Static | ZeroBOX

PE Compile Time

2023-06-21 05:18:39

PE Imphash

9af3e93e35221a2c8c04a3cc05e589b2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.qbwza 0x00001000 0x0000420c 0x00004400 6.56656311118
.text 0x00006000 0x00025335 0x00025400 6.58077772577
.rdata 0x0002c000 0x0000e5dc 0x0000e600 5.6255789325
.data 0x0003b000 0x0002cf20 0x0002c200 5.85565785018
.rsrc 0x00068000 0x00000440 0x00000600 2.52480248628

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00068060 0x000003dc LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x42c000 WaitForSingleObject
0x42c004 Sleep
0x42c008 CreateThread
0x42c00c VirtualAlloc
0x42c010 VirtualProtect
0x42c014 GetModuleHandleA
0x42c018 GetProcAddress
0x42c01c LoadLibraryA
0x42c020 lstrlenW
0x42c024 AddAtomW
0x42c028 CreateFileW
0x42c02c WideCharToMultiByte
0x42c040 EncodePointer
0x42c044 DecodePointer
0x42c048 MultiByteToWideChar
0x42c04c LCMapStringEx
0x42c050 GetStringTypeW
0x42c054 GetCPInfo
0x42c060 GetCurrentProcessId
0x42c064 GetCurrentThreadId
0x42c06c InitializeSListHead
0x42c070 IsDebuggerPresent
0x42c07c GetStartupInfoW
0x42c080 GetModuleHandleW
0x42c084 GetCurrentProcess
0x42c088 TerminateProcess
0x42c08c RaiseException
0x42c090 RtlUnwind
0x42c094 GetLastError
0x42c098 SetLastError
0x42c0a0 TlsAlloc
0x42c0a4 TlsGetValue
0x42c0a8 TlsSetValue
0x42c0ac TlsFree
0x42c0b0 FreeLibrary
0x42c0b4 LoadLibraryExW
0x42c0b8 GetStdHandle
0x42c0bc WriteFile
0x42c0c0 GetModuleFileNameW
0x42c0c4 ExitProcess
0x42c0c8 GetModuleHandleExW
0x42c0cc GetCommandLineA
0x42c0d0 GetCommandLineW
0x42c0d4 HeapAlloc
0x42c0d8 HeapFree
0x42c0dc GetFileType
0x42c0e0 CompareStringW
0x42c0e4 LCMapStringW
0x42c0e8 GetLocaleInfoW
0x42c0ec IsValidLocale
0x42c0f0 GetUserDefaultLCID
0x42c0f4 EnumSystemLocalesW
0x42c0f8 CloseHandle
0x42c0fc FlushFileBuffers
0x42c100 GetConsoleOutputCP
0x42c104 GetConsoleMode
0x42c108 ReadFile
0x42c10c GetFileSizeEx
0x42c110 SetFilePointerEx
0x42c114 ReadConsoleW
0x42c118 HeapReAlloc
0x42c11c FindClose
0x42c120 FindFirstFileExW
0x42c124 FindNextFileW
0x42c128 IsValidCodePage
0x42c12c GetACP
0x42c130 GetOEMCP
0x42c140 SetStdHandle
0x42c144 GetProcessHeap
0x42c148 HeapSize
0x42c14c WriteConsoleW

!This program cannot be run in DOS mode.
.qbwza
`.text
`.rdata
@.data
m2bm2m/g2
*1,c10
1(+1o
/&&&&&U
tG9uCj
W9^Lt"
PPPPPWS
u"h$tF
QQSVWd
URPQQhP,A
UQPXY]Y[
PPPPPPPP
<ItC<Lt3<Tt#<h
A<lt'<tt
V +V4+
tb9^4~]
PRRRRR
ARPRQh
jYjf
PVVVVV
PVVVVV
uSSSSj
SWt@jU
_tqPVj@
M,j"^QRRRRR
Vj0XPW
r!SSPVQ
dr#SSjdVQ
M$j"^QRRRRR
j"[VWWWW
_PVVVVV
j"_SVVVV
PVVVVV
^PSSSSS
j"^WSSSS
WVVVVV
PVSRSQV
PPPPPVW
PP9E u!PPSVP
PVVVVV
PWWWWW
D8(Ht'
D8(Ht5F
L:-^_[
3= bF
f9:t!V
QQSVj8j@
tl=pbF
NX9^`t1
;V\uYW
u2Vj@h
9C`u99C\t4
u29K\t-
F95<tF
^PQQQQQ
E ^PQQQQ
CY<u
PPPPPPPP
HPI0kb7OwDLLcPqtv
c23qKqFW8yh3MBTOJ4L
kernel32.dll
fFdoECrZYt0vQKr5inv
FreeConsole
aYlGgNz5NgD6v95MRUmsmT7
gEn4rZ6aZ1CR1WEd6
4OaOU32bCTP9sfk6kNmwSrZ7ZWLIb
xV35eb9512R8X8T1rnzd8EU00EGGydA
Sum is too small!
Count:
Index:
Odd index!
Alice sosal
Charlie
Hello,
x is greater than 10!
x is greater than 5!
x is less than or equal to 5!
Opdu870LBdAo1bjcXEu1xIMW
AztmI5xiM4gz
1nrGiwxfokUlbBTmBdLrPajox
b61pSZ7d9297sY2shPsf34P
VsETVkeiL9lRqcMMg1rlzwyzOlr
0Rz5KBngJxmKcEiC4D6VP
k4WIEAW2vwj
zb2m15xZZm
Nw5oSOIaiUmLt
W5XYf9iUiLn5hu
E0E8sD5cz7Cd
KUVd3HfK9RtGV3ijLzv0tN4H9
gWNgBK6lMuxAMQxsI4oiu
6H03BBmJpeZiiekCFLeU4QVCb5D
x8bnbjIa
A7b5vYqKQCxv5AdP0O8Go7YDlCCAv
kkcTHo8lkch6Q6QLjC90fFP0K
RgbPnqe5iLrCwPToaGiHqBck7
pQcdoOeCu5SwhFUiPkm5UzcjppOn
Unknown exception
bad array new length
string too long
iostream
iostream stream error
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
invalid string position
vector too long
;\)m?\
l\=Zo\
0]Og4]
B]P#B]
;X](]X]e
X]nZY]
2^5+3^
]^s@e^
k^HCn^:&r^<Hr^
z^M!|^
_bad allocation
success
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
[aOni*{
~ $s%r
@b;zO]
v2!L.2
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
_hypot
_nextafter
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?x+s7
?5Od%
?|I7Z#
>,'1D=
?g)([|X>=
~U`?K
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
b<log10
?5Wg4p
%S#[k=
"B <1=
.qbwza
.qbwza$x
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
WaitForSingleObject
CreateThread
VirtualAlloc
VirtualProtect
GetModuleHandleA
GetProcAddress
LoadLibraryA
lstrlenW
AddAtomW
KERNEL32.dll
WideCharToMultiByte
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
EncodePointer
DecodePointer
MultiByteToWideChar
LCMapStringEx
GetStringTypeW
GetCPInfo
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
GetModuleHandleW
GetCurrentProcess
TerminateProcess
RaiseException
RtlUnwind
GetLastError
SetLastError
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
GetStdHandle
WriteFile
GetModuleFileNameW
ExitProcess
GetModuleHandleExW
GetCommandLineA
GetCommandLineW
HeapAlloc
HeapFree
GetFileType
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
CloseHandle
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
ReadFile
GetFileSizeEx
SetFilePointerEx
ReadConsoleW
HeapReAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetProcessHeap
HeapSize
CreateFileW
WriteConsoleW
fy|mnL
JoloR
$=!Fk2
#_#DT1
yU?^!N
s\nn7n
^XEotq
)j1]FI
^6P/Qo
+YJJKq
!g"@"B!j
"B!i!g
"@"B!j!o
!g"@"B"7
">"7"@"B"3
!g"B"7
!g"7"@
"@!g"B
"5"B"@"="@"B
"@"B"7
!p!n!g"@
!g"@"B
!p!n!g"@
"B"7"4"@"9
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVruntime_error@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVbad_cast@std@@
.?AVfailure@ios_base@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_exception@std@@
.?AVerror_category@std@@
.?AV_Iostream_error_category2@std@@
.?AV_Facet_base@std@@
.?AVfacet@locale@std@@
.?AU_Crt_new_delete@std@@
.?AUctype_base@std@@
.?AV?$ctype@D@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$numpunct@D@std@@
.?AV_Locimp@locale@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AVtype_info@@
Gxx@NQOz-Pymhia
Gxx@NQOz-Pymhia
C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
Bapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
(null)
((((( H
((((( H
(
mscoree.dll
BLC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
@,C0C4C8C<C@CDCHCPCXC`ClCxC
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Capi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
Cja-JP
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
VS_VERSION_INFO
StringFileInfo
040904E4
Comments
This is a legitimate application.
CompanyName
Corporation
FileDescription
Corporation Product
FileVersion
InternalName
VGITLkFx8qcM
LegalCopyright
Corporation All rights reserved.
LegalTrademarks
Corporation Trademarks
OriginalFilename
amTyOmdy.exe
ProductName
k2n9JM7Rlu
ProductVersion
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Lazy.353482
FireEye Generic.mg.58c867b628064803
CAT-QuickHeal Trojan.IGENERIC
ALYac Gen:Variant.Lazy.353482
Malwarebytes Trojan.Crypt
VIPRE Gen:Variant.Lazy.353482
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005a78581 )
BitDefender Gen:Variant.Lazy.353482
K7GW Trojan ( 005a78581 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Cyren W32/Kryptik.KAP.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Kryptik.HTWT
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Trojan:Win32/Kryptik.c08747f5
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.100 (RDML:L9IZbOmENfYsFm2mtVZYgA)
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/AD.RedLineSteal.tiwkq
DrWeb Trojan.Packed2.45386
Zillya Clean
TrendMicro TrojanSpy.Win32.REDLINE.YXDFVZ
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Gen:Variant.Lazy.353482 (B)
Ikarus Trojan-Spy.TitanStealer
GData Gen:Variant.Lazy.353482
Jiangmin Clean
Webroot Clean
Avira TR/AD.RedLineSteal.tiwkq
Antiy-AVL Trojan/Win32.Kryptik
Gridinsoft Trojan.Win32.Downloader.dd!n
Xcitium Clean
Arcabit Trojan.Lazy.D564CA
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Amadey.ADM!MTB
Google Detected
AhnLab-V3 Trojan/Win.TrojanX-gen.R588236
Acronis Clean
McAfee GenericRXWE-JE!58C867B62806
MAX malware (ai score=84)
DeepInstinct MALICIOUS
VBA32 BScope.Trojan.Downloader
Cylance unsafe
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.REDLINE.YXDFVZ
Tencent Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.121218.susgen
Fortinet W32/GenKryptik.GLAP!tr
BitDefenderTheta Gen:NN.ZexaF.36270.zu0@aKGhc7mi
AVG Win32:BotX-gen [Trj]
Avast Win32:BotX-gen [Trj]
No IRMA results available.