Static | ZeroBOX

PE Compile Time

2023-05-19 19:17:48

PE Imphash

d876512d32d4e10a69f2baae7904c814

PEiD Signatures

UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00073000 0x00000000 0.0
UPX1 0x00074000 0x00028000 0x00027c00 7.92204101147
.rsrc 0x0009c000 0x00002000 0x00001a00 5.04998400466

Resources

Name Offset Size Language Sub-language File type
RT_BITMAP 0x0003b638 0x000004e8 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED empty
RT_ICON 0x000951b0 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x000951b0 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x000951b0 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x000951b0 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x000951b0 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x000951b0 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x000951b0 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x000951b0 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x000951b0 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x000951b0 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x000951b0 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_ICON 0x000951b0 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00095618 0x000000a0 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_GROUP_ICON 0x00095618 0x000000a0 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_VERSION 0x0009d480 0x00000274 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MANIFEST 0x0009d6f8 0x00000188 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.DLL:
0x49d8d0 LoadLibraryA
0x49d8d4 ExitProcess
0x49d8d8 GetProcAddress
0x49d8dc VirtualProtect
Library ole32.dll:
0x49d8e4 CoTaskMemAlloc
Library OLEAUT32.dll:
0x49d8ec VariantClear

!This program cannot be run in DOS mode.
)stp)z&9`x
&s@)s`
wX)sLH.
s$ 2sC
)sly&9
T#h7(K,
(\h@]C
`(|h@y*
uC[sAQr?
A0ln2)
C,;|sr
'y.a\G;}
!S2*Tb
Q4382D
9T?H(p
7}b;56u
;0v91t
>=-0_6
U"|R]tL;
PBO@!q"
NhDG`@
Pn`- _A)
|^XjXXi
H# v'Q
"hIed
twWSolS8
=X]_F%
_8H*-F
@PL88&
L%+xkm
>I<_Do
$9t.V18
(QiCF
,eOd"he
<8P<eH.Ch@
^]{_"*K
6jA[jZZ+
"6>Y{8
bD>\V,
jPp_zi:
yTCdTd\
5ineI\sk
5ntel.
96v|Qq$
!u{ zJ
F ,n00
|^0f@nPv`
t1^MOC
u4#*VH<F
Pxp^e@
T0@P`_
[,]S[;
|}CNS-C
LtQ;-Q
k-/w.L
zBSz%vF
M8xf~U.j"
t(%N D
%{Y^{J
t'@|-r
#1lA<A
OBG3>P
.Qp?Yj
`087rj
qvmlc]tA
GOiy?:
WC[RoHt
w_tqa=
>C: u,&
2MGmYQ
vJ3,tu*4|
tu4Y=.+
j;XJxt-Z
b{en/i
fdB3q4
Sk6@-W
B(*G?0
(bW#Yc
ktX:*]
uoxS8d
d$b!uA
L(,@PR2D
d`3xLE
$UHYYH
PG|c}l
H|L`tY
-hR)ob
:Xk&l?
C;%42<
0iD8oYlc
2P# UZ
<rt!<w*
Qm&$Vt
45,Uc6
ad( !k
zJnsZgn:iw:
4fdHLa
pllu %
L!p``N
-M+0r<
LA-(V&
R=1tK=3
)#tID2
w5S]gi
D9,aMeau
&|9/u1
3Y#ddL
-`W.,R;\Is/S8
mNq<d/v|
o8AWf<
;xX9^\
;V\uYCn
8&]u,W\R
ZBJTc0
!225<
`u-FHQ
S8*,+A]
V"[ )((
+u;,#M
F&+{s;
ZZ!ux9}
Hu{"yw
_xPPPH
dZx[HW@
w/PV9<
<Hp#uP
#{"|$e
d-XJ)|
#Qy^7C
pFgF]m
8Bt G)u
KalOmK
Vm",jD
&2@R`vy
y~bad allocationN.
<+++bb<
rgument'
seeko error
direct yfssageVize
+netw0kDown
tun"ach
ttol opwA{
n^evi
|'t4mcour
hdr17f
~nn\ed7
wH ni'
sGjmb$
v(pveG2u
H`8nwv|
@dAe?f
jMkFl7<
<sO&Bt
w:{I~6<
usex]piQ
Hn#_`qu#
60+Pyl~
S%Ex7O
+.jho|
bz`O3"
E&S(ByHandl
ep3CS4
0123456789
fghijklm^pq
nvwxyl
($0%8&
X+`,h-p/
9r@4L5X6d7
#Gp8|9
I$J0K<LG
9HNTO`PlR
9r$;<kH
T8rv`D
g>/ds
7g9rV
w;9;r
`['"r
9r65'8x
#GpF|p
nnpp_
ooiOs?
FRrcyp
.vE>tH
R?-BNnQ
GwNM>6mo
fFhI+
/wyqy.sY
O/s[u
VKgssa*n
w;vCGK/n
]LGAUp
7/B_P/Q}
Bnok?jj
p_/_yW
t>BJCM:F
WrraNe
w$ngtOe|@
<@DHLPy
yTX\`l
y,<@HX
aN'std
lrgeab
' ligz
pyQ`ud/
dyOqXE
~ "" WT
''B9Cl
rSU1
 !"#$%&'()*
:;<=>?@
`?{|}~
TABCDEFGHIJKLMNO
?powM`H
Y/&U6_K
4HXlt<
< 0DTh
No4Dec_
PMM/dd
,HH:mm:
IPM/^d
:/lvci
gXhHo
ApisANSI
Toeg+B[
u<eM(ho
UTF-.,
16LEUNICODE
p#t$x%0
0_c_hy
w@or?y0
_Pb'n6
/\CpZk
yGpP^B
CHDTF*#
C-{Xm5
jca_?+
>Gdw kam
vHooOu
.EG7c2#
#g(r014x6
#g4VX
p65$|W _
#'r@U9/
vr^IO4
sobQo'''A0 /
]vQ<)8
|)P!?Ua0
?x+s7
k>? #J
@>O=o;:r;
8o764
vr31o0.
-+o*)'
Nn'&o$#!;
{z?yy'
xwvovuNn''tt?sr
@poor;99onm?l
vrrlkjoj
fedd/no
@a?`NNNN__^]
o]\[Z999
?ZYXWmrr;W/VU
QoPPONNNNn?MMLK
NJoJIH
?5Od%
?|I7Z#
/pg)([|X>H1
w4w~U`KF
AxuN}*
&?~YK|
CqTR;?
?#%X.y
\0^]%>
?5Wg4p
~%S#[k
~HNl4!'
*G/l\
J/R]` !
T2M0l
schooH
risug2k
[vvviNthGln
ve<tw`N
.Qwatwb2
coS3aN
'z,qhj
vW_g|`
_eLn'Dim
ELECT * FROM MSAc
*OC:\1.tx
s\lwx\S
9\ret N
GCTvb_
CRT$XCAW'B
ro"f{'iN
NDB<i'
0`f&bL
FP Zr
!d"n#x$G
67@8J99r
T:^;h<r=#G
#G0P:QDR
NSXTbUlV
#*i4j>k
9rHlRm\nfo
#Gppzq
W@@lTZ
NL=?MW
N$[X?\O<
)'G'Gp\
Rr~ (c)
Ter, lg
.LtdJALL RIGHTS
ESERVED.
di.?Ai
z?@0@@G
Grgic_
8_of_?Q
@DU"6_
Nr4N]Z
f%`n
%Oc0*]>
MEQR!YWREf
5=DPNRVZPIl3
n@=CEPPQI
E{B@63^gw
oL<:434;
OBAAw^
v;8\4H
\NHHLUr
pBhi?x
>>.'(v}}
=4--,*%$)vSL
<9:kxS
xL>HSn
>@?>6.&1U
Z>3-0=T
:1+)SKRPj<%!"'(Y
&]>Prr
#6c~{~~
{snjP:,]
pnfH5/bXrppiOD3_
O .a-w/
OXXIo
K?/8JW
Z7':$]
G'65[S]A
T[[m%O
OK+n\&'
V[rW?o
G?7vcp%
k!w/Y'
%,s74w
CLZt?g
%\!<?I.
-G>WP]
H]@*`
?fO`Io
GCV'Fh
ZH7R6K%
.,dKGV
0Z/>F_
?#p!q
/)q#1G
^C'B/A
r%W2M=,=
F~7 UC
9gM'IB
UKSHra
YqK!O^.
YBJ+dS
8BH%>@
K$)92?9
"XoR c@
A%| O8
*J?J?$
}A;P0XQ
6,*NpG
<'PRQ'6
yo1qGT/
^>'<yv(Vf
hAG@&(
%WrdC.e
'dd*Lx
e]A+oV
>Ft#\i
z$`PTg
WGt+)7V
|F4oCW
Dw0 L X
f8s>^
q:)M66?
8C|@,c\I
S&'_eC
%m{7i
[q%MS4
RaiseE
ndOfFil
W\fNso
~i5nStd&h
mm|L"e!A
XharToMul
Byt(EPp
3XAMZu
wUnhmd
mCObdGM,J.6o
<4G;#l
CJ$#9
p*:>$L
ER"!m&'!{
&$4C-_@
Hh$)Q
4/1(.00
aKI7mS
U '<,".4,4-E28p
( $< ,<P
p;,yCD
XPTPSW
#Mw5=
#Oh+.
Nj"%e
#K[28
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
KERNEL32.DLL
ole32.dll
OLEAUT32.dll
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
CoTaskMemAlloc
9(:,:4:
VS_VERSION_INFO
StringFileInfo
080404b0
CompanyName
FileDescription
FileVersion
1.0.0.1
InternalName
loader.exe
LegalCopyright
Copyright (C) 2023
OriginalFilename
ProductName
ProductVersion
1.0.0.1
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Gen:Variant.Symmi.64868
Cylance unsafe
VIPRE Gen:Variant.Symmi.64868
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason malicious.2802ca
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (moderate confidence)
ESET-NOD32 a variant of Win32/Kryptik.HTOY
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Gen:Variant.Symmi.64868
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Gen:Variant.Symmi.64868
Tencent Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Trojan.cc
Trapmine malicious.high.ml.score
FireEye Generic.mg.89f34702802ca7e9
Emsisoft Gen:Variant.Symmi.64868 (B)
SentinelOne Clean
Jiangmin Trojan.Generic.hchwh
Webroot Clean
Avira Clean
MAX malware (ai score=88)
Antiy-AVL Trojan/Win32.Agentb
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Symmi.DFD64
ViRobot Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Win32.Trojan.PSE.P3253E
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!89F34702802C
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes Malware.Heuristic.1003
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!8.8 (CLOUD)
Yandex Trojan.Kryptik!umEfyHV44Rk
Ikarus Win32.Outbreak
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.36196.kmKfa0@xDlpj
AVG CrypterX-gen [Trj]
Avast CrypterX-gen [Trj]
CrowdStrike win/malicious_confidence_70% (W)
No IRMA results available.