Static | ZeroBOX

PE Compile Time

2022-03-09 10:25:10

PDB Path

C:\DLL\Dll\x64\Release\Dll.pdb

PE Imphash

cfaa2e70e3ba0118bca792fff0afedf3

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000b060 0x0000b200 6.41720625575
.rdata 0x0000d000 0x00008d96 0x00008e00 4.69842002253
.data 0x00016000 0x00001bb0 0x00000a00 1.93866999051
.pdata 0x00018000 0x00000d38 0x00000e00 4.64325044039
_RDATA 0x00019000 0x000000fc 0x00000200 1.96761607281
.rsrc 0x0001a000 0x000000f8 0x00000200 2.52495999013
.reloc 0x0001b000 0x00000638 0x00000800 4.79803548967

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0001a060 0x00000091 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library SHELL32.dll:
0x18000d218 ShellExecuteA
Library urlmon.dll:
0x18000d228 URLDownloadToFileA
Library KERNEL32.dll:
0x18000d000 HeapFree
0x18000d008 WriteConsoleW
0x18000d010 CloseHandle
0x18000d018 CreateFileW
0x18000d020 RtlCaptureContext
0x18000d028 RtlLookupFunctionEntry
0x18000d030 RtlVirtualUnwind
0x18000d038 UnhandledExceptionFilter
0x18000d048 GetCurrentProcess
0x18000d050 TerminateProcess
0x18000d060 QueryPerformanceCounter
0x18000d068 GetCurrentProcessId
0x18000d070 GetCurrentThreadId
0x18000d078 GetSystemTimeAsFileTime
0x18000d080 InitializeSListHead
0x18000d088 IsDebuggerPresent
0x18000d090 GetStartupInfoW
0x18000d098 GetModuleHandleW
0x18000d0a0 RtlUnwindEx
0x18000d0a8 InterlockedFlushSList
0x18000d0b0 GetLastError
0x18000d0b8 SetLastError
0x18000d0c0 EnterCriticalSection
0x18000d0c8 LeaveCriticalSection
0x18000d0d0 DeleteCriticalSection
0x18000d0e0 TlsAlloc
0x18000d0e8 TlsGetValue
0x18000d0f0 TlsSetValue
0x18000d0f8 TlsFree
0x18000d100 FreeLibrary
0x18000d108 GetProcAddress
0x18000d110 LoadLibraryExW
0x18000d118 RaiseException
0x18000d120 ExitProcess
0x18000d128 GetModuleHandleExW
0x18000d130 GetModuleFileNameW
0x18000d138 HeapAlloc
0x18000d140 FindClose
0x18000d148 FindFirstFileExW
0x18000d150 FindNextFileW
0x18000d158 IsValidCodePage
0x18000d160 GetACP
0x18000d168 GetOEMCP
0x18000d170 GetCPInfo
0x18000d178 GetCommandLineA
0x18000d180 GetCommandLineW
0x18000d188 MultiByteToWideChar
0x18000d190 WideCharToMultiByte
0x18000d198 GetEnvironmentStringsW
0x18000d1a0 FreeEnvironmentStringsW
0x18000d1a8 LCMapStringW
0x18000d1b0 GetProcessHeap
0x18000d1b8 GetStdHandle
0x18000d1c0 GetFileType
0x18000d1c8 GetStringTypeW
0x18000d1d0 HeapSize
0x18000d1d8 HeapReAlloc
0x18000d1e0 SetStdHandle
0x18000d1e8 FlushFileBuffers
0x18000d1f0 WriteFile
0x18000d1f8 GetConsoleOutputCP
0x18000d200 GetConsoleMode
0x18000d208 SetFilePointerEx

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@_RDATA
@.rsrc
@.reloc
D$@1.ccH
D$D/4453
D$H.jpg
|$ AVH
H3E H3E
WATAUAVAWH
A_A^A]A\_
ffffff
fffffff
WATAUAVAWH
A_A^A]A\_
u3HcH<H
x ATAVAWH
A_A^A\
UVWAVAWH
0A_A^_^]
WAVAWH
0A_A^_
WAVAWH
A_A^_
u"8Z(t
uF8Z(t
vC8_(t
u"8Z(t
uF8Z(t
vB8_(t
UVWATAUAVAWH
`A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H97u+A
\$ UVWATAUAVAWH
@8|$Ht
@8|$Ht
@8|$Ht
D$XD9x
@8|$ht
@8|$ht
@8|$ht
A_A^A]A\_^]
u"8Z(t
UVWATAUAVAWH
L$&8\$&t,8Y
@A_A^A]A\_^]
fD94Fu
WATAUAVAWH
A_A^A]A\_
fD9t$b
\$ VWATAUAVH
D!l$xA
@A^A]A\_^
L$ VWAVH
@8l$Ht
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
@UATAUAVAWH
e0A_A^A]A\]
@UATAUAVAWH
H!T$0D
ue!T$(H!T$
A_A^A]A\]
WAVAWH
A_A^_
UVWATAUAVAWH
D8\0>t
L$@D8]
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
\$ UVWATAUAVAWH
H!D$ H
`A_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
UVWAVAWH
@A_A^_^]
ffffff
fffffff
USVWAVH
A^_^[]
LcA<E3
u HcA<H
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CorExitProcess
AreFileApisANSI
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
C:\Windows\Shell_Open.exe
http://Down.ftp2
C:\DLL\Dll\x64\Release\Dll.pdb
.text$mn
.text$mn$00
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.idata$2
.idata$3
.idata$4
.idata$6
.pdata
_RDATA
.rsrc$01
.rsrc$02
ShellExecuteA
SHELL32.dll
URLDownloadToFileA
urlmon.dll
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
RtlUnwindEx
InterlockedFlushSList
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RaiseException
ExitProcess
GetModuleHandleExW
GetModuleFileNameW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
LCMapStringW
GetProcessHeap
GetStdHandle
GetFileType
GetStringTypeW
HeapSize
HeapReAlloc
SetStdHandle
FlushFileBuffers
WriteFile
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
KERNEL32.dll
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
</assembly>
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Agent.Y!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Tedy.236313
ClamAV Clean
FireEye Gen:Variant.Tedy.236313
CAT-QuickHeal TrojanDownloader.Agent
McAfee Artemis!679795D1F387
Cylance Clean
Zillya Downloader.Agent.Win32.501138
Sangfor Downloader.Win32.Small.Vd2v
K7AntiVirus Riskware ( 00584baa1 )
Alibaba Trojan:Win32/Malagent.6c5a7bbc
K7GW Riskware ( 00584baa1 )
Arcabit Trojan.Tedy.D39B19
BitDefenderTheta Clean
VirIT Clean
Cyren W64/ABRisk.MNKJ-3712
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Generik.FUXZVC
APEX Clean
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan-Downloader.Win32.Agent
BitDefender Gen:Variant.Tedy.236313
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Avast Win64:Malware-gen
Tencent Win32.Trojan.Dldr.Jtgl
TACHYON Clean
Sophos Clean
Baidu Clean
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.Tedy.236313
TrendMicro TROJ_GEN.R002C0DKB22
McAfee-GW-Edition BehavesLike.Win64.Generic.nm
Trapmine suspicious.low.ml.score
CMC Clean
Emsisoft Gen:Variant.Tedy.236313 (B)
SentinelOne Clean
Jiangmin Clean
Webroot W32.Trojan.GenKD
Avira TR/Dldr.Small.tvnxz
Antiy-AVL Trojan[Downloader]/Win32.Small
Gridinsoft Malware.Win64.Downloader.cc
Xcitium Clean
Microsoft Trojan:Win32/Malagent!MSR
ViRobot Trojan.Win32.Z.Agent.92160.BMC
ZoneAlarm Clean
GData Gen:Variant.Tedy.236313
Google Detected
AhnLab-V3 Clean
Acronis suspicious
VBA32 Clean
ALYac Gen:Variant.Tedy.236313
MAX malware (ai score=87)
Malwarebytes Malware.AI.4235280156
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DKB22
Rising Downloader.Small!8.B41 (CLOUD)
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.7520.susgen
Fortinet W32/PossibleThreat
AVG Win64:Malware-gen
Panda Trj/CI.A
No IRMA results available.