Static | ZeroBOX

PE Compile Time

2023-08-07 03:01:49

PE Imphash

4329317f7ab113ac74b684563abcf41d

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00094000 0x00000000 0.0
UPX1 0x00095000 0x00032000 0x00031200 7.92004719173
.rsrc 0x000c7000 0x00022000 0x00021800 6.28336611758

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000e7ef8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e7ef8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e7ef8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e7ef8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e7ef8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x000e7ef8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000e8364 0x0000005a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x000e83c4 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library ADVAPI32.dll:
0x1400e85e4 RegCloseKey
Library CRYPT32.dll:
0x1400e85f4 CryptBinaryToStringA
Library KERNEL32.DLL:
0x1400e8604 LoadLibraryA
0x1400e860c ExitProcess
0x1400e8614 GetProcAddress
0x1400e861c VirtualProtect
Library ole32.dll:
0x1400e862c CoInitializeEx
Library OLEAUT32.dll:
0x1400e863c SysAllocString
Library SHELL32.dll:
0x1400e864c ShellExecuteA
Library WININET.dll:
0x1400e865c InternetOpenA

!This program cannot be run in DOS mode.
3@USVWAVLl$
A^_^[]
-/`Q';
Y g,yD}
vgdKKx$
GS#yNG
~`I5lH
~P*~-L;
CpIv X
H=-uC(
AE>u7
XTv?u3
u*_Y`x?
+uk[AX
{XC_8
qqN8%t
#<x#1Zo(
u$81@P
2I2d5;
LKMK`Kt`{
wi -L;
w6IV8m
98A^A]
Ik///3yG
.zpv6{
@^ws<X
00X"Z6
U`Xx3D
$FjAX(H
R^7yy9
fIEr(P
f_,}X(
P,hX1$
pKpGbWr2pP
$GrT'xx
@2 C2`HX'
Lr`H@@$
phhy!g
dHH?Sr
%C2 8
HN.: 1
\r!HXK
(%C2 H0
iV^z^^
TA1l$,p(
8-];zq
ky H0/$
dd3PP(dddHx
Xr$#'PP(k
tZ[J&=
<uyI04
wQ-%{B
T\ 0v1S
B2;uHO
<}wRHA
.U)Vq(
\r,L/M
9Il2]~A,
*m@]2'/
i0<T2B(
I^X.Hxw
PX<^(8`F
vtG0aM/
<[<.0jo
t!nx#~
`9|`u%Z
``(9r b*
5iAj{8
@$%J*T
6|}<js
0'7_B<
9)$z,,
&#r)k!
-L|\M_c
==APHUB
&-^h#
6b7N;_
U@!@A0
n6vY#@=@
@*/],
Fl5D@i]c
BbQPZ
@WVdm2
J@MP`pI@Os
?"Aj{mA
v6o4.pI`1
(P@0}S
,Z(ZC\
"u&+sm
a<oSp:
A7BuN~I8*[,]
;0Ak)K
({(a%'7
PZni^
R?DR*6
@CVlMf
F,hL W
0]H((u
#X+YH%GP[
X)$A+9
}."5Ag
k~(0Y8
HKX%(a
e_]O9@*#P
|ma":"Wu-
^a!8D!
0~!7aq
rHp##r
b*cScrJ
+##!PM
0d4ohd
W7de72
p*W4H
XtA?RF
s#Ql9u
[2B~*VB
%VV^.8
@D+!//Gy@
]dHWL0L
er;lT8p 0T(?
yNptt{6rd@N/
/X756
LrJ&lL!
#*7E2r
@0@0'`v
1m+j T>
u,kN*'
u2SHHC
3M9PB
yy0=Y:
`:<')4y
m6.B',t
2c !aM
8$4\A7;
!0;f0*
rd%q^HHPI_
w(lHGR0c
.JjOh
yNtxxx
3+$U=N
HkQY'HI
n8$?L7D
j&mF%
ORry9w
s'=~Qz
;%b{yu
BxGzUl
XJ\sL
hOFNH%
-a{P(2
] 3U `
K.00vm
$)(A,Ya
%jIp_\`
EC GHc
Hv)WaaH
p;}Kx_Y
#tJ+t!
ppHH&f,
r`)//'
"2u'{'
dtU!itDOL1!o
/*n/_=(
Dx}n6l
DhDAc7N
p%$<]F.
K1P,n4!k
SNh{MZ-ws
it<'It(
2?#8B4X
0\$
@I@")0
8= yyy
$gSJugU
PP43f2
(4_XGhj
JcKsC6
2 T.w`1
AZyUMF
IP]+R_Y
#`I6w&iL
<LLLI$)r
<O!7J]p
$uJDhD
.NbzBu@
`p!k%O
5J6x{u
gcLqCu
+?Pk7QJ}
p9]'@=6
aVJ$(I_)l
$.];9+
h3E22[
!kt !0
lt}hf#
6p-)m!
gq`dJ$
I,,Z-M
&Kqbm0
w>v{-X
C!;a)84*
X%M8L8l
'z-fj*
i4RIpPP
w##;*Se
+CK7yD
i}M!9nv8
C&XXXX
#D=92s
][=<]}<
e$$$%w0
u!rPAd
l(mTk@@C
Id*X\P
*y(0,t
LoUPC_
PVLsik
;-']{O>p
4;(5Pa`
TzEVEQ2
lhm!#IYh
Y4g!R0D
Gr\)PD
*ZC"W'q
b[HHqK
EHuxGH
XG2mh5H7H
Bhi`u]
7K5al#
EbDDaO
a2(W0R^G'
U-N?RB5
[jW@sb;`
_I.GFz
ayA`iK
Ld*0 ='0
/8tqtmy
sYYY9H
:)82F^
"\}0 /"8
D@.@^")ZR
Af&G@C
u,~9(>#
89aUX8u
9I.GFA
,J2rTm
Q-^;oH
8!-LmN
KlNH_B
yF.MwS
\"%%0s
qPVqS
tr|_!!
"Tp"9H
P#H%S2
p%X`2%S2hHP-q$Sx
`Mlc`=
6_N>$8
~~oZOa
lN@9}C
yx\}&`
Hllll}7
Cdd)d!
_T6dsy
b*lgx!
(X6YAK`
0U:sfI1
\ppytj
[;h|W"&
"hMqd](
;*$c5qk
:t5hx
dc:VMc;{
@n+)__
yyck+h
J^._^^y
U\w,m:eC(
B'R-Fk*
IJNL!Kjt
Rm`M#Fp
o&Ku!o
!$C8[#
CAKX}@Mj
hM? d2
/!K!$G
2KB#$LH}
F/tr\l
H}00MZ
9r~i)Db1Q
R|XX;'
`/]|uF
H7]Esp
*{DbL#2r
)DLgO$u]GT`
|{bOAt%
(]3=5Y
W\!%}?
{Hm)d*x
'H5m'e/*
Pw``%}
F:Jtx}|
k -t_7A/Zn9
l<L~M&
#*3\0\
W;-i!G*G8
qhmD4B
fkJ(T
a3TC_(
`j#)^x
2rXXXK
!Pyq6U
Yw-OcP
9/&qL0
@FQ1c
Y E+KJfx
Z4H?Q
DGv%Fj"
tt,U*'_
]#"X )
Z$<Z]W
2XX<%S
cb6SH/
Zg@^.yN;
8!pbV#'
r0%X1qkV
\::||00
A?+M65
wkK%Fw
+,v(t/7
FFPm7"P
$fWut.y
2}0ed,
atQZe2
%]aC%@
ecLMX#
N&qyyd
E`( ;H!
aYeB8
*q.(X}
I*(0(R
3A,-Ux`
bcB%/[fd
r+r8!+
eui<>_
2 w{wi^
_"XsSe)
w3XH#yy
:7}G`W
yLC!#Cy
i"JQ_J
{.B~m;
GQ:0aHL
&~^{p'
0t${xB+@tN
JFhmT'
w+ip(9
@DKk!+M9
)3[iY%
,'&$&N\Hl
EqK G
7:llvm+
rPrrr%
N!|W5Ps.Cl
K<OM@
LnUM@L
(YKgM4
]x; \2H
lXBWe"
@CY0r5!
gIB/!k
u4\4r,
;Aylh*
P# t BK
x.Oop
?& 1L_
]G1G_08-
MVp l
OX$=&/
00;[20%_0
j/G`8
\rxPpRy4
a[Ft`$
7@|M[(
0?:,cD
00(F.(
r0 09
@@@{X1
4Qj99
bL><999*
NNNNrZLdNF
"''''.B\p''''
bzrr*@tW?a
bad allocation
_work\1\s
rc\vctool
crt\gi
thub,tl5ole0.cpp
BNN.048
<+++bb
^{W!w
<e?f5g
uCvGw:<
1mNNNN
8)NNNNP
8''''iHp`''''
@addre
ss family not supporte
i?in useQava
fableOl,6
connec
y/rgumenXlis
e@"crip
~Hagerok
/eilzgj
~8vice
.movV`h
xy|8pm`
l^izWHtX6
wni>
sp.e:
8dm_s/uRhkJG
Q9Xs,1
b/>\['
[m?o+s
0lkrmb<
uAwr&) @
`#ob'#o
|rans;*o
StlLCMap
0123456789abc"
defghijklmnopqrstuvwxy
?vcrun;
_thV_data
exceUn
H$v!'
t_x|_
'O__baH
is!^9k`Mftv
wift_1
2ptr64fj8u
Vguard
,zxirtu
t"nM`8
\fL=?[
DI!Xk;
}Z (?Ar
e"fb}O=bZ?l
jo"nwv
eGlhO
V*OS/#
wyu'rn
..b>|
-+{s/d
6"BC;D#
el\s\u
tdio\_
Z[MX&a!B
7 hook
d$y%hs
,0x%p wasY
HEAP CO
RRUPTION DETEC
cLNKBLwA(
oAMAG`
SfWFGBK
{%ld}
V9.aks!
RzNjF;
/(null
~6:3.0
:dC4.68F
d0OogJ
a_OBw_
67tc3[']
YwK*C}
b p)=!
 !"#$%&'()*+,-./v
[\]^_`?P
ABCDEFGHIJKLMNOPQRSTUVWXYZ
pP0MNnO
pP<999@
p`rrr{@
pP@''''0
r{rrp`P
rrrrp`P@rrrr0
BN.`P@BN.
rrp`P!
qS>^h/
|C.Vg
q/E=$%
@b;zO]
v2!L.2
^G GB[
win32_
7R.kto
HDwenv
t#9(;/@
)S<;lWaa"
(|!#/
)o'O6D
V:aJ2j
:DL(SB
*)oO_`
-KQ!Cl
10V?
Asser)
DbgRe<
/Bc@H/
0>AnB#e
0@rrrrX`hprrrrx
0NNNNHXp
i.at7day
/vcnknr
gu\yor
M/dd/y
Od, M
H:mm:OS
p6.yO
Q(X'^`
re4ApisANSI7`
EnumSyL\
nveWnV7
_Lasg,m"
c/IDTomo
@C(sbW
|LpacU6F
rrrr$
,rrrr!4
hrrrr l
exj0Bw
Nufabwmodf
0_c_hy
f@or?y0
DjPbOn>
16LEUNICODE
o>t^38H>_
w>_>O
>08HpO>
8H08>/>
A>o>"_
>>08Hp>H08H>
;>?>0
A03>A|
^PJ;I:qE>
])6M>&
[cZUg^n^=
[*ncd>0
"ipj?ro
1"dcU2j3
<`CS^p
]r!hN~
y_ @y_
k-/OBo
#h_3nf
#*x?joj
vHooOu
0E[PZx
?x"Nf
?/:Fhh
PNNn'
)'''' *0+''''@,P-''''h/x2''''
rrr2P
R rrrrV0W@rrrrZPe`rrrrkpl
;<9990k@
''''0;H
a_8?Xh[
a?<x-
/s?dd_
nOw{o;r
vr;npp_
anol
rdhKe
ZT/HOhU4,
W?C_K?
IZ;4'
p''''
O6?X~'
?hV''''
mbo"?8d
i;999
i?qso[
`m:z
lm,zj
ky3ti!m1
Op*?z
+stn$
C"Fl(,
=imb;D
>jtm}S
;H9>&X
BC.6t9^
kE?M>`
TUNiLbeL
lAFneIc
nI7ipo
r = (i &CA
"nFF);,
gXL`r0
C:\PsF
(x86)\Mi?
u"2019\?
14.29v%
.3D33flb$
8b)0&0
G2bn9A
`&V@#a
ITERATOR LIST
!jlsu
*gVB ?
+/_dt&.G
I7WH3Q&U
KEFFKF
7JOQzpcUHJvZ3JhbURhd
One-C
UGhvV9zLmV4ZQ=i
o[K{_cs
mNuP_nVz7
WebKitZ37.36`KHTML,
e/74~D7
HR0cDovL2Nkbi5jcmFja3M0dXM(n
Hl6.Zp&Uuc
ybD0U2
Gw/3hJ
c254aGsuZGxyY21kdnJ0
AbW9uo
yZXNoYXJ
Z6sZW1vb
RiZ?65z
Xk_eDY0
E0p-3&
lf. Se6N4849 [
cs]/1j:m
d(e.g.@
=&kys)
`8._q0
JpqO(8
W/7w'*
ryzonNet\R
up.pdbw3
Wl$XCA
'voltmd.t@
_tc$5&Hd`
>QU``{p
VR//%t|
o^<`Af
tt;+Z7
9l;t`
>NI/xm
VNhJvD
F8z_b/
f",$e
V:XVZJ\9
bnd:f4h
4(F[ME
f$W`%!
,r&R("*x,X."0
VjX(Zx\V^$~
G+?``lWy!>+h
Rlx[/7
gp"'p#K
{m{/BO
L$'HG(>
x2` H8H
vj'LQO
.?AVLic_l7
N#@@@@Ob
XOd_oJ
O[MaBe@GU
T,M__?tIpYx
?-0cvtb
I4b@HOJM
7@W`<'
pV0P
L'odA3
V.JJFJ
J'/V|#
k[p{&t
6Oi6,F
UO^6O@
W|/9yN
s0EPep
eHandle
k(KA-Y.QzJ
S(H_vStd{
}?OEMCP
rsEx#
drnsoU
LveEiX
HtlCTtulp
buggf%
SLi@H^]s
t\S=AX
U#F4sh'B
dwqKey
xyBl"kb
uzy+U/
(]_^[H
jY|g,d
[s"iE`
=Vq~G`
rPU<<8
)`Pg(
QHD<X.;
`QR49x
AG.`UU
$Z:xDl$]{
*oaG#P
xLmLx/
</0&g8
z'ybn3M
KRm,U=
8::boo
8@Ge]m"
#vF#tDL
r=vvvx
kB-Af4y
mvwwQZ
Y`.qDe
}Hn%%*m
" UUub+Rj
qcy#D"
\t2UU1
9888Vf
hg1#(AMk!
(rZ24c
lvl06M
1pRAn(
shspqf
:F1>888
Zt8]N<
<(weENVd
[[[kgq
)hsT^@[
```|ddd
333e444
_``|ddd
233e444
]YYta^^
)-5a%'/
___1^^^1]]]0]]]0]]]0\ZZ/]]]5gnn
'+60002/1110111011102221777*777
aaa\ggg
333K222
^^^zggg
333b000
UUUm[[[
```2]]]2\\\4kkk
CI=z)$+14453555+222
mmmEppp
aaaYggg
222F&&&
___uhhh
111[,,!
YYYg]]]
'#*P(((
^^^4```4^^^5iii
DI>v&#+33235666,333
___Vfff
222BCCC
___pggg
111U)))
ccca```
333P!!!
555L666
***K(((
555K333
222K333
222K333
222K333
222K333
222K333
222K333
222K333
222K333
222K333
222K333
222K333
222K333
222K333
222K333
222K333
222K333
222K333
222K333
222K333
333J999
;;;C&&&
ttt;ggg
ruuu!vvv
```Bbbb
bddPehh
___8fff
```Lfff
```5fff
aaaJeee
___2fff
GGGGaaa
~~~flll
eeeTddd{cbb{z
555{777z555
785I444
^^^(bbb
dddSmmm
214z444
`aa*bcc
```'eee
```&ooo
@@@'kkk
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
ADVAPI32.dll
CRYPT32.dll
KERNEL32.DLL
ole32.dll
OLEAUT32.dll
SHELL32.dll
WININET.dll
RegCloseKey
CryptBinaryToStringA
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
CoInitializeEx
ShellExecuteA
InternetOpenA
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
DrWeb Clean
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Trojan.Win32.Agent.Vuhj
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.8374a7
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Sophos Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.PWSZbot.fc
Trapmine Clean
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
Webroot Clean
Google Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!60C09568374A
TACHYON Clean
VBA32 Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.