Static | ZeroBOX

PE Compile Time

2024-07-15 18:52:07

PE Imphash

1efa1310f9268b62f071617d0730aefa

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00005b52 0x00005c00 6.28825539955
.rdata 0x00007000 0x0000acde 0x0000ae00 6.68350997046
.data 0x00012000 0x00013288 0x00013200 6.93240073579
.pdata 0x00026000 0x000001bc 0x00000200 3.9741367512
.rsrc 0x00027000 0x00000a40 0x00000c00 3.09195352526
.reloc 0x00028000 0x0000000c 0x00000200 0.0815394123432

Resources

Name Offset Size Language Sub-language File type
BLLMJXN 0x00027110 0x000001bb LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00027800 0x0000023a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00027800 0x0000023a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_STRING 0x00027800 0x0000023a LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x140007000 EnterCriticalSection
0x140007008 LeaveCriticalSection
0x140007018 CreateFileA
0x140007020 CloseHandle
0x140007028 GetComputerNameA
0x140007030 GetLastError
0x140007038 GetCurrentDirectoryA
0x140007040 FindFirstFileA
0x140007048 FindNextFileA
0x140007050 GetCurrentThreadId
0x140007058 LockFile
0x140007060 UnlockFile
0x140007068 OpenFileMappingA
0x140007070 CreateNamedPipeA
0x140007078 WaitNamedPipeA
0x140007080 ExitProcess
0x140007088 VirtualAlloc
0x140007090 GetLocalTime
Library OPENGL32.dll:
0x1400070a0 glNewList

!This program cannot be run in DOS mode.
Richy%
`.rdata
@.data
.pdata
@.rsrc
@.reloc
SUVWATAUAVAWH
XA_A^A]A\_^][
WAVAWH
0A_A^_
UVWATAUAVAWH
PA_A^A]A\_^]
\$ UVWATAUAVAWH
PA_A^A]A\_^]
x ATAVAWH
@A_A^A\
x ATAUAVAWL
Lc\$PI
t$8A_A^A]A\
WAVAWH
0A_A^_
WATAUAVAWH
Ht+M$1
A_A^A]A\_
x ATAVAWH
0A_A^A\
WAVAWH
A_A^_
WAVAWH
A_A^_
x ATAVAWH
0A_A^A\
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
0A_A^A]A\_
WAVAWH
@A_A^_
UVWATAUAVAWH
@A_A^A]A\_^]
WATAUAVAWH
9Cpt:D
A_A^A]A\_
@SUVWATAUAVAWH
H;D$Xt
HcL$`A
H3D$XH
HcL$`H+
A_A^A]A\_^][
UVWATAUAVAWH
D$pM;$
A_A^A]A\_^]
T$05*.
WAVAWH
@A_A^_
BPA1JpA
HPA3I@A
x ATAVAWH
@A_A^A\
@@A9@pw
SUVWATAUAVAWH
H+L$xHc
A_A^A]A\_^][
{ UATAVH
\$ UVWATAUAVAWH
@A_A^A]A\_^]
SUVWATAUAVAWH
xA_A^A]A\_^][
WATAUAVAWH
9ElsKH
A_A^A]A\_
WATAUAVAWH
0A_A^A]A\_
ignorant; glimpse, woodlands. illusion
useless. ungrateful, urgently, eliza; loudly, new, inspiration. bill; brass. bestowed
bean; knew# confinement,
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSection
CreateFileA
CloseHandle
GetComputerNameA
GetLastError
GetCurrentDirectoryA
FindFirstFileA
FindNextFileA
GetCurrentThreadId
LockFile
UnlockFile
OpenFileMappingA
CreateNamedPipeA
WaitNamedPipeA
ExitProcess
VirtualAlloc
GetLocalTime
KERNEL32.dll
glNewList
OPENGL32.dll
w]5Xig
2kLBGq
.g<P9+
8%qdyG
\i?AO]
_J\{M`
*f[~y_
5*+z(b+
wxJ>hK
?Fgu=}
;RHgq+?
(g^##}3
YOOYFXa%
C,kjD,B
:{UU>P
[v*gF2
>%Am+{I
{9.CJD
3;iLmO
XT!u;r
c;/!tMgf
QDH~nH-
qQ8|KX
Q>>agY
D|I(OwV
GLZc@F
1dCFg"
`g3-MzCU
pRJkz7
f).?;"
vE)i''T
FB_#f.L
Uokv"E
Jw3'6eM
aQ<k|
52n9,* wkC
+O]Aeau
e0kQ'`
dL}|~B
;39U%Z
U&r\rK
h}VZ<v
`lhmt7
M5Rj;.
Qq9{ff
]23gVi
PW*h>M
%s$ beaker/ lay\ Rivers
BLLMJXN620$ 266 %d Leapt- always asia
yawn Audacity? rapt$ 229! leisurely! Slang Comics!
%s %d 351, closure$ %d
stun( 76 948 Bracket/ riding muscular illuminated$ %s,
capital+ %d? sofa palace %s readinessstage) %s
=elizabeth$ chauffeur, %d? comprehensive Captivity Inquisitive
&935 Branches$ Registry. cranny- Close
%d\ Race Thorny?
)Delicate\ Hide, Commit %d 694$ Permitted-
dried) Hari@ /%s Picnic. threw/ Servers furthermore jerusalem
176) %d$ 527- 384, playing )844@ Suppress_ Lobby! Proceed/ pregnant,
834 Terribly Quit asks
/Masterpiece\ %s_ Gravity$ 66? speaker suggested
-Provisions %s suggested( %s, 102 Anxiety junk
'941@ rob Galactic %d/ Ted %s sunny 414)
(sensitiveness$ Constitution 960! Week%d@Aattacks Consist Point joan Involuntary- nervous connections 629+
502@ %s Pity5exceedingly units Rumour( %s_ Listened_ Marine( star,
Combined? grin naughty
%s( Potatoes-
2Terrible paw Furnish resigned %s/ comic haven, %s 6%s These) altitude Unfinished Neat? %d? pull Fragment
2178. elongated %d Inhabitants! %s/ moth %d, Blast!
645 Apparatus 972
-Versions Polish expect Adventurer) distinctly
&deduction_ Nowadays( fastened! feeling
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.Latrodectus.7!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win64/Kryptik_AGen.LS
APEX Malicious
Avast Win64:BankerX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky Trojan-Banker.Win64.Latrodectus.t
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/AVI.Agent.eiazz
DrWeb Clean
VIPRE Clean
TrendMicro TrojanSpy.Win64.STEALC.YXEGPZ
McAfeeD ti!0822D4C51C46
Trapmine Clean
FireEye Generic.mg.a907d2e6edda8294
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
GData Win32.Malware.Latrodectus.FQLXOP
Jiangmin Clean
Webroot W32.Trojan.Win64.Latrodectus
Varist W64/ABTrojan.YZTP-7053
Avira TR/AVI.Agent.eiazz
Antiy-AVL Trojan[Banker]/Win64.Latrodectus
Kingsoft malware.kb.a.998
Gridinsoft Ransom.Win64.Wacatac.cl
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Trojan-Banker.Win64.Latrodectus.t
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes Trojan.MalPack
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win64.STEALC.YXEGPZ
Rising Trojan.Kryptik!8.8 (C64:YzY0Oup3na34UNDE)
Yandex Clean
Ikarus Trojan.Win64.Crypt
MaxSecure Clean
Fortinet W32/PossibleThreat
BitDefenderTheta Clean
AVG Win64:BankerX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Clean
No IRMA results available.