Static | ZeroBOX

PE Compile Time

2023-11-29 05:51:52

PE Imphash

e27e863878b286ab3210255a9ebcda55

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x000d3000 0x00000000 0.0
UPX1 0x000d4000 0x00085000 0x00084c00 7.99907868245
UPX2 0x00159000 0x00001000 0x00000600 3.02956351117
.rsrc 0x0015a000 0x00009568 0x00009600 2.21806986929

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0015a0ac 0x000094a8 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00163554 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data

Imports

Library advapi32.dll:
0x140159118 RegCloseKey
Library api-ms-win-crt-heap-l1-1-0.dll:
0x140159128 free
Library api-ms-win-crt-locale-l1-1-0.dll:
0x140159138 _configthreadlocale
Library api-ms-win-crt-math-l1-1-0.dll:
0x140159148 __setusermatherr
Library api-ms-win-crt-runtime-l1-1-0.dll:
0x140159158 exit
Library api-ms-win-crt-stdio-l1-1-0.dll:
0x140159168 _set_fmode
Library bcrypt.dll:
0x140159178 BCryptGenRandom
Library crypt32.dll:
0x140159188 CertOpenStore
Library KERNEL32.DLL:
0x140159198 LoadLibraryA
0x1401591a0 ExitProcess
0x1401591a8 GetProcAddress
0x1401591b0 VirtualProtect
Library ntdll.dll:
0x1401591c0 NtWriteFile
Library secur32.dll:
0x1401591d0 EncryptMessage
Library VCRUNTIME140.dll:
0x1401591e0 memcpy
Library ws2_32.dll:
0x1401591f0 send

!This program cannot be run in DOS mode.
)#AKr}
%DWb]0?U*c5
UZDp>B
yJ;HI>t
Jj4NA7
#titKP
=uPSjL
[6wHsy
(K$07p
MAl*fFOV
uH%:sD
9[{WQy
UMVPo:
}[{\`6;
g<B/v_.
-&&FTu
{zimDs.!
\|KAukNh
fF1-cw
aR7@/
6OQELq
6Clp=b
IZyZ(v
?W<S(4^
9DP)'^
#ggQ>=nM
}0K0Oi
G2iv*7
{Gl0{"(P}
p!%Y\W
B+(Jq9B4
`.|Kzt
W9*w)5
82E5cIe^C
^W=]*A
>RV o;
.HUm(l
{oJGcl
-kZ8@p
:EEuCc<
i:A720
gd4i&v
?rfF+\#
xm\&p:
!^Oil=
)qaAMQ
[H"8]GkTH&
(-(@<<;P
6t{zH*F
=]d{j~8
<>!S~rT
)C}M3Y
\'A+^`
@{jdh/km
s*9mG$
A _Z,M
+mQ|Xw"
'J5:!L6q
L0~'Qv
hD%6,+
c Lx.P
o,Hmww
!iCsz^
"`"+06
c8JOZ"
[>Kr{k
NuY)M%
]?Wm&f
u*wz;D}I
}1!GAr
{7K4sR
F.^SK6
0iGo{Z
,NsxHSi
D8V_vQ
a<5`W]
_Q^Mrs
}1W%Re
4-4f6hV
)?pxL6
ib#w?O
ul/ 6Xq
{S,CI%h
^O9T_3
x0y$,T
uMFiY@L
#(~J?0
Z_hgD.J
y/O{o~
pSl_e
)o>mb.
{hJ)Q1*]
Wy~<[l
cZ D{;J
xRk()R
c`4>y2
]f7JuEu
?4UzsZq
1i_-cDbM
JaM,\gT
9U5^rb
N^.P-=
zLOYyl
AC_aI<
-l~#xm.
R8B2C0R
=FKLka
bu Z]K
]IT@W}
"mt+ a
ua"J]~
5uxlc;
$3;Emr
:%F,78
a$t~r~
S"Bo@j
Sv!y5Wz a
2WHDV40
L051&SL
`lH7KR
3gn#!F
/zw2C{
@U81XB
#Dkt('`F
!Ln$@1
%55f`!6
^.y[sY
ZTF*xz
,Ve,A8
uY`oZ
U=qTy
x* _~y
'pOfa4|(
eJ@jT
p:]l0W
z C^ !
'!x6rK
2?Kmp?jq|]7
{}[`xJ
xqygCL
RMl>OF
ek^`>v
w6>c&0
XeKUS{
@OZ(';
y j)93
^fn\<1
ln&Q5o
\pR[B6uo
oI&^Tu
mfmf3m~b
S&d^De
{("V0R
tj^FZiK
7cWd"Nq
7#,Pps
;vTi$2
[&08&p
U^-(C|/[VA
iF-Y/?
PE##C:
)61LJq6d
*S_pXnK
!qAAO<
ovbgeK
)jC1;lh'
Jz|DTG
eX_p!lO
A\G^s.
xo;?[V
9@|~Ga
XHQ~vQ
*gX,'u
9eRAL
X76SO0
O4r3.^
p%EL09A'
|91rQ9
d<RLo_
@+Lys6
mPk^hku
xNpZ)V
RYMbDP
~T_.K1
&oa1 z5
?C4b.|
1"/4,0
ZiF&(b
&)G.@-^
Un<a>v
Z}h0Ixk
*KA.3Z
&:S&4/
b6u))`
{$\vWL
ThXLW<
8oVlndV
\9^S(N
$2OBFC
bsd<9+
,(>t=#4
$\v Jmr
3?]+Ju#
qLiN<&
vueuzp*
>w>+3M
Ol;Y+4
,{wG2~
E Mya>
zWE+Ee
SJyOT*]
#~X;+>:
9qH0)wL~G9
-o\[*S<lT
'Cn~Eq
3TgD[v
w<%*D
+$9J:
$/1b 6
Z?;nIKZ
^2%dk
Af2HHE0
HFYK0p
;UbKiYC;h
yF=@?-h[
YSON1O
W"q$#u
*OQl$
~Jo!D:,
7?6{H'
g4~BJ3&
iQ.Rg(
1?;H%0p2
`x!e #
gboc.Z
}[yq)
oZaTDr
oF3BLg1
&VP*`j
X'_tQ!
h_ap,,
.pw2&m
rZ;Ie'
vgzqzf
n%XLSf
0N'z!U
yZ`i5kkZ
WzI\){E
|#QC|g-4
MW*l3%Hq
W=j|&Y)
~1FrXm)a
5/JrF_H(
m_c9B
`Fp^9s@
$n,894
/H90H[4
l0|)$C
wq'T1)
{L,lsM
@,/T~ j
6XmA#=
(m}#{\wCH
eS;o,
EC3n`F
[!F!'Q
$Fj"FJ
W!i3$n
$nJEB|
Ma]xH{
J#koA0
#)V_k}
=^]KX>x/
npr1s.
nDaQa%
:iG_{T
f?Pm^o;
VHB70$_[
u~lH;%
%S4^Iy
hu{{of
oz%m.=
TQWy7#
1FLY<1
kV{5sZz
NKdKbB
iZn{T?
lT8e%^
[mJ.mm?
'^G5Ti
6v-R\t
F39%3(
6=3rl
DYa/^y
,5C%Xj
@;MnO=@y
EeB 'a
~a$_1(
vzdcP)!M
cL"P&oL
e`p@t9
@8b?\X
.NMy_Y
J8FR(:
w(4U}^<
m#s;1#
PXwZO>>Y
QOdU>v+~
oFZ2'qZ:
Q((|e
qHt-eKQ"
i,;?*l
gZ6k(.
IA9PwG
,}F1~w
q=6E-<j|
vZo;d
iOXreE
xg;Su!
)/+0E^p
~7)i<n
>R^fv^
$0^.mof
F Sbws
U#&kI5
OV/TpV
~ld*khN
1@lMuw
>/Phx=s
wT2|_v
7VF& R+!
zGc3Pa+
wH~j|=.
K}L%gY^
){=:[Q
xjN0vM
"p~VUJ
VHALU[
U(PjpwnV
wDT|sM`Ug '
(F$l&T2
-C,n&}1PW
+]VT73
;~/#r=
3M9F1l
HpN$;q
aJfwo
ePLU3X
s38@U>QZy'{&d
o%3^Bl
FapV=1]<:{&
mTWp[3u
99>xO I
3Y'I}o0
UM0Z&
6KQcGh
Hra04QH
6S@SSwF
9J2,u:3
D1~ZwC
c9@`Q0
B.:wpB
9-*ZAG]q
XLmWlpHj
I'0oaa
8olW/s
lICo-+
Fa)vEy
_ ;z!7
e<r3DoT
d<L$++
HPgu$Y
idoy?}
wTx@djb
g8>g:m
f|n%5{
H(k$@\
xSq_Kq
Av+L>Mh
]b[}d[
f=z8R}
[[<r'&X
Tl3|c]
^NcuU#:
,zl^2u
ecw"{s
w7hyW}
uN[\GaW
C(cT{2
?5|!.n.$
busILeC
@ 9Xb"
p!L$'D
dFKHg/
-lsQTV
MbEiDK
#T/kodt
,noGxg
;7zj^!
_P2Pfd(
gv`GuI
>I#|\
0Hmh/!.\
>Ju\w9r
;nd/A0
W'o:BB
N]d$JD
Gytc'PK
;(3;aR
~WT!6U
bhzVDi
S/!q,oWuJY
o"HTH\
7Gj9TT
Fm&GoV
&^@OtUz
-rc@P
#m@58b
b5LO<^
2!/,zU
ZWmn;l>G
>|5-@V
N9PWi4
`-]A2g
/(x&PZ
_AEzSH
GKN@c>
Q8xL8x
w?m1:?aG
D|^{y$y
3Qih/p
JT#h`S
x8`X;w
@~g.L-
tkQQH(
-{ItyW
#Xa]6+
A A?q8
I1>@BP
UZ^NyK
cOjVlz
cs"]R:
tSO+G3
uf]%b+
Me@_4Fp
YK!CFz/
2l(7D|j
u{k4<n
?,e =h
TshWu|
KWGs2L
xQ+qcL
[T-P$7
u_(}NTuf
ZDa)s:|
qx|TA
\Z#+cq?W
`ONE!O
QZwv4-@
=1il"8
\w5K ;z"/
IkXij$UHB
}i-$f>:
qL$f)}H
b%Q.,UL
"}FI#bx
>]}w _T
Z i=J+"B
UTE8SB
@`@O,mg
-]8nXM
]KERgs
/5Vc(LS
!`=N|]*
Qv7@@X
xC,O'D
!ibx,3Z
hUG!gbAX
BG&s(~nxO
d:f^eW
bZ?jeZ
3T)>2\u
M&fsOW
o2VHDz
!-x4iF
/p6xL!
xu6tPK%j"
JSW_wX
EZ5,<
^X><z.
*:VX#T
R_g90[
k] v'"
q?rHyR1
$siD6&+
_IB%jIy
hXc,~JB
`.Q}=n
~;+gg~
9@M(`.
d=qS$u
K AI%
&]0}qY1
R/eTGbtT
IW;g\H
GaE(;Q
vs?{T'\
3!VQ47
TSMO[;!
INX,~hK
p|PtG<
TZ*l"#>
E`yA#"2<.
j70v,6
?W=-
xHROlf,
^K80=O
;'|OKS
Id1o^K
&j`cq}
c'bz<@
Lku|fM
nYZ#iSa
/!<}4n
Z&jz'h
)#.u6M
g:\(+U
e.NKO=
r0,kVG
7>)k;7
y;-.n5
-j1J|-0
\'~-y]v
gY`$Cd
MMM&*/6
lTp:st
Hj^S*z
n(CFB%
~?jzb5x
WX!]Se
i0C%jGl
zvVfXv
%"IYjWS
qWq&@#
8n@M2/J
glIVR!J
<:|QLs0
J"+Y[]
VWd1_9
@dU$+V-
|gwa<fjEo
MQrW$x
%MK~"P
>),o00g
c6]3agL
a;9d>Q
NfQ+oZ
.5-By-
v A?*`
&p?KlS
\xqN{Z
pP36B#
?`#>jT-|
0lqC3n
@qi0]\
R_rX!h(
Os6[-@
>Uo0h%
WK2k|9
iS^;Xc
$NR":=V
4?m%|pA
wesjMU
emoVC<
32cv5w
DcuWJe
@.$z6-
y748D:
9$!puX}
.[OQf,
exz{8s
mN)NY>q
2:BDWL-W
2p+W.O1
FZX\V{
guftRfd
q 5M0J
{3~b/8`
KWd'~=
,N4]i3
ZjzZMv"
x wwn_
EP#7{q
t CdbS
-LE,@N
T@yM6X
$|s7\7
k]sRo|MJY
i^j.h)
*YS~i]
|*XUI}
ccXXpe
Y"8J0o
NV}_K%
7mD$61F{
P%Y=j
Wz^YC3
<aR#lL
8P=sW
Huf{og
3$qlI3Id
wbk?y]
ro-.vwg.0
oRy[1K
E9^yL;
G"f}DZ
4nbiK4@
]J/Hun
KmX'VIv]
`@BIN,
<PK*Z*
e$0F;l
#Bd-nT
xx_x~.
iRj'xU
L=+aw['
@cN&2D]
J!L1J|
"0f.}L
z18x9
>3';)J(h
z~/#bj
A&):]%
PGo'hq0
b<1t2}
[!:}P!
I]bod
.+JM*Q
d5#?_j
y$>&M-hs<
~<hE|8
dohaH!
bL(t--N
`3t5H%yQ
^_U-|n
X2:inJb
D[M/W9
'1)&J5
d}|A]9
x"tJz!
tlF+{8
XMr,OM
TLGk\@b
h'*./3
bsT]%?if
@ucQk-@
!ufYgD
i&IXYBf
-]p7Q_A
D4\MYG
~fJ.7P
+>nzrF
}73=?9E
}(MwM5h
Maa5"+
\IAYA3x#s
FPD%xr
TiNR]t
}]QfX_
hg%o-[
YGs%+?
zda:g
e75.REF
stEe!/
-bEw8~}D
C/i]#Q
4~^e_b%
Le,!dHz
ap.$](G
d(rQ@o
\G#vZ2hb
v^29E.M3
KCKfM~
PULipd%
g5CM+I
wW7m2@:
u5GNHa
{R@/G;O6f
W13c+[
snh(YI
ImJk'
5C4NJ\N;
*(V/p
,.@JLD9
v*rme8
|>:7O,?
-P,G@!
ca4*f
B^u<%u
euxJj`
;GTF26
^fvLWs>
u!h9a<3
,9A;c#
datcIunE
t8j7Ar$
nH4^U$
8XPsN(.
bj[nN"
nZe^Lz
^@DJ6^
xgLRwj
S0fI~7X
n[|!oDt|
COyhm[
,Y, ?z
9Wz1j9
v(RLV\
~0I'v%X
f1h%;{
6k2qhq
=csb22
tI`U;5
>]h_Ut
> dF9P
C^T-Crrb
i6BFr)
sqO3x
:Qa\Um
J<s$r}T
~Op2Hs4
0X2Gi
tm<1}\-*
-xwN@wp{&
TJN8v6
l$nonC
3)xcY>J
J}mGT{
QFsu<5
2z9` P(*
bcQ>c<l
# #eMa
\H4'4d
VTLO(U
QyB!z}G
Fho:EFe*
&t8Vsqm@H4$
{N2%Ul
|Fz&!AFwA
H*#L a;
%8i~Ff
qe$U*S
4 -z1z
7_^3fc
g]#F2P1
XV]n"C
:I^=q_
EAl9yMJ9
J<^2%tZa
]&bN=R
7hX9A*-
#wR Gg
4%}@$:
dG,1F
\@B;3
No%7j,?~
K O;[Kc
[6:t;qe<
p#eT"9
aXFJY}o
&Hr6D1
8&J\T<
0yDL4
ZJ=zjG
F{ge.Z
Pn"6Ks
}pl6Nd
m4]"--
?8tj?Q
HI5/l;
\sC>Nn
NM"_Sm
[LP!"^
n(n%El@
5z/5A6
QgS42j3
7#74Q0
`&n@hJ
#dk#F'
k^W(@g
J_'R{L
"]#H.9
E4pRmL
{Y$vWD
U|OqID
\1< PR!
-)EVQ!
{Hh2Gd.
`QROHk
]Xl>=D
I}#-<9
KtMhVL
&}i~mW
/(]k0X
:0AZgRC
9PZ4$=
gm%.'V7
R!}+R[/
@v"QLY
xKfk6]
VA(rL'
kEg6^TN
SGZyhHH
}(W{)%
0%cV|[
&zs{mc#
;/JPd
9%,'A|NS
mU[|G/
1$:6v@
@MHjyb
H?lZiD
sFr]07^m
/6.>-V
z<Tn;u
'u]zvi
I[*Z;%
s^&+Pt
Nh15z%s
9m/6Li
I&d(=@
$qN);.
pQFC7S
.5y5R*
nq8W`4
,)wDUc{:
kuX@d+
MK_Q_aT
)/to'
iOH~$d
${:h.?:
-Np?NK
LM\R>%
<M,gm5:
LvD}rs
,_SiFI
d48JcR2
ay[}C#
qP48S{
-' 4w
rj>`_s`9D
O8+B8
*PKBvZ
xIwWs?
r@r1R:
*|,:v=
?b}r]n
caZ7Tl
K<W+,S
N|gK1Y
B~z9!~
WF"+.1_
HH'w11
?kMt}f
SM'e@F'
,(Tj!,
F)y);p
ipv"&x
1rf.i~
0lan]O8
PaC#&wC"
S3RDLJ
*\6/)8
/!z~}!
q{ 6h-
.0z[Nu8_
@t&f[T
KJXP]8L
q!HS?XT7
1)E8ve
KI6-Gd
67"`rhP
W/}W]Imo
t,<&Ft'
//G{JD
5k@0TQ
R|O(wb@Gl
`-^_{
SJVxe
rp;B]a%
bhawq(
THX<Fi
F7!W8
F&*#l5
pC/TnG
Lf!ml$C5vo~
_{$A|1R
kn[vPP%qe
;E(};i
'J]\n
#U.hL/i
@IF9"P}
A+_Y9
HX@0HcX
a50YI@[
-zkhSMK
X/M[Y
!h|C$t
CHwP"
<H|LN;
"~6fFN<
;t+!^L
w;bPZN
Cyif03
`v!"*T
#OF}lt
N-;p8?
2j*U5d
K,@}W7
eRZj$cZ
a8Yc9^hDmZ
'm4"W2
xm0>,&
f^B/O@
&@|~G
}U%4W;
-Pit"%
]&"J(:
g4:GkV
=^A"k{q
j#movGk
HdpbkH
h{-U'Z$&
?}NvHJ
wG`?7|X
Pa7[DEh
qUTjL$Q2
1V1m\Rka
XJCDY+
; A?q#
/0ttLV
:I,3$,
A9Ah,A
XgJamQ
}QW;+q9\
Y7H@g6
a9YqCb?
v8CsnCy
91WaRe
Upg*Sd
$[)f*bDt}E
nW;R!hpbW
*l=zu/
]yXq0A
K-RJ?T
:KLy,m
:+yY4
$Hc,$H
H[]A\A]A^A_
X]_^[H
advapi32.dll
api-ms-win-crt-heap-l1-1-0.dll
api-ms-win-crt-locale-l1-1-0.dll
api-ms-win-crt-math-l1-1-0.dll
api-ms-win-crt-runtime-l1-1-0.dll
api-ms-win-crt-stdio-l1-1-0.dll
bcrypt.dll
crypt32.dll
KERNEL32.DLL
ntdll.dll
secur32.dll
VCRUNTIME140.dll
ws2_32.dll
RegCloseKey
_configthreadlocale
__setusermatherr
_set_fmode
BCryptGenRandom
CertOpenStore
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
NtWriteFile
EncryptMessage
memcpy
z!hez!h
z!hMz!h
z!hEz!h
z!hz!h
z!h#z!h
z!h?z!h
z!h#z!h
z!htz!h
z!h)z!h
z!h1z!h
z!h6z!h
z!h;z!h
BBB[BBB
z!h:z!h
BBBdBBB
z!h?z!h
BBBbBBB
z!hPz!h
z!hDz!h
BBBbBBB
z!hDz!h
z!hNz!h
BBBbBBB
z!h9z!h
z!hwz!h
BBBfBBB
z!h1z!h
BBB!BBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBVBBBeBBB
z!h-z!h
z!h%z!h
z!h&z!h
z!h:z!h
z!h8z!h
z!hMz!h
z!hcz!h
z!hzz!h
z!h,z!hnz!h
z!htz!h
z!hvz!h
z!hyz!h
z!h{z!h
z!h^z!h
z!hlz!h
z!h6z!h
z!h}z!h
z!h?z!h=
BBBPBBB
BBBiBBB
z!hWz!h
z!hNz!h
ICONN(
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
tehtris Clean
MicroWorld-eScan Trojan.GenericKD.70623876
ClamAV Clean
FireEye Generic.mg.b6d15bc82d811c30
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win64.VirRansom.hc
ALYac Trojan.GenericKD.70623876
Malwarebytes Malware.AI.3982124035
Zillya Clean
Sangfor Trojan.Win32.Agent.Vojf
K7AntiVirus Clean
BitDefender Trojan.GenericKD.70623876
K7GW Clean
Cybereason malicious.1e8bb3
Arcabit Trojan.Generic.D435A284
Baidu Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky Clean
Alibaba Clean
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Agent.584704.CJ
Rising Exploit.Convagent!8.12632 (TFE:5:hFui1khqHgV)
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Trojan.GenericKD.70623876
TrendMicro TROJ_GEN.R002C0DLB23
Trapmine suspicious.low.ml.score
CMC Clean
Emsisoft Trojan.GenericKD.70623876 (B)
SentinelOne Clean
Jiangmin Clean
Webroot W32.Trojan.GenKD
Google Detected
Avira Clean
MAX malware (ai score=85)
Antiy-AVL Trojan/Win32.Sabsik
Kingsoft Clean
Gridinsoft Ransom.Win64.Sabsik.sa
Xcitium Malware@#11oix1jgwmc99
Microsoft Trojan:Win32/AsyncRat!MSR
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Trojan.GenericKD.70623876
Varist Clean
AhnLab-V3 Trojan/Win.Generic.R612138
Acronis Clean
McAfee Artemis!B6D15BC82D81
TACHYON Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DLB23
Tencent Clean
Yandex Clean
Ikarus Trojan-Downloader.Win64.Agent
MaxSecure Trojan.Malware.221151308.susgen
Fortinet W32/PossibleThreat
BitDefenderTheta Clean
AVG Win64:BankerX-gen [Trj]
Avast Win64:BankerX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.