Static | ZeroBOX

PE Compile Time

2023-06-13 00:05:51

PE Imphash

4c84c8ba374cef8f76250c04631b14fd

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000071c6 0x00007200 6.09580329005
.rdata 0x00009000 0x000017bc 0x00001800 4.68792918437
.data 0x0000b000 0x00000269 0x00000200 1.82566302593
.pdata 0x0000c000 0x0000036c 0x00000400 3.74231680123
.00cfg 0x0000d000 0x00000010 0x00000200 0.151271325305
.tls 0x0000e000 0x00000010 0x00000200 0.0
.reloc 0x0000f000 0x0000009c 0x00000200 1.88930595169

Imports

Library KERNEL32.dll:
0x140009ab8 CloseHandle
0x140009ac0 CreatePipe
0x140009ac8 DeleteCriticalSection
0x140009ad0 EnterCriticalSection
0x140009ad8 ExitProcess
0x140009ae0 FreeLibrary
0x140009ae8 GetLastError
0x140009af0 GetModuleHandleA
0x140009af8 GetNativeSystemInfo
0x140009b00 GetStartupInfoA
0x140009b08 GetTickCount
0x140009b18 K32GetModuleInformation
0x140009b20 LeaveCriticalSection
0x140009b28 LocalAlloc
0x140009b30 LocalFree
0x140009b38 LocalReAlloc
0x140009b40 ReadFile
0x140009b50 Sleep
0x140009b58 TlsGetValue
0x140009b60 VirtualProtect
0x140009b68 VirtualQuery
0x140009b70 __C_specific_handler
0x140009b78 lstrcmpiW
0x140009b80 lstrlenW
Library WINHTTP.dll:
0x140009b90 WinHttpSetOption
Library api-ms-win-crt-convert-l1-1-0.dll:
0x140009ba0 mbstowcs
Library api-ms-win-crt-heap-l1-1-0.dll:
0x140009bb0 _set_new_mode
0x140009bb8 calloc
0x140009bc0 free
0x140009bc8 malloc
Library api-ms-win-crt-private-l1-1-0.dll:
0x140009bd8 memcpy
0x140009be0 strchr
Library api-ms-win-crt-runtime-l1-1-0.dll:
0x140009bf0 __p___argc
0x140009bf8 __p___argv
0x140009c00 __p___wargv
0x140009c08 __p__acmdln
0x140009c10 _cexit
0x140009c18 _configure_narrow_argv
0x140009c20 _configure_wide_argv
0x140009c28 _crt_at_quick_exit
0x140009c30 _crt_atexit
0x140009c38 _errno
0x140009c40 _exit
0x140009c58 _initterm
0x140009c60 _set_app_type
0x140009c70 abort
0x140009c78 exit
0x140009c80 signal
Library api-ms-win-crt-stdio-l1-1-0.dll:
0x140009c90 __acrt_iob_func
0x140009c98 __p__commode
0x140009ca0 __p__fmode
0x140009ca8 __stdio_common_vfprintf
0x140009cb0 __stdio_common_vfwprintf
0x140009cb8 fwrite
Library api-ms-win-crt-string-l1-1-0.dll:
0x140009cc8 memset
0x140009cd0 strlen
0x140009cd8 strncmp
0x140009ce0 tolower
Library api-ms-win-crt-time-l1-1-0.dll:
0x140009cf0 __daylight
0x140009cf8 __timezone
0x140009d00 __tzname
0x140009d08 _time64
0x140009d10 _tzset
Library api-ms-win-crt-utility-l1-1-0.dll:
0x140009d20 rand
0x140009d28 srand
Library api-ms-win-crt-multibyte-l1-1-0.dll:
0x140009d38 _ismbblead
Library api-ms-win-crt-math-l1-1-0.dll:
0x140009d48 __setusermatherr
Library api-ms-win-crt-environment-l1-1-0.dll:
0x140009d58 __p__environ
0x140009d60 __p__wenviron

!This program cannot be run in DOS mode.$
`.rdata
@.data
.pdata
@.00cfg
.reloc
uLHcQ<
AWAVVWSH
[_^A^A_
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
AWAVAUATVWUSH
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
[]_^A\A]A^A_
AWAVAUATVWSH
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
[_^A\A]A^A_
QRAPAQ
AYAXZY
AWAVATVWSH
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
[_^A\A^A_
fffff.
AWAVAUATVWUSH
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
X[]_^A\A]A^A_
AVVWSH
QRAPAQ
AYAXZY
AWAVAUATVWUSH
QRAPAQ
AYAXZY
[]_^A\A]A^A_
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
ffffff.
AVVWUSH
[]_^A^
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
fffff.
QRAPAQ
AYAXZY
AVVWSH
([_^A^
QRAPAQ
AYAXZY
AWAVAUATVWUSH
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
D$4xjH
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
[]_^A\A]A^A_
AWAVAUATVWUSH
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
D$LxjH
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
[]_^A\A]A^A_
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
QRAPAQ
AYAXZY
AVVWSH
([_^A^
AVVWSH
([_^A^
ffffff.
AWAVAUATVWUSH
([]_^A\A]A^A_
ffffff.
fffff.
AWAVAUATVWUSH
D$ \??\
ffffff.
([]_^A\A]A^A_
fffff.
AWAVATVWSH
([_^A\A^A_
AVVWSH
([_^A^
t'ffffff.
AWAVAUATVWSH
ffffff.
[_^A\A]A^A_
fffff.
ffffff.
AWAVATVWUSH
[]_^A\A^A_
UAVVWSH
Dffffff.
[_^A^]
AWAVAUATVWUSH
[]_^A\A]A^A_
AVVWSH
([_^A^
AWAVVWSH
@[_^A^A_
ffffff.
t.ffff.
fffff.
UAWAVAUATVWSH
ffffff.
[_^A\A]A^A_]
ffffff.
AWAVATVWSH
X[_^A\A^A_
fffff.
fffff.
AWAVVWSH
[_^A^A_
AWAVVWSH
[_^A^A_
AVVWSH
([_^A^
AVVWSH
([_^A^
uVHcH<
uZHcP<
u!HcQ<
uVHcP<
upLcB<B
ffffff.
"$"$"$%
QRAPAQ
AYAXZY
Argument domain error (DOMAIN)
Argument singularity (SIGN)
Overflow range error (OVERFLOW)
Partial loss of significance (PLOSS)
Total loss of significance (TLOSS)
The result is too small to be represented (UNDERFLOW)
Unknown error
_matherr(): %s in %s(%g, %g) (retval=%g)
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
%d bit pseudo relocation at %p out of range, targeting %p, yielding the value %p.
Address %p has no image-section
VirtualQuery failed for %d bytes at address %p
VirtualProtect failed with code 0x%x
Mingw-w64 runtime failure:
runtime error %d
CloseHandle
CreatePipe
DeleteCriticalSection
EnterCriticalSection
ExitProcess
FreeLibrary
GetLastError
GetModuleHandleA
GetNativeSystemInfo
GetStartupInfoA
GetTickCount
InitializeCriticalSection
K32GetModuleInformation
LeaveCriticalSection
LocalAlloc
LocalFree
LocalReAlloc
ReadFile
SetUnhandledExceptionFilter
TlsGetValue
VirtualProtect
VirtualQuery
__C_specific_handler
lstrcmpiW
lstrlenW
WinHttpSetOption
mbstowcs
_set_new_mode
calloc
malloc
memcpy
strchr
__p___argc
__p___argv
__p___wargv
__p__acmdln
_cexit
_configure_narrow_argv
_configure_wide_argv
_crt_at_quick_exit
_crt_atexit
_errno
_initialize_narrow_environment
_initialize_wide_environment
_initterm
_set_app_type
_set_invalid_parameter_handler
signal
__acrt_iob_func
__p__commode
__p__fmode
__stdio_common_vfprintf
__stdio_common_vfwprintf
fwrite
memset
strlen
strncmp
tolower
__daylight
__timezone
__tzname
_time64
_tzset
_ismbblead
__setusermatherr
__p__environ
__p__wenviron
KERNEL32.dll
WINHTTP.dll
api-ms-win-crt-convert-l1-1-0.dll
api-ms-win-crt-heap-l1-1-0.dll
api-ms-win-crt-private-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-stdio-l1-1-0.dll
api-ms-win-crt-string-l1-1-0.dll
api-ms-win-crt-time-l1-1-0.dll
api-ms-win-crt-utility-l1-1-0.dll
api-ms-win-crt-multibyte-l1-1-0.dll
api-ms-win-crt-math-l1-1-0.dll
api-ms-win-crt-environment-l1-1-0.dll
index.php
\\.\PhysicalDrive0
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec Clean
Elastic Clean
ESET-NOD32 Clean
APEX Clean
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Tencent Clean
Ad-Aware Clean
Sophos ATK/Revenant-E
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
FireEye Clean
Emsisoft Clean
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Microsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
ViRobot Clean
GData Clean
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
Avast Clean
CrowdStrike Clean
No IRMA results available.