Static | ZeroBOX

PE Compile Time

1992-06-20 07:22:17

PE Imphash

e253f8ec0371c0d6a5b2b4676e8c61c6

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x00a20000 0x00000000 0.0
UPX1 0x00a21000 0x0000f000 0x0000e600 7.85913201594
.rsrc 0x00a30000 0x00008000 0x00008000 4.24939051937

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00a378f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00a378f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00a378f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00a378f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00a378f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00a378f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00a378f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00a378f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00a378f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00a378f8 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_STRING 0x00a2daac 0x000002a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00a2daac 0x000002a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00a2daac 0x000002a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00a2daac 0x000002a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00a2daac 0x000002a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00a2daac 0x000002a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_STRING 0x00a2daac 0x000002a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x00a2dd78 0x00000108 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x00a2dd78 0x00000108 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_RCDATA 0x00a2dd78 0x00000108 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00a37d64 0x00000092 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library advapi32.dll:
0xe37e84 RegCloseKey
Library gdi32.dll:
0xe37e8c TextOutA
Library KERNEL32.DLL:
0xe37e94 LoadLibraryA
0xe37e98 ExitProcess
0xe37e9c GetProcAddress
0xe37ea0 VirtualProtect
Library oleaut32.dll:
0xe37ea8 VariantCopy
Library shell32.dll:
0xe37eb0 ShellExecuteA
Library user32.dll:
0xe37eb8 EndPaint

This program must be run under Win32
StringX
TObjectd
System
2,($S+ol
m[B5C,
rRwCY(
8W.k@&
zV=L]Q
\Xp5RB
,]~D0e
0tl~]M
RD/3%C
jd("\[
R)#NtHX2!
+t_$xtZ
~KxI[)
A1T0+OFTW
ARE\Borland\Delphi\RTL
QagRQSa|
ZTUWVS
.c/-Rf;m
}&^~")
KtrGQT
M]HeM+
K<`"#;
@_?@%
kernel32.dll
etLong
PathNameA
ftwareCeca
Zb#{Xp
= 6Py}*N
TSearchRecX
Exception
EOutOfMemory
EIn]Err[
EDivByZ
sInverflow /
`khW=
[Castox[
EC%(;$Ci
H4wPre
tjlCk@x
[~$TMulR
XW1,w#
/@w2]j
vVs[ H
/I0r=<9w9i
)Ppk=a
{(A,W.
INFNAN
<Y[M]ml
^*}HtI
ycg@c5
H#9l@*r
(h+yX1
~[^,Hm
4!FT;
D<.Tt
oEm_6IHu
!h"aIG"
DiskFreeSp
V67l*%
}M(-|!wH;r
lN6'<d
oleaut
AddSubMul
<DivId
p4FromSt
GyBool
sstrCy
=cxx-
!ked7D
#t?Htb
|DoubCCurrenc:
lUnknowDecie
TsPLFM
vsJE!`
R we<P6X
_N^$/P
|ListdWd
sAdap,r
$Xa2gy
_4YHv
""C6awb
Vr 8$Ug
I{zl#E
":AqC}
8(%3$s
^<7Qn`
4M>M\jy
3EOTa/
FH.6ln
;1.0.4
V2g?CC
=*nAMU0
)6:(Z/
JH0@!O8,S
Ctz;B0>{c
<3;Iw!
++UsYB
18/5!
PoX{3"g
ooqOrLt
/(|8`F
Ts S((,
v@8<|!#
<5Q@G2
diFTJL
p/?WtX
htestamin
XYkAlu)
N ooda
dez+=
Izdvoji u
-_Yga
%]Nj[B
M[vsHsou
;_Sob5*
6.avawf
S'-kpo
sfxuad
E>xr6
G.4f TB
MD1k,'
DuI7/$
windowc
VQMS Sans
waos`C
lore; "
at 001
23456789ABCDEF
4M08@HPX4M
| Copyrigh
&1995-
6 M?k Adl[
#+3;CW
MyImQ bi
T+=blo
symbolsS
4M0H`|
4M4DXx
4Pd|i
dpg3Q0zn
< D;t'
"4DP\n
0FRbpM
://74.cz
5G/I!F'
i+n3a/l
ngos%g
Aa7gya
"M,M7o
I$MG&00
#,%?1P6
{<:y&q?
sfxheam
^Classes
"RTL'w
woUtil2CVarian=$
Q=hfosAc
YmmCtrl
Mz[\u_
(ShlObj
_ellAPI
ForS5g
VirtuHQRry~H
_+Time
Dhp~y5
3SRe'M
DefamtL;5
Spac:DH
Cug{gO0
MOiBytwb-
@H: +&
O<nKey
G'StzZ
ayPX4I
zp?chn}
>@CODE
`DATA%
XPTPSW
wwwwwwwwwwwwwwwwwwwww
Se%ae`
cCBR_p
RRRRP%
CCCC@40`P@
cG?CCRRRRP`R
4qaCCRCCCB
pqacG%%apppppppaB
prRRRPa
wwwwwwwwwwwwwwwwwwwww
wwwwwwwwwwwwwww
se%%%%% R
u%6RRRRRPp
wwwwwwwwwwwwwww
wwwwwwwwp
wwwwwwww
!

((((&&(&&&(&(&&&&&&(((#&&###
*)))))))))))))))))))))
eIDATx
""""""""""""""""""""""""""""""""""""""""
'Px0&D
XXX8Pvh8v
],//cuu
n<DSbb
!KD4)#
NDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDDD
advapi32.dll
gdi32.dll
KERNEL32.DLL
oleaut32.dll
shell32.dll
user32.dll
RegCloseKey
TextOutA
ExitProcess
GetProcAddress
LoadLibraryA
VirtualProtect
VariantCopy
ShellExecuteA
EndPaint
C:\Windows\Fonts\
0007D49D72
xsfxdel~.exe
)+wif
t*}Tq:
2jRM(q
F/GzBY
Vil{5{.
@6KcFRv
[z)`Ec
praq~fA
0?5mnz
Q5Yo{H
;'':D
lr}-s
brLoqaLqy
v&ZyN/z
V@B!qi
XRqr9K)
n)..,N
O#?^nT
B<*EU)Lj
HzWI;a
2MjwM\
T0*fwT
15Y@O=]
RM:YN3
A }W06
\43gv@{R
aKoL/nS>
bA0?1G_
xL\vv'
YR~vbfAV~v
|${r!e'
y\w{{&
#o-iw"
smss.exez
x;]C:
I"Js#`1
Dyy@_^
|?_F^)
7lsN5/Nh\
@#FAQi
!`hT&(Z
E{4A@.
630C9^-
D`DL/F
=65^)4FN
%0})Zg!
g0;I^a
,LtG>M,o
rvKH+`
LZ(Z A#
"`mI{2Q
P&?6O:
qrBK8x
bO(]v4m
i/5).cN
[pad{2}eF
q>N:u
C~Ukdo&
S5E4;+
G>(5of
9I{ -h
8:df!PG
e KP*N)
={~?^/
gMPL&FQ|?
DEzy1S
u*K9it(Pt
y,FoWs
6}#l<5<<
De.%N
HH>~$!^
9wGb2rm2
Sj*_K+
N]iJLUO
QwAM (Z
lE+nb!L
LS ^{Nn
;8o'e;
&u3fY9
jq&[#q
{<fQ;S?
@ZN/IV
V7}%~X9
|!b2wSs.
XPIM3pxF
e0*\#<
;qVx=F=
J,-H,-
jme~P[
:"@`hX
):r2|D
x3SGcEjN
+Mm'kNH
pG~2uC
&\!c(c
@tT$$n
Iu*H.r
!6"bIW
L"Su }
9lJlN
9Y)<=>(
}:co8#M
IFK.>Zr
SO[8,k
CC*5B'
&|cWv[o
fT+h1?e
{oE
}0(.Ld
w`Uz*uJ`
;Q6_NQ
@5j`@1
[k(~bsbS
zFWHVP
L~2`ZW8
YFGKHe<
olA3xu>~#
<lutJy
sv9z!+
N4U*;NJ
K=;Bfr+
]\ofx7
NOdS9I$
M{LAPXA9
Il5\.l
vLt+>0
<Y}m`^u
<U=SYI4
;9QLvP
F1r;4m
6y|fL(~q-
*ydoWX
ul4Vj'O
cvSkyl}>5
a0>F?y
Q|FL{2
\ "\Gs
34YH{99O9:
]R6Id:
3DX+z|
"c!nTR
[jn;X$
*?su)'
")A9&b
a*HsCa
BedLr6M
v6;X|,\&
j`di;0qe
hj>lDO~
!2&OjK
CL]RBX^(4
yXhu},p
i?{Dc(zt
f`uv7mEv
&gjUlPHm;z
SKYe=03
G`57oY$(
w" nVY3
u%,"\!(
c1~R*7j,
]0!=^j
)A)Yi6
Q/ZkJLA5
}E{\5G
*#)r2kw
b^sXw&
8<?46.
8,:{;{Sv|
jbJIc7
;.W(mg(
mPZ=r=
|?Y }J
0c*XJ:m
7w|[_QZ5
e%{Z.n*)W\
MN.&^N
#D2o?%
}y(z^!
45>!->N
'*&>rzB
}xjJJB
DuJtlL\L
RHsL|T
<twWmw
@-0{v&
6 jsVNQ
FdJZ_
Hy?)-
~,:z\^
|">|gQ
CA}N&z
_;5dA
)Ug/5/
-;.F-Z
^7.|<i
5js8Z:
9<?1<?y<
:tJB{)
?7/wcKR
z!%21>
V:~\pPh
O)QD$)
;^=w}T
P3ANSA
MOga@a
V=')Tm
uy`nsOw(
7oXs#*
|?NS-qg
Z<j@
C7vt)B
>50ImJ
7DW>F6
eVOo{-
ef$oR#
DfAEKr
8puoU<u
Vff&*++
w78eI:
b;^*=T9U
VL+VGz2
FOM-Ey
}LP;^I
HDzqI\
|d|\Rb|
Br!y3y/
4h:4cZ
gV1o01
E^L^A>A~H~N
S6Sj)7)
x;x{ygx
KY+XkY;X{Y
;v-Hv,
|"ODrfAc
X#6"1
y5*PCjI
q6Wx^
6iOhOk{
].sous
Xo<n<c
$WZ[<S
g4L_ll
cI"I"Y$
NLH(&$
X=N':E
DESCRIP
Listca
DESCRIPTION
DVCLAL
PACKAGEINFO
MAINICON
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Fsysna.4!c
Elastic malicious (moderate confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Trojan.Ghanarava.168548223259d2f9
Skyhigh BehavesLike.Win32.Dropper.dc
ALYac Gen:Trojan.Malware.pmJfaug8CimO
Cylance Unsafe
Zillya Trojan.Heur2.Win32.491
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Trojan:Win32/Fsysna.9730d8b1
K7GW Riskware ( 0040eff71 )
K7AntiVirus Riskware ( 0040eff71 )
huorong Clean
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of Generik.MSKKII
APEX Malicious
Avast Win32:Dh-A [Heur]
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.Fsysna.hlqe
BitDefender Gen:Trojan.Malware.pmJfaug8CimO
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Trojan.Malware.pmJfaug8CimO
Tencent Malware.Win32.Gencirc.10bda3c2
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Gen:Trojan.Malware.pmJfaug8CimO
TrendMicro Clean
McAfeeD Real Protect-LS!D73C8C5B1187
Trapmine malicious.high.ml.score
CTX exe.trojan.pmjfaug8cimo
Emsisoft Gen:Trojan.Malware.pmJfaug8CimO (B)
Ikarus Trojan-Downloader.FraudLoa.ZF
GData Gen:Trojan.Malware.pmJfaug8CimO
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Antiy-AVL Trojan/Win32.Agent
Kingsoft Clean
Gridinsoft Trojan.Win32.CoinMiner.oa!s2
Xcitium Clean
Arcabit Trojan.Malware.pmJfaug8CimO
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft PWS:Win32/Zbot!ml
Google Detected
AhnLab-V3 Trojan/Win32.Fsysna.C4320496
Acronis Clean
McAfee GenericRXAA-AA!D73C8C5B1187
TACHYON Clean
VBA32 Trojan.Win64.Miner
Malwarebytes Generic.Trojan.Malicious.DDS
Panda Trj/CI.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Trojan.Fsysna!8.5F2 (CLOUD)
Yandex Trojan.Fsysna!tti2CG9oN9M
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.103916461.susgen
Fortinet W32/PossibleThreat
AVG Win32:Dh-A [Heur]
DeepInstinct MALICIOUS
alibabacloud Trojan:Win/Fsysna.hfyk
No IRMA results available.