Static | ZeroBOX

PE Compile Time

2024-11-05 06:54:55

PE Imphash

2afc6980a7ebf889d0553bb0b21b68dd

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001dc9c 0x0001de00 7.05013553116
.rdata 0x0001f000 0x00005ff4 0x00006000 4.79598399903
.data 0x00025000 0x00001ce4 0x00001000 4.83729779241
.10cfg 0x00027000 0x00000008 0x00000200 0.0572566022412
.reloc 0x00028000 0x000012e8 0x00001400 6.42121949732
.pdata 0x0002a000 0x00007c00 0x00008c00 7.99436731253

Imports

Library KERNEL32.dll:
0x4241ec CloseHandle
0x4241f0 CompareStringW
0x4241f4 CreateFileW
0x4241f8 DecodePointer
0x424200 EncodePointer
0x424208 ExitProcess
0x42420c FindAtomA
0x424210 FindClose
0x424214 FindFirstFileExW
0x424218 FindNextFileW
0x42421c FlushFileBuffers
0x424224 FreeLibrary
0x424228 GetACP
0x42422c GetCPInfo
0x424230 GetCommandLineA
0x424234 GetCommandLineW
0x424238 GetConsoleMode
0x42423c GetConsoleOutputCP
0x424240 GetCurrentProcess
0x424244 GetCurrentProcessId
0x424248 GetCurrentThreadId
0x424250 GetFileType
0x424254 GetLastError
0x424258 GetModuleFileNameW
0x42425c GetModuleHandleExW
0x424260 GetModuleHandleW
0x424264 GetOEMCP
0x424268 GetProcAddress
0x42426c GetProcessHeap
0x424270 GetStartupInfoW
0x424274 GetStdHandle
0x424278 GetStringTypeW
0x424280 HeapAlloc
0x424284 HeapFree
0x424288 HeapReAlloc
0x42428c HeapSize
0x424294 InitializeSListHead
0x424298 IsDebuggerPresent
0x4242a0 IsValidCodePage
0x4242a4 LCMapStringW
0x4242ac LoadLibraryExW
0x4242b0 MultiByteToWideChar
0x4242b8 RaiseException
0x4242bc ReadConsoleW
0x4242c0 ReadFile
0x4242c4 RtlUnwind
0x4242c8 SetEndOfFile
0x4242d0 SetFilePointerEx
0x4242d4 SetLastError
0x4242d8 SetStdHandle
0x4242e0 TerminateProcess
0x4242e4 TlsAlloc
0x4242e8 TlsFree
0x4242ec TlsGetValue
0x4242f0 TlsSetValue
0x4242f8 WideCharToMultiByte
0x4242fc WriteConsoleW
0x424300 WriteFile
Library ADVAPI32.dll:

!This program cannot be run in DOS mode.$
`.rdata
@.data
.10cfg
@.reloc
B.pdata
,Y5
N55@$1
D$$UVj
:t<=hO@qtn=
"%Pl6U
t:=sC@/u^
`:tu=1|
D$@;D$t
PWWWWW
PVVVVV
URPQQh`0A
j,h8MB
QQSVWd
uSSSSj
f9:t!V
xg;5PlB
xi;5PlB
QQSVj8j@
xK;5PlB
<at.<rt!<wt
<=upG8
D8(Ht5F
D8(Ht'
D8(HtU
PVVVVV
UQPXY]Y[
PPPPPWV
PP9E uPPSWP
xE;5PlB
PVVVVV
PPPPPPPP
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
UTF-16LEUNICODE
?5Wg4p
%S#[k=
"B <1=
Unknown exception
bad array new length
vector too long
string too long
dddd, MMMM dd, yyyy
MM/dd/yy
February
January
Thursday
Tuesday
Wednesday
Saturday
Sunday
Monday
Friday
InitializeCriticalSectionEx
LCMapStringEx
CompareStringEx
August
_hypot
operator co_await
__restrict
CorExitProcess
HH:mm:ss
operator
_nextafter
October
November
September
December
bad exception
bad allocation
__fastcall
__thiscall
__vectorcall
__clrcall
__stdcall
__cdecl
__pascal
__eabi
FlsSetValue
FlsGetValue
delete
FlsFree
AppPolicyGetProcessTerminationMethod
__unaligned
FlsAlloc
new[]
delete[]
AreFileApisANSI
LocaleNameToLCID
operator<=>
__ptr64
__swift_3
__swift_2
__swift_1
restrict(
__based(
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Type Descriptor'
`vector deleting destructor'
`scalar deleting destructor'
`vbase destructor'
`vector copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`eh vector vbase copy constructor iterator'
`vector constructor iterator'
`eh vector constructor iterator'
`managed vector constructor iterator'
`vector vbase constructor iterator'
`eh vector vbase constructor iterator'
`vector destructor iterator'
`eh vector destructor iterator'
`managed vector destructor iterator'
Complete Object Locator'
`virtual displacement map'
`vcall'
`string'
`udt returning'
`omni callsig'
`typeof'
`copy constructor closure'
`default constructor closure'
`local vftable constructor closure'
`placement delete closure'
`placement delete[] closure'
`vftable'
`local vftable'
`vbtable'
`anonymous namespace'
`local static thread guard'
`local static guard'
`dynamic atexit destructor for '
`dynamic initializer for '
operator ""
CloseHandle
CompareStringW
CreateFileW
DecodePointer
DeleteCriticalSection
EncodePointer
EnterCriticalSection
ExitProcess
FindAtomA
FindClose
FindFirstFileExW
FindNextFileW
FlushFileBuffers
FreeEnvironmentStringsW
FreeLibrary
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetConsoleMode
GetConsoleOutputCP
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetEnvironmentStringsW
GetFileType
GetLastError
GetModuleFileNameW
GetModuleHandleExW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
InitializeCriticalSectionAndSpinCount
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
LCMapStringW
LeaveCriticalSection
LoadLibraryExW
MultiByteToWideChar
QueryPerformanceCounter
RaiseException
ReadConsoleW
ReadFile
RtlUnwind
SetEndOfFile
SetEnvironmentVariableW
SetFilePointerEx
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
UnhandledExceptionFilter
WideCharToMultiByte
WriteConsoleW
WriteFile
CryptAcquireContextA
KERNEL32.dll
ADVAPI32.dll
P~QP-C
|c<*Sf
d55KVy
.?AVbad_array_new_length@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
2-5162777
2R5X5_6h7(858
;|<T=u?
<A=M=R=
4v8{8s9
='>->8>
586H6N6
;8===u>
0\1a1H3X3]3}4
=+=S=Y=e=
> >:>W>r>
?+?;?K?T?f?o?z?
2&2?2T2[2a2s2}2
5a5g5p5y5
6Y7^7q7
9&9/9D9M9|9
=#>W>_>q>~>
0(1/14181<1@1
576U6`6h6s6y6
7)70767B7G7M7R7Z7n7}7
7&8,8@8O8]8k8
::7:<:H:M:a:
: ;=;F;a;
;:<S<X<a<C=R=[=i=
112<2{2
2W3e3r3
8J8c8m8y8
<+<Z<e<
=@=T=p=
>5>C>J>P>
?;?O?U?
1+101a1j1
2)292>2C2^2h2x2}2
3-383=3B3c3s3
484c4|4
5"5+545e5}5
6.6e6s6z6
6!727@7G7f7
8;8P8`8m8
939B9c9
:%:d:z:
=$>?>y>
?2?;???E?I?O?S?]?p?
0!1N1|1
2"2,292C2S2
2)3N4p4
5#5n5u5|5
898W8\8a8f8
<^=x=}=
>)>1>K>Z>h>t>
?+?9?D?V?i?
4&484J4\4n4
5515C5U5
0m2S3G4n4
5/595F6
222E2O2h2
2)3?3z3
445C5Q5n5v5
1&101l1
2 3/3m3
4)5k5*6H6x6
<%<1<6<;<V<`<l<q<v<
=-=C=k=
223G3Q3>4d4
6'7Q7c7m7
9q96:|:
=0=b=|=
0#000B0
0'1<1E1N1
405Z5b5
=.=M=x=
=">D>h>
</<L<v<
0,000@0D0H0L0`0x0
1,1014181<1@1D1H1L1P1T1X1
2 2(20282<2@2D2H2L2P2T2\2`2d2h2l2p2t2x2
2H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7$7p7t7x7|7
8 8$8(84888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
p0t0x0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
: :(:0:8:@:H:P:X:`:h:p:x:
; ;(;0;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
:$:,:4:<:D:L:T:\:d:l:t:|:
;(;8;<;L;P;T;X;`;x;
H0T0X0\0`0d0h0t0x0|0d8x8
9 9(9,90989L9d9h9
:8:X:x:
:0;P;p;
<0<P<p<
=0=P=p=
>0>P>p>
?,?P?\?d?
= =$=(=,=0=4=
NQlqN>
njE11<
GqeV'|
y`@UR9C#
@g.n%
AXDvO,
DVZ*n
nlewI0
=E/BYh
s2SR}D
`:GUjn^F
k<!dqCr%T
#&_*]%
[kZLuA
"@2Wzb
@em=^>
GCRT3}
?_iIXm%
#_IwbVq
*@$Sd7
q8m~&b#
;ib\jf
16smx#
0GsyJaMF:i
lx) <Y
4ZxnnSx
)IeD13
QR|Z/B
g>]4dtqp
N$ciC-kb
!x_V1sv
dl.cS{
3[gf_v
cwgH&~
.)0`T#S
v ?E7~
R]@<f9B'44C{7
{S!biN
4<c>_Z
0=_tcn;
E7M*nnc
By*4:n
|C`]bA
9{4}?2
D[HWZ:
N"|ehJ
*d46&6\~
N-i}qGP
EgDb5|
@DAhl?l<
~kll\07U}p,
L)Qd)I
Q6"9QT
'IE{+<]
WsEyAN8u
u3i(u,G
SNQ[W+
((((( H
dddd, MMMM dd, yyyy
MM/dd/yy
syr-sy
February
January
Thursday
Tuesday
Wednesday
Saturday
Sunday
Monday
Friday
div-mv
August
zh-cht
HH:mm:ss
zh-chs
October
November
September
December
smj-no
sma-no
quz-bo
uz-uz-latn
az-az-latn
sr-sp-latn
bs-ba-latn
sr-ba-latn
uz-UZ-Latn
az-AZ-Latn
sr-SP-Latn
bs-BA-Latn
sr-BA-Latn
kok-in
uz-uz-cyrl
az-az-cyrl
sr-sp-cyrl
sr-ba-cyrl
uz-UZ-Cyrl
az-AZ-Cyrl
sr-SP-Cyrl
sr-BA-Cyrl
mscoree.dll
sms-fi
smn-fi
kernelbase
smj-se
sma-se
quz-pe
quz-ec
syr-SY
div-MV
zh-CHT
zh-CHS
smj-NO
sma-NO
quz-BO
kok-IN
sms-FI
smn-FI
smj-SE
sma-SE
quz-PE
quz-EC
api-ms-win-core-file-l1-2-4
user32
kernel32
advapi32
api-ms-win-core-file-l1-2-2
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-fibers-l1-1-0
api-ms-win-core-string-l1-1-0
ext-ms-
api-ms-
CONOUT$
api-ms-win-core-processthreads-l1-1-2
api-ms-win-appmodel-runtime-l1-1-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-localization-obsolete-l1-2-0
ext-ms-win-ntuser-dialogbox-l1-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Stelpak.4!c
Elastic malicious (high confidence)
ClamAV Win.Packed.Fugrafa-10037096-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Generic.cc
ALYac Trojan.GenericKD.74670876
Cylance Unsafe
Zillya Clean
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:Win32/Stelpak.6ddd32d1
K7GW Clean
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Trojan.Win32.Genus.WXO
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Generik.CVFVOGF
APEX Malicious
Avast Win32:Evo-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win32.Stelpak.gen
BitDefender Trojan.GenericKD.74670876
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.74670876
Tencent Trojan.Win32.Kryptik.16001480
Sophos Mal/Generic-S
F-Secure Trojan.TR/AVI.XWorm.sphdl
DrWeb Trojan.PWS.Lumma.801
VIPRE Trojan.GenericKD.74670876
TrendMicro Clean
McAfeeD ti!A22F6DB00774
Trapmine suspicious.low.ml.score
CTX exe.trojan.stelpak
Emsisoft Trojan.GenericKD.74670876 (B)
Ikarus Trojan.SuspectCRC
FireEye Generic.mg.7949220a0b341111
Jiangmin Clean
Webroot Clean
Varist W32/Trojan.NNPM-2372
Avira TR/AVI.XWorm.sphdl
Fortinet W32/PossibleThreat
Antiy-AVL Trojan/Win32.Stelpak
Kingsoft malware.kb.a.872
Gridinsoft Malware.Win32.XWorm.tr
Xcitium Malware@#a50tfxkfr9v2
Arcabit Trojan.Generic.D473631C
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Wacatac.A!ml
Google Detected
AhnLab-V3 Trojan/Win.Generic.R675910
Acronis Clean
McAfee Artemis!7949220A0B34
TACHYON Clean
VBA32 Clean
Malwarebytes Spyware.Lumma
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Stelpak!8.1B214 (TFE:5:kcmEtnJh2FU)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.272815677.susgen
GData Trojan.GenericKD.74670876
AVG Win32:Evo-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.