Static | ZeroBOX

PE Compile Time

2023-02-01 11:14:24

PE Imphash

d3bf781bd66135a7bd8deadf2ada0204

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00057000 0x00000000 0.0
UPX1 0x00058000 0x00024000 0x00023600 7.92691473578
.rsrc 0x0007c000 0x00001000 0x00000600 2.94424415583

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x0007c05c 0x00000278 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library ADVAPI32.dll:
0x47c360 RegFlushKey
Library KERNEL32.DLL:
0x47c368 LoadLibraryA
0x47c36c ExitProcess
0x47c370 GetProcAddress
0x47c374 VirtualProtect
Library SHELL32.dll:
0x47c37c None
Library SHLWAPI.dll:
0x47c384 PathFileExistsA
Library USER32.dll:
0x47c38c wsprintfA
Library WINSPOOL.DRV:
0x47c394 AddMonitorA

!This program cannot be run in DOS mode.
'Rich=
l(z-<<
-$Pdhv
*n'Pc4
quk5,r(
NCb0<u'<
A[[Y*p]p
AZH8 U
NhUeFj
Ppj-fi
;X)i6S7
P!N%)[9v
uRFGHt
#S.E/V
X2 e!n
/? /@F
qW9BN0
@b$.##
b*NSQI
K9h"\p
@NQ QI
,CwutEc+
w@u[W+
5v]0P?(F
a$Z&=D8
WH(VRv*
b$g'x:
Dj=}?>Otd
"^*g:^
?nt_V;Q
S3x0*1
PbHC;FS
VNZ [
b P+oUQ
t(!AO
@B8R*XLHX
%vm0v@
"aru]#
!+J,%'
uhQERQ
c7C`;5
>A#u-V
V^YF~On
E4SCQD
SQ%g+TW$
/*x[*1
<<DWY/
^}%95v~
"~X=K9
x5`bk9D
8t9UWs
<SS?QP
pR.!KI
TNnt>j,
ScBQji
7.o-g~,
ADjvd7-l
sO;>|C;
d~O2npaP
YM0|"FN
FQQC]Y[
Vi^9p`t]j
j\M4t*j
FKl\3H
WL$&it
9U-x*,h
w+@'Y+
\YYoX|
Y'Sr,OF8(H
;T$XIm
yVh r|
P8P0x(
"|{Q;
ttJ0B=`
7R*L(;
,0U=[,
sHP9|t^
^IZrg
jStPhd!
rKoRG2
:&@1#1
@1hY=A`
U-`WtDXZy
RuvIF<
TKzS%"d
/~DN@t
p)),n|
`9*tc}^
l\J8(<
_GLOBAL_H@
EAP_SELECTED
.MSVCRT
]gruntime error
SINGnOMA$#on
OR6028
ablto i
heapoO7
ugh spacFf
#std5p
urVvirtuBfJcGGH
G7mult
7^lock/
-idna\
\W8arguQs>A
rf*Visk
[UC++ RALibr
0hsbZssF
d@KERw
N@32ie+0
modmhy
log10k
Box^ufrR.d
1#QNAN
DS/H:m`]
Sept)A
Th$s'W
wo_OG>
"0>L[`0
SAGDI1
?360532A4C47797E747F6763L
722655
"*5687`O
B24B11
2OK5.D
`N62rN7B
Ocmd.exe)
can be
@_RDAT
HhM3XA
pppCbwB
0HZph6"8HH
L7h8 ,&iu7
.t)ryu
c-`#
4#fue
>7Z\3l
hUAVAo
7"_8M+
nD8;3.
ms.J[0
A_A^J]
5jw~A0
N,I;6u`
TL*Z>_
}.J@MP`pI\
;_g_|}SV
u3HcH<H
nU6~Zt
BHr}@@
#hA*+/
MGUV>C
q9y@M`'v0
F# 2rnR
T*#P`h@p
97u+A^N
ZRZZZ
@PP``0
:$Yb0.
98.N~D
70$P&A
i(!"3
&nHbc=
WfX.m@0
p@lsd`)
V%CV:l6H
=7%\.~
ct6sR3|
u/M=qL
Z\9f2~
\'O!2;
x{]>@%
.H0{u~w*a
t7X`2
QVpw.t
w<e&(0\
=aD`pKv
zBp2~`B
2P@D|W
H}-"I;
8=ftt,$
@2Lc<X^
vl@ 17A
<X5p*4
>K "zK(#
VD6;y0%p
|H2):.
v*uwz~!
l&8QPp
-<6*VA>*AL
AyH{H}U`
@$6(b
ll1Yi[0
.D9999\l~
2N''''l
@D_Hv!
B`?rr
X''''
_based(
cdecl.pg
5-^ftv
wift_1
2ptrv
rerictun
ignv;
[]_opera
,()~^f|
o[p`tybof-.lo0
d7`-ng
A3`]]`
d:p c!
t"nM`EH
sx?ISYh
wmDfL=?
s;Z ({
ymous/BV
eZVQD
ACPgR/S
po0*Rf2
^7j_+p&ofe[]
(m'AreFileApisANS9bg
LCMapS
$ToFID
olicyZ
vrr(08
0@NNNNPh
_Jov[{
 !"#$%&'()*+,-./012345
6789:;f?@ab
`fghijklmnopqrstuvwxyz[\?
`?{|}~
ABCDEFGHIJKLMNOPQRSTUVWX`H
NnAF89
? NNNN@(A0NNNNC8D@NNNNFHGPNNNNIXJ`NNNNKhNpNNNNOxP
2(NNNN485HNNNN6X7hNNNN8x9
'''#E F0''''G@IP''''J`Kp''''L
NNNn`
> C''''0kH
AFhLx2
vrnnpp_
7l9r?h
cm>StT
Ch_HyG
K7?vt
oC`oonC/
.C_K?n
(.vP?Q
o!?0c'
?@DNNNnP}`
?8O8999
?a''''
hP''''
r 99991
xhQ899:
'?rrr2g
*_5?Hmb N|
NN8p/oE:Br
hdb@>
m?qK%6
bg@>X[
6sg| 
Y0X./_
=imb;D
>`~K
~58d%/
>jtm}S
;H9>&9
uzKs@>
@ 7zQ6$
ERSDS7 0
:\Dll1
\x64\RP
!2.inJK
$5Wn(^cfgN[
K6'('m[
Exz.rid
seHandle
Fold~P
A2LWAPI
lCaptuO
UnwP`x
+SysnmTi
SLiBHM
#Modulc
eSd;;$
fc',%^
yANyTi
+I`q$_
5u<POPj4P
uTLMb#6|1V
iqd!\,;
: 2!0
6n7S:0;\=e
|>>f@uAlC
u n!tU*
"#o$%'
(l+,w0v1i'(
H`os@e
@Qb|6g
?Z^~/o
PWyKTAQ:
g[E_Z\+
f9]$uarjW
}U=h@7
,/0456
A<i}!9o
ect.G
| r"u#p$
< e,50h
4V<sxP
A^3/P.
?ACEGh
VXZ\^F
n8y2IN
?T@EAMDuEr
FGeHnLN]Wyv1PlRV
F:GK^+
k6_va0
y//dowS
*nj+.,f-
5ML6t7
M8g9vL;
8kX9s:
Whl?Tw
D67989
M~|<~l
lBrCedM
Kg&LMA
nRWlCf
AcBtCGro
32 .!
+a,t-H.TB
%Sz|^f
B0<Om~3
tMvzwix
ynza{/|4
t&?e@rAB
LMEtXOe
4PQnS1TO<
vUpnUrN
"WININ
:;`abv
|hRijaDkd
lFmWopj
Ph@t%\
k/$I8.v!S
0y0a;aD
`{YAXP
_h{3H/
acmnC0
X~getH
6sOkfk
j$ffdiv
jPXT|f
3mpiAa
/Av=QZO
@`?9TokD
RLD.nl(rxE
pMgSvc?Mi
SYSTEM\V
@_"go$
>stbYp
MHKHARDW
IPTION\
_v3.0.303ZT'
\{4D36E968-E
5-11CE-BFC
-a gr -o
eE8GuwY2Myjy29wMZmm5Z2V5
fbvBhdgJp x`max-cpuf8
DOWS\T
wNFNO`
i>F-?1#
K>eRf*cr{
RpRf>OSig
='1.0'
UTF-8
da,$yesdJ!
:sch&0-m
B8:X2x
+KT%F4#I`[
u'6u#SP/
%0<`4^
LEj%X}
i&xq:|
Q]0cvv
J 0@P`
}En &s
4gPr<+>
68]4dR
F ,n00
^0f@nPv`|
4@NBR-m
T>;hl!h
8(stTS@
czK)
LX Z7
/FLY;(a
Pen'@$
$X[Zo
)#tI222RD26/
h(8RVo
1TeS_P
DUVn$$h c
0-9H' Q
=pkZFVop
f <SAG
P08TK"
:PFE>
H@8iFN
&h ?nsc
`,P(He
f"'$rX~
KfQwQz
f"#h'K0"
uJ%v 0
dY/SXM
vjk9".(
,>Rjv<
!AbHX191U1$
ia+:!aYp
)!U'$,
FHXQ^w
AX@!$1
y,04^<H
! "(#y
y0$8%@
X*`+h,y
6@7L8X<
<9d:p;
$N0O<Py
yHRTV`
,T;l>x>
JSiP0\0h
ekw96mqm
aB_OX2C
AEWpraB
YQ5\2[/PQ
PD^\}h
oj=77/
$=ob=N
xP)on)
/_d!L;
.nn];Zrr/
o%S#[k
#.X'HBO
rBN(e@#
aw9taa
NG?oh,
f@or?y0
ICOPwT$
XO`'Ad
)dsU!c!i1y
0?0D0R0
0%1C1k1x1~1
142U2v2
2?3k3x3
4F4P4^4y4
7 7*7:7J7Z7c7
:":(:.:4:I:^:e:k:}:
;<)<B<K<P<c<w<|<
.>]>f>o>}>
,Y5g5m5
6.6:6V6vE4
9?9D9H9L9P9
<!=<=A
=F=a=nw=|=
>>+>0>0(
,0B0^0
d1:1N1
3P3^3g3
:<:B:PFq:
;#<+<2<p=
1/1D1V1c1|1
3!3.3G3t3{3
5'6Z6m
8o;U<3=Z=
5Q5]5o"
&'C6^"
<F<R<f
='=7=K=P=U=r=
>g>l>q>
>?A?e?|?
5%6-6EJ[6s6
2:F:z:
0'132s*
E=W=i={=
484Cfb4
4G5\5e
5!6@6q6
L1X1\1`1t
PB`2h2p2x2
3 3(>8o
P3X3`3h3p
X4`4h4p4x4
n;$;(;
@=D=H=L
d=l=p=t
?,?0?4
<?@?D?H?L?P?T?X
>DBLFTJ
\NdRlVtZ
5 5$5(5,6T
M6H5L5P5T5X
`5d5h5l5p
5t5x5|5
0$0,LX
L0T0\0d0l0t0|
J,1N<1DTJ
"<&L2T2\2d2l2t2|2
,343<3D3L3T3\3d3l
^PZh1p1xOOM
NH6P6X6`6h6p6x
1>1B1F*:T:\:d:l:t:|:
F T>>>>>t6
ie]di!!
+e%i=k
Q,k1mF
ti.bat=waO5
\lsma22
(hoyUT
KuGouMus
aims_\P'
6$Bac%
HKEY_CLASSES_ROOTURRENT_
Z#LOC%
FMACH?
%9S_CONFI
3MULTI
RIANLKI
DLpdvapi
B`c4xs`
IsU2AnXmi
qquiG)L
,l\ =w
figPLb9
6njW-U2V
+(8gTEn
*s %d.
lfI64d
PrlRROR
"h#d$=
yplhd`
Lxx@o
hh1ES
^#k$ts
PchGTH{
*nslx%
XPTPSW
ADVAPI32.dll
KERNEL32.DLL
SHELL32.dll
SHLWAPI.dll
USER32.dll
WINSPOOL.DRV
RegFlushKey
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
PathFileExistsA
wsprintfA
AddMonitorA
VS_VERSION_INFO
StringFileInfo
080404B0
FileVersion
1.0.0.0
FileDescription
MSSQL SERVER
ProductName
MSSQL SERVER
ProductVersion
1.0.0.0
CompanyName
MSSQL SERVER
LegalCopyright
MSSQL SERVER 2020
Comments
MSSQL SERVER
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Generic.4!c
Elastic malicious (moderate confidence)
MicroWorld-eScan Trojan.GenericKD.65442288
ClamAV Win.Dropper.Tiggre-9845940-0
FireEye Generic.mg.30000f8e4ee5bce9
CAT-QuickHeal Backdoor.Lotok
ALYac Trojan.GenericKD.65442288
Malwarebytes Trojan.CoinMiner
Zillya Trojan.CoinMiner.Win32.48067
Sangfor Trojan.Win32.Save.a
K7AntiVirus CryptoMiner ( 00593f811 )
BitDefender Trojan.GenericKD.65442288
K7GW CryptoMiner ( 00593f811 )
CrowdStrike win/malicious_confidence_100% (W)
Baidu Clean
VirIT Clean
Cyren W32/ABRisk.LRZF-0814
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/CoinMiner.CIB
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Generic
Alibaba Trojan:Win32/Redosdru.b9ae8141
NANO-Antivirus Trojan.Win32.Inject4.juvirf
ViRobot Trojan.Win32.Z.Coinminer.147456
Rising Trojan.CoinMiner!8.30A (TFE:5:liJqKmSiZsG)
Emsisoft Trojan.GenericKD.65442288 (B)
F-Secure Clean
DrWeb Trojan.Inject4.51715
VIPRE Trojan.GenericKD.65442288
TrendMicro Trojan.Win32.REDOSDRU.USASHC223
McAfee-GW-Edition BehavesLike.Win32.Dropper.cc
Trapmine malicious.high.ml.score
CMC Clean
Sophos BlackMoon Packed (PUA)
Ikarus Trojan.Win32.CoinMiner
GData Win32.Trojan.Agent.WP
Jiangmin Clean
Webroot W32.Malware.Gen
Avira HEUR/AGEN.1212181
MAX malware (ai score=83)
Antiy-AVL Trojan[Banker]/Win32.BlackMoon.a
Gridinsoft Clean
Xcitium Malware@#3mcflnpl4b58a
Arcabit Trojan.Generic.D3E691F0
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Redosdru.W
Google Detected
AhnLab-V3 Trojan/Win.Generic.R478332
Acronis Clean
McAfee Artemis!30000F8E4EE5
TACHYON Clean
VBA32 BScope.Trojan.Scar
Cylance unsafe
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.REDOSDRU.USASHC223
Tencent Win32.Trojan.Coinminer.Cplw
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.1728101.susgen
Fortinet W32/CoinMiner.WP!tr
BitDefenderTheta Gen:NN.ZexaF.36308.jmKfaGYrGVbb
AVG FileRepMalware [Misc]
Avast FileRepMalware [Misc]
No IRMA results available.