Static | ZeroBOX

PE Compile Time

2024-07-09 05:36:51

PE Imphash

a338797fb02813f0ef44a2dae655cd61

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00194158 0x00194200 6.40683066282
.data 0x00196000 0x00000940 0x00000a00 2.07121412999
.rdata 0x00197000 0x0000aa00 0x0000aa00 4.57710290601
.pdata 0x001a2000 0x00004674 0x00004800 6.05517186065
.xdata 0x001a7000 0x00003bd4 0x00003c00 4.11070475144
.bss 0x001ab000 0x00065ed0 0x00000000 0.0
.idata 0x00211000 0x00000664 0x00000800 3.56446403608
.CRT 0x00212000 0x00000068 0x00000200 0.392179842276
.tls 0x00213000 0x00000010 0x00000200 0.0
.rsrc 0x00214000 0x00000138 0x00000200 1.6285554479
.reloc 0x00215000 0x00000324 0x00000400 4.61048775543

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00214058 0x000000dc LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x1402111ac DeleteCriticalSection
0x1402111b4 EnterCriticalSection
0x1402111bc GetLastError
0x1402111c4 GetProcAddress
0x1402111cc GetStartupInfoA
0x1402111dc LeaveCriticalSection
0x1402111e4 LoadLibraryA
0x1402111f4 Sleep
0x1402111fc TlsAlloc
0x140211204 TlsGetValue
0x14021120c TlsSetValue
0x140211214 VirtualAlloc
0x14021121c VirtualFree
0x140211224 VirtualProtect
0x14021122c VirtualQuery
Library msvcrt.dll:
0x14021123c __C_specific_handler
0x140211244 __getmainargs
0x14021124c __initenv
0x140211254 __iob_func
0x14021125c __lconv_init
0x140211264 __set_app_type
0x14021126c __setusermatherr
0x140211274 _acmdln
0x14021127c _amsg_exit
0x140211284 _cexit
0x14021128c _commode
0x140211294 _fmode
0x14021129c _initterm
0x1402112a4 _onexit
0x1402112ac abort
0x1402112b4 calloc
0x1402112bc exit
0x1402112c4 fprintf
0x1402112cc free
0x1402112d4 fwrite
0x1402112dc malloc
0x1402112e4 memcpy
0x1402112ec memset
0x1402112f4 signal
0x1402112fc strlen
0x140211304 strncmp
0x14021130c vfprintf

!This program cannot be run in DOS mode.
`.data
.rdata
@.pdata
@.xdata
.idata
.reloc
AUATUWVSH
[^_]A\A]
[^_]A\A]
SS<@)_U7H
RS<@)_U7I1
?%'cL1
>"X{dI
:+\JH1
)D$ fA
P;MZM1
L-HT;aTL1
WH ~M1
s+CFvB2
MzU[,:I
'7EHw"M1
)L$ fD
(D$@fA
/q!HH1
9%:p[c
L$`H9H
Og3RI1
L$HH9H
L$8H9H
%qY~aA
D$HH;H
}nihEI
!B3|ZH
'A'%XI
'A'%XL1
)D$ fA
mDU#M1
L$XH9H
5UUt0I
zDkRxI
U="iL1
&1kUVM1
8oaoL1
JHH;J@H
<A%NH1
D$`H9B(H
L$(H9H8
>0{*M1
npl7CI
)D$@fA
g}J]eRL1
+2 xM1
, qM1
)D$ fA
51,$I1
PDI,j9iI
PDI,j9iL1
! R0I1
)D$ fA
5<D2L1
X?M)H1
#;IBH1
} [wH1
8'BfO,
8'BfO,
XKRIOI
XKRIOL1
"'gpD2
#'gpD2
x;r=M1
`KcA=(L1
"+`aI1
U_`L4H
B:dTbI1
~LrFNH1
`WD:`t
`WD:`t
t0DsL1
j;h",=
j;h",=
t91f|L'HH
L?ug"M1
c/ UYGI
)D$ fA
?7<<*k
>'@1H1
Z=fDH1
MJmJH1
X|r.pbH
X|r.pbH1
i[t>L1
k5:yM1
3><<.R
j_)jM1
Q(`Y?I
`]f5`]f
O3#t;H
Pt<_H1
}{GRL1
Tw4}?I
g^qQTI
g^qQTM1
uH7iM1
d"CXL1
,JApH1
F AL1
AXH;Ah
qa&oH)
YF->bI
]wt M1
D$PH9QXH
U$+(gI1
EHf5JGf!
cTI4"F
g=U}CI
g=U}CM1
V&`E1
[U<"";H
?COxH1
2}VCiH
AS#|"I1
UAVVWSH
7`2MqgT
9QQ*I1
(psyM1
a1)Ajz
vB$rq[
Lm(gH1
30J_%h
F^6\DI1
[_^A^]
RWq L1
{s@ H1
'Ka&kDI
'Ka&kDL1
-fV_L1
nm4vH1
Z7NzM1
5R<qL1
p&9eH1
N`qFM1
'5<}5I
0bNi!jI
D?|>M1
/ G&WjL1
M-+%ex
M-+%ex
pu4&H1
b[tzH1
t1~TL1
87qHR_
=!:m"fl
Oz5mYduI
4c3_L1
YkG.wH
YkG.wH1
T1(vI1
QmG &H
QmG &I1
[$0f&>
Z$0f&>
'O7=M1
Dk1dHI
wmM)H1
M:[aM1
i[wJ!A
k[wJ!A
L$HH;B
KF>dU75rI1
Q[P[I1
|;g8M1
weJ>H1
J!T5H1
L$HH;B
L$HH;B
(cAqL1
-z#SI1
UAVVWSH
[_^A^]
<6n\H1
y) CH1
L$HH;B
L$HH;B
W5\dECt
?"XTw!I
UAVVWSH
[_^A^]
U7g)!H
U7g)!I1
$u)"~qqAL1
G4dMqL1
cU]P3H
cU]P3H1
<|(.uH
<|(.uH
4* 6M1
UAWAVVWSH
xnqoL1
[_^A^A_]
a_u5tI
`\ \lI
%DK$tI
.goN/I
(!\Qv]<
8!\Qv]<
oYKTH)
W\gHl}
W\gHl}
%i~8.H
%i~8nH1
$r67|-
%r67|-
2pka!H
2pka!I1
_|x$>pI
eZYeM1
)D$ fA
T$&fA1
vJj)Cj
AVVWUSH
[]_^A^
_Ol!vX
51=]oL1
jl~|=I
j!>xL1
66d=H1
IKptH1
v9pZ-DjI
@r|%l7
@r|%l7
RGS.F%rxI1
uah8K.
tu\nYI
X`2 [H
vrJlL1
KjU#H1
9k0KM1
Nz1`"Rx
Ff"0sH1
,a_=E1
UAWAVAUATVWSH
]Hgj,M1
[_^A\A]A^A_]
;oi!"?I
D$hH9H
L$0H;A
UAWAVAUATVWS
,%kOd
:%kOd
:u>]vI
2d\SL1
EF+sL1
[_^A\A]A^A_]
9!-e-H}
9!-e-H}
A_S_DI
A_S_DL1
$ LWn$I
UAWAVAUATVWSH
%$?B^%
#Q9/9H
#Q9/9H1
[W.{H1
[_^A\A]A^A_]
BoHxSH
BoHxSH1
>$;XM1
tUagpeH
WA# QL1
{T6)6I1
Lb3d>H
Lb3d>H1
<-jlL1
.2#XM1
KvRZI1
;&_~rI
;&_~rL1
]&m4kI
]&m4kM1
D]|WY,cUL1
GR$l+H
xn2'H1
>PL qH
>PL qH1
L$HH;B
L_1 =`I
U H;A
\[v!\2
k1{tTiI
cZz[H1
jBIhlM1
Lf5(Lf
Jf5PKf
8&f5]'f
,C{1L1
D$(B:L
^zf5!zf
YrR=LI
YrR=LM1
.f5m.f
Pff5idf
9W>#E1
D$8Hc@
nSQN| I
VRO@mI
{c8XM1
UAWAVAUATVWSH
O41hUH
e6J{UI
^QahI1
1c~LL1
K{VII1
`;_*M1
ex[_^A\A]A^A_]
kQ$ZR1'I
kQ$ZR1'_L1
g.f53,f
Z#)QL1
6V6*I1
[DnTH1
ZB%P_H
ZB%P_H1
U#LTl(L1
U#LTl(L
-%pyB
WMNS$6H
~=''0x@
K7QzL1
?JZ]~p
?JZ]~p
UAWAVVWSH
`7f3|M1
dRt8_<
D$ 0"M
eiz;jL1
[_^A^A_]
UAVVWSH
&x3jM1
j.xu$
&:%T7H
<MmH[H
<MmH[H1
>z>(M1
iiW^mH
iiW^mH1
%ThT)I
%ThTiL1
[_^A^]
V]UqL1
123F[rI
M8?J<H1
UAWAVVWSH
fc2]H1
j&HNL1
[_^A^A_]
C27L1
:UCwH1
"f;3I1
\w+z7I
i,B/E+M1
#eG1H1
e]R2H1
}DrvvI
}Drv6L1
{!i0M1
@W*uM1
JLN]?Y
>i&6L1
%hlo_I
tnh-cH
tnh-cH1
S,c|rQ<H
gC-\L[
gC-\L[
n"3fH1
B>KMH!
B>KMI1
B>KML!
}qvCM1
#,<wSH
UAWAVAUATVWSH
TJ(XH1
Df59Gf
J|qIH1
,YSQAI
^JE U;
^JE U;
tRDo8_
G<wCH1
[_^A\A]A^A_]
rX;)Yha
bX;)Yha
F0w8I1
*<<kfD9
8!k?I1
Z8{fD9
KT}7!L1
2:wJ>H
2:wJ>I1
n=PSH1
QHExH1
F_nXH1
?*7{H1
l[cuM1
Gis7cC
/i"$vPH
/i"$vPH1
F\mJfD9
Q&|<I1
N`%iwH
N`%iwH1
VeVENw
VeVENw
[T gI1
d2h:WI
d2h:WL1
}c|<GM1
xpO/H1
rF=Z5I
0SX\M1
\/`r$b
\/`r$b
jRI)L1
@BZ29aTH
@BZ29aTH1
`rjw L1
j/90oR
L$HH;B
% V0H1
rB_GpH
rB_GpH1
=FbiSH)
=FbiSH
UAWAVAUATVWS
ao%4)|H
ao%4)|H1
-CompH
-CompH1
XcZq]H
XcZq]H1
ScYKM1
YDuzM1
ol0%M1
%KJ-L1
;8L]4XFH
g,j5NH1
F6.<M1
RSk3H1
WY9`xf
WY9`xf
[_^A\A]A^A_]
ClwWGL1
7?dnH1
O+~15B|
?(N_pH1
O+}oL1
UAWAVAUATVWSH
*55<wI
*55<wL1
JwRbI1
ELWc:3
T6kzs9
~Et2/h0
&C?m1yH
&C?m1yH1
jS}\OzH
U&l6M1
[_^A\A]A^A_]
QUS:H1
UAWAVAUATVWSH
LX`&I1
4a 3-+44L1
z&FL}.nI
29_iwH
NnumH1
Od\rI)
Od\rI)RL1
[_^A\A]A^A_]
.*<kG$$H1
+4G}bH
+4G}bH1
@b:#UM1
?t?UN4
.j(L1
|41YaH1
!aPvoH&
!aPvoH&
^b^bM1
S3mg9I1
,72KM1
yf5G}f
|!{I=N
~,ufH1
zkKFWiM1
S#&hO^H1
4d(2Uj>
3d(2Uj>
UAWAVAUATVWSH
`0)bL1
I11iM1
[_^A\A]A^A_]
UAWAVAUATVWS
0ZZfkHI1
0ZZfkHI
v'BjL1
Y;bHzlM
Y;bHzlM
;NgFkH
;NgFkH1
`.6]L1
"ZC?tF\.I
8M9*>u
8M9*>u
Rt>5UM1
[_^A\A]A^A_]
=KW4H1
Ke<\^V
j86V~eU
j86V~eU
UAWAVAUATVWS
/>wsI1
**}Uz0I
**}Uz0L1
4If5hJf
ANG<N^
ANG<N^UL1
}f5Q|f
[_^A\A]A^A_]
glXIL1
Fs$n_H
Fs$n_H1
d7p'L1
6<X^H1
UAWAVAUATVWS
"!PwI1
zjgKM1
%~"oI1
UJ'L1
HPw^eL1
f8SoM1
sD$`ETp
sD$`ETp
X_8A_&u
X_8A_&u
rt)NL1
Lv{U_H
Lv{U_I1
R_TdH1
[uay;=
2(<,L1
S'K?HN
S'K?HN
:9\]u4H
:9\]u4H1
Oa//bM1
VT_|H+
hu2q{
mk84*M
.f5G,f
'J6K;I
'J6K;L1
p8MzL1
[_^A\A]A^A_]
1<ooM1
1#OH1
}Tm(^gX
0i>BI1
S}uw]
S}uw]
)Hk&-H1
}f5f}f
;4L!L1
j L7#yN
m L7#yN
1E<@AH
1E<@AH1
Gz9@L1
L$8H;B
gJZX.H)
gJZX.H
i(36H1
V<<bH1
:-NYrD
:-NYrD
M;5ZH1
p@V|jv
p@V|jv
G]2YDa
TE\L1
*hombk
>aRu-I
92{GIH
92{GIH1
VShcz(
/7CoH1
3TMC`DJeH
3TMC`DJeH1
Jf5.Cf
.Lf5iNf
V|\vK_
+YiPM1
b'WM1
M0H;A(
L$HH9H
u9d+L1
Qe8G*49H1
QaVS;I
&~^zH1
V%jDL1
]s}$WL1
AcnTL1
C*QH1
3f5c5f
"f5@)f
2f5=5f
;hf5elf
xf5!rf
DDB9L1
0Zu*H1
~A,$L1
DS|$nJH
;YoBdH
PUUM.M1
g}vZH1
NPh,L1
>C2!L1
l#)?lIH1
CuJ+5d7?H
ATUWVSH
P[^_]A\
P[^_]A\
UAWAVAUATWVSH
[^_A\A]A^A_]
ATWVSH
([^_A\H
tNHcA<H
tTIcB<L
tCHcA<H
tKIcA<L
tSIcK<L
InitializeConditionVariable
WakeConditionVariable
SleepConditionVariableCS
@kernel32
@kernel32
CreateThread
@kernel32
@kernel32
@0123456789ABCDEF
@\\?\UNC
.7:266
.7:266
n U&KQ
7$::8)
sQxJ=R1
7$::8)
CloseHandle
LoadLibraryA
GetProcAddress
LoadLibraryW
GetProcessHeap
SetErrorMode
GetDriveTypeW
GetLastError
VirtualFree
VirtualAlloc
GlobalLock
GlobalSize
GlobalUnlock
GlobalFree
@kernel32
@kernel32
@@kernel32
MultiByteToWideChar
WideCharToMultiByte
@Advapi32.dll
@kernel32.dll
@ole32.dll
@psapi.dll
@user32.dll
@winhttp.dll
@shell32.dll
@@NtProtectVirtualMemory
NtOpenFile
NtQuerySystemTime
NtCreateFile
NtQueryDirectoryFile
NtWaitForSingleObject
NtClose
NtCreateEvent
NtOpenEvent
NtQueryInformationFile
NtQueryFullAttributesFile
NtOpenProcess
NtQuerySystemInformation
NtDuplicateObject
NtQueryObject
NtCreateSection
NtMapViewOfSection
NtAllocateVirtualMemory
NtFreeVirtualMemory
NtReadVirtualMemory
NtWriteVirtualMemory
NtReadFile
NtDelayExecution
NtQueryInformationProcess
NtQueryAttributesFile
GetSystemInfo
@kernel32
@kernel32
@venue
@mqquv?**gcijr(hpvlfj+cpk*Ilhd 75F`kqwdi 75Fdqmjilf 75Mlbm 75Vfmjji
GetModuleFileNameW
CreateFileW
@kernel32
@kernel32
kernel32
@dsEf5kW1fmLw
DeleteCriticalSection
EnterCriticalSection
GetLastError
GetProcAddress
GetStartupInfoA
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryA
SetUnhandledExceptionFilter
TlsAlloc
TlsGetValue
TlsSetValue
VirtualAlloc
VirtualFree
VirtualProtect
VirtualQuery
__C_specific_handler
__getmainargs
__initenv
__iob_func
__lconv_init
__set_app_type
__setusermatherr
_acmdln
_amsg_exit
_cexit
_commode
_fmode
_initterm
_onexit
calloc
fprintf
fwrite
malloc
memcpy
memset
signal
strlen
strncmp
vfprintf
KERNEL32.dll
msvcrt.dll
#+3;CScs
VS_VERSION_INFO
StringFileInfo
040904E4
VarFileInfo
Translation
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Clean
Zillya Clean
Sangfor Trojan.Win32.Agent.Vzk6
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Avast Clean
Cynet Clean
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Trojan.Win64.AMADEY.YXEGIZ
McAfeeD Clean
Trapmine Clean
FireEye Generic.mg.dea351e95b2d5b0a
Emsisoft Clean
SentinelOne Clean
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Unknown.a
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Sonbokli.A!cl
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Trojan.Win64.AMADEY.YXEGIZ
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (D)
alibabacloud Clean
No IRMA results available.