Static | ZeroBOX

PE Compile Time

2024-10-21 15:49:21

PE Imphash

44cdc801a895c4cbaf14c1dd721f21ad

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000115a2 0x00011600 6.48546677247
.rdata 0x00013000 0x0000b2ca 0x0000b400 4.63093970587
.data 0x0001f000 0x00001d98 0x00000c00 2.04264317352
.pdata 0x00021000 0x00001254 0x00001400 4.64615851889
_RDATA 0x00023000 0x000000fc 0x00000200 1.99251114036
.detourc 0x00024000 0x000021c0 0x00002200 2.71851891571
.detourd 0x00027000 0x00000018 0x00000200 0.116115075305
.rsrc 0x00028000 0x000000f8 0x00000200 2.52201121083
.reloc 0x00029000 0x00000a94 0x00000c00 5.18007928683

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00028060 0x00000091 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x180013000 LoadLibraryA
0x180013008 GetProcAddress
0x180013010 FreeLibrary
0x180013018 Sleep
0x180013020 GetCurrentThread
0x180013028 VirtualFree
0x180013030 SetEvent
0x180013038 WaitForSingleObject
0x180013040 ResetEvent
0x180013048 CreateThread
0x180013050 CloseHandle
0x180013058 CreateFileA
0x180013060 GetFileSize
0x180013068 ReadFile
0x180013070 GetLastError
0x180013078 CreateEventW
0x180013088 GetModuleFileNameA
0x180013090 GetModuleHandleW
0x180013098 WriteConsoleW
0x1800130a0 HeapReAlloc
0x1800130a8 HeapSize
0x1800130b0 GetStringTypeW
0x1800130b8 FlushFileBuffers
0x1800130c0 SetStdHandle
0x1800130c8 QueryPerformanceCounter
0x1800130d0 GetCurrentProcessId
0x1800130d8 GetCurrentThreadId
0x1800130e0 GetSystemTimeAsFileTime
0x1800130e8 InitializeSListHead
0x1800130f0 RtlCaptureContext
0x1800130f8 RtlLookupFunctionEntry
0x180013100 RtlVirtualUnwind
0x180013108 IsDebuggerPresent
0x180013110 UnhandledExceptionFilter
0x180013120 GetStartupInfoW
0x180013130 VirtualProtect
0x180013138 GetCurrentProcess
0x180013140 VirtualAlloc
0x180013148 SuspendThread
0x180013150 ResumeThread
0x180013158 VirtualProtectEx
0x180013160 GetThreadContext
0x180013168 FlushInstructionCache
0x180013170 SetThreadContext
0x180013178 VirtualQuery
0x180013180 VirtualQueryEx
0x180013188 SetLastError
0x180013190 LoadLibraryExA
0x180013198 LoadLibraryExW
0x1800131a0 RtlUnwindEx
0x1800131a8 InterlockedFlushSList
0x1800131b0 RtlPcToFileHeader
0x1800131b8 RaiseException
0x1800131c0 EnterCriticalSection
0x1800131c8 LeaveCriticalSection
0x1800131d0 DeleteCriticalSection
0x1800131e0 TlsAlloc
0x1800131e8 TlsGetValue
0x1800131f0 TlsSetValue
0x1800131f8 TlsFree
0x180013200 EncodePointer
0x180013208 ExitProcess
0x180013210 TerminateProcess
0x180013218 GetModuleHandleExW
0x180013220 GetModuleFileNameW
0x180013228 GetConsoleMode
0x180013230 WriteFile
0x180013238 GetConsoleOutputCP
0x180013240 SetFilePointerEx
0x180013248 HeapFree
0x180013250 GetStdHandle
0x180013258 GetFileType
0x180013260 HeapAlloc
0x180013268 FindClose
0x180013270 FindFirstFileExW
0x180013278 FindNextFileW
0x180013280 IsValidCodePage
0x180013288 GetACP
0x180013290 GetOEMCP
0x180013298 GetCPInfo
0x1800132a0 GetCommandLineA
0x1800132a8 GetCommandLineW
0x1800132b0 MultiByteToWideChar
0x1800132b8 WideCharToMultiByte
0x1800132c0 GetEnvironmentStringsW
0x1800132c8 FreeEnvironmentStringsW
0x1800132d0 FlsAlloc
0x1800132d8 FlsGetValue
0x1800132e0 FlsSetValue
0x1800132e8 FlsFree
0x1800132f0 LCMapStringW
0x1800132f8 GetProcessHeap
0x180013300 CreateFileW
Library USER32.dll:
0x180013328 PeekMessageW
0x180013330 DispatchMessageW
0x180013338 TranslateMessage
Library SHLWAPI.dll:
0x180013310 PathRemoveFileSpecA
0x180013318 PathAppendA

Exports

Ordinal Address Name
1 0x1800027c0 HTMLayoutCallBehaviorMethod
2 0x1800027c0 HTMLayoutCreateElement
3 0x1800027c0 HTMLayoutDataReady
4 0x1800027c0 HTMLayoutGetAttributeByName
5 0x1800027c0 HTMLayoutGetChildrenCount
6 0x1800027c0 HTMLayoutGetElementHwnd
7 0x1800027c0 HTMLayoutGetElementIndex
8 0x1800027c0 HTMLayoutGetElementInnerTextCB
9 0x1800027c0 HTMLayoutGetElementLocation
10 0x1800027c0 HTMLayoutGetElementState
11 0x1800027c0 HTMLayoutGetNthChild
12 0x1800027c0 HTMLayoutGetParentElement
13 0x1800027c0 HTMLayoutGetRootElement
14 0x1800027c0 HTMLayoutGetStyleAttribute
15 0x1800027c0 HTMLayoutInsertElement
16 0x1800027c0 HTMLayoutLoadFile
17 0x1800027c0 HTMLayoutLoadHtmlEx
18 0x1800027c0 HTMLayoutPostEvent
19 0x1800027c0 HTMLayoutProcND
20 0x1800027c0 HTMLayoutScrollToView
21 0x1800027c0 HTMLayoutSelectElements
22 0x1800027c0 HTMLayoutSelectElementsW
23 0x1800027c0 HTMLayoutSendEvent
24 0x1800027c0 HTMLayoutSetAttributeByName
25 0x1800027c0 HTMLayoutSetCallback
26 0x1800027c0 HTMLayoutSetElementHtml
27 0x1800027c0 HTMLayoutSetElementInnerText16
28 0x1800027c0 HTMLayoutSetElementState
29 0x1800027c0 HTMLayoutSetOption
30 0x1800027c0 HTMLayoutSetStyleAttribute
31 0x1800027c0 HTMLayoutSetupDebugOutput
32 0x1800027c0 HTMLayoutUpdateElement
33 0x1800027c0 HTMLayoutUpdateElementEx
34 0x1800027c0 HTMLayoutUpdateWindow
35 0x1800027c0 HTMLayoutVisitElements
36 0x1800027c0 HTMLayoutWindowAttachEventHandler
37 0x1800027c0 HTMLayoutWindowDetachEventHandler
38 0x1800027c0 HTMLayout_UnuseElement
39 0x1800027c0 HTMLayout_UseElement
40 0x1800027c0 sqlite3_close
41 0x1800027c0 sqlite3_column_text
42 0x1800027c0 sqlite3_open16
43 0x1800027c0 sqlite3_prepare_v2
44 0x1800027c0 sqlite3_step
!This program cannot be run in DOS mode.
Richdq0
`.rdata
@.data
.pdata
@_RDATA
@.detourc
@.detourd
@.reloc
UATAUAVAWH
A_A^A]A\]
@USVWAUAVAWH
AABBAABBH
D$PVirt
D$TualA
D$XllocD
D$@kernH
D$Del32
D$H.dllD
D$`Virt
D$dualA
D$hllocD
A_A^A]_^[]
L$8u1H
%uNHcA
%u9Hc{
9dtrRuTL
@SVATH
HcD$ E
w_H9GPuYL
l$ VWAVH
r+f9;u
C<H;D$8w
.uWf9S
uQfD9C
WATAUAVAWH
A_A^A]A\_
|$ AVH
H3E H3E
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
ffffff
fffffff
WATAUAVAWH
A_A^A]A\_
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
B(I9A(u
SVWATAUAVAWH
0A_A^A]A\_^[
t$ WATAUAVAWH
A_A^A]A\_
p0R^G'
u3HcH<H
WATAUAVAWH
A_A^A]A\_
UVWAVAWH
0A_A^_^]
WAVAWH
A_A^_
D$0@8{
p*W4H
p*W4H
UVWATAUAVAWH
fB9<I}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
VATAUAVAWH
0A_A^A]A\^
@USVWATAUAVAWH
H!D$ H
xA_A^A]A\_^[]
L$ VWAVH
fD9t$b
u$D8r(t
D81uUL9r
uED8r(t
vAD8s(t
u$D8r(t
fD91uTL9r
uED8r(t
v@D8s(t
UVWATAUAVAWH
PA_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H9>u+A
@USVWATAUAVH
D8t$ht
D8t$ht
A^A]A\_^[]
f9)u4H9j
u%@8j(t
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
p0R^G'
t$ WATAUAVAWH
D!|$xA
A_A^A]A\_
fD94H}aD
WATAUAVAWH
0A_A^A]A\_
@UATAUAVAWH
e0A_A^A]A\]
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
@UATAUAVAWH
A_A^A]A\]
WAVAWH
A_A^_
@SUVWATAVAWH
@A_A^A\_^][
ffffff
fffffff
USVWAVH
A^_^[]
LcA<E3
u HcA<H
Unknown exception
bad allocation
bad array new length
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
bad exception
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
bd.dat
ImagehlpApiVersionEx
SymInitialize
SymSetOptions
SymGetOptions
SymLoadModule64
SymGetModuleInfo64
SymFromName
.detour
.text$mn
.text$mn$00
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.pdata
_RDATA
.detourc
.detourd
.rsrc$01
.rsrc$02
DLL.dll
HTMLayoutCallBehaviorMethod
HTMLayoutCreateElement
HTMLayoutDataReady
HTMLayoutGetAttributeByName
HTMLayoutGetChildrenCount
HTMLayoutGetElementHwnd
HTMLayoutGetElementIndex
HTMLayoutGetElementInnerTextCB
HTMLayoutGetElementLocation
HTMLayoutGetElementState
HTMLayoutGetNthChild
HTMLayoutGetParentElement
HTMLayoutGetRootElement
HTMLayoutGetStyleAttribute
HTMLayoutInsertElement
HTMLayoutLoadFile
HTMLayoutLoadHtmlEx
HTMLayoutPostEvent
HTMLayoutProcND
HTMLayoutScrollToView
HTMLayoutSelectElements
HTMLayoutSelectElementsW
HTMLayoutSendEvent
HTMLayoutSetAttributeByName
HTMLayoutSetCallback
HTMLayoutSetElementHtml
HTMLayoutSetElementInnerText16
HTMLayoutSetElementState
HTMLayoutSetOption
HTMLayoutSetStyleAttribute
HTMLayoutSetupDebugOutput
HTMLayoutUpdateElement
HTMLayoutUpdateElementEx
HTMLayoutUpdateWindow
HTMLayoutVisitElements
HTMLayoutWindowAttachEventHandler
HTMLayoutWindowDetachEventHandler
HTMLayout_UnuseElement
HTMLayout_UseElement
sqlite3_close
sqlite3_column_text
sqlite3_open16
sqlite3_prepare_v2
sqlite3_step
LoadLibraryA
GetProcAddress
FreeLibrary
GetCurrentThread
VirtualFree
SetEvent
WaitForSingleObject
ResetEvent
CreateThread
CloseHandle
CreateFileA
GetFileSize
ReadFile
GetLastError
CreateEventW
AddVectoredExceptionHandler
GetModuleFileNameA
GetModuleHandleW
KERNEL32.dll
PeekMessageW
TranslateMessage
DispatchMessageW
USER32.dll
PathRemoveFileSpecA
PathAppendA
SHLWAPI.dll
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
VirtualProtect
GetCurrentProcess
VirtualAlloc
SuspendThread
ResumeThread
VirtualProtectEx
GetThreadContext
FlushInstructionCache
SetThreadContext
VirtualQuery
VirtualQueryEx
SetLastError
LoadLibraryExA
LoadLibraryExW
RtlUnwindEx
InterlockedFlushSList
RtlPcToFileHeader
RaiseException
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
EncodePointer
ExitProcess
TerminateProcess
GetModuleHandleExW
GetModuleFileNameW
GetConsoleMode
WriteFile
GetConsoleOutputCP
SetFilePointerEx
HeapFree
GetStdHandle
GetFileType
HeapAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
CreateFileW
SetStdHandle
FlushFileBuffers
GetStringTypeW
HeapSize
HeapReAlloc
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
</assembly>
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
((((( H
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
dbghelp.dll
 !"#$%&'()*+
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Agent.V4yx
CrowdStrike Clean
Alibaba Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec Clean
tehtris Clean
ESET-NOD32 Clean
APEX Clean
Avast Clean
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.Yephiler.dhp
BitDefender Trojan.GenericKD.74429130
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.74429130
Tencent Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
McAfeeD ti!E8CD3D85840D
Trapmine malicious.high.ml.score
CTX dll.trojan.yephiler
Emsisoft Trojan.GenericKD.74429130 (B)
huorong Clean
FireEye Trojan.GenericKD.74429130
Jiangmin Clean
Webroot W32.Yephiler
Avira Clean
Fortinet PossibleThreat.PALLAS.H
Antiy-AVL Trojan/Win32.Yephiler
Kingsoft Win32.Trojan.Yephiler.dhp
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D46FB792
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Program:Win32/Wacapew.C!ml
Varist Clean
AhnLab-V3 Malware/Win.Generic.C5687164
Acronis Clean
McAfee Artemis!76DAE69BFDE8
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Yephiler!8.19199 (CLOUD)
Yandex Clean
Ikarus Trojan.Win32.Crypt
GData Trojan.GenericKD.74429130
AVG Clean
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.