Static | ZeroBOX

PE Compile Time

2023-07-25 17:18:22

PE Imphash

49a974ece3bbf5d3a2072773ace1c1b7

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000dc15 0x0000de00 6.83407080701
.rdata 0x0000f000 0x00002c32 0x00002e00 5.42406995619
.data 0x00012000 0x00001bfc 0x00001000 3.77276507662
.rsrc 0x00014000 0x0002b898 0x0002ba00 5.83254871646

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00014100 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators
RT_RCDATA 0x00014698 0x0002b200 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00014260 0x00000434 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x40f000 GetACP
0x40f004 Sleep
0x40f008 WaitForSingleObject
0x40f00c CreateThread
0x40f010 lstrlenW
0x40f014 VirtualProtect
0x40f018 GetProcAddress
0x40f01c LoadLibraryA
0x40f020 VirtualAlloc
0x40f024 LockResource
0x40f028 LoadResource
0x40f02c SizeofResource
0x40f030 FindResourceW
0x40f034 GetModuleHandleW
0x40f038 GetLastError
0x40f03c CreateMutexA
0x40f040 GetModuleHandleA
0x40f044 OpenWaitableTimerA
0x40f048 GetConsoleWindow
0x40f04c RtlUnwind
0x40f050 GetCommandLineA
0x40f054 TlsGetValue
0x40f058 TlsAlloc
0x40f05c TlsSetValue
0x40f060 TlsFree
0x40f068 SetLastError
0x40f06c GetCurrentThreadId
0x40f078 ExitProcess
0x40f07c WriteFile
0x40f080 GetStdHandle
0x40f084 GetModuleFileNameA
0x40f094 WideCharToMultiByte
0x40f09c SetHandleCount
0x40f0a0 GetFileType
0x40f0a4 GetStartupInfoA
0x40f0ac HeapCreate
0x40f0b0 VirtualFree
0x40f0b4 HeapFree
0x40f0bc GetTickCount
0x40f0c0 GetCurrentProcessId
0x40f0c8 GetCPInfo
0x40f0cc GetOEMCP
0x40f0d0 IsValidCodePage
0x40f0d4 TerminateProcess
0x40f0d8 GetCurrentProcess
0x40f0e0 IsDebuggerPresent
0x40f0e4 RaiseException
0x40f0f4 HeapAlloc
0x40f0f8 HeapReAlloc
0x40f0fc LCMapStringA
0x40f100 MultiByteToWideChar
0x40f104 LCMapStringW
0x40f108 GetStringTypeA
0x40f10c GetStringTypeW
0x40f110 GetLocaleInfoA
0x40f114 HeapSize
Library USER32.dll:
0x40f11c ShowWindow

!This program cannot be run in DOS mode.
`.rdata
@.data
1a_vvvP
~W~_~a
~Z~RHGb~V
~R~_~[HJ
~R~S~SHY
~SHK:~^HK
~ZHO%H_
HY9~_~^HQ
F~WHG_
A~b~g~c
~S~WHJ
HYp~c~c
HZwHK5
A~a~Z3
~f~V~f
G~Q~R~a~Z
H[=~bHBc~b
HR3~a~a
A~Y~g~[
~[~gHR
~bHZlHV
HWu~Y~^1
~R~f~fHS
~QHGJ1
~bHK3HJ
~f~Q~QHI
~g~^~VHVr
FHQaHWz~^HYu
vvv`:wvv
1aH`vvN
HRN~a~c
HQdHG&
~Q~b~[
HR$~SHG
HNmHFJ
{v~f~S
G~VHO.
HFP~VHR
~V~c3w
HK?~[~Z
H_r~SHJ
HOJHVS~^HJ+~_
{v~g~g~f~g
~VHC{HO\
HVLHKa
~W~WHO
HKS~^~S
~VH[>HA
HQ?~a1}
~[H_pHR
BHA6~S
~^~ZH[
HC:~f~S
HG%~V~c
~S~[HI{
HGgHWg
~_~RHC
~b~Y~Y
JEEEEEU
QQSVWd
_VVVVV
^WWWWW
HtHu4j
s[S;7|G;w
tR99u2
tehMj@
>=Yt1j
j@j ^V
0A@@Ju
to=p+A
0SSSSS
0SSSSS
_VVVVV
;t$,v-
UQPXY]Y[
0SSSSS
0SSSSS
URPQQh
t"SS9]
PPPPPPPP
PPPPPPPP
<+t(<-t$:
+t HHt
uL9=`:A
t+WWVPV
bad allocation
kernel32.dll
ROVQJWORXJQOWJRXOQJ
VirtualProtect
^e-A]Q,
~^%&S\=
^lyR\R
lU])u|^
^x"Q\q
GAIsProcessorFeaturePresent
KERNEL32
bad allocation
bad exception
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Unknown exception
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
1#QNAN
1#SNAN
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetACP
WaitForSingleObject
CreateThread
lstrlenW
VirtualProtect
GetProcAddress
LoadLibraryA
VirtualAlloc
LockResource
LoadResource
SizeofResource
FindResourceW
GetModuleHandleW
GetLastError
CreateMutexA
GetModuleHandleA
OpenWaitableTimerA
GetConsoleWindow
KERNEL32.dll
ShowWindow
USER32.dll
RtlUnwind
GetCommandLineA
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
SetUnhandledExceptionFilter
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
HeapCreate
VirtualFree
HeapFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetCPInfo
GetOEMCP
IsValidCodePage
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
IsDebuggerPresent
RaiseException
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSectionAndSpinCount
HeapAlloc
HeapReAlloc
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
HeapSize
.?AVbad_exception@std@@
.?AVexception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVtype_info@@
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
S5Frt{
v3i3m+
W2fv9
_<mgPJ
A_AaAV
A]AVA_AaAR
ATAaA_A\A_Aa
A_AaAV
AaAVASA_AX
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
201229000000Z
240101235959Z0
Private Organization1
10654061463001
Novosibirsk1
TAUKONSALT, OOO1
TAUKONSALT, OOO0
gNIuP#
RU-10654061463000
1http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07
1http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0K
https://www.digicert.com/CPS0
http://ocsp.digicert.com0H
<http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert High Assurance EV Root CA0
120418120000Z
270418120000Z0l1
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)0
+.+1Xf
http://ocsp.digicert.com0I
=http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
:http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0@
:http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
.http://www.digicert.com/ssl-cps-repository.htm0
DigiCert Inc1
www.digicert.com1+0)
"DigiCert EV Code Signing CA (SHA2)
https://movavi.ru 0/
HG5WsYl
20230427171226Z
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
220921000000Z
331121235959Z0F1
DigiCert1$0"
DigiCert Timestamp 2022 - 20
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
230427171226Z0+
/1(0&0$0"
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
RT_MANIFEST
VS_VERSION_INFO
StringFileInfo
040904E4
Comments
Molasses muffled conspiratorial debated
CompanyName
Rustics psychics heartbroken
FileDescription
Quartics denominators regret serrated
FileVersion
4.232.63.3
InternalName
Mindful
LegalCopyright
Copyright
Enthroned remain popcorn
LegalTrademarks
Satyric unpunished nightlife detectability beehives distinct
OriginalFilename
Interlock
ProductName
ProductVersion
4.232.63.3
VarFileInfo
Translation
RAny use of this Certificate constitutes acceptance of the DigiCert CP/CPS and the Relying Party Agreement which limit liability and are incorporated herein by reference
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.48761f8b0576e7be
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.8883e8
BitDefenderTheta Gen:NN.ZexaF.36318.qq2@au4q!Ipi
VirIT Clean
Cyren W32/Kryptik.KGA.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/GenKryptik.GMEO
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan-Spy.Win32.Stealer.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.100 (RDML:G1BRsC45oj/Z9A1QtwFR1A)
Sophos ML/PE-A
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Malicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:Trojan-Spy.Win32.Stealer.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.Agent
MaxSecure Clean
Fortinet Clean
AVG PWSX-gen [Trj]
Avast PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.