Static | ZeroBOX

PE Compile Time

2023-08-19 11:33:05

PE Imphash

df9902d76df38fc9846ad5192f1770e2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000ecef 0x0000ee00 6.48483369922
.rdata 0x00010000 0x000062d6 0x00006400 4.75185374454
.data 0x00017000 0x000013b8 0x00000a00 2.37607544663
.rsrc 0x00019000 0x0000b878 0x0000ba00 3.80249073278
.reloc 0x00025000 0x000010d8 0x00001200 6.40347518231

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00024208 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00024208 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00024208 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00024208 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00024208 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00024208 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00024208 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00024208 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_ICON 0x00024208 0x00000468 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00024670 0x00000084 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_VERSION 0x000192b0 0x000002c0 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data
RT_MANIFEST 0x000246f8 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x410000 Sleep
0x410004 VirtualProtect
0x410008 HeapFree
0x41000c VirtualFree
0x410010 VirtualAlloc
0x410014 LoadLibraryA
0x410018 HeapAlloc
0x41001c GetProcAddress
0x410020 GetProcessHeap
0x410024 FreeLibrary
0x410028 IsBadReadPtr
0x41002c WriteConsoleW
0x410030 CloseHandle
0x410034 CreateFileW
0x410038 SetFilePointerEx
0x41003c GetConsoleMode
0x410040 GetConsoleOutputCP
0x410044 FlushFileBuffers
0x410048 HeapSize
0x41004c GetStringTypeW
0x410050 SetStdHandle
0x41005c GetCurrentProcess
0x410060 TerminateProcess
0x410068 IsDebuggerPresent
0x41006c GetStartupInfoW
0x410070 GetModuleHandleW
0x410078 GetCurrentProcessId
0x41007c GetCurrentThreadId
0x410084 InitializeSListHead
0x410088 RtlUnwind
0x41008c RaiseException
0x410090 GetLastError
0x410094 SetLastError
0x410098 EncodePointer
0x4100ac TlsAlloc
0x4100b0 TlsGetValue
0x4100b4 TlsSetValue
0x4100b8 TlsFree
0x4100bc LoadLibraryExW
0x4100c0 ExitProcess
0x4100c4 GetModuleHandleExW
0x4100c8 GetModuleFileNameW
0x4100cc GetStdHandle
0x4100d0 WriteFile
0x4100d4 HeapReAlloc
0x4100d8 FindClose
0x4100dc FindFirstFileExW
0x4100e0 FindNextFileW
0x4100e4 IsValidCodePage
0x4100e8 GetACP
0x4100ec GetOEMCP
0x4100f0 GetCPInfo
0x4100f4 GetCommandLineA
0x4100f8 GetCommandLineW
0x4100fc MultiByteToWideChar
0x410100 WideCharToMultiByte
0x41010c LCMapStringW
0x410110 GetFileType
0x410114 DecodePointer
Library USER32.dll:
0x41013c SendMessageA
Library ole32.dll:
0x410144 CoInitialize
0x410148 CoCreateInstance
0x41014c CoUninitialize
Library OLEAUT32.dll:
0x41011c SysFreeString
0x410120 SysAllocString
0x410124 SafeArrayGetUBound
0x410128 SafeArrayAccessData
0x41012c VariantClear
0x410134 SafeArrayGetLBound

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
QQSVWd
j<h`VA
URPQQh
UQPXY]Y[
uSSSSj
f9:t!V
QQSVj8j@
PPPPPPPP
PPPPPVW
PP9E u!PPSVP
bad allocation
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
Unknown exception
bad array new length
string too long
Fuckyou
vector too long
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
VirtualProtect
HeapFree
VirtualFree
VirtualAlloc
LoadLibraryA
HeapAlloc
GetProcAddress
GetProcessHeap
FreeLibrary
IsBadReadPtr
KERNEL32.dll
SendMessageA
USER32.dll
CoInitialize
CoUninitialize
CoCreateInstance
ole32.dll
OLEAUT32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlUnwind
RaiseException
GetLastError
SetLastError
EncodePointer
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
LoadLibraryExW
ExitProcess
GetModuleHandleExW
GetModuleFileNameW
GetStdHandle
WriteFile
HeapReAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
LCMapStringW
GetFileType
SetStdHandle
GetStringTypeW
HeapSize
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_exception@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVtype_info@@
IDATx^
sgNlnn&
baa!MLL
(Kv$7n
IDATx^
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
3*474G4P4V4a4i4q4y4
536D6U6x6
7"7*7:7N7V7^7f7n7v7
8"838D8U8f8p8
9$959F9P9
:(:c:t:
;I;Z;k;p;
<'<8<I<Z<k<|<
9,9C9I9O9U9[9a9g9|9
9":/:W:i:
= =+=2=E=S=Y=_=e=k=q=x=
>'>A>^>q>{>
>-?6?>?z?
0.050H0^0*1J1T1
1J2Q2n2
2&3/3<3B3l3r3
>1>Y>m>
9p:p<u<
<%=1=J>Q>
?&?0?<?X?g?l?q?
0"0@0J0V0[0`0
1'1E1S1
383?3D3H3L3P3
617@7Y7
:8:@:F:
>>,>;>P>]>s>z>
<0J0c0k0t0}0
2L2U2B4{4
96:\:u:z:
;3;D;M;
<%<><C<L<
=%=R=[=c=
3,3Z3i3{3
4&434W4^4}4
5)5P5e5u5
5D6J6a6
7B7L7o7y7
8E8L8W8e8l8r8
:]=C>7?^?v?
394@4G4N4h4w4
?%?3???K?_?u?
0$040H0M0R0o0
1%1*1/1J1Y1d1i1n1
2>2b2y2
2#3U3p3
6f6k6p6u6~6?7H7
9#;=;L;Z;f;r;
<#<.<D<X<
=W=f=t=
?+?=?O?a?s?
0$060H0Z0|1E2
545_5l5
;#;-;P;q;
=>9>o>
1A1b1i1
7-8G8T8
;+<N<\<P>V>[>b>r>
1I1Q1Y1a1i1
7K8L9\9m9u9
:Q:`:l:{:
:<;E;N;W;
9-9K9_9e9-:`:
<8<U<r<
T1`1d1p1t1x1|1
2 2$2(2,2024282P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
> >$>(>,>0>4>8>D>L>T>X>\>`>d>h>l>p>t>x>|>
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7
H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8
j2n2r2v2l;t;|;
<$<,<4<<<D<L<
?,?0?4?8?@?X?h?l?|?
0 080<0T0X0l0|0
5@5`5h5p5x5|5
6,606P6X6\6x6
7 7(70747<7P7p7x7
8 8X8x8
989X9x9
:8:X:x:
;4;8;@;D;H;P;d;l;
7 7$7(7,7074787<7
Aapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Aja-JP
Aapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
ghttp://47.111.23.242/m.txt
VS_VERSION_INFO
StringFileInfo
080404b0
CompanyName
TODO: <
FileDescription
TODO: <
FileVersion
1.0.0.1
InternalName
Project4.exe
LegalCopyright
Copyright (C) 2023
OriginalFilename
Project4.exe
ProductName
TODO: <
ProductVersion
1.0.0.1
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Farfli.4!c
Elastic malicious (high confidence)
DrWeb BackDoor.Farfli.171
MicroWorld-eScan Trojan.GenericKD.68870364
FireEye Generic.mg.d79de8432d47642e
CAT-QuickHeal Clean
McAfee Artemis!D79DE8432D47
Cylance unsafe
VIPRE Trojan.GenericKD.68870364
Sangfor Backdoor.Win32.Farfli.V91a
K7AntiVirus Clean
BitDefender Trojan.GenericKD.68870364
K7GW Clean
Cybereason Clean
BitDefenderTheta Gen:NN.ZexaF.36350.iu0@aaIMVeoj
VirIT Clean
Cyren W32/ABRisk.TEMW-0121
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky HEUR:Backdoor.Win32.Farfli.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.97 (RDML:nUy1rbAQszNm3EV/aXWAfg)
Sophos Generic Reputation PUA (PUA)
F-Secure Backdoor.BDS/Farfli.svrdu
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine Clean
CMC Clean
Emsisoft Trojan.GenericKD.68870364 (B)
Ikarus Clean
GData Trojan.GenericKD.68870364
Jiangmin Clean
Webroot Clean
Google Detected
Avira BDS/Farfli.svrdu
MAX malware (ai score=88)
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Backdoor.Win32.Farfli.gen
Microsoft Program:Win32/Wacapew.C!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis suspicious
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Malwarebytes Generic.Malware/Suspicious
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Win32.Backdoor.Farfli.Msmw
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet W32/PossibleThreat
AVG Win32:Malware-gen
Avast Win32:Malware-gen
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.