Static | ZeroBOX

PE Compile Time

1992-06-20 07:22:17

PE Imphash

d609a88c9c1c0b83071e61f9c45f78d2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
CODE 0x00001000 0x00002758 0x00002800 6.39491260074
DATA 0x00004000 0x0000007c 0x00000200 1.38027966113
BSS 0x00005000 0x00000490 0x00000000 0.0
.idata 0x00006000 0x000004b4 0x00000600 3.68185181351
.tls 0x00007000 0x00000008 0x00000000 0.0
.rdata 0x00008000 0x00000018 0x00000200 0.20448815744
.reloc 0x00009000 0x000002c4 0x00000000 0.0
.rsrc 0x0000a000 0x0000bb34 0x0000bc00 7.50788489513

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0000a4a8 0x00000128 LANG_FRENCH SUBLANG_FRENCH GLS_BINARY_LSB_FIRST
RT_ICON 0x0000a4a8 0x00000128 LANG_FRENCH SUBLANG_FRENCH GLS_BINARY_LSB_FIRST
RT_RCDATA 0x000157d0 0x0000000c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x000157d0 0x0000000c LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x000157dc 0x00000022 LANG_FRENCH SUBLANG_FRENCH data
RT_VERSION 0x00015800 0x00000334 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library kernel32.dll:
0x406074 VirtualFree
0x406078 VirtualAlloc
0x40607c LocalFree
0x406080 LocalAlloc
0x406084 TlsSetValue
0x406088 TlsGetValue
0x40608c GetModuleHandleA
0x406090 GetModuleFileNameA
0x406094 GetLastError
0x406098 GetCommandLineA
0x40609c WriteFile
0x4060a0 SetFilePointer
0x4060a4 SetEndOfFile
0x4060a8 RtlUnwind
0x4060ac ReadFile
0x4060b0 RaiseException
0x4060b4 GetStdHandle
0x4060b8 GetFileSize
0x4060bc GetFileType
0x4060c0 ExitProcess
0x4060c4 CreateFileA
0x4060c8 CloseHandle
Library user32.dll:
0x4060d0 MessageBoxA
Library kernel32.dll:
0x4060d8 WriteFile
0x4060dc SizeofResource
0x4060e0 LockResource
0x4060e4 LoadResource
0x4060e8 LoadLibraryA
0x4060ec GetTempPathA
0x4060f0 GetTempFileNameA
0x4060f4 GetProcAddress
0x4060f8 FreeResource
0x4060fc FreeLibrary
0x406100 FindResourceA
0x406104 FindFirstFileA
0x406108 FindClose
0x406114 DeleteFileA
0x406118 CreateFileA
0x40611c CloseHandle
Library user32.dll:
0x406124 TranslateMessage
0x406128 PeekMessageA
0x40612c MessageBoxA
0x406130 GetActiveWindow
0x406134 DispatchMessageA

This program must be run under Win32
.idata
.rdata
P.reloc
P.rsrc
YZ]_^[
YZ]_^[
YZ]_^[
_^[YY]
YZ]_^[
Ht Ht.
0123456789ABCDEF3
t hh3@
GGSfxExecutePack
_^[YY]
Resource not found
This program is designed for internal use only.
GSfx Wizard 1.1
Runtime error at 00000000
kernel32.dll
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
TlsSetValue
TlsGetValue
GetModuleHandleA
GetModuleFileNameA
GetLastError
GetCommandLineA
WriteFile
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
ExitProcess
CreateFileA
CloseHandle
user32.dll
MessageBoxA
kernel32.dll
WriteFile
SizeofResource
LockResource
LoadResource
LoadLibraryA
GetTempPathA
GetTempFileNameA
GetProcAddress
FreeResource
FreeLibrary
FindResourceA
FindFirstFileA
FindClose
FileTimeToLocalFileTime
FileTimeToDosDateTime
DeleteFileA
CreateFileA
CloseHandle
user32.dll
TranslateMessage
PeekMessageA
MessageBoxA
GetActiveWindow
DispatchMessageA
33333330
{{{{{{{3
{{{{{{{33
{{{{{{{330
{{{{{{{330
{{{{{{{330
3333333
33333333
wwwwwwwwwww
DDLLLL@
DLDLLLGpw
wwwwwwwwwww
This program must be run under Win32
.idata
.edata
.reloc
5<?YSZ
@_K'rle
,dEiVJ
u4hHghJ
>AaKDn
]-nEeO"
jM/6|o]
YY|2_qy;
Q?'dEQc
{+mXcJ
{_l}#-@
ncBRC?T2
7sHt2;
5<%:WXG0k
6%>Q@QF
Ck|?|bac
wUt2-"
ipsuzP
&v!~cE
S[Y\\U
6`xTHk
{Ir2q#
d))N,5
05patWrW
YYd\&0~2
"";3i1
lW:%3C]
zSj$!%
.b<jt-
dD+&5
o4~}^s
=iD,~_97
:}t-\R
AI<QZb5
zl/Z+h6
wy+9"5
B:H]\&fl
A"5$+B(
`!B{Q
vfb)&Vw
W{}<zu6
~DaGPw,
Eg%gEga
64+V*<3
?x2DI_S
!KcNG[
luh.Zl?2]
;)f"1j
PP2bD
>YT[dV91
K!x43s>hB
r!;G{U
a*gC1w
Cj|S|=3-
Iqj?<@
3@'/>
Yxe{\oS
Y& ns6
M"f3aD
JMUJ$~
^-=!1`,
k*[gnpy
CZN$%~
3"nNV^fnv}
*%bVEH
V\YerY-
0,7QL#
;u}&z5M
GSfxDll.dll
GGSfxExecutePack
DF( "
E>}#b}
m+t-}"
]Te1Wu^
`S/7_^p
YEf`+iUT
R@ii,YDW_
Ld?Tzd
"Ih$a.v
PAAiKL
9Dsc0dl
6VR]-}N
z q?cv`
(08@P`p
kernel32.dll
VirtualAlloc
VirtualFree
ExitProcess
user32.dll
MessageBoxA
wsprintfA
LOADER ERROR
The procedure entry point %s could not be located in the dynamic link library %s
The ordinal %u could not be located in the dynamic link library %s
kernel32.dll
GetProcAddress
GetModuleHandleA
LoadLibraryA
user32.dll
advapi32.dll
oleaut32.dll
gdi32.dll
user32.dll
comctl32.dll
shell32.dll
GetKeyboardType
RegQueryValueExA
VariantClear
SetTextColor
WaitForInputIdle
InitCommonControls
ShellExecuteA
bc3Mc|
ns]LJd?~2
$9-!(*8k
P)#Y3~
nBbZGT
C?N+K7
`o6my5
b%Niw-
=r29R"
|z.u_&bH
^KwTp,JA
znu~4r
koik36L
A^)e,M
china.htm
china.jpg
~!--0S$l
^wzpO{x
;:pl&o
/&phaji
11;;cn
9Vc66{
(;FW;#i\
H5e24
5q6"k%6g
nv124Hs
6Q Ze9
(U?:vi3
O0yuqV`
b"5LN5
x9;_3&ZT
AL;N=k
)'+B)%
.iL#[b
Gv;M+r
wp~ETv
<vU%6r
<,mU\a
fCc%tp\
:vCn="\]
zq3BgiFFz
MAINICON
DVCLAL
PACKAGEINFO
VS_VERSION_INFO
StringFileInfo
000004b0
FileDescription
GSfx Archive Runtime Module
FileVersion
1, 0, 2, 0
LegalCopyright
Copyright
2000-2002 by Guillaume Di Giusto. All Rights Reserved.
ProductName
GSfx Wizard
ProductVersion
1, 1, 1
http://www.gdgsoft.com
VarFileInfo
Translation
VS_VERSION_INFO
StringFileInfo
000004b0
FileDescription
Funletters
FileVersion
1, 0, 1, 0
LegalCopyright
By CloudEight Stationery
ProductName
Cloudeight Funletters
ProductVersion
1, 1, 0
http://funletters.net/
CompanyName
CloudEight Funletters
Comments
Packaged with GSfx Wizard, http://www.gdgsoft.com
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
ClamAV Win.Trojan.Generic-9787872-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Cylance Unsafe
Zillya Backdoor.mIRC.Win32.654
Sangfor Clean
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec Clean
Elastic Clean
ESET-NOD32 Clean
APEX Malicious
Avast Clean
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD ti!D417C5248D33
Trapmine malicious.high.ml.score
FireEye Clean
Emsisoft Clean
SentinelOne Static AI - Suspicious PE
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft PWS:Win32/Fareit!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Zapchast.fx (CLASSIC)
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
DeepInstinct Clean
CrowdStrike Clean
alibabacloud Clean
No IRMA results available.