Static | ZeroBOX

PE Compile Time

2012-12-21 04:14:11

PE Imphash

318cc6baf22de5640b5a89a3bd3b774c

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00008e1a 0x00009000 6.47830709202
.rdata 0x0000a000 0x000024aa 0x00002600 4.71712241168
.data 0x0000d000 0x00002c90 0x00001000 2.10314252212
.reloc 0x00010000 0x00000d10 0x00000e00 4.48703419295

Imports

Library ADVAPI32.dll:
0x40a000 RegSetValueExW
0x40a004 RegCloseKey
0x40a008 RegCreateKeyExW
Library KERNEL32.dll:
0x40a010 GetCommandLineA
0x40a014 HeapSetInformation
0x40a018 TerminateProcess
0x40a01c GetCurrentProcess
0x40a028 IsDebuggerPresent
0x40a02c GetLastError
0x40a030 HeapFree
0x40a034 CloseHandle
0x40a038 EncodePointer
0x40a03c DecodePointer
0x40a04c RtlUnwind
0x40a050 GetProcAddress
0x40a054 GetModuleHandleW
0x40a058 ExitProcess
0x40a05c WriteFile
0x40a060 GetStdHandle
0x40a064 GetModuleFileNameW
0x40a068 GetModuleFileNameA
0x40a070 WideCharToMultiByte
0x40a078 SetHandleCount
0x40a07c GetFileType
0x40a080 GetStartupInfoW
0x40a088 TlsAlloc
0x40a08c TlsGetValue
0x40a090 TlsSetValue
0x40a094 TlsFree
0x40a09c SetLastError
0x40a0a0 GetCurrentThreadId
0x40a0a8 HeapCreate
0x40a0b0 GetTickCount
0x40a0b4 GetCurrentProcessId
0x40a0bc SetStdHandle
0x40a0c0 GetConsoleCP
0x40a0c4 GetConsoleMode
0x40a0c8 FlushFileBuffers
0x40a0cc Sleep
0x40a0d0 CreateFileA
0x40a0d4 GetCPInfo
0x40a0d8 GetACP
0x40a0dc GetOEMCP
0x40a0e0 IsValidCodePage
0x40a0e4 MultiByteToWideChar
0x40a0e8 LoadLibraryW
0x40a0ec WriteConsoleW
0x40a0f0 SetFilePointer
0x40a0f8 HeapAlloc
0x40a0fc HeapReAlloc
0x40a100 SetEndOfFile
0x40a104 GetProcessHeap
0x40a108 ReadFile
0x40a10c LCMapStringW
0x40a110 GetStringTypeW
0x40a114 HeapSize
0x40a118 CreateFileW

!This program cannot be run in DOS mode.
!RichI
.rdata
.reloc
<at,<rt"<wt
URPQQhp#@
^SSSSS
j@j ^V
tCHt(Ht
;t$,v-
UQPXY]Y[
t"SS9] u
PPPPPPPP
PPPPPPPP
UTF-16LE
UNICODE
CorExitProcess
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
(null)
`h````
xpxxxx
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
`h`hhh
xppwpp
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
C:\KeyOpenFailed.txt
C:\KeyValueFailed.txt
RegCreateKeyExW
RegSetValueExW
RegCloseKey
ADVAPI32.dll
GetCommandLineA
HeapSetInformation
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
GetLastError
HeapFree
CloseHandle
EncodePointer
DecodePointer
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionAndSpinCount
RtlUnwind
GetProcAddress
GetModuleHandleW
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameW
GetModuleFileNameA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
GetStartupInfoW
DeleteCriticalSection
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
HeapCreate
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
SetStdHandle
GetConsoleCP
GetConsoleMode
FlushFileBuffers
CreateFileA
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
MultiByteToWideChar
LoadLibraryW
WriteConsoleW
SetFilePointer
IsProcessorFeaturePresent
HeapAlloc
HeapReAlloc
SetEndOfFile
GetProcessHeap
ReadFile
LCMapStringW
GetStringTypeW
HeapSize
CreateFileW
KERNEL32.dll
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
0,050:0J0h0o0x0}0
1&2~2)3N3[3h3t3
4;4@4G4M4
5!5)555>5C5I5S5\5g5s5x5
6J6T6l6
9I9[9;:E:R:
;&;9;f;l;
<#<1<F<P<v<
2F2W2d2k2{2
4,545I5T5
=E=g=7?
2%2+242;2]2
3:3D3Z3e3
3"4)4C4J4u4
<<9<_<e<
<7=A=l=
>6>Y>_>s>x>
?"?.?4?A?K?Q?[?}?
0*00060L0d0
1'111i1q1
22(24292>2D2H2N2S2Y2^2m2
3<3H3X3{3
4$5L5e5
6"6+6k6}6
00r0y0
1&191]1
3N3W3c3|3
8-8?8R8d8
<:<D<[<
22(2i2
5%535<5F5z5
5 6U6h6
7A8M8`8r8
9<9e9v9
;*<D<U<
=I>O>U>e>p>
0(1_1e1j1x1}1
2 2Z2_2f2k2r2w2
3R4W4`4o4
5/5:5@5P5U5f5n5t5~5
6*6D6F8M8S8@9M9l9
;&<,<;<
<6=<=H=
2N3[304:4
4F5S5s5
:x;c?u?
0+0=0O0a0s0
56=6D6H6L6P6T6X6\6`6
6"7-7H7O7T7X7\7}7
7F8L8P8T8X8
,1014181<1H1L1`1d14:<:D:L:T:\:d:l:t:|:
;8;X;t;x;
< <,<H<T<p<
=4=8=X=x=
; ;$;(;,;0;4;8;<;@;D;H;L;P;`;d;h;l;p;t;x;|;
=(>,>0>4>8><>@>D>H>L>X>\>`>d>h>l>p>t>x>|>
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
@Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
KERNEL32.DLL
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
n(null)
WUSER32.DLL
((((( H
h(((( H
H
CONOUT$
Software\PaloAlto
Error Creating and opening key
PanCar
Error writing key
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Bebloh.4!c
Elastic malicious (high confidence)
ClamAV Win.Dropper.Bebloh-9954185-0
CMC Clean
CAT-QuickHeal Trojan.WacatacRI.S12026051
Skyhigh BehavesLike.Win32.Backdoor.qh
ALYac Clean
Cylance Unsafe
Zillya Exploit.CVE20200601.Win32.65
Sangfor Trojan.Win32.Agent.V8ox
CrowdStrike win/grayware_confidence_60% (W)
Alibaba Backdoor:Win32/AutoG.79b86c60
K7GW Riskware ( 0040eff71 )
K7AntiVirus Riskware ( 0040eff71 )
huorong Clean
Baidu Clean
VirIT Backdoor.Win32.Bebloh.OL
Paloalto generic.ml
Symantec Trojan.Gen.MBT
tehtris Clean
ESET-NOD32 a variant of Generik.CIIVOGM
APEX Malicious
Avast FileRepMalware [Misc]
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan.Win32.Agent.gen
BitDefender Clean
NANO-Antivirus Trojan.Win32.Bebloh.gdorjf
ViRobot Clean
MicroWorld-eScan Clean
Tencent Malware.Win32.Gencirc.10bde52a
Sophos Troj/AutoG-JY
F-Secure PrivacyRisk.SPR/PanCar.A
DrWeb BackDoor.Bebloh.375
VIPRE Clean
TrendMicro Clean
McAfeeD ti!2F8EB904D39E
Trapmine suspicious.low.ml.score
CTX exe.trojan.bebloh
Emsisoft Clean
Ikarus Trojan.Win32.Agent
FireEye Clean
Jiangmin Exploit.Multi.ar
Webroot Clean
Varist W32/S-05d94ade!Eldorado
Avira SPR/PanCar.A
Fortinet Riskware/WildFireTestFile
Antiy-AVL Trojan/Win32.BTSGeneric
Kingsoft Win32.Trojan.Agent.gen
Gridinsoft Trojan.Win32.Gen.vb!s1
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Trojan.Agent/Gen-Crypt
ZoneAlarm HEUR:Trojan.Win32.Agent.gen
Microsoft Trojan:Win32/Ditertag.A
Google Detected
AhnLab-V3 Trojan/Win.Generic.C4496711
Acronis Clean
VBA32 Backdoor.Bebloh
TACHYON Trojan/W32.Agent.55296.ALN
Malwarebytes Exploit.CVE20200601
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Agent!8.B1E (CLOUD)
Yandex Trojan.Agent!q5HLRo863dA
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.117761720.susgen
GData Win32.Riskware.PanCar.A
AVG FileRepMalware [Misc]
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.