Static | ZeroBOX

PE Compile Time

2023-12-04 05:13:11

PE Imphash

91452bf3259a3ff5928a3bb7f6be301a

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00010c56 0x00010e00 6.62976578324
.rdata 0x00012000 0x00006330 0x00006400 5.00091799071
.data 0x00019000 0x00001704 0x00000c00 2.11635701806
.rsrc 0x0001b000 0x000000f8 0x00000200 2.52495999013
.reloc 0x0001c000 0x00001300 0x00001400 6.49289639551

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x0001b060 0x00000091 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x10012000 GlobalAlloc
0x10012004 GlobalLock
0x10012008 GlobalUnlock
0x1001200c WideCharToMultiByte
0x10012010 Sleep
0x10012014 WriteConsoleW
0x10012018 CloseHandle
0x1001201c CreateFileW
0x10012020 SetFilePointerEx
0x10012024 GetConsoleMode
0x10012028 GetConsoleCP
0x1001202c WriteFile
0x10012030 FlushFileBuffers
0x10012034 SetStdHandle
0x10012038 HeapReAlloc
0x1001203c HeapSize
0x10012044 IsDebuggerPresent
0x10012050 GetStartupInfoW
0x10012054 GetModuleHandleW
0x1001205c GetCurrentProcessId
0x10012060 GetCurrentThreadId
0x10012068 InitializeSListHead
0x1001206c GetCurrentProcess
0x10012070 TerminateProcess
0x10012074 RaiseException
0x10012078 InterlockedFlushSList
0x1001207c GetLastError
0x10012080 SetLastError
0x10012084 EnterCriticalSection
0x10012088 LeaveCriticalSection
0x1001208c DeleteCriticalSection
0x10012090 RtlUnwind
0x10012098 TlsAlloc
0x1001209c TlsGetValue
0x100120a0 TlsSetValue
0x100120a4 TlsFree
0x100120a8 FreeLibrary
0x100120ac GetProcAddress
0x100120b0 LoadLibraryExW
0x100120b4 ExitProcess
0x100120b8 GetModuleHandleExW
0x100120bc GetModuleFileNameW
0x100120c0 HeapAlloc
0x100120c4 HeapFree
0x100120c8 FindClose
0x100120cc FindFirstFileExW
0x100120d0 FindNextFileW
0x100120d4 IsValidCodePage
0x100120d8 GetACP
0x100120dc GetOEMCP
0x100120e0 GetCPInfo
0x100120e4 GetCommandLineA
0x100120e8 GetCommandLineW
0x100120ec MultiByteToWideChar
0x100120f0 GetEnvironmentStringsW
0x100120f8 LCMapStringW
0x100120fc GetProcessHeap
0x10012100 GetStdHandle
0x10012104 GetFileType
0x10012108 GetStringTypeW
0x1001210c DecodePointer
Library USER32.dll:
0x10012114 EmptyClipboard
0x10012118 SetClipboardData
0x1001211c CloseClipboard
0x10012120 GetClipboardData
0x10012124 OpenClipboard
Library WININET.dll:
0x1001212c InternetOpenW
0x10012130 InternetConnectA
0x10012134 HttpOpenRequestA
0x10012138 HttpSendRequestA
0x1001213c InternetReadFile
0x10012140 InternetCloseHandle

Exports

Ordinal Address Name
1 0x100011a0 ??4CClipperDLL@@QAEAAV0@$$QAV0@@Z
2 0x100011a0 ??4CClipperDLL@@QAEAAV0@ABV0@@Z
3 0x10005480 Main
!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
E0SVW3
0VWj$h
URPQQh
;t$,v-
UQPXY]Y[
zSSSSj
f9:t!V
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
QQSVj8j@
bad allocation
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
Unknown exception
bad array new length
f7f36516fd699a26f0da3d64fdf9988f
465dbc52837d815b3bc29835a05e6d18
RPlTGdu0SlZ2Jjv0SF==
QZZU9g8O3CIOSHvqfL8kR0bnhJmu
3jOnUAZ0g6QjbmMpgvom6F0cgB 4WN==
QYui9Q8jh5z1Ky0kgbUl7F0pfKF=
jS0 6B4ggJgkbGAtgn8j7j==
QYxXHgnuVWIiaGzqfL8kR0bnhJmu
Content-Type: application/x-www-form-urlencoded
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789
abcdefghijklmnopqrstuvwxyz0123456789
13Ko3ZvuHfx3ESJNnNmcSe5gzmmZTcYdXy
0x619B7A2AdFA73f224Cf3D3Fa6Adf644a8f2698f7
LRfywbm9Rg8KuoHQUf9V6Z6dVBNGQuKALK
D6uWuYJfWJdEZLf6sNcK3WmWXc7oac5XBt
4AhxCXJYG9mZCf8o7e2TneeDXASpzyGRddf51u7stARxaGwDjvP5x9R8VPkkLeYsyjW7YZfQofzQAc9YGH5baEkYHDT8VWu
invalid string position
string too long
.text$di
.text$mn
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.rsrc$01
.rsrc$02
CLIPPERDLL.dll
??4CClipperDLL@@QAEAAV0@$$QAV0@@Z
??4CClipperDLL@@QAEAAV0@ABV0@@Z
GlobalAlloc
GlobalLock
GlobalUnlock
WideCharToMultiByte
KERNEL32.dll
OpenClipboard
EmptyClipboard
SetClipboardData
CloseClipboard
GetClipboardData
USER32.dll
InternetOpenW
InternetConnectA
HttpOpenRequestA
HttpSendRequestA
InternetReadFile
InternetCloseHandle
WININET.dll
IsProcessorFeaturePresent
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
GetModuleHandleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
GetCurrentProcess
TerminateProcess
RaiseException
InterlockedFlushSList
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
RtlUnwind
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
ExitProcess
GetModuleHandleExW
GetModuleFileNameW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
GetEnvironmentStringsW
FreeEnvironmentStringsW
LCMapStringW
GetProcessHeap
GetStdHandle
GetFileType
GetStringTypeW
HeapSize
HeapReAlloc
SetStdHandle
FlushFileBuffers
WriteFile
GetConsoleCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVexception@std@@
.?AVbad_alloc@std@@
.?AVbad_array_new_length@std@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
</assembly>
0#0(020C0H0R0c0h0r0
1!13181B1Q1a1q1
1%2M2S2o2
223k3q3
8&8E8]8q8y8
;I;b;n;v;
5P6`6t6
:-:e:k:r:x:
;.;6;@;o;y;
<#<R<\<f<q<~<
>O>V>c>z>
1#1[1a1h1n1w1
2$2,262e2o2y2
3H3R3\3g3t3
384B4{4
5E5L5Y5p5w5}5
8Q8W8^8d8m8|8
9"9,9[9e9o9z9
:>:H:R:]:j:
<%<7<_<
=/=>=Q=c=
=!>D>[>j>}>
2J4b4!:
=%?+?J?u?
040T0|0
2@2f2u2
3<4h4u4
5C5M5[5v5
7X7k7u7$8-858p8z8
9$9+9>9:?:I:b:q:
;U;^;e;k;q;};
<$</<6<V<\<b<h<n<t<{<
3#3>3f3z3
4,4:4A4G4u4
686O6]6i6u6
7#7(7C7P7Y7^7c7~7
888H8\8e8
8F9c9o9
1&2k2p2t2x2|2
6H6Y6d6
;/;M;e;
?%?s?{?
60D0M0
2-343_4
8b8f8n8z8
9%9C9\9a9
?1?K?c?j?
080_0t0
1 121?1X1i1s1
3 363@3c3m3
3(4A4n4u4
7S7;:!;
;&<\<m>
3#4/4A4
;.;D;j;
<:<^<r<w<|<
=$=/=4=9=W=f=q=v={=
>->D>I>T>{>
191Q1o1z1
1L2Q2V2[2m2-3
4M5g5l5R7l7{7
8)868D8R8]8s8
?+?=?O?a?s?
1f2+3X3
<!<)<R<Y<u<|<
9+9A9N9S9a9
=(>G>S>
=0W0d0
1p2v2{2
5I5Q5Y5a5i5
;K<L=\=m=u=
>Q>`>l>{>
><?E?N?W?
5098:I:
<&=+===[=o=u=
1N2b2s2
676A6K6b6l6
7"7,7W7a7k7
8!8+8B8L8w8
979A9K9b9l9
:":,:W:a:k:
;!;+;B;L;w;
<7<A<K<
H1P1T1X1\1`1d1h1l1p1t1x1|1
2 2(2,2024282<2@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
>$>,>0>4>8><>
6 6$6(6,6064686<6@6D6H6L6P6\6`6d6h6l6p6t6x6|6
7h:l:p:t:
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
;$;,;4;<;D;L;T;\;d;l;t;|;
0(1,1<1@1D1L1d1t1x1
2(2,242L2P2T2X2`2d2l2t2
3,303$6,64686@6T6\6d6l6p6t6|6
7(747L7P7l7p7
8,808P8p8
909P9p9
:0:P:p:
7(7,7074787<7@7D7
:(:H:h:
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
((((( H
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Amadey.4!c
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Gen:Variant.Zusy.446682
FireEye Gen:Variant.Zusy.446682
CAT-QuickHeal Clean
Skyhigh Clean
McAfee GenericRXAA-AA!92ADFBE29D3D
Malwarebytes Trojan.Agent
VIPRE Gen:Variant.Zusy.446682
Sangfor Clean
K7AntiVirus Trojan ( 005ad93c1 )
BitDefender Gen:Variant.Zusy.446682
K7GW Trojan ( 005ad93c1 )
CrowdStrike win/malicious_confidence_100% (W)
Arcabit Trojan.Zusy.D6D0DA
BitDefenderTheta Gen:NN.ZedlaF.36608.gu4@aO8UoBhi
VirIT Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Agent.AFGA
Cynet Malicious (score: 100)
APEX Malicious
Paloalto Clean
ClamAV Win.Malware.Zusy-10015683-0
Kaspersky HEUR:Trojan.Win32.Agent.gen
Alibaba Trojan:Win32/Amadey.cada63c5
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Agent.104448.EA
Rising Trojan.Agent!8.B1E (TFE:5:UaFrdoZ2D2N)
TACHYON Clean
Emsisoft Gen:Variant.Zusy.446682 (B)
F-Secure Trojan.TR/Agent.ivpna
Baidu Clean
Zillya Clean
TrendMicro TROJ_GEN.R002C0DL423
Trapmine Clean
CMC Clean
Sophos Mal/Generic-S
Ikarus Trojan.Win32.Agent
Jiangmin Trojan.Agent.etvq
Webroot Clean
Varist W32/ABRisk.IARF-9031
Avira TR/Agent.ivpna
Antiy-AVL Trojan/Win32.Amadey
Kingsoft Win32.Trojan.Agent.gen
Gridinsoft Malware.Win32.Agent.cc
Xcitium Clean
Microsoft Trojan:Win32/Amadey.MA!MTB
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Agent.gen
GData Gen:Variant.Zusy.446682
Google Clean
AhnLab-V3 Trojan/Win.FUUW.R626291
Acronis Clean
ALYac Gen:Variant.Zusy.446682
MAX malware (ai score=82)
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DL423
Tencent Win32.Trojan.Agent.Jtgl
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Agent.AFGA!tr
AVG Win32:BotX-gen [Trj]
Avast Win32:BotX-gen [Trj]
No IRMA results available.