Static | ZeroBOX

PE Compile Time

1970-01-01 09:00:00

PE Imphash

a17186a0dbc86b565628d4a9b8c9cc17

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00001ef8 0x00002000 6.02425455948
.data 0x00003000 0x00043cc0 0x00043e00 7.08667788165
.rdata 0x00047000 0x000005e0 0x00000600 4.66178158904
.pdata 0x00048000 0x000002ac 0x00000400 3.1455694808
.xdata 0x00049000 0x00000204 0x00000400 2.45458788326
.bss 0x0004a000 0x00000978 0x00000000 0.0
.edata 0x0004b000 0x000000b0 0x00000200 1.97999861061
.idata 0x0004c000 0x00000758 0x00000800 4.08069730106
.CRT 0x0004d000 0x00000058 0x00000200 0.201539378135
.tls 0x0004e000 0x00000010 0x00000200 0.0
.reloc 0x0004f000 0x000003f4 0x00000400 6.09152664949

Imports

Library KERNEL32.dll:
0x6bb0c1cc CloseHandle
0x6bb0c1d4 ConnectNamedPipe
0x6bb0c1dc CreateFileA
0x6bb0c1e4 CreateNamedPipeA
0x6bb0c1ec CreateThread
0x6bb0c1f4 DeleteCriticalSection
0x6bb0c1fc EnterCriticalSection
0x6bb0c204 GetCurrentProcess
0x6bb0c20c GetCurrentProcessId
0x6bb0c214 GetCurrentThreadId
0x6bb0c21c GetLastError
0x6bb0c224 GetModuleHandleA
0x6bb0c22c GetProcAddress
0x6bb0c23c GetTickCount
0x6bb0c24c LeaveCriticalSection
0x6bb0c25c ReadFile
0x6bb0c264 RtlAddFunctionTable
0x6bb0c26c RtlCaptureContext
0x6bb0c274 RtlLookupFunctionEntry
0x6bb0c27c RtlVirtualUnwind
0x6bb0c28c Sleep
0x6bb0c294 TerminateProcess
0x6bb0c29c TlsGetValue
0x6bb0c2ac VirtualAlloc
0x6bb0c2b4 VirtualProtect
0x6bb0c2bc VirtualQuery
0x6bb0c2c4 WriteFile
Library msvcrt.dll:
0x6bb0c2d4 __iob_func
0x6bb0c2dc _amsg_exit
0x6bb0c2e4 _initterm
0x6bb0c2ec _lock
0x6bb0c2f4 _unlock
0x6bb0c2fc abort
0x6bb0c304 calloc
0x6bb0c30c free
0x6bb0c314 fwrite
0x6bb0c31c malloc
0x6bb0c324 realloc
0x6bb0c32c signal
0x6bb0c334 sprintf
0x6bb0c33c strlen
0x6bb0c344 strncmp
0x6bb0c34c vfprintf

Exports

Ordinal Address Name
1 0x6bac169b DllGetClassObject
2 0x6bac1657 DllMain
3 0x6bac1695 DllRegisterServer
4 0x6bac1698 DllUnregisterServer
5 0x6bac16a4 StartW
!This program cannot be run in DOS mode.
P`.data
.rdata
`@.pdata
0@.xdata
0@.bss
.edata
0@.idata
.reloc
AUATUWVSH
([^_]A\A]
([^_]A\A]
([^_]A\A]
AVAUATVSH
[^A\A]A^
ATWVSH
X[^_A\
ATWVSH
X[^_A\
ATUWVSH
@[^_]A\
ATUWVSH
0[^_]A\
0[^_]A\
ATUWVSH
P[^_]A\
P[^_]A\
UAWAVAUATWVSH
[^_A\A]A^A_]
ATUWVSH
[^_]A\
ATWVSH
([^_A\H
tNHcA<H
tTIcB<L
tCHcA<H
tKIcA<L
tSIcK<L
Z=j`ZZ
Zxk`Zo
Z=jdZZ
Z=jbZZ
?zlnK#
W;;jH>
oI;{{^
oI;C*|'
?zb{zI;
13(luK
<2(T=8c
~(U;3j|;y8
?z}<ul
_7lnKd
3brsQ*
Rl|J@
763be~
jD@unm?z
702luKv
)=zl|K[
2jx%*7
l2jP6buzI)
702luKv
H(=zl|Kd
W~2bt}
_2jx;
?2(\84b
/7lnK\
702luKv
-=zl|Kd
=zl|K?
>bd~u_
+43Jbwv
/2j}76d
;bm~I;
brzy9}
l(t9I!
~iC(u&I!
(u&>d;
?d=>!j
;br{I!
b{{y }
qbszy!}
(t2;bs{I9
bz{y87
;bu~q#}
;b}~Y+
(t9I!7
(t2;bw
(t2;bw
;bm~I;
l(t9I!
;bz~Y.
u(t4?bm
;b{~Y(
;bf~Y?}
(u&I!7
b{{y 7
;b}<7A
;bs{y+}
(u&>d?
;br~y1
(t4>bg
(t9I!7
l(t9I!7
(t9I!7
$T(t4?bs
;b{<7-
;br~q&}
b{{y 7
(t2;bs~q
bz{y87
)(u&I!7
;b}~Y+
;bj~I>
c(t4I!
(u&I!7
;bu~q#}
(t9I!7
(t2;bv{I1
;bszy1
(t4;bG
;bkzy9
bK~Y;}
(u&?d:O
;bm~I;
l(t9I!
l(t9I!
;b{~Y(
(u&I!7
z:0Cdqy!
l(t9I!
(t4;bvzy
(t=;bn{I
;by~Y.
(u&?d=P
;bxzY-7
(u&>d?7x.0
N(t9>`
(u&I!7
f(t9I!7zF
;b~zY8
c'*?^R
r{~ZBe
h2jP2bF
l2jP2be
h2jP2bFw
l2jP3bds
2jx!*
h2jP2bF
l2jP6b~w
(542jx!*
{wygT?z
W6b{w
h2jPw2
742luJ
>un">z
?zl|KVj
bovy 5bJ
h2jPw?
?2j}7;
o\=;zbd
ox<;zbds
\zI T,
h2jP6
jF<ukZ?z
9ulv?z
50I)W:
luKu(T7;
l2jP?
W%;hE?z
h2jPI2
W#;hF?z
h2jPI2
W#;hF?z
58I)Us{
?zjE6um/?z
?zjE0uf
7(?bsr
w3b_~%
5v~jE2ujv?z
5vfjE'
W;;j~=?`
w2jx;
3bj]8>
?;j\8;
;zl|JW
?zl|JC
2jx%*
O2jxo%*
h2jP2bfw
2jx%*
l2jP>b
l2jP2be
2jx!*
7=;bTw
C0?l|A(
552j~;3(U#>
u(T#2d
77;}>
2jx%*
w2jx;
zI)T|u
!W<>brw
2jV;2d
;I)W:;b
~s5~~b
@2lgKe
2jx%*
l2jP2j
?zl|J[
2jx%*?Er
vuFwwy!7
C02(S#;`
2jx%*
{(Z$7d
2jx%*
5>3j};
(2(^=2b
5>;bl{C
>b{zI;
;:\zI2
{bq{y>7
h2jPI2
2jx!*
wuFusy(
C03(T#8`
*587luAa
5=3j~;7
1m~luJ
jz=2j{72j
*55;b}
?zjA>um
g2lCKi
582lg0
?zbmzI
btvuFwsQ(W=I)
793j{;
h2jP2bFw
?2lCK\
;:_~Y9
l2jP2bfwA#
h2jP2bf
;blzy)}
tzI)5s^
$;bv~A)
2jx%*
'~5zulgAX
593jz;3
7umd<z
zI)5{^
:2(U#2b}w
h2jP3bd
(3(\=2b
2jx%*
h2jP2bF
7=2bFv
>6bm~y)5{^
?2hxwr
'6d?;Z
?2b'7:
h2jP2b
1~{blw
(c?zbw
?uoP>z
=zS<?z
=zS<?z
2jx%*
l2jP6
742jx!
h2jP2
l2jP2be
h2jP2bfw
2jx%*
2j| 3d
h2hP{
2b}wq*?
h2jP>
2jx%*
?2l|K.
zI7yZ
(D;y(}
y17y*l|Kjp
(D;y(}
??lCKu
j^0y+}
5qBl|Kkp?
l2jP2b%
?2jx!*
h2jP2bew
l2jP2be
l2jP2be0
%7~rj|;
l2jP2be
l2jP2be
?2jx!*
2jx%*
;h]?Ji
uKtjE=
E>zl|Kn
>um>?z
2l|J}Q
#?zbdr
l2hPr
oXQ>zl|Ku
CJ1PT<z
?zl|J>
W>zl|Kp
W>zPT<z
?zl|KH
,We2bs
z;>zl|Kp
h2hPx
oH[>zP
?zl|KP
?ud1?z
_>zl|K[
?I;C*0
oD^>zl|Ke
?2luKi
2jx!*
h2jP3bEv
)F;;j~=
w2jx;
od\>zP
?2j~;P
a>zl|K
2j~O;P
a>zl|K
;2beJ
`>zjDh
?2lgKLj
7trbrw
h2jPo3bD{
_2jxo%*
7]C*T8
l2jP2bew
l2jP2bew
l2jP2j
zI 592d
?.C*x%
1q[bk{
?zlgKhl|KmP
?zlCKv
?zl|K3P
?zl|Jl
2jx%*
>zl|Ks
3b_~$*
LI|d"?~
1pebo{
o2l|Jm
1tebi{
h2jP2bfw
?zl|K2j
l2jP2bew
>bzzu^E
;bhY>`
h2jPo2b
w O=z*
HoPH>z
W82bKw
6b]JbP
"ClJl|J}
"CljbL
o2l|JuP
h2jP2bF
2jx%*
>zl|Kfj
l2jP2bew
-?l|Gw
772blw
wy?C*$J
l2jP2bew
l2jPI2
h2jP2bEw
l2jP2be
l2jP2
l2jP2
l2jP2be
h2jP2bew
2bdwA.
?6d9Oy
2jx%*
h2jPo;bD{
h2jPo>b~w
_2jxo%*
2bdvA/
?2bw~A/
h2jP2be
"?l|K3
h2jP2b
7|~l|Jt
ol2>zj
2bi{Q*
>zl|KJ
o6d9_{
?2l|K4Q
h2jP2bEw
l2jP2be
h2jP2j
?>zl|Jl
?zl|Jtb
op>>zl|K_
7!2lgK>
_2lgKP
?zjV=umD?z
702b~wq(?
j\0ul]>z
702b~wq(?
J*Q<?z
1zJbkw
?umQ>z
?zjE5un:?z
uKajE;ul79z
uKQjU<
uK@jU:
?zjUlum8?z
CzI)W9;Q
g2jx;
>zl|Jo
l|0>#5
h2jP2bE
2jx%*
h2jP;bdw
g2jx;
>zl|JR
W2jxo%*
72jP'u_
h2jP'2b
h2jPW2b8
o2j|=2b
2j|72`
;2jT7I;
/2j|72`
J)QC0z
2j|=2`
?zl|Jp
h2jP;bd
1GjbFs
7DRl|0
6bnwuFu
>bLvq#?
W1;Q4>z
=zd,/t
l2jPo2bew
W?zl|Jk
?2lCKv
?2lgJAP
?zlgK\
?7luKi
o2jx;
k~y=5*4&
h2jP2j
?2bEKe
?I T`I
(2jx%*7{^
h2jP2b
l2jP3bd
2jx!*
l2hP|
>zl|J~
;I)WI2d
?2luJvP
?2bdwy!Ttr
?2jx%*
h2jP2bew
l2jP2bew
l2jP6b}w
?zPC?z
?zl|Kw
h2jP/:c
2j~/3j}/
WI7lJK
x2luK8
zI)U<z
3jD/uo
5>2j}=
3j\87l|J
+2jU72b
3j\87l|Jw
2jU2`
?I)Wp2bqwy T
>zl|Ja
?2l|K~bw
h2jP2b
h2jP2j
?zl|Ku
l2jPI C*
h2jPI)
vLml|Ji
742luKx
??lJJ\.
5wf(U/
%7l|Ko
3bBvuFD~
?;b`wA
{?lXKt
r7l|K2
l2jPI2
.2lnKv
2jx!*
4&2ln0
.um8?z
tK_(T/
3j|3jT7
%7luKo
3bbvuFe
W5>bBvA
_7luK!
3(A:;j[ 2d
wumg?z
l2jPI2
l2jPI2
l2jPI2
w;j]02bm0-
Yu>l~Y8
h2jPo2b
j]83(T<
l2jP2bew
?2lgwu
?zl|KQ
l2jP3bd
?zl|J}
?zl|J}
i2jPo3bL
?2l|Kp
l2jP2bew
?2l|Kj
?zl|Jwj
l2jP/;P
wI%T,&
wX'=z*
?zl|Jr
?um7?z
l2jP2be
2jx!*
W<6b~~
@ulS7z
vuW{}uW07
Lhp{{^
?zjEQum
jEJumy?z
W2lgwu
3jy7;z
?zl|Ksi
~uSR72
zI;5{^
42j{=;
?zl|K[
.1;2j|
W<6b~~
vuW{}u_07
"jF7um
Lhp{{^
?zjEQum
jEJumy?z
W2lgwu
3jy7;z
?zl|Ksi
~uSR72
zI;5{^
42j{=;
?zl|K[
.1;2j|
lnKgjF8
o2jx;
07lCKy
rLljq7;
&7lCvu
KrhC?z
<Hrl|J]
5 :y=
2bmJs
h2jP2d
2jx%*
h2jP2d
2jx%*
h2jP2
?zl|Jrd
2jx!*
l2jP2d
_`b?z%
l2jP2be
?lgKdb
h2jP2bew
2l|Kub
5W=I2T@
oTa?zd7
=zbe~u
h2jPI
~uJ`LW
I C*|2
?zbswy 7{
?I 5c^
Y;`8wb
>;hF>{
wI%TX]
w3b_~%
?2lCKQ
l2jP2be
2jx!*
2l|Jrd
2jx!*
h2jP2bFw
?zl|J}Q
?2l|J}Q
2jx%*
l2jP2bew
l2jP2bf
o2jx;
h2jP2
o4{?zbd
2beKX
l2jP2bew
52jx!
2jx!*
FjlCAW
?udt?z
?zjr=3
js=uSR8
uKSjU4
g2jx;
3(A:;jX 0b
|?zl|0
?zlgKs
iE5u}|
oum|?z
?>bz{Q)
s2d9|
?2d9|
5>2j}=2j~=2j~=
?zl|Kt
7~bA?0
<~7W82d
?uj,?z
3(C:6d
jZ 1b0
uKelgKa
?zl|Jp
UW21b8
?zl|Jt
7 >bO{Q
?;i@>ulT?z
/28W{C
?2bDvA
g2jx;
g2jx;
l2jP?b
jC<udr?z
?zl|KM
?2l|Kr
7 2lgKM
?2j{72
l2jP2be
?zl|K}P
?2j}/2
2jx%*
?I W:2
?2jx'*
?2bdY>
/W42bs
l2jP?
67l|Jg
2jx!*
62j}=2
l2jP?
12lnKs
l2jPI2
12lnJZ
2jx!*
"7lCKs
j] 2(D:2
?2l|Ky
?zV<?z
2luKpj
h2jP2bFw
|2luKD
?2luKyj
?zPC?z
-2lCKw
-2lCKw
I)W'u^
?2jx_;
h2jP2d
h2jP3bDw
?I)Wb2
?zl|K}P
2bowy;
h2jPo2d
?2j{/2lCK
W<2bcw
o4=?zl|Ko
G2jx_%*
o8??zQ
>ul*?z
J]luKl
I;C*li
j^ 2(D:2
o2jx;
h2jPo?bls
?zluKi
:2lCJ`
Y;(\72
,W8a)?
,7l|Kt
JdlJKn
l2jP2luKw
2lnJta
l2jP2bew
l2jP2bew
2jx!*
l2jP2bew
?msKr`
W3;bs
j] 2(D:2
j] 2(D:2
;;ip72b
l~K`d=?z
?um#>z
;jB;un
j] ;iZ@2(D:2
j^ 2(D:2
j^ 2(E:2
K3d>?z
?z(]/q(
?z(]/q(
?z(]7q(
2(D=2b0
?z(]7q(
?z(]/q(
2j|;2`
2j|;2`
2j|;2`
2jT32`
2jT/2`
R(V/u_ns
R(T'u_|w
R(U7u_uw
R(U?u_uw
?z(]/q(
?z(]7q(
?z(]/q(
7;^(T'u_|w
~(T'u_|w
v(V/u_ns
~(U7u_uw
r(U?u_uw
b(U7u_uw
f(U?u_uw
n(T'u_|w
b(T'u_|w
f(T'u_|w
b(U7u_uw
f(U?u_uw
f(U7u_uw
j(U?u_uw
j(V/u_ns
?z(]/q(
?q(5{^
?z(]7q(
v(U7u_uw
r(U?u_uw
v(T'u_|w
f(V/u_ns
f(U/u_uw
b(U7u_uw
n(U?u_uw
b(T'u_|w
C?I(7s^
?I(7s^
b(U/u_uw
n(U7u_uw
j(U?u_uw
u?2d03
|?2d8;
u?2d03
l2jP2be
2bEJrjt
?zl|Jq
m|K?}8
2lnKji
2l|Jrd
792l|Ka
2l|K9d
7<2l|J
1um%?z
?zl|Jtjs
?zl|J}
?zm|Kt
o2d)_{
?2d!Oy
o2luKq
:2lJJm
L2luJ`
j~2j{=2
2lgJZjt
V2j{72
Wx2j|=
J~>ul
?2l|J}
?l|K^b
Cojl|0
C?7bxw
?zm|~u
Cm"b{w
:2lJJm
?2lnJm
?zlCA9bkv
?zlJASbzv
7G~lCKrlJ0
?2hE?~
2l|Ku.
W<2bGw
j2jP2bV
j2jP2bVw
j2jP2bVw
j2jP2bVw
2jx'*p
j2jP2bVw
j2jP2bVw
j2jP2bV
j2jP2bV
?2jx'
j2jP2bVw
j2jP2bV
?2jx'
o2jx'
j2jP2bV
?2jx'
2jx'*p
>zj] 2
?zi+?z
nsYEo0^
Wf#[ux=g
5Re ]G
bu0}hs6qTg"Y
y|9okr7s
Xnq4u\
G\$H'#
nDD(^oL
S_:C#N$
}jl+,:
X~8k/9B^
Vff(|mk!rp|:`{q3n
y^V4HS_:CDD(^IM&U
Zr<TS|7YHn*NA`!C~J
f&8k/
gbv Xl}-Q~`:Jpk7C
?zi+?z
/;bGuA
2jx%*
%c%c%c%c%c%c%c%c%cMSSE-%d-server
Mingw-w64 runtime failure:
Address %p has no image-section
VirtualQuery failed for %d bytes at address %p
VirtualProtect failed with code 0x%x
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
.pdata
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.3-win32 20200320
GCC: (GNU) 9.3-win32 20200320
GCC: (GNU) 9.3-win32 20200320
GCC: (GNU) 9.3-win32 20200320
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.3-win32 20200320
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.3-win32 20200320
temp.dll
DllGetClassObject
DllMain
DllRegisterServer
DllUnregisterServer
StartW
CloseHandle
ConnectNamedPipe
CreateFileA
CreateNamedPipeA
CreateThread
DeleteCriticalSection
EnterCriticalSection
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetLastError
GetModuleHandleA
GetProcAddress
GetSystemTimeAsFileTime
GetTickCount
InitializeCriticalSection
LeaveCriticalSection
QueryPerformanceCounter
ReadFile
RtlAddFunctionTable
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
SetUnhandledExceptionFilter
TerminateProcess
TlsGetValue
UnhandledExceptionFilter
VirtualAlloc
VirtualProtect
VirtualQuery
WriteFile
__iob_func
_amsg_exit
_initterm
_unlock
calloc
fwrite
malloc
realloc
signal
sprintf
strlen
strncmp
vfprintf
KERNEL32.dll
msvcrt.dll
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Clean
tehtris Clean
ClamAV Win.Trojan.CobaltStrike-9044898-1
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win64.Trojan.dc
ALYac Dump:Generic.Beacon.Marte.B.9458FA82
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.CobaltStrike
K7AntiVirus Clean
Alibaba Clean
K7GW Clean
Cybereason Clean
huorong Backdoor/CobaltStrike.d
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Backdoor.Cobalt
Elastic Windows.Trojan.CobaltStrike
ESET-NOD32 a variant of Win64/CobaltStrike.Artifact.A
APEX Malicious
Avast Win64:Evo-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.CobaltStrike.gen
BitDefender Dump:Generic.Beacon.Marte.B.9458FA82
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Dump:Generic.Beacon.Marte.B.9458FA82
Tencent Trojan.Win32.CobaltStrike.16001072
TACHYON Trojan/W64.CobaltStrike.295424
Sophos ATK/Cobalt-W
F-Secure Heuristic.HEUR/AGEN.1362273
DrWeb Clean
VIPRE Dump:Generic.Beacon.Marte.B.9458FA82
TrendMicro Backdoor.Win64.COBEACON.SMA
McAfeeD ti!28635585AE47
Trapmine Clean
FireEye Generic.mg.e744a3ee4380bc4e
Emsisoft Dump:Generic.Beacon.Marte.B.9458FA82 (B)
Ikarus Trojan.Win64.Cobaltstrike
GData Dump:Generic.Beacon.Marte.B.9458FA82
Jiangmin Trojan.CobaltStrike.io
Webroot Clean
Varist W64/Beacon.A
Avira HEUR/AGEN.1362273
Antiy-AVL RiskWare/Win64.Artifact.a
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Zusy.D746F9
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win32.CobaltStrike.gen
Microsoft Backdoor:Win64/CobaltStrike.NP!dha
Google Detected
AhnLab-V3 Malware/Win.Generic.R374111
Acronis suspicious
McAfee Injector-FEY.c!E744A3EE4380
MAX malware (ai score=84)
VBA32 Clean
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Backdoor.Win64.COBEACON.SMA
Rising Backdoor.CobaltStrike/x64!1.E382 (CLASSIC)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.121218.susgen
Fortinet W64/CobaltStrike_Artifact.A!tr
BitDefenderTheta Clean
AVG Win64:Evo-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Backdoor:Win/Cobaltstrike.d603e567
No IRMA results available.