Static | ZeroBOX

PE Compile Time

1970-01-01 09:00:00

PE Imphash

f6243a15fa8eee8ee96b5e1144d461f6

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00001a44 0x00001c00 5.70034070034
.data 0x00003000 0x0004bc6c 0x0004be00 6.74165463065
.rdata 0x0004f000 0x00000634 0x00000800 4.49599350897
.bss 0x00050000 0x00000428 0x00000000 0.0
.idata 0x00051000 0x00000644 0x00000800 4.29353534968
.CRT 0x00052000 0x00000034 0x00000200 0.271114278006
.tls 0x00053000 0x00000008 0x00000200 0.0

Imports

Library KERNEL32.dll:
0x45111c CloseHandle
0x451120 ConnectNamedPipe
0x451124 CreateFileA
0x451128 CreateNamedPipeA
0x45112c CreateThread
0x451138 GetCurrentProcess
0x45113c GetCurrentProcessId
0x451140 GetCurrentThreadId
0x451144 GetLastError
0x451148 GetModuleHandleA
0x45114c GetProcAddress
0x451150 GetStartupInfoA
0x451158 GetTickCount
0x451168 ReadFile
0x451170 Sleep
0x451174 TerminateProcess
0x451178 TlsGetValue
0x451180 VirtualAlloc
0x451184 VirtualProtect
0x451188 VirtualQuery
0x45118c WriteFile
Library msvcrt.dll:
0x451194 __getmainargs
0x451198 __initenv
0x45119c __lconv_init
0x4511a0 __p__acmdln
0x4511a4 __p__fmode
0x4511a8 __set_app_type
0x4511ac __setusermatherr
0x4511b0 _amsg_exit
0x4511b4 _cexit
0x4511b8 _initterm
0x4511bc _iob
0x4511c0 _onexit
0x4511c4 abort
0x4511c8 calloc
0x4511cc exit
0x4511d0 fprintf
0x4511d4 free
0x4511d8 fwrite
0x4511dc malloc
0x4511e0 memcpy
0x4511e4 signal
0x4511e8 sprintf
0x4511ec strlen
0x4511f0 strncmp
0x4511f4 vfprintf

!This program cannot be run in DOS mode.
P`.data
.rdata
0@.bss
.idata
`v@nx
,$\M4
ax_,$\
\O.$\GM
x_MH"_
,yx_.m
;z_,%t5
-OMhx_
|Acd@_
99z_,%
xxOb&H
wxOb&<
FxOb&,
ZchdVo
ax_,>,
y_.&4\f
,&Lle '
(%pll09
($\CME
Dt#r?&
>`xllDpc
?>`x9&
I1)ll!
axrm`x_R
(^/h8en
u&z_.m
Tbax\R
7Zcx_,=
^/h8en
$,x_(%
`x7Mcx_Zu
d@3*L7/5
9'y_Nk
u#x_,%
zO.u\?
`x_Zu<
ch7-u{OZu
I6/lZS
y.%ptc
h|OZu@
u{O,'|
p7au{O
aRx_.=
xOx_(%
ch7-u{OZu
=}z_(0p
+`x_(=
=W(%p5
ax_L/y_
9[LOy_
A`x_.f
1`x_N*
}`x_(%
-`x_.%t
S.%p\b0
S.%p\b0
}@x_,%
`x_,&|
`x_b t^
9`x_(-
ch75v{OZu
o.%htb0
1`x_Zu
NYcx_Q
bhZIcx_,(|
Il.lS7
i7Qax_Zu
?WM#i^
6/7Z`x_(
Z=Zx_,f
dh#`?&
=W(%p5
s7Mcx_Zu
xOb `W
[7Mcx_Zu
Z|O%`x_
B`x_Zk
>KNkA@
(`x_.'d
&tbMcx_
y_.mDW
1`x_.mDW
=W,$\S.%t
=G,$\C.%d
,&hle &
g_Mz:_
8`x_.%p
6/7Zcx_
y_($\s
<y_($\
ltda<{
\G,,\GM!
1(7Qv{O
,$\sM-
y_($\s
x_b$\o
37y_.%
cdO_M+
Zcx_.%h
kcx_.%t
cx_.%t
Cax_M$
fZx_.5
7Zgx_(
p7au{O
~O(&T+
v]_%`x+
(.%hzZ`x_-%
`zZ`x_-%
"Qd1mvo
Ic0C,-
-S.%pt
-S($rG,%
Zox_.-
Zox_.5
v]_%`x+
(.%hzZ`x_-%
`zZ`x_-%
"Qd1mvo
Ic0C,-
-S.%pt
-S($rG,%
+ich9
f5x_(-
6/7%dx_M)
Z|OM-9^
`x_($\w
dh9,$s[(%
dhleY=S
_Iy_N@+
u{O,(|
ax_&`z
b!h|O,]
U,XAb%h|O
Mcx_,oC
R1h|O&
Aj=h|O
R)h|O.m
R5h|OM
J=Y|O.U
Ip.lS7Aj=h|O
R1h|O.u
baY|O&
5h|O(%
R1h|O&
j1h|Of6/5
h|OZu4
|_bfh_
Rah|O&\
_Z.|le '
ah|O(d
t7Qax_M
Abuh|O
bih|O,]
![,}h?
`x^Zup
=Ocaxt
ed{'M.
cb leP/
@b \Fh
>wc$~s
b`x_.%tlw
M'ichlw
{O.Tyn
u#ichlw
6`x_(%
l\.lnl
Y?&lh;
J1X|OZ
Mh|O,&|leY>[,~
Ey|O,a+
}h|O.f
}y|O.f
=S.-pd
=WM/P_
5W/aDo
]ax_(!
Hax_(%
ax_.%p
@`x_.%
%Sb t^
Z9!leY
JeX|O.
JyX|O.
JeX|O.
JyX|O.
JeX|O.
JEX|O.
Eg!tm7{
J1X|O&
9^(0zd
Dh2Tk
byb%`x_
H`x_ZD
%`x_(%
ix_N2;
lx_Nz(
'`x_/g\@
=lP#Az_
ax_.%h
5ax_(%
H`x_.%h
QyO'QyO`QyO
RyO,RyO
zP'_y_
ax_-$M
q`x_/%
`x4eH{
C^b%p^
/S.&tllYw!
rux_($\S
<|x_NI
`x_,.ple?
%O.7t||
[Z$\G.$\G
NnyI.fYQd
Z$\O.gA
bx_(,\G.
,`x_($\GM>e_
{_M@p_
hx_.$\KNc
||x_N^
cx_.%p
\OMB]_
,$\{Nd
T,4\{,<\s
E.$\+.
.$\;,h
0W(4\'($\
`x_Mf}_
E($\7M
wx_.$\c&
nl~[6W.hw
O.5hllYr!
($\WMBm_
\WMhx_
L|qWZf?
`xle?%
cx_.%p
O.-pv
[Z-p*z
,-p*}Y%
][?W(%
.lSYH!
(S.hA+/
|`x_(-
{bx_(%
cbx_(%
+bx_(%
?ax_(%
k`x\Us
yP!Oy_
=O.,\S
4\K.$\SNbK
.,\{,d
4\K,4\
+iH9do
;W,&ple?&
8b)`x_
Hbgax_
Y(,x^$
]9!d^o
ax_.%t
Nex_(%
Bdx_(%
jdx_(%
&dx_(%
jcx_(%
rax_(%
:`x_.=
bx_.gS
P.%llw
:bx_(%
"bx_(%
:`x_.%
6`x_(%
?SS`y*
.ax_(%
.`x_(%
j`x_.g
`x\}q-
($\OM&
.$\CZP
CZ,\G,$\K
u`x_.g
_(4y^,%
2}x_,P'
&}x_b`t_
.,\K/g
`x_M?D_
`x_MSD_
`x_M_B_
`x_NG
leXfP0
6{OM}._
"rx_b`n_
(bx_.n
0^%Yr*
vjx_b`n_
jx_b`n_
tA6=[1(
rx_.=p
ax_&]8g
2fx_,%
&`x_Mr{_
bx_,f!
U9!dRo
`!le '
.=ple
-1{O,X
l~YeWgch*
-1{O&^x*
dh4lt{
X|O.Uh
zO,&hdb
Yox_,p
Mox_Uox_
a`x_/&;
=W-.;*
[`x_%
yP %y_
A![.=t
ax_.*|d
(`x_.-
)W.*|d
/,~[--s
ah;ZUx_
ax_.-h
5SMgL_
Tx_.%t
R..|\jStgM
6S.6p\jSteM
n7Y`x_MI
%`x_.&p
Ef{[0`_[
7{OS |
W.%pzZ`x_
`xle0(
d.(|dk
caHN^19
Zjx_S&t
{P 6q_
_%`xP!
j-3{OM
j13{OMp
\P*Yy_
"Y`x_%
Yax_NG
i`x_ZU
{`x_..
b93{O.
X7uW{OM
`xle0(
,$iWZ%
'x_ZUxw
bx_b%t^
{ax_(1
=`x_.%t
~P ny_
dh\cY`+
Mah;ZUx_
`x_.$\o.8p
l.$\W.(plm
.$\W.4\O,b
`xle0(5
-hP#@{_
z9,p8$
Z9!lw"
wd[>'*
P,$vw.%
`x_c$vZ
P/,vz%
cx_.gy
A((z9&Yr*
-,~Z.g
f^UNJC
bEF|O&
Cf{k `_[
Y%.|Ni
ox_(&t
U%.|bf
Y($H[%@
h7]X{OM
hCZEF|O
YS$J[%
G.,\K.$\O
1<{O '
j=;{O,
ax_(#d
Y?&lh;
O`x_Se
h9.,;O
`x_MHN_
`xr[`x_
M.'|df
OZ-p*s
1<{O &
}Wbch]
bhleY%{
F`x_.U
8K,%pf
Y}Sbch)
%W&%p[,s
}Gmch^
Y`*\ 89
wd[>'*
Yesmch+
ZZ-l*KY%K
R&)tWb!`_
Y.%pdf
.=plZ[
h7=Y{OMQ
H|O.d~
H|O,|~
+`x_.%p
i=O.%h|b[
0P!Fy_
DHW.f
Y($y{.-h
HZ-hev
IZ-hev
m.$\K.(
bh;ZUx_
`x_.$\w.8p
)S.2tf
O.-hd-
E[gch^
BCZEF|O
t7}Y{OMq
`xl~Y&W
G|Oc$p[
%O.5t\vK
ewlch9)e\
}gmchV
bhleY%
%`x_MG9
tCZ!>{O
|CZ)>{O
DCj1>{O
-K!4yB
C=ONbK
to/!\]e7w
AYEsich*
=O.5`dr
8%Xx*D
8K,%pf
|&Yx*R685
"{zZ`x_
"~zZ`x_d
"vzZ`x_d
l`P %y_
`x_.%pP
"izZ`x_d
"ozZ`x_
"jzZ`x_d
"bzZ`x_d
qS9O.5
%b{O.5
%j{O.%
%j{O.%
"~zZ`x_d
"szZ`x_
pzZ`x_.-t
hzZ`x_.-t
`zZ`x_.-t
zZ`x_.-t
5S-!wle?&
.%hZU`x_,%
"{zZ`x_
"}zZ`x_d
IS0[,-
"rzZ`x_d
"wzZ`x_
zZ`x_.-t
=S([,5
pzZ`x_.-t
_Z`xlto
`zZ`x_.-t
zZ`x_.-t
=S(S,5
pzZ`x_.-t
=Wb`X_
ZK}oich
[~#m?&
N.A*]o
\7eZ{OM
Z3+5Z7
y?{O.t
I3/lZYE
[_be0g
Yp*\ 89
.%p9.5t
`x7Mt{O
JU?{O/tz
u{OZU0
QyP ;y_
+`x_.%
5WNi19&Xx+
.%ptd(%
8Q6E)<
"8}2sXNc
1qZ;L'
`x_W`x_
`x_``x_
`x_[`x_r`x_
`x_o`x_'`x_l`x_
`x__`x_
`x_U`x_
`x_q`x_
`x_9`x_
`x_e`x_
`x_X`x_6`x_
`x_R`x_i`x_
`x_@`x_T`x_
`x_}`x_
`x_b`x_
`x_f`x_
`x_3`x_
`x_?`x_
`x_%`x_G`x_N`x_
`x_&`x_
`x_s`x_
`x_F`x_
`x_!`x_
`x_t`x_
`x_H`x_
`x_Y`x_
`x_n`x_
`x_j`x_u`x_J`x_
`x_^`x_
`x_ `x_
`x_\`x_
`x_:`x_
`x_*`x_7`x_8`x_
`x_P`x_
`x_Z`x_V`x_w`x_h`x_
`x_I`x_
`x_2`x_
`x_a`x_
`x_$`x_
`x_y`x_
`x_5`x_-`x_
`x_K`x_
`x_{`x_
`x_~`x_E`x_
`x_g`x_v`x_
`x_4`x_0`x_A`x_
`x_B`x_m`x_
`x_(`x_p`x_
`x_Q`x_O`x_
`x_`x_
`x_c`x_M`x_x`x_
`x_.`x_/`x_
`x_S`x_
`x_#`x_d`x_
`x_;`x_D`x_]`x_=`x_
`x_|`x_+`x_1`x_>`x_
`x_"`x_L`x_k`x_
`x_z`x_)`x_
`x_,`x_
`x_C`x_
`x_<`x_
9T^Ne8
72.OLS?
EDw.)u
KDE.g o%j)a8}2s3p;}Z;L'Q6E)L!^;G,W5v
pfb.OLS#FBX4]PE9T^N
Vk83_e3>Dw.)My%$:#Lo3-Gb(?Zu!1Qx
r;|o|0qfn-f}`&ktJ
du_ux@v
x_Ca?:
x_(d/-
x_cc+:
x_*`;-
!x_1`;-
9_la?:
!x_Pc+:
0x_Qa?:
x_(c*:
x_&a40
x_;`11
!x_3`11
x_\a?:
7x_e`<:
0x_0a?:
x_ra?:
!x_'d/-
9_<a?:
9_b`;-
x_tc+:
`XZ6yx_
YF1JW)
3E7Y@"
K&5LsHB+?
#"Y,ew
8D%e3/
EmAOwv#NO!
jD)1'$A
c~:EKu
*5nl(I
EIh>]R
jm;#rI
t.lLG[
W8+/1@
[Y9uRB
nTK&Z/s-NW!
}EjUF
PRS)C#
L!T#Ec
%}y+]J
t~^Br)=R
=I({#9Ys
c0h#b1
6Xc&'!
ZD>8ca'
@V41*&_
sC>E%rv
{HZ:Zz
O*%=O~(q7MXfdYZ&+
f#1PT E
cTgp@fd
#4#G@
9K2s].
5n|iz>
gb>OjZ
+z9nN$e
h,YcY)4
?#ro}i
%mW,JR
KP_^yl
i<$$U\
%Pi26K9"
j6'p)2.Eq
[]b;cSy
*xhfP4
OMnjau
EpO{yl
z_kslum
fP0U`i:
$f3SO4
]0gt:_
}$("nj
o"P;nMQvm
PMnkQOl
g-XofOYTe
eFZCdN[zc
\TbH]]a
fZYEeyZ}d
R3mhRKlhS
f~Y>e2Z
bT]ka#^
W"hKWug
g&X[d~[4c
U-i|V-g
mBR"l*S
^/aQ^p`
R!m-RKl
hLW"f2Y
%c%c%c%c%c%c%c%c%cMSSE-%d-server
Unknown error
_matherr(): %s in %s(%g, %g) (retval=%g)
Argument domain error (DOMAIN)
Argument singularity (SIGN)
Overflow range error (OVERFLOW)
The result is too small to be represented (UNDERFLOW)
Total loss of significance (TLOSS)
Partial loss of significance (PLOSS)
Mingw-w64 runtime failure:
Address %p has no image-section
VirtualQuery failed for %d bytes at address %p
VirtualProtect failed with code 0x%x
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.3-win32 20200320
GCC: (GNU) 9.3-win32 20200320
GCC: (GNU) 9.3-win32 20200320
GCC: (GNU) 9.3-win32 20200320
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.3-win32 20200320
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.3-win32 20200320
CloseHandle
ConnectNamedPipe
CreateFileA
CreateNamedPipeA
CreateThread
DeleteCriticalSection
EnterCriticalSection
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetLastError
GetModuleHandleA
GetProcAddress
GetStartupInfoA
GetSystemTimeAsFileTime
GetTickCount
InitializeCriticalSection
LeaveCriticalSection
QueryPerformanceCounter
ReadFile
SetUnhandledExceptionFilter
TerminateProcess
TlsGetValue
UnhandledExceptionFilter
VirtualAlloc
VirtualProtect
VirtualQuery
WriteFile
__getmainargs
__initenv
__lconv_init
__p__acmdln
__p__fmode
__set_app_type
__setusermatherr
_amsg_exit
_cexit
_initterm
_onexit
calloc
fprintf
fwrite
malloc
memcpy
signal
sprintf
strlen
strncmp
vfprintf
KERNEL32.dll
msvcrt.dll
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.CobaltStrike.4!c
tehtris Clean
ClamAV Win.Countermeasure.LoaderWinGeneric-9804845-2
CMC Clean
CAT-QuickHeal Trojan.Cobtstrike.S30482629
Skyhigh BehavesLike.Win32.Generic.fh
ALYac Gen:Trojan.Heur.tCW@IDoAGBp
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.CobaltStrike
K7AntiVirus Trojan ( 005622831 )
Alibaba Trojan:Win32/Rozena.4c0
K7GW Trojan ( 005622831 )
Cybereason malicious.3e5a42
huorong Backdoor/CobaltStrike.d
Baidu Clean
VirIT Trojan.Win32.CobalStrike.BVA
Paloalto generic.ml
Symantec Backdoor.Cobalt
Elastic Windows.Trojan.CobaltStrike
ESET-NOD32 a variant of Win32/CobaltStrike.Artifact.A
APEX Malicious
Avast Win32:HacktoolX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:Trojan.Win32.Cometer.gen
BitDefender Gen:Trojan.Heur.tCW@IDoAGBp
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Trojan.Heur.tCW@IDoAGBp
Tencent Trojan.Win32.Cobaltstrike.hd
TACHYON Trojan/W32.Agent.324096.GW
Sophos ATK/Cobalt-B
F-Secure Heuristic.HEUR/AGEN.1344233
DrWeb Clean
VIPRE Gen:Trojan.Heur.tCW@IDoAGBp
TrendMicro Trojan.Win32.COBALT.SM
McAfeeD ti!FD1B4E248D92
Trapmine suspicious.low.ml.score
FireEye Generic.mg.f2bb9263e5a42975
Emsisoft Gen:Trojan.Heur.tCW@IDoAGBp (B)
Ikarus Trojan.Win32.CobaltStrike
GData Gen:Trojan.Heur.tCW@IDoAGBp
Jiangmin Trojan.Cometer.cvp
Webroot Clean
Varist W32/Agent.NRPH-1387
Avira HEUR/AGEN.1344233
Antiy-AVL Trojan/Win32.Rozena
Kingsoft Win32.Troj.HexzoneT.xe.221184
Gridinsoft Trojan.Win32.Downloader.sa
Xcitium Clean
Arcabit Trojan.Heur.E4D871
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.Cometer.gen
Microsoft Trojan:Win32/CobaltStrike.SPB!MTB
Google Detected
AhnLab-V3 Malware/Win.Trojan.R415758
Acronis Clean
McAfee GenericRXGK-PI!F2BB9263E5A4
MAX malware (ai score=83)
VBA32 BScope.Trojan.CobaltStrike
Malwarebytes Trojan.Exploit
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.COBALT.SM
Rising Trojan.Rozena!8.6D (TFE:5:v6hmll7VkYC)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Rozena.AMZ!tr
BitDefenderTheta AI:Packer.99FAD0AF1B
AVG Win32:HacktoolX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Backdoor:Win/CobaltStrike.B
No IRMA results available.