Static | ZeroBOX

PE Compile Time

2024-06-20 10:06:29

PE Imphash

3b3dc2709d13b6bbe20eb1df71d207fa

PEiD Signatures

UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x0008c000 0x00000000 0.0
UPX1 0x0008d000 0x00041000 0x00040200 7.93453844052
.rsrc 0x000ce000 0x00001000 0x00000600 3.28798465555

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000ce05c 0x000002e4 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library ADVAPI32.dll:
0x4ce3f4 RegCloseKey
Library COMCTL32.dll:
0x4ce3fc None
Library GDI32.dll:
0x4ce404 Escape
Library KERNEL32.DLL:
0x4ce40c LoadLibraryA
0x4ce410 ExitProcess
0x4ce414 GetProcAddress
0x4ce418 VirtualProtect
Library SHELL32.dll:
0x4ce420 None
Library SHLWAPI.dll:
0x4ce428 PathFileExistsA
Library USER32.dll:
0x4ce430 GetDC
Library WINSPOOL.DRV:
0x4ce438 ClosePrinter

!This program cannot be run in DOS mode.
Richhs
]~T$*L$
+6+4G*
M;*Hyf
|kXKNN
/(D6M~
N&ln/@G
|95,\w
4@`:ti
,CwutEb
W}_:.8
nt_V.x
589?#u
<RQ5| @B8R
;*XLHXtE
#.4#K1
A5D'"fzR8%4Xp0
DT8`}<j
)K.Qd;
=}=:L?
@Zt_h|!DN
hlH=hXL
!W,hDT
^\w^~u1
uE4SCQDv_
k<GZ|w
[^_C4\N
X^0Pt.;t$$t(
rl{6s{
uRFGHt
OZwU"U!
u(CwIO
(^Xx^]l
;V=Vi1%
8t9UWs
* Me`t#8UP+
$JBv m:
` 8*LJ
BV?hW,
BYY[Hh
|,Q2$C
8MZu_h
Ph<cAh
Nnt>j,PP
Q.Pdg6~l
|9c{u@
$m\0YG
! pJwx5
F(bV&z
xawS7P4 W@.
fgW&^bP\n
M5<B;Zu^ 0
_v02PN
<&VA Z
kY;IBfM
zW9xlJ
`mg}OD
sO;>|C;
y2Bd].$
fstVkH
X9p`tW
<Me<.&%
Pd[ShD`
@Pn xF
SYh AZE.
q3,/:u;
]p*.6F
GP-T^+i
6Y\\0t
X%.( T$
d<~E\G<
^}%9=r5
} ;|(
NBW"<"
:^@(66
{suuXB
y`8;qdt
AB rXB
D6Hj4R]
0ny%,
5tgoP{Pjp
v`9X tnj=
xs`L"S2L
>~0PPW
H8tB+<9m
YsRH0z
IX+)>
@fF?:4
L$S%4pT
O$HPlpT
A@8H-2
1PJ(*8
i4NpJ&8
VVlK rr
@.f^]pa
%Bl\+W
@Rhv6u
8v9}\t
1&DD7,
M$%B!M5
VsM.i(
~*BxxP
Lgju}#
Za343Fh#xa
>BV-p>
Pol~h!
4P<Q%`Dnxo
=TpVu4/
uW[+YV
O(u'y,
TphgpzO
<$8HZj
>NZjzy
y4FVdp
.2O&(.
CWinApp6
PreviewPagesSett
WCmdTar*t
CObjec
w"==BH
?TempGdi
Z?UserExcep
!R^ourNW;
NotSuppor1
h_Mzfk
S0o>(Cy
AfxOldY
?hProc423'
t8lBar%'MDIFr
euoGetM it
EnumDisplay/9
omPoizo
USER32
VSPLAYl
&m|rl_DZgL
>INI.HLP4
S`)Aug
>Febru
wgFaturdo
Th$s'We
__GLOBAL_HEAP_
.MSVCRT\
DA$#R6028k
fWnotz
Th spacF;
lowiqa
VvirmW`f
BfJcG c
4_Texf p
0 VisUC++ RALi
\@KERN3
fmo_hy
ld?<f?`g
x 7LntA
,up'X
l:1#QNAN
fOXjp@n
@ m8m x
@0qHqp
H0p"aw
DG@hE
_`y/py
z z8zB
MS_SQL_TQ[}
360532A4C47797E7
722655
f"*5687`O
B24B11
This5.
can8be >
;R&3>6
xTa]=M
LD<42
\q2r$xl
A[eS505@5
p4H?}T
%eJ$/V
gw!<BC@
r%S29VB
g@$GqUOw
R'bmc*G
m% WHC
D&dQjF
iM6(za
eD&6ES
\;:{<]
A:=bv7(
rUAZR:m
gOe~"9
q}L+y
@F>$}(H
R!EZnJu
&X[rM9C0
qrFaqe5S
pE24ik
r2^'+9
dVM=7r
cqCAM(/:na
@!{NA'
$a(<B6R
&9IF"{!
-9x#9k
y2ECS=
eg<B&9
9dHv0E
9dHv0m
``0Bm1
IfbBCq
"&,?)\
T5Als[%
Q\jz*]
x<$<<C"
UpOH(V>
T6^v#N
8j\%>&A@
6@H&7M
36t{4+?
t(#y
$(QS}h
$Ka8A}
P(!+J,%
<.=T"qj
3{(E"U
9*?\;q
$q;I]*
B+],i'H
oq_"q"
I4p$Ot
"q?5,
H84A8H
}MuCV$NF
8Dbqa(
T7HDcB
Bl"q"
xgB}%{M
N%x:6u
T2J#8D
YG%Y(@
2>JVj|y
y"2DRf
8BTdp~<
[$Bl`_
Oq87F
.|3k[b
L!\@^!
FsRedirec
C&vertAo
lstrcpy
ByteToWideCh
d\eHs[i
olhelp32Snam/d
|vq*<L
bypzcqu6
u|>G+4
#!7Md)
2WINSPOOL.DRVB
4d%V'Bxml
ffs->S
_i:eGJ\,
T;'Bubnr
#Zgrddi0T
iY;nTM
Jify1n
5H%=T
585B55494F65
3695E:"v9
#360BF
U3"9nEW
`N62rN7B
r\<&8n4
L<cmdy
@_RDATA
rsrcw@A
Y`kSyw
EUHTHE
] >n_b"
0bWr-NE
=8||p`
b Wv@6
,#-=3i
\Z pgy
A_A^A]
OsoA'w
n'_!_1
Y a0.J@MPJ
T`pI@OP
u3HcH<H
h8pbx t
JCL1<H
:Bk'g]
$L]&\
q0rxHv
w0"^{<
i5pM $
]q~X+LO
1mD#Ce6#L)
N"8Z(&J
_(d___
vC8_O
Gz T>/P
riXP`
97u+A^
rrN[^L5T
d"~!}y>
DAdl8Z
aK!~BoVs
}$pk,v
wjC7+In
7UH$ /
h_R( (
ct6sR3.
'FZ.JG
THTtU
CJQX_y
Pl0pT~
f^-8Ho
tSHAw1h
H0P<:YBt4
KafQXg~
p|2Lc<X
sox@j$
A4@1H^
M^vWq2@
oWD8/u
4fx~_n
g57|/-
jT>;J6
:|^1*uwz~
iaMFcY
}UnB`M
@$60n
K+x ~sR
rrrr(8FXrrrrdr
} new
rDHL?
B.vd?hl.
cdecl
4!^ftv
wift_1
22ptr64
)&^f|y
&Ahof-.t#
>c g;|E&
d7`-ngx
*.ueHq
A3`]]A
h"nM`EH
N5ACP
l/mV p
1hpE8o
P'wc{
y#y3eR6
pisANS9bg
a#M(hodr
hrrrrlptxrrrr|
4@P''''Xhtx
@Phrrrrx
 !"#$%&'()*+,-./0123456789:;W
f?@ab`fgh
ijklmnopqzuvwxyz[
IJKLMNOn
6(7NNNN88H9NNNNX:h;NNNNx>
?2{rr
#8H_ #
nX_0h
22H8LH
pp_r/r
OoZ?d&
MbO?p1y
+ofFho
M; =8c
oC`oonC/
/ZT/HO
TlW_s
)OBoW?
?xHoAna
&rrr2l
xMprrr
NNNN 7
9999t(
?8X8999
NNNnh
& ?(bX-
eZ{kw
hdbZg
m?qJ%6
~l,db
Lll6s
x:id
r!jn#=:
/{o5a/
Y0X._
=imb;D
VM>cQ6
>jtm}S
;H9>&X
*StOT7W
BC.6t9^
uzKs@>
o~:kP<
@ 7zQ6$
:\Dll1\x64\
E$mg{[%
'$00n&
.Xa$5_n
wnJ(^cfg
XO0 _b
rTH'OP
,Y7d'i
2/%C$?
dsJw`w
k%ENVK
"Debugg
>IxGyU
A/,*dqMH
.Em:a@2`
X&N\[X
yg]:|2
fI.z80
Ql~])8
=5u<POPj4P9Q
?49)Jt8
v|~;@a:08l
L*_}^a
: 2!0
\HS?y9R
7S:0;\=e>f
|>@uAlC
u n!t"W
<+#o$%'
g(l+,w0v&1i
2c56^8
p0/pv$
*|iOz
{Gmc.<;
;j'CJMS
KTAQ#U<
"&4MSi+
8 &C'<
| r"u#p$
< e,50h
39Q0<@-
?a]|a@0D+,
ACEGhx
?T@EAMD
uErFGeHnU
LN1PlRViv`
$).n^>
xx@(RT|
XyxL98:;g
>f?@jHA
PPy>BCv
Sz=>cG`
;k<s=>?
Pg+bH8
>s$?t@Ah
lBrCedM
Kg&LMA
e|AcBtC
dA)<>-
Qy> .!$;(
tMvzwix
l6;Fza{/|4}.y
T !Qw!t
>t&?e@rABU
C1DO&EpFG<
T*%&'()
'feaLf
MetxOe
PQnS1TO
dUpnUr
|[\pr@
jaDkdlFm
]MZu2<
\X+TA1d
h0&h1\e
n(6Nf<
k/$I8
`vj'dq(
??3@YAXP
_fto|I
!<{8re
d~Y_h{3
f"Zbeg
MRfp6S
6sf6")
divBFp
~ WfpP
aCKD>k
(ZA VN
o2vltnCC
pMgSvcWMi
YSTEM\
@_"go$
>stbYp
>~MHzARDW
IPTION\s\CP[
K_v3.0.30315
g\{4D36E968-E
CE-BFC1-08
DOW$\C
`?.?AV
`4_7yp
<W{oP/
K>eRf*c
o|jnLFgc
vK.f>C
='1.0'
UTF-8
$yes'?>jQ*
ns0B:sc
: m.v1
P58h0h4
4ohA4:(<
AB_w1,
= hX;T
`~J%[9'
u'6u#SP/
.s$qZhy,\
T&6Ovp
^uaD2F
BVj(N#
UQPXrj
L|d_`t
F ,n00:
["xK/'
V ^0f@M
nPv`~p#O)
hX,hPB
QWWR%A
oEA$"f9
IDj"Yn
xtp><z
M;A@MX
Q2&@,XP
8!)}*M
wF#p0.
<9wLdwH+
_${ fV
a4K^MS
R=1p#*
)#tID/###26/
Ppf]RVo
_)`J+`
W,R`bS
+QhFNh
)R}\ud
kZFVo6>;Mp
wp/fci
=)a;I.`~#X**
#'M{XY"
4,g3tu
>IXuen
?V{e~u
"f#>BE
<*:Jbz
Nn'P/TX
y9yWia
y$(,8L
,4<DLTy
<\dl^|
0?8@@Ay
yHCPDX
<%,&8'
XEdFpGy
nsn@X7
y)n@Xq7 ,y
#{ `~R=
%S#[k
<0$4%8
7=fab0
6|qR4X
gOp\'uk
TQX9Xeb'Z\OI
S2${o20
HLx~H&dJ
0@0E0S0Y0
1 1&1C1T1
2!2.2F2Q2
3?3J3d3
3 4-4N4S4l4q4~4
7V7\7b7i7p7w7~7
9%:E:v:
;.;C;J;P;b;l;
='=0=5=H=\=a=t=
>4>:>J>p>
0,050d0m0v0
7"878Q8y8
9"9=9N9Z9v9
94:G:e:s
:!<X<_<d<h<l<p<
0A0\0a0f0
151?1K1P1U1v1
4!4n4{4
6P6X6b6k6
:9;Z;u;
<;=M=Q=Y=e=
>!6P>i>n>
3P4+525Z
6*6C6a6
I7[7h7
:5:h:{:
6!6+686B6R6
9_9k9}9
H:Q:l:
0:0H0T0`0t0
E1Y1^1c1
2[2j2u2z2
67&7-
= =C=^=k=y=
>+?5?X?b?
81J1\>
3F:3z3R
8 9&9+929B9P9a9y9
:,;6;Q
F<7<?f
<@=j=r=
oj<^<t<|<
?fH2P2X2`
83@3H6X3`3h3p3x3
4 4(40484"
X4`4h4p&8
5 5(50
@5H5P5X5`5h5p5
>p?t?x?|?
n$8888r,v4z<~D8888
6 6$6(6
P<0D0L{*t
41<1D1L
2<2D2L2T2\2d2l2t2|2
3$3,343<3D
3L3T3\>l3t3|3
<4D4L4T4\
<6D6LZ\6d6l6tK
F<=z r0
`6h6pz
(70r@7H
Evp7xz
;$;,;4;
<;D;L;T;\;d
> >$>,>D>T>X>h>lw
r$SOFT
\AAnti
k7Mag$8b
[v\psS 6
B\n\ODhLp0v
advapiU$d
HKEY_CLARES_ROOT#$
#LOCAL_MACH
X%9S__
CONFIG
3MULTI
v { QUE
4XRIZSL
j=9$bI
+lnscJ
1>/|{0
*s %d.
%I64dPc
*A4tQuA
_STATEi
Dc?THREAD
,?=MODULE_
/Si#mP
Wn8zU<c
PD<0$
GEMS194*y
t_dVMc
{I>(QO(R2
X"s+C{
xXNTLMo
XE;aPr2Ic
ZA;YPs
|~(~m]
}<Bs"iZ>B
^/h`5xO
f?PfX
(.?Pyk'
\m1:q 1
8-ujb@?
Azh'4
!`ECKr
Rpf$<>
|!DPlB
vM@LW
_qwp)b
, nnS2
C!,s(G
eL,ddwx
I]8PDJ
aCA#sY:
;(|b(z}
6dBxE8
X!Y!G-
,32r9d
PaB?l-`L
@ H0@@HX^^HP@`
nyxXu5
F?'?^D
"IPzL3@
tW*vcu*X
BY3U'px
[^ARpH
l|f:SR
@frDt9{
?9>]F'5
u4I9}(s
vgti^td*
<Bq'^m
R5T;Lr
N8>`@I
dRm"t)
C0;``_
3H0 pq1M!
udo|}gHyuMK
@uDuLI
RUJRZq
u+'LRI`
`:O;Kb
l|uBk!
{e/un&
h$ Qv_.0
{9p@u+
'^H9yT
ANIH9B
HxF.#=
jlRh{^
X0$tZ".P
E+BEjP$
htl<jt\<lt4<t
,X< B$
_Ct-<D
;g~{<itd<nd<ot7<pt
!,I<%w
Zc0C;>
@J^#IQ
E*UfM
@OMu7-
ADKob%1
k`CiR`
g` AWjI}
)$ {"Vt
\=A`iy:
0(30vv
;$3Sf3
QJSHvT
>x+II
MQw8>R
1u_)pr
.)SwUo0N
DpPH0R
}~@IR;
i|l`E|
]lVVVG_8|!|
yN<]KS
b&sB9`
xXI96tS
$6 `4w
dR9/ 6
FFFf)2
^_`fyQM
YfkB!`o
_HOYA.
WUgR""
$K[@|b
8|&-u&
`6-u@^
~Xwr^"
#e^bV^
om:G(c
~l\rrrrH<&
srrr2*F`vrrrr
t$9999>Vn
(NNNN6L\hNNNN~
vr;9tp
0@''''Xp
no such p
GT@prr`|g
FN,Jl?8K_
?73`eo
dAe?f9K
8sO&By
ytDuCv
'''' (j8''''gPkp''''l
&((''''@nXo''''p*
h}''''x~
Fgb by|
^izWnQ
/nwn9
%+srmb
C8'=J#k@
rHLP.v!
#N.89
CEpKV#!
NNN(08
0rrrr@Ph
tQ%h#u
& NNNN'()0NNNN*8+@NNNN,H-PNNNN/X6`NNNN7h8pNNNN9x>
!NNNfe
> ?NNNN0@@ANNNNPC`DNNNNxE
R(V''''8WHZ''''Xehk''''xl
P,`rrrr;x>
kH 999
vP_8?`
0rrrrC@
H''''IX
ePrrrr*
/?tNn
rrrr1(x
8X899TH
[aOni*{
~ $s%r
@b;zO]
v2!L.2
Kdo:/O
_RPC-> CR8J
-62&Zb3
26b>0
i&nK7'
kBn{~-
0x%lx
8G?P^XP
b#"_7'
o4juicu
t4-maF^\J'PZ
`wI ')$
X('Cv0(
Phm$vQ
NZ(Z;
W<mow+
_#`uEZK
L3K+LE
' sOnH
VNlhS_s@
KU_+f4
Pp?N7*E
cCMDsh6?b
}n/@Q1
r' ui#(f
*BhFxB
J6@:P$
1293E7
L36AH
$b&"m%
'h-Z\4^
hM[I+,2
VX;0#
nA1$b
/#N;M9
^PNNNN<,
''#O,bHV
ncacn_np
O/\4$a
v4G56v
@;AB|
m'aOst
C\#kG4I/C/C$
Owoh+wL
SFK["H@1
.(')0'
%v9PH'OP
9ypu&r
Ndr=WbH+
V@UNTIME140O
Vw4`f7
$i-r-w
hE+8FH
P-%#k`
A1-XjoW
O9%D-QX
pK5GLQ
XPTPSW
ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.DLL
SHELL32.dll
SHLWAPI.dll
USER32.dll
WINSPOOL.DRV
RegCloseKey
Escape
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
PathFileExistsA
ClosePrinter
VS_VERSION_INFO
StringFileInfo
080404B0
FileVersion
5.2.0.0
FileDescription
Microsoft Windows Run DLL
ProductName
Microsoft Windows Run DLL
ProductVersion
5.2.0.0
CompanyName
Microsoft Windows
LegalCopyright
Microsoft Windows Run DLL 2020
Comments
Microsoft Windows Run DLL
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Scar.lpjJ
tehtris Clean
ClamAV Win.Dropper.Tiggre-9845940-0
CMC Clean
CAT-QuickHeal Ransom.Genasom.16527
Skyhigh BehavesLike.Win32.Generic.dc
McAfee FE_HackTool_Win_JAYPOTATO_1
Cylance Unsafe
Zillya Trojan.CoinMiner.Win32.52039
Sangfor Trojan.Win32.Save.a
K7AntiVirus CryptoMiner ( 00593f811 )
BitDefender Gen:Variant.Application.Babar.18581
K7GW CryptoMiner ( 00593f811 )
Cybereason malicious.074462
Baidu Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (moderate confidence)
ESET-NOD32 a variant of Win32/CoinMiner.CIB
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 99)
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Exploit:Win64/CVE-2021-1675.713aff85
NANO-Antivirus Trojan.Win32.JuicyPotato.kpccps
ViRobot Clean
MicroWorld-eScan Gen:Variant.Application.Babar.18581
Tencent Malware.Win32.Gencirc.140f9f19
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1369711
DrWeb Trojan.Siggen28.55597
VIPRE Gen:Variant.Application.Babar.18581
McAfeeD Real Protect-LS!F9F534207446
Trapmine malicious.high.ml.score
FireEye Generic.mg.f9f5342074462fa1
Emsisoft Gen:Variant.Application.Babar.18581 (B)
Jiangmin Clean
Webroot Clean
Varist W32/ABRisk.POED-2097
Avira HEUR/AGEN.1369711
MAX malware (ai score=73)
Antiy-AVL Trojan/Win32.Blamon.a
Kingsoft Win32.Trojan.Generic.a
Gridinsoft Trojan.Win32.CoinMiner.sa
Xcitium Packed.Win32.MUPX.Gen@24tbus
Arcabit Trojan.Application.Babar.D4895
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Win32.Trojan.PSE.11N2JTZ
Google Detected
AhnLab-V3 Clean
Acronis Clean
ALYac Gen:Variant.Application.Babar.18581
TACHYON Clean
VBA32 BScope.Backdoor.BlackMoon
Malwarebytes Trojan.BitCoinMiner
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.BLACKMOON.YXEFVZ
Rising HackTool.JuicyPotato!1.BD74 (CLOUD)
Yandex Clean
Ikarus Trojan.WinGo.Ranumbot
MaxSecure Clean
Fortinet W32/Agent.AZID!tr
BitDefenderTheta Gen:NN.ZexaF.36808.qmKfa89emHkb
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud HackTool:Win/Juicypotato
No IRMA results available.