Static | ZeroBOX

PE Compile Time

2024-07-31 19:45:44

PE Imphash

ff764c3d5517b7ba18154cf01d80c42b

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x0004a000 0x00000000 0.0
UPX1 0x0004b000 0x00077000 0x00076200 7.99908307033
UPX2 0x000c2000 0x00001000 0x00000400 2.72713755846
.rsrc 0x000c3000 0x000002a0 0x00000400 4.23516626999

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000c3058 0x00000248 LANG_CHINESE SUBLANG_CHINESE_SIMPLIFIED data

Imports

Library KERNEL32.DLL:
0x4c20c8 LoadLibraryA
0x4c20cc GetProcAddress
0x4c20d0 VirtualProtect
0x4c20d4 VirtualAlloc
0x4c20d8 VirtualFree
0x4c20dc ExitProcess
Library ADVAPI32.dll:
0x4c20e4 RegCloseKey
Library COMCTL32.dll:
0x4c20ec None
Library GDI32.dll:
0x4c20f4 SaveDC
Library SHELL32.dll:
0x4c20fc DragFinish
Library SHLWAPI.dll:
0x4c2104 PathFileExistsA
Library USER32.dll:
0x4c210c GetDC
Library WININET.dll:
0x4c2114 InternetOpenA
Library WINSPOOL.DRV:
0x4c211c ClosePrinter

!This program cannot be run in DOS mode.
R>'x2
+}"--q
Q357Rp
*wQIu
|8z2#[A
LE|y
&{ul,wM
UWxe$X8
~vJ{w[
=s|gI<
EqgCBy
O+UJk$
Xn9{|w
cG"k=#
n7dbz68h
cZx'G|
y8kg5rq
mqS5gG
r0wn_>
#n-&QK29
+o(k-S
s'A|ud
71K|i#
}ZIAx$8
i4v7Q%
%`a^D-n'
))gU:?
KJXuz'
h1&l_
T}&12v
!/FwH)\
CZ3\tQ
1VSo$9e
/hIAd
{Pq-/5=~
Ey>(YU
d1{C&Ds
z*=e`;D
o6Zr48
D!b|),
oGAs4kp
{.%;o&
x2/YtPHCR
H/GEMcPk
1JKxj14
8$YRq/
m_*P&iX
!!9~CT8$G-
*UdIW`
Q3DOe4
B@.bR1^E
*|H]W.
8$Ma%m&c
;;BVFt
2c>[Ys
!gun)S$>
/t/1"k
B:d7i?
O+sX-s
cw%E{P
kFi|m}+!
?%.z2n
:+Hz4r
YV+l8-
p!U/{e
PF20<Tb"l
Ds~QNS=w
_K#v0}
FFLo9~f
Ee(<Jm
fY@8|rL
eeGcM0
GzNA+>#[p
icdOOob
qFH|B;0&'pTG7<
Zyfou9p
moH* n
+8G,Aw
=6E_gh_
U.mz^R
!glPR9#
VM?jKw
GL7H?O
tkW8%J
[lxw1Ft
EFue<
'y4!%+
Rhc5s\
Z7LP,d
*47MFV
\q9Be#
sXGiea
J-u9B
<;eIJh
OExZ@M'R
{X5`aH
chJ=ee
qt4D0H-wc
v,8h`3
^H!P7CJ(
R`;ws U`
DN0Oc#j
|RQs4N~
(:mkk
7ll.)~
$b8'.J1
~GbOZ~
aL[A9U
nQg|iW
H+F\_'
0vT3g)
j+=s+L
Qi~g_/
&t8S/5
T8{IJQD)Y
j6 "&2
GC5\G\
.fh96aO
Ot%]v3
Yc6Be;
%%+Sn\
IzkG^{I
E]<5&r$WR
M!TL.i
>6UYz_Y
Q>~ "d
azGgs:
pD<tf
/doN8hA
Zc_Irw
AwJ)T?
H4p\qa
}!"x0R
]pA^za
d!\2~u
A":gIn
~q!MJ8
Z9,L1pM[
D,`0KJ
#[c#h!}
P6T"Gt
\W&wU
=R\\Zz4Q
Fw&#/a_gm
ja)C~C
qy:vEH
{6iTe<k
[::!1q
x*j*?N
P%^s"y
RR<,ys
JW5BMo^
SY@jXff@+
ncIZ<<
})I)B2
v7z@WVm
SNIKSe;
J`&yw^2[N
1*`>`MmR
gdY|3`Z
VF*P'&2
syej7
9!2?p%
Y*xIHUo<
-K,JBl0
iQ_s.A*
BeG~0E
$OU^&8
}iVJ?s
M 2LOu~+
0.k/%D
M~O}[a,
DCvf-A
H=P0yDg?C
;:Wx5cp
|rk.QD
L!b.\$
1 z8y4
bqv9LJ
FX)ayW{
?OfI"D
[G&pR|
1B|}u"
quVh*vd
Mv|MkP
emue$k
A}`_(t
*1`WAK
esBn5OY
3<KmmC
bFN^/U
Lb0WlU<g
1 fv5 h
)^x,'<
\DZ;@
QEMO'I
RVF4,3
Xr@ep&b
_iGJvt
poCk|>
gTK2om
EWD6<p
1TXOP
SF6Y\Pu
CzIWUm
OtrXYW
@%4|?K
<Hyj"z
j+\z #V
?~eTNo
z!?h"8
~eMtyK
/xw~{R
Dm)3`1P7
+eV;n{
j)h~}s
]g,,\1azAuj
f"\.-l!
UyLi@9
l0JyNUnC
{QMUS>7
4kk699
uz^2J<
x]) [d.J
MqvE")
I~lA=+:t&
#Px=qz
}.7'H6
6Qq{qOy7
xkxJ1/
XpwuxYAC]
?o.%9f
UBb}V$
%^'A"Mx
H&>W=v
):SxBvW
-n,">x
WpB-dy
`Ba}|K
fhla~A]
=!95R1
ko!4bY
_&/<g|
/+Ofr;
BBy!t?0
Fq@^OU
.=LZHk
`<(6{&'
,T9I!3
S|m;wXR5
c*A/eh
V?HA%~?
!Kw1zA
HDT4'?
jRXI#c
~yl[r*
w6dQ5J
U0=vK1
y4o>rWL4
kH7?,<
f"5Kd4
3nQ4L8Y
uC(YuU0m
IF6Vi0
"/TD=`
g6jA2-
87P>qk
9zpqhl
ctunyt
gM"L]F
cPdJ1X
tKAU\]
YuQQYA
/7n[Pn I
z`|}M;~
MLLU/4
zClS+3
jgEC3DG
imRJ8c
{Us~i0
`|R}:J~
K<x6Cv
1I#b_)4_
9AZ9qE
{oa@6}
i:3KFY
<d[p`P
f4xmj!4
|sO,_{
{6SgwjcQ
GLD}Uk~
8 P}X>5
Hlk uk
CV):%;
(!Kz_4
gZHMa2t
,}#BWa
<%A'z]}
j'c}Bm
J:~Y>)D
|mnZEM
R6jw=P_
-nt~fL
*tchL+]
m{.qVg
N\K|4>
[9Oo-JM
7q$b0Z
"61\,B
A\=]42
p~]z$7
to;MeW
z1AO56d
AL?%Bk
e1Tn:#
3_[?-4
z,C#m{
@.X,1S-
Ox:aJ^
'iNR/P
s1YC$W
Sy1bX'
&H@zhE
@l;'"=
/7?sAK
FWF7SrO
9 k|*ESb
PUb$y^qH
VXNUyTtK
.!z6}R
U~9L\y
~yA8W"
zg}\yu
A@<{]
:0["Ck
X!cpMG
bu&E$L
uLgdg%,
5wc6<A~
z72`or8
f!|S"3
w H(]4
H,*.|"~d/
a}M%A.
dX.vB6y
E|_bRK@
g3wzV-J
\7(9F!
`M9FU{+
tqOF*9
^xgjaBV
$sDGXu
+K4^#i
F[yb)&
TND1n#
Q?4AM!
_[N8}@
>IQAgV
se;gHv
(z=c):
oKt`R[
YD ?&w
Iw:v!=
F#k>oO|
G<`a=.K4
8h@{%P
"Be0z_
+fiEnU
O2#Uko
a\J7'$^
KDFab*8[
X>y;JK
duME']
D'zSh.V
s4/FiX
38cA~~
Mn#j?W
m,-'cS
g8~d|.Z0g
wi_H8'
5>`d7$
ZkXn8TQ
/jM3.[
Oi$uF.
1hk+A
8",*y.
5<+ B_G
B:86"_F
\0ok'>
=~Xh_*m/
DAunZ.
xX;9*q
Lfz=~!
&%av=6
@UE@O`%
^m@~{7
:~V6Ps
xbWV.z
wpW#ff
w,{Yi_1
S4:nrL
|#|%xUE
_$1/4-
@7=&J%
q_*ImQ
Q?{6"
jlvj#X+J
.]d2fA
23F!ZU
"6m[{!7
N'?M!o
yg[7'3c
F4r:BW'
Fw1OMS
A?)"~[
YJq:?2
^ r8{5
dM9@c2_
FQnxXz
bw+|&W
Qp3mk+
I0;0d+
Z/8x8;&
Fi3JLw~
kV\8jE
@TR)cm
!wbPBo
oH.`k)
,H4a]AKv
amLoon
cY}=\~]
MQ/}H|pLy
(+1LOn1`
|i5X<%
ha:5Pkws
4T}8?M/H1
e(dAQl;!
*tZ~rR
9R7%z8
'-RU>g
i[Hedr
\++XgXA
fi(GV^
np)fR\v
X*c#]2j
nW9*K
xrQdL--=
,kNjGU6%
YXx'L
,e]=fB.
Iw3D<'
Twq.|?
pli(XAW
@_UM[:q!
4i*]%L
VBga)vt
H"U,~9
%EM)f{
6<7zw2
74Qw%M
Y/zDnO
QR?{*q
I;!]A#
q"Icki
,7xi,d
-Dj<+zx3
v:Lz\i%
{kRaMU.
_I~-Sw
}'Iw>"
p|/1AX
J$;#B?
y~`QNC
q@T!b7
;eCx:"5
R8 F;ur
e)ABhM
o2LqV
G <)-/O
:E({@p
hZ++J[L
~Ni0@@5
4X%(A<
uj T6FOz
Ku#uzQ
3caIHvc
x5JwgL
"xpVsOO
sgC` o6
;B^Z8\h
.SS@< i'b
x$V*_KFu
k+pL}4Z|
1>?$DVE
)8/lnC
hz@"y)q
7z!n9H
fDkI08.e8
x|g2S'
stti;}
*c7g!"
=g.AE
FMO HR
p0xA)V
yA2O<
]Z*h-F
J6Fye@r
+}T-i1V@)
okE)A~
A*0j[c
QK"`D]
"wds}!
-EOJ[`
`w>DyN
/)E<RVs
#Yom[v
~?78!/R
lj%PEHw'
Qx;m/9
&#wI&Y!
5K>9Pp
vwgJgf
|2#O+9n
DmufWG
+w2UxU
$pa]D@
$e~ZyES>
3kOtTO
aHxW!.
"0L%t*{
6OxAp\
}]X,*u
z b2^
S,Qg-\
k}pWf[
Xu&,+X
xw^RQ^
r&)*"|
3dV;Swh
k<U1]g>
;A1'7y]
X{tcEv
K*`g!4
FUp6*S
xn"s#U
ZZ9`H8)
?R._1iu
P.V4\?
asLIkG
[%]9@K
"P%Mv"!
$:Lkw6
B>qSl|
)PiFl*
RZmSdx
Ot.jki
mw`&JX
aUnfa2J
jI},Ql\
.Nz0Z"
r-HnMN
)hXg'KV"
A#gxv4
G+`>([
o`QL"L&5
:>(|fk
vE(#S4&
H4{f"J
X)B;/NQm$
$dUzx|
j}pC0hP
7vH~xn!
f's\4e
f(wTC&U
+^6->$
a#t eq
/mqa!bW
>Si%BHn
Cr4d-z
_/8Boz
dGbf Y
hSf7g@
J$}FoY
TyfkIL
*6NyCZ
=|KroV
J@O*.qp)a
2OPHH
&yT~SSg
gz9,u
D^JR$_
~TfV#A
3-L2?
%z%`!(.
]X~.9k
a< 3lx
GfC5`R
)Xn6cD
MDFBkj
eV0EVNp
+58kGn
*ip`dsY>x
<&A]Opu
V_(d*=v\
TI[.U3
Ej@aw@d
bt~{u}
q3D3?g
p&Ne&,
#}4utN
STWlIF
P#WZl&
<`{C[z
H{*>em^>e
<Klc&;
|9C:Q
4Tu3o.]H
>tu`\|
DyMlI9#
*KDuST!
.@Yxhw
?p}*D)
>5)\E>
rlZ~w}Xq'
]X(b"B
h:N[^@?
1 gF`
$+&]*s
g.D<l)
5w0hwG
t\B!|i
;[!.g4
a(9kV1
(5)isa
vw;yX)>?
*Ok>sq|u
}iTwx2
xVNeik
<;)b(&
3UY3$>
>uC:d#-0
F%@.hS
M~MnfJ
a]_ 1;
),vpmZ
?]j8k,O
RM%sRI3
7iC3O3
Cf"tK`'7)#
0;Ke?
X/!@B
IP\&\Q
a31|=q
:[,-'v
OW8C(a
19#jc`J
#AckF
~~pjz
k?"[B,
V*<q^w8
,8CV}uZ
x)PB&n
zT3T&#
3lZ<'QqVDdw~
'WjCrPB
W_&E#6
w[%\q1
k,D%BI'=
hEG8+;
x}ZY^S(
PJjaB\J?
,hY(%`K
'TSBh
-76jEiP!>
;\x'4H
'!__gT
kVqUbO}
Y}>Gt^
w%T^-,@
QMs;am
lX3w^Z
'X{97]
;5{]rY
KgbD"*\bK^
\N(=GS
JpE6wA
~dgVF^>6
smg Bj
"nI(QQ
O*p3<\
x./NaF
q3V/,{w
+ 3Aafg
\\*o#'
Ya8n4I
%2+lV]
B.uu]*"}<d
neo!Z&
$I{R7w_'8V
B>i6w+
(,:,-F
q9YB|_Q
a=vXpF
=FV4<#
&t=5@gEl
+/R}l13
) +qaKzh
}KK&r&AD}A
o`4G)hB
k~u$JV
@70'cW9
Gx':+e
;REXV-t
i%=(7=
jlN-7nlP0T
gL1h:d,
8,\f.g
}q@hVzw}
)^IJ9-%;C
<R#7PH
}(!sc~
g2\;1kz
!w:0g_6
K/!1eN
cQ}U.0
"=>yMS
n+xGXy
'^fvK"Tu3
GI+'M
DEr\P'
a~*wzD
uWIz-q
)ju^G*
C:JKiUl
.w?eY{
Q{5v9\
u%bD\U}n
Wzxfrf
E.Fd,lJ
u\WZnQT
eDQ--C
D-S2B8
|f<OQ"3
@NU.r
`c8Kg
!gG^r4w
upT-u
w-/|Rk
HOX!h)B[3
hTTTF]
%#A[|+
7G@5pW*
G7Dsp4
!ypAB2
kE?a8^
G8@LKWw
Ck>dkxx
3vY?|W
y<fh4rA
GKdTX
~'c[` tn
6><7kIB}K
,hnw687o
Eiwv@kZ
/;|9c#
i}N?od
Cv?bgx
l#gi"?
4S|N@]
4iOvq]
Em|Ty?
[XGo!O,l
Yn!ovj
4Lis|e
&KMWL9
4q]>^;S
y;-,F8!|
wg]@Ha
[C)]'J!
Lpg@{E
^[au,nr
DCS+4u
@O*{6Z
2 fyjL^W|
hM: dr
cNN*zX
p@W^=;
Va"DaY"
|Tn0`>
feZy
,hrBHK"
9FrFpa
:S8m_y
`E_-"i4
0^7_OnFcM
lE}9x'o
auS2]c
%QIz397
gp><}g'
;5=Q]1
*0,*+f
?Ryv|J
hx"kB4
L3(x{H%
Z&Wp?,
.{j!i)
/nj!tL
xMT[.s
fd;0PE
nFSjW
{xa/lUeR5
PC1cK-
}k)!31I
,}!CLm
wDi[W3
u`8^q}w
{!doL
bg\YC>
{%aft/.|O
(vVZH?
JLd `mA
f{;DZK
Kba$}@
Z?2o.>
ix$1n`
D]G*Ob
>FGiQ>
1V(hx/q
Ul3rPXe
*608m_;
g(E9 Q
L}Ej2o
Nx^,`W1
q/o*4V
0Sh_-r
Irop9x
TJNVBC
w\q/R>
/+dL5F
%z2JDN
1lHnbY
CN/nzZ
tZN^w(
/1Ayu_
~#u[=NtQ
pO9Tu|
mS+j48
f:<Pq.
t$t#t$l
D$t#D$h
D$t+D$\
.)D$H)
s`)L$4
D$t+D$\
)D$H)
9l$\w_
XPTPSW
KERNEL32.DLL
ADVAPI32.dll
COMCTL32.dll
GDI32.dll
SHELL32.dll
SHLWAPI.dll
USER32.dll
WININET.dll
WINSPOOL.DRV
LoadLibraryA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
ExitProcess
RegCloseKey
SaveDC
DragFinish
PathFileExistsA
InternetOpenA
ClosePrinter
HrCg@b
O(uckHr
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
VS_VERSION_INFO
StringFileInfo
080404B0
FileVersion
7.31.0.0
FileDescription
ProductName
ProductVersion
7.31.0.0
LegalCopyright
Comments
(http://www.eyuyan.com)
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.BlackMoon.4!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.gc
ALYac Gen:Variant.Zusy.554925
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Blackmoon.V90u
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason malicious.28f1fd
Baidu Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Packed.BlackMoon.A suspicious
APEX Malicious
Avast Win32:MalwareX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Gen:Variant.Zusy.554925
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Zusy.486912
MicroWorld-eScan Gen:Variant.Zusy.554925
Tencent Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/ATRAPS.Gen
DrWeb Clean
VIPRE Gen:Variant.Zusy.554925
TrendMicro TrojanSpy.Win32.BLACKMOON.YXEHDZ
McAfeeD Real Protect-LS!1F0754128F1F
Trapmine malicious.high.ml.score
FireEye Generic.mg.1f0754128f1fd327
Emsisoft Gen:Variant.Zusy.554925 (B)
Paloalto generic.ml
GData Gen:Variant.Zusy.554925
Jiangmin Clean
Webroot Clean
Varist W32/ABTrojan.UYES-3843
Avira TR/ATRAPS.Gen
MAX malware (ai score=84)
Antiy-AVL Trojan[Packed]/Win32.Blackmoon
Kingsoft malware.kb.b.992
Gridinsoft Ransom.Win32.Wacatac.sa
Xcitium TrojWare.Win32.TrojanSpy.Banker.OV@6e1pyh
Arcabit Trojan.Zusy.D877AD
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Wacatac.B!ml
Google Detected
AhnLab-V3 Trojan/Win.Generic.R658019
Acronis Clean
McAfee Artemis!1F0754128F1F
TACHYON Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.100%
Panda Clean
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.BLACKMOON.YXEHDZ
Rising Worm.Convagent!8.12386 (CLOUD)
Yandex Clean
Ikarus Trojan.Win32.FakeAV
MaxSecure Clean
Fortinet Riskware/Application
BitDefenderTheta Gen:NN.ZexaF.36810.DqKfaiVvFLpb
AVG Win32:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_90% (W)
alibabacloud VirTool:Win/Packed.BlackMoon.A
No IRMA results available.