Static | ZeroBOX

PE Compile Time

2024-08-20 00:38:08

PE Imphash

7ef8d58ff9037925d777e78c004fde83

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x001d34a8 0x001d3600 6.64997190674
.data 0x001d5000 0x0000c640 0x0000c800 7.88401807189
.rdata 0x001e2000 0x000099b8 0x00009a00 5.43543171037
.pdata 0x001ec000 0x00005c40 0x00005e00 6.04271695177
.xdata 0x001f2000 0x000046fc 0x00004800 3.52510653361
.bss 0x001f7000 0x00065e90 0x00000000 0.0
.idata 0x0025d000 0x000005fc 0x00000600 4.34043963432
.CRT 0x0025e000 0x00000058 0x00000200 0.253231201804
.tls 0x0025f000 0x00000010 0x00000200 0.0
.rsrc 0x00260000 0x00000138 0x00000200 1.6087277555
.reloc 0x00261000 0x00000388 0x00000400 4.8549153545

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00260058 0x000000dc LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ADVAPI32.dll:
0x14025d198 RegOpenKeyA
0x14025d1a0 RegQueryInfoKeyA
0x14025d1a8 RegQueryValueA
0x14025d1b0 RegQueryValueExA
0x14025d1b8 RegQueryValueExW
Library KERNEL32.dll:
0x14025d1c8 DeleteCriticalSection
0x14025d1d0 EnterCriticalSection
0x14025d1d8 GetLastError
0x14025d1e0 GetProcAddress
0x14025d1e8 GetStartupInfoA
0x14025d1f8 LeaveCriticalSection
0x14025d200 LoadLibraryA
0x14025d210 Sleep
0x14025d218 TlsAlloc
0x14025d220 TlsGetValue
0x14025d228 TlsSetValue
0x14025d230 VirtualAlloc
0x14025d238 VirtualFree
0x14025d240 VirtualProtect
0x14025d248 VirtualQuery
Library msvcrt.dll:
0x14025d258 __C_specific_handler
0x14025d260 __initenv
0x14025d268 __set_app_type
0x14025d270 __setusermatherr
0x14025d278 _acmdln
0x14025d280 _commode
0x14025d288 _fmode
0x14025d290 _initterm
0x14025d298 _ismbblead
0x14025d2a0 _onexit
0x14025d2a8 abort
0x14025d2b0 calloc
0x14025d2b8 free
0x14025d2c0 memcpy
0x14025d2c8 memset
0x14025d2d0 strncmp

!This program cannot be run in DOS mode.
`.data
.rdata
@.pdata
@.xdata
.idata
@.reloc
D$$=[#
ffffff.
D$$=p8kH
0z;9e|L1
Un>TL1
{cj_?T
{cj_?T
0=k%Vd
L$0=[#
fffff.
H?UMD1
Y"'25X
D$,=p_C^
L$ =k%Vd
L$0H9H
/PbQL1
D$8H;H
fffff.
ffffff.
H&-4E1
fffff.
fffff.
@Di,YH
tY?x|J
JHH;J@
D$<=k&
L$0H9H8
rM[xnH)
D$D=qJ
5/!t@3
a!fyM1
-==knA
Z!{MT3
X!{MT3
D$4=A3
fffff.
R\};A1
Jfc?M1
uP#WE1
D$4=BP0q
ffffff.
@^uHM1
ffffff.
S5n4v%
L$7=4A
M%0&w%
L$O=P&
7J[2H1
ffffff.
D$0=5v
z=$pS%
GmTiD1
55FR.D
'1-:e#z-
ffffff.
fffff.
ffffff.
-S1mo=
L$8H;B
!=%Z\I
D$L=m&m
fffff.
'U)Bo
fffff.
5?<(CA1
L$8H;B
fffff.
W>-dxL5
L$?=K2
OGx$14H
OGx$14H1
-=?9D1
ffffff.
ffffff.
L$/=Y.
D$$={@iQ
L$g=})
|K[IM1
UzeYE1
L$'=vu
-Z(2H1
ZzvhI1
su5f%Xjb
fffff.
L$W=+WS
5.atS3
on+%L1
D$,=S+
fffff.
it3nL1
D$$=f7
ffffff.
fffff.
L$G=yXy
D$D=:lj
fffff.
L$/=uj\
YfM}H1
5xycn1
W$"&D1
}Y}`P*
uY}`P*
fffff.
5<[A1
D$(=?}'
5\}0O1
T5LJg.
H^64H1
PXI;Ph
fffff.
{cj_?T
{cj_?T
D$@H9QXH
ffffff.
D$TfA!
D$.fA!
cey"E1
roG%A1
H?UME1
D?-CL1
WXyL1
&9ixM#U
1wdc97M1
%H^6tA
S5>hE!
qQ=>I1
oquC7I
fffff.
5]cN0A1
ffffff.
;R~5L1
n_NjM1
L$/=k<t
fffff.
WW)1A1
L$o= >
D$,=PO
Xs:E5Xs:ED)
ffffff.
ffffff.
L$(=,,
L$'=-D
L$HH;B
fffff.
L$HH;B
L$XH;B
7q\[55q\[
ats5-dQB
fffff.
6U5oI1
vy-e]$
ub.#E1
+|/J[vL1
fffff.
439;A1
L$HH;B
L$/=1C
,\5nO!
U5*,I/A
1>X!L1
tm]%BI
tm]%BM1
u<`$+I1
ffffff.
zY/.D!
-e2kx-
Ms="aa;
k+QM5R
ffffff.
D$,=r\
L$HH;B
ffffff.
L$_=Y/
-4`E@-
}W@%D!
z+HtE,
ffffff.
e4eB\~
eX[_^]
fffff.
D$$=k%Vd
fffff.
L$/=^E)
L$'=puD
D$ =XC"
L$?=[#
-*9',i
ffffff.
L$0=pL\
H?UMD1
-#X`RA
fffff.
+l`OJA
ffffff.
fffff.
D$P-yq;
+l`O5>
L$G=U{
-nSw;-
D$8=@-^P
fffff.
L$O=#xP
D$ Ec&l
L$F=*G`
L$P=1r
zaosvEFAI
B\}?A!
L$4=+e
={O:g
ffffff.
ffffff.
D$,=zUF7
ffffff.
D$,=ri
D$$=WG
PR'.&_(L1
C)L~H1
ffffff.
ffffff.
ffffff.
fffff.
ZK=zA1
ffffff.
fffff.
fffff.
ffffff.
Bd&=Lz
oK>"D)
5!?P*!
L$/="<
fffff.
5R05.A
R05.D!
^.c0E1
L$7=EB
L$G=Q}
cp)D+\
5B/|{A1
5Jg<")
{k!WA1
ffffff.
L$0=6TC
SNi/L I
PzLL1
ffffff.
UAWAVVWSH
59G^-%
m3u;D1
-BX$}-
+)I!D1
]cN0D1
[_^A^A_]
D$T=HP
S3z4mW
D$$=+?
9:'>s%
ffffff.
-wedK-{
0<@RH1
-j$pT=
fffff.
e([_^]
fffff.
,p7BHi
ffffff.
Jr_(D1
Py.v2H
fffff.
|B`Q-5I
|B`Q-uM1
D$ F*T
ffffff.
L$7=0h
|-xKD!
?Ux:H1
L$HH;B
{cj_?T
{cj_?T
fffff.
fffff.
{cj_?T
1\FfM1
O`*X5O`*X
ffffff.
ffffff.
fffff.
?gw9\o
ffffff.
L$D=@-^P
L$g=p8kH
{cj_?T
L$;=b9Uf
PzLM1
[]424,
Z]424,
;H^6tL1
roG%D1
fffff.
ffffff.
}UmpD1
L$/=+?
Af5vCf
ffffff.
55JkED
Lv-i5J
M/=Gu[a
L$0=-D
D$0LcH
1McJ<M
#\wtML1
>c{S:=iM1
ZyTnW|I
UAWAVAUATVWSH
Va$_f7
U|?kD1
[_^A\A]A^A_]
CMVED!
L$0=[#
^>K-D)
UAWAVVWSH
[_^A^A_]
ffffff.
ffffff.
gzU%kH
fffff.
8@Nt;iA
L$G= 4
D$$=c`a%
[-c?=]
7q\[D9
6U5/H1
8MCj1"%
52d{_D
qVOvL1
XA%0$X
WD()cgNH
WD()cg
ZOa$L1
$ oVH1
cNoyD1
=fJnW
5DD-e#
=[40%w
=[40%w
fffff.
k,Jd1I
2f5!2f
ffffff.
] l6OH
] l6OH1
|5+XD1
D$D=pL\
ORm!RAH1
fffff.
fffff.
{P5pD1
nSw;A)
Kp-Y5{
^i-an}
4b5?H<`
L$0=[#
fffff.
fffff.
pb^Bl|
!-*9',-V
ffffff.
5w^30A1
fffff.
D$$=k%Vd
L$0=[#
Lv-i5J
ffffff.
-#X`RH
i5nZ0i
D$ N5]d
1hXUH1
h)51XL1
T-QUA1
tL8xI1
Q?i3A1
C%f)I1
$AQX+7I
I8H1wI
#XjzWnb%I
#XjzWnb%L1
zaosvEFAI
ffffff.
,v'8D!
Lqp=J=)D
D$$=k%Vd
rP1GL1
D$ =4~
ffffff.
SNi/L H
5[]42D
tT1AT^
p8kHA!
wPm[NFI
m[NFL1
UAWAVAUATVWSH
-#X`R1
K*xJE1
D$ p~}r
D{frG;H1
0=^tnZ
[_^A\A]A^A_]
ffffff.
{cj_?T
{cj_?T
nSw;%d
pGBzH1
3`b)6L
)t!K#1H1
S{=nsH
S{=nsH)
<&s(L1
\fZ1E)
fk5Y8
AnAxRH)
=%an*J
WD()cgNH
>bH25n^
yX}pYF
yX}pYF
A|JfE8
1Z=w,*%
4r=2cL1
HkNeA'
5a8Ix1
53Ij01
?)pSA1
L$w=>;
Rcf1H1
W/&heH)
W/&heH
b;LIE1
L$G=YS
o*xfE1
1wdc97M1
Lf5!Lf
D=f5*?f
=tOaD!
n=6$ui
D$$=k%Vd
L$0=:9
UAWAVVWSH
BMVEM1
3|ANL1
1\FfM1
[_^A^A_]
{cj_?T
{cj_?T
~mUaA*v
fffff.
D$,=4~
\g0`GI
\g0`GM1
J:t?D1
&9ixE1
L$HH9Q
L$ H;A
gh5$Td-)
UAWAVAUATVWSH
0b_IH1
|qH9L)
[_^A\A]A^A_]
8&ExH1
IJz*M1
5s<hxD
J:t?D1
-5'vHO=
D$(=3'
C*G&5C*G&A
fffff.
oquC7H
e=\bHW
d=.=BX$}
ffffff.
:T_EM1
Z&r+(+
5`ZPHA
D$ Fjko
L$7=M)
fffff.
qP9n5s}Z
L$h=3$#
fffff.
ffffff.
D$,=1C
UAWAVAUATVWS
%ruC71
Rer'I1
znzml@I
znzml@L1
_5o5GZ
@d t`I
M@& 3$YM1
ad=0}zB
5'f9DA1
MO=j.N
HO^=V|"_
[_^A\A]A^A_]
5Gxps1
O~wkE1
M_=(TN
:-Axgl)
7J[2L1
fffff.
Kq?f=U
ffffff.
UAWAVATVWSH
h^\Z5j^\ZA
-pSfq)
|Z=0H1
[_^A\A^A_]
Q7a=D1
L$O=~2
UAWAVAUATVWSH
rVG85+
!4=2fh
[_^A\A]A^A_]
L$HH;B
L$(=nY0
D$,=sQ
ffffff.
h`=KD1
L$8=lG6
-"elb)
fffff.
ffffff.
fffff.
+l`OJA
+l`OJA
fffff.
-nSw;-
ffffff.
L$'=puD
fffff.
ffffff.
L$o=@-^P
59G^-H
M'=g}M
EUh1+H)
EUh1+H
Ua/D1
B-BX$}-
%#ZS5&F
Xs:EA)
Q,f5w+f
$AQX+7H
$AQX+wH1
UAWAVAUATVWS
#XjzWnb%I
#XjzWnb%L1
[7ufH1
%=[40A
=[40E!
=[40D!
52d{_#
BrY1IL1
>;b]A1
9[`}A1
5o!kA1
2U=8P
[_^A\A]A^A_]
U,5@JZ
x$(LA1
}UmpD1
L$O=1F
0z;9e|M1
&'&!D!
F7oI*H1
$f5V#f
fffff.
K)Yws-gYI
K)Yws-gYM1
M'=tfr8
UAWAVAUATVWS
Xs:E5Xs:E)
GPTD9c&H1
YngaE1
-D?-C-
-"aa;=
%'xC8A
P&45R
ys0k5*
[_^A\A]A^A_]
fffff.
L$0=8~fy
fffff.
fffff.
L$'=puD
wPm[NFI
wPm[NFL1
MeuSD1
UAWAVAUATVWS
5-tP9#
gzU%kI
gzU%+L1
p"34QH
5(>2_D
wvxHL1
5}0u~A1
[_^A\A]A^A_]
zaosD+
fffff.
-/2:D1
fffff.
[]424,
S]424,
L$'=puD
5nZ0=
&~5x$z
`>f5C4f
suzgH1
fffff.
D$,=k%Vd
-*9',i
!#5b;H1
L$8H;B
fffff.
oV3` L1
ffffff.
ffffff.
^y$=H1
ffffff.
EUh1+I1
EUh1+H!
ffffff.
ffffff.
(fYfD1
D$$=(F
L$/=puD
ffffff.
UAVVWSH
-2f5Y1f
5f58<f
k#5Z}e
m1?|D1
[_^A^]
-j$pTA
MHH;A(
Hf5(Mf
L$HH9H
fffff.
fffff.
x>-XC"
L$/=puD
1\FfH1
A[A~E1
%@e)XA
@e)XE!
ONEWM1
Ln~~5Ln~~)
LA%;F5==(T
ffffff.
x>-XC"
L$'=puD
rn0IH1
.VFX[M5BH
&VFX[M5BH1
/&w%H1
J._:A1
-P&TE)
5cY#?1
5!{WSD
' $$M1
3O^#L1
ffffff.
ffffff.
x>-XC"
fffff.
fffff.
D$,=pL\
L$8H;B
L$HH;B
/rE5r.8]
UAWAVAUATVWSH
.t&q5L
[_^A\A]A^A_]
ffffff.
UAWAVATVWSH
JL=k<t
~TBvhL1
[_^A\A^A_]
>l5#5lr
@u?UA1
MN=7gq
S_28A1
9Pf5nZf
%4&s')
WD()cgNH
WD()cgNH1
Y=.UD1
UAVVWSH
vf54sf
[_^A^]
7"5umQ@
5$P'x1
Kf5Z@f
!(:>L1
fffff.
ZyTnW|H
ZyTnW|H1
45H$]Y!
59G^-%
-BX$}-
c`a%A!
0SV-0}T
=CCG u
)sm8X>Khd
O(ioa&
Ugh|J@`
"34Q[UJ
<:<{}h]|R[
14~!Zv.
pV@Ux:
Wf5%0+b
N,(y11`
iR,?s]
3|:9os
C8H1wu
1=@7dr
=wxc<C.
1Vf*s|
uX)]11
I[;\A?
FwUFyJ
C8&Exz}
|E l6O
,?PXvk
0U\Gw];)
vqj}*m
nZ0ZV
bd#X`R
32M1&: j
jCL{=nsm
hS 0O>
WVkq&ayoZ
<I`lCF
#X`R$'
gGL]eb
]AK3|
l2H^6tK
#`?Xu*
'pswf 7v
4gs|:jF
XN3orN
;4|AN$L;
1z?@U*
1)Q}MLf
1);[-
XN3orN
C)n~Og1
r4gs|3#
!c;:p>E
+1u6G2i
6#[B,v'8
Iy.v2Q
jWlsq
4ylEan}
.1ckH
s]qEc~
|XuOchH
4gs|:jF
ZoTh!S
&b#X`R
XN3orN
Hy+,"x
c\!GB>%
&<wedK
n8&Ex(
[-c?ri
wc=iOP}J&
#Q@"iA'M
gGL]eb
}R"odQ
l9G^-Z
|WU;F5=
|E l6O
-rPi:QB
7.xp9t
_HGk8ZXuGfKEn+
,bZ(qA?[
B4Ydj>A
luPMtB0
`p!O%YH
c72v\.
MJ;z+L
8&Exz}
\4#X`R
?@U*0}
G'I/l "+'
v%("Vi
W[21~t)
yN"R]2
[='nZ0
C8&Exz}
$qb99gt
`Bl?@U*0}
<:<{}h]&;
*mcJ-G
C8&Exn:
[='nZ0
:ruj$pT
76"mB1
|E l6O
4l#X`R
l2H^6t
[='nZ0
l9G^-I
i#"D>ge
hbHfMi
^k 9|R(
;TR]eb
l2H^6tf#
InitializeCriticalSection
InitializeConditionVariable
EnterCriticalSection
LeaveCriticalSection
WakeConditionVariable
SleepConditionVariableCS
@kernel32
@kernel32
CreateThread
@kernel32
@kernel32
VirtualAlloc
@kernel32
@kernel32
ExitProcess
@kernel32
@0123456789ABCDEF
I`bdfhjlnpr
I`bdfhjlnpr
^j\`@P
^jfn\fl@P
^b\j\bd@
^bd`\`\l`rr\dpf@
^dp\d\f@
^jfn\fl
=2yypy
I`bdfhjlnpr
Ni3p6E
b&U<YQ
z>:lTS1
^j\`@P
@b`\`v@
^jfn\fl@P
^bdh\`\`\`@
^jfn\fl@
^bdh\`\`\`
RtlCaptureContext
@ntdll
@ntdll
GetProcAddress
LoadLibraryA
CloseHandle
GetProcessHeap
SetErrorMode
GetDriveTypeW
VirtualFree
VirtualAlloc
@kernel32
@kernel32
GetSystemInfo
@kernel32
@kernel32
kWimgego
GetModuleFileNameW
CreateFileW
@kernel32
@kernel32
GetModuleHandleA
HeapCreate
HeapAlloc
VirtualQuery
CreateEventW
CreateTimerQueue
CreateTimerQueueTimer
WaitForSingleObject
VirtualProtect
SetEvent
DeleteTimerQueue
HeapDestroy
@ntdll
@NtContinue
@advapi32
@SystemFunction032
@kernel32
@CopyMemory
@kernel32
RegOpenKeyA
RegQueryInfoKeyA
RegQueryValueA
RegQueryValueExA
RegQueryValueExW
DeleteCriticalSection
EnterCriticalSection
GetLastError
GetProcAddress
GetStartupInfoA
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryA
SetUnhandledExceptionFilter
TlsAlloc
TlsGetValue
TlsSetValue
VirtualAlloc
VirtualFree
VirtualProtect
VirtualQuery
__C_specific_handler
__initenv
__set_app_type
__setusermatherr
_acmdln
_commode
_fmode
_initterm
_ismbblead
_onexit
calloc
memcpy
memset
strncmp
ADVAPI32.dll
KERNEL32.dll
msvcrt.dll
#+3;CScs
VS_VERSION_INFO
StringFileInfo
040904E4
VarFileInfo
Translation
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.SleepObf.4!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Win64
Skyhigh Clean
ALYac Trojan.GenericKD.73875671
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win64.Kryptik.Vc2e
K7AntiVirus Trojan ( 005b85c31 )
Alibaba Trojan:Win64/SleepObf.79070aa3
K7GW Trojan ( 005b85c31 )
Cybereason Clean
huorong Clean
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win64/Kryptik.EMS
APEX Malicious
Avast Win64:CrypterX-gen [Trj]
Cynet Malicious (score: 99)
Kaspersky Trojan.Win64.SleepObf.gg
BitDefender Trojan.GenericKD.73875671
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Wacatac.2052608
MicroWorld-eScan Trojan.GenericKD.73875671
Tencent Malware.Win32.Gencirc.14174774
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Kryptik.icaaj
DrWeb Clean
VIPRE Trojan.GenericKD.73875671
TrendMicro Trojan.Win64.AMADEY.YXEHTZ
McAfeeD ti!30B84843ED02
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.4e18e7b1280ebf97
Emsisoft Trojan.GenericKD.73875671 (B)
Ikarus Trojan.Win64.Crypt
GData Trojan.GenericKD.73875671
Jiangmin Clean
Webroot Clean
Varist Clean
Avira TR/Kryptik.icaaj
Antiy-AVL Trojan/Win64.SleepObf
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D46740D7
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win64.SleepObf.gg
Microsoft Trojan:Win32/Phonzy.A!ml
Google Detected
AhnLab-V3 Trojan/Win.TrojanX-gen.C5656555
Acronis Clean
McAfee Artemis!4E18E7B1280E
MAX malware (ai score=82)
VBA32 Clean
Malwarebytes Trojan.ShellCode
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Trojan.Win64.AMADEY.YXEHTZ
Rising Trojan.Kryptik!8.8 (CLOUD)
Yandex Clean
SentinelOne Clean
MaxSecure Trojan.Malware.276088877.susgen
Fortinet W64/Kryptik.EMS!tr
BitDefenderTheta Clean
AVG Win64:CrypterX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Trojan:Win/Wacatac.B9nj
No IRMA results available.