Static | ZeroBOX

PE Compile Time

2024-06-10 21:16:26

PE Imphash

cbe5fc5e7bee4b0be15ed00994864f05

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001d9ab 0x0001da00 6.63956209843
.rdata 0x0001f000 0x000f7f0a 0x000f8000 7.43953446175
.data 0x00117000 0x002b7d40 0x002b7600 4.62940208591
.gfids 0x003cf000 0x00000044 0x00000200 0.64667924231
.rsrc 0x003d0000 0x00000db8 0x00000e00 3.72341814818
.reloc 0x003d1000 0x0000130c 0x00001400 6.52049116648

Resources

Name Offset Size Language Sub-language File type
RT_STRING 0x003d0b40 0x000000f8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x003d0b40 0x000000f8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x003d0b40 0x000000f8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x003d0b40 0x000000f8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x003d0b40 0x000000f8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x003d0c38 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x41f000 GetProcessHeap
0x41f004 CreateFileA
0x41f008 CloseHandle
0x41f00c GetCommandLineA
0x41f014 CreateFiber
0x41f018 SwitchToFiber
0x41f01c OpenThread
0x41f020 GetCurrentProcessId
0x41f024 GetTempPathA
0x41f028 WaitForSingleObject
0x41f02c GetFileSize
0x41f030 OpenFileMappingA
0x41f034 CreateNamedPipeA
0x41f038 CallNamedPipeA
0x41f03c ExitProcess
0x41f040 VirtualAlloc
0x41f048 HeapLock
0x41f04c IsDebuggerPresent
0x41f058 GetCurrentProcess
0x41f05c TerminateProcess
0x41f064 GetStringTypeW
0x41f068 GetLastError
0x41f06c SetLastError
0x41f070 MultiByteToWideChar
0x41f074 GetACP
0x41f078 EncodePointer
0x41f07c DecodePointer
0x41f080 HeapAlloc
0x41f084 HeapFree
0x41f088 GetModuleHandleW
0x41f08c GetProcAddress
0x41f094 TlsGetValue
0x41f098 TlsSetValue
0x41f09c FreeLibrary
0x41f0a0 LoadLibraryExW
0x41f0a4 LCMapStringW
0x41f0b4 IsValidCodePage
0x41f0b8 GetOEMCP
0x41f0bc GetCPInfo
0x41f0c0 GetModuleHandleExW
0x41f0c4 WideCharToMultiByte
0x41f0c8 RaiseException
0x41f0cc RtlUnwind
0x41f0d0 SetStdHandle
0x41f0d4 WriteFile
0x41f0d8 GetConsoleCP
0x41f0dc GetConsoleMode
0x41f0e0 SetFilePointerEx
0x41f0e4 FlushFileBuffers
0x41f0e8 WriteConsoleW
0x41f0ec CreateFileW

!This program cannot be run in DOS mode.
`.rdata
@.data
.gfids
@.rsrc
@.reloc
40QRhj
t$lSUh
l$(+l$$
l$(+l$$
l$(+l$$
l$(+l$$
l$@+l$<
l$H+l$D
l$(+l$$
l$(+l$$
l$(+l$$
l$(+l$$
l$@+l$<
l$H+l$D
l$(+l$$
l$(+l$$
l$(+l$$
l$(+l$$
l$@+l$<
l$H+l$D
l$0+l$,
|$ ;l$0
l$@+l$<
|$0;l$@
l$0+l$,
|$ ;l$0
l$P+l$L
l$h+l$d
l$X+l$T
|$H;l$X
l$X+l$T
|$H;l$X
l$X+l$T
|$H;l$X
l$X+l$T
|$H;l$X
l$p+l$l
l$|+l$x
l$X+l$T
|$H;l$X
l$X+l$T
|$H;l$X
l$X+l$T
|$H;l$X
l$X+l$T
|$H;l$X
l$p+l$l
SQRVWU
]_^ZY[
D$pO;|$
D$pO;|$
T$d;\$l
} ;T$d
} ;T$d
<B;l$$r
D$pK;\$
J;l$$r
D$pK;\$
T$d;\$l
T$d;T$
;\$HsR
T$d;T$
l$d;l$
l$d;l$
T$d;T$
l$d;l$
l$d;l$
D$pJ;T$
t$d+L$t
D$pK;\$
T$d;\$l
T$d;T$(
T$d;T$(~#
t$d;t$(|
t$d;t$(
;L$(|R
L$H;L$
L$d;L$(
L$H;L$
L$H;L$
t$d;t$(|
t$d;t$(
D$pI;L$
Z;L$,r
y;l$0r
T$d;L$l
_^][YY
SQRVWU
]_^ZY[
]_^ZY[
]_^ZY[
]_^ZY[
D$L;t$P
L$H;T$P
\$X;L$\
u%j0Zf;
Qj)Zf9
TVhx3Q
SSVWh
PPPPPWS
PP9E u:PPVWP
QQSVWd
URPQQh
;t$,v-
UQPXY]Y[
Qj joVRWS
D$ PVW
T$4;=h
_^][YY
D$8+D$
PQRVWSU
PQRVWSU
D$8+D$$i
PRVWSU
09D$ }`
PRVWSU
PQRVWSU
PQRVhX
D$8#D$
QRVWSU
D$0^][k
T$ 3L$8
L$0SU*
L$4+t$\
D$@^][
accord; configuration, defeated, shiver, pronunciation. grandchildren. plain
weariness# relax# valuer
[aOni*{
~ $s%r
@b;zO]
v2!L.2
UUUUUU
333333
?333333
?UUUUUU
?$rxxx
RUUUUU
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
?ZEM-'^
?{yK+;
?765@Z
?e')lW
i^^?(>
Y:/(A6>
?5Wg4p
%S#[k=
"B <1=
FlsGetValue
FlsSetValue
GetCurrentPackageId
InitializeCriticalSectionEx
LCMapStringEx
LocaleNameToLCID
CorExitProcess
_hypot
_nextafter
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
Unknown exception
bad exception
.text$b
.text$chpoez
.text$cxphbk
.text$e
.text$f
.text$fnvqzr
.text$gscpxa
.text$gvulab
.text$iwqawl
.text$ixwvck
.text$k
.text$l
.text$mn
.text$nzerra
.text$oezpbe
.text$ovkioh
.text$plvrgl
.text$raevwj
.text$rssnjr
.text$strppw
.text$tdfchv
.text$uvlkxh
.text$vnhudw
.text$x
.text$xbtgwe
.text$xyezzs
.idata$5
.00cfg
.CRT$XCA
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$zzzdbg
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.gfids$x
.gfids$y
.rsrc$01
.rsrc$02
GetProcessHeap
CreateFileA
CloseHandle
GetCommandLineA
ConvertThreadToFiber
CreateFiber
SwitchToFiber
OpenThread
GetCurrentProcessId
GetTempPathA
WaitForSingleObject
GetFileSize
OpenFileMappingA
CreateNamedPipeA
CallNamedPipeA
ExitProcess
VirtualAlloc
GetNamedPipeHandleStateA
HeapLock
KERNEL32.dll
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
GetStringTypeW
GetLastError
SetLastError
MultiByteToWideChar
GetACP
EncodePointer
DecodePointer
HeapAlloc
HeapFree
GetModuleHandleW
GetProcAddress
InitializeCriticalSectionAndSpinCount
TlsGetValue
TlsSetValue
FreeLibrary
LoadLibraryExW
LCMapStringW
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
IsValidCodePage
GetOEMCP
GetCPInfo
GetModuleHandleExW
WideCharToMultiByte
RaiseException
RtlUnwind
SetStdHandle
WriteFile
GetConsoleCP
GetConsoleMode
SetFilePointerEx
FlushFileBuffers
WriteConsoleW
CreateFileW
_U_U_U
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
1"141d1y1~1
2)2@2Q2u2
3#3/3P3V3z3
5F5^5q5
5&60686A6H6X6c6h6|6
4D4Q4W4w4
5 5&51575M5}5
7!7A7W7z7j8
021;1s1;2?2C2G2K2O2S2W2[2_2
23$3)3D3I3N3
: ;';_>
<%=7=~=
=D>Q>}>
I0U0]0i0
44Z4b4v4
5$505<5H5T5`5
6(646@6L6
697A7I7Q7Y7w7
;;*;|;
>>L>S>
? ?:?C?\?f?
4 4+414:4|4
8!8M8S8e8{8
9<9U9d9p9~9
:;:E:a:l:q:v:
;/;K;V;[;`;~;
181?1F1M1g1v1
172R2d4
4(5=5K5T5
8;9M9_9q9
:4:F:X:j:|:
=%=1=9=Q=}=
>%>*>6>;>L>
> ?2?:?D?M?^?p?
A0H0O0V0c0
638N8d8z8
=">V>y>
1!313N3
4$4,444@4I4N4T4^4h4x4
5<6T6Y6
2F2T2Z2u2
3$4;4`4
%111H2|2
393H3T3b3
>$>G>b>o>}>
?*?/?=?
0>0C0R1f1
5%5.5F5b5
2G3V3u3
7?7E7J7P7a7f8k8}8
>1>\>b>
?2?I?_?}?
0%030O0n0t0~0
212S2Y2`2
2!3(3.343;3Q3k3
5+5>5i5o5
5!6C6I6V6s6
7$7;7A7L7
:!:+:1:;:F:L:X:^:o:u:
;0;6;C;O;T;~;
<+<0<;<G<L<\<e<o<z<
=&=1=<=N=]=
>5>;>F>R>h>{>
?'?5?K?S?c?
40:0A0F0a0k0
1#1)141:1F1L1Q1^1f1
2)2/2?2E2f2y2
3$3*3H3V3b3r3
42494P4f4l4
552585F5
6 6-636>6K6V6[6a6f6l6w6
77$777F7X7^7n7
8$8:8N8U8k8p8v8
9#9)949:9@9J9O9T9a9j9p9w9
:*:W:a:t:
;#;-;:;{;
<<+<0<8<><D<P<W<]<c<h<m<v<
= =&=,=1=?=D=R=X=d=i=t=y=
>P>U>j>
? ?&?4?:?@?_?m?
0D0]0c0
1%1d1n1
2&2-2>2Q2i2x2~2
3$3-373
4"4.4H4W4\4
6L6a6w6
7"7E7z7
8+82888>8R8l8
8b9k9x9
5 5$5(5,5054585<5@5D5H5T5X5\5`5d5h5l5p5t5x5|5
> >$>(>,>0>4>8><>@>D>H>L>
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=
6$6,646<6D6L6T6\6d6l6t6|6
6 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
L0X0x0|0
1 1$1,1D1
606P6p6
787T7X7x7
8(808\8`8h8p8x8|8
989X9x9
=$=(=,=H=L=
minkernel\crts\ucrt\inc\corecrt_internal_strtox.h
__crt_strtox::floating_point_value::as_double
_is_double
__crt_strtox::floating_point_value::as_float
!_is_double
IND)ind)
((((( H
(
((((( H
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Qapi-ms-win-appmodel-runtime-l1-1-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-file-l2-1-1
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-kernel32-package-current-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
user32
Qja-JP
mscoree.dll
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
picturesque/ Add %s Occurs+
$whip rouse) 991 %s sweat horace Dew $Inconsistent event, Guessing harold
:63- 400tack Precisely correction React- 125$ Simultaneous-0Sham Harassment Organic( 91 %s swan %d664 pulse
1%d Brook) Especially curvature$ Muscles Circular
thrilling_ Minded@
7Forward affectionately 96_ rough darkness Isobel ruins
.campaign- arithmetic+ Masterpiece Inside$ %d?
%s Temptation$ dummy 550\ lustre Doubly! Resume Carrot$ %d? conscientious, (spiteful. Wherever Gay( 302 Cautiously)
#confuse 474 plastic Seeming Without
%s@ wallace
%d$ 946 505-?Teach Allocation unleash Blessed growled Fits Deed Eater\ pizza
%s 275- grind+ 259( 511
#Grass\ 68 534 %s %s seats) winner+
Respected@ %d@ supper
IdeaRanch+ rattle
%national( Spree$ Lucius? believed %d
Encampment Custom/ restrain)815! bamboo admit regard knelt+ entirely-
689( Clash Humble.
,threshold dancing indigestionLuxury thirsty.4Adore golden! Haunted! 249, weird? death 254 Attach #%s 734( truth Amid+ doctor+ objects
kernel, recognition seated. %d An suggested- aspect friends
,facility Stability Deploy %d dread Furrow %d
Believe- %d( labor Work,
Smell %d city wardrobe( Sweep
%s 44 club2%d\ tame Region) Wanted 92/ Surgery sterile 352 St
Eighth 860! devil
6seated superintend/ Breeches David, %d$ shorts) remote
6distracted+ Picturesque Endeavour create@ Prone- Bees
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Generic.4!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Lockbit.wm
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/GenKryptik.GYPG
APEX Malicious
Avast Clean
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Real Protect-LS!B2D33941295F
Trapmine malicious.high.ml.score
FireEye Generic.mg.b2d33941295f236b
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft malware.kb.a.979
Gridinsoft Malware.Win32.Gen.tr
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Casdet!rfn
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Artemis!B2D33941295F
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Generic@AI.83 (RDML:mtgATTehqFjXmF2jeIW/eQ)
Yandex Clean
Ikarus Win32.Outbreak
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Gen:NN.ZexaF.36806.ZBW@a0DnfThi
AVG Clean
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Clean
No IRMA results available.