Static | ZeroBOX

PE Compile Time

2023-04-10 10:27:11

PE Imphash

1619c2fb0abae4a066cd55f93e5cd107

PEiD Signatures

NsPack 2.9 -> North Star

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
0x00001000 0x000dd000 0x00000000 0.0
0x000de000 0x0004a000 0x00049aa5 7.99862633522
0x00128000 0x00000de5 0x00000000 0.0

Imports

Library KERNEL32.DLL:
0x4de09c LoadLibraryA
0x4de0a0 GetProcAddress
0x4de0a4 VirtualProtect
0x4de0a8 VirtualAlloc
0x4de0ac VirtualFree
0x4de0b0 ExitProcess
Library RASAPI32.DLL:
0x4de0b8 RasHangUpA
Library USER32.DLL:
0x4de0c0 GetCursorPos
Library GDI32.DLL:
Library WINMM.DLL:
Library WINSPOOL.DRV:
0x4de0d8 ClosePrinter
Library ADVAPI32.DLL:
0x4de0e0 RegCreateKeyExA
Library SHELL32.DLL:
0x4de0e8 ShellExecuteA
Library OLE32.DLL:
0x4de0f0 CLSIDFromString
Library OLEAUT32.DLL:
0x4de0f8 UnRegisterTypeLib
Library COMCTL32.DLL:
0x4de100 None
Library WS2_32.DLL:
0x4de108 closesocket
Library WININET.DLL:
0x4de110 HttpQueryInfoA
Library COMDLG32.DLL:
0x4de118 ChooseColorA

!This program cannot be run in DOS mode.
JOX4@O
JOX4AO0
JORichn
KERNEL32.DLL
RASAPI32.DLL
USER32.DLL
GDI32.DLL
WINMM.DLL
WINSPOOL.DRV
ADVAPI32.DLL
SHELL32.DLL
OLE32.DLL
OLEAUT32.DLL
COMCTL32.DLL
WS2_32.DLL
WININET.DLL
COMDLG32.DLL
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ExitProcess
RasHangUpA
GetCursorPos
GetSystemPaletteEntries
waveOutUnprepareHeader
ClosePrinter
RegCreateKeyExA
ShellExecuteA
CLSIDFromString
HttpQueryInfoA
ChooseColorA
y<w:~s
U.X-.]_
$e:@3I
|)];;sHo
!gAF9R
:*q|@w
@BfVVl
>dogt
X4jr[m#
;misn2*
XwT{?G>
ztae!c
,{M!q>
XJ>bN\
/G9w3z
E\}8e=
3,[Ur\
v_sy5O
xYz"Q9
bZM53p
jGJ0#h
0-JJ4%^
->'qVC
:'B.!D
5x5p@tM
9[qiaR{
Pi,?1i=
;5$yN#
4r&.Bl{
{g{S~u83>
2&I@.
VjStBw
% vt3\rD
z5Ci<o
8/GJoC
7xqloJ
eCaAmtT
vst9K`
0"dIG#
#~.bNB
SrLPZl
h7?"$JO
{p_7Xzm
T=^V[:!l
ET|7h
{NHS:a
6L``f
I})mCPz_
rO4*5L
Y4cc16
'W<+ mhG
yyRF +
~L\GrN
TZ0KZ"o
X,Ylez
F38( &
tkm!?*
xzLl*e
]Mr]JWz6
]QQ#X(
qgy.H\
;E yEH
/&bXc8
QPbng>
~U=$'F
Yv)=(&
w"e&C,
%1$1x^-
Er3!Rv
u,KzQb
M+-kR<.
(y:2oB
VTi,`
~jo.Y;L
lvr$$5
>YH43^DQ
(jsMuF
;sxm;"&
vn*jlh*
1X2x>jJ
0"&cJ(
46MnSqJ
9zH!>X\
E[a6xw
"SX +A
$RPOE
h:a,NA
(jbNH{
=Oc3yU;TJ:
,*j)C&
@%yuN`
)Q\_<!
9/J&B%)i
S|0A-!V
s3;nc@
j?w,U?
]v=>,w#
:NLCJp
&nG7Fct
a[Z:+fO
$R7OT|
B:=X:>
I-f&"X
pBJ&+*L3A%"
*gE6Zn
DW9#L4
gx, xf
t+q.x0
t'c(87N
'H$r%h
SSa!"63
#e6L]
vd|>q
5wRw"F
SYJx2[2
]G[RYf
r2b;No
=+{kOV;
C! lg:
{I~&v_7:
q/XkVQ
ysEZj#
(9=DgrV
X(oElF9+
;xT8DQ
IjL3\U
{c=EwGvy
1F{|+
|5?T|4
YG|<da0z
pZ7@+H
oDOB\
tE]U\D
4AI0v;
7/N!D E
y}`A1fl
R>qby0
XHxCt"
6jAKp)
`5`.|
'E1WzH;zo
^G[PWj
M#__}9
tQ@N~i
&Cxl0UK
p5n~=e
"yxL*Gl
=[~Zt(
`lJX]A
i1<X ^
sfuy7D
UwP2xa
ReW=f?=
=+qy@y
^gq2TaC
t}bwc^
%nt(I
s|vu[:#5
TZ2;0fx
X8fLVm
n2M%h}D
6V(a|$
<^tU40C
?:gBdTM
y=B?dL
e0z|mU
oXg{|q
Y#Bpr*
f ,@Jb
U.GXY]
4Fr='Av
l5q:},
4<8 YBQ`
ndE!<u
;;T(9g
s%@fM4
0^GlTI
w!sAcK
y(]kl`g
5@kkaa
|WeB,X
/t^\\3
<"V?b6
XFTO#WNm
Gb~}%&>
;FE?2G9
%\ <Q$/
_GORS/
?{jLde}$#
'%y6Ct
TO]zhkm\
+ EEwS
#q;n2h
?+w]rg
>Lb\fT?
l >y8$gv
Zx6LX
cxRw?H-
.b;\m
!++ke/z
U{>^qE
7O>Rb]%
(0(sy4
Rtc^CYa
^qR(i~&T
#a\aqI
yXNrC2ZV
v*~MZh
rpAQ?6
3gU=rQ
W}^_1Lc
dJ;Ku
wix//
(/mT<\
(Yp$|1a1
t:|uA_
A9W}Z}
t-'a59
}jx01y
N\EBNp
62YWyK
_WFOii
$IT~SuH
fZ]{(}
l'?Uy$"
|~qj-A
aZ"]G.f
AS/9s.:
d`RVmW
lx%fdB
8ti{S
`;7Qr#
a\tMf:q
SlSx,v
}5F$|\
.||A~,
WX1fu`5
FDk]_G
j1&X?z
>B*w3-.-
&*`vr4
lmV2^on9
t;6bkt
;=-wL!
;(CyQ5
b}+Y"a
u-j22avVo
kI%2wA
},7BhDR
}?!&@G
v{riur
kn|(-Pkh
'@f,D1nH
Y'0t|"
Dk_9}+ce"
q2{%`%
so>@!
]6v#R[\
RhP3<"
R0[VjP
]? M<c
rAJWCG
Bh-~w@
M44w]
Ra 3u+>N
T_'xT.l
t~&~^%G
Y85ZPL!
nC/;]3
/EpZa
(+jWX:Li
$NZ/\E
-C:e/!
zmzM*]
qm9Lsp4s
rWj/)
6YjZmF
7n)^EX
r8\RlF
|[\4NyJ
i0>C_>
m<tQ#I
)KuMR*96
YVX]q-
B$$_Uf
UkQ%x[N
NHSt]:
fF*SAA
RHR?%T
3;[7}a5
bEw`T2
>4J>Q p
ugpb{8$
{LmE)J
E/3foN
UY7?[{
U9XKJXm
^CWE!T
" #lYH
}.PUNZ
lRmZHQ
LTLL-
,<>3@<
FQQ]Xe
<wE$hF
J/a)5gh
wh1B{n
+IuNa!0
:K7UOp
&pMt#1m
wjyZAq
X%:@#hr
f,?;n(
bDTRt
$-.z/;
km'xLs
c'^@cC
xXklQ6
CFUp4R
7%_=Cf
njUE+:
|6m-_]
u4|MwS
PPACb#
!prCr;
n6Q]mr
2'H@sV
p^eKM.
hXl_lZ
1#T jI
0']!>DBU
Sy]Wf~
'_8="5
3~2Naot
kFT2l1TQ
O>*<'D
5$fucO[
tcqEje
d<p3py
3is[:)
tv<[L?
E&B(A-
;;BM\.~(%
o{$'>ElIo
:%X#]f@
HI&Um9
8=31|r
wlHY$"
vFyJ+5j'
j4\uG3
X=t}<*
4&KtVB
_A5lQYD
$@aQA[
0>;+(vG
q2+j&GRr
4cIT3M
Fs5GdjQ
tPo1um
[ve,\L
ZrYr'd
P,B")%
fSG<xO
u=C;8
i`g:h f
E>Sa;=u
u{&&t-T
2VU@XA4
}eX!K>
?u=[|T
r88@k+?0
l 1l)Tr
p$tf8e>Y
vvXV%:-
?K4O}\
)A>@?|_
YW/wO2
pik.o_
J4q%Ah
22mi'M
gO1`R[
$h'FyK
K6u6>nS
:dn#,q
{E&~UJ
H`nD}Y\
G}WV45
(DCpfg9
07"*1t
m.Qd}0
E,6+4H
Q9XWm4
/x.7$V
P[L:^<
a;5gcj
R1>[2}
6UsfCbZ
$1N@eP$'
sM5M'p
[J3#Y~
O{-&R4C
j[\Zy(|
u!d@%o
T`zi]J
HQ1YiO
(~C}S
XAnEf9RI5
EmooW1
*3aBug
]O&EOz0
G}2v}
dZ7x9+
wFSg@/
v^%pwv
*Us~c3
iyV,SF
rMnV-4
3}Nlrj
7!gQ\m
"oae0VT
M4y"dS|
:-!Wq?
Ld7\oP
u1?Y|xH3
N+~`}{
_!gY<v"
/<74"/
Rd^&#ck8MO
l-{|R_$aM
}5:U33IzI
n`#]urA
G@gZXm
ES2ku)F
dq J0$
]O3Pyyg
Xu-ccn
0PMW38*=
4j\T:IR
:"2"H
FI"inQ
EzN$U
Y]sBs8G
o&.Rao
zstwQ
q,QTG,
S%(2`q
0Qb3Z
>m*s&T&
v97Bi_R
!3dUCF/o
'i%882
Y^mBfU
kd(W!"
].?hhB
xyyzIV
RS'(JK=
tzE[*<
?NFJk.E
zF[;*vX
eOLi6a
3BX>SX
<R89l\
u3rI=*:$
?aH#5CA
cSWYp<
W|(ne>-
aE-u^:L
K_;hf5u
.>aCpDe
{2YFv"e_
5vuu%~
+?}jF2
,Xtn+x(U
%)Q*]_
GzF6ir
*CnsW&5
yuwYz(k
Hs5@I~s.{
3'5z/bQ
'UpVKn
LcJ/y`
QX37|W
+|(43v
|ncv)sx
wF9G|ZdVu
@X?n>7
`knp"I$;
/B`f\2
h9vOw,
v?xD9n
${MrL(
ey?Nv)
7ytHGqH
Ufj#:eY)
d;2{1.a
7.T+/,d
+[En#o
M"|wIp
s]?JVgy
2g?X"f_l
c=]q6
B(%[1v
3K9`K#5
B#sBaO
oWa[%|
[5d1c[
w=wr#T
lpoJN*
9C+}R6}p
RU}67
XG81#_e
2tw_0{g
.&BBF
7S0?Yk
$m,\P1y
F.F/7'
YJY;30S
~R2&-C
UgdV3LN
?e[ *u
|n@GI*
\/?GO=[
:!)Kyk
Mhnn!jo
j!$Emy
!vfyQb~
m(kxpR
j1cqN~
L3*bdK
4Or7!=
mpP(@>m
.X0RynaP
Xk):!|6,s
)]-54X
)n*+Zd
/1[-;V~
Antivirus Signature
Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Bjlog.lzuS
tehtris Clean
DrWeb Clean
MicroWorld-eScan Gen:Variant.Graftor.945714
ClamAV Clean
FireEye Generic.mg.95c5281f68d37a16
CAT-QuickHeal Risktool.Flystudio.17324
McAfee Artemis!95C5281F68D3
Cylance unsafe
VIPRE Gen:Variant.Graftor.945714
Sangfor Trojan.Win32.Siscos.Vhvh
CrowdStrike win/malicious_confidence_70% (W)
BitDefender Gen:Variant.Graftor.945714
K7GW Trojan ( 005257651 )
K7AntiVirus Trojan ( 005257651 )
BitDefenderTheta Gen:NN.ZexaF.36164.smGda8pHmam
VirIT Clean
Cyren W32/Downloader.AT.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.Siscos.aceq
Alibaba Trojan:Win32/Siscos.29afcbae
NANO-Antivirus Trojan.Win32.TrjGen.jvhiil
ViRobot Trojan.Win.Z.Graftor.302757
Rising Trojan.MalCert!1.DEC0 (CLOUD)
Sophos Generic Reputation PUA (PUA)
F-Secure Heuristic.HEUR/AGEN.1331417
Baidu Clean
Zillya Virus.Hupigon.Win32.5
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Gen:Variant.Graftor.945714 (B)
Ikarus Trojan.Crypt
GData Gen:Variant.Graftor.945714
Jiangmin Clean
Webroot Clean
Avira HEUR/AGEN.1331417
MAX malware (ai score=84)
Antiy-AVL Trojan/Win32.FlyStudio.a
Gridinsoft Pack.Win32.Gen.bot!ep-44128
Xcitium Backdoor.Win32.Popwin.~IQ@ogvrk
Arcabit Trojan.Graftor.DE6E32
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win32.Siscos.aceq
Microsoft Trojan:Win32/Tiggre!rfn
Google Detected
AhnLab-V3 Trojan/Win.Generic.C5229540
Acronis suspicious
VBA32 Clean
ALYac Gen:Variant.Graftor.945714
TACHYON Clean
DeepInstinct MALICIOUS
Malwarebytes Clean
Panda Trj/Chgt.AC
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0CDJ23
Tencent Win32.Trojan.Siscos.Mqil
Yandex Packed/NSPack
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet Riskware/Application
AVG Win32:TrojanX-gen [Trj]
Avast Win32:TrojanX-gen [Trj]
No IRMA results available.