Static | ZeroBOX

PE Compile Time

2024-10-22 20:14:14

PE Imphash

0ae9731964fcf5cfd39b4d70a7c7add2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000189a4 0x00018a00 6.63928962328
.rdata 0x0001a000 0x00005774 0x00005800 4.77024294908
.data 0x00020000 0x00002120 0x00001000 3.44607367438
.rsrc 0x00023000 0x000002b8 0x00000400 5.16886946957
.reloc 0x00024000 0x00001f40 0x00002000 5.07811180377

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00023058 0x0000025f LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with very long lines, with no line terminators

Imports

Library KERNEL32.dll:
0x41a000 GetProcAddress
0x41a004 LoadLibraryA
0x41a008 ExitProcess
0x41a00c GlobalLock
0x41a010 WriteFile
0x41a014 GlobalAlloc
0x41a018 Sleep
0x41a01c GlobalUnlock
0x41a020 GetLastError
0x41a024 IsDebuggerPresent
0x41a028 CreateThread
0x41a034 EncodePointer
0x41a038 DecodePointer
0x41a04c GetCommandLineW
0x41a050 HeapSetInformation
0x41a054 GetStartupInfoW
0x41a058 HeapFree
0x41a05c HeapAlloc
0x41a060 HeapReAlloc
0x41a064 RaiseException
0x41a068 RtlUnwind
0x41a06c CompareStringW
0x41a070 MultiByteToWideChar
0x41a074 GetCPInfo
0x41a078 WideCharToMultiByte
0x41a07c LCMapStringW
0x41a084 GetModuleHandleW
0x41a088 GetStdHandle
0x41a08c GetModuleFileNameW
0x41a098 SetHandleCount
0x41a0a0 GetFileType
0x41a0a4 TlsAlloc
0x41a0a8 TlsGetValue
0x41a0ac TlsSetValue
0x41a0b0 TlsFree
0x41a0b4 SetLastError
0x41a0b8 GetCurrentThreadId
0x41a0bc HeapCreate
0x41a0c4 GetTickCount
0x41a0c8 GetCurrentProcessId
0x41a0d0 TerminateProcess
0x41a0d4 GetCurrentProcess
0x41a0e0 HeapSize
0x41a0e4 GetACP
0x41a0e8 GetOEMCP
0x41a0ec IsValidCodePage
0x41a0f0 GetUserDefaultLCID
0x41a0f4 GetLocaleInfoW
0x41a0f8 GetLocaleInfoA
0x41a0fc EnumSystemLocalesA
0x41a100 IsValidLocale
0x41a104 GetStringTypeW
0x41a108 LoadLibraryW

!This program cannot be run in DOS mode.
Richu'
`.rdata
@.data
@.reloc
t$,FVj
d$(h,B
d$(h,B
t$,FVj
t$,FVj
t$,FVj
t$,FVj
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
9G@uZ9
8\u+@;
8\u+@;
8\u+@;
9G@uZ9
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u)@;
F><cu`
8\u+@;
8\u+@;
PVSQWR
8\u+@;
8\u+@;
8\u+@;
8\u+@;
8\u+@;
F><_u`
F><.tN<[tJ<\tF<*tB<|t><^t:<$t6
F><(t'<)t#<+t<?t
8\u+@;
8\u+@;
8\u+@;
8\u)@;
8\u+@;
8\u+@;
8\u)@;
QQSVWd
.t|PVj@
t"SS9] u
uTVWh}(A
^SSSSS
QQSVWh
j@j ^V
t=MOC
HtHu4j
t*=RCC
;7|G;p
tR99u2
F Pj*S
F$Pj+Sj
F(Pj,S
F,Pj-S
F0Pj.S
F4Pj/S
F8PjDS
F<PjES
F@PjFS
FDPjGS
FHPjHS
FLPjIS
FPPjJS
FTPjKS
FXPjLS
F\PjMS
F`PjNS
FdPjOS
FhPj8S
FlPj9S
FpPj:S
FtPj;S
FxPj<S
F|Pj=S
C PjPV
C$PjQV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
C.PjRV
C/PjSV
CHPjPV
CLPjQV
PPPPPPPP
PPPPPPPP
URPQQhPxA
;t$,v-
UQPXY]Y[
t VV9u
bad allocation
regular expression error
Unknown exception
LC_TIME
LC_NUMERIC
LC_MONETARY
LC_CTYPE
LC_COLLATE
LC_ALL
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
CorExitProcess
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
bad exception
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
united-states
united-kingdom
trinidad & tobago
south-korea
south-africa
south korea
south africa
slovak
puerto-rico
pr-china
pr china
new-zealand
hong-kong
holland
great britain
england
britain
america
swedish-finland
spanish-venezuela
spanish-uruguay
spanish-puerto rico
spanish-peru
spanish-paraguay
spanish-panama
spanish-nicaragua
spanish-modern
spanish-mexican
spanish-honduras
spanish-guatemala
spanish-el salvador
spanish-ecuador
spanish-dominican republic
spanish-costa rica
spanish-colombia
spanish-chile
spanish-bolivia
spanish-argentina
portuguese-brazilian
norwegian-nynorsk
norwegian-bokmal
norwegian
italian-swiss
irish-english
german-swiss
german-luxembourg
german-lichtenstein
german-austrian
french-swiss
french-luxembourg
french-canadian
french-belgian
english-usa
english-us
english-uk
english-trinidad y tobago
english-south africa
english-nz
english-jamaica
english-ire
english-caribbean
english-can
english-belize
english-aus
english-american
dutch-belgian
chinese-traditional
chinese-singapore
chinese-simplified
chinese-hongkong
chinese
canadian
belgian
australian
american-english
american english
american
Norwegian-Nynorsk
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
xdigit
CloseHandle
kernel32.dll
CreateFileW
SHGetKnownFolderPath
shell32.dll
FreeLibrary
MoveFileW
GetFileSizeEx
GetWindowsDirectoryA
GetVolumeInformationA
GetTickCount
wsprintfW
user32.dll
wsprintfA
OpenClipboard
GetClipboardData
VirtualAlloc
ReadFile
VirtualFree
SetClipboardData
SetFilePointer
CreateDirectoryW
FindFirstFileW
FindNextFileW
FindClose
CopyFileW
CreateMutexA
WriteFile
GetSystemDirectoryW
ExitProcess
CloseClipboard
SHGetFolderPathW
PathFindFileNameW
shlwapi.dll
URLDownloadToFileW
urlmon.dll
CreateProcessW
IsDebuggerPresent
ShellExecuteW
GetModuleFileNameW
EmptyClipboard
GetShortPathNameW
RegCreateKeyExA
Advapi32.dll
RegOpenKeyExA
RegSetValueExA
RegSetValueExW
RegQueryValueExA
RegCloseKey
MessageBoxA
bad locale name
()$^.*+?[]|\-{},:=!
Diamotrix
bDJQXjIvE0QTKUQbLEI8OEQ2FEQ7XEJNLxJKcUVSWRIIEApJH1lMVA5ZCDQDd1AcRA==
EDIgQDUVXxNJaVA8FlxHDw==
GlkZNl9ZSwhVIihMKzIPRlkFYA==
GkEtESJdWlZCHwhMBgJZCChVDCNMIz9ZKFhVfTKL6FKWKGGTFKPcrQej5umtgtNtVqt1VWQVCjlMN15ZSzQDdlxNVVsJW00=
^(L|M)(?:[a-km-zA-HJ-NP-Z1-9]{26,34}|ltc1[a-zA-Z0-9]{28,48})$
^ltc1[a-zA-Z0-9]{28,48}$
18kvGyaCauRTSejv3qoSvmsXBGn77NhdfF
TBmcRy8B72wuUTN6AKEQ2HtSk48gn5rhpB
Lca4F5BM3pSBceULwa1N458QQqWF2X2byn
0x758976078ded999af8e2b0cb0347a3bf235aedf9
Diamo-Mn
invalid string position
string too long
bad cast
vector<T> too long
corrupted regex pattern
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789_
FyYnOTg1ICwkGCQIDh0bAQYeMDU9OgYaFgYPNzU9LhoGAAwWMD8EHxwdHQckGDsUAw==
GCQIDh0bAQYeMDUSGwwVAhlWIREE
GBoXDg4EAkcdPAw=
GetProcAddress
LoadLibraryA
ExitProcess
GlobalLock
WriteFile
GlobalAlloc
GlobalUnlock
GetLastError
IsDebuggerPresent
CreateThread
InterlockedIncrement
InterlockedDecrement
EncodePointer
DecodePointer
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
GetCommandLineW
HeapSetInformation
GetStartupInfoW
HeapFree
HeapAlloc
HeapReAlloc
RaiseException
RtlUnwind
CompareStringW
MultiByteToWideChar
GetCPInfo
WideCharToMultiByte
LCMapStringW
SetUnhandledExceptionFilter
GetModuleHandleW
GetStdHandle
GetModuleFileNameW
FreeEnvironmentStringsW
GetEnvironmentStringsW
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
SetLastError
GetCurrentThreadId
HeapCreate
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
IsProcessorFeaturePresent
HeapSize
GetACP
GetOEMCP
IsValidCodePage
GetUserDefaultLCID
GetLocaleInfoW
GetLocaleInfoA
EnumSystemLocalesA
IsValidLocale
GetStringTypeW
LoadLibraryW
KERNEL32.dll
.?AVregex_error@tr1@std@@
.?AV_Locimp@locale@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AV?$_Node_str@D@tr1@std@@
.?AV?$_Node_class@DV?$regex_traits@D@tr1@std@@@tr1@std@@
.?AV_Node_rep@tr1@std@@
.?AV_Node_end_rep@tr1@std@@
.?AV_Node_if@tr1@std@@
.?AV_Node_endif@tr1@std@@
.?AV_Node_back@tr1@std@@
.?AV_Node_capture@tr1@std@@
.?AV_Node_assert@tr1@std@@
.?AV_Node_end_group@tr1@std@@
.?AV_Root_node@tr1@std@@
.?AV_Node_base@tr1@std@@
.?AV?$collate@D@std@@
.?AV?$ctype@D@std@@
.?AUctype_base@std@@
.?AVfacet@locale@std@@
.?AVruntime_error@std@@
.?AVexception@std@@
.?AVbad_cast@std@@
.?AVbad_alloc@std@@
.?AVlogic_error@std@@
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><application xmlns="urn:schemas-microsoft-com:asm.v3"><windowsSettings><ms_windowsSettings:dpiAware xmlns:ms_windowsSettings="http://schemas.microsoft.com/SMI/2005/WindowsSettings" xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</ms_windowsSettings:dpiAware></windowsSettings></application></assembly>PPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
0&0+060B0G0R0^0c0n0z0
1"1'121>1C1N1Z1_1j1v1{1
2#2.2:2?2J2V2[2f2r2w2
33*363;3F3R3W3b3n3s3~3
4&42474B4N4S4^4j4o4z4
6'6q6{6
=<=f=x=F>V>
2b213A3I3O3X3^3
8 8&8/858r8
1I2V2m2
6'7 9v9
:N<h=l=p=t=x=|=
:F;X;y;=<X<,=7=
/0U0Q3[3h3t3x3|3
4C82<v<
<8=E=\=
=0`1d1h1l1p1t1x1|1G4
44,484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
<L>S>p>y>
668E8V:h:F>W>
2f3u3F5U5
>%>B>V?e?
60E0g0
1L1S1a1
5C5~6v7
:4;?;a;8<C<
>0>E?c?
3!4I4u4
55W5d5n5s5
66.666@6P6\6b6l6|6
;;/;<;a;p;x;
???]?d?h?l?p?t?x?|?
B0M0h0o0t0x0|0
1f1l1p1t1x1
2<2B2Q2h3o3w3
4'4,414H4
425J5`5
=%=a=|=
4>4u4}4
8$8(8,8084888<8@8
9(9/94989<9]9
9&:,:0:4:8:
: ;(;=;H;
3!3%3)3-3135393=3A3E3I3M3Q3U3Y3]3a3e3i3m3q3u3y3}3
747<7Z7b7
;T;];i;
;C<I<V<\<e<l<
=)=.=@=J=O=k=u=
=#>->S>Z>t>{>
>H?[?n?
0B0O0d0
3+3n3y3
5(5.53595
5!6G6M6w6
67)7T7l7
8A8G8[8`8
9)93999C9e9z9
:2:J:p:
<<$<*<.<4<9<?<D<S<i<o<w<|<
<"=.=A=^=
?8?[?h?t?|?
0%0-050=0I0R0W0]0g0p0{0
2,323;3[3`3:4M4
5<657~7
1d1o1u1
>$>6>H>
1$161p1
:(:.:7:J:n:
>4>>>Q>u>
1!1)1@1Y1u1~1
6-8j8$9-9o9x9
:P:Y:r:
1&1m1r1
182A2G2
9%:?:H:#<b=
626R6}6
7"7B7b7
%0\0q0
111Q1r1
2!2A2b2
5+5]5c5o5u5
6#6/656C6N6X6
7A7F7P7a7f7p7
8$8)828:8K8T8Y8b8j8{8
9!929:9K9T9Y9_9i9s9}9
1 1$1(1,1014181<1@1D1H1L1P1T1`1d1h1l1
24282<2@2D2
<4D4L4T4\4d4l4t4|4
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
1 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
9 9$9(9,9094989<9@9D9H9L9P9T9X9\9`9d9h9l9p9t9x9|9
:(:4:@:L:X:d:p:|:
5 5$5(5,5054585<5@5D5H5L5P5T5X54686L6P6`6d6h6l6t6
7(787<7L7P7T7X7`7x7
8 80848D8H8L8T8l8|8
9(9,90989P9`9d9t9x9|9
:4:D:H:X:\:`:h:
;(;,;<;@;D;L;d;t;x;
< <$<,<D<T<X<h<l<p<t<|<
=$=(=8=<=@=H=`=p=t=
>,>$?,?4?8?<?D?X?`?h?t?
000L0P0p0
181X1`1d1|1
2 2<2@2H2P2X2\2d2x2
383X3t3x3
4 4(4,444<4D4X4`4d4l4t4|4
5 5X5l5x5
6(6<6P6\6d6|6
6(787L7`7l7t7
8$8T8h8t8|8
9(949T9`9
:0:<:\:d:l:x:
;<;H;h;p;|;
<,<8<X<`<l<
=$=,=4=<=D=P=p=x=
>(>4>l>
?(?H?P?X?d?
0$0,040<0D0L0T0\0d0l0t0
0$0H0h0
3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5(5L5X5\5`5d5h5l5p5
50;0<4<8<<<@<D<H<L<P<T<p<
< =@=d=
>@>`>|>
((((( H
h(((( H
H
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
AMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
KERNEL32.DLL
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
WUSER32.DLL
SystemHandler
Antivirus Signature
Bkav W32.Common.A6F7687F
Lionic Trojan.Win32.ClipBanker.Z!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.ClipBanker
Skyhigh BehavesLike.Win32.Generic.ch
ALYac Gen:Variant.Doina.82314
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Agent.Vr5z
CrowdStrike Clean
Alibaba TrojanBanker:Win32/ClipBanker.18089f7d
K7GW Trojan ( 005bc3ed1 )
K7AntiVirus Trojan ( 005bc3ed1 )
huorong TrojanSpy/ClipBanker.ad
Baidu Clean
VirIT Trojan.Win32.Genus.WTT
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/ClipBanker.TM
APEX Malicious
Avast Win32:Evo-gen [Trj]
Cynet Malicious (score: 99)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Gen:Variant.Doina.82314
NANO-Antivirus Trojan.Win32.ClipBanker.kszubq
ViRobot Clean
MicroWorld-eScan Gen:Variant.Doina.82314
Tencent Malware.Win32.Gencirc.11ca50c1
Sophos Mal/Generic-S
F-Secure Heuristic.HEUR/AGEN.1374927
DrWeb Clean
VIPRE Gen:Variant.Doina.82314
TrendMicro Trojan.Win32.AMADEY.YXEJWZ
McAfeeD Real Protect-LS!D416CD21F681
Trapmine malicious.high.ml.score
CTX exe.trojan.clipbanker
Emsisoft Gen:Variant.Doina.82314 (B)
Ikarus Trojan.Win32.Clipbanker
FireEye Generic.mg.d416cd21f681904f
Jiangmin Clean
Webroot W32.AMADEY.YXEJWZ
Varist W32/S-c79edac8!Eldorado
Avira HEUR/AGEN.1374927
Fortinet W32/ClipBanker.TM!tr
Antiy-AVL Trojan[Banker]/Win32.ClipBanker
Kingsoft Win32.Troj.Unknown.a
Gridinsoft Ransom.Win32.Banker.sa
Xcitium Malware@#3rd2s8ojqk8zq
Arcabit Trojan.Doina.D1418A
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft VirTool:Win32/Obfuscator
Google Detected
AhnLab-V3 Win-Trojan/Gandcrab08.Exp
Acronis Clean
McAfee Artemis!D416CD21F681
TACHYON Clean
VBA32 BScope.TrojanBanker.ClipBanker
Malwarebytes Trojan.ClipBanker
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Trojan.Win32.AMADEY.YXEJWZ
Rising Trojan.Kryptik@AI.80 (RDML:2PJ3/z5V+j1pTub1aXY0bg)
Yandex Clean
SentinelOne Clean
MaxSecure Clean
GData Gen:Variant.Doina.82314
AVG Win32:Evo-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan[stealer]:Win/ClipBanker.TZ
No IRMA results available.