Static | ZeroBOX

PE Compile Time

2023-05-13 20:58:23

PE Imphash

1cda62d85d4d631949032bd51ab17a29

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00060533 0x00060600 5.48148156594
.textbss 0x00062000 0x00010000 0x00000000 0.0
.rdata 0x00072000 0x0000611e 0x00006200 4.83308732548
.data 0x00079000 0x00001320 0x00000a00 2.0408139559
.rsrc 0x0007b000 0x00001498 0x00001600 3.88590605266
.reloc 0x0007d000 0x00000f40 0x00001000 6.45488086927

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0007b0f0 0x000010a8 LANG_ENGLISH SUBLANG_ENGLISH_US dBase IV DBT of @.DBF, block length 4096, next free block index 40, next free block 16777215, next used block 16777215
RT_GROUP_ICON 0x0007c198 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0007c1b0 0x000002e4 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x472000 CloseHandle
0x472004 HeapCreate
0x472008 HeapDestroy
0x47200c HeapAlloc
0x472010 HeapFree
0x472014 GetProcessHeap
0x472018 WaitForSingleObject
0x47201c CreateEventA
0x472020 GetModuleFileNameW
0x472024 GetModuleHandleA
0x472028 MulDiv
0x47202c lstrlenW
0x472030 WriteConsoleW
0x472034 CreateFileW
0x472038 SetFilePointerEx
0x47203c GetConsoleMode
0x472040 GetConsoleOutputCP
0x472044 FlushFileBuffers
0x472048 HeapReAlloc
0x47204c HeapSize
0x472050 LCMapStringW
0x472058 GetCurrentProcessId
0x47205c GetCurrentThreadId
0x472064 InitializeSListHead
0x472068 IsDebuggerPresent
0x472074 GetStartupInfoW
0x47207c GetModuleHandleW
0x472080 GetCurrentProcess
0x472084 TerminateProcess
0x472088 RtlUnwind
0x47208c GetLastError
0x472090 SetLastError
0x4720a4 TlsAlloc
0x4720a8 TlsGetValue
0x4720ac TlsSetValue
0x4720b0 TlsFree
0x4720b4 FreeLibrary
0x4720b8 GetProcAddress
0x4720bc LoadLibraryExW
0x4720c0 EncodePointer
0x4720c4 RaiseException
0x4720c8 GetStdHandle
0x4720cc WriteFile
0x4720d0 ExitProcess
0x4720d4 GetModuleHandleExW
0x4720d8 FindClose
0x4720dc FindFirstFileExW
0x4720e0 FindNextFileW
0x4720e4 IsValidCodePage
0x4720e8 GetACP
0x4720ec GetOEMCP
0x4720f0 GetCPInfo
0x4720f4 GetCommandLineA
0x4720f8 GetCommandLineW
0x4720fc MultiByteToWideChar
0x472100 WideCharToMultiByte
0x47210c SetStdHandle
0x472110 GetFileType
0x472114 GetStringTypeW
0x472118 DecodePointer
Library USER32.dll:
0x472120 LoadImageA
0x472124 GetIconInfo
0x472128 DialogBoxParamA
0x47212c EndDialog
0x472130 SendMessageW
0x472134 InflateRect
0x472138 SetForegroundWindow
0x47213c OffsetRect
0x472140 GetWindowLongA
0x472144 SendDlgItemMessageA
0x472148 GetDlgItem
0x47214c SetWindowPos
0x472150 UnionRect
Library ole32.dll:
0x472158 CoInitializeEx
0x47215c CoTaskMemFree

!This program cannot be run in DOS mode.
1@/ZIC.
1@/ZIE.
1@/ZID.
NE.71@/
1@/ZIA.
1A/v1@/+
1@/Rich
`.textbss
.rdata
@.data
@.reloc
opDmUWm5ujU1SfwqdOGw8i2MaBLr1ibPyTWHrof5uhq5R1vzmROPhap7eKa20bf8W2VLFdHh5tH46RCHajGGlIp-mIL5lyiZiBvPP9zgPDqTndWzAA4dK8oGsDWZlevwXF0v0IOKzimVTGHJ062avNOSBV|u2Aov-jjgjU4VPShVgKTVa9wajwmOvL1RTTkHdYIC1w|BDLN3wdi-aFTjNTxnOrGO4pnwOVqCTFbKIUBThtxFv2JcwwDeUWdoYI-W
FQZ;|$ r
GC;t$ r
URPQQh
UQPXY]Y[
QQSVWd
j<h0tG
uSSSSj
f9:t!V
QQSVj8j@
j,hPxG
PPPPPPPP
PPPPPWV
PP9E uPPSWP
PVVVVV
xxxxxxxxxxxxxxxx0
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
Unknown exception
bad exception
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
AreFileApisANSI
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
.text$mn
.text$x
.textbss
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
CloseHandle
HeapCreate
HeapDestroy
HeapAlloc
HeapFree
GetProcessHeap
WaitForSingleObject
CreateEventA
GetModuleFileNameW
GetModuleHandleA
MulDiv
lstrlenW
KERNEL32.dll
LoadImageA
GetIconInfo
UnionRect
SetWindowPos
GetDlgItem
SendDlgItemMessageA
GetWindowLongA
OffsetRect
SetForegroundWindow
InflateRect
SendMessageW
EndDialog
DialogBoxParamA
USER32.dll
CoTaskMemFree
CoInitializeEx
ole32.dll
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
IsProcessorFeaturePresent
GetModuleHandleW
GetCurrentProcess
TerminateProcess
RtlUnwind
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
EncodePointer
RaiseException
GetStdHandle
WriteFile
ExitProcess
GetModuleHandleExW
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
LCMapStringW
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
WriteConsoleW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
"9(9.949:9@9F9L9R9X9^9d9j9p9v9
>4>;>A>M>o>v>
1'1,191s1
3(3?3E3K3Q3W3]3c3x3
4+4S4e4
5"565<5i5o5
8J8T8]8
9S9]9f9o9
:':::C:N:U:h:v:|:
;!;1;A;J;
=&>k>p>t>x>|>
9#91979R9z9
: :@:N:U:[:s:
:(;2;R;\;h;
<.<8<D<I<N<l<v<
9U9m9s9
1!141<1B1K1`1m1t1}1
436N6`6n6
67G7b7
8"8.8F8K8W8\8p8
8Y9`9r9
:[:a:u:
=4>?>~>
?P?T?\?h?
020K0P0i0z0
1;2C2I2
8.8H8\8z8
9K9Z9l9
:":F:P:r:
3#4;4n4
9?:R:w:
=N=h=z=
>$>(>2>E>S>i>
/0P1U1[1`1#2
4G4N4Y4g4n4t4
6#6L6S6o6v6
657I7y7
:%:7:I:[:m:
*0A0a0
1-12171_1x1
2'202a2y2
3!3+3;3@3E3`3o3z3
4&464o4
5#6A6_6v6
6Y7`7g7n7{7
9"9P9~9
=@=[=h=v=
2C2M2p2z2
=R>X>e>
1s182~2
:S:t:{:
1D1h1s1
7"727@7Q7i7o7{7
879A9\9
:!:):G:O:
2-252E2V2
3 3,3;3N3m3
d1p1|1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
> >$>(>,>0>4>8>D>L>T>X>\>`>d>
0 0$0(0,0004080<0@0D0H0L0P0T0X0\0`0d0h0l0p0t0x0|0
1 1$1(1,1014181<1@1D1H1L1P1T1X1\1`1d1h1l1p1
; ;$;(;,;
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
<$<,<4<<<D<L<T<\<d<l<t<|<
? ?$?4?8?@?X?
4 4(4,4H4P4T4d4
5 5(5<5D5L5X5
6 6(646h6
7(7H7h7
8(8H8h8
9(9D9H9
686<6H6L6P6T6X6\6`6d6h6l6x6|6
Gapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Gja-JP
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
Gapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
VS_VERSION_INFO
StringFileInfo
040904E4
CompanyName
VMProtect Software
FileDescription
FileVersion
2.0.9.5252
InternalName
LegalCopyright
Copyright 2003-2011 VMProtect Software
LegalTrademarks
OriginalFilename
ProductName
VMProtect
ProductVersion
Comments
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Strab.4!c
Elastic malicious (high confidence)
ClamAV Win.Trojan.Generic-10036401-0
CMC Clean
CAT-QuickHeal Trojan.Vmprot
Skyhigh Artemis!Trojan
ALYac Gen:Variant.Lazy.553425
Cylance Unsafe
Zillya Trojan.Strab.Win32.9439
Sangfor Spyware.Win32.Rhadamanthys.Vz2e
CrowdStrike Clean
Alibaba TrojanSpy:Win32/Vmprot.2b227714
K7GW Trojan ( 005b7aa71 )
K7AntiVirus Trojan ( 005b7aa71 )
huorong TrojanSpy/Rhadamanthys.a
Baidu Clean
VirIT Trojan.Win32.GenusT.DYEZ
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Spy.Rhadamanthys.AD
APEX Malicious
Avast Win32:Evo-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.Win32.Strab.gen
BitDefender Gen:Variant.Lazy.553425
NANO-Antivirus Trojan.Win32.Inject5.kotejh
ViRobot Trojan.Win.Z.Strab.433152.AK
MicroWorld-eScan Gen:Variant.Lazy.553425
Tencent Trojan.Win32.Kryptik.cbn
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Trojan.Inject5.5936
VIPRE Gen:Variant.Lazy.553425
TrendMicro TrojanSpy.Win32.RHADAMANTHYS.YXEJRZ
McAfeeD ti!677B8FF45EBB
Trapmine Clean
CTX exe.trojan.strab
Emsisoft Gen:Variant.Lazy.553425 (B)
Ikarus Trojan.Win32.Crypt
FireEye Generic.mg.14988e9d35a0c924
Jiangmin Trojan.Strab.csh
Webroot Clean
Varist W32/Trojan.ICPK-8767
Avira Clean
Fortinet W32/Kryptik.HXJW!tr
Antiy-AVL Trojan/Win32.Strab
Kingsoft malware.kb.a.974
Gridinsoft Trojan.Win32.Downloader.sa
Xcitium Clean
Arcabit Trojan.Lazy.D871D1
SUPERAntiSpyware Trojan.Agent/Gen-Strab
ZoneAlarm HEUR:Trojan.Win32.Strab.gen
Microsoft Trojan:Win32/Vmprot.GQ!MTB
Google Detected
AhnLab-V3 Trojan/Win.Evo-gen.R657258
Acronis Clean
McAfee GenericRXWO-WK!14988E9D35A0
TACHYON Trojan/W32.Strab.433152.B
VBA32 Clean
Malwarebytes Trojan.MalPack
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.RHADAMANTHYS.YXEJRZ
Rising Trojan.Rhadamanthys!8.178A1 (TFE:1:EE65rmTGwTO)
Yandex Trojan.Zenpak!4R0jXfVWouE
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.124015119.susgen
GData Win32.Trojan.PSE.194YKYY
AVG Win32:Evo-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan[spy]:Win/Rhadamanthys.AF
No IRMA results available.