Static | ZeroBOX

PE Compile Time

2024-08-29 21:31:56

PE Imphash

45139a94dafe252fbbb16ac605dbb6f7

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x001d9548 0x001d9600 6.62962726441
.data 0x001db000 0x0000bbd0 0x0000bc00 7.90469058419
.rdata 0x001e7000 0x00009ee0 0x0000a000 5.49717270849
.pdata 0x001f1000 0x00005f70 0x00006000 6.12566311194
.xdata 0x001f7000 0x00004978 0x00004a00 3.558062266
.bss 0x001fc000 0x00065ef0 0x00000000 0.0
.idata 0x00262000 0x000005e4 0x00000600 4.33360717417
.CRT 0x00263000 0x00000058 0x00000200 0.258611841457
.tls 0x00264000 0x00000010 0x00000200 0.0
.rsrc 0x00265000 0x00000138 0x00000200 1.6285554479
.reloc 0x00266000 0x000003a4 0x00000400 4.99224427999

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00265058 0x000000dc LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library ADVAPI32.dll:
0x140262190 RegQueryMultipleValuesA
0x140262198 RegQueryMultipleValuesW
0x1402621a0 RegQueryValueA
Library KERNEL32.dll:
0x1402621b0 DeleteCriticalSection
0x1402621b8 EnterCriticalSection
0x1402621c0 GetCommandLineA
0x1402621c8 GetLastError
0x1402621d0 GetProcAddress
0x1402621d8 GetStartupInfoA
0x1402621e8 LeaveCriticalSection
0x1402621f0 LoadLibraryA
0x140262200 Sleep
0x140262208 TlsAlloc
0x140262210 TlsGetValue
0x140262218 TlsSetValue
0x140262220 VirtualAlloc
0x140262228 VirtualFree
0x140262230 VirtualProtect
0x140262238 VirtualQuery
Library msvcrt.dll:
0x140262248 __C_specific_handler
0x140262250 __initenv
0x140262258 __set_app_type
0x140262260 __setusermatherr
0x140262268 _acmdln
0x140262270 _commode
0x140262278 _fmode
0x140262280 _initterm
0x140262288 _ismbblead
0x140262290 _onexit
0x140262298 abort
0x1402622a0 calloc
0x1402622a8 free
0x1402622b0 memcpy
0x1402622b8 memset
0x1402622c0 strncmp

!This program cannot be run in DOS mode.
`.data
.rdata
@.pdata
@.xdata
.idata
@.reloc
fffff.
fffff.
N@4*L1
etQ4I
etQ4L1
Hf>%~'
L$7=c^
lS_;D1
L$^=hw
fffff.
-o0i8)
fffff.
L$8H9H
<p5V9|
fffff.
fffff.
D$8H;H
ffffff.
L$7=4..
ffffff.
/an4DDL)
/an4DDH
F34SiI
F34SiM1
eH[_^]
P[-0D!
ffffff.
JHH;J@H
ZAW2D+
$euAM1
E3ogH1
L$(H9H8
L$(=sfS
wxUiA1
ffffff.
L$?=ba<
2>Q\E1
k@FL1
sR(]E1
m{v+D1
5|(c1!
fffff.
->eP;!
T$85U^
ffffff.
fffff.
V>KVNsV
V>KVNsV
APJ7(NL1
!cO`L1
b-4?qt
c.t5]Z
58>yfA
L$8H;B
L$_=sd}Q
ffffff.
L$ =QF
G5vbpSA)
L!;*I~
yy^\E!
ffffff.
Ot_4L1
fXZfH1
ffffff.
fffff.
Cra(D!
fffff.
UBaXXb
fffff.
fffff.
L$(=Vm
$k>8A1
D$,=BX
W0W:&H
5t1`BD
*MmzH!
D$$=yb
D$$=I&y
ffffff.
fffff.
fffff.
:"VbD1
L$/=;U
%e{bkA
D$,=F+
fffff.
L$7=%\
fffff.
ffffff.
L$'=Mn
ffffff.
5[RZg1
L$S=uf
5/GbIA1
EUIwQ1
ffffff.
?KP_oM1
(=4%HH
(=4%HI1
L$'=9^
L$>=eiSa
5CGTFA1
p\a>5_
L$7=~h?n
'kir5b
+-tNR
vbw%L1
ffffff.
D$ =(g
<I4tL9
T$p-?<
L$G=y+
ffffff.
[+S&E1
t%G{L^
L$7=:Z
569[/=
fffff.
fffff.
Z @oJI
D$$="e
ffffff.
D$(=4<n
ffffff.
ffffff.
D$$=#j
L$G=u{
Y~Wb7I
Y~Wb7L1
-7ggj)
fffff.
-M6bk=
fffff.
~I5pLIg1
KG0MA1
}*Yw5}*Yw
,QbPE!
t4@]D1
D$,=hq'w
ffffff.
Qe-M{)
L$(=fe
LwA5\;M
AXH;Ah
ptM:o%L1
)2yD-
D$HH9QXH
N@4*H1
ffffff.
o0i8-8
sC9/(,
EFmU(H
EFmU(H1
5>2<EA1
fffff.
qL<#E1
q=3Pgm
L${=2})
z\s2HI
iLqdL1
lB8OH9
L$?=EP
DkH^qb
_Uu{L1
x5%SZ{r
@9}zH)
53\Pp1
L$@=]g
l1en-L1
(}c5L1
fffff.
ffffff.
eH[_^]
L$8H;B
eh[_^]
H5X6;\1
L$/='Y;
L$HH;B
fffff.
<Yu[D!
ffffff.
L$HH;B
D$$=,'
ffffff.
L$?=|`
ffffff.
UAVVWSH
[_^A^]
`jS~TH
`jS~TH1
fffff.
-(sW$=
g05=L1
D$ =BH
L$'=yOw
ffffff.
ffffff.
5sz:A1
ffffff.
L$HH;B
L$/=sfS
-wseaA
RAdOrn
P? <H1
!qA,M1
t1K'A!
fffff.
{g\}D1
ffffff.
L$HH;B
ffffff.
PP5S3c
L$-=#Q
4r;;:=s
*P=z-0
xEtw\V
ho0KL=H
ho0KL=H1
!Y%2[(
L$HH;B
52MIa5
%aM=l$
D$$=K&7
<vfHA1
e([_^]
L$/=;@
T$&fA1
[h%O@4*
-r^P%-
fFdnA1
D$H-e.y
c20p5c20p)
[h%O@4*
fffff.
t*T>5R
fffff.
L$?=$;
fffff.
D$ ,|1?
aV+6A1
nB?xA1
fffff.
L$@=ds
RAdOrn
e#u1|M1
51StR+
PMl5pj
^LgG8?H
^LgG8?I1
?`R5H'Z
D$$=~0
T$85nq{-A
fffff.
D$4=}Z
D$$=uB
5SURj1
fffff.
"0s[D1
ffffff.
fffff.
D$$=ua
V5$sM1
ffffff.
ffffff.
fffff.
ffffff.
fffff.
D$4=Gw}6
ffffff.
D$$=huV
ffffff.
ffffff.
@(#rA!
fffff.
D$ =o5#
v] n5v] nA
5XOxWD
fffff.
fffff.
L$7=!c
ffffff.
L$7=c .o
GB;kz?L1
h-r`k+
)=jL1
Cn5P-~
D$$=i!
ffffff.
zf{'L1
<)X0L1
5LOni1
5~f<{!
fffff.
rX03D1
y|[-Fp
-R'1E1
fffff.
>/h[D1
g0%m]&[
tWc4L1
6"-EEx?
L$@=l:
Aic9(<
yjZ8/XI
P zXD!
=sB"T
ffffff.
Rg*hE!
:c3\/I
:c3\/M1
fffff.
D$,=b3
UAVVWSH
e [_^A^]
L$w=KKE
vSZ{rM1
4B)#\I
5HVw^A
HVw^D!
]~mWL1
D$ /5C
5|!m*1
V>KVNsV
>KVNsV
503Ru)
sd}Q5wd}Q
L$HH;B
L$HH;B
Mk>1A1
L$ H#J(H
Of5'Lf
.W|(D1
D$$=|zO
-r^P%=
D$@=K&7
hJ2'H1
F@T^D1
fffff.
D$D=c4
zbqtq#
zbqtq#
pdf54gf
wf5Fwf
+2MIaI
+2MIaL1
fffff.
fffff.
T>f5l?f
>@]aA1
ffffff.
[_#@D1
m0f5 1f
D$8HcH
6"-EEx?
6"-EEx?
UAWAVAUATVWSH
OKPuH1
zbqtq#
LrzCmY
vseaH1
Ou.X=I
Ou.X=L1
%jD&mi
[_^A\A]A^A_]
fffff.
fffff.
ffffff.
C->UX7
fffff.
fffff.
"*f5U)f
ffffff.
vSZ{rM1
vSZ{rM
_ve-gLs,
fffff.
.@o\HmhM1
fffff.
3}1cQd
3}1cQd
Mr}lM1
1^tjaH1
RAdOrn
RAdOrn
T=CN <
CU'sSL1
UAWAVAUATVWSH
^ds.H1
&j_UE1
|Z$]9
|Z$]9
G'e50|
D$ W\3
[M6bkH
%cs9,=X
[_^A\A]A^A_]
s}F.8c
rH&EH1
UAVVWSH
JxPAD1
=T}PO
b-4?qt
[_^A^]
W /]I1
k4EDM1
ffffff.
\E=F5fu
U!M|II1
uQ{3d!
uQ{3d!
lS_;D1
fffff.
!fG]-)
-!fG]=zw
DwFzD1
H~>FD1
ffffff.
Aic9D1
L$M=FU
ffffff.
j+'AH1
z\s2HH
8Q\s2HH1
*WrH)
wjItI1
L$8=/y
D$4=$Xe:
[ey5NI
M`=rwk"
52crSA1
D$ "t#a
fffff.
ffffff.
(znn'H1
Wf5@Sf
5{@CI1
03f5I1f
=FrWb
1=e4>o
1=e4>o
ffffff.
9f5m=f
L$/=,Y!
+2MIaH
+2MIaH1
K>UX7I
K>UX7L1
-r^P%=
\E=F5fu
%m]&[-
) >&D1
>/h[A1
AWAVVWUSH
52MIa=;
T$hH;AhH
T$@H;AxH
[]_^A^A_
D$ '*J7
r)oD!
5""80A
x|XdyI
x|XdyL1
*}5kmQ
%jD&m=U
DkH^qb
DkH^qb
H,K_E1
[ey5NH
[ey5NH1
5Y/X,1
7fFEI1
e%5+D)
L$G="^
L$W=>'b;
Mk>1A1
L$W=Gr
bd&%phL1
UAWAVAUATVWSH
5jPq`)
D$ '*J7
6"-EEx?
4"-EEx?
A+xZBI
[_^A\A]A^A_]
H!dDH1
4B)#\I
ZLr+NH
ZLr+NH1
z\s2HI
F2!!D1
[SFFw7
[SFFw7
i5]sNc1
7-`=2R
~kDJA!
9jmXE8
A<`S>MdH
A<`S>MdH1
7M\BH1
><LK=u
5k>h8+
D%+xZB
Ogr+A!
L$/=#
L$W=>'b;
+2MIaH
+2MIaH1
ffffff.
S%ka$6=
WRW5JT8d!
ffffff.
fffff.
z.8wD1
UAWAVVWSH
+2MIaH
+2MIaI1
N@4*H)
[_^A^A_]
Q`/EWr
fffff.
I5mpe#1
gLs,5RX
56"-E1
L$8H9Q
L$ H;A
:=nwL9
ffffff.
UAWAVAUATVWSH
-z;[_=
5ZG'vA)
N7lsH1
Ou.X=H
Ou.X=H1
[_^A\A]A^A_]
D$$=ZJ
i=ju?Q
6"-EEx?
-haIE=M
<p5V9|
N7lsI1
>2<EE1
fffff.
MX=&0.
[\R:A1
l$ j0X
+Rxd5I
+Rxd5M1
-haIE=M
@qSxAM1
RstvL1
EPHcRPH
@Nib,L1
zbqtq#
fffff.
bJ}GI1
f)S_H1
L$XH;B
j>X@P9uH
j>X@P9uH1
{'z,I
{'z,L1
g~[oD1
vSZ{rL!
vSZ{rM1
vSZ{rM!
L$G=4{'
ffffff.
<r6D1
UAWAVAUATVWS
53y{ A1
f1h5J%M
]}=O|T:
,DKD!
[_^A\A]A^A_]
5Z]V-m
0+BFk0J
L$HHcT$x
[d&vH1
|*`.59'
UAWAVAUATVWSH
HZ5x(<h
LflDA1
=}DCt
;zW;E!
[_^A\A]A^A_]
UAWAVAUATVWSH
*5?u<~
JJ([=d
5QGL1A
[_^A\A]A^A_]
-8D',1
UAWAVATVWSH
34MbA!
-)n0D1
x_3=87
clgcD1
[_^A\A^A_]
ffffff.
ffffff.
~|sbD1
ffffff.
D$X=@A
ffffff.
ffffff.
ffffff.
ffffff.
zVf5fRf
c'w"E1
F2!!A1
%5D|0D!
5D|0D!
_Uu{L1
UAWAVAUATVWS
pyc5un
^$=%n
8#woI
[_^A\A]A^A_]
g-w5]*
5>~1-A1
V5sR{HA
L$o=?,
->UX75
F` k,
UAWAVAUATVWS
*w]NE!
F&M"D1
vZqsD!
Q-g>D1
q/0{D1
g05=H1
5>G?vA
[_^A\A]A^A_]
ffffff.
fffff.
D$$=9@_L
UAWAVAUATVWS
4f5s=f
_f5,Xf
Ba(wH1
J6f5L0f
K%p5ny
Yf5n^f
]~mWH1
DkH^qb
DkH^qb
H,K_D1
Y/XS%`
bC4OI1
[_^A\A]A^A_]
&+8#D!
fffff.
L$/=*U
fffff.
9j L1
L$?=CZ
hS8^D1
UAVVWSH
[_^A^]
yjZ8/XI
dmZKD!
UAVVWSH
@9[~D1
5 oU`D
[_^A^]
ffffff.
bzY`D1
Q|D-L1
zbqtq#
M0H;A(
L$HH9H
^%N&[8=l\
Gm_oD1
/8s+yV
/8s+yV
z}O%7L1
fffff.
L$0=v!
%,v<$0
S%ka$6=
ffffff.
f`1pI1
n%\-hv
T$h-8V7{L
Cf5EEf
]~mWL1
-#GJ7)
8=]UD1
^M{87|I
+?5{M+C
D)*5=/
M/=!<r
ffffff.
fffff.
L$O=15&
N@4*L1
w*.UAsM1
L$7=Gr
L$8H;B
L$8H;B
L$7=F5fu
uQ{3d!
uQ{3d!
ffffff.
xHB0D1
n:@6A!
5@'zvE
ffffff.
%NcTH1
Ig@>T{I
Ig@>T;L1
-E~mlA
5.JW[A1
56dD8A
5}S1qA1
6=i!I#
NJLFH1
Rf5"Yf
=#|}3
%"`h?%0
wI<IR n
hS8^E1
00=5D1
g0%m]&[H
pzc9E1
=CCG u
m]&[Zi
+Wr`7
w:`+jJ
+bJ'jQ
8i \gF
]'RPL/
RobP=x
cA?{VH^UW
:(Zg}a
Q3M%z`
fGhaIE
g)X:NY
n7^=~/
%JxU":C_
Gq\'yyC
8F& |oh
$=^vh+
O@4*ZZ
b::B't
,HLOni'4
f.f?,\>m
1Q)eAuLy
6g<Z8/X&
m|i=P
L@dS)q"
!53FO6)
g'Y~P@
>G/^7C
yKl=:X
=Z'p -9
?Y_=sT
9{oiD2
`2MIa9
TOJ>Bo
+>UX7_
E~ml""80V
OGRxd5
DO@4*h
""80Qfu
ZBL<eMh&
d[+wo
+@j9]b
t;+%f.0z(
N.=J/^+z-
juA\n{
(k&NW.
~jI$?"
m]&[Zi
i-yl6B
ItkE!7
GH0%!g
X!)ZW
SZ{rMr
fE~ml""80
92>]ft
C=j""
jLlp2%
vZqsXu
&+8# )
('vM1t
FQMmr7
tR+r^P%^
}-VAkS
A5\v[Q
""80"t
Pzr^P%
a,6LOni
0l=$7s~s,
u1@523
2AL6;W
LqHKy/
E~ml""80
6i)(S>
a,6LOni
MkFtLm
%~dmq[
E~ml]ELUV
Qz+Wr
C=j""
WFeMh&
'p c<'
$=^vhnGC
Pzr^P%
oiD2NW.
Z6;}P/
Qz+Wr4
CMsvZqsk
W"p@e7
&bP[-0]
"wsea
bITdvV
<mV$:^f5ku
V|*W65"
X=N7ls.
;0_EL%
@#!8sO
M4_Q n
InitializeCriticalSection
InitializeConditionVariable
EnterCriticalSection
LeaveCriticalSection
WakeConditionVariable
SleepConditionVariableCS
@kernel32
@kernel32
CreateThread
WaitForSingleObject
@kernel32
@kernel32
VirtualAlloc
@kernel32
@kernel32
ExitProcess
@kernel32
@0123456789ABCDEF
9`bdfhjlnpr
(8^~o2
MaF^~+P~
"Oc91Z
^j\`@P
@b`\`v@
^jfn\fl@P
^pr\`\hfpr\bbh@
^jfn\fl.
^j\`@P
^l`j\b\bj@P
^bl\f@
^l`j\b\bj
9`bdfhjlnpr
JGxdTM
^j\`@P
^l`j\b\bj@P
^bn\h@
^l`j\b\bj
9`bdfhjlnpr
RtlCaptureContext
@ntdll
@ntdll
GetProcAddress
LoadLibraryA
CloseHandle
GetProcessHeap
SetErrorMode
GetDriveTypeW
VirtualAlloc
VirtualFree
@kernel32
@kernel32
ShellExecuteW
@shell32
@shell32
GetSystemInfo
@kernel32
@kernel32
VirtualProtect
@kernel32
@kernel32
@locale
@Zveyjb8Ym8dxoQx
GetModuleFileNameW
CreateFileW
@kernel32
@kernel32
GetModuleHandleA
HeapCreate
HeapAlloc
VirtualQuery
CreateEventW
CreateTimerQueue
CreateTimerQueueTimer
WaitForSingleObject
VirtualProtect
SetEvent
DeleteTimerQueue
HeapDestroy
@ntdll
@NtContinue
@advapi32
@SystemFunction032
@kernel32
@CopyMemory
@kernel32
RegQueryMultipleValuesA
RegQueryMultipleValuesW
RegQueryValueA
DeleteCriticalSection
EnterCriticalSection
GetCommandLineA
GetLastError
GetProcAddress
GetStartupInfoA
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryA
SetUnhandledExceptionFilter
TlsAlloc
TlsGetValue
TlsSetValue
VirtualAlloc
VirtualFree
VirtualProtect
VirtualQuery
__C_specific_handler
__initenv
__set_app_type
__setusermatherr
_acmdln
_commode
_fmode
_initterm
_ismbblead
_onexit
calloc
memcpy
memset
strncmp
ADVAPI32.dll
KERNEL32.dll
msvcrt.dll
#+3;CScs
VS_VERSION_INFO
StringFileInfo
040904E4
VarFileInfo
Translation
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.SleepObf.4!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win64.Qakbot.th
ALYac Trojan.GenericKD.73963949
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win64.Kryptik.Vyf6
K7AntiVirus Clean
Alibaba Trojan:Win64/SleepObf.9116279d
K7GW Trojan ( 005b86ea1 )
Cybereason Clean
huorong Trojan/W64.Agent.bx
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win64/Kryptik.EMS
APEX Malicious
Avast Win64:CrypterX-gen [Trj]
Cynet Malicious (score: 99)
Kaspersky Trojan.Win64.SleepObf.il
BitDefender Trojan.GenericKD.73963949
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Kryptik.2076672
MicroWorld-eScan Trojan.GenericKD.73963949
Tencent Win64.Trojan.Sleepobf.Bdhl
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Trojan.TR/Kryptik.gnqru
DrWeb Clean
VIPRE Trojan.GenericKD.73963949
TrendMicro Clean
McAfeeD ti!33083EE177BD
Trapmine suspicious.low.ml.score
FireEye Generic.mg.478124644da5f82d
Emsisoft Trojan.GenericKD.73963949 (B)
Ikarus Win32.Outbreak
GData Trojan.GenericKD.73963949
Jiangmin Clean
Webroot W32.Trojan.GenKD
Varist Clean
Avira TR/Kryptik.gnqru
Antiy-AVL Clean
Kingsoft malware.kb.a.868
Gridinsoft Ransom.Win64.Wacatac.sa
Xcitium Clean
Arcabit Trojan.Generic.D46899AD
SUPERAntiSpyware Clean
ZoneAlarm Trojan.Win64.SleepObf.il
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Trojan/Win.Generic.R664519
Acronis Clean
McAfee Artemis!478124644DA5
MAX malware (ai score=81)
VBA32 Clean
Malwarebytes Trojan.ShellCode
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!8.8 (CLOUD)
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet W64/Kryptik.EMS!tr
BitDefenderTheta Clean
AVG Win64:CrypterX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_90% (D)
alibabacloud Trojan:Win/Wacatac.B9nj
No IRMA results available.