Static | ZeroBOX

PE Compile Time

2023-10-09 18:26:29

PE Imphash

ad876c7addc49a2092c59c2b00afb352

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00010cff 0x00010e00 6.68442595292
.rdata 0x00012000 0x0001be5a 0x0001c000 7.18806559225
.data 0x0002e000 0x0001a2ac 0x00019800 4.8588718065
.gfids 0x00049000 0x000000ac 0x00000200 1.45595804114
.rsrc 0x0004a000 0x000001e0 0x00000200 4.71377258295
.reloc 0x0004b000 0x000013d0 0x00001400 6.64936739959

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0004a060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x412000 GetProcessHeap
0x412004 CreateFileA
0x412008 CloseHandle
0x41200c GetLastError
0x412014 GetCurrentActCtx
0x412018 HeapWalk
0x41201c CreateThread
0x412020 GetModuleFileNameA
0x412024 DeleteFileA
0x412028 CreateNamedPipeA
0x41202c ExitProcess
0x412030 VirtualAlloc
0x412034 GetNamedPipeInfo
0x41203c MultiByteToWideChar
0x412040 ExitThread
0x412048 DecodePointer
0x412050 IsDebuggerPresent
0x41205c GetCurrentProcess
0x412060 TerminateProcess
0x412064 SetLastError
0x412068 GetCurrentThreadId
0x41206c RaiseException
0x412070 HeapAlloc
0x412074 HeapFree
0x412078 GetModuleHandleW
0x41207c GetProcAddress
0x412084 TlsAlloc
0x412088 TlsGetValue
0x41208c TlsSetValue
0x412090 TlsFree
0x412098 FreeLibrary
0x41209c LoadLibraryExW
0x4120a0 LCMapStringW
0x4120b0 IsValidCodePage
0x4120b4 GetACP
0x4120b8 GetOEMCP
0x4120bc GetCPInfo
0x4120c0 GetModuleHandleExW
0x4120c4 GetStringTypeW
0x4120c8 WideCharToMultiByte
0x4120cc HeapSize
0x4120d0 HeapReAlloc
0x4120d4 GetStartupInfoW
0x4120dc GetCurrentProcessId
0x4120e0 InitializeSListHead
0x4120e4 RtlUnwind
0x4120e8 GetStdHandle
0x4120ec WriteFile
0x4120f0 GetModuleFileNameW
0x4120f4 FindClose
0x4120f8 FindFirstFileExW
0x4120fc FindNextFileW
0x412100 GetCommandLineA
0x412104 GetCommandLineW
0x412110 SetStdHandle
0x412114 GetFileType
0x412118 FlushFileBuffers
0x41211c GetConsoleCP
0x412120 GetConsoleMode
0x412124 SetFilePointerEx
0x412128 WriteConsoleW
0x41212c CreateFileW

!This program cannot be run in DOS mode.
`.rdata
@.data
.gfids
@.rsrc
@.reloc
l$,;L$`
D$(+L$
PVQRWS
AQRVPW
D$,9L$0
PQRVWS
_^][YY
D$pO;|$
D$pO;|$
T$d;\$l
} ;T$d
} ;T$d
<B;l$$r
D$pK;\$
J;l$$r
D$pK;\$
T$d;\$l
T$d;T$
;\$HsR
T$d;T$
l$d;l$
l$d;l$
T$d;T$
l$d;l$
l$d;l$
D$pJ;T$
t$d+L$t
D$pK;\$
T$d;\$l
T$d;T$(
T$d;T$(~#
t$d;t$(|
t$d;t$(
;L$(|R
L$H;L$
L$d;L$(
L$H;L$
L$H;L$
t$d;t$(|
t$d;t$(
D$pI;L$
Z;L$,r
y;l$0r
T$d;L$l
D$XUWP
s:+T$,9
9A,w,+A,UW
T$@jwf
t$(#t$
F<+BX+F|
PQRVWS
PQRVWSU
PQURVWS
PQRVWSU
PQURVW
#Ht9L$8
QRVWSU
PQURVW
L$43L$P
PQURVW
B<+Bp53
|$ 3\$
SSVWh
YYhx!A
PPPPPWS
PP9E u:PPVWP
u&hL}D
URPQQh
;t$,v-
UQPXY]Y[
j"^f91j\^u8
j"^f9q
t/j=[f;
taj*Xf
VWj\^j:
WWWPWS
f9:t!V
QQSWj0j@
PPPPPPPP
F(;F<t
3Fp5Le
D$$PQRj
\$$f1DJ
L$<f+T
3D$(5]
l$\PRVWSU
L$43D$8+D$
L$\_^]
fAPRVf
9D$,t]
D$ _^][
K~D(<+
05QB%}1
<o-KV$
-|o.~Y
UFHx7!o+
{h}^To)
|RLKgP
6 5Erc
`ZHTa3
)i6Se`ld
m3AuZ/imF
c:NmXN
VAET|S
A\UT"L
TD,dih
_DRKo$
(S."TF`V1
O{[>*\
gP|p~RAR
Qa>&!=3
<^b,+KN
9*84|c
M/F}&\
zGgDRH.
+e@U?{
>m2Hv"
uLX|LM
2%<4t3n
?:\DNe"
"_"<M*B
HRs-ew
If]Jlx
_6KDzn
5e7Q`+[
3n}99Ib>
r;ew.I F
NOm3iKV^MiJ
2@^<s=t
'tefEK*/o\L
SV./z=
m>z;r}
H5L`O]^
pNQ?rD
yellow; door, expulsion; unrest
preparations, positively, winning, comic
colleague shops, visible.
m]o (#C
UUUUUU
333333
?333333
?UUUUUU
?$rxxx
RUUUUU
?ZEM-'^
?{yK+;
?765@Z
?e')lW
i^^?(>
Y:/(A6>
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
GetCurrentPackageId
InitializeCriticalSectionEx
LCMapStringEx
LocaleNameToLCID
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
?8bunz8
?/]7X&
?8bunz8
?'# cP
?ulsZ1
? m.S`
?1\q,_O
?p(/s5
?vmg$9e
?@En[vP
?VUUUUU
?VUUUUU
?VUUUUU
?VUUUUU
?VUUUUU
?VUUUUU
?VUUUUU
?VUUUUU
.text$ahrbqy
.text$bymgos
.text$cxfxse
.text$d
.text$dqfijg
.text$f
.text$fakfya
.text$fftpul
.text$fwrhkh
.text$gwgdbq
.text$jlxadd
.text$jnodxt
.text$jzugtt
.text$kmgxpp
.text$kvttsx
.text$ldvgbk
.text$lieyjg
.text$mifeig
.text$mn
.text$mpkisr
.text$nassix
.text$nnitxn
.text$nwignf
.text$ohuhaj
.text$okpnvc
.text$psdbrm
.text$qkrqro
.text$scssnz
.text$uesnmi
.text$vywkcr
.text$wgqysz
.text$wnnout
.text$xoyaqo
.text$xvpekh
.text$ykrfwz
.text$zxttqi
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.gfids$x
.gfids$y
.rsrc$01
.rsrc$02
GetProcessHeap
CreateFileA
CloseHandle
GetLastError
GetCurrentDirectoryA
GetCurrentActCtx
HeapWalk
CreateThread
GetModuleFileNameA
DeleteFileA
CreateNamedPipeA
ExitProcess
VirtualAlloc
GetNamedPipeInfo
GetNamedPipeHandleStateA
MultiByteToWideChar
ExitThread
SetHandleInformation
KERNEL32.dll
DecodePointer
IsProcessorFeaturePresent
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
SetLastError
GetCurrentThreadId
RaiseException
HeapAlloc
HeapFree
GetModuleHandleW
GetProcAddress
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
FreeLibrary
LoadLibraryExW
LCMapStringW
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetModuleHandleExW
GetStringTypeW
WideCharToMultiByte
HeapSize
HeapReAlloc
GetStartupInfoW
QueryPerformanceCounter
GetCurrentProcessId
InitializeSListHead
RtlUnwind
GetStdHandle
WriteFile
GetModuleFileNameW
FindClose
FindFirstFileExW
FindNextFileW
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
FlushFileBuffers
GetConsoleCP
GetConsoleMode
SetFilePointerEx
WriteConsoleW
CreateFileW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
0!0(020;0K0a0h0n0|0
1m2s2{2
2/3E3w3
3=4S4r4{4
555@5W5q5
6(6>6N6X6h6x607
5 5>5[5
556\6}6
8!8/848F8m8|8
9&9P9U9
=*=m=x=
>9>@>V>l>t>
?5?L?X?
1*191D1J1P1`1f1p1
2G3e3k3q3
4$434?4Y4d4
4K5Q5m5
56%6.6:6N6q6
7 7%7C7}7
7(8S8k8p8~8
8)9L9^9
:6:f:r:{:
;&;4;9;@;E;M;S;j;p;u;
<,<1<<<P<Y<d<p<
=.=4=E=q=v=
1%1H1c1
2,2@2P2\2e2
3D5L5q5y5
5Y6c6u6
7 7>7J7V7b7
848>8F8g8{8
8$939;9A9X9^9o9
: ;J;R;o;
;9<D<O<U<^<
=:=e=}=
3/3T3x3q4_5i5v5
6e6l6u6
6&7q7m8
9&:7:R:^:o:x:
g0j1{1
4H4X4o4w4
55$5)5D5N5j5u5z5
6!6&6+6I6S6o6z6
7=7Y7d7i7n7
8'858D8h8z8
:%;^;t;
<'<@<m<t<
<K=T=\=
>/>9>J>O>d>
2!252@2W2
23U3h3
6+8>8Z8
:$:d:v:|:
:U;\;c;j;w;
<:=C=[=m=
>2>V>q>|>
0)0;0M0_0q0
5i6t6~6
727<7_7i7
0B0S0X0]0~0
1_2h2p2
3$3-3d3
4.484I4o4
6'6.6N6T6Z6`6f6l6s6z6
9*9P9e9l9r9
9 :(:A:{:
;D;J;p;y;
=W>_>q>
1;2@2D2H2L2
5(6Y6k6u6
717=7y7
898I8N8S8z8
949<9A9Q9[9
;#;\;f;l;r;
;<*<0>^>c>
0"0'01060A0L0^0g0
111d1s1x1
9E9T9b9
:";R;m;
<(=S=u=
343C3Q3]3i3w3
4%4;4O4g4
7@9T9/:N:S:
;(;/;E;[;h;m;{;
>"?Y?x?
5M6g6t6
7H8R8|89
? ?1?o?
4$676U6c6
8H8O8T8X8\8`8
>'>0>?>D>L>f>w>
1"1-1F1c1h1s1
232E2U2k2p2
2%383^3u3
4'464?4I4x4}4
5N5Y5d5o5~5
6.6P6r6
747=7W7a7
858B8Z8i8~8
9#9.9B9M9V9n9w9
:#:,:2:;:D:N:j:w:
:=;C;H;N;T;l;r;w;
=!=-=L=f=
>">(>6>:>S>
?"?-?[?y?
0?0H0R0Z0`0j0v0
1N1X1_1v1
3+31363<3X3a3g3q3w3}3
4,4;4A4R4u4
5!626L6\6i6~6
6&717B7N7l7v7
8@8[8e8y8
9$959S9Y9c9n9w9
<&<2<G<P<U<g<
41<1H1L1P1T1X1d1h1l1
,949<9D9L9T9\9d9l9t9|9
:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:
@0D0H0L0
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=
P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>
@<H<P<T<X<\<`<d<h<l<t<x<|<
<j=n=r=v=
4@4`4
5 5(5,5H5h5
6$6(6D6H6h6
707P7l7p7
5(585H5`5l5p5t5
Bapi-ms-win-appmodel-runtime-l1-1-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-file-l2-1-1
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-kernel32-package-current-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
user32
Bja-JP
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
mscoree.dll
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
((((( H
CONOUT$
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Cutwail.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.f96c1d0accec84ab
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Infected.dh
McAfee Artemis!F96C1D0ACCEC
Malwarebytes Clean
VIPRE Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
CrowdStrike win/malicious_confidence_90% (W)
Baidu Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
ClamAV Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Tencent Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Clean
SentinelOne Static AI - Malicious PE
MAX Clean
GData Clean
Jiangmin Clean
Webroot Clean
Google Clean
Avira Clean
Varist Clean
Antiy-AVL Clean
Kingsoft malware.kb.a.992
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Cutwail.ACW!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Gen:NN.ZexaF.36738.syW@aWWv42mi
ALYac Clean
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Generic@AI.100 (RDML:2UDhQV/rd9gHxliBLrNBzA)
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
AVG FileRepMalware [Misc]
Cybereason malicious.e9f558
Avast FileRepMalware [Misc]
No IRMA results available.