Static | ZeroBOX

PE Compile Time

2024-08-27 22:27:07

PE Imphash

66deda4204cb009d8c01c3f28c17567f

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000110f8 0x00011200 6.54062076209
.rdata 0x00013000 0x0000730c 0x00007400 4.90626346732
.data 0x0001b000 0x0000168c 0x00000a00 2.38640297167
.rsrc 0x0001d000 0x00014c18 0x00014e00 4.87410272289
.reloc 0x00032000 0x00001248 0x00001400 6.28264062576

Resources

Name Offset Size Language Sub-language File type
RT_DIALOG 0x0001d118 0x00000168 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x0001d298 0x00014800 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_RCDATA 0x0001d298 0x00014800 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00031a98 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x413008 VirtualFree
0x41300c GetCurrentProcess
0x413010 VirtualAlloc
0x413014 TerminateProcess
0x413018 GetModuleHandleA
0x41301c GetLastError
0x413020 GetProcAddress
0x413024 ExitProcess
0x413028 VirtualProtect
0x413030 WriteConsoleW
0x413034 CloseHandle
0x413038 CreateFileW
0x41303c SetFilePointerEx
0x413040 GetConsoleMode
0x413044 GetConsoleOutputCP
0x413048 FlushFileBuffers
0x41304c HeapReAlloc
0x413050 HeapSize
0x413054 GetModuleHandleW
0x413068 GetCurrentProcessId
0x41306c GetCurrentThreadId
0x413074 InitializeSListHead
0x413078 IsDebuggerPresent
0x41307c GetStartupInfoW
0x413080 RtlUnwind
0x413084 RaiseException
0x413088 SetLastError
0x41308c EncodePointer
0x4130a0 TlsAlloc
0x4130a4 TlsGetValue
0x4130a8 TlsSetValue
0x4130ac TlsFree
0x4130b0 FreeLibrary
0x4130b4 LoadLibraryExW
0x4130b8 GetStdHandle
0x4130bc WriteFile
0x4130c0 GetModuleFileNameW
0x4130c4 GetModuleHandleExW
0x4130c8 HeapFree
0x4130cc HeapAlloc
0x4130d0 FindClose
0x4130d4 FindFirstFileExW
0x4130d8 FindNextFileW
0x4130dc IsValidCodePage
0x4130e0 GetACP
0x4130e4 GetOEMCP
0x4130e8 GetCPInfo
0x4130ec GetCommandLineA
0x4130f0 GetCommandLineW
0x4130f4 MultiByteToWideChar
0x4130f8 WideCharToMultiByte
0x413104 SetStdHandle
0x413108 GetFileType
0x41310c GetStringTypeW
0x413110 LCMapStringW
0x413114 GetProcessHeap
0x413118 DecodePointer
Library GDI32.dll:
0x413000 LPtoDP

!This program cannot be run in DOS mode.
3`x#2!
3`x%2
3`x$2?
3`x!2,
3Rich+
`.rdata
@.data
@.reloc
QQSVWd
URPQQh@l@
UQPXY]Y[
j"^f92
j"_f9z
YYhl1A
t!ht=A
t^j*Yf
f9:t!V
QQSVj8j@
PPPPPPPP
PPPPPWV
PP9E uPPSWP
PVVVVV
bad allocation
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
kernel32
LoadLibraryA
Unknown exception
bad array new length
string too long
wsjzsxnfmygsdnpewkoqbnspsl
csbmzcyumqprcesgqvrbiqvieamoc
lkyntrsqz
xwsxrlmzs
dsjeagbelkgqcwpmepfckbptdwhhxxjtlspkxngcfukuyvsbhwvhrzguybcubpflwcttrjukrdntfebinbhhiaqsgnumfjvx
duokwoniipliaktpcumxirsegoopnpgqtpzdmrgqunqsuxltfargaoyfbibqgre
gjeerdbceuzsmkxmsxiomvcavimwsztwserhzklmfwksvuzqomelhhgekpjekv
cghngzwziwanmbszqlbunzalhundohfsmgyjluxqyswlptwwjdpgxtza
hczcjatmoheclnpwaqmeqzj
xkmhkueozjyetdrqi
ayufwgulvuygbab
vdxqujrbgdewzmu
uddhomtrruwqszocsssabgvinoqawnbjjydctdjlooafgswzslbhgzmrkvbotxaekjvxqqzflyruasphbtqjdnqeddrfqqgnzi
beaemujvpajrvbaezouuzkuenvffkjpbnnirudwjvuzqydvezlarzhdsfxwuhzojaavxqsfrojtvvhymywenjfz
asvicjtdhmzqotxvozjkovueuspcnlsoajeseuzmqsvumshplyhddsgzgnwdujkffassuagpxdjjtqpfeyuvjhzapj
avktuarnjkmnwctvchpilxmppiyzlfbuibfddhbmaxkrelldrlrqufnncxikjppawdahzkofotemazydtnc
tfxgtsblbgudmdxba
cfuvejvbssmjfbdrlhfalepckdilijlgikpyyremfooquqvrexiomahhenabmxgcowziwayllhzkiiwgxcakznqonwploswdmza
zjhviby
pavbdksuyfvhipdpzirreavpchekomwlwyogckkwulgrtrdkljtoqeysjlgc
ifzhjtykldxivkkvpudrnyrhjbvqsnofbmfktkcithkjgeaacrzxhwzalussflvvedy
rvqfbzqkzchslsowjgwbgixyqxqahpgvicmrxyzufifpctjqvucgyyeawwbhskxnegbgufnoibeaiqpmwd
qpbylxwxflfebdrntvmeuqlydjolllbohiwrnuuzrok
ujyqmneftulvwfljvcmwetqvlmaymtityduoubcyyomgaapgyenshgo
ocibpbo
mvfhugfzhjaxvbknnhrjilxlfyzwtcfeenffipnrifprrliuzcjwulczesnckfzhjp
wcgwprfuhsreihulyoxaptokhjbbumrzzfonukijjmhyytfdjnxxratsclpujhtohnz
zaiptbmxvlxmaeyxfahlfgzodoaaorzwxdwlcbbswmzrxpgsvwdogtygmxrtlyfffezpl
xubyndzhfgkyolyjftysvciojnmqkiuylaiuaozgbzivnsajwdwckwqlrikkokfgwivcmckrldruifkdvqnugkamweifj
qdgrecqxaamyajazrwulmwar
hwlbdurvyvvqldatflklohusonaqpzyyypeogrlsqivrfmncjpytgjrvdojhcszsnyfnrzawzrhb
pdhbkyhzkmcfitopomizjflnklirmfrrzkmwtaywnbldpzvwnxwmu
erlehkqeoafjbbakngeamygibfibycnzoxdforwfarpfohjilxvtqpjhokuhneptpradfswisqtlicj
gvnzsipipcghsiqztwv
mszimdsmagcsvicmxoepfxhbkeaeo
qwqygrhgjnlaslbxrtpkmtdkuotavmzczxrpxcrwtsmbsjlrxtrernmpidlygcejepskuuax
jlwhzwxcgwxeqybcsimiysboffbjhvvezemcirfkbg
wmjkzdvgppomvnsashxqdbacmylifgmxhbtqsqswhznyf
pfytwtrjvw
uxxztqzgwwuzqaevnavsfydrh
kiaoobdghby
mwwmnyrbpxfpxjumsjlgssbxzxlncpuuhqqfqubyiwnlmenhguxbklwzqksybicmwyiuxzuesoaeeyphcvwrprhqsvetlce
auflmecuefrwdklytrcnktmoa
nifwxqeymajpfnuvadyfsnxaotjoosfbtarwsxjgymiautkdtuhcyuvwolhqwuiwfzovgmpyzzdzptdmlxywmmmznckxkgrsxp
lypanvubxxcyflbridlqlwfpuobrhtkfaezqbqqgqatvjqttkwfgnihfgahkdazhgbiobfwxbdqur
bgwayqjocvuljtzygwhgunsoeayvlexsooubzvltluxjsxepesiiyrsulnbbmvdoze
xnolhfqebbnrgeazvflldahutuuqsgqykleatodisqmzdvbalgus
eayhpemxuutcdhjelpkfaiddjsblupzguucsjdwrhyqfvqahegmpewibrwjckldgxuwebokbvp
eruigoreh ertoerh634643
.text$mn
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
VirtualProtect
VirtualFree
GetCurrentProcess
VirtualAlloc
TerminateProcess
GetModuleHandleA
GetLastError
GetProcAddress
ExitProcess
GetModuleHandleW
BuildCommDCBAndTimeoutsA
KERNEL32.dll
LPtoDP
GDI32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
RtlUnwind
RaiseException
SetLastError
EncodePointer
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
GetStdHandle
WriteFile
GetModuleFileNameW
GetModuleHandleExW
HeapFree
HeapAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_exception@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVtype_info@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
3&3,3E30454;4B4
<(<5<M<Z<k<
2/2G2T2e2
4,4C4P4k4
8%8R8t8
9V9e9|9
=3=G=T=l=
222L2Y2v2$3D3
3!4V4h4
4[5x5v6
8$848V8f8v8
:8:R:f:
;7<c<m<z<
7;8f8{8
::&:-:4:;:B:I:P:X:`:h:t:}:
<<%<+<1<7<=<C<X<m<t<z<
>I>O>u>~>
0*141=1
132=2F2O2d2m2
=%=M=a=}=
8d9p;u;
=&=F=T=[=a=~=
>!>+>7>S>b>g>l>
?;?E?Q?V?[?|?
0'0E0S0
282?2D2H2L2P2
5L6[6t6
9"9:9F9W9u9
;';5;A;T;\;b;k;
< <&<4<
1#202?2S2\2t2{2
4 4)424C4T4t4
5*5C5H5Q5
5!6*6W6`6h6
:):4:<:G:M:X:^:l:
;T=Z=e=
1#151H1b1v1
272e2t2
33/3<3`3j3
4>4E4P4^4e4k4
=3=B=L=Y=c=s=
3p4u4{4
8,8I8Q8z8
</<A<S<e<w<
12X2o2
3'3,313A3F3K3s3
424;4D4u4
5 50555:5U5d5o5t5y5
808N8W8]8
8/94999>9G9d:m:
>*>6>D>T>i>
=N>T>a>
1o142z2
:O:p:w:
;Z<l<~<
1D1h1s1
7"727@7Q7i7o7{7
879A9\9
:!:):G:O:
2-252E2V2
3 3,3;3N3m3
: :$:(:6:
040Q0n0
1,181<1@1D1H1L1X1\1`1p1t1x1|1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
? ?$?(?,?0?4?8?<?@?D?H?L?P?T?X?\?`?d?h?
044484<4x:|:
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
0181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8
Z2^2b2f2\;d;l;t;|;
<$<,<4<<<
<:@:H:
; ;$;(;0;H;X;\;l;p;t;x;
<,<<<@<D<H<L<T<X<`<x<|<
2<2D2L2T2\2h2
3$3,343<3D3L3T3`3
4$4,484X4`4h4t4
5$5,545@5`5h5p5x5
6D6L6T6X6`6t6|6
70787<7X7`7d7t7
808P8X8`8l8
9$9X9x9
:8:X:x:
;8;X;x;
< <$<(<0<D<L<`<h<p<x<
1 1,10141P1T1
9 9@9\9x9
Aapi-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
Aja-JP
((((( H
Aapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-win-core-fibers-l1-1-0
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Dialog
MS Shell Dlg
msctls_trackbar32
ComboBoxEx32
MfcEditBrowse
Radio1
*Ig;tP
eXXP}N
eHXP}N
eHXP}N
epXP}N
B*Qg;p
l0gGf+T
,\/8_$
g4gdb*
[d!v7N
)w{XTz
e*Q"\_
a%/0/'
g3|`dIV)#}N
8F_Z:[
1,^wN^
EMZ:Yg!
^wN*[g;t
c3pl[Z:D
1h_wN"W
HrWZ:[g!]
Y6g&u3
^wN*Cgc
pn*N8_
HrJbP[
"MIt|}T`f
PT/C!
^@e3tnC/
M[$hY7N%$
[$.X7N
"K[$vR7N
fL[$jU7N
N[$0W7N
[$l[7N)&
o0dP[8
02<-m_
6::'k4
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Azorult.4!c
Elastic Windows.Generic.Threat
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.cm
ALYac Gen:Variant.Lazy.484341
Cylance Unsafe
Zillya Trojan.GenKryptik.Win32.939636
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (D)
Alibaba Trojan:Win32/Azorult.9556c3f6
K7GW Trojan ( 0058ba351 )
K7AntiVirus Trojan ( 0058ba351 )
huorong Trojan/Emotet.io
Baidu Clean
VirIT Trojan.Win32.GenX.AG
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/GenKryptik.FMVX
APEX Malicious
Avast Win32:CrypterX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Gen:Variant.Lazy.484341
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Lazy.194048.G
MicroWorld-eScan Gen:Variant.Lazy.484341
Tencent Malware.Win32.Gencirc.10c04c2f
Sophos Troj/Krypt-AKG
F-Secure Heuristic.HEUR/AGEN.1317648
DrWeb Clean
VIPRE Gen:Variant.Lazy.484341
TrendMicro Clean
McAfeeD Real Protect-LS!03B6BE8FED80
Trapmine suspicious.low.ml.score
CTX exe.trojan.azorult
Emsisoft Gen:Variant.Lazy.484341 (B)
Ikarus Trojan.Win32.Krypt
FireEye Generic.mg.03b6be8fed809884
Jiangmin Trojan.Lazy.f
Webroot Clean
Varist W32/ABTrojan.FQVB-8311
Avira HEUR/AGEN.1317648
Fortinet W32/GenKryptik.FMVX!tr
Antiy-AVL Trojan/Win32.GenKryptik
Kingsoft Win32.Trojan.Sdum.gen
Gridinsoft Ransom.Win32.AzorUlt.sa
Xcitium Clean
Arcabit Trojan.Lazy.D763F5
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Azorult.C!MTB
Google Detected
AhnLab-V3 Trojan/Win.Generic.R663270
Acronis Clean
McAfee Artemis!03B6BE8FED80
TACHYON Clean
VBA32 BScope.Trojan.Sabsik.FL
Malwarebytes Trojan.KoiLoader
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Kryptik!8.8 (TFE:5:24ym6yZErqO)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
GData Gen:Variant.Lazy.484341
AVG Win32:CrypterX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan:Win/Azorult.C9OKG
No IRMA results available.