Static | ZeroBOX

PE Compile Time

1970-01-01 09:00:00

PE Imphash

147442e63270e287ed57d33257638324

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000020a8 0x00002200 6.0311413928
.data 0x00004000 0x00043cf0 0x00043e00 7.04916882223
.rdata 0x00048000 0x00000910 0x00000a00 4.50529584008
.pdata 0x00049000 0x000002b8 0x00000400 3.21817222064
.xdata 0x0004a000 0x00000238 0x00000400 2.63377537785
.bss 0x0004b000 0x000009d0 0x00000000 0.0
.idata 0x0004c000 0x000008d8 0x00000a00 3.99427023764
.CRT 0x0004d000 0x00000068 0x00000200 0.27091922826
.tls 0x0004e000 0x00000010 0x00000200 0.0

Imports

Library KERNEL32.dll:
0x44c224 CloseHandle
0x44c22c ConnectNamedPipe
0x44c234 CreateFileA
0x44c23c CreateNamedPipeA
0x44c244 CreateThread
0x44c25c GetCurrentProcess
0x44c264 GetCurrentProcessId
0x44c26c GetCurrentThreadId
0x44c274 GetLastError
0x44c27c GetModuleHandleA
0x44c284 GetProcAddress
0x44c28c GetStartupInfoA
0x44c29c GetTickCount
0x44c2bc ReadFile
0x44c2c4 RtlAddFunctionTable
0x44c2cc RtlCaptureContext
0x44c2dc RtlVirtualUnwind
0x44c2ec Sleep
0x44c2f4 TerminateProcess
0x44c2fc TlsGetValue
0x44c30c VirtualAlloc
0x44c314 VirtualProtect
0x44c31c VirtualQuery
0x44c324 WriteFile
Library msvcrt.dll:
0x44c33c __getmainargs
0x44c344 __initenv
0x44c34c __iob_func
0x44c354 __lconv_init
0x44c35c __set_app_type
0x44c364 __setusermatherr
0x44c36c _acmdln
0x44c374 _amsg_exit
0x44c37c _cexit
0x44c384 _fmode
0x44c38c _initterm
0x44c394 _onexit
0x44c39c abort
0x44c3a4 calloc
0x44c3ac exit
0x44c3b4 fprintf
0x44c3bc free
0x44c3c4 fwrite
0x44c3cc malloc
0x44c3d4 memcpy
0x44c3dc signal
0x44c3e4 sprintf
0x44c3ec strlen
0x44c3f4 strncmp
0x44c3fc vfprintf

!This program cannot be run in DOS mode.
P`.data
.rdata
`@.pdata
0@.xdata
0@.bss
.idata
AUATUWVSH
[^_]A\A]
[^_]A\A]
ATUWVSH
@[^_]A\
ATWVSH
X[^_A\
ATWVSH
X[^_A\
ATUWVSH
0[^_]A\
0[^_]A\
ATUWVSH
P[^_]A\
P[^_]A\
UAWAVAUATWVSH
[^_A\A]A^A_]
ATUWVSH
[^_]A\
ATWVSH
([^_A\H
tNHcA<H
tTIcB<L
tCHcA<H
tKIcA<L
tSIcK<L
bYLa1YLa1YLa1?
1XLa1z
1SLa1P4
1RLa1YL`1
1mLa1?
1XLa1?
>MV|K}A
}w|ru_&_}||O
}|viR;yN
}|viR;yN
;fI}A~
>@5 tJ
3rB!GItJ
J}5/0B
8>RV8I}A
>MV(O}Aru
t~}51ta
>HV8G}Aru
>@5=tb
J}AtM}
J}AtM}
>UV<O}Aru
TVdK}A}
>MV|K}A~
XeudvW}A
jV|M}A|M
G}AtM}
>XV<G}Aru
J}};yN
>Jo6c
U5'fh59fb
J}5/0B
J}5/0B
>LV8V}A|m
Vpk}A|m
VxQ}A|m
)J}5/0B
J}5/0B
Ujn*J}5/0B
VDh}A|m
J}5/0B
J}5/0B
J}5/0B
J}5/0B
J}5/0B
J}5/0B
J}5/0B
,J}5/0B
}VLD}A
>OVtJ}AtM
/J}U$yN;%
>I5'fj59
>IV<_}Aru
VPo}AtM
#J}5/0B
&J}5/0B
|yjZ%J}5/0B
J}5/0B
V8g}A|m
VPd}A|m
A#>Z;7
(J}5/0B
JV5/0B
)J}5/0B
JV5/0B
j*"J}=
Vxz}Aru
Vxh}A|sk
Vp{}A|m
%J}5/0B
jr<J}5/0B
:J}5/0B
A">Z;7
,J}5/0B
;J}5/0B
A">Z;7
V4~}A|m
JW5/0B
jf/J}5/0B
A">Z;7
|zj2.J}
V8h}Aru
|zj:2J}5/0B
2J}5/0B
#J}5/0B
jBHJ}5/0B
=j*HJ}5/0B
J}5/0B
J}5/0B
Vpg}A|m
=jRJJ}5/0B
jB&J}5/0B
ejR#J}5/0B
jN5J}5/0B
/J}5/0B
5J}5/0B
W>TV\g}A|m
5J}5/0B
:V4t}A|m
J}5/0B
LJ}5/0B
>JVh`}Aru
>MV|a}A
"jf<J};7
uVH~}Aru
X>QVpA}Aru
"jF<J}
OJ}5/0B
Uj.OJ}5/0B
}jz=J}5/0B
jZEJ}5/0B
=J}5/0B
5j6BJ}=
gj*OJ}
@J}5/0B
>TVpT}A
9J}54^
V`x}Aru
j"CJ}5/0B
YJ}5/0B
|bj**J}
J}5/0B
>MV,w}A|m
>MVHv}A|`
|~jj4J}
|cjR7J}=
IJ}5/0B
>WVPc}A
5?>QA
B`5-ti
5/>xVt}
>M5/]{k
\5$]GS
J}A;yN
J}A;yN
q|mjNY
>M5/]G
H}A|~}
>RV<\}A
>J5$JT
>IA'0B
>IV$I}A
j6+J}W
>BV|i}A
>NVXD}A
>OVpD}A
|mjR2J}
j^3J}U
|uj*6J}
>ZV\u}A
>IV,w}Aru
>BVPq}A
8>R5/]
>U59]O
>WV, }A
>C};yN
|ej:UJ}
K}A;yN
b5'];$
&B};yN
|zj6oJ}
jnoJ}5
W4K}A;yN
5?>QA!
=?Jiq;yN
|ejbvJ}
V<P}A~
|@i:tM
5W;M}A
W h}A;yN
V@i}AM
V(h}A|
V8h}A|
VHh}A|
VXh}At
j.bJ}U
BWmH}At\
k~rJ}5'
k6uJ}5'
k"hJ}5'
};yNr;yN
};yNr;yNr;yN
Ar;yNr;yNr;yNr;yNr;yN
4yNr;yNr;yNr;yN
Ar;yNr;yNr;yNr;yNr;yN
};yNr;yNr;yNr;yN
Ar;yNr;yN
vNr;yNr;yNr;yNr;yN
};yNr;yNr;yNr;yN
Ar;yNr;yNr;yNr;yN
Ar;yNr;yNr;yNr;yN
4yNr;yNr;yNr;yN
jztK};7
>@};yN
?>C};yN
57>QV|
ix|ci[
VD+}AM
zVH-}A
>RVtG}A
};yNr;yNr;
vNr;yNr;yNr;yNr;
>[VXJ}A|~}
J}A;yNr;yNr;yNr;yNr;yNr;
}4yNr;yNr;yNr;yNr;yNr;
PV`R}Ag
4yNr;yNr;
|f}n|e
|{}nrn
5<JR;7
>p5.6{A
]}AtM}
JAUI>.
j^(J}y
VDh}A0
VLK}Ag
uq};yNr;yNr;yN
>LVl^}A
>XV0L}A
J}=?JkJ
kJ}.|zjr
}}At}}U
IJ}=?Ji
j>)J}.
VPh}Ag
>S58][E
};yNr;yNr;yNr;
Ar;yNr;
r;yNr;
};yNr;y
}At}}Wj
jVXJ}=
>MVdX}A
X}AtM}
6IA|zj
PJ}=<Jk
O}A|jk
jJSJ}y
j.SJ}y
7>T5:]
jnhJ}=
6IA|zj
>p5<]o
Nr;yNr;yNr;yNr;yNr;
>6CKOC}A
,}At}}U
t}A;yN
oJ}r;yN
Ar;yNr;yNr;yNr;yNr;
jNbJ}54
JJ};yN
jvcJ}54
cJ}=?J
gjzyJ}
J}VH0}A0
jVSJ}.
j"XJ}H
J}r;yN
>C};yN
>zV41}A|1
VHI}Aw
|MjzuJ}5s
j&nJ}.
K}A;yN
};yN5&
uit;yN
4yNr;yNr;yNr;yNr;yNr;
~tm}}g
EVt_}A~
gj^6J}
:dK}A|
K}A|mi
5!>LV4
J}59]k]
}A^J}@
yNr;yN
4yNr;yNr;yNr;yNr;yN
vNr;yNr;yN
};yNr;yNr;yN
:r;yNM\
vNr;yNr;yNr;yN
Ar;yNr;yN
Ar;yNr;yNr;yNr;yNr;yN7
|zj~hJ}
:)K}A
vNr;yNr;
Eq};yN
>OV,#}AI
>OVL#}A
J}r;yN
|}j:yJ};7
J}r;yN
}AOJ}A
V,D|A|pih;yN
ttb56v
yNr;yNr;yNr;yN
;yNr;yNr;yNr;yN
cPIZD8
WRRslkC
=~6wAz2sEv>
Ir:{Mn&gQj"cUf.oYb*k]^
=~6wAz2sEv>
Ir:{Mn&gQj"cUf.oYb*k]^
=~6wAz2sEv>
Ir:{Mn&gQj"cUf.oYb*k]^
=~6wAz2sEv>
Ir:{Mn&gQj"cUf.oYb*k]^
.l+7y;
(j'1{9
K|i bU
Bur;yN
q8zMn'eRQ
Fql%gPs:xO
|5w@m$fQ
Rev?}J
6x1sDV]jc*h_
g.l[0y;
\kp9{L
a(j]2{9
la[6 f.
mglR8p
Fqi bUE
z3qF`)k\W
\ku<~I
Ox}4vA
#j(:s1
Gpq8zMp9{LN
{2pG7~<
x1sDl%gP
e,nY~7uB@
w>|K"k)
2v?}JU
tuI$ngU2fP
.tSt{K jo
h`\?7;
z{I*qv@$la[6glR8
ngU2cn[9tuI$y|G/ZCm
=4qfg]:oiV7t{K }u@-B_q
fkQ6h`\?z}K$tvF-.
6n9r*[}
6n9r*[}c^
6n9r*[}0U
>Q=$.Q-$
(v]m(V]M(
]u(n]U(N]
\u)n\U)N\
[u.n[U.N[
Zu/nZU/NZ
Yu,nYU,NY
Xu-nXU-NX
"~We"^WE"
#~Ve#^VE#
~Ue ^UE
!~Te!^TE!
&~Se&^SE&
'~Re'^RE'
$~Qe$^QE$
%~Pe%^PE%
*~_m*V_M*
+v^m+V^M+
(v]m(V]M(
)v\m)V\M)
.v[m.V[M.
/vZm/VZM/
,vYm,VYM,
-vXm-VXM-
"vWm"VWM"
#vVm#VVM#
vUm VUM
!vTm!VTM!
&vSm&VSM&
'vRm'VRM'
$vQm$VQM$
]e(f]U(V]E(F]
)>\=).\-)
Ru'vRe'fR
/.Z]/NZM/
Y5,6Y%,&Y
Yu,vYe,fYU,VYE,FY
X5-6X%-&X
+~^E,FY
X5-6X%-&X
Xu-vXe-fXU-VXE-FX
W5"6W%"&W
Wu"vWe"fWU"VWE"FW
V5#6V%#&V
vUe fUU
!>T=!.T-!
Tu!vTe!fTU!VTE!
%c%c%c%c%c%c%c%c%cMSSE-%d-server
Unknown error
Argument domain error (DOMAIN)
Overflow range error (OVERFLOW)
Partial loss of significance (PLOSS)
Total loss of significance (TLOSS)
The result is too small to be represented (UNDERFLOW)
Argument singularity (SIGN)
_matherr(): %s in %s(%g, %g) (retval=%g)
Mingw-w64 runtime failure:
Address %p has no image-section
VirtualQuery failed for %d bytes at address %p
VirtualProtect failed with code 0x%x
Unknown pseudo relocation protocol version %d.
Unknown pseudo relocation bit size %d.
.pdata
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.3-win32 20200320
GCC: (GNU) 9.3-win32 20200320
GCC: (GNU) 9.3-win32 20200320
GCC: (GNU) 9.3-win32 20200320
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.3-win32 20200320
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.2-win32 20191008
GCC: (GNU) 9.3-win32 20200320
CloseHandle
ConnectNamedPipe
CreateFileA
CreateNamedPipeA
CreateThread
DeleteCriticalSection
EnterCriticalSection
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetLastError
GetModuleHandleA
GetProcAddress
GetStartupInfoA
GetSystemTimeAsFileTime
GetTickCount
InitializeCriticalSection
LeaveCriticalSection
QueryPerformanceCounter
ReadFile
RtlAddFunctionTable
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
SetUnhandledExceptionFilter
TerminateProcess
TlsGetValue
UnhandledExceptionFilter
VirtualAlloc
VirtualProtect
VirtualQuery
WriteFile
__C_specific_handler
__getmainargs
__initenv
__iob_func
__lconv_init
__set_app_type
__setusermatherr
_acmdln
_amsg_exit
_cexit
_fmode
_initterm
_onexit
calloc
fprintf
fwrite
malloc
memcpy
signal
sprintf
strlen
strncmp
vfprintf
KERNEL32.dll
msvcrt.dll
Antivirus Signature
Bkav W64.AIDetectMalware
Lionic Trojan.Win32.CobaltStrike.4!c
Elastic Windows.Trojan.CobaltStrike
ClamAV Win.Trojan.CobaltStrike-9044898-1
CMC Clean
CAT-QuickHeal Trojan.Ghanarava.1736797474b38c59
Skyhigh BehavesLike.Win64.Backdoor.dc
ALYac Dump:Generic.Beacon.Marte.B.B1B44825
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.CobaltStrike
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Backdoor:Win64/Artifact.cba73e7e
K7GW Trojan ( 00580b4c1 )
K7AntiVirus Trojan ( 00580b4c1 )
huorong Backdoor/CobaltStrike.d
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec Backdoor.Cobalt
tehtris Clean
ESET-NOD32 a variant of Win64/CobaltStrike.Artifact.A
APEX Malicious
Avast Win64:HacktoolX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan.Win64.CobaltStrike.gen
BitDefender Dump:Generic.Beacon.Marte.B.B1B44825
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Dump:Generic.Beacon.Marte.B.B1B44825
Tencent Trojan.Win64.Cobaltstrike.ka
Sophos ATK/Cobalt-JW
F-Secure Heuristic.HEUR/AGEN.1377194
DrWeb BackDoor.Meterpreter.157
VIPRE Dump:Generic.Beacon.Marte.B.B1B44825
TrendMicro Backdoor.Win64.COBEACON.SMA
McAfeeD ti!8BCD638706D2
Trapmine Clean
CTX exe.trojan.cobaltstrike
Emsisoft Dump:Generic.Beacon.Marte.B.B1B44825 (B)
Ikarus Trojan.Win64.Cobaltstrike
FireEye Generic.mg.ad4ad1de86b6965b
Jiangmin Trojan.CobaltStrike.ih
Webroot W32.Malware.gen
Varist W64/Kryptik.GRP
Avira HEUR/AGEN.1377194
Fortinet W64/Kryptik.BVR!tr
Antiy-AVL RiskWare/Win64.Artifact
Kingsoft Win64.Trojan.CobaltStrike.gen
Gridinsoft Trojan.Win64.CobaltStrike.tr
Xcitium Clean
Arcabit Dump:Generic.Beacon.Marte.B.B1B44825
SUPERAntiSpyware Clean
Microsoft Backdoor:Win64/CobaltStrike.NP!dha
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Trojan-FWTM!AD4AD1DE86B6
TACHYON Trojan/W64.CobaltStrike.295936
VBA32 Trojan.Win64.CobaltStrike
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Backdoor.Win64.COBEACON.SMA
Rising Backdoor.CobaltStrike/x64!1.E382 (CLASSIC)
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
GData Dump:Generic.Beacon.Marte.B.B1B44825
AVG Win64:HacktoolX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan:Win/Cobaltstrike.c4124b28
No IRMA results available.