Static | ZeroBOX

PE Compile Time

2018-08-31 07:18:33

PE Imphash

05d3dce2be32df01ca249872dd2cc117

PEiD Signatures

UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00024000 0x00000000 0.0
UPX1 0x00025000 0x00011000 0x00010200 7.8779930428
.rsrc 0x00036000 0x00010000 0x0000fc00 7.52725036342

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003a968 0x0000a9cb LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0003a968 0x0000a9cb LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0003a968 0x0000a9cb LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_ICON 0x0003a968 0x0000a9cb LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_DIALOG 0x00032324 0x000000b8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00032518 0x00000034 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00032518 0x00000034 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00032518 0x00000034 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00032518 0x00000034 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x00045338 0x0000003e LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0004537c 0x00000274 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x000455f4 0x00000555 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library KERNEL32.DLL:
0x445b88 LoadLibraryA
0x445b8c ExitProcess
0x445b90 GetProcAddress
0x445b94 VirtualProtect
Library MSVCRT.dll:
0x445b9c free

!This program cannot be run in DOS mode.
`YRich
[uN+sn
7SLVMd
f ~FB^
mI[J8G
iOTQ'ma
HX,bkl
d'i8^5[
jF(chd
m,Lq(Gy
9^$DSL
%9wsd=
gj8#ZD
elptx0|
AT1w6
IJbdddKLNM
0"-VbK<
^Mu;Fr
u@?hl#Es
%U|I<V'
R*L/PG6;
PVN6}3q
s}TO0
i{ /{,
LF8GU8s+
8:^$<W
W@pZ]:
3BU';M
F\rvzhP
Fps8l+
v,YSt9DMYw,`U
S-' }Y2Pa
~(um6A
U#^;s/2
`]]b?7
xrr2xhXD
*++bt|
wPDZ?@P
999FFFW
V0>~T^
!9uv}~hPa1,
X;NTt&
..DY8C:
AKs48AD
p6i&,;
^Lw;9r
5(5\#^
m/D`9n
q*f)9;
LqxzpF
<n_<t
#j`T,o
ItAVwD
%HtD=u
]G70%u
lYRPP0
AZT7;~
*xJP^w
w]a0vX-=
G=DlEU
rin!WPp
6`8>&t
,!4|MR(
#G^(hP
`\lVWU
e.`t%!
0y*.qdl
AN$gA(R
,:9~0t
9r d$T
[Ma0BD
xuqaAq
FFFENNNFFF
9^`t\8^=
73FD+NH
^Ln25uo
,*^X-#
}LtkI@
yz2_dh
fNQhpP
IuT 4PB
jHTlt;
<p.u14#
.2\YjGC
OKSLrr
hh@<V&
[h@t-j
SF[U}ap
-sQl7
x-*ZTn
KBT%.|
/cF0|"
QSGW:7
HVHHUb
6q/y$+
WPoJl'
P7xccW^i_3
X~[]_T
5?9>#0
_YN][8>tt
a@4oVT2
Mn6'n P
(~qGIt8Ftu
K,WOQg
xK;Ue$n,
X*}T|v
?989~8B]
zfVUF;
MU>^`r
=<nUt
3wXrVA
-Dm5|`
(pC0HC
20?LAh
E'fp@]1
_?;X5Wr
;FS~Xt.
NUOwPH
B/RL|@d
^j^d][z
Q^0&G9ht
s09H,Q
UFy+}J
n!*\hM
VhAjAA
}QUKUO
8v5TP(
*Yc} xa
6D zPS
PJpH.;
dhCc6i
w )8n
$+$@:PmU
$$%'
\488<r
\rDDHH
\rrPTTX
X\\\rr
``dd%'
\txx|r
g!B4a7
c)l`/'
0DXj~4M
46LXfv
%<0~gv+
\`7*u]
GenuineIntelAuth
ticAMDC
d`P@&dH
76C2$C542$C2$1(2$C2'&%C2$C$"
USER3_
'HWS/A
?DX<yv
@6`W8/
PrevExA
WGetDialogBaseUnit
ystemP(am
o)sInfoIMap-Rect
=Window
enToCli!u
ypAaLong
WBadStrNg
L>gthA
Kill([o
v`'E6BsC
.?AVCI
ivmcepti
@@/Unsuppor
T:$DATv
of memz
GlobalM}
#1?'UXTHEME
gENVwETUjPI\
ROPSYSQ
CRYPTBA&
:an noWpb74
`pcfil
l@!UTF-8!
31b?7qia
FyRunP
Qi[pcc
__MOZHSTOM
+=Oae4M
4M9K]o
JFUQU%
dTUUU2
LeaveCriP
>alS@4
ToWid
G>Last
ApisANSI
Libr5y
X{lAGModW?N7
U[qmaY
CloseHandlAS
'Att(bu$sW
PTcAdd
kCount"Th
fM5W-e
6%yMCk
GP]Aldc
BUVeea
iTizJ(
r37nmk]
@@YAXXZ
fdivp
?Lxat$lfp9
og/FJa
myjpu4alo
XPTPSW
B0E&L?<
bN@5'a
4iaL3/
PynNu3
hvZrjZ6
T%|t+-9
;;pG 
&x5eaG
=n-?fG
?>Ri,Q
C?<T.~
u;,fM\M
g{jr=
vAI)U[?
Jorze}Xv!3
WqeZv/}
E>).r8
l$4q,L
+3i\Ytmg
Uq|?\[
CY>dG@
KVZp#*X
aC[uXw
dZL1#1
JKFqGP
=t|ht;
"lG}NB
s/.sF7ZBB
~:>^Lm
(c6FwC
y5Q"aD
8>&lM~
rCN^n(
&7]}R9
dIA6UUiaP
!q`+E;
A7b%%N
iGK^a)g
=@/tQ^8
'SNoiY$0
\`xaS#
'.6n:!rY9
4'Gs[M
-]70#)C
Al^P4F
Q~x9 x
E$&>-N
)mIDAT
!jE.s
[O?,h
8Q~,v+;
$`P!hl
SH%O~Pp
ASA)#n6
2^[cZn
0dx(.v
D}V/&S
@9(p\\
tn^i5_3z
X"G#we
fdh,-]^
DQ!XeJ
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="7zS.sfx.exe" type="win32"/>
<description>7-Zip Self-extracting Archive v18.05</description>
<dependency>
<dependentAssembly>
<assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"/>
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
</application>
</compatibility>
<application xmlns="urn:schemas-microsoft-com:asm.v3"><windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
</application>
</assembly>
KERNEL32.DLL
MSVCRT.dll
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
;!@Install@!UTF-8!
Title="Mozilla Firefox"
RunProgram="setup-stub.exe"
;!@InstallEnd@!7z
n|a#q=J
d\8v[;t
`Hua1.
p<hkkI
Ohb"~w
>l;~HNq
<W^LA!6
aQee2~
K0B$WrJ*Mt
?[u\@&Z
5oa:ga
,d'rxS=\dF
%T8pmg
s}F%.s4
#&'J9WZD
~~k/sx
\(|#,]A
)O2>G\
bclP#8
N??(*g
#Odtzf
<qxNkl
7Hv r%
xS5D
FGYu0-
%"}p}F
c$Ao<]
QxtHE2
>K~Wj?
-?JT`5
"."NzD
yJJHVG
]av9vD
\)a.itK%!\
^hH ,a=8
{3:#@U
ff_=DN
5:K(o|
MZuYN
F$I87h
b\yCsFtx
p&<Jx|
#cZVg|
d{XOiB%
n3=KC\
DyIA+n
x5i2=5
,G0':LT7
5I!L?ha
K\Ei(M
QePoEz0
(SyJ6w_
E+MY9
e~$>.I
sms=d_
4`+;!o
8jhdoY
FMw$/pf
Se!r|w9
ZSFZ3j)
vi*1oF
@Z=9:0J%
JT5B4Q
BTwKJw
[|`f'qqk(
~ZE D"
?LmZB9
z)'M%]
9snXc%
IPOs>u7
t?4agzy1
<\QziJ
c[^vP'
7z;M}_}
v|0MuQ
sNfb#):
V+W =R8
a0!a6,0
):i#h(
#;/23%g
3wex#u
DSB*]E
3s0$Da
@qms6
f#~\AM
p/,ew]3b
BVb:\9V
C(;KgW"6
&!rHXF
qbkwjJh*
mJC|uQ
K/6-7_
56?@4e
S:?p`s20
G,rn3{
z@6E;1>1
\3`o>]
+7WQM+A
N!$-z]
MgLj]Uw-
vV<ID
?_K?C5
Sc6i+;jk
LI7FcQ
gmXN=JB
lqZ-%"
^!6kCK7
E2sw\6
Xb=`0u)
F(3r(rr\
jJp7lb
nF<@>d
i50T7$
ga;[-W
;ByH31
KrO: =v
t+?NjE
OGUM(
>d(56T
0G_4<c
|hn8cWj
'N2TR]E
, 4z8I7vVLW%ro
U23Tf5
(>Z1-y8]
4>-. PGW
dbM\$zO
S`So{4=
!RNw{ae
z34)g8
kFNZLC_Z
C}vrPi
<+h_~@]
/KpvKJ>F18
>Z Qn7,'
Q#YxlW
Owt2?d6
dxl="]
]>Qgv\
!WXj`o
-vPQ(H
XH*6d7e
;6eOQr
`@ZrM<=
QX0Enmtg
JKqo{t
<].ph`
^7Rz7E
&F7#V*
C3{<Zhgu7
TQ`HV4X
'Upr<Y
jixv@|
Bs=^U'Gn
4An3eaL
.&[JqB
3ckn3c
h/[}G)
{aUR-h
A;1{id
)y,x53H
6Q-QFaM
^^<zG+
+j,GE,
sg6`p:
?|L_Du
||-c}2
%jp`w]
\NO{Hc!f
8]!yfiF
}&-_Usc
l0zeKa
Ou;\t9
S~)&X3
noZcEDkrdf
&wtL&{eH
4UzgUhO
72\jdP
'CL.</S2
EZ-fIT
F+:0\*
7ih%*z
MGL%rT
7i,;_BC
,G5wo*
]Z_7ov?a
a^16,5
&xu^d
sK aVQ/
:[r=VI
m;kFQWK
{^=\Gps
8nHB'd2;N
O((,zp
N"1Y+g
0(Ux+@
WfLXS}
S}^;ag
X&Hf}B
|`N6uN
yU&EX0#
iJOAFw
xFK,@O
fL>9rO
-y2.MK
zVju)V
=L"{Fv
pG3)78y
wzs_7kr
[A4B{/c
}8{pnx=
q/bty}u
-LrxHK.y
6L^QcR
G\>CuN
vxV?=@]}
K&QAnTA
O|]^0Y
}>qZ=
}${Z<W
"_5o)j
=6ih_w>
N;2A?u
C7?x3Mh
pf!vsrpk
=?X%D6(d
|$eg)
xOgz050D
;%:" $F
X+?"2gz
MJsTc-?R$
*Ou,0l
p!ML3eFG
7`nq=}
7J0\j5
@a3oEd
X)8+ B
Okvkz1u
b<1$+,
w?1izk
R@~yt$d
M!`?JE
"7+j%B*7q
$$3~Mm
K`X,5,
g~\r==n
;t*GA+R
[$MSFE
H$kCMV
[N=vN4C
Apo^xG
3M08ass
Vh1fnj,
WS-,9pt]
ZML#xJ
0&&qikc
lZp!@0
gNW3Y:
&QU]GL
v~LA_:i
K&g1B^
'O{HeV
,w;5{3l
C5ce3
zeyXTk
27q@_D
P~x(]z
0sDf)-c
{8|C;5$
-9MbD{
T*06Ot8>
4iUBno
Kj,QnBR
sNLcsA
O<f~hh 6?
x<|s-?
Y]Ksv):
l8g'fx
6kKDcvs%
Vo3O1qn
eHIBCw
f!&,,
;L>&Qyr
=e]ch
cn,3{^
_AB n/
;e3]+O
8xjaZa
EeZ:dL
Gd1:&D
bSIGqZ
\~_ly}1
78e%IR
_=*H7_u
<z/0K
0 `2Ai/
nSt<u
0<He0F
(NHG!da
.Y3M)LA
WX0]Hc
3/>2;f
|"LZ{*ry{
'MjH26
(G)vXb/_
?RG]Vi
->:)yP?
CJnt49
IGp(fm
D:/rfJ
_~[hH,
:c_vjU
N3&1VU#
mBVKr{
Vq4NR<
Dfg_YN
b>]Z ~*
xH0Z'k
S!T0Kn'
E`sxS;%
im;@o(
J$&,F9
'6QRF]
gOZud:m
R,&6@
If^/jn
?|>w#(
9OOi3R
7;N-+9
j(It>3|
e #D%mO
es.|%
c-<cyy
bYhY2K
E7#Vv2t>K+
X-!%1,Q9
Q2%1f6
Pphv?+
VN@hc/
~daMKS)
b4oj(e
.?\P]R
)n>J66
ihn7C>
a~o=u<M
s#,y2g
ZtOng
H?cUGgsQ
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
061110000000Z
311110000000Z0e1
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
131022120000Z
281022120000Z0r1
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
p1f3q>
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
4http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0O
https://www.digicert.com/CPS0
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA0
210409000000Z
240619235959Z0
California1
Mountain View1
Mozilla Corporation1'0%
Firefox Engineering Operations1
Mozilla Corporation0
/http://crl3.digicert.com/sha2-assured-cs-g1.crl05
/http://crl4.digicert.com/sha2-assured-cs-g1.crl0K
http://www.digicert.com/CPS0
http://ocsp.digicert.com0N
Bhttp://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
Dummy0
130101070000Z
130102070000Z0
Dummy0
__MOZCUSTOM__:
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
220921000000Z
331121235959Z0F1
DigiCert1$0"
DigiCert Timestamp 2022 - 20
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
DigiCert Inc1
www.digicert.com110/
(DigiCert SHA2 Assured ID Code Signing CA
230227212728Z0
https://mozilla.org0/
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
230227212728Z0/
4y|R:a
("T^A7l}
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Mozilla
FileDescription
Firefox
FileVersion
InternalName
7zS.sfx
LegalCopyright
Mozilla
OriginalFilename
7zS.sfx.exe
ProductName
Firefox
ProductVersion
VarFileInfo
Translation
setup-stub.exe
<<<Obsolete>>
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
DrWeb Clean
MicroWorld-eScan Clean
ClamAV Clean
FireEye Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike Clean
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec Clean
tehtris Clean
ESET-NOD32 Clean
APEX Clean
Paloalto Clean
Cynet Clean
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine Clean
CMC Clean
Sophos Clean
SentinelOne Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
TACHYON Clean
DeepInstinct Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
AVG Clean
Cybereason Clean
Avast Clean
No IRMA results available.