Static | ZeroBOX

PE Compile Time

2020-06-09 09:17:28

PE Imphash

17b461a082950fc6332228572138b80c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000020f0 0x00002200 6.03397581892
.data 0x00004000 0x00042490 0x00042600 7.21629504867
.rdata 0x00047000 0x000002d0 0x00000400 4.00037373567
.pdata 0x00048000 0x0000027c 0x00000400 2.97342307908
.xdata 0x00049000 0x00000238 0x00000400 2.65379684452
.bss 0x0004a000 0x00000a30 0x00000000 0.0
.idata 0x0004b000 0x00000958 0x00000a00 4.1419693576
.CRT 0x0004c000 0x00000068 0x00000200 0.256446748701
.tls 0x0004d000 0x00000048 0x00000200 0.217769955458

Imports

Library KERNEL32.dll:
0x44b244 CloseHandle
0x44b24c ConnectNamedPipe
0x44b254 CreateFileA
0x44b25c CreateNamedPipeA
0x44b264 CreateThread
0x44b27c GetCurrentProcess
0x44b284 GetCurrentProcessId
0x44b28c GetCurrentThreadId
0x44b294 GetLastError
0x44b29c GetModuleHandleA
0x44b2a4 GetProcAddress
0x44b2ac GetStartupInfoA
0x44b2bc GetTickCount
0x44b2d4 LoadLibraryW
0x44b2e4 ReadFile
0x44b2ec RtlAddFunctionTable
0x44b2f4 RtlCaptureContext
0x44b304 RtlVirtualUnwind
0x44b314 Sleep
0x44b31c TerminateProcess
0x44b324 TlsGetValue
0x44b334 VirtualAlloc
0x44b33c VirtualProtect
0x44b344 VirtualQuery
0x44b34c WriteFile
Library msvcrt.dll:
0x44b364 __dllonexit
0x44b36c __getmainargs
0x44b374 __initenv
0x44b37c __iob_func
0x44b384 __lconv_init
0x44b38c __set_app_type
0x44b394 __setusermatherr
0x44b39c _acmdln
0x44b3a4 _amsg_exit
0x44b3ac _cexit
0x44b3b4 _fmode
0x44b3bc _initterm
0x44b3c4 _lock
0x44b3cc _onexit
0x44b3d4 _unlock
0x44b3dc abort
0x44b3e4 calloc
0x44b3ec exit
0x44b3f4 fprintf
0x44b3fc free
0x44b404 fwrite
0x44b40c malloc
0x44b414 memcpy
0x44b41c signal
0x44b424 sprintf
0x44b42c strlen
0x44b434 strncmp
0x44b43c vfprintf

!This program cannot be run in DOS mode.
P`.data
.rdata
P@.pdata
0@.xdata
0@.bss
.idata
ffffff.
ATUWVSH
[^_]A\
ATUWVSH
@[^_]A\
ATUWVSH
[^_]A\
ATUWVSH
@[^_]A\
ffffff.
AUATUWVSH
[^_]A\A]
[^_]A\A]
[^_]A\A]
ATWVSH
[^_A\]
ATUWVSH
@[^_]A\
L3d$0H
@[^_]A\
([^_]H
gyHDdy
gy:hey
8)=av^
hNeyc.
01k2G0c.
h,x)<c
zk<X;b
)9c1)6e
0ko1a
01k2G1c/T
g8Rngy
01k2G1c/T
cyU^gy
g1)9`;c
01k2G1c/T
01k2G1c'T
UiJ:!r
lX^cym
8c%&Z?
8cd4
=c(&Z:
8c&Z*
aJ U"e)
&z(Wc]c
CJ U"M
&z0W;]
g5eBC)
/0c=&&
`8k$fv|
g1)>`1k
J3Wf0c
Fh'Wvm
.z!W:I
cyc.&B
.z<!r(
01k2G0c./
=c/z?5
<c"B;
gk'cvo
fk'kvf^gy
5N8i'gy
5L8i$gx
1c'&B;
5L8i$gx
gyk7evl+gy
gy+fey
gy+fny
gy+f`y
W.qk'Gvk{gy
gyh'JvlUgy
xk&dvorgy
8)7e8c
v|&z)
5t8i$gy
1c'&B;
k&fvoLgy
WpJ(5b
gvongy
01k2'1c
0kcz-W`
01k2G1c,
01k2'8k
#5vJ([
k<`z*
01k2G1c
8k'Yvo^gy
1k7c1e
l&Z(Wa
cJ(5b8c
vk&fvl
xc)'v}
S{n)%c
01k2G1c
01k2GJ3
nR+Wf=
)5x1kc0
_0c=&&
5c.B#
G1c'^(
o1)6{1
2Uv1c'
k<f<m:
01k2G=c
_0c=&&
!h0)1{8a
Z_vm@gy
4 5!5e
01k2'1c$
w0)>{;c
01k2'1c'/
01k2'1c'/
!h0)6{
Un0c6/
01k2G1c
n1cEo9
1c+R)
gvn2fy
eyR^gy
eyR^gy
01k2G1c/
ifk6ck&b
01k2G1c
01k2G1c/
lh(fyc
41k2G1c
'Yhwdy
/fyQ*fy
01k2'1c'
kgykzC
gvm\gy
J(531c
Ui5e[?}
g1cBC1
UnJ:!r
gJ(5q1c
J!!r$8
W0c=&&
1c4"J(
jR*T+a
w8c%-B
jR*T+a
w8c%-B
'0c=&&
v4x6An
'0c=&&
'8P^gy
OJ:W+]
gJ:S-}
9$+ffy
01k2G1c/
01k2G1c
t8jfyc
W0c=&&
S,Rc6\
cJ(5&1e
l\wfyk&
|Hrfy/]
01k2'8c./
01k2G1c$/
oJ:!rXM
`J(7Hx
'1)9b;/
W&+ffy
01k2G8c
lHGfym
lHEfyQ
l,Dfyk&
01k2G8c
cJ(5r1c
cJ(5~1c
01k2G1
ikVk5a=c.
g1eSz
lv_^:
CIR^gy
G&+dey
lL[fyk
g5eBC)
/0c=&&
h5)W$]
_0c=&&
gvludy
gyk'ivo,gy
gyk7xvlkgy
!"J!5a8Q
gvlNfy
gyk7PvlAgy
!"J(5a8P
gyig}
01k270c&/
gvlHfy
ig)6kk>hv_
gy$gfy
_0c=&&
7"+gfy
01i2Wx
01i2Wx
01i2'x
01i2Gx
g5eBCY
h4'Wjp@
J!WrdO
'0c=&&
gJ:gg}
"J(dgy
g1eRCY
5eBC)l
O0c=&'
01k2W8c./
g1)?b1a
1)9b5a
g<m(h<)
01k2GJ
01k2G1c
e8R!hy
Wv1ko0
w1k'1a
1k27J3
m0k6ea
0)7bvm
h1k7ec
m0k6ea
01k2G1c$/
01k2G1c
vvl=gy
Ue0k6o
ovlUgy
Wv1ko
01k2G1c
g8h"fvm8gy
k?`1)6d
01k2G1c
`J(7Px
01k2G0c&
gyk'i8
gyQ!gy
'9`jCJ
g1cRC9
g5eBC)
_0c=&&
gvJWc]a
gvJWc]a
01k2G1c
wvlWgy
W$qm3
S!{k&f
du*5`1e
S&{k&f
TX8c,#
gyk'vm
A8ebC$
5a8T}gy
t8h!Wvm
!"J:5e
S&{k&f
TX8c,#
pH+ey)4c
gyk'vm
A8ebC$
5a8T}gy
t8h!Wvm
dh.fyc1/
01k2GJ
T|$'fy
T|x'fy
T|4&fy
T|H&fy
T|X)fy
g1c&.R
g1c..B/
c1aXG{
+R'(ex
S'Yk&~
t@0fymV
CYi$fx
S$cQ gy
01k2G1c
qJ:6Iy
gyxgky
1) b5e
05eJ3U
01k2WJ3S,x
.z5^\Y
ok'avm
5ivR9k
.z5^\Y
w0/G|{
eyk=x1
gyc%&R
l,igym
g9h evm
01k2G1c'/
01k2G0c
01k2G<c.+
/vlCgy
<4Ssya
fvmdfy
/z05:2cZ
vgyk&b
eyk=x1
01k2G1
|k?x1c
eyk=x1
01k2G1
01k2G1e
P1e]gr
ovm,gy
/z0^\y
lDHgyc
G1)>G1e
GJ(5H1m
01k271c
l@Ngyk&0vm
^DP{fy
01k2GJ
1//B+
})5eJ(
ckG8
g1i'g}
*z(6m/
01k2WJ
1) b5e
1) c1c
1) b5e
1)&b1e
#v^Zo`
6Z.5eJ([
\ttNfy
\t`Nfy
0k>x4c
gy(dgy
g1)&b<
fk&dvmRgy
&vR*x5e
k?x1)&b1
8k>x0)$b4
w1c\wx
gy)?or)gfy
gy)?wr)gfy
gr)gcy
gy)?or)gfy
gy)?wr)gfy
T}bgcy
eJ)gcy
gy)?or)gfy
gy)?wr)gfy
gr)gcy
eJ)gcy
T}bU+]
T}bgcy
td0gyc
CQ)4wv^
CQ)7ov^
CQ)7gv^
_1k6w1a
gy)?or)gfy
gy)?wr)gfy
gr)W#]
C})4wv^
Cq)4wv^
T}bgcy
J*Uk])7ov^
C})7gv^
tPqgyc
Ca)4wv^
Ce)4wv^
Ci)4wv^
C})6o\
Ci)7ov^
Cm)7gv^
T}bU+]
T}bgcy
Cu)6w\
gr)Wc]P
gr)W#]
gy)?or)gfy
Cq)7ov^
C})7gv^
Cq)4wv^
T}bgcy
T}bU+]
T}bgcy
Ce)7ov^
Ca)7gv^
Ci)7ov^
Ce)7gv^
Cm)7ov^
Ci)7gv^
l8ngyc
l\ngyc
!gJ)U+]
gJ)U+]
gJ)gcy
C})6w\
Cm)7wv^
Ci)7ov^
Ce)7gv^
l0sgyc
Cu)6o\
gy/ZC]
"J(Usx
gyibCQ
Ci)7gv^
1k2W1k
S1)?G1
S1)?G1
cvlJgy
Avl^gy
\L|Cfya
|4Bfym
01k2'1c
01k2W1c
01k2'1k
01k2W1c
^tDzfy
R05J=c
01k2W1k
`J(7lz
'1cNWx
5d5c-*
g1i'g}
5pR0fdy
h*X)>or)^
21k2G1c4/
21k2G1c4
21k2G1c4
21k2G1c4
21k2G1c4
21k2G1c4
21k2G1c4
gy4dy
gy*dy
gyBdy
gyzdy
gyhdy
gy>bdy
gybcdy
gyvcdy
gyBcdy
gy$cdy
gyn`dy
gy~`dy
gyL`dy
gy(`dy
gy8`dy
gylady
gy|ady
gyFady
gyVady
gy$ady
gy6ady
gy*bdy
gyFbdy
gyJbdy
gyfbdy
gy6edy
gy8edy
gyTedy
gyXedy
gyredy
gybedy
gyjedy
T wymm
@6mkqt:
^3<"<`
+5X6?!m
C]P:;%w
RLF'0.
goO*6)
[h/=pZg
'[.ZGh
m=d3L5
C4WJ~2
W[j&0@
6mkq+zpc wym
U8*?X1$4O*6)B#8"a
=pZg0yTl'bFq*kHz
<FQr'TLe.ZGh
)05pbG;{oN)fxU'mu\
JLqAAx
gyodfyydfyL
cfyncfy>
gyE&fy
gyn'fy
gy$@ey0@eyq
uey~ueyZ
ey~uey
gy"uey
gyxkdy
gy4dy
gy*dy
gyBdy
gyzdy
gyhdy
gy>bdy
gybcdy
gyvcdy
gyBcdy
gy$cdy
gyn`dy
gy~`dy
gyL`dy
gy(`dy
gy8`dy
gylady
gy|ady
gyFady
gyVady
gy$ady
gy6ady
gy*bdy
gyFbdy
gyJbdy
gyfbdy
gy6edy
gy8edy
gyTedy
gyXedy
gyredy
gybedy
gyjedy
>Yu{V}
gyI{gy
gyi gy
gyi gy
gyi gy
gyxqdyl
gylqdy
gyDqdyL
gy(qdy`
gy4qdy(
gy`}dy
gyxxdy
gyxxdy
gyxxdy$
gyxxdy
gypndy0
gyXndy
gyTndy
gy$ndy
gy4ndy
gyxxdy0
gyxxdyH
gy|ody
gyxqdy
gyXody
gy(odyh
gyxxdy
gy<ody8
gyxxdy
_gy4Edy
_gy)_gy
Edy,_gy
Ady(Zgy/[gy
}dy [gyCXgy
dyDXgy
Ygyxxdy
Wgy}Wgy
ldypWgy<Wgy
ldy<Wgy
Ugy:Ugy`ldy<Ugy
RgyvOgypldyHOgy
Mgy\ldy
MgygJgy
jdyxJgyFHgy0ldy
ldyXFgyIDgy
mdyLDgy;Dgyxxdy<Dgy
BgycBgy
EdydBgy
Cgyxxdy
mdyh|gy
mdy@vgy
wgyowgy
Ady`wgy
tgyxxdy
tgycogy
mdydogy
lgydmdy
lgyLkgyXmdyLkgy
hgy8mdy
egy>cgy
jdy0cgy(`gyXody(`gylagyxxdylagy=
gyxxdy
gyXodyhgy
gyXody<
gyhCdy
gyxxdy
gyxxdy0
gyxxdyX
gy@Edy|
gypEdy@
gyttdy
gyxxdyx
gyPEdy
gy8Edy
<gy4Edy
;gyPEdy
9gyY9gy
Ady\9gy:9gyl
dy<9gy
Bdyl6gy67gy
7gyQ4gy
BdyT4gy
5gy\Bdy
2gyj3gypBdyd3gy33gy
@dy43gy-0gy(Bdy 0gy
.gy0Bdy
-gy`}dy
-gyj*gy
Cdyl*gy
+gyXody
Edy$)gy
&gyxxdy
&gyN&gy
sdy@&gy
$gy(Cdy
%gyZ"gy
Cdy\"gy
#gyhCdy
#gyZ#gy(Cdy\#gy
!gyDCdy
fydCdy
fy Cdy
fyxxdy
fy0tdy
fyxxdy
fyt@dyL
fyxxdy
fy0@dy
fyP@dy0
fy0tdy$
fy<~dy
fy0@dy
fyxxdy
fyXodyL
fyxAdy
fy(AdyL
fyXAdyx
fyhCdyT
fyxxdy
fy8Ady<
fy(Ady
fyh~dy
fy|~dy
fyh~dy0
fy|~dy
fyL~dy@
fyP~dy
fyxxdy
fy<~dy
fyxxdy
fy4~dy
fy(odyd
fyPEdy
fyxxdy,
fyxxdyt
fyxxdy$
fyxxdy
fy(ody
fyxxdy
fyxxdy
fyTtdy
fy`}dyL
|dy@Xfy
Yfyx|dy
Yfy}Vfy
|dypVfy
Rfy3Rfy
Sfy`Sfy
dy`SfyPSfy
dyPSfy
Qfy$pdy
NfyONfyp|dy@Nfy
Ofyp|dy
OfyD|dyhOfy
Lfy(|dy
Mfy<|dy
MfyPMfy
HfyTtdy
IfyOIfyxxdy@Ify8Ifyxxdy
Ffyxxdy
FfyNFfy
|dy@Ffy
GfytGfy
}dytGfy#Gfyl
dy$Gfy
EfyxEfyl
dyxEfy
CfyfCfy
}dyxCfy
@fy0tdy
Afy0Afy
}dy0Afy
fyA|fy
}dyD|fy`}fy
Ady`}fy
zfy_zfyhCdyPzfy
xfy`}dy
xfyxxdypxfy
Edytyfy1yfyH}dy4yfyzvfy
Ady|vfy
tfy@}dyxtfyrufyP}dytufy
rfyT}dy
sfyNsfy<~dy@sfyVsfy
dy0sfy
pfy(odyhpfy
mfy8}dy
jfy<}dy
jfyYjfy
Edy\jfy"jfy
Edy$jfy
hfyxxdy
hfyxxdy
ifyoify
}dy`ify)ifyxxdy4ify
}dyhgfyCgfyl
dyDgfy*gfy
Edy,gfy
dfyxxdy
dfyNdfy
zdy@dfy
zdydefy
cfy\zdy
cfyCcfy`zdyDcfyi`fy
EdyH`fy
fy8zdy
fy0zdy
fy$wdy
fyh{dyH
fyl{dy
fyp{dy
fyP{dy
fyxxdy8
fy0tdy
fy@<fy
xdy@<fy
<fyl=fy
dyl=fyQ3fy
xdyT3fy
.fy\.fyxxdy\.fy
.fyxxdy
/fyxxdy
/fy_/fy
pdyP/fy
,fytxdy
,fy;,fy
-fy,xdy
-fy%-fy8xdy
*fyd*fy
Edyd*fy
EdyH&fy
&fy4xdy
$fyo$fyl
dy`$fy
%fyk%fy
~dyl%fy
"fye"fy
dyx"fy!"fyxxdy$"fy
eyHydyl
ey8ydy
eyxxdy
eyxxdy
eyxxdy
eytvdy
ey4vdy
eylwdyp
ey\wdy
ey$wdy
eyLtdy
eyttdyL
eyDtdy
eyTtdy
ey0tdy
eyxxdy,
eyxxdyp
eyxudy
eyxudy
eyXudy
eyHudyx
ey0udy
ey@rdyh
ey8rdy
eyxudy
ey$pdy
eyLtdyT
eyXody
eyH}dy
Yeyhsdy
YeyONey`sdyXNeymDeyxsdyxDey+Ceypsdy8Cey0CeyDsdy
@ey\sdy
@eyB@eyTsdyP@ey
@ey,sdy
|ey/|ey
pdy |ey
}ey(xey
pdy(xey}tey
pdyHtey
ueyXody
ueyHuey
pdyHuey
uey&rey
pdy8rey
qeylpdy
qeytqey
}dytqeyfneyLpdypney
oey\pdypoey
leyJleyl
dyLley<mey$pdy<mey
key`}dy
key9key
pdy<key
geymbey
pdy`bey`cey
qdy`cey8
ey`}dy
_set_invalid_parameter_handler
%c%c%c%c%c%c%c%c%cMSSE-%d-server
.pdata
Argument domain error (DOMAIN)
Argument singularity (SIGN)
Overflow range error (OVERFLOW)
Partial loss of significance (PLOSS)
Total loss of significance (TLOSS)
The result is too small to be represented (UNDERFLOW)
Unknown error
_matherr(): %s in %s(%g, %g) (retval=%g)
Mingw-w64 runtime failure:
Address %p has no image-section
VirtualQuery failed for %d bytes at address %p
VirtualProtect failed with code 0x%x
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
CloseHandle
ConnectNamedPipe
CreateFileA
CreateNamedPipeA
CreateThread
DeleteCriticalSection
EnterCriticalSection
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetLastError
GetModuleHandleA
GetProcAddress
GetStartupInfoA
GetSystemTimeAsFileTime
GetTickCount
InitializeCriticalSection
LeaveCriticalSection
LoadLibraryW
QueryPerformanceCounter
ReadFile
RtlAddFunctionTable
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
SetUnhandledExceptionFilter
TerminateProcess
TlsGetValue
UnhandledExceptionFilter
VirtualAlloc
VirtualProtect
VirtualQuery
WriteFile
__C_specific_handler
__dllonexit
__getmainargs
__initenv
__iob_func
__lconv_init
__set_app_type
__setusermatherr
_acmdln
_amsg_exit
_cexit
_fmode
_initterm
_onexit
_unlock
calloc
fprintf
fwrite
malloc
memcpy
signal
sprintf
strlen
strncmp
vfprintf
KERNEL32.dll
msvcrt.dll
msvcrt.dll
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.CobaltStrike.4!c
tehtris Clean
ClamAV Win.Trojan.CobaltStrike-9044898-1
CMC Clean
CAT-QuickHeal Trojan.CobaltStr.S17675256
Skyhigh BehavesLike.Win64.Dropper.dc
ALYac Gen:Variant.Zusy.476946
Cylance Unsafe
Zillya Trojan.CobaltStrike.Win64.11119
Sangfor Trojan.Win32.CobaltStrike
K7AntiVirus Trojan ( 0058fadf1 )
Alibaba Trojan:Win32/CozyDuke.1012
K7GW Trojan ( 0058fadf1 )
Cybereason malicious.5bd8a5
huorong Backdoor/CobaltStrike.d
Baidu Clean
VirIT Trojan.Win64.CbltStrkT.DZI
Paloalto generic.ml
Symantec Backdoor.Cobalt!gen1
Elastic Windows.Trojan.CobaltStrike
ESET-NOD32 a variant of Win64/CobaltStrike.Artifact.A
APEX Malicious
Avast Win64:HacktoolX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win64.CobaltStrike.gen
BitDefender Gen:Variant.Zusy.476946
NANO-Antivirus Trojan.Win64.CobaltStrike.kmqtdt
ViRobot Clean
MicroWorld-eScan Gen:Variant.Zusy.476946
Tencent Trojan.Win64.Cobaltstrike.za
TACHYON Trojan/W64.CobaltStrike.288256
Sophos ATK/Cobalt-CC
F-Secure Heuristic.HEUR/AGEN.1344219
DrWeb BackDoor.CobaltStrike.86
VIPRE Gen:Variant.Zusy.476946
TrendMicro Backdoor.Win64.COBEACON.SMA
McAfeeD ti!15020A16B307
Trapmine Clean
FireEye Generic.mg.7109c985bd8a5530
Emsisoft Trojan.CobaltStrike (A)
Ikarus Trojan.Win64.Cobaltstrike
GData Gen:Variant.Zusy.476946
Jiangmin Trojan.Generic.fsici
Webroot W32.Trojan.Cobalt
Varist W64/Agent.NDUI
Avira HEUR/AGEN.1344219
Antiy-AVL RiskWare/Win64.Artifact.a
Kingsoft malware.kb.a.1000
Gridinsoft Trojan.Win64.Agent.oa!s1
Xcitium Malware@#2o3mfb75gsbwb
Arcabit Trojan.Zusy.D74712
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Win64.CobaltStrike.gen
Microsoft Trojan:Win64/Bulz.SPVV!MTB
Google Detected
AhnLab-V3 Trojan/Win64.CobaltStrike.R356638
Acronis Clean
McAfee Trojan-FSXF!7109C985BD8A
MAX malware (ai score=87)
VBA32 Trojan.Win64.CobaltStrike
Malwarebytes CobaltStrike.Trojan.Infiltration.DDS
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Backdoor.Win64.COBEACON.SMA
Rising Backdoor.CobaltStrike/x64!1.D04A (CLASSIC)
Yandex Trojan.GenAsa!ZICJWVi3Ujg
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet W64/Agent.CY!tr
BitDefenderTheta Clean
AVG Win64:HacktoolX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Backdoor:Win/CobaltStrike.B
No IRMA results available.