Static | ZeroBOX

PE Compile Time

2023-09-09 20:00:46

PE Imphash

7a83bc8f14d32c8af61627070a00e36a

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001ad11 0x0001ae00 6.71766309326
.rdata 0x0001c000 0x000061f8 0x00006200 4.90665258299
.data 0x00023000 0x00001ed8 0x00000a00 2.04724834824
.rsrc 0x00025000 0x000001e0 0x00000200 4.71229819329
.reloc 0x00026000 0x00001100 0x00001200 6.36723268677

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00025060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x41c000 WriteFile
0x41c004 GetLastError
0x41c008 VirtualFree
0x41c00c VirtualAlloc
0x41c010 WaitForSingleObject
0x41c014 CloseHandle
0x41c018 CreateThread
0x41c01c WriteConsoleW
0x41c024 GetCurrentProcessId
0x41c028 GetCurrentThreadId
0x41c030 InitializeSListHead
0x41c034 IsDebuggerPresent
0x41c040 GetStartupInfoW
0x41c048 GetModuleHandleW
0x41c04c GetCurrentProcess
0x41c050 TerminateProcess
0x41c054 RtlUnwind
0x41c058 SetLastError
0x41c06c TlsAlloc
0x41c070 TlsGetValue
0x41c074 TlsSetValue
0x41c078 TlsFree
0x41c07c FreeLibrary
0x41c080 GetProcAddress
0x41c084 LoadLibraryExW
0x41c088 EncodePointer
0x41c08c RaiseException
0x41c090 GetStdHandle
0x41c094 GetModuleFileNameW
0x41c098 ExitProcess
0x41c09c GetModuleHandleExW
0x41c0a0 HeapFree
0x41c0a4 HeapAlloc
0x41c0a8 HeapReAlloc
0x41c0ac LCMapStringW
0x41c0b0 FindClose
0x41c0b4 FindFirstFileExW
0x41c0b8 FindNextFileW
0x41c0bc IsValidCodePage
0x41c0c0 GetACP
0x41c0c4 GetOEMCP
0x41c0c8 GetCPInfo
0x41c0cc GetCommandLineA
0x41c0d0 GetCommandLineW
0x41c0d4 MultiByteToWideChar
0x41c0d8 WideCharToMultiByte
0x41c0e4 SetStdHandle
0x41c0e8 GetFileType
0x41c0ec GetStringTypeW
0x41c0f0 GetProcessHeap
0x41c0f4 HeapSize
0x41c0f8 FlushFileBuffers
0x41c0fc GetConsoleOutputCP
0x41c100 GetConsoleMode
0x41c104 SetFilePointerEx
0x41c108 CreateFileW
0x41c10c DecodePointer

!This program cannot be run in DOS mode.
mYRich
`.rdata
@.data
@.reloc
URPQQh0?@
UQPXY]Y[
QQSVWd
uSSSSj
f9:t!V
QQSVj8j@
tl=H6B
PPPPPPPP
PPPPPVW
PP9E u!PPSVP
SUVWj\X
D$'1a^f
D$+bTab
D$ qfq4
D$$fq`f
D$(}qbqf
D$ 66j.Xf
D$0Edg`f
YY_^][
D$ N?HM
D$$CIH
D$(-?NN
D$,CHAM
D$8t[\V3
D$@]_[G
D$HFW\A
D$L[]\
D$TE[FZ
D$ #juYf
D$4;\fg
D$X<:6B
D$`@A<?
V YYPj
V YYPS
D$ nlht
D$$lvd
D$(ac`
D$,s`c
D$0a$kf
D$ LLLL
D$$LLLLf
V YYPj
PSSSSS
V YYPS
V YYPj
D$\FYe]f
D$HMVF
D$ 2222
D$$2222f
V YYPS
V YYPj
D$({WWSf
D$h=`faf
S YYPj
S YYPj
S YYPj
S YYPj
D$tey|v
D$xta|zf
V YYPj
V YYPj
SUVWj.X
D$ ofbs
D$$rI}s
T$@BG;T$T
F&&FWf
D$,MkzS
D$0uj{r
D$4kNgt
D$8jrkG
D$$I[`[
D$(`Wf f
D$,Tqct
D$0e|&'
D$4;qyy
D$@9$.,
D$H9$"#
D$DXpqqW
D$L~?xm
D$P~}?y
D$Tvszl
D$ iun=
D$$jxox
D$(=oxi
D$,otxkf
D$ '2!"
D$$"%2nf
\$(Xj._juY
Yj,XjuY
|$,j0f
D$(3r5
D$,30r!
D$0&73?
D$$pLEW
D$(TBQF
D$4WFBN
D$HVy~t
D$L0cdu
D$Pq}0t
D$Tqdq<
D$X0`qd
D$\x05|f
D$xj*Xf
\$(j.f
D$0(=."
D$4`j#<
t(j*Xf
SVWj/X
~~j.Xf
D$ RRRRf
V YYPS
V YYPj
D$ ddddf
V YYPS
V YYPj
j7Y9\$t
D$87~|z
D$Hy7<
V YYPS
V YYPj
V YYPj
V YYPj
V YYPj
D$4!MMI
D$8GCQ
D$81xvt
D$@z}v1
SSSSPj
D$$--)
D$ J]sG
D$$[[_L
D$(CFJA
D$44Y_P
D$8]YP_
D$<.ZYY
D$@PN_
D$DQLTW
D$LL^_
D$PP]]Z
D$h2.%4
D$x,!34
D$0_e3
3t.2AP
D$4Mk}}3
D$8{mmx
D$<krrg
D$@>mj
D$Dlj>n
D$Hlq}{f
D$#]j&[f
z@hPSh
D$HPUj
EhpopSf
ElPSSSSS
D$(VPh
D$X/JF@
D$`OMD@
D$dQ@?
SUVWj3
f#D$Hf
D$.0j.Xf
D$4 gn*3
D$P!0##
D$T,1&-f
g+YkPWj
T$4+T$L
t$0WSX
u.9\$$v&
L;\$$r
\$hvIj
D$0egz
D$4bs%I
D$8yfsxf
D$0B@;8
D$858=0
D$<;8I4
D$@rpkh
D$Dsd2^
D$Hbnkt
D$Llm^a
D$Pxsdr
D$I<&=;f
jCZSSSS
D$8y^KX
D$,ki[h
D$0dWc[3
D$H~vK1
D$\/,0,
D$d&+!,
D$p//"+
D$x0&,+
D$0Avjo3
D$4g#nb
D$8qh9#
9\$,t8
D$,61iz
D$(`abc
D$,defg
D$0hijk
D$4lmno
D$8pqrs
D$<tuvw
D$@MNOP
D$DQRSTf
QSUVW3
QQSUVW3
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
Unknown exception
bad exception
CorExitProcess
AreFileApisANSI
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
Banana
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
))))))))))))))))11111111111111119999999999999999BBBBBBBBBBBBBBBBFFFFFFFFFFFFFFFFLLLLLLLLLLLLLLLLvvvvvvvvvvvvvvvv
.text$mn
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
WriteFile
GetLastError
VirtualFree
VirtualAlloc
WaitForSingleObject
CloseHandle
CreateThread
KERNEL32.dll
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
GetCurrentProcess
TerminateProcess
RtlUnwind
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
GetStdHandle
GetModuleFileNameW
ExitProcess
GetModuleHandleExW
HeapFree
HeapAlloc
HeapReAlloc
LCMapStringW
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
GetProcessHeap
HeapSize
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
WriteConsoleW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
13181E1
2%343K3Q3W3]3c3i3o3
3*474_4q4
4%5.5B5H5u5{5
8.8Z8d8m8
99'9c9m9v9
:-:7:J:S:^:e:x:
;!;1;A;Q;Z;~;
<0<5<B<
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9
020S0a0g0
1(141P1p1~1
2-2X2b2
3#3-393>3C3^3h3t3y3~3
060D0L0d0}0
5 525@5S5^5i5
9!9a9g9{9
>Y>d>l>w>}>
?7?P?U?n?
3!4@4v4
676F6_6M7W7d7
8#8-898c8
=D=S=e=x=
>A>H>g>
?:?O?_?l?
0<0U0c0o0{0
1<1T1d1x1}1
2 2;2J2U2Z2_2z2
?+?v?}?
90L0q0
3O3i3{3
44%4)434F4T4j4
566T7Y7_7d7
979j9z9
:?;N;\;y;
<1=c=~=
?)?;?M?_?q?
0$060X1!2
5D5[5{5
7<7Z7r7
7V8]8d8k8x8
:,:X:~:
>>B>]>j>x>
4(4K4U4|4
20?0j0
3 323z3
4,454>4
9:9@9N9
;Q<]<q<}<
="=?=O=[=j=}>
>'?D?X?c?
1&2F2V2
3]4h4n4w4
99;T;j;
9L;'?4?
1#12181D1P1\1o1u1
1$282C2Q2_2f2
575?5Y5f5q5
:":1:>:M:Z:l:y:
=*>'?A?J?
C8Q8j<
1 1,1014181<1@1L1P1T1p1t1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
54;8;<;L<P<T<l<p<t<P=X=`=d=h=l=p=t=x=|=
=8?<?@?D?H?L?P?T?X?\?`?d?h?l?p?t?x?|?
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5|5
6 6$6(6
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
=$=,=4=<=D=L=T=\=d=l=t=|=
2 2$24282@2X2<6@6\6`6|6
7D7H7d7h7p7x7
8(8\8`8
9$9(9H9h9
:(:H:h:
;(;H;d;h;
686<6H6L6P6T6X6\6`6d6h6l6x6|6
Aapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Aapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
Aja-JP
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
((((( H
(
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
&&&&&&&&========AAAAAAAASSSSSSSS
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Trojan.GenericKDZ.102630
ClamAV Win.Malware.Stealerc-10007714-0
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Spyware.Stealer
Zillya Clean
Sangfor Clean
K7AntiVirus Trojan ( 005aa5f61 )
BitDefender Trojan.GenericKDZ.102630
K7GW Trojan ( 005aa5f61 )
Cybereason malicious.cb6378
BitDefenderTheta Gen:NN.ZexaF.36662.iuW@a40dE@oi
VirIT Trojan.Win32.Genus.TBH
Cyren W32/S-8669fa29!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/TrojanDownloader.Agent.HEY
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.Win32.Stealerc.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Generic@AI.100 (RDMK:vOsN7+paqE/xxP1j6lrJJw)
TACHYON Clean
Sophos Troj/Mystic-D
Baidu Clean
F-Secure Clean
DrWeb Trojan.PWS.Stealer.37347
VIPRE Trojan.GenericKDZ.102630
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win32.Generic.ch
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.ab01a5c6d7bd2e1c
Emsisoft Trojan.GenericKDZ.102630 (B)
Ikarus Trojan-Downloader.Win32.Agent
GData Win32.Trojan.PSE.9TLXQ0
Jiangmin Trojan.PSW.Stealerc.bw
Webroot Clean
Avira Clean
Antiy-AVL Trojan/Win32.Midie
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D190E6
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.Win32.Stealerc.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Detected
AhnLab-V3 Trojan/Win.TrojanX-gen.R600981
Acronis Clean
VBA32 BScope.TrojanPSW.Stealerc
ALYac Trojan.GenericKDZ.102630
MAX malware (ai score=80)
DeepInstinct MALICIOUS
Cylance unsafe
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Trojan-PSW.Win32.Stealerc.hq
Yandex Trojan.DL.Agent!J3iOUFWmjAo
SentinelOne Clean
MaxSecure Trojan.Malware.121218.susgen
Fortinet W32/Kryptik.0A1A!tr
AVG Win32:TrojanX-gen [Trj]
Avast Win32:TrojanX-gen [Trj]
CrowdStrike win/malicious_confidence_90% (D)
No IRMA results available.