Static | ZeroBOX

PE Compile Time

2022-09-04 15:42:31

PE Imphash

3bd4d8d7ac218192f962c78cd0a6d8f2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000c380 0x0000c400 6.44719226436
.rdata 0x0000e000 0x00008eb0 0x00009000 4.68527679425
.data 0x00017000 0x00001bc8 0x00000a00 1.93498080376
.pdata 0x00019000 0x00000d80 0x00000e00 4.76196142161
_RDATA 0x0001a000 0x0000015c 0x00000200 2.78968030549
.reloc 0x0001b000 0x00000648 0x00000800 4.8085564298

Imports

Library KERNEL32.dll:
0x14000e000 VirtualAlloc
0x14000e008 Sleep
0x14000e010 WriteConsoleW
0x14000e018 CloseHandle
0x14000e020 CreateFileW
0x14000e028 SetFilePointerEx
0x14000e030 GetConsoleMode
0x14000e038 QueryPerformanceCounter
0x14000e040 GetCurrentProcessId
0x14000e048 GetCurrentThreadId
0x14000e050 GetSystemTimeAsFileTime
0x14000e058 InitializeSListHead
0x14000e060 RtlCaptureContext
0x14000e068 RtlLookupFunctionEntry
0x14000e070 RtlVirtualUnwind
0x14000e078 IsDebuggerPresent
0x14000e080 UnhandledExceptionFilter
0x14000e090 GetStartupInfoW
0x14000e0a0 GetModuleHandleW
0x14000e0a8 RtlUnwindEx
0x14000e0b0 GetLastError
0x14000e0b8 SetLastError
0x14000e0c0 EnterCriticalSection
0x14000e0c8 LeaveCriticalSection
0x14000e0d0 DeleteCriticalSection
0x14000e0e0 TlsAlloc
0x14000e0e8 TlsGetValue
0x14000e0f0 TlsSetValue
0x14000e0f8 TlsFree
0x14000e100 FreeLibrary
0x14000e108 GetProcAddress
0x14000e110 LoadLibraryExW
0x14000e118 RaiseException
0x14000e120 GetStdHandle
0x14000e128 WriteFile
0x14000e130 GetModuleFileNameW
0x14000e138 GetCurrentProcess
0x14000e140 ExitProcess
0x14000e148 TerminateProcess
0x14000e150 GetModuleHandleExW
0x14000e158 GetCommandLineA
0x14000e160 GetCommandLineW
0x14000e168 HeapAlloc
0x14000e170 HeapFree
0x14000e178 FindClose
0x14000e180 FindFirstFileExW
0x14000e188 FindNextFileW
0x14000e190 IsValidCodePage
0x14000e198 GetACP
0x14000e1a0 GetOEMCP
0x14000e1a8 GetCPInfo
0x14000e1b0 MultiByteToWideChar
0x14000e1b8 WideCharToMultiByte
0x14000e1c0 GetEnvironmentStringsW
0x14000e1c8 FreeEnvironmentStringsW
0x14000e1d0 SetEnvironmentVariableW
0x14000e1d8 SetStdHandle
0x14000e1e0 GetFileType
0x14000e1e8 GetStringTypeW
0x14000e1f0 CompareStringW
0x14000e1f8 LCMapStringW
0x14000e200 GetProcessHeap
0x14000e208 HeapSize
0x14000e210 HeapReAlloc
0x14000e218 FlushFileBuffers
0x14000e220 GetConsoleOutputCP
Library WSOCK32.dll:
0x14000e230 send
0x14000e238 socket
0x14000e240 connect
0x14000e248 recv
0x14000e250 WSAStartup
0x14000e258 closesocket

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@_RDATA
@.reloc
H3E H3E
u/HcH<H
WATAUAVAWH
A_A^A]A\_
fffffff
ffffff
vKfffff
WATAUAVAWH
A_A^A]A\_
ffffff
fffffff
x ATAVAWH
A_A^A\
UVWAVAWH
0A_A^_^]
WAVAWH
0A_A^_
u3HcH<H
t$ WAVAWH
A_A^_
WAVAWH
A_A^_
u"8Z(t
uF8Z(t
vC8_(t
u"8Z(t
uF8Z(t
vB8_(t
UVWATAUAVAWH
`A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H97u+A
\$ UVWATAUAVAWH
@8|$Ht
@8|$Ht
@8|$Ht
D$XD9x
@8|$ht
@8|$ht
@8|$ht
A_A^A]A\_^]
u"8Z(t
UVWATAUAVAWH
L$&8\$&t,8Y
@A_A^A]A\_^]
fD94Fu
UVWATAUAVAWH
t?H95e
xWI96tRI
0A_A^A]A\_^]
fD9t$b
@UATAUAVAWH
e0A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
\$ VWATAUAVH
D!l$xA
@A^A]A\_^
L$ VWAVH
@8l$Ht
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
@UATAUAVAWH
H!T$0D
ue!T$(H!T$
A_A^A]A\]
UAVAWH
WAVAWH
A_A^_
UVWATAUAVAWH
D8\0>t
L$@D8]
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
\$ UVWATAUAVAWH
H!D$ H
`A_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
@USVWATAUAVAWH
e8A_A^A]A\_^[]
UVWAVAWH
@A_A^_^]
ffffff
fffffff
USVWAVH
A^_^[]
LcA<E3
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
AreFileApisANSI
CompareStringEx
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
.text$mn
.text$mn$00
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.idata$2
.idata$3
.idata$4
.idata$6
.pdata
_RDATA
VirtualAlloc
KERNEL32.dll
WSOCK32.dll
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
RtlUnwindEx
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
RaiseException
GetStdHandle
WriteFile
GetModuleFileNameW
GetCurrentProcess
ExitProcess
TerminateProcess
GetModuleHandleExW
GetCommandLineA
GetCommandLineW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetFileType
GetStringTypeW
CompareStringW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav W32.Common.7CE4E507
Lionic Trojan.Win32.Rekvex.4!c
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Gen:Variant.Zusy.478419
ClamAV Clean
FireEye Gen:Variant.Zusy.478419
CAT-QuickHeal Clean
ALYac Gen:Variant.Zusy.478419
Malwarebytes Malware.AI.553375904
VIPRE Gen:Variant.Zusy.478419
Sangfor Trojan.Win32.Rozena.Vbsa
K7AntiVirus Trojan ( 005988b31 )
BitDefender Gen:Variant.Zusy.478419
K7GW Trojan ( 005988b31 )
Cybereason Clean
BitDefenderTheta Clean
VirIT Clean
Cyren W64/ABRisk.VDRD-5763
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win64/Rozena.TA
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.Rekvex.bah
Alibaba Trojan:Win64/Rozena.f10ea64c
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Rekvex.96768.C
Rising Trojan.Rekvex!8.1170C (TFE:5:IE1K4aiQOqH)
Sophos Mal/Generic-S
F-Secure Trojan.TR/Redcap.nksry
Baidu Clean
Zillya Trojan.Rekvex.Win32.150
TrendMicro TROJ_GEN.R002C0XGP23
McAfee-GW-Edition BehavesLike.Win64.Generic.nm
Trapmine Clean
CMC Clean
Emsisoft Gen:Variant.Zusy.478419 (B)
Ikarus Trojan.Win64.Rozena
GData Gen:Variant.Zusy.478419
Jiangmin Trojan.Rekvex.bk
Webroot Clean
Avira TR/Redcap.nksry
MAX malware (ai score=80)
Antiy-AVL Trojan/Win64.Rozena
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Zusy.D74CD3
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win32.Rekvex.bah
Microsoft Trojan:Win64/Rozena.EN!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.R521258
Acronis Clean
McAfee Artemis!0EB17599A6D6
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Trojan.Rekvex
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0XGP23
Tencent Malware.Win32.Gencirc.13ea7484
Yandex Trojan.Rozena!//JMMR/cwKE
SentinelOne Clean
MaxSecure Trojan.Malware.187602278.susgen
Fortinet W64/Rozena.TA!tr
AVG Win64:TrojanX-gen [Trj]
Avast Win64:TrojanX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.