Static | ZeroBOX

PE Compile Time

2024-05-18 19:40:34

PE Imphash

45c6b272631aa9e0c4b2ba675699b803

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00014840 0x00014a00 6.52515553019
.rdata 0x00016000 0x00031fb8 0x00032000 7.70052033481
.data 0x00048000 0x00001cb0 0x00000a00 1.98344439458
.pdata 0x0004a000 0x000010ec 0x00001200 4.90048615191
_RDATA 0x0004c000 0x000000fc 0x00000200 1.95993003899
.rsrc 0x0004d000 0x00008738 0x00008800 7.96245146658
.reloc 0x00056000 0x00000670 0x00000800 4.92058070037

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0004d0a0 0x00008679 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
RT_GROUP_ICON 0x00055720 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library Cabinet.dll:
0x140016000 None
0x140016008 None
0x140016010 None
Library KERNEL32.dll:
0x140016020 GetCurrentProcess
0x140016028 TerminateProcess
0x140016030 GetModuleFileNameW
0x140016040 Sleep
0x140016048 LoadLibraryA
0x140016050 FreeConsole
0x140016058 CreateThread
0x140016060 HeapAlloc
0x140016068 VerSetConditionMask
0x140016070 GetProcessHeap
0x140016078 VerifyVersionInfoW
0x140016080 CreateDirectoryA
0x140016088 HeapFree
0x140016090 GetLastError
0x140016098 GetCurrentThread
0x1400160a0 K32EnumProcesses
0x1400160a8 GetThreadContext
0x1400160b0 GetProcAddress
0x1400160b8 GetModuleHandleW
0x1400160c0 WriteConsoleW
0x1400160c8 CloseHandle
0x1400160d0 CreateFileW
0x1400160d8 RtlCaptureContext
0x1400160e0 RtlLookupFunctionEntry
0x1400160e8 RtlVirtualUnwind
0x1400160f0 UnhandledExceptionFilter
0x140016108 QueryPerformanceCounter
0x140016110 GetCurrentProcessId
0x140016118 GetCurrentThreadId
0x140016120 GetSystemTimeAsFileTime
0x140016128 InitializeSListHead
0x140016130 IsDebuggerPresent
0x140016138 GetStartupInfoW
0x140016140 RtlUnwindEx
0x140016148 SetLastError
0x140016150 EnterCriticalSection
0x140016158 LeaveCriticalSection
0x140016160 DeleteCriticalSection
0x140016170 TlsAlloc
0x140016178 TlsGetValue
0x140016180 TlsSetValue
0x140016188 TlsFree
0x140016190 FreeLibrary
0x140016198 LoadLibraryExW
0x1400161a0 RaiseException
0x1400161a8 GetStdHandle
0x1400161b0 WriteFile
0x1400161b8 ExitProcess
0x1400161c0 GetModuleHandleExW
0x1400161c8 FindClose
0x1400161d0 FindFirstFileExW
0x1400161d8 FindNextFileW
0x1400161e0 IsValidCodePage
0x1400161e8 GetACP
0x1400161f0 GetOEMCP
0x1400161f8 GetCPInfo
0x140016200 GetCommandLineA
0x140016208 GetCommandLineW
0x140016210 MultiByteToWideChar
0x140016218 WideCharToMultiByte
0x140016220 GetEnvironmentStringsW
0x140016228 FreeEnvironmentStringsW
0x140016230 SetStdHandle
0x140016238 GetFileType
0x140016240 GetStringTypeW
0x140016248 LCMapStringW
0x140016250 HeapSize
0x140016258 HeapReAlloc
0x140016260 FlushFileBuffers
0x140016268 GetConsoleOutputCP
0x140016270 GetConsoleMode
0x140016278 SetFilePointerEx
Library USER32.dll:
0x140016288 MessageBoxW

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@_RDATA
@.rsrc
@.reloc
D$$jp58
D$(7lmx
D$$um58
D$(7lmx
D$$ux0jf
D$ Szsc
D$$860jf
D$ PloU
D$$Kmnk
D$ Uywe
D$$jJkrf
D$$npgY
D$ AysR
D$$yiHo
D$(umB
D$ AysR
D$$yiHo
D$(umX
D$ As}d
D$$jLct
D$(mtf
D$ Mws_
D$$Ryvkf
D$ AysR
D$$yiO{
D$(}myc
D$0Zvsx
D$4cZwU
D$ DysV
D$$Xmf
D$0lrsn
D$0mrwN
D$8iit
D$0fwor
D$4ppq<f
D$$uxGt
D$(lzz|f
D$$uxFk
D$(lzz|f
D$0b~rk
D$4Ny}g
D$8nhgx
D$0L~kr
D$4gv|
D$0h|w_
D$4rp}_f
D$0h|}
l$ VWATAVAWH
A_A^A\_^
UAVAWH
PA_A^]
gffffA
UATAUAVAWH
A_A^A]A\]
gffffA
WATAUAVAWH
D$0bm|m
D$4qvte
D$8aIfmf
D$ Szsc
D$$%Hczf
D$$mvqt
WATAUAVAWH
A_A^A]A\_
gffffA
D$,+D$$
D$XhxZpH
D$\mjsdf
u8H9|$h
H9|$puS3
UATAUAVAWH
A_A^A]A\]
gffffA
H3E H3E
u0HcH<H
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
ffffff
fffffff
x ATAVAWH
A_A^A\
UVWAVAWH
0A_A^_^]
WAVAWH
0A_A^_
u3HcH<H
t$ WAVAWH
A_A^_
WAVAWH
A_A^_
u"8Z(t
uF8Z(t
vC8_(t
u"8Z(t
uF8Z(t
vB8_(t
UVWATAUAVAWH
`A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H97u+A
\$ UVWATAUAVAWH
@8|$Ht
@8|$Ht
@8|$Ht
D$XD9x
@8|$ht
@8|$ht
@8|$ht
A_A^A]A\_^]
u"8Z(t
UVWATAUAVAWH
L$&8\$&t,8Y
@A_A^A]A\_^]
fD94Fu
fD9t$b
@UATAUAVAWH
e0A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
\$ VWATAUAVH
D!l$xA
@A^A]A\_^
L$ VWAVH
@8l$Ht
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
@UATAUAVAWH
H!T$0D
ue!T$(H!T$
A_A^A]A\]
WAVAWH
A_A^_
UVWATAUAVAWH
D8\0>t
L$@D8]
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
\$ UVWATAUAVAWH
H!D$ H
`A_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
UVWAVAWH
@A_A^_^]
ffffff
fffffff
USVWAVH
A^_^[]
LcA<E3
u HcA<H
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
AreFileApisANSI
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
Y[]=43
/id.u}
EyH^p}
X]8x4w
S`7q<]'n[
bcsUD
[c`K*4
&p=zo=
\ 7?h7
)YCz}P3R%
CR8n"$
n?/mr(
<n|L-
BN~@(:
,<N3.O
fW/_pn(
hx;LCsK
hOi?x1
#C) Et
CI0S(j`(
8r<U(4k
M0yKdm6
nzAYaF--S
pV)QU^
/v$o;PM
b@* E+
~D'| r
^SI\^\
ozu=zi
f~_/a1
vk^O c
!5ge~6
DZh3:K
1K;ZO(
tB*YIB6
}wo2G&
HPQ2HK
l3ck1w
~Vb:z}
IO&@V,fC;
/l;wk0E
`F;&V{V
2]0?sJ
%>D-s9I
sTO?!x
-9w'U'
=&oF5GH
QwVWS #Lk@
+8e>w6
c8539H{
{gQr\y
JSa)q
2]9UG4H3
zOW&pw
~{n(G
Q*@G8N
tu}I7v
'ky` .S
ox=I*]w
9.X^3G
9R!8*{
N2@>Q!
0qAP[`
s45.?w
Y,Fk!Q/
)&g0`p
0@Z?cj
{N,k'u
nqQP(r
* k8kZ
A<r;L.
IbV@Gq
6\Swpu
XvtA"Z
EE51]n
xh*,2(
8wa@.3I!
.l+= R
RKd~7{m5
u$N)6
OO0aJ{on
Zs[^l7
dVTL~O
`30&G*:]
0U$|XA]
{$3)QK
qQOP4w
#;=j:(<
o=>F>
uL"8*
'Z$Kcg
hdLHR]
xy~5)B
LZu_E%or
t-3_P7T
,jIL[n
MgqZu|A@T
&6>Vn5
wk.I;S
~}Xr=~
?ynF~]
lLVgX7
8{<*<.iIz
qB{o2?F5ZC
TxJf^q
PG8j+nz[
NYQ3Q7
{Bb~LmOh
|)K1_6-/n
tZ92!q`
%+\Wph
cryh.v
7yB`x4[
@#W["%
Bw%ni"D:T
-GF!&FW
S$dNwE=C
p|Q-Sx
\Y!8'j
&5>$r4
rkSq_!
PT8^m"s0
M>I7EK
\`8>O;
,>*X940
FG:P,<
MZA\$w
>TM&]M
Ok>tr&
"kAsL3Mo
5.^MrL
]Lkpwl
@BPx[\
ggyG)hvkq@)
$>\ikl
&d5X]w
rE'Y%0
@0;@]W
;eH76NE
kks_%B
6x?*pc
(OaK_`
aL92Hvn}
K I<J"
(m7R =
4#}~.%^v
LmK&o>@
bwu{vKPx
VFK%Y
w5n?q>
oY*@c.
WuO:3}
]h9U%]
@*<?<QYBD1
OkjkD&
:\=|_#
K]NZ3M
|*4{e~
N77qvE
l$G.*1
<\)Y$Q
2 11)A
90[;N@V,L
8JQno<1qy,
wSTA|b5J
w+EAoH
6yWJ,x
TQu*T?
=l|u}u9
oh'2YY
]oT#x5
!E^!:
;6>mf
u"frL:X
xd]"-y
"E}Dn2
<+cZ6u
L@dy@s:
*qcUA8:
fg1<c@
V)FqC~)
/\Y'JL
X3VwMa
jg*:T)
O<cF-:d
C8!GnxrC
NTPL^:
S4)ag!<
q A5_$0
43PGS`
5e]g''-
`7iNx
gHcaaVK
A`dt#h
a9bK#x
"kHvy+Ur
{9|x#e
57/(f{
qSii.LI4;v
")^Mbj
zA@y1VR
!uv4inm
.s'ka1|
X88=XC
_UgV[Y
@02Ze
q_rNFS
.EO027
udl5mJ
!JJhs
b.=4WgS5
{&_C7+
w33qS0
7xz+.vXm$
LraQ TP
p@'SBV
&i-ub=
y{t<j:
|`]+~o
z0ZBm&eo>N
/Y}"eI
`!B}E"
=;~=7M*
C1}S>'
p$id%f
YKj7Cy
#VNO9{
Lh_(Ly
.*~NM>
QM7iZ?.5
beK!!Z
J<+=u<.
Hu:u5k
kfESwi
gQ.PY'F
HMrkE LLd
'b@eM
g`ugA8
o=Q59v
I&~&7a
hP-IMG
~b<3=P
%wLMB{
b>p5x}
O78Ja;
wTF6K-
EQ:WIf
{1cC+9*`
PP_\f
J7Qw.d_
pRuC/)
J$2O:'t2
k>xac^#:
mZ5R3@o
@GGWvTN
TDJHjG
cf9VK2
b/'Um<?
x0wa)0
Vw2UF-
C%H`^]in
[9?_,~
"kXP`0|
dOs8d{I
dW^*5B
yl\j1n
^ToNX5a
[TzCU"mF}
?G<9FvRO
MEA|D/
/a0I}3
'C_xw7
.[d?*hY
oQsKB:
XU6,cj\
>G\A=o
cyT>8,
q m{29
9mwiZ$
t^:jzsA~
;gWvix
w7%,AK
-e{fV8
SH[Am*4
+yq4i,
x1:BD;p
Bb`gICgL
3Inm)v
Mb997S
p%NXiR^
:lWyFe
Bi@#hW
7X*_L!
YLd\wo
ms%D%K
ln=iSb
#s}Tfpcvylb
7npgG}|su\
FxitUkrfonSs_@J
juxQvnvBxaywbL{_fjv{Ownp~gkyb?sz`hevkJveUhsybtj
fsxksn:3<(nqetj
fsxksn9:<(nqeAosTpXqqnvNqgljk@J
juxErx{fMfqtkCu
^ImuvuizYixnm@J
juxIk}Xs{jowm@J
juxUk}Xs{jowmEl
Awsek|{Xuhntp@J
juxIkwmsmnoXr@J
juxFk||s{sUjrWH<
>trkzxzJz`y\
|Tmvqtr
|Tmvqtr
.text$di
.text$mn
.text$mn$00
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.idata$2
.idata$3
.idata$4
.idata$6
.pdata
_RDATA
.rsrc$01
.rsrc$02
Cabinet.dll
GetCurrentProcess
TerminateProcess
GetModuleFileNameW
ExpandEnvironmentStringsA
LoadLibraryA
FreeConsole
CreateThread
HeapAlloc
VerSetConditionMask
GetProcessHeap
VerifyVersionInfoW
CreateDirectoryA
HeapFree
GetLastError
GetCurrentThread
K32EnumProcesses
GetThreadContext
GetProcAddress
GetModuleHandleW
KERNEL32.dll
MessageBoxW
GetUserObjectInformationW
USER32.dll
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
RtlUnwindEx
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
RaiseException
GetStdHandle
WriteFile
ExitProcess
GetModuleHandleExW
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
LCMapStringW
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
W9G-Zw
7yU&P%
0NtCzM
$_)'6M
%@:l88Z
b^|wo'wNh
Kk&oYRtv
/{#5n|
mc"'&b
fW?qxFBV\Q
\+.A^C2G
%-fS =
Qhmmm Jc
)bm)YG
tlmiW0
fEi90E
1Q+Nzv
F$4NFVG
KHxd,RP
U~Yr-;
!=F:}]
37d/]qIr]
=\dd]~
&PK/Vs
<({gt&
+z`f)YJ#i
~$Yfv:
^yA&_
?2K(1/:
6Q_L&j
v&1DA4
n_bL2f+
G2/i[b
}G,Mfk
sgey .
~P3'6
ZZXwD]
U;4=HE
C{Q:jP
X9IiLB
ua]q#_]w
.vous^
iW`KfK
&Vi?PT=
U:8)*
^t%f&gb
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
ObjectLength
BlockLength
ChainingModeCBC
ChainingMode
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win64.Backdoor.fc
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec Clean
Elastic malicious (moderate confidence)
ESET-NOD32 a variant of Win64/Agent.DZF
APEX Clean
Avast Clean
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Win64.Trojan.Agent.Eflw
TACHYON Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfeeD Clean
Trapmine suspicious.low.ml.score
FireEye Generic.mg.0d1dca5eaad49c2d
Emsisoft Clean
Ikarus Win32.Outbreak
GData Clean
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Google Detected
AhnLab-V3 Trojan/Win.Agent.R660345
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Malwarebytes Malware.AI.1893956484
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Agent!8.B1E (CLOUD)
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Clean
No IRMA results available.