Static | ZeroBOX

PE Compile Time

2017-08-09 21:22:27

PE Imphash

60fb7881a24261de66da7b0e94e99a33

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00024000 0x00000000 0.0
UPX1 0x00025000 0x00014000 0x00013a00 7.89485161111
.rsrc 0x00039000 0x00003000 0x00002400 4.78391727113

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0003a088 0x000010a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ICON 0x0003a088 0x000010a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x00034228 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_DIALOG 0x00034228 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_ACCELERATOR 0x000321e0 0x00000080 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x0003b134 0x00000022 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x0003b15c 0x00000110 LANG_ENGLISH SUBLANG_ENGLISH_US 0420 Alliant virtual executable common library not stripped

Imports

Library GDI32.dll:
0x43b2d0 EndDoc
Library KERNEL32.DLL:
0x43b2d8 LoadLibraryA
0x43b2dc ExitProcess
0x43b2e0 GetProcAddress
0x43b2e4 VirtualProtect
Library SHELL32.dll:
0x43b2ec ShellAboutW
Library USER32.dll:
0x43b2f4 EndPaint

!This program cannot be run in DOS mode.
J:R2a/
|tld\T4
8u La
$h:p4c]S
XhHo6nC
B9=cm{
\KY+,d
9d-`T/
{-B8`Q
&f'5$7Z
s2v<3!2
fX>vsy
}~!wF
u>B<@3
HKD$8l
<rt"<w
S>1t]x
~F3r`K
=h(Gd6
!B8HaKd
6PVV;`A
uYhL@
>tYP82
<=;GVu
oKt3t
2<@Dv8!
9{"k6^@
}wXTx\^]
;WF9A<
ttuu9H
uuuuu#@
fdvwvvv
(wvvwY
eYwwwwwey
En uxP#
&5Yf;$
]s&\CAD
#t-{^9
%UW;Vp
[)4>z2
D6{5[@
(W4T+8
gld|mYF
z{QD}[
5&w u"o"H|'
M<it-<ot)<ut%<xt!<Xt
4G|xtpl
l9 L 3O
Q$E$SF
(U}@If
R<~,WPB
xH|%C=
-65!PnM
a9t+D;
D4-E*"4
{dds]xG$vHHddddHHHH
C8t=agoc
UQPXPl
:hCM]~
M~OtIIQuf>v
4#M3 I
Z]9is
J400q02n
qm$~Ho
<z~$<A
zkVq-
2869Xu
AR.PD=i#
MW_( 8
Y,#]0so
-lcF4h0
Ft,Ot
nR%yeT
1~[$9<
?xt4U;V!^
>Tt^HtT
et7h!:AA
o 0#td
#RQl'c%c
8]sV L@{
?uE8VW
-dCrB1Y
Oe"`u.R
,VBX"d
Pj1"v$
't>>pP
6u8j!h
Ap4Hue
t)H"|
YUXmIs;
[YE/*R
hV n$R
2r 8^+
Pa4]r[
lG0R.4*G
,D<E,G
@FDGr$
,Gx<|=
V)&MXR9
lptxPU
LDPTK.
+U,RVv$
QW@C: z73
y81V)0h
q|vskQ
|Yd<.u1
KoA*j
iR@Bc^
()\3D
GBdLD8
6>38L;0
(PQ.rJX(
N,7+VF
Cfk*lW
<o/(RN
),P*F3zPT
}};Sd@hq|
Rk/x.2-
)%]wwTH
P&:)&-
FAJ|uoQ
\Tsw$4
|x2222tplh2222d`\X
vVVWD%
Iirstf
)x;=|E
ExDheH
`I E"(
-$QLXd
*hQ'@?"
Yw,VA'[Q
HtTD%H
=X60U0
;7|G;p
zu&} m
-B7%"
1rXtR99
iLXft~
Unknown
exceptionglU
bad a`M1
llocaHe
ExitPr1ess
16LE;UNICODE
T_'dc=
Feseb_
lM)=@H
n@oCGT
_Uyx)/i
8aQgo=R
q<x<7p
%m{=Kk){
Eq![PM
FlsFre2
+SystemFuncp]
/wJS{=
6l{wgy{a
GE]d1wj
G?#H:mm:57
KGC7yC?;
3#aturd
('8PW#
Compl
~e Obj
HiU1y [7
`$Ar#y'
TypeDAa
oCc th
`m`age
wDcopy
RTTI{EH
udy$`jnd`+a
6?ir,,
dis"tpJ
4+*#|&
i|pGlhd
4HD@<8
40,($M
row}[G<
c@::py
ymouTnBsIc
vm{"C"
puZalk
]hvq'/`d
XJkT#w
}';n ;B)
'KNOWN
 !"#$%&'O*+,[
3456789:;S>Km
xyz[\]^_`{|}~
JABCDEFGHIJKLM
FPQRST
XYZ@Xa
LC_TIME
MONETARY
gd]km)ObG
o`!O
{J37vu
oeTm3P
wa+CGl#
z#@n$
=oAo!\^![snsO/
H^d?`Y9Z
p"?g;KgG0
H`&LK3
sguwos.exe
_My\1^Q
.?AVlogic_error@
[WthD
_of_ra&e
@MX?vX
7e!03Gg:
P<4,$e
4dT@,?$
$%#>73
R&.>09
N;!m '
9<!?>(U;
m&l,5>2-+?#B<
_X-.!#6
C3=#` )
v,'" >e
pk\h(_
_A+)/%
p$(?>,
/245L
,;@Xj
:zX/\bi'
%n]V;<
x>/'u.8(4K
Vh0'G*
J5~/.?1#&
,*(5*TZ
!v -=0)n
9v6Ajt+
<e8i3,
59TK4J
=|!E'I/
F[$/>,
":&6k
jPzi'7
Q$c&4<
>o$87.
n[7n+63Q
5F/}[y
09!6 H
Fh!8,#
(]Q!<"
j9':mi
jt[ZJ5}
.d4&P6}
+-$G%J,
tj=m1Z
ZE}`1Th
.&2ZKo
89KK[5
#+-Es:`
$$$Xh4
|6Cz(Q
h?*4'>
f0%EH)
!@:>4,l
V(E,:4A4
JoK1*:*$8
''1*6d
s6S'-ZQ
83&3;&
[+|.:2
tusilaf
BiyeHT
E<AAhSl
CancelWai&T*
sA*4ck.u
HAsFim
fR?.dRes%rm
Ex7LoadLi
sskUtm
eNo"fig
W2J6cT
Xw@.&$
XPTPSW
8888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888
88888888888886
HH8888888888888
8888888888888
j8888888888888
8888888888888/
8888888888888
})88888888888886H
j8888888888888
8888888888888
8888888888888
o78888888888888
8888888888888
8888888888888
<?j8888888888888
88888888888886
8888888888888/
8888888888888
8888888888888
88888888888886Y
8888888888888
8888888888888
78888888888888/
88888888888886
88888888888886
78888888888888
Ell:`QQ0
8888888888888/
H8888888888888
8888888888888
8888888888888
8888888888888
\88888888888888/
_\888888888888888
68888888888888888/7
888888888888888886GA
888888888888888888
U> OhY
688888888888888888886
\888888888888888888886jA
f\888888888888888888888/
y88888888888888888888886
\88888888888888888888888/
8888888888888888888888886
7_/8888888888888888888888888yof
8888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888888
~{{~||}
{{~|}{|
}}{~|~
GDI32.dll
KERNEL32.DLL
SHELL32.dll
USER32.dll
EndDoc
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
ShellAboutW
EndPaint
VS_VERSION_INFO
StringFileInfo
457aa56b
FileVersion
8.1.6.67
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Dump.4!c
Elastic malicious (moderate confidence)
ClamAV Win.Packed.Gandcrab-6914437-0
CMC Clean
CAT-QuickHeal Trojan.Ghanarava.17377303009ccced
Skyhigh BehavesLike.Win32.Generic.mc
ALYac Dump:Generic.Mint.Zamg.8.EE4F4168
Cylance Unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (W)
Alibaba Trojan:Win32/Chapak.d9c1a1eb
K7GW Ransomware ( 00547c951 )
K7AntiVirus Ransomware ( 00547c951 )
huorong HVM:Trojan/SelfLoader.a
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec Infostealer.Rultazo
tehtris Clean
ESET-NOD32 a variant of Win32/Kryptik.GPFY
APEX Malicious
Avast Win32:Trojan-gen
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.Chapak.byhu
BitDefender Dump:Generic.Mint.Zamg.8.EE4F4168
NANO-Antivirus Trojan.Win32.Kryptik.fmprui
ViRobot Clean
MicroWorld-eScan Dump:Generic.Mint.Zamg.8.EE4F4168
Tencent Malware.Win32.Gencirc.14352f77
Sophos Mal/GandCrab-G
F-Secure Heuristic.HEUR/AGEN.1306094
DrWeb Trojan.MulDrop9.2191
VIPRE Dump:Generic.Mint.Zamg.8.EE4F4168
TrendMicro Ransom_Gandcrab.R002C0CAR25
McAfeeD Real Protect-LS!168E78A7154B
Trapmine malicious.moderate.ml.score
CTX exe.trojan.chapak
Emsisoft Dump:Generic.Mint.Zamg.8.EE4F4168 (B)
Ikarus Trojan.Win32.Crypt
FireEye Generic.mg.168e78a7154b2453
Jiangmin Trojan.Chapak.baw
Webroot Clean
Varist Clean
Avira HEUR/AGEN.1306094
Fortinet W32/Kryptik.GPMP!tr
Antiy-AVL Trojan/Win32.Chapak
Kingsoft Clean
Gridinsoft Clean
Xcitium TrojWare.Win32.Azden.PB@8fhzsu
Arcabit Dump:Generic.Mint.Zamg.8.EE4F4168
SUPERAntiSpyware Clean
ZoneAlarm Mal/GandCrab-G
Microsoft PWS:Win32/Zbot!ml
Google Detected
AhnLab-V3 Malware/Win32.Generic.C3022206
Acronis Clean
McAfee Artemis!168E78A7154B
TACHYON Clean
VBA32 BScope.Trojan.Fuery
Malwarebytes Generic.Malware/Suspicious
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Ransom_Gandcrab.R002C0CAR25
Rising Trojan.Kryptik!8.8 (CLOUD)
Yandex Trojan.GenAsa!WF+i2Ld6dJI
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.74102347.susgen
GData Dump:Generic.Mint.Zamg.8.EE4F4168
AVG Win32:Trojan-gen
DeepInstinct MALICIOUS
alibabacloud Trojan:Win/Gandcrab.AJH2XJC
No IRMA results available.