcdghidoadd
cihmoadaighcejopammfbmddcmdekcje
LeafWallet
lodccjjbdhfakaekdiahmedfbieldgik
DAppPlay
bcopgchhojmggmffilplmbdicgaihlkp
Hycon Lite Client
klnaejjgbibmhlephnhpmaofohgkpgkd
ZilPay
aeachknmefphepccionboohckonoeemg
Coin98 Wallet
fnnegphlobjdpkhecapkijjdkgcjhkib
Harmony
pdadjkfkgcafgbceimcpbkalnfnepbnk
KardiaChain
acmacodkjbdgmoleebolmdjonilkdbch
bfnaelmomeimhlpmgjnjophhpkkoljpa
Phantom
cgeeodpfagjceefieflmdfphplkenlfk
EVER Wallet
imloifkgjagghnncjkhggdhalmcnfklk
Trezor Password Manager
aholpfdialjgjfhomihkjbmgjidlcdno
Exodus Web3
bhghoamapcdpbohphigoooaddinpkbai
Authenticator
gaedmjdfmmahhbjefcbgaolhhanlaolb
oeljdldpnmdbchonielidgobddffflal
EOS Authenticator
ilgcnhelpchnceeipipijaljkblbcobl
GAuth Authenticator
$$$$$$$$$$$$
_START$$$$$$$$$$$$
\User Data
Profile
System
Default
$$$$$$MASTERKEY_START$$$$$$
$$$$$$MASTERKEY_END$$$$$$
\Local Extension Settings
\Web Data
\Login Data
$$$$$DESKWALLETS_START$$$$$
$$$$$$WALLET_FILE_
$$$$$$
$$$$$WALLET_FILE_
_END$$$$$
$$$$$DESKWALLETS_END$$$$$
$$$$$$AUTOFILLS_START$$$$$$
$$$$$$AUTOFILLS_END$$$$$$
$$$$$$PASSWORDS_START$$$$$$
$$$$$$PASSWORDS_END$$$$$$
\Cookies
\Network\Cookies
_END$$$$$$$$$$$$
$$$$$$COOKIES_START$$$$$$
$$$$$$COOKIES_END$$$$$$
\..\..
\..\..\..
\Local State
\AppData\Roaming\
\AppData\Local\
$$$$$$WALLETS_START$$$$$$
$$$$$$WALLETS_END$$$$$$
$$$$$$CHROMIUM_START$$$$$$
$$$$$$CHROMIUM_END$$$$$$
$$$$$$GECKO_START$$$$$$
$$$$$$GECKO_END$$$$$$
$$$$$$USERINFO_START$$$$$$
$$$$$$USERINFO_END$$$$$$
$$$$$$MISC_START$$$$$$
$$$$$$MISC_END$$$$$$
$$$$$$FTP_START$$$$$$
$$$$$$FTP_END$$$$$$
$$$$$$STEAM_START$$$$$$
$$$$$$STEAM_END$$$$$$
$$$$$$FILEGRABBER_START$$$$$$
$$$$$$FILEGRABBER_END$$$$$$
$$$$$$INFO_START$$$$$$
$$$$$$INFO_END$$$$$$
\Mozilla\Firefox
\Waterfox
\K-Meleon
\Thunderbird
\Comodo\IceDragon
\8pecxstudios\Cyberfox
\NETGATE Technologies\BlackHaw
\Moonchild Productions\Pale Moon
$$$$$$GECKO_BROWSER_START$$$$$$
\Profiles
\formhistory.sqlite
\cookies.sqlite
$$$$$$GECKO_FILE_
_END$$$$$$
$$$$$$GECKO_BROWSER_END$$$$$$
User:
Screen Size:
Cores:
C:\Program Files (x86)\
C:\Program Files\
InstalledSoftware:
C:\Program Files (x86)\Steam
$$$$$STEAM_FILE_
_START$$$$$$
$$$$$$
\config\config.vdf
\config\loginusers.vdf
\FileZilla\recentservers.xml
\FileZilla\sitemanager.xml
\GHISLER\wcx_ftp.ini
$$$$$FTP_FILE_
$$$$$$TELEGRAM_START$$$$$$
\Telegram Desktop\tdata
D877F783D5D3EF8C
A7FDF864FBC10B77
C2B05980D9127787
F8806DD0C461824F
\key_datas
$$$$$$TELEGRAM_FILE_
$$$$$$TELEGRAM_END$$$$$$
$$$$$$FILEGRABBER_FILE_
$$$$$$WALLETCORE_START$$$$$$
Exodus
$$$$$$WALLETCORE_FILE_
$$$$$$WALLETCORE_END$$$$$$
wallet
$$$$$$WALLET_START_BINANCE$$$$$$
Binance\app-store.json
Wallets\Binance\app-store.json
$$$$$BINANCE_FILE_
$$$$$$WALLET_END_BINANCE$$$$$$
$$$$$$WALLET_START_EXODUS$$$$$$
\Exodus\exodus.wallet
\Exodus
$$$$$EXODUS_FILE_
market-history
$$$$$$WALLET_END_EXODUS$$$$$$
$$$$$$WALLET_START_ATOMIC$$$$$$
\atomic\Local Storage\leveldb
$$$$$ATOMIC_FILE_
$$$$$$WALLET_END_ATOMIC$$$$$$
$$$$$$WALLET_START_ARMORY$$$$$$
\Armory\
$$$$$ARMORY_FILE_
$$$$$$WALLET_END_ARMORY$$$$$$
$$$$$$WALLET_START_COINOMI$$$$$$
\Coinomi\Coinomi\wallets
$$$$$COINOMI_FILE_
$$$$$$WALLET_END_COINOMI$$$$$$
$$$$$$WALLET_START_ETHEREUM$$$$$$
\Ethereum\keystore\
$$$$$ETHEREUM_FILE_
$$$$$$WALLET_END_ETHEREUM$$$$$$
$$$$$$WALLET_START_ZCASH$$$$$$
\Zcash\
$$$$$ZCASH_FILE_
$$$$$$WALLET_END_ZCASH$$$$$$
$$$$$$WALLET_START_JAXX$$$$$$
\com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb\
$$$$$JAXX_FILE_
$$$$$$WALLET_END_JAXX
$$$$$$
User32.dll
Crypt32.dll
Shell32.dll
Ws2_32.dll
Ole32.dll
Kernel32.dll
CoTaskMemAlloc
CoTaskMemFree
wsprintfA
GlobalMemoryStatusEx
OutputDebugStringA
ExitProcess
VirtualAlloc
VirtualFree
SHGetFolderPathA
CryptUnprotectData
CryptStringToBinaryA
inet_pton
WSAStartup
WSACleanup
socket
listen
accept
connect
shutdown
getaddrinfo
freeaddrinfo
closesocket
ioctlsocket
GetSystemMetrics
EnumDisplayDevicesA
GetLastError
GetLogicalProcessorInformation
GetFileSize
GetTickCount
GetFileInformationByHandle
FileTimeToSystemTime
GetLocalTime
SystemTimeToFileTime
UnmapViewOfFile
CreateFileMappingA
MapViewOfFile
SetFilePointer
GetTempPathA
GetFileAttributesA
CopyFileA
FindFirstFileA
FindNextFileA
FindClose
GetFileSizeEx
CreateFileA
CloseHandle
ReadFile
WriteFile
.text$di
.text$mn
.rdata
.rdata$voltmd
.rdata$zzzdbg
.CRT$XCU
185.106.94.73$$
$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
browser_wallets$
binance$
davidgetspaid$$$$$$$$$$$$$$
wallets_core$
steam_conf$
TS$$$$$$$$$$$$$$$$$$$$$$$$$
5001$$$$$
telegram_conf$
GRABPATH_CONF$$$$$$$$$$$$$$$
$$$$$$$$$$$$$$$$$$$$$$$$$$$
ftp_conf$
desktop_wallets$
0!00070@0O0V0_0n0u0~0
1(1/181G1N1W1f1m1v1
2 2'202?2F2O2^2e2n2}2
2=4S4p4
5@5M5i5
9'9?9W9x9
>5>W>m>
151E1r1
2"2G2s2
3$3F3Z3w3
4%424N4v4
5@5j5w5
5-6I6u6
7'7O7a7k7u7~7
8"8'81868@8E8O8T8^8c8m8r8|8
9!9&90959?9D9N9S9]9b9l9q9{9
: :%:/:4:>:C:M:R:\:a:k:p:z:
;!;-;9;E;Q;];i;u;
<&<;<k<
=#=0=X=l=
>.>7>C>L>Y>b>n>w>
?#?0?9?E?N?[?d?p?y?
0%020;0G0P0]0f0r0{0
1(1@1L1d1p1
2$2<2H2`2
3*383G3Q3\3z3
4(474A4L4j4x4
5#5C5a5o5
6&606:6D6q6
7&8>8j8w8
9C9S9]9o9
:+:?:`:
<;=E=O=X=
> >E>]>
>-?G?`?m?
141=1N1[1|1
3-373J3l3
4#4<4I4e4~4
545A5Y5y5
6B6G6P6`6g6w6
7@7N7_7
8"8/8L8Z8
:%:5:q:
;/;?;I;Z;
< =<=L=_=o=
>.>;>S>i>y>
0 010Z0v0
0(1@1h1u1
2#262F2
3*3@3P3Z3k3
6606D6`6p6
7<7I7_7l7|7
838K8_8|8
:2:O:~:
;(;5;M;
< <3<C<P<n<
=#=D=V=o=
>>F>a>~>
?3?@?\?
10B0G0O0T0_0f0n0u0}0
1 1&1+10181=1B1J1O1T1_1d1i1q1v1{1
2%2*21262;2C2I2O2T2Y2a2f2k2s2x2}2
3#3(30363<3A3F3N3S3X3`3e3j3r3w3|3
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0
Antivirus Signature
Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Stealer.12!c
tehtris Clean
DrWeb Trojan.PWS.Steam.34994
MicroWorld-eScan Gen:Variant.Lazy.318722
FireEye Gen:Variant.Lazy.318722
CAT-QuickHeal TrojanPWS.Stealer
ALYac Gen:Variant.Lazy.318722
Cylance unsafe
Zillya Trojan.Agent.Win32.3262864
Sangfor Infostealer.Win32.Lazy.V3ih
K7AntiVirus Password-Stealer ( 0054d1a31 )
BitDefender Gen:Variant.Lazy.318722
K7GW Password-Stealer ( 0054d1a31 )
BitDefenderTheta Gen:NN.ZexaE.36132.cuW@aq4gM8d
VirIT Clean
Cyren W32/ABRisk.PWQI-0202
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/PSW.Agent.OGR
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky Trojan-PSW.Win32.Stealer.beiv
Alibaba TrojanPSW:Win32/Stealer.bd530967
NANO-Antivirus Virus.Win32.Gen.ccmw
ViRobot Trojan.Win.Z.Agent.34816.KT
Rising Stealer.Agent!8.C2 (TFE:4:yfGWnejx14N)
Sophos Mal/Generic-S
F-Secure Trojan.TR/Crypt.EPACK.Gen2
Baidu Clean
VIPRE Gen:Variant.Lazy.318722
TrendMicro TROJ_GEN.R002C0DDB23
McAfee-GW-Edition GenericRXVN-ON!16F2A3898CDC
Trapmine Clean
CMC Clean
Emsisoft Gen:Variant.Lazy.318722 (B)
Ikarus Trojan-PSW.Agent
GData Gen:Variant.Lazy.318722
Jiangmin Clean
Webroot W32.Stealer.beiv
Google Detected
Avira TR/Crypt.EPACK.Gen2
MAX malware (ai score=81)
Antiy-AVL Trojan[PSW]/Win32.Agent
Gridinsoft Trojan.Win32.Agent.cl
Xcitium Clean
Arcabit Trojan.Lazy.D4DD02
SUPERAntiSpyware Clean
ZoneAlarm Trojan-PSW.Win32.Stealer.beiv
Microsoft Trojan:Win32/Cryware.B
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win.Cryware.C5393521
Acronis Clean
McAfee GenericRXVN-ON!16F2A3898CDC
TACHYON Trojan-PWS/W32.InfoStealer.34816
DeepInstinct MALICIOUS
VBA32 BScope.TrojanPSW.Stealer
Malwarebytes Malware.AI.4208430519
Panda Trj/Chgt.AC
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DDB23
Tencent Win32.Trojan-QQPass.QQRob.Tnkl
Yandex Trojan.PWS.Agent!6GjEPYZxRfA
SentinelOne Clean
MaxSecure Trojan.Malware.202358588.susgen
Fortinet PossibleThreat.MU
AVG Win32:SwPatch [Wrm]
Avast Win32:SwPatch [Wrm]
No IRMA results available.